Privacy Policy
Effective date: 21 August 2026 Last updated: 21 August 2026
1. Controller details
| Item | Details |
|---|---|
| Name of the controller | Happy Dev Solutions Kft. (a Hungarian limited liability company; referred to below as HappyDev or the Controller) |
| Registered office | 1202 Budapest, Brassó utca 4., Hungary |
| Postal address / office | 1203 Budapest, Török Flóris utca 70., 2nd floor 201, Hungary |
| Company registration number | 01-09-387525 |
| Registering authority | Company Registry Court of the Budapest-Capital Regional Court (Fővárosi Törvényszék Cégbírósága) |
| Tax number | 27183854-2-43 |
| info@happydev.hu | |
| Website | https://happydev.hu |
| Telephone |
For any data protection matter, you can reach us at info@happydev.hu.
We have not appointed a data protection officer, as none of the conditions set out in Article 37 GDPR applies to us.
2. Scope of this policy
This policy covers the processing of personal data in connection with visits to the https://happydev.hu website (both the Hungarian and the English version), together with the handling of enquiries sent to us by e-mail.
The website is a single-page corporate presentation site. It has no contact form, no newsletter sign-up, no registration, no login, no online shop, no payment function, no user accounts and no comment facility, and no data entry fields of any other kind. There is no database behind the website: we store no personal data about your visit on the server side.
This policy does not extend to processing carried out in the course of performing contracts concluded with our clients, or to the use of our own product, PetMetic (https://petmetic.hu), which are covered by separate notices, nor does it extend to external websites linked from ours.
The legal framework for our processing is Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), together with Act CXII of 2011 on Informational Self-Determination and Freedom of Information.
3. Data processed: categories, purposes, legal bases and retention periods
| Processing activity | Data processed | Purpose | Legal basis | Retention period |
|---|---|---|---|---|
| Web server and edge logging | IP address, timestamp, URL requested, user agent, HTTP response code | Operational security, troubleshooting, and the prevention and investigation of abuse (such as denial-of-service and automated attacks) | Legitimate interest, Article 6(1)(f) GDPR. Our legitimate interest is protecting the availability and security of the service | A short period set by the hosting provider, no longer than 30 days |
| Strictly necessary cookies | happydev_session, XSRF-TOKEN, happydev_cookie_consent (see Section 5 for details) | Operating the website, session management, CSRF protection, and recording your consent choice | Legitimate interest, Article 6(1)(f) GDPR, consistent with Section 155(4) of the Hungarian Electronic Communications Act (Act C of 2003 on Electronic Communications): cookies strictly necessary for providing the service do not require consent | 2 hours; 1 year in the case of the cookie that stores the consent choice |
| Non-essential cookies and embedded content (Google Maps, and Google Analytics 4 if enabled) | Cookie identifiers, IP address, device and browser data | Displaying the map at the visitor's request; audience statistics | Consent, Article 6(1)(a) GDPR | Until consent is withdrawn, or until the cookies expire |
| Enquiries received by e-mail | Name, e-mail address and any further data you choose to provide in your message (such as company name, telephone number, project description) | Answering the enquiry, providing a quotation, and discussing the project | Steps taken prior to entering into a contract, Article 6(1)(b) GDPR; for other enquiries, legitimate interest, Article 6(1)(f) (business communications) | No longer than 1 year after the matter is closed. Where a business relationship arises, for as long as is necessary to perform the contract; data qualifying as accounting records is kept for 8 years under Section 169(2) of the Hungarian Accounting Act (Act C of 2000 on Accounting) |
Using the website requires you to provide no data at all: of the data listed above, only the content of an e-mail comes from you, and the rest arises as a by-product of how the technology works.
4. Processors and data transfers
Hosting provider (processor): Laravel Holdings Inc. Address: 60 Broad Street, 24th Floor #1559, New York, NY 10004, United States E-mail: support@laravel.com Website: https://cloud.laravel.com Role: serving the website and keeping web server logs. The physical servers behind the service are located in the European (Frankfurt) region of Amazon Web Services (AWS), eu-central-1, so the data is stored within the EEA. As the provider is established in the United States, access to the data from outside the EEA cannot be ruled out in principle; this is safeguarded by the data processing agreement and by the standard contractual clauses set out in European Commission Implementing Decision 2021/914 (SCCs), pursuant to Article 46(2)(c) GDPR.
Font delivery: The website serves its fonts from our own server: the font files are downloaded when the site is built and are then delivered from the happydev.hu domain. As a result, displaying the fonts requires no connection to any third party from your browser, and no data, including your IP address, is transmitted to any font provider. This is a deliberate choice: it removes the font-related data transfer entirely, rather than merely disclosing it.
Embedded map (Google Maps): The map on the website does not load automatically. Until you click the "Load map" button, not a single request is sent to Google and no data is transmitted. By clicking the button, you consent to your browser establishing a connection with Google's servers. At that point Google receives your IP address, the time of the request and information about your browser, and may place its own cookies on your device (for example NID, with an expiry of around 6 months). From that point onwards, the processing is governed by Google's own privacy policy: https://policies.google.com/privacy. Within the EEA the service is provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), which may transfer the data to Google LLC in the United States. Transfers outside the EEA take place on the basis of the European Commission's adequacy decision on the EU-US Data Privacy Framework under Article 45 GDPR; the list of certified organisations can be checked at https://www.dataprivacyframework.gov/list.
Beyond the above, we neither disclose data to third parties nor sell it, save where we are required to do so by law or where an authority or court requests it through official channels.
5. Cookies
The website uses the following cookies:
| Cookie name | Purpose | Category | Lifetime |
|---|---|---|---|
| happydev_session | Laravel session cookie, with encrypted contents | Strictly necessary | 2 hours |
| XSRF-TOKEN | Protection against cross-site request forgery (CSRF) | Strictly necessary | 2 hours |
| happydev_cookie_consent | Storing your cookie consent choice | Strictly necessary | 1 year |
| Google Maps cookies (such as NID) | Operating the embedded map, but only where you expressly click to load it | Consent-based | approx. 6 months |
| _ga, ga* | Audience statistics (Google Analytics 4), currently not enabled | Analytics, consent-based | 2 years |
Google Analytics 4 does not currently run on the website and places no cookies. If we enable it in the future, we will do so solely with your prior consent, where the analytics category has been accepted, and we will update this policy beforehand.
A detailed description of the cookies, how to give and withdraw consent, and the relevant browser settings can be found in our Cookie Policy.
6. Data security
The website is accessible only over an encrypted HTTPS/TLS connection, so traffic between your browser and the server is protected against interception. The website has no database, no user accounts, no login and no data entry fields, so the personal data held about visitors is limited to technical logs. The contents of session cookies are stored in encrypted form.
Access to the hosting infrastructure and to the company e-mail system is protected by multi-factor authentication and is limited to those members of our team who need it in order to do their jobs.
7. Your rights as a data subject
Under the GDPR you have the following rights:
- Access (Article 15): you may ask us to tell you whether we process personal data relating to you, and to provide you with a copy.
- Rectification (Article 16): you may ask us to correct inaccurate data and to complete incomplete data.
- Erasure (Article 17): you may ask us to erase your data where it is no longer needed, where you withdraw your consent, or where the processing is unlawful. This right does not apply where the law requires us to retain the data.
- Restriction of processing (Article 18): you may ask us to store your data but otherwise not to process it, for example while an objection or a dispute about accuracy is being resolved.
- Data portability (Article 20): where data is processed by automated means on the basis of consent or a contract, you may ask to receive it in a machine-readable format, or ask us to transmit it to another controller.
- Objection (Article 21): you may object to processing based on legitimate interests; if you do, we will stop, unless there are compelling legitimate grounds for continuing.
- Withdrawal of consent (Article 7(3)): you may withdraw your consent at any time, free of charge; this does not affect the lawfulness of processing carried out beforehand. Cookie consent can be withdrawn through the website's cookie settings.
- Not to be subject to automated decision-making (Article 22): you have the right not to be subject to a decision based solely on automated processing which produces legal effects concerning you. We take no such decisions (see Section 10).
8. Enforcing your rights
Please raise any request or complaint with us directly in the first instance, at info@happydev.hu or at our postal address, 1203 Budapest, Török Flóris utca 70., 2nd floor 201, Hungary. We will respond to your request within 30 days of receiving it; in the case of a complex request this deadline may be extended by a further two months, and we will let you know within the initial 30 days if that happens.
We are generally unable to link the data contained in our technical logs to an identified individual. In such cases we may, under Article 11 GDPR, ask you for additional identifying information, or inform you that identification is not possible.
If you believe that our processing infringes your rights, you may lodge a complaint with the supervisory authority:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH) Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary Telephone: +36 1 391-1400 E-mail: ugyfelszolgalat@naih.hu Website: https://www.naih.hu
You may also bring court proceedings if your rights are infringed. Such cases fall within the competence of the regional courts (törvényszék) and, under Section 23(3) of Act CXII of 2011 on Informational Self-Determination and Freedom of Information, may, at your choice, be brought before the regional court for your place of residence or place of stay. Proceedings of this kind are exempt from court fees.
9. Children's data
The website and our services are aimed at people aged 16 and over, primarily business decision-makers, and we do not knowingly collect personal data from children. Since the website offers no way of entering data, using it does not create any opportunity for a child's data to be submitted in the first place. If we become aware that an e-mail sent to us contains the data of a child under 16 without appropriate parental consent, we will delete that data without delay.
10. Automated decision-making and profiling
We carry out no decision-making based solely on automated processing, and no profiling, within the meaning of Article 4(4) and Article 22 GDPR. We do not build behavioural profiles of visitors, we do not target advertising, and we do not share data with advertising networks.
11. Changes to this policy
We reserve the right to amend this policy unilaterally, for example following a change in the law or the engagement of a new processor. The version in force at any given time is available at /en/privacy-policy, showing the dates given at the top of the document. In the event of a material change, such as a new processing purpose or a new recipient, we will draw attention to it prominently on the website and, where processing is based on consent, we will ask for consent again.
Related documents: Imprint, Terms of Use, Cookie Policy.