Skip to content
AboutServicesTestimonialsQualificationsPricing
🇭🇺HUContact
01About02Services03Testimonials04Qualifications05PricingContact

Legal information

Privacy policy

This policy explains how personal data is handled on the Szívecske Pihenő website and in the iOS application.

Last updated: 20 August 2026

1. Data controller

Gehér Zsófia (Szívecske Pihenő)

Website: www.szivecskepiheno.com

Email: szivecske.piheno@gmail.com

Phone: +36 30 441 65 81

2. Scope of this policy

This policy applies to visitors to szivecskepiheno.com, people who use its enquiry form, and adult users of the Szívecske Pihenő iOS application or its appointment-booking features.

We do not sell or rent personal data. We use it only for the purposes described here and only to the extent necessary.

3. Data handled on the website

The information you submit through the enquiry form is sent to Szívecske Pihenő. Please do not include health information or other special-category data in the free-text message unless it is necessary for your enquiry.

To deliver the website securely and limit abuse, the technical infrastructure may briefly process your IP address, request time, requested page, and basic browser and device information. Your IP address is not stored with your enquiry.

  • name and email address;
  • an optional phone number;
  • the service selected or asked about;
  • the content of the message, the form language and the fact of consent;
  • submission time and the internal handling status.

4. Data handled in the iOS application

The application helps users book appointments for Gehér Zsófia’s services. We handle only the information you explicitly provide and the data needed to operate the application.

If you enable analytics sharing with Apple in your device settings, Apple may make anonymised crash reports and technical analytics available to the developer. Apple’s own processing is governed by Apple’s privacy policy.

  • contact details: name, email address and phone number;
  • account and booking details: identifier, service, date, time and booking status;
  • notes you voluntarily add to a booking, such as a child’s name or age;
  • technical information needed to run the application and, where enabled, anonymised crash reports.

5. Purposes and legal bases

  • Enquiries and replies: your consent (Article 6(1)(a) GDPR) and, where applicable, steps taken at your request before entering into a contract (Article 6(1)(b) GDPR).
  • Booking, confirmation, reminders and service delivery: steps before entering into and performance of a contract (Article 6(1)(b) GDPR).
  • Any special-category data that you voluntarily include in a message or booking note: your explicit consent (Article 9(2)(a) GDPR), solely to discuss or provide the requested support or service.
  • Accounting, tax and other mandatory records: compliance with a legal obligation (Article 6(1)(c) GDPR).
  • Website and application security, troubleshooting and abuse prevention: the controller’s legitimate interests (Article 6(1)(f) GDPR).

6. Children’s privacy

Although the services may involve children, the website enquiry form, the application and the booking system are intended for parents and other adults. We do not knowingly collect personal data directly from anyone under 18 without the involvement of a parent or legal guardian.

Child-related information voluntarily provided by a parent is used only to discuss and provide the requested service. Please provide only information that is genuinely necessary.

7. Processors and data disclosures

Providers needed to operate the services may access data only under the controller’s instructions, applicable contracts and law. We use Google Firebase/Google Cloud for the website’s content database, image storage, enquiry records and administrator authentication. Apple is involved in distributing the iOS application and in device analytics that users have enabled.

A website enquiry – together with the contact details given and the content of the message – is delivered to the controller’s mailbox through the Resend email service, so that a reply can follow promptly. Delivery takes place within the European Union (Ireland), and the controller’s mailbox is operated by Google (Gmail).

We may also disclose data to a competent authority where required by law or a binding official request. Where a provider processes data outside the European Economic Area, we rely on the safeguards and contractual mechanisms available under applicable law.

The providers’ own privacy information: Firebase privacy and security · Apple Privacy Policy

8. Retention

  • A website enquiry that does not lead to a service relationship is retained for no longer than 12 months, then deleted or anonymised. That limit also covers the copy held in the mailbox as a notification email.
  • Information connected with a service, booking or invoice is retained as needed to perform the contract, establish or defend legal claims, and comply with mandatory accounting and tax retention periods.
  • Security and abuse-prevention data is handled only for the short period needed for that purpose. Provider logs are retained according to the provider’s settings and terms.
  • After an application account is deleted or a valid erasure request is fulfilled, data is removed from active systems. It disappears from backups during their normal overwrite cycle unless the law requires further retention.

9. Cookies and analytics

The current public website does not use advertising, visitor-tracking or audience-measurement cookies, and it does not run third-party marketing analytics. A cookie-consent banner is therefore not required for the public site in its current form.

The private administrator area uses one strictly necessary, secure session cookie. It identifies authorised administrators only and is not used for marketing. If analytics or marketing technology is added later, we will update this policy and, where required, obtain consent before it is used.

10. Data security

We use technical and organisational measures to protect data against unauthorised access, alteration, disclosure and loss. Administrator access is restricted, communications are encrypted in transit, public database writes are disabled, and form submissions are protected by server-side validation and abuse controls.

No electronic system can guarantee that all risk is eliminated. If a personal-data breach occurs, we will act in accordance with applicable law and notify affected people and the authority where required.

11. Your rights

Using the email address above, you may request information and access, correction, erasure, restriction, and data portability, or object to processing based on legitimate interests. You may withdraw consent at any time; this does not affect processing that was lawful before withdrawal.

You may request deletion of your application account and associated data using Delete Account in the application’s Account/Settings menu, or by contacting the controller by email.

If you believe that the processing of your data infringes your rights, you may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), or seek a judicial remedy.

1055 Budapest, Falk Miksa utca 9–11, Hungary; postal address: 1363 Budapest, P.O. Box 9, Hungary.

NAIH customer service: ugyfelszolgalat@naih.hu · NAIH website: naih.hu

12. Changes to this policy

We may update this policy when the services, technology or applicable law changes. Material changes will be communicated through an appropriate service interface or, where appropriate and available, by email. The current version will remain available on this website.

Warm, informed support for families.

Explore

AboutServicesPricingPrivacy

Contact

+36 30 441 65 81szivecske.piheno@gmail.comBudapest and surrounding area
© 2026 Gehér ZsófiaAll rights reserved.