Privacy Policy
Bovirex Kft. | Effective date: 1 June 2026 | Version: 2.0
The purpose of this Privacy Policy is to provide transparent information on how Bovirex Kft. processes the personal data of website visitors, clients, partners and other data subjects, including the purposes, legal bases and duration of processing, as well as the rights available to data subjects.
This Policy applies to processing activities carried out in connection with the Bovirex Kft. website and the company's services and business operations.
1. Data Controller Details
Name of the Data Controller: Bovirex Kft.
Registered seat: Korona u. 55., 8500 Pápa, Hungary
Website: https://bovirex.hu
Email: adatvedelem@bovirex.hu
Representative: Imre Borbély
Company registration number: 19-09-503755
Tax number: 11528184-2-19
For the purposes of this Policy, "Data Controller" means Bovirex Kft.
2. Data Protection Contact
Questions, requests or complaints regarding personal data processing may be addressed to the Data Controller at the following contact details:
Email: adatvedelem@bovirex.hu
Postal address: Bovirex Kft., Korona u. 55., 8500 Pápa, Hungary
Data Protection Officer: Szabolcs Csepi
Email: adatvedelem@bovirex.hu
Postal address: Korona u. 55., 8500 Pápa, Hungary
3. Applicable Legal Framework
The Data Controller processes personal data in particular in accordance with the following legislation:
- Regulation (EU) 2016/679 of the European Parliament and of the Council, the General Data Protection Regulation ("GDPR");
- Act CXII of 2011 on Informational Self-Determination and Freedom of Information;
- Act C of 2000 on Accounting;
- legislation applicable to electronic commerce services and electronic advertising;
- other applicable Hungarian and European Union legislation relevant to the specific processing activity.
4. Principles of Personal Data Processing
The Data Controller processes personal data lawfully, fairly and transparently. In the course of processing, the Data Controller seeks to process only personal data that is necessary and proportionate for the relevant purpose.
The Data Controller ensures that the data processed is accurate and, where necessary, kept up to date, and that personal data is retained only for the period necessary. The Data Controller protects personal data against unauthorised access, alteration, transmission, disclosure, deletion, destruction or damage by means of appropriate technical and organisational measures.
5. Data Processing Related to Website Use
5.1. Technical Data Related to Website Operation
When the website is accessed, certain technical data may be generated automatically, such as the visitor's IP address, browser type, operating system data, time of visit and technical information relating to the pages viewed.
Purpose of processing: ensuring the secure and proper operation of the website, preventing misuse and maintaining IT security.
Categories of data processed: IP address, browser data, time of visit and technical log data.
Legal basis: Article 6(1)(f) GDPR, the legitimate interest of the Data Controller in operating the website securely.
Retention period: technical log data is generally retained for a maximum of 90 days, unless a longer retention period is required for the investigation of a security incident.
6. Contact and Quote Requests
Data subjects may contact the Data Controller through the quote request form available on the website, by email, by telephone or through other communication channels to ask questions, request a quote or send another enquiry.
Purpose of processing: handling contact requests, responding to quote requests, issuing offers, pre-contractual communication and documenting client communication.
Categories of data processed: name, email address, phone number, content of the enquiry, time of the enquiry and any other data voluntarily provided by the data subject.
Legal basis:
- for individual quote requesters: Article 6(1)(b) GDPR, taking steps at the request of the data subject prior to entering into a contract;
- for contact persons of business partners: Article 6(1)(f) GDPR, the legitimate interest of the Data Controller and its business partner in business communication and quote handling.
Retention period: a maximum of 1 year from the conclusion of the quote request or enquiry, unless a contract is concluded on the basis of the enquiry or a longer retention period is required for the establishment, exercise or defence of legal claims.
7. Newsletter and Direct Marketing Communications
The Data Controller sends newsletters or marketing communications only on the basis of the data subject's prior, voluntary and informed consent.
Purpose of processing: sending newsletters, marketing communications and information about events, services and offers.
Categories of data processed: name, email address, time of subscription and technical data necessary to prove consent.
Legal basis: Article 6(1)(a) GDPR, consent of the data subject.
Retention period: until consent is withdrawn.
The data subject may withdraw consent at any time by sending an email to adatvedelem@bovirex.hu or by using the unsubscribe link included in the newsletter. Withdrawal of consent does not affect the lawfulness of processing carried out prior to withdrawal.
8. Contractual and Client Relationship Data Processing
The Data Controller processes the personal data of clients, partners and their contact persons with whom it has a contractual relationship.
Purpose of processing: preparing, concluding, performing, modifying and terminating contracts, maintaining contact, fulfilling rights and obligations, and establishing, exercising or defending legal claims.
Categories of data processed: name, address, email address, phone number, position, data relating to representation authority, contractual data, performance data and content of communication.
Legal basis:
- for natural person contracting parties: Article 6(1)(b) GDPR, performance of a contract;
- for contact persons of legal entity partners: Article 6(1)(f) GDPR, the legitimate interest of the Data Controller and its partner in maintaining the contractual relationship;
- for legal claims: Article 6(1)(f) GDPR, legitimate interest.
Retention period: for the duration of the contract and, after termination, until expiry of the limitation period for legal claims, generally 5 years.
9. Invoicing and Accounting Obligations
The Data Controller processes personal data in order to comply with its statutory invoicing and accounting obligations.
Purpose of processing: issuing invoices, fulfilling bookkeeping and accounting obligations, and complying with tax obligations.
Categories of data processed: name, billing address, tax number, invoice content, payment data, bank account number and data included in documents evidencing performance.
Legal basis: Article 6(1)(c) GDPR, compliance with a legal obligation.
Retention period: according to the statutory retention period for accounting documents, generally 8 years.
10. Postal and Parcel Delivery Data
Where the Data Controller sends or receives postal items, parcels or other documents for delivery, it processes the personal data necessary for that purpose.
Purpose of processing: sending and receiving postal items, parcels and documents, tracking deliveries and handling related administrative matters.
Categories of data processed: name, address, phone number, email address, shipment identifier and delivery data.
Legal basis: Article 6(1)(b) GDPR, performance of a contract, or Article 6(1)(f) GDPR, legitimate interest.
Retention period: a maximum of 1 year from the conclusion of the matter; for items linked to contractual or accounting documents, the retention period applicable to the relevant document.
11. Telephone Communications
The Data Controller may maintain contact with data subjects by telephone. The Data Controller records telephone calls only if it has clearly informed the data subject in advance.
Purpose of processing: telephone communication, callbacks, administration, handling quote requests or contractual matters.
Categories of data processed: phone number, time of call and data voluntarily provided during the call.
Legal basis: Article 6(1)(b) or Article 6(1)(f) GDPR, depending on the nature of the matter.
Retention period: for general enquiries, a maximum of 90 days from conclusion of the matter; for quote requests or contractual matters, the retention period applicable to that matter.
12. Handling Individual Client Requests
The Data Controller processes personal data relating to individual client requests, needs or complaints to the extent necessary for handling the matter.
Purpose of processing: handling and fulfilling individual client requests, comments and complaints.
Categories of data processed: name, contact details, content of the request or complaint, and any other data voluntarily provided.
Legal basis: Article 6(1)(b), Article 6(1)(c) or Article 6(1)(f) GDPR, depending on the nature of the matter.
Retention period: a maximum of 5 years from conclusion of the matter where necessary for the establishment, exercise or defence of legal claims; otherwise a maximum of 1 year from conclusion.
The Data Controller processes identity document numbers or other document data only where strictly necessary for handling the matter in question, or where required by law.
13. Handling Data Subject Requests and Data Protection Matters
The Data Controller processes personal data related to the exercise of data subject rights, data protection questions, complaints and other data protection matters.
Purpose of processing: handling data subject requests, investigating data protection complaints, fulfilling statutory obligations and ensuring accountability.
Categories of data processed: name, contact details, content of the request or complaint, identification data, response data and documentation of proceedings.
Legal basis: Article 6(1)(c) GDPR, compliance with a legal obligation, and Article 6(1)(f) GDPR, legitimate interest in establishing, exercising or defending legal claims.
Retention period: 5 years from the conclusion of the matter.
14. Cookies and Analytics Services
The website may use cookies and similar technologies. Cookies are small data files that may be placed on the user's device.
14.1. Necessary Cookies
Necessary cookies are required for the basic operation, security and usability of the website, including language settings and recording cookie consent preferences.
Legal basis: Article 6(1)(f) GDPR, the legitimate interest of the Data Controller in operating the website, and the use of cookies that are technically necessary for providing the service under electronic communications rules.
14.2. Analytics Cookies, Google Analytics 4
The Data Controller uses Google Analytics 4 through the Google Site Kit plugin to measure website traffic, analyse website usage and improve the website. Analytics cookies are placed only on the basis of the data subject's prior consent.
Purpose of processing: measuring website traffic, producing statistics and improving the website.
Categories of data processed: IP address or its truncated form, device and browser data, visit data, page views and cookie identifiers.
Legal basis: Article 6(1)(a) GDPR, consent of the data subject.
Retention period: for the lifetime of the relevant cookie or until consent is withdrawn.
The data subject may modify or withdraw cookie consent at any time through the cookie settings available on the website.
14.3. Main Cookies and Similar Technologies Used on the Website
| Cookie / service | Provider | Purpose | Category | Expiry |
|---|---|---|---|---|
| pll_language | Bovirex.hu / Polylang | Stores the selected language. | Necessary / functional | 1 year |
| viewed_cookie_policy | GDPR Cookie Consent / Cookie Law Info plugin | Stores whether the user has accepted the cookie notice. | Necessary | 11 months |
| cookielawinfo-checkbox-necessary | GDPR Cookie Consent / Cookie Law Info plugin | Stores the consent state for necessary cookies. | Necessary | 11 months |
| cookielawinfo-checbox-analytics | GDPR Cookie Consent / Cookie Law Info plugin | Stores the consent state for analytics cookies. | Necessary / consent management | 11 months |
| cookielawinfo-checbox-functional | GDPR Cookie Consent / Cookie Law Info plugin | Stores the consent state for functional cookies. | Necessary / consent management | 11 months |
| cookielawinfo-checkbox-performance | GDPR Cookie Consent / Cookie Law Info plugin | Stores the consent state for performance cookies. | Necessary / consent management | 11 months |
| cookielawinfo-checbox-others | GDPR Cookie Consent / Cookie Law Info plugin | Stores the consent state for other cookies. | Necessary / consent management | 11 months |
| _ga | Google Analytics 4 | Creates a unique identifier for statistical measurement and website usage analysis. | Analytics | Up to 2 years |
| _ga_* | Google Analytics 4 | Stores GA4 measurement state and session-related data. The exact cookie name depends on the measurement ID. | Analytics | Up to 2 years |
| Google Maps embed | Google Ireland Limited / Google LLC | Displays the company's location on a map and supports navigation. Google may use its own technical identifiers and cookies when the map is loaded. | Third-party service / functional | According to Google's current settings |
The actual set of cookies may vary depending on browser settings, consent status and the current operation of Google and WordPress plugins.
15. Social Media and Third-Party Services
Based on the actual operation of the website, the website uses or may use the following third-party services:
- Google Maps: to display the company's location on a map and support navigation;
- Google Analytics 4: to prepare website traffic and usage statistics, based on consent;
- Google Search Console: to analyse the website's appearance in Google Search and its technical indexing status, through the Google Site Kit plugin;
- Google Site Kit: to connect Google services with the WordPress administration interface and display statistical data.
If further third-party services, embedded content or marketing technologies are activated on the website in the future, this Policy must be updated accordingly.
The Data Controller recommends that data subjects also read the privacy policies of the relevant third-party service providers.
16. CCTV Surveillance
The Data Controller may operate an electronic surveillance system in areas under its management.
Purpose of processing: protection of persons and property, prevention and detection of unlawful acts, and securing evidence.
Categories of data processed: image of the data subject, movements, location and time of recording.
Legal basis: Article 6(1)(f) GDPR, the legitimate interest of the Data Controller in the protection of persons and property.
Retention period: generally a maximum of 30 days, unless the recording is required in connection with an unlawful act, regulatory proceedings or legal claims.
Access: designated employees and officers of the Data Controller and, where applicable, designated staff of any data-processing security service provider.
Data transfer: to authorities, courts or other authorised bodies pursuant to a statutory obligation or legitimate claim.
Data subjects may request access to recordings relating to them, or request restriction of recordings where this is necessary for the establishment, exercise or defence of legal claims.
The Data Controller displays clearly visible notices in areas covered by CCTV surveillance.
17. Accommodation Services and Tourist Tax
In connection with its accommodation services, the Data Controller processes guests' personal data to fulfil statutory obligations, provide the service and comply with tourist tax registration and reporting requirements.
Purpose of processing: providing accommodation services, maintaining guest records, fulfilling tourist tax obligations and providing data to authorities.
Categories of data processed: name, home address, date and place of birth, nationality, document data, arrival and departure times and other data required by law.
Legal basis: Article 6(1)(c) GDPR, compliance with a legal obligation, and, where applicable, Article 6(1)(b) GDPR, performance of a contract.
Retention period: as specified in applicable legislation.
18. Data Processors and Recipients
The Data Controller may engage data processors in connection with personal data processing. Data processors may only process personal data in accordance with the instructions of the Data Controller and for the purpose of the processing.
Categories of data processors and recipients used may include in particular:
- hosting service provider;
- website operator and web developer;
- IT service provider;
- accountant or accounting service provider;
- invoicing software provider;
- postal and courier service providers;
- Google services: Google Analytics 4, Google Search Console, Google Site Kit and Google Maps;
- security service provider, where CCTV or security services are in operation;
- legal, tax or other professional advisers;
- authorities, courts and bodies specified by law.
19. Transfers to Third Countries
The Data Controller transfers personal data to a third country outside the European Economic Area only where the conditions set out in the GDPR are met.
The Google services used on the website - in particular Google Analytics 4, Google Search Console, Google Site Kit and Google Maps - may involve the transfer of personal data or technical identifiers to the Google group, including transfers outside the European Economic Area.
The primary European provider of the relevant Google services may be Google Ireland Limited, while Google LLC and other Google group companies may also participate in certain processing operations. Such transfers may take place subject to appropriate safeguards applied by Google, including in particular the EU-U.S. Data Privacy Framework based on the European Commission's adequacy decision and, where necessary, standard contractual clauses.
Further information on Google's privacy terms and transfer frameworks is available at:
20. Data Security
The Data Controller applies appropriate technical and organisational measures to protect the security of personal data. These measures include in particular the restriction of access to data, adequate protection of IT systems and the prevention of unauthorised access to, modification, deletion or destruction of data.
The Data Controller treats personal data confidentially and ensures that it is accessible only to authorised persons.
21. Automated Decision-Making and Profiling
The Data Controller does not engage in automated decision-making, including profiling, that produces legal effects concerning the data subject or similarly significantly affects the data subject.
The use of Google Analytics 4 serves the statistical measurement of website traffic and does not result in automated decisions producing legal or similarly significant effects concerning data subjects.
22. Children's Personal Data
The Data Controller's services and website are not directed specifically at children under the age of 16. The Data Controller asks that persons under the age of 16 do not provide personal data without the consent of a parent or legal guardian.
If the Data Controller becomes aware that personal data has been collected from a child under the age of 16 without valid consent, it will take the necessary steps to delete that data.
23. Rights of Data Subjects
Data subjects have the following rights in relation to the processing of their personal data.
23.1. Right of Access
The data subject is entitled to request information as to whether the Data Controller processes their personal data and, if so, to obtain details of the key aspects of the processing.
23.2. Right to Rectification
The data subject may request the rectification of inaccurate personal data or the completion of incomplete personal data.
23.3. Right to Erasure
The data subject may request the erasure of their personal data where the purpose of processing has ceased, the data subject has withdrawn consent, the data subject has objected to processing, the processing is unlawful or erasure is required by law.
Erasure may not be requested where processing is necessary for compliance with a legal obligation, or for the establishment, exercise or defence of legal claims.
23.4. Right to Restriction of Processing
The data subject may request restriction of processing where the data subject contests the accuracy of the data, the processing is unlawful but the data subject does not request erasure, the Data Controller no longer needs the data but the data subject requires it for legal claims, or the data subject has objected to processing.
23.5. Right to Data Portability
Where processing is based on consent or a contract and is carried out by automated means, the data subject may request that the Data Controller provide their personal data in a structured, commonly used, machine-readable format, or transmit it to another controller.
23.6. Right to Object
The data subject is entitled to object to the processing of personal data based on legitimate interests. In such a case, the Data Controller may no longer process the data unless it demonstrates compelling legitimate grounds for the processing that override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.
Where personal data is processed for direct marketing purposes, the data subject may object at any time, in which case the Data Controller will no longer process the data for that purpose.
23.7. Right to Withdraw Consent
Where processing is based on consent, the data subject is entitled to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
24. Handling Data Subject Requests
Data subjects may submit requests by email to adatvedelem@bovirex.hu or by post to the address of the Data Controller.
The Data Controller responds to data subject requests without undue delay and, in any event, within one month of receipt. Where necessary, taking into account the complexity and number of requests, this period may be extended by a further two months, of which the Data Controller will notify the data subject.
The Data Controller may request verification of the data subject's identity before fulfilling a request where it has doubts as to the identity of the applicant.
The exercise of data subject rights is generally free of charge. Where a request is manifestly unfounded or excessive, in particular owing to its repetitive character, the Data Controller may charge a reasonable fee or refuse to act on the request.
25. Remedies
Data subjects may direct questions or complaints regarding processing in the first instance to the Data Controller at:
Email: adatvedelem@bovirex.hu
Postal address: Bovirex Kft., Korona u. 55., 8500 Pápa, Hungary
Data subjects are also entitled to lodge a complaint with the supervisory authority:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: Falk Miksa utca 9-11., 1055 Budapest, Hungary
Mailing address: Pf. 9., 1363 Budapest, Hungary
Telephone: +36 (1) 391 1400
Email: ugyfelszolgalat@naih.hu
Website: https://www.naih.hu
Data subjects are further entitled to seek judicial remedy if they consider that the processing of their personal data infringes the GDPR or other data protection legislation.
26. Amendment of this Policy
The Data Controller reserves the right to amend this Policy. Any amended Policy will be published on the Data Controller's website. In the event of a material change, the Data Controller may also notify data subjects separately in a manner appropriate to the nature of the change.
27. Version Information
Document title: Privacy Policy
Data Controller: Bovirex Kft.
Version: 2.0
Effective date: 1 June 2026
Last amended: 8 July 2026