This document describes how Innovatív Marketing Megoldások Kft. (the "Controller", "we") processes personal data in connection with operating the Pufffi application (a Progressive Web App, "PWA") and the associated pufffi.com and pufffi.hu websites, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the "GDPR").
We are not required to appoint a Data Protection Officer and have not done so. For any privacy matter, please contact us using the details above.
Purpose: to create and manage your Pufffi account, provide the service, authenticate you and enable sign-in.
Data: email address, password (stored hashed), optional name/username, account creation and last login times, language and app settings.
Legal basis: performance of a contract [Art. 6(1)(b) GDPR], as the account is necessary to use the service.
Retention: for the lifetime of the account or until you request deletion; after deletion, data is permanently removed within 30 days unless a longer retention period is required by law.
Purpose: to process your Pufffi premium (digital) subscription order, take payment, perform the contract, issue invoices/receipts and manage the recurring (monthly/annual) subscription.
Data: name, email address, billing details, the selected plan, the amount, time and reference of the payment, and subscription status. We never receive or store your card details: payment is handled on the secure interface of our payment provider, Barion Payment Zrt.
Legal basis: performance of a contract [Art. 6(1)(b) GDPR]; for accounting records, compliance with a legal obligation [Art. 6(1)(c) GDPR].
Retention: accounting documents are retained for 8 years as required by Hungarian law; other order data for the applicable limitation period (generally 5 years).
Purpose: to receive and respond to your enquiries and complaints and to communicate with you.
Data: the details you provide (typically name, email address, message content).
Legal basis: your consent [Art. 6(1)(a) GDPR]; for complaints, compliance with a legal obligation [Art. 6(1)(c)].
Retention: until the enquiry is resolved; complaints are retained for 5 years.
Purpose: to send news, offers and updates about our services by electronic means. This is currently planned; newsletters are only sent if you give explicit, separate consent.
Data: name, email address, time of consent.
Legal basis: your explicit consent [Art. 6(1)(a) GDPR].
Retention: until you withdraw consent (unsubscribe). Every newsletter includes a one-click unsubscribe link.
Purpose: to measure traffic and improve the user experience, and to display and measure advertising (Google Analytics 4, Google Ads, Meta Pixel).
Data: device and browser data, (truncated/anonymised) IP address, online identifiers, cookie-stored identifiers, and data about visitor/user behaviour.
Legal basis: your consent [Art. 6(1)(a) GDPR], given or refused via the cookie panel in line with Google Consent Mode v2. See the Cookie Policy.
Retention: for the lifetime of the relevant cookies or until you withdraw consent.
We use cookies on the website and app and have integrated Google Consent Mode v2. Strictly necessary cookies are placed on the basis of our legitimate interest [Art. 6(1)(f)]; statistics and marketing cookies only with your consent [Art. 6(1)(a)]. Full details are in the separate Cookie Policy.
A processor is an organisation that processes personal data on our behalf. We use the following processors:
The processor stores personal data and is not entitled to access its content.
Barion Payment Zrt. carries out the processing of online payments. Card data is handled directly by Barion; we do not have access to it. Barion also acts as an independent controller in respect of the payment transaction and fraud prevention, as described in Barion's own privacy policy.
Through the Számlázz.hu system, KBOSS.hu Kft. issues, delivers and retains invoices as required by law. For this it processes the data shown on the invoice (billing name and address, tax number for companies, the selected plan and the payment details) on our behalf.
Based on the issued invoices, the accountant carries out our accounting and tax-reporting obligations. In doing so it processes the personal data appearing on the invoices for the retention period prescribed by accounting law.
To operate the AI features (task breakdown, “Explain it”), we send the AI provider only the text you type, or the image you upload for photo breakdown, for processing, and receive the output (the steps/explanation) back. The AI provider does not receive any account identifier (name, email address, user ID), and because the request originates from our server, your IP address is not transferred either. The text or image may, however, contain personal data if you include it — so please do not enter or photograph unnecessary personal or special-category data. Per its policy, the provider does not use data submitted via the API to train its models, and may retain it for a limited period for abuse monitoring. We do not store the uploaded photo. The limitations of the AI features, moderation and child protection are described in the separate AI Notice.
| Provider | Purpose | Location |
|---|---|---|
| Google Ireland Ltd. / Google LLC (Google Analytics 4, Google Ads) | Traffic measurement, advertising, remarketing | Dublin, Ireland / USA |
| Meta Platforms Ireland Ltd. / Meta Platforms, Inc. (Meta Pixel) | Advertising, conversion measurement, remarketing | Dublin, Ireland / USA |
For data collected via consent-based cookies, these providers act partly as independent controllers and partly as processors.
Beyond the above, we do not transfer personal data to third parties unless required by law (e.g. a lawful authority request).
The analytics and advertising providers (Google, Meta) may in some cases transfer data outside the European Economic Area, including to the United States. Such transfers take place with appropriate safeguards, primarily under the European Commission's adequacy decision for the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses (SCCs). Without your explicit consent, no marketing or analytics data is transferred. The AI provider (OpenAI) may also process content submitted when using the AI features in the United States; this transfer takes place with appropriate safeguards, primarily under the Standard Contractual Clauses (SCCs) and — where applicable — the EU–US Data Privacy Framework.
We apply appropriate technical and organisational measures to protect personal data, including hashed password storage, encrypted (HTTPS/TLS) transmission, access restrictions and regular backups. In the event of a data breach we act in accordance with Articles 33–34 GDPR.
Within the retention period you have the rights below under the GDPR. To exercise them, contact us using the details above; we will respond within 30 days.
You may withdraw consent-based processing at any time without giving reasons. This does not affect the lawfulness of processing before withdrawal.
You may obtain confirmation of whether we process your data and, if so, access it and receive information about the purposes, categories, recipients, retention, your rights and remedies.
You may request correction of inaccurate data and completion of incomplete data.
You may request erasure where data is no longer needed, you withdraw consent with no other legal basis, you object to processing, or processing is unlawful. Erasure does not override statutory retention obligations (e.g. 8-year invoice retention).
You may request restriction of processing where you contest accuracy, processing is unlawful but you oppose erasure, you need the data for legal claims, or you have objected to processing.
On grounds relating to your particular situation, you may object at any time to processing based on legitimate interests.
For consent- or contract-based automated processing, you may receive the data you provided in a structured, commonly used, machine-readable format (e.g. XML, JSON, CSV) and, where technically feasible, have it transmitted to another controller.
If you believe we have breached data protection rules, you may lodge a complaint with the supervisory authority:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: Falk Miksa utca 9-11, 1055 Budapest, Hungary
Mail: 1363 Budapest, Pf. 9.
Email: ugyfelszolgalat@naih.hu · Phone: +36 (1) 391-1400
Web: https://naih.hu
You may also bring the matter before the competent court of your place of residence or stay, or the supervisory authority of your EU/EEA country.
We reserve the right to amend this Policy. The current version is always available on pufffi.com and pufffi.hu. Where a change materially affects processing, we will inform users appropriately.