Privacy Policy

On the processing of personal data in the Pufffi application and the pufffi.com / pufffi.hu websites · v1.0 · Effective: 4 July 2026

This document describes how Innovatív Marketing Megoldások Kft. (the "Controller", "we") processes personal data in connection with operating the Pufffi application (a Progressive Web App, "PWA") and the associated pufffi.com and pufffi.hu websites, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the "GDPR").

I. The Controller

Name:
Innovatív Marketing Megoldások Kft.
Registered seat:
Gizella út 19/B, 1143 Budapest, Hungary
VAT / tax number:
25803965-2-42 (HU25803965)
Company reg. no.:
01-09-338878
Represented by:
Zsuzsanna Radics
Email:
hello@pufffi.com
Phone:
+36 70 500 0800
Websites:
https://pufffi.com · https://pufffi.hu

We are not required to appoint a Data Protection Officer and have not done so. For any privacy matter, please contact us using the details above.

II. Processing activities

II.1. Registration and user account

Purpose: to create and manage your Pufffi account, provide the service, authenticate you and enable sign-in.

Data: email address, password (stored hashed), optional name/username, account creation and last login times, language and app settings.

Legal basis: performance of a contract [Art. 6(1)(b) GDPR], as the account is necessary to use the service.

Retention: for the lifetime of the account or until you request deletion; after deletion, data is permanently removed within 30 days unless a longer retention period is required by law.

II.2. Subscription and payment

Purpose: to process your Pufffi premium (digital) subscription order, take payment, perform the contract, issue invoices/receipts and manage the recurring (monthly/annual) subscription.

Data: name, email address, billing details, the selected plan, the amount, time and reference of the payment, and subscription status. We never receive or store your card details: payment is handled on the secure interface of our payment provider, Barion Payment Zrt.

Legal basis: performance of a contract [Art. 6(1)(b) GDPR]; for accounting records, compliance with a legal obligation [Art. 6(1)(c) GDPR].

Retention: accounting documents are retained for 8 years as required by Hungarian law; other order data for the applicable limitation period (generally 5 years).

II.3. Contact and customer support

Purpose: to receive and respond to your enquiries and complaints and to communicate with you.

Data: the details you provide (typically name, email address, message content).

Legal basis: your consent [Art. 6(1)(a) GDPR]; for complaints, compliance with a legal obligation [Art. 6(1)(c)].

Retention: until the enquiry is resolved; complaints are retained for 5 years.

II.4. Newsletter and marketing (planned)

Purpose: to send news, offers and updates about our services by electronic means. This is currently planned; newsletters are only sent if you give explicit, separate consent.

Data: name, email address, time of consent.

Legal basis: your explicit consent [Art. 6(1)(a) GDPR].

Retention: until you withdraw consent (unsubscribe). Every newsletter includes a one-click unsubscribe link.

II.5. Analytics and advertising

Purpose: to measure traffic and improve the user experience, and to display and measure advertising (Google Analytics 4, Google Ads, Meta Pixel).

Data: device and browser data, (truncated/anonymised) IP address, online identifiers, cookie-stored identifiers, and data about visitor/user behaviour.

Legal basis: your consent [Art. 6(1)(a) GDPR], given or refused via the cookie panel in line with Google Consent Mode v2. See the Cookie Policy.

Retention: for the lifetime of the relevant cookies or until you withdraw consent.

III. Cookies

We use cookies on the website and app and have integrated Google Consent Mode v2. Strictly necessary cookies are placed on the basis of our legitimate interest [Art. 6(1)(f)]; statistics and marketing cookies only with your consent [Art. 6(1)(a)]. Full details are in the separate Cookie Policy.

IV. Recipients and data processors

A processor is an organisation that processes personal data on our behalf. We use the following processors:

IV.1. Hosting provider

Name:
Tárhely.Eu Szolgáltató Kft.
Address:
Könyves Kálmán körút 12-14, 1097 Budapest, Hungary
Contact:
+36 1 789-2-789 · support@tarhely.eu · https://tarhely.eu

The processor stores personal data and is not entitled to access its content.

IV.2. Payment provider

Name:
Barion Payment Zrt.
Registered seat:
1117 Budapest, Irinyi József utca 4-20., Hungary
Company reg. no.:
01-10-048552 · Tax no.: 25353192-2-43
MNB licence:
H-EN-I-1064/2013 · https://www.barion.com

Barion Payment Zrt. carries out the processing of online payments. Card data is handled directly by Barion; we do not have access to it. Barion also acts as an independent controller in respect of the payment transaction and fraud prevention, as described in Barion's own privacy policy.

IV.3. Invoicing provider

Name:
KBOSS.hu Kft. (Számlázz.hu)
Registered seat:
1031 Budapest, Záhony utca 7., Hungary
Company reg. no.:
01-09-303201 · Tax no.: 13421739-2-41
Website:
https://www.szamlazz.hu

Through the Számlázz.hu system, KBOSS.hu Kft. issues, delivers and retains invoices as required by law. For this it processes the data shown on the invoice (billing name and address, tax number for companies, the selected plan and the payment details) on our behalf.

IV.4. Accounting provider

Name:
HANS-GLOBÁL Kft.
Registered seat:
1188 Budapest, Napló utca 13. A, Hungary
Company reg. no.:
01-09-729261 · Tax no.: 13320951-1-43

Based on the issued invoices, the accountant carries out our accounting and tax-reporting obligations. In doing so it processes the personal data appearing on the invoices for the retention period prescribed by accounting law.

IV.5. AI provider

Name:
OpenAI, L.L.C. (EU representative: OpenAI Ireland Ltd)
Registered seat:
San Francisco, USA / 1st Floor, The Liffey Trust Centre, 117–126 Sheriff Street Upper, Dublin 1, Ireland

To operate the AI features (task breakdown, “Explain it”), we send the AI provider only the text you type, or the image you upload for photo breakdown, for processing, and receive the output (the steps/explanation) back. The AI provider does not receive any account identifier (name, email address, user ID), and because the request originates from our server, your IP address is not transferred either. The text or image may, however, contain personal data if you include it — so please do not enter or photograph unnecessary personal or special-category data. Per its policy, the provider does not use data submitted via the API to train its models, and may retain it for a limited period for abuse monitoring. We do not store the uploaded photo. The limitations of the AI features, moderation and child protection are described in the separate AI Notice.

IV.6. Analytics and advertising providers

ProviderPurposeLocation
Google Ireland Ltd. / Google LLC (Google Analytics 4, Google Ads)Traffic measurement, advertising, remarketingDublin, Ireland / USA
Meta Platforms Ireland Ltd. / Meta Platforms, Inc. (Meta Pixel)Advertising, conversion measurement, remarketingDublin, Ireland / USA

For data collected via consent-based cookies, these providers act partly as independent controllers and partly as processors.

IV.7. Transfers to third parties

Beyond the above, we do not transfer personal data to third parties unless required by law (e.g. a lawful authority request).

V. International (third-country) transfers

The analytics and advertising providers (Google, Meta) may in some cases transfer data outside the European Economic Area, including to the United States. Such transfers take place with appropriate safeguards, primarily under the European Commission's adequacy decision for the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses (SCCs). Without your explicit consent, no marketing or analytics data is transferred. The AI provider (OpenAI) may also process content submitted when using the AI features in the United States; this transfer takes place with appropriate safeguards, primarily under the Standard Contractual Clauses (SCCs) and — where applicable — the EU–US Data Privacy Framework.

VI. Data security

We apply appropriate technical and organisational measures to protect personal data, including hashed password storage, encrypted (HTTPS/TLS) transmission, access restrictions and regular backups. In the event of a data breach we act in accordance with Articles 33–34 GDPR.

VII. Your rights

Within the retention period you have the rights below under the GDPR. To exercise them, contact us using the details above; we will respond within 30 days.

VII.1. Right to withdraw consent

You may withdraw consent-based processing at any time without giving reasons. This does not affect the lawfulness of processing before withdrawal.

VII.2. Right of access

You may obtain confirmation of whether we process your data and, if so, access it and receive information about the purposes, categories, recipients, retention, your rights and remedies.

VII.3. Right to rectification

You may request correction of inaccurate data and completion of incomplete data.

VII.4. Right to erasure ("right to be forgotten")

You may request erasure where data is no longer needed, you withdraw consent with no other legal basis, you object to processing, or processing is unlawful. Erasure does not override statutory retention obligations (e.g. 8-year invoice retention).

VII.5. Right to restriction

You may request restriction of processing where you contest accuracy, processing is unlawful but you oppose erasure, you need the data for legal claims, or you have objected to processing.

VII.6. Right to object

On grounds relating to your particular situation, you may object at any time to processing based on legitimate interests.

VII.7. Right to data portability

For consent- or contract-based automated processing, you may receive the data you provided in a structured, commonly used, machine-readable format (e.g. XML, JSON, CSV) and, where technically feasible, have it transmitted to another controller.

VII.8. Right to lodge a complaint

If you believe we have breached data protection rules, you may lodge a complaint with the supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: Falk Miksa utca 9-11, 1055 Budapest, Hungary
Mail: 1363 Budapest, Pf. 9.
Email: ugyfelszolgalat@naih.hu · Phone: +36 (1) 391-1400
Web: https://naih.hu

You may also bring the matter before the competent court of your place of residence or stay, or the supervisory authority of your EU/EEA country.

VIII. Other provisions

We reserve the right to amend this Policy. The current version is always available on pufffi.com and pufffi.hu. Where a change materially affects processing, we will inform users appropriately.