Legal

Privacy notice

Effective from 24 August 2026 · Version 1.0

This notice describes how Aboard Strategy Kft. handles personal data received through its website.

1. The controller

Data protection officer: the Company has not appointed a data protection officer, as its activities do not meet the conditions in Article 37(1) GDPR. Data protection queries can be sent to the email address above.

NameAboard Strategy Korlátolt Felelősségű Társaság
Short nameAboard Strategy Kft.
Registered seatPodmaniczky utca 57. 2/14, 1064 Budapest, Hungary
Company registration01-09-458736, Budapest Metropolitan Court of Registration
Tax number33093185-2-42
EU VAT numberHU33093185
Represented byRóbert Leskó, managing director
Emailinfo@aboardstrategy.com
Websiteaboardstrategy.com

2. Scope of this notice

This notice applies to visitors of the website and to those contacting the Company by email. It does not cover the processing of data of clients with whom the Company has a contractual relationship; a separate notice applies to them.

The website currently contains no contact form, calculator, newsletter sign-up, analytics measurement or marketing cookies. Should any of these launch, the Company will update this notice in advance.

3. Processing activities

3.1 Enquiries by email

Data processedName, email address, company name, the content of the message and its attachments, and any further data provided voluntarily.
PurposeAnswering the enquiry, providing a quote, preparing a contract.
Legal basisArticle 6(1)(b) GDPR, steps taken at the request of the data subject prior to entering into a contract. Where the enquiry does not concern a contract, the basis is the legitimate interest of the Company in answering enquiries, Article 6(1)(f) GDPR.
Source of dataDirectly from the data subject.
Retention12 months from closing the enquiry. If a contract is concluded, processing continues under the contractual processing rules.

3.2 Operating the website

Data processedIP address, browser and device data, time of request, page viewed. These are recorded in the hosting provider server logs.
PurposeOperating the website securely, preventing abuse, investigating incidents.
Legal basisLegitimate interest of the Company in the availability and security of the website, Article 6(1)(f) GDPR.
RetentionUp to 30 days.

4. Cookies

The website uses no analytics, profiling or marketing cookies, and embeds no third-party tracking scripts. Fonts are served from the Company own infrastructure, so no request is made to an external font provider during a visit.

The hosting provider may set technical cookies or similar identifiers strictly necessary for operation, for example for load balancing or security filtering. Under electronic communications rules these do not require consent.

5. Processors and recipients

The Company uses the following processors. They process personal data solely on the instructions of the Company, under a data processing agreement.

Vercel Inc. (United States)Website operation, hosting, server logging
Google Ireland Limited (Ireland)Business email and document storage

The Company does not transfer or sell personal data to third parties for marketing purposes.

Disclosure to authorities: the Company may transfer data on the basis of a legal obligation, at the request of an authority. The data subject will be informed unless the law precludes this.

6. Transfers to third countries

Some processors carry out processing outside the European Economic Area, primarily in the United States. In such cases the transfer relies on an adequacy decision of the European Commission (EU–US Data Privacy Framework) or, failing that, on Standard Contractual Clauses adopted by the European Commission, together with any necessary supplementary measures.

Information on the safeguards applied can be requested at the contact details in section 1.

7. Security

The website is served over an encrypted connection (HTTPS). Incoming enquiries are accessible only to the managing director and, to the extent necessary, to authorised staff, through individual accounts protected by two-factor authentication. Access rights are reviewed regularly and data no longer needed is deleted.

In the event of a personal data breach, the Company acts in accordance with Articles 33 and 34 GDPR.

8. Rights of the data subject

Data subjects may exercise the following rights:

Access
Request confirmation of whether their personal data is processed and, if so, a copy of it.
Rectification
Request correction of inaccurate data and completion of incomplete data.
Erasure
Request deletion where the purpose has ceased, consent has been withdrawn, or processing is unlawful. Erasure cannot be requested where processing is necessary for compliance with a legal obligation or for legal claims.
Restriction
Request restriction of processing, for example while the accuracy of data is contested.
Portability
Receive data processed by automated means on the basis of consent or a contract in a structured, commonly used, machine-readable format, and request its transmission to another controller.
Objection
Object to processing based on legitimate interest. Where processing is for direct marketing, the right to object may be exercised without restriction.

Requests should be sent to the email address in section 1. The Company will respond within one month at the latest. This period may be extended by two months where the request is complex; the Company will inform the data subject within one month of receipt.

9. Remedies

Complaint to the Company: data subjects may raise any concern directly with the Company at the contact details in section 1.

Supervisory authorityHungarian National Authority for Data Protection and Freedom of Information (NAIH)
SeatFalk Miksa utca 9-11, 1055 Budapest, Hungary
Postal address1363 Budapest, PO Box 9, Hungary
Phone+36 (1) 391-1400
Emailugyfelszolgalat@naih.hu
Websitenaih.hu

Judicial remedy: data subjects may bring an action before a court. At the choice of the data subject, proceedings may be brought before the court of their place of residence or stay.

10. Changes to this notice

The Company reserves the right to amend this notice and will publish changes on the website. Where an amendment affects a material element of processing based on consent, the Company will seek fresh consent.


Prepared under Regulation (EU) 2016/679 (GDPR) and Act CXII of 2011 on Informational Self-Determination and Freedom of Information.