Legal
Privacy notice
Effective from 24 August 2026 · Version 1.0
This notice describes how Aboard Strategy Kft. handles personal data received through its website.
1. The controller
Data protection officer: the Company has not appointed a data protection officer, as its activities do not meet the conditions in Article 37(1) GDPR. Data protection queries can be sent to the email address above.
| Name | Aboard Strategy Korlátolt Felelősségű Társaság |
|---|---|
| Short name | Aboard Strategy Kft. |
| Registered seat | Podmaniczky utca 57. 2/14, 1064 Budapest, Hungary |
| Company registration | 01-09-458736, Budapest Metropolitan Court of Registration |
| Tax number | 33093185-2-42 |
| EU VAT number | HU33093185 |
| Represented by | Róbert Leskó, managing director |
| info@aboardstrategy.com | |
| Website | aboardstrategy.com |
2. Scope of this notice
This notice applies to visitors of the website and to those contacting the Company by email. It does not cover the processing of data of clients with whom the Company has a contractual relationship; a separate notice applies to them.
The website currently contains no contact form, calculator, newsletter sign-up, analytics measurement or marketing cookies. Should any of these launch, the Company will update this notice in advance.
3. Processing activities
3.1 Enquiries by email
| Data processed | Name, email address, company name, the content of the message and its attachments, and any further data provided voluntarily. |
|---|---|
| Purpose | Answering the enquiry, providing a quote, preparing a contract. |
| Legal basis | Article 6(1)(b) GDPR, steps taken at the request of the data subject prior to entering into a contract. Where the enquiry does not concern a contract, the basis is the legitimate interest of the Company in answering enquiries, Article 6(1)(f) GDPR. |
| Source of data | Directly from the data subject. |
| Retention | 12 months from closing the enquiry. If a contract is concluded, processing continues under the contractual processing rules. |
3.2 Operating the website
| Data processed | IP address, browser and device data, time of request, page viewed. These are recorded in the hosting provider server logs. |
|---|---|
| Purpose | Operating the website securely, preventing abuse, investigating incidents. |
| Legal basis | Legitimate interest of the Company in the availability and security of the website, Article 6(1)(f) GDPR. |
| Retention | Up to 30 days. |
4. Cookies
The website uses no analytics, profiling or marketing cookies, and embeds no third-party tracking scripts. Fonts are served from the Company own infrastructure, so no request is made to an external font provider during a visit.
The hosting provider may set technical cookies or similar identifiers strictly necessary for operation, for example for load balancing or security filtering. Under electronic communications rules these do not require consent.
5. Processors and recipients
The Company uses the following processors. They process personal data solely on the instructions of the Company, under a data processing agreement.
| Vercel Inc. (United States) | Website operation, hosting, server logging |
|---|---|
| Google Ireland Limited (Ireland) | Business email and document storage |
The Company does not transfer or sell personal data to third parties for marketing purposes.
Disclosure to authorities: the Company may transfer data on the basis of a legal obligation, at the request of an authority. The data subject will be informed unless the law precludes this.
6. Transfers to third countries
Some processors carry out processing outside the European Economic Area, primarily in the United States. In such cases the transfer relies on an adequacy decision of the European Commission (EU–US Data Privacy Framework) or, failing that, on Standard Contractual Clauses adopted by the European Commission, together with any necessary supplementary measures.
Information on the safeguards applied can be requested at the contact details in section 1.
7. Security
The website is served over an encrypted connection (HTTPS). Incoming enquiries are accessible only to the managing director and, to the extent necessary, to authorised staff, through individual accounts protected by two-factor authentication. Access rights are reviewed regularly and data no longer needed is deleted.
In the event of a personal data breach, the Company acts in accordance with Articles 33 and 34 GDPR.
8. Rights of the data subject
Data subjects may exercise the following rights:
- Access
- Request confirmation of whether their personal data is processed and, if so, a copy of it.
- Rectification
- Request correction of inaccurate data and completion of incomplete data.
- Erasure
- Request deletion where the purpose has ceased, consent has been withdrawn, or processing is unlawful. Erasure cannot be requested where processing is necessary for compliance with a legal obligation or for legal claims.
- Restriction
- Request restriction of processing, for example while the accuracy of data is contested.
- Portability
- Receive data processed by automated means on the basis of consent or a contract in a structured, commonly used, machine-readable format, and request its transmission to another controller.
- Objection
- Object to processing based on legitimate interest. Where processing is for direct marketing, the right to object may be exercised without restriction.
Requests should be sent to the email address in section 1. The Company will respond within one month at the latest. This period may be extended by two months where the request is complex; the Company will inform the data subject within one month of receipt.
9. Remedies
Complaint to the Company: data subjects may raise any concern directly with the Company at the contact details in section 1.
| Supervisory authority | Hungarian National Authority for Data Protection and Freedom of Information (NAIH) |
|---|---|
| Seat | Falk Miksa utca 9-11, 1055 Budapest, Hungary |
| Postal address | 1363 Budapest, PO Box 9, Hungary |
| Phone | +36 (1) 391-1400 |
| ugyfelszolgalat@naih.hu | |
| Website | naih.hu |
Judicial remedy: data subjects may bring an action before a court. At the choice of the data subject, proceedings may be brought before the court of their place of residence or stay.
10. Changes to this notice
The Company reserves the right to amend this notice and will publish changes on the website. Where an amendment affects a material element of processing based on consent, the Company will seek fresh consent.
Prepared under Regulation (EU) 2016/679 (GDPR) and Act CXII of 2011 on Informational Self-Determination and Freedom of Information.