01The data controller
02Purpose & principles of this policy
The controller acknowledges the content of this legal notice as binding on itself. The purpose of this Privacy Policy is to inform our clients and partners about the processing of their personal data.
The controller processes personal data exclusively in accordance with applicable law, strictly observing data-processing and data-protection rules, and respecting the principles of lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, and storage limitation.
The controller takes every technical and organisational measure to process partners' personal data securely and in the manner required by Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), and has adapted its day-to-day operations, policies, records, document templates and notices accordingly.
The applicable data-protection principles are continuously available at the controller's registered office and on its website. The controller reserves the right to amend this policy at any time and will notify its audience of any changes in good time. The controller is committed to protecting the personal data of its clients and to respecting their right to informational self-determination, treating personal data confidentially and taking all security, technical and organisational measures that guarantee the security of the data.
03Scope
Personal scope: this policy covers the controller, the natural persons whose data are included in the processing activities under this policy, and persons whose rights or legitimate interests are affected by the processing.
Material scope: this policy covers all processing arising during the controller's activity on the www.friday-creative.com website.
Temporal scope: this policy enters into force on the day of its approval and remains in effect for an indefinite period until further notice.
04Key definitions
Personal data: any information relating to an identified or identifiable natural person, who can be identified directly or indirectly - in particular by reference to an identifier such as a name, a number, location data, an online identifier, or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity.
Special-category data: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership, as well as genetic data, biometric data for the purpose of uniquely identifying a person, health data, and data concerning a person's sex life or sexual orientation.
Processing: any operation performed on personal data, whether automated or not - including collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Controller / Processor / Joint controllers / Third party: bear the meanings given in the GDPR. Consent means the freely given, specific, informed and unambiguous indication of the data subject's wishes. A personal-data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
05Lawful bases for processing
The controller processes personal data only where at least one of the following applies:
- the data subject has given consent for one or more specific purposes;
- processing is necessary for the performance of a contract to which the data subject is a party;
- processing is necessary for compliance with a legal obligation;
- processing is necessary to protect the vital interests of the data subject or another natural person;
- processing is necessary for the legitimate interests of the controller or a third party.
The controller examines the lawfulness of processing at every stage of its activity and only processes data whose purpose and legal basis it can justify, and only for as long as that basis exists. Where a legal basis ceases, processing may continue only if another appropriate basis can be demonstrated. As a general rule legal bases are documented in writing; in the case of consent, written confirmation (paper-based or electronic) is required for later verification.
06What personal data we process
The controller produces films and commercials, and also carries out technical supervision of real-estate developments, the management of construction works, and technical consultancy. In the course of these activities it comes into contact with the personal data of natural persons, as follows.
Customer enquiries & contracts
Contracts are preceded by a request for a quotation, received by phone, email or social media. The enquirer provides their name, phone number and email address so the controller can send its quotation. Purpose: sending the quotation and making contact. Legal basis: steps prior to entering into a contract (GDPR Art. 6(1)(b)). If a quotation is rejected, the enquirer's data are deleted without delay but within 30 days of rejection at the latest; if no response is received, within 60 days of the quotation being sent. If the enquirer accepts and orders the service, a contractual relationship is established and further personal data of the partners and contact persons are processed for performance of the contract and for keeping in contact - legal basis: performance of the contract (Art. 6(1)(b)), or, for a contact person of a legal entity, the controller's legitimate interest (Art. 6(1)(f)).
Invoicing
The controller issues invoices for the services it sells. Invoices contain the customer's name, address and, where applicable, tax number. Issuing invoices is a statutory obligation; legal basis: compliance with a legal obligation (Art. 6(1)(c)). Personal data on invoices are retained for 8 years under the record-keeping obligation in Section 169 of the Accounting Act.
Suppliers & subcontractors
The controller has contractual relationships with subcontractors, suppliers and service providers, and processes contact details (name, email, phone). Legal basis: performance of the contract for a natural person or sole trader (Art. 6(1)(b)); for the contact person of a legal entity, the controller's legitimate interest (Art. 6(1)(f)).
Emails & phone numbers
The controller processes the email addresses and phone numbers of clients, partners and other affected persons, primarily to perform contractual obligations (Art. 6(1)(b)) or based on individual consent (Art. 6(1)(a)).
Job applications
Applicants submit CVs. Purpose: filling the advertised position or a possible future vacancy, and finding suitably qualified staff. Legal basis: the data subject's consent (Art. 6(1)(a)). CVs are stored for 3 months from receipt and then destroyed, unless the data subject sets a longer period in their consent. The controller does not post anonymous job advertisements and always discloses its identity.
Photos & video recordings
The controller occasionally makes photo or video recordings of clients, partners, employees, participants in shoots and other affected persons. Where an identifiable individual appears, the recording is made and used (on the website, social media or other appearances) only with the data subject's prior, voluntary, written and informed consent. Legal basis: consent (Art. 6(1)(a)). If consent is withdrawn, the controller stops using and/or deletes the recording without delay, within 30 days at the latest.
Team & complaints
The controller presents its team members on the website and in reference materials (name, email, phone, image) only with their prior, written, informed consent (Art. 6(1)(a)), and processes the data until consent is withdrawn. For complaint handling, processing serves to enable the complaint, identify the complainant, record the legally required data and investigate and resolve the matter - a mandatory activity under Act CLV of 1997 on Consumer Protection; legal basis: legal obligation (Art. 6(1)(c)). The controller keeps a processing register that also records the deletion deadlines (see the Annex).
07Processors & joint controllers
Where processing is carried out on the controller's behalf, the controller engages only processors that provide sufficient guarantees of GDPR compliance and appropriate technical and organisational measures. By accepting this policy, data subjects acknowledge that their personal data may be transferred to the processors and joint controllers listed below.
The controller also transmits customers' personal data to the National Tax and Customs Administration of Hungary. Contracted processors and partners process personal data only on the controller's instructions (except where required by law) and under a duty of confidentiality.
08Children & special-category data
The controller provides its services only to persons over 18. By consenting to cookies on the website, the data subject declares that they are at least 16 years old; a person under 16 may not consent to cookie data collection, since under GDPR Art. 8(1) the authorisation of a legal guardian is required. The controller cannot verify a person's age or capacity, so the data subject warrants that the data they provide are accurate.
The controller does not record special-category data brought to its attention. If such data enters any of its systems without its knowledge, it is deleted without delay upon detection.
09The website & cookies
The controller presents its activities and services on www.friday-creative.com. The website uses cookies; the legal basis for processing data obtained through them is the visitor's consent (Art. 6(1)(a)).
Cookies collect information about visitors and their devices, remember individual settings, make the website easier to use and provide a quality experience. A small data packet is placed on the user's device and read back on later visits. If the visitor disables some or all cookies, they may not be able to use every function of the website. Cookie preferences can be managed and existing cookies deleted in the browser settings.
| Cookie | Duration | Type |
|---|---|---|
| cookieyes-consent | 1 year | Strictly necessary |
| __cf_bm | 30 minutes | Strictly necessary |
| player | 1 year | Strictly necessary |
| vuid | 2 years | Statistics - Vimeo |
| sync_active | Session | Strictly necessary |
Strictly necessary session cookies allow visitors to browse the site and use its functions; they expire when browsing ends and are automatically deleted when the browser is closed.
11Cloud applications
The controller uses cloud services mainly to store, back up and share recordings and documents. In these cases the cloud provider acts as a processor, processing personal data on the controller's behalf, under a duty of confidentiality and only on the controller's instructions. The controller selects its cloud partners with the utmost care, contracts with data security in mind, and regularly checks data security. Cloud storage is password-protected and accessible only to the controller. By accepting this policy, partners expressly consent to the data transfers required to use these cloud applications (Art. 6(1)(a)).
12Security of processing
The controller ensures the security of the data and maintains the technical, organisational and procedural measures needed to protect recorded, stored and processed data and to prevent their destruction, unauthorised use and unauthorised alteration. It requires any third party to whom data are transferred to meet the same data-security requirements.
The controller ensures that unauthorised persons cannot access, disclose, transmit, modify or delete the data. Data are known only to the controller and its processors and are not handed to third parties not entitled to access them. Protection includes physical security (documents kept in lockable rooms and cabinets, monitored by security cameras and protected by an alarm) and IT security (e.g. firewalls). Data subjects acknowledge that, despite the controller's efforts, protection of data on the internet and in computer systems cannot be fully guaranteed.
13Your rights
You may exercise any of the rights below - or ask for related information - by contacting:
Friday Creative Kft., 1025 Budapest, Csatárka út 82-84. · titkarsag@fridaymails.com
We respond within 30 days - by post to postal requests, and by email to email requests.
Transparent information. This policy itself is intended to provide clear, concise and intelligible information about our processing.
Right of access. You may obtain confirmation as to whether your data are being processed and, if so, access to the data and information on the purpose, the categories of data, the recipients and the envisaged storage period.
Right to rectification. You may have inaccurate personal data concerning you corrected.
Right to erasure. You may request erasure where: the data are no longer needed for the purpose collected; you withdraw consent and there is no other legal basis; you object and there is no overriding legitimate ground; the data were processed unlawfully; or erasure is required by law.
Right to restriction. You may request restriction, in particular where you contest the accuracy of the data, or consider the processing unlawful but do not want erasure.
Right to data portability. You may receive your data in a structured, commonly used, machine-readable format and transmit it to another controller.
Right to object. You may object at any time, on grounds relating to your particular situation, to the processing of your personal data, as set out in Article 21 of the GDPR.
Automated decision-making. You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects. The controller does not use such automated tools with significant effects on data subjects' rights.
The controller informs every recipient to whom the data were disclosed of any request relating to the above rights, unless this proves impossible, and notifies the data subject of its decision within 30 days at the latest.
14Data breaches
A personal-data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data - whether intentional or negligent. Examples include unlawful transmission of data, unauthorised access to systems or applications, and the corruption or loss of part or all of a database.
Unless a breach is unlikely to result in a risk to the rights and freedoms of natural persons, the controller notifies the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) without undue delay and, where feasible, within 72 hours of becoming aware of it; if later, the reasons for the delay are given. The controller keeps a register of breaches, recording the facts, effects and remedial measures. Where a breach is likely to result in a high risk to data subjects, the controller informs the affected partners without delay, clearly describing the nature of the breach and the key information and measures - except where the conditions for exemption under the GDPR are met (e.g. the data were rendered unintelligible by encryption, subsequent measures eliminate the high risk, or individual notification would involve disproportionate effort, in which case a public communication is used).
15Applicable law & remedies
Relevant legislation includes: Regulation (EU) 2016/679 (GDPR); Act CXII of 2011 on the right to informational self-determination and freedom of information; Act V of 2013 (Civil Code); Act CXLVII of 2012 (on the itemised tax of small taxpayers and small-business tax); Act C of 2000 (Accounting Act); Act XXV of 2023 (on complaints, public-interest disclosures and whistleblowing); and Act CLV of 1997 (Consumer Protection).
The controller provides information about any processing not listed here at the time of collection, applying the provisions of applicable law. Courts, prosecutors, investigating and other authorities, NAIH and the Magyar Nemzeti Bank may request information; the controller discloses only as much personal data as is strictly necessary for the stated purpose.
Right to go to court
If your rights are infringed, you may bring proceedings against the controller before a court, which deals with the case as a priority.
Supervisory authority
Budapest, 27 March 2026 - Eszter Falvai, Managing Director
16Annex - processing register
| # | Personal data | Purpose | Legal basis | Erasure deadline |
|---|---|---|---|---|
| 1 | Enquiry data of a natural person / sole trader (name, email, phone) | Quotation, contact | Pre-contractual steps - Art. 6(1)(b) | Within 30 days of rejection; or 60 days of sending if no response |
| 2 | Enquiry data of a legal entity's contact person (name, email, phone) | Quotation, contact | Legitimate interest - Art. 6(1)(f) | Within 30 days of rejection; or 60 days of sending if no response |
| 3 | Contract data of a natural person / sole trader (name, address, email, phone) | Performance of contract, contact | Contract - Art. 6(1)(b), then legal obligation - Art. 6(1)(c) | Within 30 days after the 8-year statutory retention |
| 4 | Contact-person data under a contract with a legal entity (name, email, phone) | Performance of contract, contact | Legitimate interest - Art. 6(1)(f) | Within 30 days of contract ending (or after statutory retention) |
| 5 | Personal data on invoices to service users (natural person / sole trader) | Statutory invoicing | Legal obligation - Art. 6(1)(c) | Within 30 days after the 8-year statutory retention |
| 6 | Suppliers', service providers', subcontractors' data (natural person / sole trader) | Performance of contract, contact | Contract - Art. 6(1)(b), then legal obligation - Art. 6(1)(c) | Within 30 days after the 8-year statutory retention |
| 7 | Contact persons of suppliers, service providers, subcontractors | Performance of contract, contact | Legitimate interest - Art. 6(1)(f) | Within 30 days of contract ending (or after statutory retention) |
| 8 | Incoming emails (senders' addresses) and phone numbers | Performance of contract or consent | Contract - Art. 6(1)(b), or consent - Art. 6(1)(a) | Within 30 days of contract performance, or of consent withdrawal |
| 9 | Personal data in applicants' CVs | Filling a position / future vacancy | Consent - Art. 6(1)(a) | Within 30 days of closing the role; or per consent for unsolicited CVs |
| 10 | Image in photos/videos of clients, staff, shoot participants, others | Promotion; use on website, social, appearances | Consent - Art. 6(1)(a) | Within 30 days of consent withdrawal |
| 11 | Personal data recorded via website cookies | Improving experience, developing the website | Consent - Art. 6(1)(a) | Within 30 days of consent withdrawal |
| 12 | Team data published on the website / reference materials (name, email, phone, image) | Presenting the activity and staff | Consent - Art. 6(1)(a) | Within 30 days of consent withdrawal |
| 13 | Personal data obtained via social-media use | Promoting the activity and services | Consent - Art. 6(1)(a) | Within 30 days of consent withdrawal |
| 14 | Personal data learned during complaint handling | Identifying and handling complaints | Legal obligation - Art. 6(1)(c) | Within 30 days after the 3-year statutory retention |
10Social media
The controller operates social-media pages where personal data are processed on the basis of consent (Art. 6(1)(a)), given by liking, following or commenting. The controller uses data obtained there only to respond to enquiries, not for further advertising; the platforms themselves may use the data for their own purposes, including profiling and ad targeting. The controller has no influence over, and does not receive personal data from, the platform operators.