Back to site

Legal · Privacy

Privacy Policy.

How Friday Creative Kft. processes personal data in connection with the www.friday-creative.com website.

Effective from 27 March 2026 until revoked · This is an English translation provided for convenience; the Hungarian original prevails.

01The data controller

Friday Creative Kft. Registered office: 1025 Budapest, Csatárka út 82-84., Hungary Company reg. no.: 01-09-969706 · Tax no.: 23525731-2-41 Registry court: Company Registry Court of the Budapest-Capital Regional Court Representative: Eszter Falvai, Managing Director Phone: +36 30 595 4979 · Email: titkarsag@fridaymails.com

02Purpose & principles of this policy

The controller acknowledges the content of this legal notice as binding on itself. The purpose of this Privacy Policy is to inform our clients and partners about the processing of their personal data.

The controller processes personal data exclusively in accordance with applicable law, strictly observing data-processing and data-protection rules, and respecting the principles of lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, and storage limitation.

The controller takes every technical and organisational measure to process partners' personal data securely and in the manner required by Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), and has adapted its day-to-day operations, policies, records, document templates and notices accordingly.

The applicable data-protection principles are continuously available at the controller's registered office and on its website. The controller reserves the right to amend this policy at any time and will notify its audience of any changes in good time. The controller is committed to protecting the personal data of its clients and to respecting their right to informational self-determination, treating personal data confidentially and taking all security, technical and organisational measures that guarantee the security of the data.

03Scope

Personal scope: this policy covers the controller, the natural persons whose data are included in the processing activities under this policy, and persons whose rights or legitimate interests are affected by the processing.

Material scope: this policy covers all processing arising during the controller's activity on the www.friday-creative.com website.

Temporal scope: this policy enters into force on the day of its approval and remains in effect for an indefinite period until further notice.

04Key definitions

Personal data: any information relating to an identified or identifiable natural person, who can be identified directly or indirectly - in particular by reference to an identifier such as a name, a number, location data, an online identifier, or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity.

Special-category data: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership, as well as genetic data, biometric data for the purpose of uniquely identifying a person, health data, and data concerning a person's sex life or sexual orientation.

Processing: any operation performed on personal data, whether automated or not - including collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Controller / Processor / Joint controllers / Third party: bear the meanings given in the GDPR. Consent means the freely given, specific, informed and unambiguous indication of the data subject's wishes. A personal-data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

05Lawful bases for processing

The controller processes personal data only where at least one of the following applies:

  • the data subject has given consent for one or more specific purposes;
  • processing is necessary for the performance of a contract to which the data subject is a party;
  • processing is necessary for compliance with a legal obligation;
  • processing is necessary to protect the vital interests of the data subject or another natural person;
  • processing is necessary for the legitimate interests of the controller or a third party.

The controller examines the lawfulness of processing at every stage of its activity and only processes data whose purpose and legal basis it can justify, and only for as long as that basis exists. Where a legal basis ceases, processing may continue only if another appropriate basis can be demonstrated. As a general rule legal bases are documented in writing; in the case of consent, written confirmation (paper-based or electronic) is required for later verification.

06What personal data we process

The controller produces films and commercials, and also carries out technical supervision of real-estate developments, the management of construction works, and technical consultancy. In the course of these activities it comes into contact with the personal data of natural persons, as follows.

Customer enquiries & contracts

Contracts are preceded by a request for a quotation, received by phone, email or social media. The enquirer provides their name, phone number and email address so the controller can send its quotation. Purpose: sending the quotation and making contact. Legal basis: steps prior to entering into a contract (GDPR Art. 6(1)(b)). If a quotation is rejected, the enquirer's data are deleted without delay but within 30 days of rejection at the latest; if no response is received, within 60 days of the quotation being sent. If the enquirer accepts and orders the service, a contractual relationship is established and further personal data of the partners and contact persons are processed for performance of the contract and for keeping in contact - legal basis: performance of the contract (Art. 6(1)(b)), or, for a contact person of a legal entity, the controller's legitimate interest (Art. 6(1)(f)).

Invoicing

The controller issues invoices for the services it sells. Invoices contain the customer's name, address and, where applicable, tax number. Issuing invoices is a statutory obligation; legal basis: compliance with a legal obligation (Art. 6(1)(c)). Personal data on invoices are retained for 8 years under the record-keeping obligation in Section 169 of the Accounting Act.

Suppliers & subcontractors

The controller has contractual relationships with subcontractors, suppliers and service providers, and processes contact details (name, email, phone). Legal basis: performance of the contract for a natural person or sole trader (Art. 6(1)(b)); for the contact person of a legal entity, the controller's legitimate interest (Art. 6(1)(f)).

Emails & phone numbers

The controller processes the email addresses and phone numbers of clients, partners and other affected persons, primarily to perform contractual obligations (Art. 6(1)(b)) or based on individual consent (Art. 6(1)(a)).

Job applications

Applicants submit CVs. Purpose: filling the advertised position or a possible future vacancy, and finding suitably qualified staff. Legal basis: the data subject's consent (Art. 6(1)(a)). CVs are stored for 3 months from receipt and then destroyed, unless the data subject sets a longer period in their consent. The controller does not post anonymous job advertisements and always discloses its identity.

Photos & video recordings

The controller occasionally makes photo or video recordings of clients, partners, employees, participants in shoots and other affected persons. Where an identifiable individual appears, the recording is made and used (on the website, social media or other appearances) only with the data subject's prior, voluntary, written and informed consent. Legal basis: consent (Art. 6(1)(a)). If consent is withdrawn, the controller stops using and/or deletes the recording without delay, within 30 days at the latest.

Team & complaints

The controller presents its team members on the website and in reference materials (name, email, phone, image) only with their prior, written, informed consent (Art. 6(1)(a)), and processes the data until consent is withdrawn. For complaint handling, processing serves to enable the complaint, identify the complainant, record the legally required data and investigate and resolve the matter - a mandatory activity under Act CLV of 1997 on Consumer Protection; legal basis: legal obligation (Art. 6(1)(c)). The controller keeps a processing register that also records the deletion deadlines (see the Annex).

07Processors & joint controllers

Where processing is carried out on the controller's behalf, the controller engages only processors that provide sufficient guarantees of GDPR compliance and appropriate technical and organisational measures. By accepting this policy, data subjects acknowledge that their personal data may be transferred to the processors and joint controllers listed below.

EGM Adó-Kontír Kft.Accounting · 1116 Budapest, Talpas u. 3.adokontir.hu
Petrovics és Társa Bt.Auditing · 1141 Budapest, Szederkény u. 3. 3/14.
KBOSS.hu Kft. (Számlázz.hu)Invoicing · 1031 Budapest, Záhony u. 7.info@szamlazz.hu
Redda Motor Kft.Courier · 1097 Budapest, Gubacsi út 30.+36 1 218 0888 · redda@redda.hu
Valentyik Zoltán (sole trader)Web hosting · 1221 Budapest, Mária Terézia u. 28-30. 7/42.valzol@gmail.com
iSolutions Kft.Email server · 2040 Budaörs, Baross utca 89.gondolatebreszto@isolutions.hu
Coupa Software Inc.Project management · San Mateo, CA, USAgdpr@coupa.com
ComboSoft Informatikai Kft.Accounting systeminfo@combosoft.hu
Google Ireland LimitedCloud storage (Google Drive) · Gordon House, Barrow Street, Dublin 4, Ireland
Vimeo, Inc.Video hosting · 555 West 18th Street, New York, NY 10011privacy@vimeo.com
Meta Platforms Ireland Ltd.Joint controller (social) · 4 Grand Canal Square, Dublin 2, Ireland
LinkedIn CorporationJoint controller (social) · 1000 W Maude Ave, Sunnyvale, CA 94085, USA

The controller also transmits customers' personal data to the National Tax and Customs Administration of Hungary. Contracted processors and partners process personal data only on the controller's instructions (except where required by law) and under a duty of confidentiality.

08Children & special-category data

The controller provides its services only to persons over 18. By consenting to cookies on the website, the data subject declares that they are at least 16 years old; a person under 16 may not consent to cookie data collection, since under GDPR Art. 8(1) the authorisation of a legal guardian is required. The controller cannot verify a person's age or capacity, so the data subject warrants that the data they provide are accurate.

The controller does not record special-category data brought to its attention. If such data enters any of its systems without its knowledge, it is deleted without delay upon detection.

09The website & cookies

The controller presents its activities and services on www.friday-creative.com. The website uses cookies; the legal basis for processing data obtained through them is the visitor's consent (Art. 6(1)(a)).

Cookies collect information about visitors and their devices, remember individual settings, make the website easier to use and provide a quality experience. A small data packet is placed on the user's device and read back on later visits. If the visitor disables some or all cookies, they may not be able to use every function of the website. Cookie preferences can be managed and existing cookies deleted in the browser settings.

Cookies used on www.friday-creative.com
CookieDurationType
cookieyes-consent1 yearStrictly necessary
__cf_bm30 minutesStrictly necessary
player1 yearStrictly necessary
vuid2 yearsStatistics - Vimeo
sync_activeSessionStrictly necessary

Strictly necessary session cookies allow visitors to browse the site and use its functions; they expire when browsing ends and are automatically deleted when the browser is closed.

10Social media

The controller operates social-media pages where personal data are processed on the basis of consent (Art. 6(1)(a)), given by liking, following or commenting. The controller uses data obtained there only to respond to enquiries, not for further advertising; the platforms themselves may use the data for their own purposes, including profiling and ad targeting. The controller has no influence over, and does not receive personal data from, the platform operators.

11Cloud applications

The controller uses cloud services mainly to store, back up and share recordings and documents. In these cases the cloud provider acts as a processor, processing personal data on the controller's behalf, under a duty of confidentiality and only on the controller's instructions. The controller selects its cloud partners with the utmost care, contracts with data security in mind, and regularly checks data security. Cloud storage is password-protected and accessible only to the controller. By accepting this policy, partners expressly consent to the data transfers required to use these cloud applications (Art. 6(1)(a)).

12Security of processing

The controller ensures the security of the data and maintains the technical, organisational and procedural measures needed to protect recorded, stored and processed data and to prevent their destruction, unauthorised use and unauthorised alteration. It requires any third party to whom data are transferred to meet the same data-security requirements.

The controller ensures that unauthorised persons cannot access, disclose, transmit, modify or delete the data. Data are known only to the controller and its processors and are not handed to third parties not entitled to access them. Protection includes physical security (documents kept in lockable rooms and cabinets, monitored by security cameras and protected by an alarm) and IT security (e.g. firewalls). Data subjects acknowledge that, despite the controller's efforts, protection of data on the internet and in computer systems cannot be fully guaranteed.

13Your rights

You may exercise any of the rights below - or ask for related information - by contacting:

Friday Creative Kft., 1025 Budapest, Csatárka út 82-84. · titkarsag@fridaymails.com

We respond within 30 days - by post to postal requests, and by email to email requests.

Transparent information. This policy itself is intended to provide clear, concise and intelligible information about our processing.

Right of access. You may obtain confirmation as to whether your data are being processed and, if so, access to the data and information on the purpose, the categories of data, the recipients and the envisaged storage period.

Right to rectification. You may have inaccurate personal data concerning you corrected.

Right to erasure. You may request erasure where: the data are no longer needed for the purpose collected; you withdraw consent and there is no other legal basis; you object and there is no overriding legitimate ground; the data were processed unlawfully; or erasure is required by law.

Right to restriction. You may request restriction, in particular where you contest the accuracy of the data, or consider the processing unlawful but do not want erasure.

Right to data portability. You may receive your data in a structured, commonly used, machine-readable format and transmit it to another controller.

Right to object. You may object at any time, on grounds relating to your particular situation, to the processing of your personal data, as set out in Article 21 of the GDPR.

Automated decision-making. You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects. The controller does not use such automated tools with significant effects on data subjects' rights.

The controller informs every recipient to whom the data were disclosed of any request relating to the above rights, unless this proves impossible, and notifies the data subject of its decision within 30 days at the latest.

14Data breaches

A personal-data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data - whether intentional or negligent. Examples include unlawful transmission of data, unauthorised access to systems or applications, and the corruption or loss of part or all of a database.

Unless a breach is unlikely to result in a risk to the rights and freedoms of natural persons, the controller notifies the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) without undue delay and, where feasible, within 72 hours of becoming aware of it; if later, the reasons for the delay are given. The controller keeps a register of breaches, recording the facts, effects and remedial measures. Where a breach is likely to result in a high risk to data subjects, the controller informs the affected partners without delay, clearly describing the nature of the breach and the key information and measures - except where the conditions for exemption under the GDPR are met (e.g. the data were rendered unintelligible by encryption, subsequent measures eliminate the high risk, or individual notification would involve disproportionate effort, in which case a public communication is used).

15Applicable law & remedies

Relevant legislation includes: Regulation (EU) 2016/679 (GDPR); Act CXII of 2011 on the right to informational self-determination and freedom of information; Act V of 2013 (Civil Code); Act CXLVII of 2012 (on the itemised tax of small taxpayers and small-business tax); Act C of 2000 (Accounting Act); Act XXV of 2023 (on complaints, public-interest disclosures and whistleblowing); and Act CLV of 1997 (Consumer Protection).

The controller provides information about any processing not listed here at the time of collection, applying the provisions of applicable law. Courts, prosecutors, investigating and other authorities, NAIH and the Magyar Nemzeti Bank may request information; the controller discloses only as much personal data as is strictly necessary for the stated purpose.

Right to go to court

If your rights are infringed, you may bring proceedings against the controller before a court, which deals with the case as a priority.

Supervisory authority

National Authority for Data Protection and Freedom of Information (NAIH) 1055 Budapest, Falk Miksa u. 9-11. · Postal: 1363 Budapest, Pf. 9. Phone: +36 1 391 1400 · Fax: +36 1 391 1410 Email: ugyfelszolgalat@naih.hu · naih.hu

Budapest, 27 March 2026 - Eszter Falvai, Managing Director

16Annex - processing register

Record of processing activities
#Personal dataPurposeLegal basisErasure deadline
1Enquiry data of a natural person / sole trader (name, email, phone)Quotation, contactPre-contractual steps - Art. 6(1)(b)Within 30 days of rejection; or 60 days of sending if no response
2Enquiry data of a legal entity's contact person (name, email, phone)Quotation, contactLegitimate interest - Art. 6(1)(f)Within 30 days of rejection; or 60 days of sending if no response
3Contract data of a natural person / sole trader (name, address, email, phone)Performance of contract, contactContract - Art. 6(1)(b), then legal obligation - Art. 6(1)(c)Within 30 days after the 8-year statutory retention
4Contact-person data under a contract with a legal entity (name, email, phone)Performance of contract, contactLegitimate interest - Art. 6(1)(f)Within 30 days of contract ending (or after statutory retention)
5Personal data on invoices to service users (natural person / sole trader)Statutory invoicingLegal obligation - Art. 6(1)(c)Within 30 days after the 8-year statutory retention
6Suppliers', service providers', subcontractors' data (natural person / sole trader)Performance of contract, contactContract - Art. 6(1)(b), then legal obligation - Art. 6(1)(c)Within 30 days after the 8-year statutory retention
7Contact persons of suppliers, service providers, subcontractorsPerformance of contract, contactLegitimate interest - Art. 6(1)(f)Within 30 days of contract ending (or after statutory retention)
8Incoming emails (senders' addresses) and phone numbersPerformance of contract or consentContract - Art. 6(1)(b), or consent - Art. 6(1)(a)Within 30 days of contract performance, or of consent withdrawal
9Personal data in applicants' CVsFilling a position / future vacancyConsent - Art. 6(1)(a)Within 30 days of closing the role; or per consent for unsolicited CVs
10Image in photos/videos of clients, staff, shoot participants, othersPromotion; use on website, social, appearancesConsent - Art. 6(1)(a)Within 30 days of consent withdrawal
11Personal data recorded via website cookiesImproving experience, developing the websiteConsent - Art. 6(1)(a)Within 30 days of consent withdrawal
12Team data published on the website / reference materials (name, email, phone, image)Presenting the activity and staffConsent - Art. 6(1)(a)Within 30 days of consent withdrawal
13Personal data obtained via social-media usePromoting the activity and servicesConsent - Art. 6(1)(a)Within 30 days of consent withdrawal
14Personal data learned during complaint handlingIdentifying and handling complaintsLegal obligation - Art. 6(1)(c)Within 30 days after the 3-year statutory retention