PRIVACY POLICY

Last updated: 31 July 2026

1. Introduction

This Privacy Policy explains how personal data may be processed in connection with the website available at zoltanpannon.com.

The website is operated as a professional portfolio presenting the work, experience and projects of Zoltán Pannon in the fields of industrial design, product development, food design and marketing.

The website does not operate an online shop, does not provide user registration, does not allow visitors to post comments and does not use a contact form.

2. Data Controller

Name: Zoltán Pannon, Sole Proprietor
Registered office: 10 Jegenye Street, 8060 Mór, Hungary
Registration number: 61410202
Tax number: 91558691-1-27
Email: zoltan.pannon@gmail.com
Telephone: +36 20 595 8686
Website: zoltanpannon.com

For questions regarding this Privacy Policy or the processing of personal data, visitors may contact the Data Controller using the email address above.

3. Personal Data Processed Through Direct Contact

The website displays an email address and telephone number through which visitors may contact the Data Controller directly.

When a visitor sends an email, makes a telephone call or otherwise contacts the Data Controller, the following personal data may be processed:

  • name;
  • email address;
  • telephone number;
  • company name or professional position, where provided;
  • the content of the message;
  • any other personal data voluntarily provided by the visitor.

Purpose of processing

Personal data provided during direct communication are processed for the following purposes:

  • responding to enquiries;
  • professional communication;
  • discussing possible employment, freelance work, cooperation or project opportunities;
  • preparing an offer or taking steps before entering into an agreement;
  • maintaining records of relevant professional correspondence;
  • establishing, exercising or defending legal claims where necessary.

Legal basis

Depending on the nature of the communication, the legal basis for processing may be:

  • taking steps at the request of the data subject prior to entering into a contract, pursuant to Article 6(1)(b) of the GDPR;
  • compliance with a legal obligation, pursuant to Article 6(1)(c) of the GDPR;
  • the legitimate interest of the Data Controller in responding to enquiries, maintaining professional correspondence and protecting legal interests, pursuant to Article 6(1)(f) of the GDPR;
  • the consent of the data subject, pursuant to Article 6(1)(a) of the GDPR, where consent is the appropriate legal basis.

Providing personal data through direct communication is voluntary. However, the Data Controller may be unable to respond to an enquiry without the contact information necessary for communication.

4. Retention of Correspondence

Personal data contained in general enquiries are retained only for as long as necessary to respond to and resolve the relevant matter.

Where an enquiry does not result in further cooperation or a contractual relationship, the related correspondence will normally be deleted no later than one year after the matter has been concluded, unless longer retention is necessary for the establishment, exercise or defence of legal claims.

Where communication results in a contractual or business relationship, the relevant data may be retained for the duration required by applicable contractual, accounting, taxation and other legal obligations.

5. Technical Data and Server Logs

When the website is visited, the hosting provider may automatically process certain technical information necessary for delivering and securing the website.

Such information may include:

  • the visitor’s IP address;
  • date and time of access;
  • requested page or file;
  • browser type and version;
  • operating system;
  • referring website;
  • technical error and security information.

These data are processed for the purposes of:

  • displaying and operating the website;
  • ensuring network and information security;
  • preventing misuse, attacks and unauthorised access;
  • identifying and correcting technical errors.

The legal basis for this processing is the legitimate interest of the Data Controller in operating a secure, reliable and technically functional website, pursuant to Article 6(1)(f) of the GDPR.

Technical logs are retained only for the period necessary for security, maintenance and troubleshooting purposes, subject to the hosting provider’s applicable retention practices.

6. Hosting Provider

The website is hosted by:

Hostinger International Ltd
61 Lordou Vironos Street
6023 Larnaca
Cyprus
Email: support@hostinger.com

The hosting provider may process technical and server log data on behalf of the Data Controller to the extent necessary for hosting, operating and protecting the website.

7. Cookies and Tracking Technologies

The public portfolio website does not intentionally use:

  • analytics cookies;
  • advertising cookies;
  • marketing or profiling cookies;
  • social media tracking pixels;
  • visitor tracking or behavioural analysis tools.

The website does not use Google Analytics, Meta Pixel or comparable visitor-tracking services.

No cookie consent banner is displayed because the website does not intentionally place non-essential cookies on visitors’ devices.

The website’s administrative interface, which is not available to ordinary visitors, may use strictly necessary technical cookies when an authorised administrator logs in. These cookies are used solely for authentication, security and website administration and are not used to track public visitors.

If the website’s functionality or use of cookies changes in the future, this Privacy Policy will be updated accordingly and, where legally required, prior consent will be requested.

8. External Links

The website may contain links to external websites, professional platforms, social media pages or project-related websites.

When a visitor follows an external link, the external website may process personal data in accordance with its own privacy policy. The Data Controller does not control and is not responsible for the data processing practices or content of external websites.

Simply displaying a link to an external website does not mean that personal data are automatically transferred to that website. Data may be transferred when the visitor actively opens the external link.

9. Embedded Third-Party Content

The website does not intentionally embed third-party videos, social media feeds or other third-party content that automatically tracks visitors.

If third-party embedded content is added in the future, this Privacy Policy will be updated and any legally required privacy settings or consent mechanisms will be introduced.

10. Disclosure of Personal Data

Personal data are not sold, rented or provided to third parties for advertising purposes.

Personal data may be disclosed only where:

  • it is necessary for the operation or hosting of the website;
  • a service provider processes data on behalf of the Data Controller;
  • disclosure is required by law or by a competent authority;
  • it is necessary for the establishment, exercise or defence of legal claims;
  • the data subject has expressly requested or authorised the disclosure.

Only the minimum amount of personal data necessary for the relevant purpose will be disclosed.

11. International Data Transfers

The Data Controller does not intentionally transfer personal data collected through the website to countries outside the European Economic Area.

However, if a visitor independently contacts the Data Controller through an external email, social media or communication service, that service provider may process data outside the European Economic Area in accordance with its own privacy policy and applicable data-transfer safeguards.

12. Automated Decision-Making and Profiling

The Data Controller does not use personal data collected through the website for automated decision-making or profiling.

13. Data Security

The Data Controller applies reasonable technical and organisational measures to protect personal data against:

  • unauthorised access;
  • unlawful disclosure;
  • accidental loss;
  • alteration;
  • destruction;
  • misuse.

The website uses encrypted HTTPS communication. Access to website administration and professional correspondence is restricted to authorised persons.

Despite these measures, no internet-based transmission or storage system can be guaranteed to be completely secure.

14. Rights of Data Subjects

Under the GDPR, data subjects may have the right to:

  • request information about the processing of their personal data;
  • request access to their personal data;
  • request the correction of inaccurate or incomplete personal data;
  • request the erasure of their personal data;
  • request the restriction of processing;
  • object to processing based on legitimate interests;
  • withdraw consent at any time where processing is based on consent;
  • request data portability where the legal conditions are met;
  • lodge a complaint with a supervisory authority;
  • seek a judicial remedy.

The withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Requests concerning these rights may be submitted to:

zoltan.pannon@gmail.com

The Data Controller will respond without undue delay and generally within one month of receiving the request. Where necessary, the Data Controller may request additional information to verify the identity of the applicant.

15. Right to Lodge a Complaint

Anyone who believes that the processing of their personal data infringes applicable data protection law may lodge a complaint with the Hungarian supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information
Nemzeti Adatvédelmi és Információszabadság Hatóság – NAIH

Address: 1055 Budapest, Falk Miksa utca 9–11., Hungary
Postal address: 1363 Budapest, P.O. Box 9, Hungary
Telephone: +36 1 391 1400
Email: ugyfelszolgalat@naih.hu

A data subject may also seek a judicial remedy before a competent court.

16. Children’s Data

The website is not directed specifically at children and does not intentionally collect personal data from children.

Children should not submit personal information by email or telephone without the involvement and permission of a parent or legal guardian.

17. Changes to This Privacy Policy

The Data Controller may update this Privacy Policy if the operation of the website, the data-processing activities or the applicable legal requirements change.

The current version will always be published on this page together with the date of the latest update.