Legal information
Privacy Policy
Last updated: 30 July 2026
This notice applies to visitors of the chestgraph.com website and to persons who contact ChestGraph by email. It covers the website’s current operation: contact, secure operation of the website, and — where consent is given — Google Analytics 4 based measurement of visits.
1. Data controller
- Name
- Vass Dávid sole trader (egyéni vállalkozó)
- Registered seat
- 1095 Budapest, Gát utca 21. fszt. 1., Hungary
- Registration number
- 59372008
- Tax number
- 90218000-2-43
- info@chestgraph.com
- Website
- chestgraph.com
2. Principles of processing
The controller processes personal data for specified, explicit and legitimate purposes, and only to the extent necessary for those purposes. Processing follows the principles of data minimisation, accuracy, confidentiality, integrity and storage limitation.
3. Contact by email
If you contact ChestGraph at info@chestgraph.com, we process the data provided in the email to respond to your enquiry, for professional or business discussions and — where relevant — for steps prior to entering into a contract.
- Data processed
- Name, email address, content of the message, and any organisational or contact details you voluntarily provide
- Purpose
- Responding to the enquiry, professional or business discussions, and where necessary taking steps prior to contracting
- Legal basis
- Article 6(1)(b) GDPR if you initiate contracting in your own name or request pre-contractual measures for your own contract; for enquiries sent on behalf of or as a contact person of an organisation, or other professional/business enquiries: Article 6(1)(f) GDPR — the controller’s legitimate interest in handling the enquiry, business communication and maintaining contact
- Legitimate interest
- Substantive handling of professional and business enquiries received by the controller, providing a response and carrying out necessary discussions
- Retention
- For general contact, up to 1 year after the matter is closed; if a contractual relationship is established, necessary data may be retained further in line with applicable statutory retention duties
- Provision of data
- Voluntary; without an email address or other contact details needed to reply, we cannot respond to the enquiry
- Recipients
- The email provider that delivers and hosts mailbox technology; where needed for technical operation, the hosting provider
4. Technical log data
When the website is served, the server may process technical log data. These typically include the IP address, time of the request, requested resource, technical data about the browser and operating system, and error information.
- Purpose
- Ensuring secure and stable operation of the website, troubleshooting, and detecting abuse and IT incidents
- Legal basis
- Legitimate interest under Article 6(1)(f) GDPR for the secure operation of the service
- Legitimate interest
- Ensuring the security, availability and fault-free operation of the website and related IT infrastructure
- Retention
- Up to 30 days, unless a longer period is necessary to investigate a security incident, abuse, or a legal claim
- Recipient
- RackForest Zrt. for hosting and server infrastructure
5. Google Analytics 4
The website uses Google Analytics 4 to measure visits and statistically analyse use of the site. Analytics measurement is activated only after your prior consent. Until consent is given, ChestGraph keeps Google Analytics measurement in a disabled state.
During measurement, Google Analytics may process, among other things, page-view and event data, device and browser characteristics, approximate geographic data, and technical identifiers related to the session. For users from the European Union, Google may use the IP address to determine geographic data and then discard it before logging; according to Google, the IP address is not logged or stored by Google Analytics.
- Purpose
- Statistical measurement of website traffic, use and performance, and improving content and user experience
- Legal basis
- Consent under Article 6(1)(a) GDPR
- Provider / processor
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland
- GA4 retention
- User-level and event-level data retention period: 14 months
- Data sharing with Google products
- ChestGraph keeps the Google Analytics “Google products & services” data-sharing setting disabled
Analytics cookies
After consent is given, Google Analytics may place first-party analytics cookies. According to Google’s documentation, the default expiry of the _ga and _ga_<id> cookies is 2 years. They are used to distinguish visitors and sessions for statistical purposes.
Managing consent
On the first visit you may decide whether to allow analytics measurement. If you refuse, analytics measurement does not start. To remember your choice, the website may use only the technical storage needed to record the consent setting. Consent may be withdrawn or changed at any time; withdrawal does not affect the lawfulness of processing carried out before withdrawal on the basis of valid consent.
International transfers
Google operates a global infrastructure, so Google Analytics data may in some cases also be processed outside the European Economic Area. For transfers to the United States to Google LLC, the EU–US Data Privacy Framework adequacy decision may apply where the recipient is an active participant in the Framework. Google LLC is currently listed among Data Privacy Framework participants. Where the adequacy decision does not apply to a transfer, Google may also rely on the European Commission’s Standard Contractual Clauses as an appropriate safeguard.
Further information on safeguards for international transfers is available in Google’s data transfer notices and in the EU–US Data Privacy Framework register.
6. Recipients, processors and providers
| Recipient / category | Role | Related processing |
|---|---|---|
| RackForest Zrt. 1132 Budapest, Victor Hugo utca 11. 5. em. B05001., Hungary | Hosting and server infrastructure | Website delivery, technical log data |
| Email provider (as configured in production) | Email delivery and mailbox technical operation | Contact emails and data contained therein |
| Google Ireland Limited Gordon House, Barrow Street, Dublin 4, Ireland | Google Analytics 4 | Visit and usage statistics based on consent |
Under Article 13 GDPR, this notice may also refer to categories of recipients. The specific email provider for the info@chestgraph.com mailbox is determined by the production configuration; the category means the provider that delivers and stores email.
7. Automated decision-making and profiling
In ChestGraph’s current operation, no automated decision-making that produces legal effects concerning the data subject, or similarly significantly affects them, takes place. The website does not create individual profiles with legal effects from analytics data.
8. Your rights
Under the conditions of the GDPR you may request access to your personal data, their rectification, erasure, or restriction of processing. Where applicable, you have the right to data portability. Where processing is based on legitimate interest, you may object on grounds relating to your particular situation.
Consent given for consent-based processing may be withdrawn at any time. Requests to exercise rights may be sent to info@chestgraph.com. The controller handles requests without undue delay, as a rule within one month of receipt.
9. Remedies
If you believe that the processing of your personal data infringes data protection law, you may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), or bring the matter before a court.
- Authority
- Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
- Address
- 1055 Budapest, Falk Miksa utca 9-11., Hungary
- Postal address
- 1363 Budapest, Pf. 9., Hungary
- Phone
- +36 1 391 1400
- Website
- naih.hu
10. Data security
The controller applies technical and organisational measures appropriate to the nature and risks of processing to protect personal data against unauthorised access, alteration, disclosure, erasure or loss. The website uses encrypted HTTPS connections.
11. Changes to this notice
The controller may amend this notice when the website’s operation, the services used, or the legal environment change. The version in force is available on the chestgraph.com website.
Effective: 30 July 2026.
Legal background: Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), Act CXII of 2011 (Infotv.), and the applicable provisions of Act C of 2003 on electronic communications, in particular rules on storing and accessing information on terminal equipment.