Data protection

Privacy policy

In force from 11 September 2026 · Version 1.0

This is an English translation provided for information. The service is supplied in Hungary under Hungarian law. In the event of any difference in meaning, the Hungarian version prevails.

Contents
  1. The controller
  2. When and how do we receive personal data?
  3. Data processed: purpose, legal basis, retention
  4. Who do we share data with?
  5. Cookies and third-party services
  6. Data security
  7. Your rights
  8. Data breach
  9. Remedies
  10. Changes to this notice

1. The controller

ControllerPapp Sándor, sole trader
BrandCIMEX
Registered seat2112 Veresegyház, Egressy Béni utca 15/A, Hungary
VAT number92145474-1-33
Registration number62455206
Phone, WhatsApp+36 30 601 3736
E-mailinfo@cimex.hu
Data protection officerNot appointed – the controller is not required to do so under Article 37 GDPR

We process personal data lawfully, fairly and transparently, for specified purposes and with data minimisation in mind. We ask only for what is actually needed to give a quote and carry out the service.

Bed bugs are a sensitive subject. We know many people worry that their neighbours or colleagues will find out. That is why we ask only for the data the work requires, work without drawing attention on site, and never use your data for marketing.

2. When and how do we receive personal data?

In three ways:

  1. Through the callback request form on this website.
  2. By phone, WhatsApp or e-mail, when you contact us directly.
  3. On site, during the survey and the work, when the work sheet is issued.

We do not collect data covertly, do not buy databases, do not send newsletters, and carry out no automated decision-making or profiling.

The price calculator collects no data. The postcode, number of rooms and other settings you enter are processed only in your own browser and do not reach us unless you submit the callback request form. The same applies to the photo preview: the image you select does not leave your device.

3. Data processed: purpose, legal basis, retention

3.1 Requesting contact (form, phone, WhatsApp, e-mail)

Data processed: name, phone number, postcode, requested treatment type, number of affected rooms and sleeping places, and a short description of the problem if you provide one. When the form is submitted, the values set in the calculator and the estimated price are also sent, so you do not have to repeat them.

Purpose: making contact, preliminary assessment, quoting, agreeing a time for the visit.

Legal basis: steps taken at your request prior to entering into a contract – Article 6(1)(b) GDPR. Without a name, phone number and postcode we cannot quote; the other fields are optional but allow a more accurate quote.

Retention: 6 months from the quote if no contract is concluded. If you ask earlier, we delete without delay.

3.2 Performing the service, work sheet

If the order goes ahead, we issue a work sheet, as required by law. Data processed: the customer's name, the exact address treated, phone number and e-mail address, the size of the treated area, the target pest, the technology applied, the name and active ingredient of the biocidal product used, the quantity applied, the professional recommendation, and the customer's signature.

Legal basis: performance of the contract – Article 6(1)(b) GDPR – and compliance with a legal obligation – Article 6(1)(c) GDPR – under Hungarian Ministry of Welfare Decree 18/1998 (VI. 3.) NM.

Retention: 5 years from performance (the general limitation period under section 6:22 of the Hungarian Civil Code), so that legal claims remain enforceable.

3.3 Invoicing

Data processed: name, billing address, the name and price of the service; for business customers, the tax number.

Legal basis: compliance with a legal obligation – Article 6(1)(c) GDPR – under section 169(2) of Hungarian Act C of 2000 on Accounting.

Retention: 8 years. This is required by law, so we cannot delete these data within that period.

3.4 Photographs

Photographs you send us, and those taken on site to document the survey, are processed solely for professional assessment and documentation of the work.

Retention: 1 year after performance, after which we delete them.

We use photographs as references or for marketing only with your prior, express and written consent – Article 6(1)(a) GDPR. Consent can be withdrawn at any time without giving reasons; withdrawal does not affect the lawfulness of earlier use.

3.5 Complaints

We retain the data of a complaint and our reply for 3 years under section 17/A(7) of Hungarian Act CLV of 1997 on Consumer Protection. Legal basis: compliance with a legal obligation.

4. Who do we share data with?

We do not sell, rent or transfer personal data for marketing purposes. The following processors may access data, strictly to the extent needed for their own task:

Rackhost Zrt.
6000 Kecskemét, Sulyok u. 3/A, Hungary
hosting and e-mail – all data given on the website and by e-mail
Google Ireland Ltd.
Gordon House, Barrow Street, Dublin 4, Ireland
receiving the callback form and storing the work sheet (Google Workspace, Apps Script)
KBOSS.hu Kft. (Számlázz.hu)
1031 Budapest, Záhony u. 7., Hungary
invoicing – billing data
Accountantbookkeeping – billing data

Beyond this we transfer data only where required by law, or where an authority (for example the NNGYK or a court) requests it in an official procedure.

Transfers outside the EEA: when using Google Workspace, data may be transferred outside the European Economic Area. Google is a certified participant in the EU–US Data Privacy Framework and applies standard contractual clauses, which constitute appropriate safeguards under Chapter V GDPR.

5. Cookies and third-party services

This website uses no cookies. There is no Google Analytics, Google Tag Manager, Meta Pixel, advertising or tracking code, embedded video, embedded map, chat widget or newsletter system. We do not load fonts from an external provider either.

One exception: the exchange rate on this English page. To show indicative euro prices, your browser requests the current euro–forint reference rate from the Frankfurter API (api.frankfurter.dev), an open-source service that publishes European Central Bank reference rates. This request transmits your IP address to that service. No cookie is set and no identifier is sent; the request contains no information about you beyond what any web request contains. The rate is stored in your browser’s local storage for the rest of the day so the request is not repeated on every page view; this stored value is a public exchange rate, not personal data, and is not read by us. Legal basis: legitimate interest – Article 6(1)(f) GDPR – in showing prices that are up to date. If the request fails, the page falls back to a fixed rate and nothing else changes. The Hungarian version of this site makes no external request at all.

WhatsApp: the WhatsApp button is an external link. It contacts the WhatsApp service only if you click it. In that case the terms of WhatsApp (Meta Platforms Ireland Ltd.) apply.

Form submission: when the callback form is submitted, the data reach us through the Google Apps Script service. This happens only at the moment of sending.

Hosting logs: for security and fault handling, the server logs technical data of visits (IP address, timestamp, requested page, browser type). Legal basis: legitimate interest – Article 6(1)(f) GDPR. Retention: up to 30 days.

If we ever introduced statistical or marketing cookies, we would do so with a prior consent banner and by amending this notice.

6. Data security

Personal data are stored in password-protected systems accessed over an encrypted connection (HTTPS). Access is limited to the controller. Paper documents are kept in a locked place. We take regular backups and delete data that are no longer needed in an unrecoverable way.

7. Your rights

Under the GDPR you have the right to:

You can submit a request using the contact details above. We reply free of charge within one month at the latest. Where justified, this may be extended by a further two months; we will tell you and give the reason for the delay.

Processing based on a legal obligation – in particular invoicing and work sheet data – cannot be deleted before the retention period expires.

8. Data breach

If an event occurs that endangers the security of personal data, we record it and – where the event is likely to result in a risk – report it to the Hungarian National Authority for Data Protection and Freedom of Information within 72 hours. Where the risk is high, we also inform you directly.

9. Remedies

Please raise any complaint with us first: info@cimex.hu or +36 30 601 3736. Most questions are resolved fastest this way.

If that does not succeed, you may complain to the supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
1055 Budapest, Falk Miksa utca 9–11. · Postal address: 1363 Budapest, Pf. 9.
Phone: +36 1 391 1400 · E-mail: ugyfelszolgalat@naih.hu · www.naih.hu

You may also go to court. The action may – at your choice – be brought before the regional court of your place of residence or stay.

10. Changes to this notice

We reserve the right to amend this notice unilaterally if our services or the legal environment change. The version in force is always available at cimex.hu. We will draw attention to any material change on the website.

Legal background