01Who we are
This website, 1one.hu, is operated by 1One Kft., a company registered in Hungary that trades as First One ("First One", "we", "us"). For the personal data described in this policy we are the data controller.
For any question about your personal data, or to exercise your rights, write to info@1one.hu. We are not required to appoint a data protection officer, so this address is our single point of contact for privacy matters.
We process personal data in line with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and Hungarian Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information.
02What this policy covers
This policy explains what happens to your personal data when you visit this website, use the contact form, or write to us by email. It does not cover the software and services we build or run for our clients: personal data processed in those projects is governed by the contract — and, where we act as a processor, the data processing agreement — with the client concerned.
We do not run a newsletter, we do not send marketing emails, and we do not use your data for advertising or profiling.
03What we process, and why
3.1 Visiting the website
- Data
- Your IP address, the date and time of the request, the page requested, the referring page, your browser and operating system (user agent), and the status and size of the response.
- Purpose
- Delivering the website to you, keeping it secure (detecting and blocking attacks and misuse) and fixing errors.
- Legal basis
- Our legitimate interest in running a secure, working website (GDPR Art. 6(1)(f)).
- Retention
- These server logs are kept only as long as needed for security and troubleshooting, and are then deleted automatically by our hosting provider.
3.2 The contact form and email
- Data
- Your name and email address, and — if you choose to give them — your phone number, company and the topics you tick; the content of your message, and our correspondence that follows.
- Purpose
- Answering your enquiry, discussing your project and preparing a proposal.
- Legal basis
- Taking steps at your request before entering into a contract (GDPR Art. 6(1)(b)); for other enquiries, our legitimate interest in replying to messages we receive (GDPR Art. 6(1)(f)).
- Retention
- If your enquiry does not lead to a contract, we delete it no later than one year after our last exchange. If it does, the correspondence becomes part of the contract file and is kept for as long as the law requires (see section 7).
Name, email address and message are needed for us to reply; everything else is optional. The form sends your message to our mailbox by email — the website itself does not store form submissions. Please do not send us special categories of data (for example health data) or other people's personal data unless it is necessary for your enquiry.
3.3 Protecting the contact form from abuse
- Data
- A pseudonymised (hashed) form of your IP address — not the address itself — and the times you submitted the form.
- Purpose
- Limiting how many messages can be sent from one connection in a short time, to stop spam and automated abuse.
- Legal basis
- Our legitimate interest in protecting the form and our mailbox (GDPR Art. 6(1)(f)).
- Retention
- Ten minutes, after which it is discarded.
3.4 Security reports
If you report a vulnerability to us (see our Security page), we use your contact details and report to investigate the issue, keep you informed and, if you wish, credit you. The legal basis is our legitimate interest in keeping our systems secure (GDPR Art. 6(1)(f)). We keep the report for as long as needed to resolve the issue and document it, and no longer than two years.
04Cookies and third parties
This website does not set cookies and does not use analytics, advertising or social media tracking. Fonts and scripts are served from our own server, so visiting the site does not send your data to third parties such as Google.
If we ever introduce analytics, we will only switch it on with your prior consent, which you will be able to give or refuse — and later withdraw — on the site, and we will update this policy before we do.
The website links to other sites (for example our clients' products). Those sites have their own privacy policies; we are not responsible for how they handle your data.
05Who receives your data
We use two service providers for this website. They process personal data only on our instructions, under data processing agreements as required by GDPR Art. 28:
- Hostinger International Ltd. (Cyprus) — hosts the website and keeps its server logs.
- Microsoft Ireland Operations Limited (Ireland) — provides our email (Microsoft 365), where contact form messages and emails arrive.
Within First One, only the people who need to answer or act on your message can see it. We do not sell, rent or trade personal data. We disclose personal data to authorities or courts only where the law requires us to.
06Transfers outside the EEA
We aim to keep personal data in the European Economic Area. The website is hosted in the European Union, and Microsoft stores Microsoft 365 data for European customers within the EU Data Boundary. If one of our providers transfers personal data outside the EEA — for example to the United States for support or security purposes — it does so under an adequacy decision of the European Commission (such as the EU–US Data Privacy Framework) or under the Commission's standard contractual clauses.
07How long we keep data
- Server logs: only as long as needed for security and troubleshooting, then deleted automatically.
- Enquiries that do not lead to a contract: no later than one year after our last exchange.
- Correspondence that leads to a contract: for the life of the contract and as long as the law requires afterwards — for example, documents that support our accounts are kept for eight years under Hungarian Act C of 2000 on Accounting.
- Contact form abuse protection: ten minutes.
- Security reports: no longer than two years.
We may keep data longer only where we need it to establish, exercise or defend legal claims, and only for as long as that need lasts.
08How we protect your data
The website is served only over encrypted connections and sits behind a web application firewall; access to our mailboxes and systems is restricted to the people who need it. You can read more about the technical and organisational measures we use on our Security page. No method of transmission or storage is completely secure, but if a personal data breach affecting you were likely to put your rights at high risk, we would tell you without undue delay.
09Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy of it (Art. 15);
- have inaccurate data corrected (Art. 16);
- have your data erased (Art. 17);
- restrict how we use your data (Art. 18);
- receive your data in a portable format, where processing is based on a contract (data portability, Art. 20);
- object to processing based on our legitimate interests (Art. 21) — we will then stop, unless we have compelling legitimate grounds or need the data for legal claims.
To use any of these rights, email info@1one.hu. It is free of charge. We answer within one month; for complex requests we may extend this by up to two further months, in which case we tell you why within the first month. We may ask for information to confirm your identity before acting on a request.
10Complaints
If you are unhappy with how we handle your data, please contact us first — we would like the chance to put it right. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU country where you live or work. In Hungary this is:
Nemzeti Adatvédelmi és Információszabadság Hatóság (Hungarian National Authority for Data Protection and Freedom of Information, NAIH)
1055 Budapest, Falk Miksa utca 9–11 · postal address: 1363 Budapest, Pf. 9.
Phone: +36 1 391 1400 · Email: ugyfelszolgalat@naih.hu · Web: naih.hu
You may also take legal action in court. In Hungary the regional courts (törvényszék) have jurisdiction, and you can choose to bring the case before the court of the place where you live.
11Other information
- We do not make decisions about you based solely on automated processing, including profiling.
- This website is intended for businesses and is not directed at children under 16.
- Providing personal data to us is voluntary. Without your name, email address and message, however, we cannot answer your enquiry.
12Changes to this policy
We update this policy when the way we process personal data changes, for example if we add a new service provider. The current version is always published on this page, with the date of the last update at the top.