Skip to content
miniakadémia

Privacy Policy

Last updated: 3 June 2026

1. Data controller

miniakadémia – Jordán Lili Judit EV
Registered address: Szabadság utca 114., 2085 Pilisvörösvár, Hungary
Tax number: 90532003-1-33
E-mail: miniakademia2024@gmail.com
Phone: +36 30 373 2852
This notice has been prepared in accordance with EU Regulation 2016/679 (GDPR) and the Hungarian Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (Infotv.).
The data controller is not required to appoint a Data Protection Officer (DPO) under GDPR Art. 37. For data protection enquiries, please contact the data controller at miniakademia2024@gmail.com.

2. Booking-related data processing

Data processed:
  • Parent / guardian name, e-mail address, phone number
  • Child's name and date of birth
  • Allergies and other health-related notes (special category data under GDPR Art. 9; provision is voluntary)
  • Consent logs: consent text, timestamp, IP address and browser identifier (to evidence consent and for legal compliance)
Purpose:processing bookings, sending confirmations, customer service communication relating to the booking, ensuring the child's safety (allergy / health information), and fulfilling legal and tax obligations.
Legal basis:
  • GDPR Art. 6(1)(b) – processing necessary for the performance of the contract (booking): guardian and child identity data, contact details
  • GDPR Art. 6(1)(a) – consent of the data subject (for a child: consent of the parent / legal guardian)
  • GDPR Art. 9(2)(a) – explicit consent for processing special category data (allergy and health information)
  • GDPR Art. 6(1)(c) – compliance with a legal obligation (accounting retention)
  • GDPR Art. 6(1)(f) – legitimate interest of the data controller in evidencing consent (accountability)
Necessity of providing data:Guardian and child identity data must be provided to complete a booking; the booking cannot be fulfilled without them. Health / allergy information is voluntary and is collected solely in the interest of the child's safety; failure to provide it does not prevent booking but may limit the data controller's ability to accommodate the child's health needs.
Retention periods:
  • Accounting documents (e.g. invoices, payment requests): 8 years from the date of issue (Hungarian Accounting Act, Act C of 2000, § 169).
  • Other booking and communication data not forming part of accounting records: until the purpose of the booking is fulfilled, then until the expiry of the general civil law limitation period (5 years, Civil Code § 6:22), after which the data is deleted.
  • Data processed solely on the basis of consent (e.g. health information): until consent is withdrawn, subject to the retention periods above.
Automated decision-making: The data controller does not use automated decision-making or profiling in connection with bookings.

3. Photo and media consent

Photos and videos may be taken of children participating in workshops and camps for documentation purposes and for publication on miniakadémia's social media channels.
Legal basis: GDPR Art. 6(1)(a) – voluntary, explicit written consent of the parent or legal guardian, given via a separate checkbox during booking.
Withdrawal of consent: consent may be withdrawn at any time by e-mail to miniakademia2024@gmail.com. Withdrawal does not affect the lawfulness of processing prior to withdrawal. Published images will be removed within a reasonable time following the request.

4. Newsletter

miniakadémia sends newsletters to subscribers about upcoming programmes, offers and news.
Data processed: e-mail address, name (optional).
Legal basis: GDPR Art. 6(1)(a) – voluntary consent.
Unsubscribing: every newsletter contains an unsubscribe link; you may also contact us directly to unsubscribe.
Retention: data is processed until consent is withdrawn, after which it is deleted.

5. Technical and security data processing

In the course of operating and protecting the website, the data controller and its processors automatically process certain technical data:
  • Server access logs: IP address, time of access, browser and device data — for the purpose of ensuring the proper operation of the website.
  • Abuse prevention and rate limiting: IP address — to protect the website and booking system and prevent abuse (e.g. automated attacks).
  • Traffic statistics (Vercel Analytics): Vercel Analytics produces anonymised, cookie-less visit statistics (e.g. pages viewed, approximate geographic location); it does not identify or track individual users.
Legal basis: GDPR Art. 6(1)(f) – legitimate interest of the data controller in operating the website securely and without interruption. A legitimate interests assessment has been carried out and is available on request.
Retention: technical log data is retained by the data controller and its processors for the time necessary to achieve the security purpose, after which it is deleted or anonymised.

6. Cookies

The website uses strictly necessary (session) cookies required to maintain user sessions and provide core website functionality. These are processed on the basis of the legitimate interest in operating the website (GDPR Art. 6(1)(f)) and do not require prior consent.
If the website uses cookies that are not strictly necessary (e.g. analytical, statistical or marketing cookies), these will only be placed with the user's prior, explicit consent (GDPR Art. 6(1)(a), and the relevant provisions of the Hungarian Act CVIII of 2001 on electronic commerce). Consent may be withdrawn at any time, and cookies can be deleted or disabled via browser settings.

7. Processors and data transfers

The data controller uses the processors listed below. A valid Data Processing Agreement (DPA) is in place with each processor. Transfers outside the EU/EEA are based on the EU Standard Contractual Clauses (SCC, Decision 2021/914/EU), except where an EU adequacy decision applies. Copies of the SCC documents may be obtained from the data controller at the contact address above.
  • Vercel Inc. – hosting and runtime infrastructure; processes personal data incidentally (e.g. IP addresses in access logs).
    Address: 340 Pine St Suite 401, San Francisco, CA 94104, USA.
    Privacy: vercel.com/legal/privacy-policy · DPA: vercel.com/legal/dpa. Transfer basis: SCC.
  • Neon, Inc. – SQL database service; stores all booking, customer and consent-log data.
    Address: 2261 Market Street #5765, San Francisco, CA 94114, USA.
    Privacy: neon.tech/privacy-policy · DPA: neon.tech/dpa. Transfer basis: SCC.
  • Upstash, Inc. – Redis-based rate limiting and security protection; processes IP addresses to prevent abuse.
    Address: 2261 Market Street #4673, San Francisco, CA 94114, USA.
    Privacy: upstash.com/trust/privacy.pdf. Transfer basis: SCC.
  • Resend Inc. – transactional and newsletter e-mail delivery (booking confirmations, reminders, newsletters); accesses recipient name and e-mail address.
    Address: 2261 Market Street Suite 5765, San Francisco, CA 94114, USA.
    Privacy: resend.com/legal/privacy-policy · DPA: resend.com/legal/dpa. Transfer basis: SCC.
  • Cloudinary Ltd. – cloud image storage and delivery; stores website images including photos taken at sessions (including child photos processed under consent).
    Registered address: 3 Jonathan Street, Petah Tikva 4951046, Israel (covered by EU adequacy decision 2011/61/EU). Subsidiary: Cloudinary, Inc., 111 Pine Street Suite 1500, San Francisco, CA 94111, USA.
    Privacy: cloudinary.com/privacy · DPA: cloudinary.com/legal/dpa. Transfer basis: EU adequacy decision (Israeli entity) / SCC (US entity).
  • GitHub, Inc.(Microsoft subsidiary) – source code hosting and software development infrastructure. GitHub stores the website's source code; it does not ordinarily access end-user personal data.
    Address: 88 Colin P Kelly Jr St, San Francisco, CA 94107, USA.
    Privacy: GitHub Privacy Statement. Transfer basis: SCC.
Personal data is not transferred to third parties outside the above processors unless required by law.

8. Your rights

You have the following rights under GDPR:
  • Right of access (Art. 15) – request information about data we hold about you.
  • Right to rectification (Art. 16) – request correction of inaccurate data.
  • Right to erasure (Art. 17) – request deletion of your data where processing is no longer necessary or consent is withdrawn.
  • Right to restriction (Art. 18).
  • Right to data portability (Art. 20).
  • Right to object (Art. 21) – to processing based on legitimate interests.
  • Right to withdraw consent (Art. 7(3)) – at any time and free of charge where processing is based on consent; withdrawal does not affect the lawfulness of processing prior to withdrawal.
To exercise your rights, please contact: miniakademia2024@gmail.com. The data controller will respond within one month of receiving the request. This period may be extended by a further two months where necessary, taking into account the complexity and number of requests; the data controller will inform you of any extension within one month of receiving the request (GDPR Art. 12(3)).

9. Supervisory authority – NAIH

If you believe that your data has been processed in violation of GDPR, you may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):
The right to lodge a complaint does not affect other administrative or judicial remedies. You may also bring proceedings before a court; in Hungary, proceedings may be brought before the court of the county in which you are domiciled or habitually resident.

10. Data security

The data controller implements appropriate technical and organisational measures to protect personal data: the website is accessible via HTTPS, and the database is encrypted and access-controlled.
In the event of a personal data breach, the data controller will notify the supervisory authority without undue delay in accordance with GDPR Art. 33, and — where the breach is likely to result in a high risk to the rights and freedoms of individuals — will also notify the affected individuals (GDPR Art. 34).

11. Protection of children's data

A significant portion of the data processed through this website relates to children. Children's personal data enjoys enhanced protection under GDPR recital 38. All consents required for the processing of children's data — including health data and the use of photographs — must be given and may be withdrawn exclusively by the child's parent or legal guardian.