Privacy policy
Effective from 3 October 2026
Mermida Kft. takes the personal data of the visitors of its website seriously. In line with Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation, GDPR) and the Hungarian Act CXII of 2011 on the right of informational self-determination and on freedom of information, this policy explains what data we process when you use mermida.com, for what purpose, on what legal basis and for how long, and what rights you have.
1. Controller
- Name: Mermida Kft.
- Registered office: Szkíta krt. 12., 2100 Gödöllő, Hungary
- Company registration number: 13-09-244775
- Tax number: 32001718-1-13
- Represented by: Gábor Takács, Managing Director
- E-mail: info@mermida.com
We are not required to appoint a data protection officer. For any data protection question, contact us at the e-mail address above or by post at our registered office.
2. What data do we process?
2.1. Contact form
- Data: name, e-mail address, company name (optional), subject of the enquiry, message, language of the page and time of submission.
- Purpose: answering your enquiry, keeping in touch and, if you ask for it, preparing a quote.
- Legal basis: your consent (Article 6(1)(a) GDPR), given by ticking the checkbox before sending the form. You can withdraw your consent at any time by writing to info@mermida.com; this does not affect the lawfulness of processing before the withdrawal.
- Retention: we keep the message for 2 years from submission, after which our system deletes it automatically. If you withdraw your consent earlier, we delete it without delay. If the enquiry leads to a contract, we keep the data required for it for the period prescribed by law (for example, accounting rules).
- E-mails: we receive a notification of the submission at info@mermida.com, and you receive an automatic confirmation at the address you provided. Our e-mail runs on our own server.
2.2. Abuse prevention (spam protection)
- Data: a pseudonymised, keyed fingerprint (hash) of your IP address, stored with the message – the IP address itself is not stored with the message – and the number of submissions per IP address, kept temporarily for up to one hour.
- Purpose: filtering out automated spam and abuse (at most 5 submissions per IP address per hour).
- Legal basis: our legitimate interest (Article 6(1)(f) GDPR) in protecting the website and our mailbox. We will provide our balancing test on request.
- Retention: the fingerprint is deleted together with the message, the submission counter after one hour.
- If we also enable Cloudflare Turnstile for spam protection, your browser connects to Cloudflare's servers when the form loads, and Cloudflare processes technical data (such as your IP address and browser data) to determine whether the sender is human. The legal basis for this is also our legitimate interest.
2.3. Server logs
- Data: IP address, time of the visit, address of the page opened, browser type, referring page and server response code.
- Purpose: secure and uninterrupted operation of the website, detecting errors and attacks.
- Legal basis: our legitimate interest (Article 6(1)(f) GDPR).
- Retention: up to 30 days, after which the logs are deleted automatically.
2.4. Cookies and local storage
We only use cookies that are strictly necessary for the website to work; under section 155(4) of the Hungarian Act C of 2003 on electronic communications these do not require consent. We do not use analytics, marketing or tracking cookies, and we do not embed external social media, video or advertising services. Our fonts are served from our own server, so no data reaches third parties when they load.
- mermida-session – session identifier needed for the contact form; expires after 2 hours.
- XSRF-TOKEN – protects the form against forged submissions; expires after 2 hours.
- theme – your choice of light or dark appearance. Not a cookie: it stays in your browser's local storage, never reaches us, and you can delete it at any time.
3. Who has access to the data?
Only authorised staff of Mermida Kft. can access the data. We do not sell your data or share it with anyone for marketing purposes. Our processors:
- netcup GmbH (Daimlerstraße 25, 76185 Karlsruhe, Germany) – server and hosting services: running the website, the database and our e-mail. The data is stored in the European Union, in Germany.
- Cloudflare, Inc. (101 Townsend St., San Francisco, CA 94107, USA) – only if Turnstile spam protection is enabled. Cloudflare is certified under the EU–US Data Privacy Framework, so the transfer is based on the European Commission's adequacy decision.
We may disclose data to authorities or courts where the law requires it.
4. Data security
We receive data over an encrypted (HTTPS) connection and store it on a server in the European Union, and only authorised persons can access it, to the extent their tasks require. The administration area is protected by two-factor authentication, the system is updated regularly and the data is backed up.
5. Your rights
- Information and access (Article 15 GDPR): you can ask whether we process data about you and, if so, request a copy.
- Rectification (Article 16): you can ask us to correct inaccurate data.
- Erasure (Article 17): you can ask us to delete your data.
- Restriction of processing (Article 18): you can ask us to only store your data temporarily, without using it.
- Data portability (Article 20): you can request the data processed on the basis of your consent in a structured, machine-readable format.
- Objection (Article 21): you can object to processing based on legitimate interest.
- Withdrawal of consent (Article 7(3)): at any time, without affecting the lawfulness of processing before the withdrawal.
You can send your request to info@mermida.com or by post to our registered office. We will respond without undue delay and within one month at the latest; where justified, this period may be extended by two further months, in which case we will inform you. Handling your request is free of charge.
6. Remedies
If you believe we have infringed your data protection rights, please contact us first so that we can resolve the issue as quickly as possible. You can also lodge a complaint with the Hungarian supervisory authority:
- Nemzeti Adatvédelmi és Információszabadság Hatóság (Hungarian National Authority for Data Protection and Freedom of Information, NAIH)
- Address: Falk Miksa utca 9–11., 1055 Budapest, Hungary
- Postal address: 1363 Budapest, Pf. 9.
- Phone: +36 1 391 1400
- E-mail: ugyfelszolgalat@naih.hu
- Website: naih.hu
You may also take legal action in court; at your choice, you can bring proceedings before the regional court of your place of residence or stay. If you live in another EU member state, you can also contact the supervisory authority of that state.
7. Changes to this policy
If our data processing changes, we will update this policy. The version in force is always available on this page, together with its effective date.