Skip to content
Ziryvo
HU DE EN
Book a consultation
← Back to the site

Effective: 15 September 2026

PRIVACY

Privacy Notice

This translation is provided for information. Only the Hungarian version is legally binding: Adatkezelési Tájékoztató. Questions: bence@ziryvo.com

Contents

  1. 01Introduction
  2. 02The controller
  3. 03Definitions
  4. 04Two separate roles
  5. 05Processing as controller
  6. 06Processing on behalf of clients
  7. 07Processors and recipients
  8. 08Transfers outside the EEA
  9. 09Security
  10. 10Cookies and browser storage
  11. 11Automated decisions and AI
  12. 12Your rights
  13. 13Remedies
  14. 14Changes to this notice
  15. 15Applicable law
01

INTRODUCTION

Bence Borbás, sole trader (the Controller or Provider), takes the protection of personal data seriously. This notice sets out what personal data the Controller processes, for what purpose and on what legal basis, how long it is kept, and what rights data subjects have.

It is based on Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and on Hungarian Act CXII of 2011 on informational self-determination and freedom of information.

02

THE CONTROLLER

NameBence Borbás, sole trader
Registered seatAlsóerdősor utca 35., 2045 Törökbálint, Hungary
Tax number90924152-1-33
Registering authorityMinistry of the Interior of Hungary — Register of Sole Traders
Emailbence@ziryvo.com
Phone+36 70 595 2613
Websitehttps://ziryvo.com

The Controller is not required to appoint a data protection officer and has not appointed one. For data protection matters, write to bence@ziryvo.com.

03

DEFINITIONS

Personal data: any information relating to an identified or identifiable natural person.

Data subject: the natural person whose personal data is processed.

Controller: the party that determines the purposes and means of processing.

Processor: the party that processes personal data on behalf of, and on the instructions of, the controller.

Special category data: data requiring heightened protection under Article 9 GDPR, including health data.

04

TWO SEPARATE ROLES

The Controller processes personal data in two clearly separated roles.

4.1. As a controller in relation to its own clients, enquirers and website visitors. Section 5 applies to these activities.

4.2. As a processor when it operates a phone assistant on behalf of its clients — healthcare providers, practices or businesses. In respect of callers' personal data the client is the controller, and the Provider acts solely on the client's written instructions. Section 6 applies to these activities.

05

PROCESSING AS CONTROLLER

5.1. Enquiries and requests for a quote

Data processed: name, email address, phone number, company name, content of the message.

Purpose: answering the enquiry, preparing a quote, keeping in contact.

Legal basis: steps taken at the data subject's request prior to entering into a contract — Article 6(1)(b) GDPR; and the Controller's legitimate interest in business contact — Article 6(1)(f) GDPR.

Retention: where a contract is concluded, as under 5.3; otherwise 1 year from the last contact.

5.2. Using the demonstration

Enquirers may speak with a phone assistant for demonstration purposes, by telephone or through the website.

Data processed: the audio recording of the conversation, its transcript, details volunteered during the call (name, phone number), the time and duration of the call.

Purpose: running the demonstration, showing how the system works, improving the quality of the service.

Legal basis: consent — Article 6(1)(a) GDPR. Consent may be given by continuing the conversation after the notice provided before it begins.

Retention: the recording and the transcript are deleted within 30 days of the demonstration.

Please do not state real health data, identity document numbers or other sensitive information during the demonstration. Consent may be withdrawn at any time, without giving reasons, at bence@ziryvo.com.

The voice assistant on the website. The website carries a button labelled "Talk to the assistant", next to which a short notice appears before anything loads. Until that button is pressed the browser makes no connection whatsoever to the provider of the voice assistant: the code of the conversation interface is loaded only afterwards. The conversation — and therefore any transmission of voice data — begins only after that, once microphone access has been granted separately in the browser. Microphone access can be withdrawn at any time in the browser settings, and the conversation can be ended at any time.

The voice assistant runs on the platform of ElevenLabs, Inc. (United States), which processes the audio and the transcript as a processor for the purpose of providing the service. The safeguards in Section 8 apply to that transfer.

After the button is pressed, the conversation interface loads further external resources: its code from unpkg, an audio processing module from the jsDelivr content delivery network, a typeface from Google Fonts and image assets from Google Cloud storage. In the course of these requests the data subject's IP address and technical browser details may reach those providers. The interface code may also derive a device identifier from certain technical characteristics of the browser. None of this happens before the button is pressed.

5.3. Contracted clients' data

Data processed: name, registered seat, tax number, company registration number, name, position, email address and phone number of the contact person, bank account number, contract details.

Legal basis: performance of a contract — Article 6(1)(b) GDPR; for contact persons' data, legitimate interest — Article 6(1)(f) GDPR.

Retention: 5 years from termination of the contract.

5.4. Invoicing and accounting obligations

Legal basis: compliance with a legal obligation — Article 6(1)(c) GDPR, under Section 169 of Hungarian Act C of 2000 on accounting.

Retention: 8 years from the issue of the accounting document. Deletion cannot be requested before that period expires.

5.5. Complaint handling

Legal basis: compliance with a legal obligation — Article 6(1)(c) GDPR, under Section 17/A of Hungarian Act CLV of 1997 on consumer protection.

Retention: 5 years from the recording of the complaint.

5.6. Operating the website and measuring its use

Server log. For secure operation the hosting provider keeps an automatic log containing the time of the request, the address requested, the browser and device type and the visitor's IP address. The Controller accesses it to diagnose faults and prevent abuse.

Own measurement. To improve the website the Controller uses its own measurement, running on the website itself. It uses no cookies, sets no identifier on the visitor's device and does not record IP addresses. It stores only the following, as individual unlinked events: the name of the event (for example a page view or a form submission), the address of the page viewed, the chosen language, the device category (phone, tablet, desktop), the domain name of the referring website, and the time of the event to the minute. No natural person can be identified from this, and the entries are not combined.

The measurement data stays on the Controller's own hosting, is not shared with any third party and is not used for profiling.

Legal basis: the Controller's legitimate interest in operating and improving the website securely — Article 6(1)(f) GDPR.

Retention: the server log according to the hosting provider's practice; the Controller's own measurement data for 12 months from the event.

5.7. Marketing communication

Newsletters and marketing messages are sent only on the basis of prior, explicit consent. Legal basis: consent — Article 6(1)(a) GDPR. Consent may be withdrawn at any time, free of charge.

06

PROCESSING ON BEHALF OF CLIENTS

6.1. When the Provider operates a phone assistant on a client's behalf, it acts as a processor in respect of callers' personal data. The purposes and means are determined by the client.

6.2. The data processed in this capacity is typically: the caller's name and phone number, the reason for the call, the audio recording and transcript of the conversation, and the time and duration of the call.

6.3. A caller may also disclose information about their health, which is special category data under Article 9 GDPR. The Provider configures the system so that collection of such data is kept to the minimum necessary and no questions about medical details are asked.

6.4. Before the service begins, the Provider and the client enter into a written data processing agreement compliant with Article 28 GDPR.

6.5. In this capacity the Provider processes data solely on the client's written instructions, binds those with access to confidentiality, applies appropriate technical and organisational measures, assists the client in responding to data subject requests, notifies the client of any personal data breach without delay and within 24 hours at the latest, and on termination deletes or returns the data at the client's choice.

6.6. Data subjects (callers) should address their requests primarily to the organisation they called. Requests received by the Provider are forwarded to the client concerned without delay.

6.7. Informing callers — including about call recording and the use of an automated system — is the responsibility of the client as controller.

07

PROCESSORS AND RECIPIENTS

To provide the service the Controller uses processors in the following categories:

Hosting provideroperating the website
Speech and artificial intelligence platformoperating the assistant, speech recognition, speech synthesis, language processing
Telecommunications providercarrying the phone calls
Email and office providercorrespondence, document handling
Automation and notification servicepassing recorded data to the client
Accountantbookkeeping services

On request, the Controller provides the name, seat and activity of the processors used in writing at bence@ziryvo.com. Contracted clients are notified in advance of changes to the set of processors.

Beyond this, the Controller transfers personal data only with the data subject's consent or on the basis of a legal obligation or a request from an authority or court.

08

TRANSFERS OUTSIDE THE EEA

8.1. Some of the technology providers used have their seat or processing infrastructure outside the European Economic Area, typically in the United States.

8.2. The Controller relies for such transfers on an adequacy decision of the European Commission — including the EU–US Data Privacy Framework — on the Standard Contractual Clauses adopted by the Commission, or on another appropriate safeguard under Chapter V GDPR.

8.3. Where a provider offers it, the Controller selects a European processing region. Information about the safeguards applied is available at bence@ziryvo.com.

09

SECURITY

9.1. The Controller applies appropriate technical and organisational measures, taking into account the state of the art, the cost of implementation and the nature and risks of the processing.

9.2. These include in particular:

  • encrypted transmission (HTTPS/TLS) on the website and between systems;
  • strong, unique passwords and — where available — two-factor authentication on every service account;
  • access limited on a need-to-know basis;
  • regular backups;
  • the strictest available retention settings on provider platforms, including minimising how long audio recordings are kept;
  • encryption and password protection of the devices used for work.

9.3. In the event of a personal data breach the Controller notifies the supervisory authority without undue delay and within 72 hours at the latest, unless the breach is unlikely to result in a risk. Where the breach is likely to result in a high risk to data subjects' rights, the Controller also informs them.

10

COOKIES AND BROWSER STORAGE

10.1. The website uses no cookies: it sets neither first-party nor third-party cookies on the visitor's device, and it carries no advertising or social media tracking code.

10.2. The website stores two technical values in the browser's own storage. They are necessary for the website to work, contain no personal data and never leave the site:

Language choiceremembers the language selected so it need not be chosen again on the next visit — stays in the browser's storage and can be cleared at any time
Intro animationrecords that the opening animation has played, so it does not repeat within a visit — cleared when the tab is closed

10.3. The measurement works as described in 5.6: no cookie, no identifier, no IP address recorded. As it neither stores nor reads information on the visitor's device, no prior consent is required; the legal basis is the Controller's legitimate interest, which may be objected to under Section 12.

10.4. The voice assistant loads only after the relevant button is pressed. From that point ElevenLabs, Inc. and the content delivery networks it uses may process their own technical data, including data stored in the browser; Section 5.2 gives the detail. Without pressing the button no such processing takes place.

11

AUTOMATED DECISIONS AND AI

11.1. The Controller does not carry out decision-making based solely on automated processing — including profiling — which produces legal effects concerning data subjects or similarly significantly affects them.

11.2. The phone assistant is an AI-based system that processes what is said and produces structured data from it. This is not automated decision-making under Article 22 GDPR, as it makes no substantive decision: its task is to record information and pass it on for human handling.

11.3. The systems are set up so that the person speaking is informed that they are talking to an automated system, in line with the transparency requirements of the EU regulation on artificial intelligence.

11.4. Conversation content is not used to train artificial intelligence models, and where providers allow it to be configured, use for model training is switched off.

12

YOUR RIGHTS

12.1. Access. You may ask whether the Controller processes your personal data and, if so, request a copy of it.

12.2. Rectification. You may ask for inaccurate data to be corrected and incomplete data to be completed.

12.3. Erasure. You may ask for your data to be erased, in particular where it is no longer necessary for its purpose or where you have withdrawn consent. Erasure cannot be requested where processing is required by law — for example the eight-year accounting retention.

12.4. Restriction. You may ask for processing to be restricted, for instance while the accuracy of the data is contested.

12.5. Portability. Data processed by automated means on the basis of consent or a contract may be requested in a structured, commonly used, machine-readable format.

12.6. Objection. You may object to processing based on legitimate interest. In the case of direct marketing the objection is unconditional.

12.7. Withdrawal of consent. Where processing is based on consent, it may be withdrawn at any time, free of charge. Withdrawal does not affect the lawfulness of processing before it.

12.8. Requests may be submitted to bence@ziryvo.com or by post to Alsóerdősor utca 35., 2045 Törökbálint, Hungary. The Controller responds without undue delay and within one month at the latest. That period may be extended by two further months given the complexity of a request, of which the Controller gives notice within one month. The response is free of charge.

13

REMEDIES

13.1. Complaint to the Controller. Please raise any complaint first with the Controller at bence@ziryvo.com.

13.2. Supervisory authority. You have the right to lodge a complaint with the supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Falk Miksa utca 9–11., 1055 Budapest, Hungary
Postal address: 1363 Budapest, Pf. 9.
Phone: +36 (1) 391-1400
Email: ugyfelszolgalat@naih.hu
Website: https://naih.hu

Data subjects resident in another Member State may also contact the supervisory authority competent there.

13.3. Judicial remedy. If your rights are infringed you may bring court proceedings. At your choice, proceedings may also be brought before the court of your place of residence or stay.

13.4. Compensation. Anyone who suffers damage as a result of unlawful processing is entitled to compensation, and to damages for an infringement of personality rights.

14

CHANGES TO THIS NOTICE

14.1. The Controller reserves the right to amend this notice unilaterally, in particular where the law, regulatory guidance or the service changes.

14.2. The amended notice takes effect on publication on the website. Contracted clients are also notified of material changes by email.

15

APPLICABLE LAW

  • Regulation (EU) 2016/679 (GDPR)
  • Hungarian Act CXII of 2011 on informational self-determination and freedom of information
  • Hungarian Act CVIII of 2001 on electronic commerce services
  • Hungarian Act C of 2000 on accounting
  • Hungarian Act CXXVII of 2007 on value added tax
  • Hungarian Act XLVIII of 2008 on the basic conditions of commercial advertising
  • Hungarian Act CLV of 1997 on consumer protection
  • Hungarian Act V of 2013, the Civil Code

Bence Borbás, sole trader
Alsóerdősor utca 35., 2045 Törökbálint, Hungary

This Privacy Notice takes effect on 15 September 2026.

Ziryvo

AI phone assistants and websites for businesses that don’t want to be missed.

Site

  • Phone assistants
  • Websites
  • Capabilities

Contact

  • bence@ziryvo.com
  • Book a consultation

To be heard. To be seen.

Book a consultation
© 2026 ZIRYVO. All rights reserved.
Privacy Notice Terms Imprint