Privacy Policy

Last updated: 6 August 2026

1. Data controller

The controller responsible for personal data processed through this website is:

THERMODUL System Hungary Kft.
Registered office: 2724 Újlengyel, Petőfi Sándor utca 41, Hungary
Company registration number: 13-09-238605
Tax number: 27037344-2-13
Legal representative: Mathe Laszlo
Email: info@thermodul.com
Telephone: +36 30 660 2020
Website: https://thermodul.com

2. Scope of this policy

This policy explains how personal data is processed when you visit thermodul.com, use the site search, or contact THERMODUL System Hungary Kft. by email, telephone or WhatsApp. The website is informational and does not provide online ordering, online payment, user registration or newsletter subscription. There is currently no contact form.

3. Data processed when you visit the website

When you visit the website, the hosting server may automatically receive technical data such as your IP address, date and time of access, requested page or file, referrer URL, browser type and version, operating system, device information, access provider and technical status information.

Purpose: delivering the website, maintaining availability and security, preventing misuse, diagnosing technical faults and keeping necessary server records.

Legal basis: Article 6(1)(f) GDPR – our legitimate interest in operating a secure, reliable and functional company website.

Retention: technical logs are retained only for the operational period set by the hosting environment and for as long as reasonably necessary for security, fault analysis or the establishment, exercise or defence of legal claims. They may be retained longer where a security incident or legal obligation requires it.

4. Site search and language selection

If you use the website search, the search term is transmitted to our server in order to display matching content. The site may store a technically necessary language preference so that pages are shown in the selected language.

Legal basis: Article 6(1)(f) GDPR – our legitimate interest in providing navigation, search and multilingual functionality requested by visitors.

5. Contact by email, telephone or WhatsApp

When you contact us, we process the information you choose to provide. This may include your name, company, email address, telephone number, the content of your enquiry, project information, quotation requirements and subsequent correspondence.

Purposes: responding to enquiries, preparing and discussing quotations, taking steps before entering into a contract, maintaining business communication and documenting relevant correspondence.

Legal bases: Article 6(1)(b) GDPR where processing is necessary to take steps at your request before entering into a contract or to perform a contract; Article 6(1)(f) GDPR for general business communication and follow-up; and Article 6(1)(c) GDPR where records must be retained to meet a legal obligation.

Ordinary enquiries that do not lead to a contract are normally deleted or anonymised within 12 months after the last substantive communication, unless a longer period is justified by ongoing discussions, a legal obligation or the establishment, exercise or defence of legal claims. Contractual, accounting and tax-related records are retained for the periods required by applicable law.

The WhatsApp button opens a service provided by Meta. If you choose WhatsApp, Meta processes your account and communication data under its own terms and privacy policy. You may contact us by email or telephone instead.

6. Cookies and similar technologies

The website may use cookies or local storage that are strictly necessary for WordPress administration, security, session handling and language preferences. These technologies are not used by us to build advertising profiles.

At the date of this policy, our technical review did not identify Google Analytics, Google Tag Manager, Google Ads, Meta Pixel, Microsoft Clarity, Hotjar or a newsletter tracking system on the public website. If optional analytics, advertising or marketing technologies are introduced later, this policy and the cookie information will be updated and any legally required consent mechanism will be implemented before those technologies are activated.

7. Hosting, fonts and technical service providers

The website is hosted using Hostinger infrastructure. The hosting provider may process server and security logs as a processor or technical service provider in order to operate and protect the website. Email and website administration providers may also process limited data where necessary to provide their services.

The website loads Google Fonts from Google servers. When a font is requested, Google may receive technical information such as the visitor’s IP address, browser information and the requested resource. This processing is subject to Google’s own privacy information. The legal basis for our use of website typography and consistent presentation is Article 6(1)(f) GDPR. We periodically review whether external resources can be reduced or hosted locally.

8. External links and third-party services

The website contains links to external services, including YouTube, Facebook, WhatsApp and Gmail. These are links and not embedded social feeds, videos or maps. The relevant provider normally receives data only after you click the link and leave our website. From that point, the provider acts under its own privacy policy and may collect technical, account or usage information.

We are not responsible for the content or independent data-processing practices of third-party websites. You can avoid such processing by not opening the external link.

9. Recipients and disclosure

Personal data may be accessible, only where necessary, to authorised company representatives and persons responsible for responding to enquiries, website administration or email administration. Data may also be processed by hosting, email, IT-security and maintenance providers acting under appropriate contractual or legal obligations.

We do not sell personal data. Data is disclosed to public authorities, courts, professional advisers or other recipients only where required by law, necessary to protect legal rights, or otherwise permitted under the GDPR.

10. International data transfers

Some third-party providers, particularly Google and Meta services, may process data outside the European Economic Area. Such transfers must be based on a valid mechanism under Chapter V GDPR, such as an adequacy decision, the EU-US Data Privacy Framework where applicable, standard contractual clauses or another legally recognised safeguard. Opening an external service may result in a transfer governed by that provider’s privacy policy.

11. Your rights

Subject to the conditions of the GDPR, you may request:

  • access to your personal data and a copy of it (Article 15);
  • correction of inaccurate or incomplete data (Article 16);
  • erasure of personal data (Article 17);
  • restriction of processing (Article 18);
  • data portability where applicable (Article 20);
  • objection to processing based on legitimate interests (Article 21); and
  • withdrawal of consent at any time where processing is based on consent, without affecting earlier lawful processing.

To exercise your rights, email info@thermodul.com. We may request information necessary to verify your identity. We will respond within the period required by the GDPR.

12. Right to complain

You may lodge a complaint with the supervisory authority, in particular in the Member State of your residence, workplace or the alleged infringement. In Hungary:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9-11, Hungary
Postal address: 1363 Budapest, Pf. 9, Hungary
Email: ugyfelszolgalat@naih.hu
Website: https://www.naih.hu/

13. Whether providing data is mandatory

You are not required to provide personal data merely to browse the public website. Contact information is provided voluntarily. If you do not provide enough information to identify and answer your request, prepare a quotation or take requested pre-contractual steps, we may be unable to assist you.

14. Automated decision-making and children

We do not use website data for solely automated decision-making, including profiling, that produces legal or similarly significant effects. The website is intended for business and general informational use and is not directed at children.

15. Data security

We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures include HTTPS encryption, access controls, software maintenance and hosting security. No method of transmission or storage can guarantee absolute security.

16. Changes to this policy

We may update this policy when the website, services, providers or legal requirements change. The current version and update date will always be published on this page.