Last updated: June 08, 2026
This privacy notice provides information, in accordance with Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR), to data subjects whose personal data is processed by the data controller in the course of providing its services.
The primary purpose of data processing on the https://peakship.net website is to present the services provided by PeakShip, maintain contact with interested parties, ensure the communication necessary for using the services, handle user inquiries, and develop the services and improve the user experience.
You can access the data processing notice for the PeakShip app at https://peakship-36hx3.ondigitalocean.app/privacy_policy.html.
| Name and contact information of the data controller | Controller name: Peak Tech Korlátolt Felelősségű Társaság Headquarters: Hungary, (zip:) 1196, (city:) Budapest, (street:) Hunyadi utca 140. Fsz. 2. ajtó Tax number: 32863576-2-43 Company registration number:01-09-446645 Representative: Gulyás Bendegúz Address: 1106 Budapest, Gyakorló utca 6. 9. em. 38. ajtó E-mail: [email protected] |
| Hosting provider: | |
| Netlify Inc. Headquarters: 44 Montgomery Street, Suite 300, San Francisco, California 94104. [email protected] | Necessary for the website to function Privacy Policy: https://www.netlify.com/privacy/ https://www.netlify.com/gdpr-ccpa/ |
| Name and contact information of the data controller | Peak Tech Limited Liability Company Registered office: 1196 Budapest, Hunyadi Street 140, Ground Floor, Door 2 Tax ID: 32863576-2-43 Representative: Bendegúz Gulyás Address: 1106 Budapest, Gyakorló Street 6, 9th Floor, Door 38 Email address:[email protected] |
| Recipient's name | |
| Hosting provider : Netlify Inc. Headquarters: 44 Montgomery Street, Suite 300, San Francisco, California 94104. [email protected] | Required for the website to function Privacy Policy: https://www.netlify.com/privacy/ https://www.netlify.com/gdpr-ccpa/ |
| Processed data | Your name, email address, and any other information entered in the comments field |
| Data subjects | You, as the person making contact |
| Purpose processing of data | maintaining contact, providing information to the interested party |
| Legal basis for data processing | Your consent (GDPR Article 6(1)(a)) |
| Duration processing of data | 15 days following the response (unless a contract is concluded or a marketing inquiry is made). |
| Data transfer | No data is transferred to third parties |
| Recipients | Possible recipients: telecommunications provider, email service provider In the case of a contact form, the web hosting provider. |
| Data processing for purposes other than the intended purpose | None |
| Data processing risk | I assess the processing of contact information as low-risk, and I act in accordance with data protection and data security regulations. |
| Source of data: directly from you, as the data subject | |
| No automated decision-making or profiling takes place. | |
| Data processed | Name of the person providing the review, review content |
| Data subjects | Those who provide feedback on the data controller’s work |
| Purpose processing of data | Opinions about the service serve as a reference for the data controller |
| Legal basis for data processing | Data processing is based on Article 6(1)(a) of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR). |
| Duration processing of data | Until the data subject withdraws their consent |
| Potential recipients, data transfer | None |
| Data processing for purposes other than those for which it was collected | None |
| Data processing risk | low |
| Basis for data provision: the customer’s decision to form an opinion about the data controller’s work | |
| Method of data processing: electronically | |
| Source of data: directly from the data subject | |
| Data Processed | Name and address of the data subject, as well as any data provided during the complaint |
| Purpose of data processing | Investigation and resolution of the complaint |
| Legal basis for data processing | Act CLV of 1997 on Consumer Protection (Fgytv.) Sections 17/A, 17/B, and 17/C Decree No. 19/2014 (IV. 29.) of the Ministry for National Economy on the detailed rules for the handling of consumer complaints |
| Duration of data processing | 5 years from the date of receipt of the complaint |
| Data processing risk | Low |
| Data processed | the data subject’s name, contact information, and other data necessary to identify the data subject; data regarding the applicant’s eligibility; and data provided by the data subject in connection with the case or request, including, where applicable, special categories of personal data |
| Scope of data subjects | The purpose of data processing is to assess and fulfill requests and submissions received by the data controller from the data subject—including requests for access to, rectification, erasure, or restriction of the processing of personal data, and objections to the processing of personal data. |
| Purpose processing of data | Proper identification of the data subject, as well as the appropriate assessment and fulfillment of the request received by the data controller, the documentation thereof, and the enforceability of the data subject’s rights |
| Legal basis for data processing | Data processing is based on Article 6(1)(e) of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR) |
| Duration processing of data | 5 years |
| Potential recipients, data transfer | None |
| Data processing for purposes other than those specified | None. |
| Processed data | Name, email address |
| Scope of data subjects | Individuals filling out the form. |
| Purpose of data processing | By filling out this Google form, we would like to provide our current and prospective customers with information about Shopify and the Peakship app, as well as gauge their opinions regarding the app. The form also gives respondents the option to subscribe to our newsletter. |
| Legal basis for data processing | The processing of personal data is based on Article 6(1)(a) of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR), which requires the consent of the data subject. |
| Duration of data processing | We will process your data until you withdraw your consent. You may withdraw your consent by email or mail (using any of the contact details provided in the privacy notice). |
| Potential recipients | The form is filled out via a Google form, and we use Google Ireland Limited (Registration No.: 368047 / Tax ID: IE6388047V) (Gordon House, Barrow Street, Dublin 4, Ireland) as our data processor. We do not share email addresses obtained with your consent with third parties. |
| Data processing for purposes other than those specified | None |
| Data processing risk | Low |
| Basis for data provision: based on the data subject’s consent. | |
| No automated decision-making or profiling takes place with respect to the personal data provided | |
| Data processed | The email address and name of the person giving consent to the newsletter on the website, on the “Newsletter Subscription” page, or via the Google form, which we may post on the following platforms: - Facebook: (https://www.facebook.com/business/news/facebooks-commitment-to-data-protection-and-privacy-in-compliance-with-the-gdpr) - Reddit, (https://www.reddit.com/policies/privacy-policy) - LinkedIn, (https://www.linkedin.com/legal/privacy/eu)) |
| Data subjects | – for this, the data subject must provide their email address – subject to their having read this privacy notice and acknowledged its contents |
| Scope of Data Subjects | Persons giving consent |
| Purpose of data processing | Providing information about the service, sending personalized offers to customers, and sending newsletters |
| Legal basis for data processing | Data processing is based on Article 6(1)(a) of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR). Based on the data subject’s prior, unambiguous, and explicit consent, the Company sends newsletters via email to the data subject regarding its most important news, events, and programs. |
| Duration of data processing | Until consent is withdrawn. You may withdraw your consent via email, by mail, or by clicking the unsubscribe button in the email you received. (using any of the contact details provided in the privacy notice) |
| Potential recipients | The email addresses provided are processed exclusively by the data controller for marketing purposes. Due to the nature of its services, the hosting provider has access to these, but pursuant to the data processing agreement, it does not use them for marketing purposes; it is solely responsible for their storage and security. With regard to email addresses provided via Google forms, Google also acts as a data processor. |
| Data processing for purposes other than those specified | None |
| Data processing risk | low |
| Source of data: directly from the data subject | |
| Legal basis for data processing: Section 6(1) of the Grtv. Unless otherwise provided by a separate law, advertising directed at a natural person as the recipient of the advertisement by means of direct contact (hereinafter: direct marketing), in particular via electronic mail or other equivalent means of individual communication—with the exception specified in paragraph (4)—may be communicated only if the recipient of the advertisement has given their prior, clear, and explicit consent. | |
| Processed data | exclusively the email address containing personal data assigned to the legal entity |
| Data subjects | the natural person whose personal data is contained in the email address (the data controller does not process the name of this natural person, but the data subject is able to identify this natural person) |
| Purpose of data processing | An email sent to the requested company. |
| Legal basis for data processing | Data processing is based on Article 6(f) of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR). |
| Legitimate interest of the data controller | Contacting the contacted company, which is possible exclusively via the email address containing personal data provided for the purpose of maintaining contact |
| Duration of data processing | |
| Potential recipients, data transfer | No data transfer takes place with respect to the email addresses of the data subjects |
| Data processing for purposes other than the intended purpose | None |
| Data processing risk | Low |
| Source of data: Requests sent to our partner companies for the purpose of providing information about the application | |
| Basis for data provision: If a company provides an email address containing personal data as its official contact information, communications addressed to that company (including promotional messages) may be sent to it. | |
In connection with the processing of personal data, you have the following rights under Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).
You have the right to receive confirmation as to whether our Company processes personal data concerning you in connection with the operation of the PeakShip website, the handling of contact requests, the provision of services, the maintenance of customer relationships, and the fulfillment of contractual obligations.
If your personal data is being processed, you have the right to receive information, in particular regarding the following:
the purposes of the data processing;
the categories of personal data being processed;
the recipients or categories of recipients to whom your personal data has been or will be disclosed;
the planned duration of the storage of personal data, or the criteria used to determine it;
the data subject rights to which you are entitled;
the right to lodge a complaint with a supervisory authority;
if the data was not obtained directly from you, its source;
the fact that automated decision-making or profiling is used, as well as the relevant circumstances thereof.
You also have the right to request a copy of the personal data we process about you. The first copy is provided free of charge.
You have the right to request the rectification or completion of inaccurate or incomplete personal data concerning you. Our company takes all reasonable measures to ensure that the data we process is accurate and up-to-date; however, we ask that you notify us immediately of any changes to your data.
We will act on requests for rectification without undue delay.
You have the right to request the erasure of your personal data if:
the personal data is no longer necessary for the purpose for which it was collected or processed;
the processing is based on consent and you withdraw your consent;
you object to the processing, and there are no overriding legitimate grounds for the processing;
we have processed the personal data unlawfully;
erasure is required by law.
The right to erasure does not apply in cases where data processing is necessary for compliance with a legal obligation, or for the establishment, exercise, or defense of legal claims.
You have the right to request the restriction of the processing of your personal data in the following cases:
you contest the accuracy of the personal data;
the processing is unlawful, but you request the restriction of its use instead of its erasure;
Our company no longer needs the personal data, but you require it to establish, exercise, or defend legal claims;
You have objected to the processing, and the matter is under review.
In the event of restriction, we will process your personal data beyond storage only with your consent or in cases specified by law.
If the data processing is based on your consent or the performance of a contract and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format.
You also have the right to request that this data be transmitted directly to another data controller, provided that this is technically feasible.
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data where the processing is based on a legitimate interest.
In this case, we will no longer process the personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or that are related to the establishment, exercise, or defense of legal claims.
If we process your personal data for direct marketing purposes, you have the right to object to such processing at any time. In this case, we will no longer process your personal data for marketing purposes.
If the processing of personal data is based on your consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing prior to withdrawal.
You have the right not to be subject to a decision based solely on automated processing— including profiling—that produces legal effects concerning you or similarly significantly affects you.
Our company does not currently use automated decision-making or profiling that would have such legal effects on data subjects.
The Company will comply with a request to exercise data subject rights within one month of receiving it.
If necessary—due to the complexity of the request or the number of requests—this deadline may be extended by an additional two months, of which the Company will inform the data subject within one month of receiving the request.
The Company pays special attention to the security of personal data processed on the website and, in accordance with Article 32 of the GDPR (Regulation (EU) 2016/679 of the European Parliament and of the Council), takes all technical and organizational measures necessary to ensure an appropriate level of data protection.
The application’s internal monitoring is performed using the Faro application. (https://grafana.com/docs/grafana-cloud/monitor-applications/frontend-observability/data- privacy/ ) Log entries, metrics: Grafana DPA (https://grafana.com/legal/documents/grafana-labs-data- processing-agreement-ver2023.pdf)
https://trust.grafana.com/
https://trust.grafana.com/?itemUid=45220873-6e51-4dbb-b1b1-37d66ee9ef95&source=click
Server, PDF storage: Digital Ocean (servers, PDF storage) https://www.digitaloc/legal/gdpr
Email, ad management: Google Cloud (Google Analytics, emails) https://cloud.google.com/privacy/gdpr?hl=hu
Data stream storage: CloudAMQP https://www.cloudamqp.com/legal/gdpr.html
Trello (to-do lists, bug tracking) https://support.atlassian.com/trello/docs/trello-and-gdpr-our- commitment-to-data-privacy/
Zoho (tracking leads and communications) https://help.zoho.com/portal/en/kb/crm/security- control/compliance-setting/gdpr/articles/gdpr-introduction
Slack (daily communication) https://slack.com/trust/compliance/gdpr
Terraform Cloud (infrastructure management) https://www.hashicorp.com/en/trust/privacy
- Version control system: https://docs.github.com/en/site-policy/privacy-policies/github- general-privacy-statement
Hosting provider and data security
Netlify, Inc. Address: 512 2nd Street, Suite 200, San Francisco, CA 94107
Name, position, and contact information of the contact person:[email protected] https://trust-center.netlify-corp.com/
The Data Processor processes personal data exclusively in accordance with the Company’s instructions and, in accordance with Articles 28 and 32 of the GDPR, implements technical and organizational measures to ensure an appropriate level of data protection.
The hosting provider places great emphasis on data security; detailed information can be found on its website at the following address: https://www.netlify.com/blog/netlify-launches- advanced-web-security-and-new-web-application-firewall-waf/#security-at-netlify
To ensure transparent information for data subjects, we provide the following information on the most important settings from the information sheet available at the link below: Netlify ensures secure access control by implementing robust mechanisms that allow only authorized users to access authorized applications.
Through Single Sign-On (SSO), we support both Team SSO and Organization SSO, enabling team and organization owners to enforce strict policies to minimize security risks. For large-scale user access management, SCIM Directory Sync integrates with supported identity providers, enabling seamless management of Netlify access across multiple teams directly from the identity provider.
In addition, role-based access control (RBAC) offers granular access control by restricting developers’ access to specific locations within a team. We also provide a Security Scorecard to ensure your organization is configured according to best practices.
Compliance and Certifications
Netlify is committed to meeting the complex security and compliance needs of enterprises. Netlify adheres to industry standards and frameworks such as SOC 2 Type 2, ISO 27001, PCI DSS, GDPR, and CCPA, and implements various anti-fraud and anti-abuse controls. For the latest compliance information, visit the Netlify Trust Center.
Advanced Web Security
This is the latest addition to our list of security features, designed to protect your site from threats and unauthorized access. Netlify Advanced Web Security includes the following enterprise-grade security features:
World-class DDoS mitigation protections
A user-customizable web application firewall
Configurable rate limiting
Firewall traffic rules to block traffic based on IP address or geographic location
Access to Log Drains for complete visibility into user traffic
The Netlify Web Application Firewall
To ensure the security of our customers, Netlify employs various protections and filters worldwide to prevent common website attacks. These protections include protocol and method validation checks, route attack detection, and validation of request headers, user agents, and URIs, among other filters. These rules complement our global IP blocks, which block known malicious traffic, as well as traffic associated with Distributed Denial of Service (DDoS) attacks. On average, Netlify blocks over half a billion malicious Layer 7 HTTP requests on our customers’ websites each week, with peak volumes reaching several times that amount. This attack-blocking feature is built into our core service and cannot be customized by users. Starting today, customers can apply and configure firewall rules compatible with the OWASP Core Rule Set (OWASP CRS), which Netlify has curated to handle attack traffic targeting composite website architectures. The OWASP CRS is one of the most recognized WAF rule sets. It is specifically designed to detect the most commonly exploited modern web attack signatures, including those listed in the OWASP Top 10. Netlify WAF also supports passive mode, which, along with log downloads, allows web developers to observe the rules triggering on-site traffic, enabling rule set tuning. Similar to the functionality of our custom rate-limiting rules, our WAF also supports route exclusion.
If you have any questions regarding the data processed by the Company, or if you believe that your rights have been infringed upon during data processing, please first contact the Company via one of the provided contact details, either in writing (email, postal mail) or verbally.
In order to process your request, it is important that the Company be able to identify you based on the available data.
If the Company does not take action in response to the data subject’s request, it shall inform the data subject without delay, but no later than one month from the receipt of the request, of the reasons for the failure to act, as well as of the data subject’s right to file a complaint with a supervisory authority and to seek judicial remedy.
National Authority for Data Protection and Freedom of Information
Address: 1055 Budapest, Falk Miksa Street 9-11.
Phone: +36-1-391-1400
Anyone—not just the data subject—may initiate an investigation with the Authority on the grounds that a violation of rights has occurred or is imminent in connection with the processing of personal data.
The Authority’s investigation is free of charge; the detailed rules of the procedure are set forth in the Act on the Right to Self-Determination in Information and Freedom of Information.
In the event of a violation of their rights, the data subject may bring a lawsuit against the Company. The lawsuit may be filed—at the data subject’s discretion—before the competent court of their place of residence or domicile.
Court contact information and search tool: Court Finde