Privacy Policy

Last updated: June 08, 2026

This privacy notice provides information, in accordance with Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR), to data subjects whose personal data is processed by the data controller in the course of providing its services.

The primary purpose of data processing on the https://peakship.net website is to present the services provided by PeakShip, maintain contact with interested parties, ensure the communication necessary for using the services, handle user inquiries, and develop the services and improve the user experience.

You can access the data processing notice for the PeakShip app at https://peakship-36hx3.ondigitalocean.app/privacy_policy.html.

Table of Contents

DATA CONTROLLER, NAME OF THE DATA SUBJECT, CONTACT INFORMATIONDATA CONTROLLER, NAME OF THE ADDRESSEE CONTACT INFORMATIONINFORMATION REGARDING DATA PROCESSINGPersonal data processed for contact purposes or via the contact formCustomer reviewsData processing related to complaint handlingData processing related to the exercise of data subject rightsThe personal data to be provided on the Google Form is collected for the purpose of registering for Shopify-themed meetups and community events, as well as for gathering customer feedback and measuring satisfaction with the appData processing for marketing purposes related to newsletter subscriptionsContacting legal entities electronically via an email address containing personal dataData subject rights regarding data processingRight of access (Article 15 of the GDPR)Right to Rectification (GDPR Article 16)Right to erasure (“right to be forgotten”) (Article 17 of the GDPR)The right to restriction of processing (Article 18 of the GDPR)Right to data portability (GDPR Article 20)Right to Object (Article 21 of the GDPR)Right to Withdraw ConsentRights regarding automated decision-making (Article 22 of the GDPR)Time LimitsWebsite Data Security SettingsWhere can you turn if you wish to seek redress or have a question?Data ControllerThe National Authority for Data Protection and Freedom of Information (NAIH)Court

DATA CONTROLLER, NAME OF THE DATA SUBJECT, CONTACT INFORMATION

Name and contact information of the data controllerController name: Peak Tech Korlátolt Felelősségű Társaság Headquarters: Hungary, (zip:) 1196, (city:) Budapest, (street:) Hunyadi utca 140. Fsz. 2. ajtó Tax number: 32863576-2-43 Company registration number:01-09-446645 Representative: Gulyás Bendegúz Address: 1106 Budapest, Gyakorló utca 6. 9. em. 38. ajtó E-mail: [email protected]
Hosting provider:
Netlify Inc. Headquarters: 44 Montgomery Street, Suite 300, San Francisco, California 94104. [email protected]Necessary for the website to function Privacy Policy: https://www.netlify.com/privacy/ https://www.netlify.com/gdpr-ccpa/

DATA CONTROLLER, NAME OF THE ADDRESSEE, CONTACT INFORMATION

Name and contact information of the data controllerPeak Tech Limited Liability Company Registered office: 1196 Budapest, Hunyadi Street 140, Ground Floor, Door 2 Tax ID: 32863576-2-43 Representative: Bendegúz Gulyás Address: 1106 Budapest, Gyakorló Street 6, 9th Floor, Door 38 Email address:[email protected]
Recipient's name
Hosting provider :
Netlify Inc.
Headquarters: 44 Montgomery Street, Suite 300, San Francisco, California 94104.
[email protected]
Required for the website to function Privacy Policy: https://www.netlify.com/privacy/ https://www.netlify.com/gdpr-ccpa/

INFORMATION REGARDING DATA PROCESSING

Personal data processed for contact purposes or via the contact form

Processed dataYour name, email address, and any other information entered in the comments field
Data subjectsYou, as the person making contact
Purpose processing of datamaintaining contact, providing information to the interested party
Legal basis for data processingYour consent (GDPR Article 6(1)(a))
Duration processing of data15 days following the response (unless a contract is concluded or a marketing inquiry is made).
Data transferNo data is transferred to third parties
RecipientsPossible recipients: telecommunications provider, email service provider In the case of a contact form, the web hosting provider.
Data processing for purposes other than the intended purposeNone
Data processing riskI assess the processing of contact information as low-risk, and I act in accordance with data protection and data security regulations.
Source of data: directly from you, as the data subject
No automated decision-making or profiling takes place.

Customer reviews

Data processedName of the person providing the review, review content
Data subjectsThose who provide feedback on the data controller’s work
Purpose processing of dataOpinions about the service serve as a reference for the data controller
Legal basis for data processingData processing is based on Article 6(1)(a) of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR).
Duration processing of dataUntil the data subject withdraws their consent
Potential recipients, data transferNone
Data processing for purposes other than those for which it was collectedNone
Data processing risklow
Basis for data provision: the customer’s decision to form an opinion about the data controller’s work
Method of data processing: electronically
Source of data: directly from the data subject

Data processing related to complaint handling

Data ProcessedName and address of the data subject, as well as any data provided during the complaint
Purpose of data processingInvestigation and resolution of the complaint
Legal basis for data processingAct CLV of 1997 on Consumer Protection (Fgytv.) Sections 17/A, 17/B, and 17/C Decree No. 19/2014 (IV. 29.) of the Ministry for National Economy on the detailed rules for the handling of consumer complaints
Duration of data processing5 years from the date of receipt of the complaint
Data processing riskLow

Data processing related to the exercise of data subject rights

Data processedthe data subject’s name, contact information, and other data necessary to identify the data subject; data regarding the applicant’s eligibility; and data provided by the data subject in connection with the case or request, including, where applicable, special categories of personal data
Scope of data subjectsThe purpose of data processing is to assess and fulfill requests and submissions received by the data controller from the data subject—including requests for access to, rectification, erasure, or restriction of the processing of personal data, and objections to the processing of personal data.
Purpose processing of dataProper identification of the data subject, as well as the appropriate assessment and fulfillment of the request received by the data controller, the documentation thereof, and the enforceability of the data subject’s rights
Legal basis for data processingData processing is based on Article 6(1)(e) of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR)
Duration processing of data5 years
Potential recipients, data transferNone
Data processing for purposes other than those specifiedNone.

The personal data to be provided on the Google Form is collected for the purpose of registering for Shopify-themed meetups and community events, as well as for gathering customer feedback and measuring satisfaction with the app

Processed dataName, email address
Scope of data subjects Individuals filling out the form.
Purpose of data processingBy filling out this Google form, we would like to provide our current and prospective customers with information about Shopify and the Peakship app, as well as gauge their opinions regarding the app. The form also gives respondents the option to subscribe to our newsletter.
Legal basis for data processingThe processing of personal data is based on Article 6(1)(a) of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR), which requires the consent of the data subject.
Duration of data processingWe will process your data until you withdraw your consent. You may withdraw your consent by email or mail (using any of the contact details provided in the privacy notice).
Potential recipientsThe form is filled out via a Google form, and we use Google Ireland Limited (Registration No.: 368047 / Tax ID: IE6388047V) (Gordon House, Barrow Street, Dublin 4, Ireland) as our data processor. We do not share email addresses obtained with your consent with third parties.
Data processing for purposes other than those specifiedNone
Data processing riskLow
Basis for data provision: based on the data subject’s consent.
No automated decision-making or profiling takes place with respect to the personal data provided

Data processing for marketing purposes related to newsletter subscriptions

Data processedThe email address and name of the person giving consent to the newsletter on the website, on the “Newsletter Subscription” page, or via the Google form, which we may post on the following platforms: - Facebook:
(https://www.facebook.com/business/news/facebooks-commitment-to-data-protection-and-privacy-in-compliance-with-the-gdpr)
- Reddit, (https://www.reddit.com/policies/privacy-policy)
- LinkedIn, (https://www.linkedin.com/legal/privacy/eu))
Data subjects– for this, the data subject must provide their email address – subject to their having read this privacy notice and acknowledged its contents
Scope of Data SubjectsPersons giving consent
Purpose of data processingProviding information about the service, sending personalized offers to customers, and sending newsletters
Legal basis for data processingData processing is based on Article 6(1)(a) of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR). Based on the data subject’s prior, unambiguous, and explicit consent, the Company sends newsletters via email to the data subject regarding its most important news, events, and programs.
Duration of data processingUntil consent is withdrawn. You may withdraw your consent via email, by mail, or by clicking the unsubscribe button in the email you received. (using any of the contact details provided in the privacy notice)
Potential recipientsThe email addresses provided are processed exclusively by the data controller for marketing purposes. Due to the nature of its services, the hosting provider has access to these, but pursuant to the data processing agreement, it does not use them for marketing purposes; it is solely responsible for their storage and security. With regard to email addresses provided via Google forms, Google also acts as a data processor.
Data processing for purposes other than those specifiedNone
Data processing risklow
Source of data: directly from the data subject
Legal basis for data processing: Section 6(1) of the Grtv. Unless otherwise provided by a separate law, advertising directed at a natural person as the recipient of the advertisement by means of direct contact (hereinafter: direct marketing), in particular via electronic mail or other equivalent means of individual communication—with the exception specified in paragraph (4)—may be communicated only if the recipient of the advertisement has given their prior, clear, and explicit consent.

Contacting legal entities electronically via an email address containing personal data

Data subject rights regarding data processing

In connection with the processing of personal data, you have the following rights under Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).

Right of access (Article 15 of the GDPR)

You have the right to receive confirmation as to whether our Company processes personal data concerning you in connection with the operation of the PeakShip website, the handling of contact requests, the provision of services, the maintenance of customer relationships, and the fulfillment of contractual obligations.

If your personal data is being processed, you have the right to receive information, in particular regarding the following:

the purposes of the data processing;
the categories of personal data being processed;
the recipients or categories of recipients to whom your personal data has been or will be disclosed;
the planned duration of the storage of personal data, or the criteria used to determine it;
the data subject rights to which you are entitled;
the right to lodge a complaint with a supervisory authority;
if the data was not obtained directly from you, its source;
the fact that automated decision-making or profiling is used, as well as the relevant circumstances thereof.

You also have the right to request a copy of the personal data we process about you. The first copy is provided free of charge.

Right to Rectification (GDPR Article 16)

You have the right to request the rectification or completion of inaccurate or incomplete personal data concerning you. Our company takes all reasonable measures to ensure that the data we process is accurate and up-to-date; however, we ask that you notify us immediately of any changes to your data.

We will act on requests for rectification without undue delay.

Right to erasure (“right to be forgotten”) (Article 17 of the GDPR)

You have the right to request the erasure of your personal data if:

the personal data is no longer necessary for the purpose for which it was collected or processed;
the processing is based on consent and you withdraw your consent;
you object to the processing, and there are no overriding legitimate grounds for the processing;
we have processed the personal data unlawfully;
erasure is required by law.

The right to erasure does not apply in cases where data processing is necessary for compliance with a legal obligation, or for the establishment, exercise, or defense of legal claims.

The right to restriction of processing (Article 18 of the GDPR)

You have the right to request the restriction of the processing of your personal data in the following cases:

you contest the accuracy of the personal data;
the processing is unlawful, but you request the restriction of its use instead of its erasure;
Our company no longer needs the personal data, but you require it to establish, exercise, or defend legal claims;
You have objected to the processing, and the matter is under review.

In the event of restriction, we will process your personal data beyond storage only with your consent or in cases specified by law.

Right to data portability (GDPR Article 20)

If the data processing is based on your consent or the performance of a contract and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format.

You also have the right to request that this data be transmitted directly to another data controller, provided that this is technically feasible.

Right to Object (Article 21 of the GDPR)

You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data where the processing is based on a legitimate interest.

In this case, we will no longer process the personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or that are related to the establishment, exercise, or defense of legal claims.

If we process your personal data for direct marketing purposes, you have the right to object to such processing at any time. In this case, we will no longer process your personal data for marketing purposes.

If the processing of personal data is based on your consent, you have the right to withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing prior to withdrawal.

Rights regarding automated decision-making (Article 22 of the GDPR)

You have the right not to be subject to a decision based solely on automated processing— including profiling—that produces legal effects concerning you or similarly significantly affects you.

Our company does not currently use automated decision-making or profiling that would have such legal effects on data subjects.

Time Limits

The Company will comply with a request to exercise data subject rights within one month of receiving it.

If necessary—due to the complexity of the request or the number of requests—this deadline may be extended by an additional two months, of which the Company will inform the data subject within one month of receiving the request.

Website Data Security Settings

The Company pays special attention to the security of personal data processed on the website and, in accordance with Article 32 of the GDPR (Regulation (EU) 2016/679 of the European Parliament and of the Council), takes all technical and organizational measures necessary to ensure an appropriate level of data protection.

The application’s internal monitoring is performed using the Faro application. (https://grafana.com/docs/grafana-cloud/monitor-applications/frontend-observability/data- privacy/ ) Log entries, metrics: Grafana DPA (https://grafana.com/legal/documents/grafana-labs-data- processing-agreement-ver2023.pdf)
https://trust.grafana.com/
https://trust.grafana.com/?itemUid=45220873-6e51-4dbb-b1b1-37d66ee9ef95&source=click

Server, PDF storage: Digital Ocean (servers, PDF storage) https://www.digitaloc/legal/gdpr

Email, ad management: Google Cloud (Google Analytics, emails) https://cloud.google.com/privacy/gdpr?hl=hu

Data stream storage: CloudAMQP https://www.cloudamqp.com/legal/gdpr.html

Trello (to-do lists, bug tracking) https://support.atlassian.com/trello/docs/trello-and-gdpr-our- commitment-to-data-privacy/

Zoho (tracking leads and communications) https://help.zoho.com/portal/en/kb/crm/security- control/compliance-setting/gdpr/articles/gdpr-introduction

Slack (daily communication) https://slack.com/trust/compliance/gdpr

Terraform Cloud (infrastructure management) https://www.hashicorp.com/en/trust/privacy

- Version control system: https://docs.github.com/en/site-policy/privacy-policies/github- general-privacy-statement

Hosting provider and data security

Netlify, Inc. Address: 512 2nd Street, Suite 200, San Francisco, CA 94107

Name, position, and contact information of the contact person:[email protected] https://trust-center.netlify-corp.com/

The Data Processor processes personal data exclusively in accordance with the Company’s instructions and, in accordance with Articles 28 and 32 of the GDPR, implements technical and organizational measures to ensure an appropriate level of data protection.

The hosting provider places great emphasis on data security; detailed information can be found on its website at the following address: https://www.netlify.com/blog/netlify-launches- advanced-web-security-and-new-web-application-firewall-waf/#security-at-netlify

To ensure transparent information for data subjects, we provide the following information on the most important settings from the information sheet available at the link below: Netlify ensures secure access control by implementing robust mechanisms that allow only authorized users to access authorized applications.

Through Single Sign-On (SSO), we support both Team SSO and Organization SSO, enabling team and organization owners to enforce strict policies to minimize security risks. For large-scale user access management, SCIM Directory Sync integrates with supported identity providers, enabling seamless management of Netlify access across multiple teams directly from the identity provider.

In addition, role-based access control (RBAC) offers granular access control by restricting developers’ access to specific locations within a team. We also provide a Security Scorecard to ensure your organization is configured according to best practices.

Compliance and Certifications

Netlify is committed to meeting the complex security and compliance needs of enterprises. Netlify adheres to industry standards and frameworks such as SOC 2 Type 2, ISO 27001, PCI DSS, GDPR, and CCPA, and implements various anti-fraud and anti-abuse controls. For the latest compliance information, visit the Netlify Trust Center.

Advanced Web Security

This is the latest addition to our list of security features, designed to protect your site from threats and unauthorized access. Netlify Advanced Web Security includes the following enterprise-grade security features:

World-class DDoS mitigation protections
A user-customizable web application firewall
Configurable rate limiting
Firewall traffic rules to block traffic based on IP address or geographic location
Access to Log Drains for complete visibility into user traffic

The Netlify Web Application Firewall

To ensure the security of our customers, Netlify employs various protections and filters worldwide to prevent common website attacks. These protections include protocol and method validation checks, route attack detection, and validation of request headers, user agents, and URIs, among other filters. These rules complement our global IP blocks, which block known malicious traffic, as well as traffic associated with Distributed Denial of Service (DDoS) attacks. On average, Netlify blocks over half a billion malicious Layer 7 HTTP requests on our customers’ websites each week, with peak volumes reaching several times that amount. This attack-blocking feature is built into our core service and cannot be customized by users. Starting today, customers can apply and configure firewall rules compatible with the OWASP Core Rule Set (OWASP CRS), which Netlify has curated to handle attack traffic targeting composite website architectures. The OWASP CRS is one of the most recognized WAF rule sets. It is specifically designed to detect the most commonly exploited modern web attack signatures, including those listed in the OWASP Top 10. Netlify WAF also supports passive mode, which, along with log downloads, allows web developers to observe the rules triggering on-site traffic, enabling rule set tuning. Similar to the functionality of our custom rate-limiting rules, our WAF also supports route exclusion.

Where can you turn if you wish to seek redress or have a question?

Data Controller

If you have any questions regarding the data processed by the Company, or if you believe that your rights have been infringed upon during data processing, please first contact the Company via one of the provided contact details, either in writing (email, postal mail) or verbally.

In order to process your request, it is important that the Company be able to identify you based on the available data.

If the Company does not take action in response to the data subject’s request, it shall inform the data subject without delay, but no later than one month from the receipt of the request, of the reasons for the failure to act, as well as of the data subject’s right to file a complaint with a supervisory authority and to seek judicial remedy.

The National Authority for Data Protection and Freedom of Information (NAIH)

National Authority for Data Protection and Freedom of Information

Address: 1055 Budapest, Falk Miksa Street 9-11.

Phone: +36-1-391-1400

Anyone—not just the data subject—may initiate an investigation with the Authority on the grounds that a violation of rights has occurred or is imminent in connection with the processing of personal data.

The Authority’s investigation is free of charge; the detailed rules of the procedure are set forth in the Act on the Right to Self-Determination in Information and Freedom of Information.

Court

In the event of a violation of their rights, the data subject may bring a lawsuit against the Company. The lawsuit may be filed—at the data subject’s discretion—before the competent court of their place of residence or domicile.

Court contact information and search tool: Court Finde