Contents
- 1. Introduction
- 2. Controller details
- 3. Principles we follow
- 4. What data we process
- 5. Why we process it
- 6. How consent works
- 7. Cookies
- 8. Web analytics services
- 9. Marketing services
- 10. Contact forms and client data
- 11. Processors
- 12. Transfers outside the European Union
- 13. Security and data breaches
- 14. Your rights
- 15. Complaints and remedies
- 16. When we act as a processor for a client
- 17. Other provisions
1. Introduction
This notice explains what personal data Mana Digital Kft. processes on its website and in its business relationships, for what purpose, on what legal basis, for how long, and who we share it with. It also explains how to withdraw your consent and what rights you have.
We process personal data solely for the purposes set out here, and we always uphold the rights the GDPR gives data subjects. Where a rule applies to every processing activity — such as withdrawing consent or exercising your rights — we state it in one place instead of repeating it under every service.
This notice covers visitors to the website, enquirers, contact persons at our clients and partners, users of the client portal, and job applicants. It does not cover cases where we process data on a client's behalf as a processor within a project — see section 16.
2. Controller details
- Company
- Mana Digital Kft. (Mana Digital Korlátolt Felelősségű Társaság)
- Registered office
- Napfény utca 2. A. ép., 3525 Miskolc, Hungary
- Company reg. no.
- 05-09-034789 (Registry Court of the Miskolc Regional Court)
- Tax number
- 27477829-2-05
- hello@ineedmana.io
- Website
- ineedmana.io
We have not appointed a data protection officer, as none of the cases listed in Article 37 GDPR applies to us. We answer data protection questions and requests at the email address above.
3. Principles we follow
Four principles, applied consistently:
- We ask for no more data than the purpose requires.
- Every processing activity has a concrete purpose, and the data is deleted once that purpose ends.
- We do not sell your data and do not pass it to third parties for their own marketing purposes.
- A new measurement or marketing tool is only introduced together with an update to this notice and its version number.
4. What data we process
Five categories of data occur. The table in the next section shows which is used for what.
- Technical data: IP address, browser and device data, the time of the request, the pages visited and the source of the visit. This arises from serving the website and from measurement after consent.
- Contact data: name, company, email address, phone number, role, and the content of the message you write. You provide this on a form or in correspondence with us.
- Portal access data: email address, name, permissions for individual client spaces, and a log of actions taken in the portal.
- Billing data: the data appearing on invoices and accounting documents.
- Application data: CV, cover letter, contact details and notes made during selection.
We do not process — and do not ask for — special categories of data, such as health data or political opinions.
5. Why we process it
The table below lists all of our processing activities with their legal basis and retention period. Legal bases refer to the points of Article 6(1) GDPR.
| Purpose | Data processed | Legal basis | Retention |
|---|---|---|---|
| Serving and securing the website | Technical data (server logs) | Legitimate interest — (f): secure, stable operation | At most 30 days |
| Measuring traffic and user experience | Technical data, page interaction events | Consent — (a); statistics cookies | See section 8, per service |
| Answering enquiries and requests for proposals | Contact data | Steps prior to a contract — (b), and legitimate interest — (f) | 2 years from closing the enquiry |
| Sending the newsletter and professional content | Email address, subscription status | Consent — (a), and Section 6 of Act XLVIII of 2008 | Until withdrawn, deletion after 3 years of inactivity |
| Managing client portal access | Portal access data | Performance of a contract — (b), or legitimate interest — (f) | Until access is revoked |
| Logging actions taken in the portal | User identifier, event, path, timestamp | Legitimate interest — (f): proposal follow-up and access control | 1 year after access ends |
| Client relationship, contracting and delivery | Contact data, project communication | Performance of a contract — (b), or legitimate interest — (f) | 5 years from the end of the contract |
| Invoicing and accounting records | Billing data | Legal obligation — (c), Section 169 of Act C of 2000 | 8 years |
| Assessing job applications | Application data | Consent — (a) | 6 months from the close, or 1 year with explicit consent |
Where the legal basis is legitimate interest, the table names what that interest is, and you may object at any time as described in section 14.
6. How consent works
This section states the rules of consent once. The services in sections 8 and 9 rely on these rules, so they are not repeated there.
Cookies strictly necessary for the website to work may be used without consent under the applicable law. Everything else — statistics and marketing cookies, and the measurement code that goes with them — is activated only after you consent.
Consent is collected by the cookie banner shown on your first visit, displayed and logged by the CookieYes consent management platform. Until you accept, the measurement code cannot run: it ships in the page's HTML in an inactive state and only becomes live once you accept.
Giving consent is voluntary and can be withdrawn at any time without giving reasons. Withdrawal does not affect the lawfulness of processing before it, and takes effect going forward: no new measurement data is generated, and data collected earlier is deleted when its retention period expires.
You can withdraw consent in two ways: the cookie icon shown at the bottom of the site, or the “Cookie settings” button on this page. You can also delete or pre-emptively block cookies in your browser — but if you block strictly necessary cookies, some features, such as signing in to the client portal, will not work.
7. Cookies
Cookies are small text files that the website saves to your browser. They let the site recognise your browser, so it can remember your language preference or that you are signed in. This section also covers similar technologies, such as your browser's local storage.
Strictly necessary cookies
Required for the website to work; without them certain features are unusable. No consent is needed for these.
Statistics cookies
They help us understand how visitors use the website. They are activated only after consent. This includes Microsoft Clarity and Google Analytics 4 — see section 8 for details.
Marketing cookies
These would serve to measure campaign performance and to show personalised advertising, only after consent. We currently place no such cookies — see section 9.
Cookies used on this website
| Cookie | Set by | Purpose | Category | Lifetime |
|---|---|---|---|---|
| cookieyes-consent | CookieYes | Stores which categories you allowed | Necessary | 1 year |
| portal_session | Mana Digital | Keeps you signed in to the client portal | Necessary | 30 days |
| NEXT_LOCALE | Mana Digital | Remembers the language you chose | Necessary | 1 year |
| _clck | Microsoft Clarity | Links your visits to an anonymous identifier | Statistics | 1 year |
| _clsk | Microsoft Clarity | Connects page views within a single session | Statistics | 1 day |
| CLID | Microsoft Clarity | Identifies whether this is your first visit | Statistics | 1 year |
| _ga | Google Analytics | Distinguishes visitors using an anonymous identifier | Statistics | 2 years |
| _ga_5PVVP89VTE | Google Analytics | Session state for this measurement property | Statistics | 2 years |
Beyond the above, Microsoft and Google may set further technical cookies tied to their own accounts (for example MUID, ANONCHK, MR, SM). These too are placed only if you consent to statistics.
8. Web analytics services
We use two web analytics services. Both are activated only after statistics cookies are accepted.
| Service | Purpose | Legal basis | Activation |
|---|---|---|---|
| Microsoft Clarity | Usage analysis, UX improvement | Consent | After statistics cookies are accepted |
| Google Analytics 4 | Traffic statistics | Consent | After statistics cookies are accepted |
Microsoft Clarity
- Purpose
- Analysing how the website is used and improving the user experience, producing heatmaps and session recordings.
- Activation
- Only after statistics cookies are accepted.
- Data processed
- Clicks, scrolling, cursor movement, page interaction and technical events, device and browser data, approximate location derived from the IP address.
- Provider
- Microsoft Ireland Operations Limited
- Retention
- Recordings are available for 30 days, aggregated statistics for up to 13 months.
- Note
- A recording is tied not to your name but to a random identifier stored in a cookie. Clarity masks text you type by default, and in the client portal we additionally mask every element that identifies a client. Clarity also runs in the client portal; Google Analytics does not.
Google Analytics 4
- Purpose
- Traffic statistics: which pages are opened, where visitors arrive from, what device they use.
- Activation
- Only after statistics cookies are accepted.
- Data processed
- Pages visited, source of the visit, technical identifiers, device and browser data, approximate location derived from the IP address.
- Provider
- Google Ireland Limited
- Retention
- Up to 14 months, per the property's configuration.
- Note
- The measurement code denies storage for advertising, ad user data and personalisation purposes by default, so consenting to statistics does not on its own switch on remarketing.
Google Tag Manager
We do not use a Google Tag Manager container. The Google Analytics measurement code loads from the googletagmanager.com domain — that is Google's tag library, not Tag Manager. Should we introduce Tag Manager later, it performs no statistics or marketing processing on its own, and the services it manages activate strictly in line with the consent you gave.
9. Marketing services
We currently use no marketing measurement code — no Meta Pixel, no LinkedIn Insight Tag, no other advertising audience tool — and we place no marketing cookies on the website.
If that changes, the service in question will appear in this section in the same structure used in section 8 — purpose, activation, data processed, provider, retention — the cookie banner will gain a marketing category, and this notice's version number will be raised. Marketing processing never starts without consent.
10. Contact forms and client data
Contact and discovery form
We receive what you submit by email and use it to answer your enquiry and to prepare a proposal. Form content does not go into a database or a CRM — it lives in our mailbox. We do not send newsletters based on this data; that requires a separate subscription.
Newsletter
Subscribing takes only an email address. Every message carries an unsubscribe link, and unsubscribing takes effect immediately. The newsletter and the portal's emails are two different things: the sign-in link is a system message tied to performing the contract, so unsubscribing from the newsletter does not affect signing in.
Client portal
The client portal has no passwords. To sign in, we email you a link valid for 15 minutes; after a successful sign-in we place a session cookie readable only by the server, valid for 30 days. We log who signed in and when, and which proposal they opened — we use this to follow up on proposals and to check access for security. The log holds no IP address, and is kept for at most one year after access ends, enforced by automatic deletion.
For sign-in attempts we use the email address and the IP address solely for abuse protection, to limit the number of requests, and only transiently in memory. We do not store this in a database and do not link it to the activity log.
Client and partner relationships
To prepare and perform a contract and to stay in touch, we process the contact person's name, role and business contact details, along with the project's communication. We do not collect private data. Billing data must be retained for the period prescribed by accounting law, and we cannot make an exception to that even on a deletion request.
Job applications
The application is seen by those involved in the selection, and kept for six months after the process closes. With your explicit consent we keep it for a year, so we can approach you about a later role.
11. Processors
We use the providers below, each under a data processing agreement. We do not sell data and do not pass it to third parties for their own marketing purposes.
| Processor | What it does | Location |
|---|---|---|
| Vercel Inc. | Hosting, serving and logging of the website and the client portal | United States |
| Neon, LLC (part of Databricks, Inc.) | The client portal database, in a European region | United States |
| Resend, Inc. | Email delivery: form notifications, sign-in links, newsletter | United States |
| Google Ireland Limited | Google Analytics 4 | Ireland |
| Microsoft Ireland Operations Limited | Microsoft Clarity | Ireland |
| CookieYes Limited | Collecting and logging cookie consent | United Kingdom |
In addition, our accountant and — in the event of a legal claim — our legal counsel may access the data they need, and we may disclose data at the request of an authority or court where the law requires it. Where possible, we will inform you of such a request.
Each provider's own privacy notice is available directly here:
12. Transfers outside the European Union
This section states the rules of transfer once, for every service above.
Some of our processors operate in the United States, so certain processing operations involve a transfer to a third country. In those cases the transfer is based on the European Commission's EU-U.S. Data Privacy Framework adequacy decision or on the standard contractual clauses adopted by the Commission, with the additional technical and organisational safeguards required. CookieYes operates in the United Kingdom, which is covered by an adequacy decision.
We send a copy of the safeguards applied on request at hello@ineedmana.io.
13. Security and data breaches
We apply technical and organisational measures proportionate to the risk:
- all traffic on the website and the portal runs over an encrypted connection (HTTPS),
- the client portal has no passwords, and therefore no password database — sign-in uses a short-lived, signed token,
- the session cookie is readable only by the server and is not accessible from JavaScript,
- each client space is accessible only to authorised users, and permissions are checked at the database level,
- only those colleagues who need it for their work have access to personal data,
- we use European data centre regions wherever they are available.
If a personal data breach occurs, we contain access, assess which categories of data are affected, and document the breach. If it is likely to result in a risk to your rights, we report it to the Hungarian supervisory authority (NAIH) within 72 hours of becoming aware of it. If the risk is high, we also inform you directly without undue delay.
14. Your rights
This section states your rights once, for every processing activity above.
- Access: you may ask whether we process data relating to you and, if so, what data, for what purpose and for how long.
- Rectification: you may ask us to correct inaccurate data and complete incomplete data.
- Erasure: you may ask us to delete your data where the purpose has ceased, you have withdrawn consent, or the processing is unlawful.
- Restriction: you may ask us to only store the data without using it, for example while you contest its accuracy.
- Data portability: for data processed by automated means on the basis of consent or a contract, you may receive it in a machine-readable format or ask us to transmit it to another controller.
- Objection: you may object to processing based on legitimate interest. For direct marketing we always honour the objection without asking for reasons.
- Withdrawal of consent: at any time, as described in section 6.
We accept requests at hello@ineedmana.io and respond within 1 month of receipt at the latest. If a request is complex, we may extend that by up to 2 further months, and we will tell you within the first month. The procedure is free of charge.
Your request is handled faster if it states which right you wish to exercise, what exactly it concerns, and a contact address for our reply. If we cannot identify you beyond doubt, we may ask for additional information.
15. Complaints and remedies
If you believe our processing does not comply with the law, we would appreciate hearing it directly at hello@ineedmana.io first. Independently of that, you may lodge a complaint with the supervisory authority:
- Authority
- Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
- Address
- Falk Miksa utca 9-11., 1055 Budapest, Hungary
- Postal address
- 1363 Budapest, Pf. 9., Hungary
- Phone
- +36 (1) 391-1400
- ugyfelszolgalat@naih.hu
- Website
- naih.hu
You may also go to court. You may bring proceedings against us as controller if our processing infringed your rights, and you may also seek judicial remedy against a decision of the authority. Proceedings may be brought before the Miskolc Regional Court, which has jurisdiction over our registered office, or at your choice before the tribunal of your place of residence or stay. The court handles such cases out of turn, and you can find the competent court using the court finder at birosag.hu.
16. When we act as a processor for a client
In client projects — when we build or operate a system, or run a campaign — we often work with data about our client's end users, customers or prospects. There we are not the controller: our client is, and we act as a processor under Article 28 GDPR, on the basis of a written data processing agreement and the client's instructions.
In practice this means we use the data solely to deliver the engagement and never for our own purposes, and at the end of the engagement we return or delete it as the client decides. Subcontractors and further processors are engaged within the framework of the agreement signed with the client. Whatever this notice does not cover is governed by that contract.
- We do not send personal data originating from client projects to US artificial intelligence or large language model (LLM) providers.
- We do not use live client data in test, development or demo environments.
If you provided your data through a client's product or service, that company's own notice governs the processing, and that is where you can exercise your rights. If you are unsure who to turn to, write to us and we will help you find the right controller.
17. Other provisions
Children's data
Our services are aimed at companies, and our website is not intended for children under 16. We do not knowingly collect data relating to anyone under 16. If such data reaches us, we delete it without delay.
Automated decision-making and profiling
We do not use solely automated decision-making or profiling that would produce legal effects concerning you or similarly significantly affect you. We use statistics in aggregated form to improve the website.
Applicable law
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR),
- Act CXII of 2011 on the Right to Informational Self-Determination and on Freedom of Information,
- Act XLVIII of 2008 on Commercial Advertising — for the newsletter,
- Act CVIII of 2001 on Electronic Commerce Services,
- Act C of 2000 on Accounting — for the retention of accounting documents,
- Act V of 2013 on the Civil Code.