← Home
Legal

Privacy Notice

This notice explains what personal data we process on our website and in our business relationships, for what purpose, on what legal basis and for how long, who we share it with, and how you can withdraw your consent.

Effective: 31 July 2026 · Version: 3.1

Contents

1. Introduction

This notice explains what personal data Mana Digital Kft. processes on its website and in its business relationships, for what purpose, on what legal basis, for how long, and who we share it with. It also explains how to withdraw your consent and what rights you have.

We process personal data solely for the purposes set out here, and we always uphold the rights the GDPR gives data subjects. Where a rule applies to every processing activity — such as withdrawing consent or exercising your rights — we state it in one place instead of repeating it under every service.

This notice covers visitors to the website, enquirers, contact persons at our clients and partners, users of the client portal, and job applicants. It does not cover cases where we process data on a client's behalf as a processor within a project — see section 16.

2. Controller details

Company
Mana Digital Kft. (Mana Digital Korlátolt Felelősségű Társaság)
Registered office
Napfény utca 2. A. ép., 3525 Miskolc, Hungary
Company reg. no.
05-09-034789 (Registry Court of the Miskolc Regional Court)
Tax number
27477829-2-05
Email
hello@ineedmana.io
Website
ineedmana.io

We have not appointed a data protection officer, as none of the cases listed in Article 37 GDPR applies to us. We answer data protection questions and requests at the email address above.

3. Principles we follow

Four principles, applied consistently:

4. What data we process

Five categories of data occur. The table in the next section shows which is used for what.

We do not process — and do not ask for — special categories of data, such as health data or political opinions.

5. Why we process it

The table below lists all of our processing activities with their legal basis and retention period. Legal bases refer to the points of Article 6(1) GDPR.

PurposeData processedLegal basisRetention
Serving and securing the websiteTechnical data (server logs)Legitimate interest — (f): secure, stable operationAt most 30 days
Measuring traffic and user experienceTechnical data, page interaction eventsConsent — (a); statistics cookiesSee section 8, per service
Answering enquiries and requests for proposalsContact dataSteps prior to a contract — (b), and legitimate interest — (f)2 years from closing the enquiry
Sending the newsletter and professional contentEmail address, subscription statusConsent — (a), and Section 6 of Act XLVIII of 2008Until withdrawn, deletion after 3 years of inactivity
Managing client portal accessPortal access dataPerformance of a contract — (b), or legitimate interest — (f)Until access is revoked
Logging actions taken in the portalUser identifier, event, path, timestampLegitimate interest — (f): proposal follow-up and access control1 year after access ends
Client relationship, contracting and deliveryContact data, project communicationPerformance of a contract — (b), or legitimate interest — (f)5 years from the end of the contract
Invoicing and accounting recordsBilling dataLegal obligation — (c), Section 169 of Act C of 20008 years
Assessing job applicationsApplication dataConsent — (a)6 months from the close, or 1 year with explicit consent

Where the legal basis is legitimate interest, the table names what that interest is, and you may object at any time as described in section 14.

This section states the rules of consent once. The services in sections 8 and 9 rely on these rules, so they are not repeated there.

Cookies strictly necessary for the website to work may be used without consent under the applicable law. Everything else — statistics and marketing cookies, and the measurement code that goes with them — is activated only after you consent.

Consent is collected by the cookie banner shown on your first visit, displayed and logged by the CookieYes consent management platform. Until you accept, the measurement code cannot run: it ships in the page's HTML in an inactive state and only becomes live once you accept.

Giving consent is voluntary and can be withdrawn at any time without giving reasons. Withdrawal does not affect the lawfulness of processing before it, and takes effect going forward: no new measurement data is generated, and data collected earlier is deleted when its retention period expires.

You can withdraw consent in two ways: the cookie icon shown at the bottom of the site, or the “Cookie settings” button on this page. You can also delete or pre-emptively block cookies in your browser — but if you block strictly necessary cookies, some features, such as signing in to the client portal, will not work.

7. Cookies

Cookies are small text files that the website saves to your browser. They let the site recognise your browser, so it can remember your language preference or that you are signed in. This section also covers similar technologies, such as your browser's local storage.

Strictly necessary cookies

Required for the website to work; without them certain features are unusable. No consent is needed for these.

Statistics cookies

They help us understand how visitors use the website. They are activated only after consent. This includes Microsoft Clarity and Google Analytics 4 — see section 8 for details.

Marketing cookies

These would serve to measure campaign performance and to show personalised advertising, only after consent. We currently place no such cookies — see section 9.

Cookies used on this website

CookieSet byPurposeCategoryLifetime
cookieyes-consentCookieYesStores which categories you allowedNecessary1 year
portal_sessionMana DigitalKeeps you signed in to the client portalNecessary30 days
NEXT_LOCALEMana DigitalRemembers the language you choseNecessary1 year
_clckMicrosoft ClarityLinks your visits to an anonymous identifierStatistics1 year
_clskMicrosoft ClarityConnects page views within a single sessionStatistics1 day
CLIDMicrosoft ClarityIdentifies whether this is your first visitStatistics1 year
_gaGoogle AnalyticsDistinguishes visitors using an anonymous identifierStatistics2 years
_ga_5PVVP89VTEGoogle AnalyticsSession state for this measurement propertyStatistics2 years

Beyond the above, Microsoft and Google may set further technical cookies tied to their own accounts (for example MUID, ANONCHK, MR, SM). These too are placed only if you consent to statistics.

8. Web analytics services

We use two web analytics services. Both are activated only after statistics cookies are accepted.

ServicePurposeLegal basisActivation
Microsoft ClarityUsage analysis, UX improvementConsentAfter statistics cookies are accepted
Google Analytics 4Traffic statisticsConsentAfter statistics cookies are accepted

Microsoft Clarity

Purpose
Analysing how the website is used and improving the user experience, producing heatmaps and session recordings.
Activation
Only after statistics cookies are accepted.
Data processed
Clicks, scrolling, cursor movement, page interaction and technical events, device and browser data, approximate location derived from the IP address.
Provider
Microsoft Ireland Operations Limited
Retention
Recordings are available for 30 days, aggregated statistics for up to 13 months.
Note
A recording is tied not to your name but to a random identifier stored in a cookie. Clarity masks text you type by default, and in the client portal we additionally mask every element that identifies a client. Clarity also runs in the client portal; Google Analytics does not.

Google Analytics 4

Purpose
Traffic statistics: which pages are opened, where visitors arrive from, what device they use.
Activation
Only after statistics cookies are accepted.
Data processed
Pages visited, source of the visit, technical identifiers, device and browser data, approximate location derived from the IP address.
Provider
Google Ireland Limited
Retention
Up to 14 months, per the property's configuration.
Note
The measurement code denies storage for advertising, ad user data and personalisation purposes by default, so consenting to statistics does not on its own switch on remarketing.

Google Tag Manager

We do not use a Google Tag Manager container. The Google Analytics measurement code loads from the googletagmanager.com domain — that is Google's tag library, not Tag Manager. Should we introduce Tag Manager later, it performs no statistics or marketing processing on its own, and the services it manages activate strictly in line with the consent you gave.

9. Marketing services

We currently use no marketing measurement code — no Meta Pixel, no LinkedIn Insight Tag, no other advertising audience tool — and we place no marketing cookies on the website.

If that changes, the service in question will appear in this section in the same structure used in section 8 — purpose, activation, data processed, provider, retention — the cookie banner will gain a marketing category, and this notice's version number will be raised. Marketing processing never starts without consent.

10. Contact forms and client data

Contact and discovery form

We receive what you submit by email and use it to answer your enquiry and to prepare a proposal. Form content does not go into a database or a CRM — it lives in our mailbox. We do not send newsletters based on this data; that requires a separate subscription.

Newsletter

Subscribing takes only an email address. Every message carries an unsubscribe link, and unsubscribing takes effect immediately. The newsletter and the portal's emails are two different things: the sign-in link is a system message tied to performing the contract, so unsubscribing from the newsletter does not affect signing in.

Client portal

The client portal has no passwords. To sign in, we email you a link valid for 15 minutes; after a successful sign-in we place a session cookie readable only by the server, valid for 30 days. We log who signed in and when, and which proposal they opened — we use this to follow up on proposals and to check access for security. The log holds no IP address, and is kept for at most one year after access ends, enforced by automatic deletion.

For sign-in attempts we use the email address and the IP address solely for abuse protection, to limit the number of requests, and only transiently in memory. We do not store this in a database and do not link it to the activity log.

Client and partner relationships

To prepare and perform a contract and to stay in touch, we process the contact person's name, role and business contact details, along with the project's communication. We do not collect private data. Billing data must be retained for the period prescribed by accounting law, and we cannot make an exception to that even on a deletion request.

Job applications

The application is seen by those involved in the selection, and kept for six months after the process closes. With your explicit consent we keep it for a year, so we can approach you about a later role.

11. Processors

We use the providers below, each under a data processing agreement. We do not sell data and do not pass it to third parties for their own marketing purposes.

ProcessorWhat it doesLocation
Vercel Inc.Hosting, serving and logging of the website and the client portalUnited States
Neon, LLC (part of Databricks, Inc.)The client portal database, in a European regionUnited States
Resend, Inc.Email delivery: form notifications, sign-in links, newsletterUnited States
Google Ireland LimitedGoogle Analytics 4Ireland
Microsoft Ireland Operations LimitedMicrosoft ClarityIreland
CookieYes LimitedCollecting and logging cookie consentUnited Kingdom

In addition, our accountant and — in the event of a legal claim — our legal counsel may access the data they need, and we may disclose data at the request of an authority or court where the law requires it. Where possible, we will inform you of such a request.

Each provider's own privacy notice is available directly here:

12. Transfers outside the European Union

This section states the rules of transfer once, for every service above.

Some of our processors operate in the United States, so certain processing operations involve a transfer to a third country. In those cases the transfer is based on the European Commission's EU-U.S. Data Privacy Framework adequacy decision or on the standard contractual clauses adopted by the Commission, with the additional technical and organisational safeguards required. CookieYes operates in the United Kingdom, which is covered by an adequacy decision.

We send a copy of the safeguards applied on request at hello@ineedmana.io.

13. Security and data breaches

We apply technical and organisational measures proportionate to the risk:

If a personal data breach occurs, we contain access, assess which categories of data are affected, and document the breach. If it is likely to result in a risk to your rights, we report it to the Hungarian supervisory authority (NAIH) within 72 hours of becoming aware of it. If the risk is high, we also inform you directly without undue delay.

14. Your rights

This section states your rights once, for every processing activity above.

We accept requests at hello@ineedmana.io and respond within 1 month of receipt at the latest. If a request is complex, we may extend that by up to 2 further months, and we will tell you within the first month. The procedure is free of charge.

Your request is handled faster if it states which right you wish to exercise, what exactly it concerns, and a contact address for our reply. If we cannot identify you beyond doubt, we may ask for additional information.

15. Complaints and remedies

If you believe our processing does not comply with the law, we would appreciate hearing it directly at hello@ineedmana.io first. Independently of that, you may lodge a complaint with the supervisory authority:

Authority
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address
Falk Miksa utca 9-11., 1055 Budapest, Hungary
Postal address
1363 Budapest, Pf. 9., Hungary
Phone
+36 (1) 391-1400
Email
ugyfelszolgalat@naih.hu
Website
naih.hu

You may also go to court. You may bring proceedings against us as controller if our processing infringed your rights, and you may also seek judicial remedy against a decision of the authority. Proceedings may be brought before the Miskolc Regional Court, which has jurisdiction over our registered office, or at your choice before the tribunal of your place of residence or stay. The court handles such cases out of turn, and you can find the competent court using the court finder at birosag.hu.

16. When we act as a processor for a client

In client projects — when we build or operate a system, or run a campaign — we often work with data about our client's end users, customers or prospects. There we are not the controller: our client is, and we act as a processor under Article 28 GDPR, on the basis of a written data processing agreement and the client's instructions.

In practice this means we use the data solely to deliver the engagement and never for our own purposes, and at the end of the engagement we return or delete it as the client decides. Subcontractors and further processors are engaged within the framework of the agreement signed with the client. Whatever this notice does not cover is governed by that contract.

If you provided your data through a client's product or service, that company's own notice governs the processing, and that is where you can exercise your rights. If you are unsure who to turn to, write to us and we will help you find the right controller.

17. Other provisions

Children's data

Our services are aimed at companies, and our website is not intended for children under 16. We do not knowingly collect data relating to anyone under 16. If such data reaches us, we delete it without delay.

Automated decision-making and profiling

We do not use solely automated decision-making or profiling that would produce legal effects concerning you or similarly significantly affect you. We use statistics in aggregated form to improve the website.

Applicable law