Effective: 27 August 2026

Document version: 1.1.0

Privacy Notice

This notice explains which personal data we process, for what purposes and for how long, who may receive it, and how you can exercise your data-protection rights.

This English text is provided for information and convenience. If it differs from the Hungarian version, the Hungarian text governs.

1. Data controller

Controller
Data Engineering Solutions Kft.
Brand
DES Hosting
Registered office
8000 Székesfehérvár, Nagyváradi utca 15.
Company registration number
07-09-037589
Tax number
33052645-2-07
Privacy contact
hello@deshosting.hu
Telephone
+36 30 788 7011

Based on the current processing activities, appointing a data protection officer is not mandatory and no separate DPO has been appointed. Privacy questions and requests may be submitted to the email address above.

2. Scope and principles

This notice applies to personal-data processing in connection with the Website at www.deshosting.hu, the DES Hosting Customer Portal, web hosting, domains, billing, payments, customer support and legal administration.

Personal data is processed only for specified lawful purposes, to the extent and for the time necessary. Appropriate technical and organisational measures protect it against unauthorised access, alteration, disclosure, loss and destruction.

3A. AI-powered customer-support chat

Data
The full conversation, including the user’s questions and the AI assistant’s answers, together with the random end-user identifier, response identifiers, language setting, IP address, timestamps and related technical logs.
Purpose
Answering visitor questions, maintaining conversation continuity and secure operation, and training the AI model and improving the assistant.
Legal basis
Article 6(1)(a) GDPR: the data subject’s consent. Use of the chat is voluntary; withholding consent does not affect use of the Website or non-AI customer-support channels.
Retention
The full conversation and related identifiers are retained in local browser storage for 30 minutes after the last message. Data set aside for AI-model training is processed for as long as necessary for that development purpose or until consent is withdrawn, unless further retention is required for legal claims or by law.
Recipients and transfers
The conversation is processed by the AI backend operated for DES Hosting. Data is not transferred outside the European Economic Area.

Before starting the chat, the visitor consents to storage of the full conversation and its use for model training. The consent timestamp and version are retained in local browser storage until withdrawal, deletion of site data or a material change to the consent terms, so consent does not need to be repeated in the same browser. The withdrawal function below prevents future use in that browser and removes the local conversation. The locally stored conversation can also be removed with the “New conversation” function or by deleting the browser’s site data. There is currently no self-service server-side deletion function; full withdrawal of consent and a GDPR erasure request may be submitted through the privacy email address in section 1.

No active AI-training consent is stored in this browser.

The AI assistant can make mistakes and its response is not an individual offer, contractual statement or customer-service decision. Passwords, payment-card data, special-category personal data and other unnecessary confidential information must not be entered in the chat.

3. Website, log data and browser storage

Data
IP address, request time, visited page or resource, HTTP status, browser and device technical data, and security-event logs.
Purpose
Operating and troubleshooting the Website, performance, information security, and detecting and preventing misuse and attacks.
Legal basis
Article 6(1)(f) GDPR: legitimate interest in operating a secure and reliable service.
Retention
Technical logs are generally retained for up to 30 days. Data needed for a security incident, dispute or official procedure may be retained until closure and the end of the applicable limitation period.

To assemble an order, the Website may store the selected plan, domain and ordering state in local or session storage on the user’s device. This is removed on handoff, deletion or according to browser settings.

The Customer Portal may use cookies strictly necessary for login, session, security and ordering. The public Website does not use advertising or profiling cookies.

3B. Web analytics

Provider
Google Analytics 4 (Google Ireland Limited)
Data
Online identifiers, IP address and approximate location derived from it, device and browser data, visited pages, referring page, and the time and technical events of the visit.
Purpose
Measuring Website traffic and use, identifying errors, and improving content and user experience.
Legal basis
Article 6(1)(a) GDPR: the data subject’s prior consent.
Operation and withdrawal
The Google Analytics tag loads only after analytics consent. Consent is communicated through Google Consent Mode v2 signals; advertising storage, user data and personalisation remain denied. The browser stores the decision locally and it can be changed at any time with the “Cookie settings” button at the bottom of the Website.

Refusing consent does not limit use of the Website. Google may also act as an independent controller when providing the service, and data may be transferred outside the European Economic Area subject to the appropriate safeguards used by Google. Previously stored analytics data can be removed by deleting the Website’s browser data.

4. Customer account, order and contract

Data
Name, residential or registered address, email, telephone, customer and account identifiers, encrypted password, optional two-factor authentication data, company, tax and registration details, representative and contacts, order and contract data, IP address, timestamps and accepted declarations.
Purpose
Creating and protecting an account; handling enquiries and orders; concluding and performing contracts; contact; activation, amendment, renewal and termination; and legal claims.
Legal basis
Article 6(1)(b) GDPR for contract and pre-contract steps; Article 6(1)(f) for contacts of legal entities; Article 6(1)(c) for mandatory records.
Retention
While the account and service are active; contract and claim data for five years after termination; accounting-document data for at least eight years.

Mandatory fields are necessary to create an account, process an order or perform a contract. The Customer Portal operates under the Service Provider’s responsibility on rented infrastructure. Using licensed portal software does not itself transfer data to its manufacturer.

5. Web hosting and security backups

Data
Content uploaded to or created in hosting, databases and mailboxes; account and access data; domain connections; technical logs; IP addresses; resource and fault information.
Purpose and basis
Supplying hosting, database and email services under Article 6(1)(b) GDPR; system security and misuse prevention under Article 6(1)(f).
Retention
For the service term. Customer data remains restorable for 14 days after termination and may then be permanently deleted. Daily backups rotate over 14 days.

Where a customer processes personal data of its own users or other data subjects in hosting, the customer is generally the controller and DES Hosting acts as processor on its instructions. A separate data processing agreement governs details where required.

6. Domain registration and administration

Data
Applicant or registrant name, address, email, telephone, organisation and representation details, administrative and technical contacts, selected domain, EPP or authorisation code, and registry-required evidence and declarations.
Purpose and basis
Availability checking, registration, transfer, maintenance, renewal and related dispute resolution under Article 6(1)(b) and (c) GDPR and, for contacts where applicable, Article 6(1)(f).
Recipients
The contracted registrar partner, domain registry, technical registry and dispute-resolution body applicable to the chosen extension.
Retention
For the domain transaction and contract, then five years for claim-related data. Registries may retain data for different periods under their own rules and laws.

Some international registrars or registries operate outside the EEA. Only data necessary for the relevant domain is transferred, to the extent required for contract performance and with applicable transfer safeguards.

7. Payments and billing

Payment data
Customer and order identifier, amount, currency, payment method, transaction identifier and status, and technical data returned by the payment provider.
Billing data
Name or company, billing address, tax number, email, service, performance, amount, tax and other mandatory invoice data.
Purpose and basis
Processing payment under Article 6(1)(b) GDPR and issuing and retaining invoices under Article 6(1)(c).
Retention
Transaction data for five years after the contract ends; invoices and supporting accounting data for at least eight years.

Raiffeisen Bank Zrt. for bank transfers, the card payment provider available in the Customer Portal, and PayPal for PayPal transactions act as independent controllers for payment data they require. DES Hosting does not store full card numbers, security codes or PayPal passwords. Providers process data under their own privacy notices.

Electronic invoices are issued, stored and delivered using Számlázz.hu, operated by KBOSS.hu Kft., as processor.

8. Contact, support and illegal-content notices

Data
Name, email, telephone, company, customer and service identifiers, topic, message and attachments, location of reported content, good-faith statement, correspondence and technical data, and actions taken.
Legal basis
Contract or pre-contract steps under Article 6(1)(b) GDPR; legitimate interest for general enquiries and security under Article 6(1)(f); legal obligation for illegal-content notices and mandatory official cooperation under Article 6(1)(c).
Retention
Five years after closure for contract-related matters and illegal-content notices; one year after closure for other general enquiries, unless a dispute or mandatory procedure requires longer.

Where legally permitted, an illegal-content notice may be submitted without a name or email. An automated receipt and direct updates are possible only if contact details are provided.

9. Withdrawal, termination and complaints

Data
Declaration type, name, email, residential address, order or contract identifier, service, contract and submission times, note, and for complaints their content, evidence, response and action taken.
Purpose and basis
Exercising consumer rights, investigating complaints and related settlement under Article 6(1)(b) and (c) GDPR and, for legal claims, Article 6(1)(f).
Retention
Withdrawal or termination declarations and resulting settlement data for five years; consumer complaint records and response copies for three years; at least eight years where part of accounting documentation.

10. Processors and other recipients

Contabo GmbH

processor

server, network and infrastructure services

Aschauer Straße 32a, 81549 Munich, Germany (EEA)

KBOSS.hu Kft. – Számlázz.hu

processor

issuing, storing and delivering electronic invoices

1031 Budapest, Záhony utca 7., Hungary (EEA)

Raiffeisen Bank Zrt.

independent controller

bank transfers and related payment operations

1133 Budapest, Váci út 116–118., Hungary (EEA)

PayPal and the selected card payment provider

independent controller

online payments, fraud prevention and legally required checks

EEA and possible third-country processing locations described in the provider’s notice

Contracted domain registrars and registries

processor or independent controller, depending on the process

domain registration, transfer, maintenance and dispute resolution

EEA or a third country, depending on the chosen extension

Data may also be disclosed to accountants, legal or IT providers to the extent necessary for their task, and to courts, authorities or other mandatory recipients on a lawful request. Access is always limited to the necessary data and period.

11. Transfers to third countries

DES Hosting’s main infrastructure and Számlázz.hu processing are in the EEA. Personal data may leave the EEA when using an international domain, PayPal or another global payment service.

Such transfers rely on an adequacy decision, European Commission standard contractual clauses, another safeguard under Article 46 GDPR, or exceptionally an Article 49 basis necessary to perform the contract at the data subject’s request. Information on the specific safeguard is available from the privacy contact.

12. Data-subject rights

A data subject may request access, rectification, erasure or restriction of processing, may have a right to data portability, and may object to processing based on legitimate interests. Consent may be withdrawn at any time without affecting earlier lawful processing.

Requests may be sent to hello@deshosting.hu or the Controller’s registered office. We generally respond within one month; where justified, this may be extended by two further months. Additional identification may be requested to protect the data subject.

A complaint may be lodged with the Hungarian National Authority for Data Protection and Freedom of Information: 1055 Budapest, Falk Miksa utca 9–11.; postal address: 1363 Budapest, Pf. 9.; email: ugyfelszolgalat@naih.hu; website: naih.hu. Judicial remedies are also available.

13. Automated decisions and data security

DES Hosting does not use solely automated decision-making or profiling that produces legal or similarly significant effects. Automated technical operations may create accounts, services or invoices or limit suspected misuse; human review may be requested in a disputed case.

Security measures include encrypted transmission, access control, permissions management, logging, backups and regular security updates. For a personal-data breach, risk is assessed under the GDPR, the supervisory authority is notified where required, and affected persons are informed where risk is high.

14. Changes to this notice

This notice is updated for changes in law, new services or processors, or material changes in processing. The current version remains available on the Website. Data subjects will also be appropriately informed where a change materially affects their rights or the purpose of processing.