Privacy policy
Last updated: 3 August 2026
Introduction – who we are
This privacy policy explains how personal data is processed in connection with the Consia service. It is issued by Széll Máté Csongor, a Hungarian sole trader (egyéni vállalkozó), who operates both this website and the Consia platform.
- Name: Széll Máté Csongor e.v.
- Registration number (nyilvántartási szám): 54494969
- Tax number (adószám): 55768568-1-29
- Registered seat: H-4032 Debrecen, Kosztolányi Dezső utca 4., Hungary
- Contact email: [email protected]
Consia is a software-as-a-service (SaaS) platform that lets service providers – beauty salons, tattoo and permanent make-up artists, and private clinics – collect declarations of consent (statements) digitally from their customers (declarants) for treatments, replacing paper consent forms. The declarant signs on their own phone via a link or QR code; no account is required.
This policy draws an important distinction based on the role we play in each processing activity, and is therefore divided into two parts. Part A describes the marketing website's own minimal processing; Part B describes the personal data processed through the Consia platform.
Scope – Part A and Part B
Part A – This website: the independent processing carried out by the consia.hu marketing website. For this processing, Széll Máté Csongor e.v. is the data controller.
Part B – The Consia platform / product: the processing of customer data (statements) collected by service providers through the platform. For this data, the service provider is the data controller and Consia (Széll Máté Csongor e.v.) acts as a data processor under a data processing agreement (DPA) signed with each provider. Note, however, that for provider-account data (data about the provider as our own customer), Consia is the controller.
PART A – THIS WEBSITE
This part covers the processing associated with visiting the consia.hu marketing website. The site is static and serves marketing and informational purposes.
What data we process
The website is intentionally minimal in its data processing. We use no analytics, no tracking, and no advertising cookies. There is no contact form; the only interactive element is a mailto: link, which opens a message to [email protected] in your own email client.
The website stores a single functional value in your browser's localStorage: your language preference (hu/en). This is not a cookie, is not sent to any server, and does not constitute personal data. Its sole purpose is to display the website in the language you have chosen.
Server logs and hosting
The website is served on the DigitalOcean App Platform, delivered via the Cloudflare CDN. To deliver the website and keep it secure, the hosting and CDN providers may process standard server access logs, which can include your IP address, the time of the request, the page requested, and your browser identifier (user-agent). The legal basis for this processing is our legitimate interest in providing the service and maintaining network security (Article 6(1)(f) GDPR).
Purposes and legal bases
- Remembering your language preference: stored locally in your browser; no personal data is processed.
- Serving and securing the website (server logs): legitimate interest (Article 6(1)(f) GDPR).
- Email contact (mailto): if you write to us, we process the data contained in your email to the extent needed to respond; legal basis: our legitimate interest in responding to your enquiry (Article 6(1)(f) GDPR).
Retention – Part A
Server-side logs are handled according to the hosting and CDN providers' own short retention periods. Email correspondence with you is retained after your enquiry is closed for as long as our legitimate interest persists and for any period needed to establish or defend legal claims.
PART B – THE CONSIA PLATFORM / PRODUCT
This part explains how we process the personal data contained in the statements signed by declarants (the service providers' customers) through the Consia platform. Importantly, for this data the service provider (for example, the salon or private clinic) is the data controller, and Consia acts as a data processor on the provider's documented instructions (Article 28 GDPR). If you are a declarant and wish to exercise your rights, you should as a rule address your request to the relevant service provider; Consia, as processor, will assist in fulfilling it.
What data we process
The personal data collected in statements – the standard fields for Hungarian legal declarations – may include:
- full name,
- maiden name,
- mother's name,
- place of birth,
- date of birth,
- email address,
- the declarant's answers to the provider's treatment questions.
In addition, signing evidence is stored for each signed statement (see How signing works and what evidence is stored, below).
Special-category (health) data
Every statement includes a mandatory, platform-controlled health-data consent checkbox under Article 9 GDPR. No statement can be saved or signed unless this checkbox is ticked. Health data is special-category personal data under Article 9 GDPR and is processed solely on the basis of the data subject's explicit consent (Article 9(2)(a) GDPR).
Purposes and legal bases
The purpose of processing the data in statements is to document informed consent before a treatment is provided, and to preserve authentic, subsequently verifiable evidence that the declaration was made. The legal bases are:
- for the declaration (consent) itself: the data subject's consent (Article 6(1)(a) GDPR);
- for health (special-category) data: the data subject's explicit consent (Article 9(2)(a) GDPR);
- the provider may additionally rely on legitimate interest or a legal obligation to retain the record (Article 6(1)(f) and (c) GDPR);
- Consia, as a data processor, acts in every case on the provider's documented instructions, in accordance with Article 28 GDPR.
How signing works and what evidence is stored
The declarant opens the statement on their own phone via a link or QR code, without creating an account. Signing is carried out using a simple electronic signature (SES): ticking the checkbox(es), opening an authentication link, and typing their full name. Qualified (eIDAS) timestamps are not currently implemented and are not used.
To ensure the authenticity and integrity of the signature, the following evidence is stored per signature:
- the exact wording shown in the statement,
- the template version,
- the declarant's answers,
- an HMAC-SHA256 content hash (to prove integrity and tamper-evidence),
- the server-side signed-at timestamp,
- the IP address,
- the browser identifier (user-agent),
- the authentication method,
- the locale (language setting).
A PDF of the signed statement is generated on demand from the stored data; the PDF itself is never stored.
Confirmation email
After signing, the declarant receives their signed statement by email as a PDF attachment. Delivery is carried out via our email sub-processor (see the sub-processor table).
Sub-processors and international transfers
We use the following sub-processors (further processors) to provide the service. All of them operate within the European Union under appropriate data processing agreements (DPAs) and, where relevant, standard contractual clauses (SCCs). The data contained in statements is not transferred outside the EU.
| Sub-processor | Role | Location | Purpose |
|---|---|---|---|
| DigitalOcean | Hosting and database | Frankfurt (fra1), Germany | Operating the platform and storing the Managed PostgreSQL database |
| Resend (delivering via AWS SES) | Email delivery | AWS SES eu-west-1, Ireland | Delivering confirmation emails and the PDF attachment |
| Sentry (EU region) | Error monitoring | European Union | Detecting and fixing application errors; personal and health data are scrubbed before sending |
| Cloudflare | CDN / edge | European Union | Delivering content and strengthening the security of the service |
Personal and health data are scrubbed from the data sent to the Sentry error-monitoring system before it is transmitted. The list of sub-processors may change from time to time; we will inform you of material changes by updating this policy.
Retention and erasure
Signed statements carry a retention period. By default this is aligned to the Hungarian civil limitation period (five years under Section 6:22 of the Hungarian Civil Code, Ptk.). When the retention period lapses, the signed statement is automatically and permanently purged by the system.
Erasure requests are handled in accordance with Article 17 GDPR. Please note that, under Article 17(3)(e) GDPR, the service provider (controller) is entitled to retain a record where this is necessary for the establishment, exercise, or defence of legal claims.
Withdrawal versus erasure
The confirmation email contains a self-service link through which the declarant can withdraw their consent going forward (Article 7(3) GDPR). Withdrawing consent does not affect the lawfulness of consent-based processing carried out before withdrawal, and does not, in itself, delete the authentic, previously recorded evidence of a signature that has already taken place.
Withdrawal therefore ends consent for the future, whereas erasure (under Article 17 GDPR, subject to the limitations above) is directed at removing the stored record itself.
Data-subject rights and how to exercise them
Under applicable law, data subjects have the following rights:
- access to their data,
- rectification,
- erasure,
- restriction of processing,
- data portability,
- objection,
- withdrawal of consent.
For declarant data, requests should as a rule be submitted to the relevant service provider (the controller); Consia, as processor, assists in fulfilling them. We respond to requests within 30 days of receipt, and assist the provider within that period. Contact: [email protected].
Security
We apply appropriate technical and organisational measures to protect personal data. These include, among others, an HMAC-SHA256 content hash proving the integrity of signed content, encrypted data transmission, storage of data within the European Union, and scrubbing personal and health data from data sent to our error-monitoring system.
Children
The Consia platform is intended solely for the statements of adults (persons aged 18 or over). We do not knowingly collect the data of minors. Verifying that the declarant is of age is the responsibility of the service provider (the controller).
Changes to this policy
We may amend this policy from time to time, for example in response to changes in the law or changes to the service or to the sub-processors we use. The current version is always available on this page; we will indicate material changes by updating the Last updated date.
Contact and supervisory authority
You can send questions or requests concerning data processing to [email protected].
If you consider that the processing of your data infringes the law, you may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):
- Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
- Web: naih.hu
You also have the right to seek a judicial remedy.