Privacy Policy

Boojum Kft. (hereinafter: Data Controller), as the operator of the website available under the domain name feedbooster.io (hereinafter: Website), hereby publishes the rules, data protection and data processing principles and information applicable to the processing of personal data carried out through the Website.

By starting to use the Website and by ticking the box provided for this purpose, visitors of the Website and users of the Data Controller’s services (hereinafter: User) accept all the terms set out in this Privacy Policy (hereinafter: Policy); therefore, please read this Policy carefully before using the Website.

1. Details of the Data Controller

BOOJUM Online Marketing Korlátolt Felelősségű Társaság
Registered office: 8600 Siófok, Szabadi út 35.,
Hungary Tax number: 23512784-2-14
EU Tax number: HU23512784
Company registration number: 14-09-311852
E-mail address: hello@jabjab.hu

2. Information on the individual processing activities

Registration, access

No prior registration or provision of personal data is required to view the textual content published on the Website; it can be read freely, free of charge and without any consideration, by clicking on the title of the article.

The operator of the Website reserves the right to make certain content available to the User only after prior registration in the future; the operator of the Website will inform the User of the detailed data protection principles of such registration before it takes place.

The operator of the Website reserves the right to restrict some or all of the freely available content for certain Users if the User’s activity or activities cause a malfunction in the operation of the Website or amount to vandalism.

Contact, quote request

Scope of data processed

On the Quote Request form available on the Website, the User may provide their details in order to receive information or to make comments regarding the Data Controller’s activities (hereinafter: Contact). The following data may be provided during Contact (fields marked with * are mandatory):

  • full name*
  • company name*
  • e-mail address*
  • phone
  • selected product package*
  • name of the website concerned*
  • message

Purpose of the processing

Providing information about the Data Controller’s services and activities, including establishing and maintaining contact with the interested User, informing the User, and handling comments regarding the Data Controller’s activities.

Duration of the processing

The Data Controller deletes the User’s personal data without delay after the two-way communication has been closed, and also if the User requests the deletion of their data or withdraws the consent given to the processing of their personal data.

Legal basis of the processing

The User’s explicit consent (given by ticking the box provided for accepting this Policy) pursuant to Article 6(1)(a) of the GDPR.

Only persons who have reached the age of 18 are entitled to provide data!

3. Persons entitled to access personal data; data processors

The Data Controller is entitled to access personal data in accordance with the applicable legislation.

The Data Controller uses the following data processor in the course of the processing:

Websupport Magyarország Kft. (registered office: 1132 Budapest, Victor Hugo utca 18-22., Hungary; e-mail: info@mhosting.hu)

Purpose of the data processing

Providing the technical background required for the operation of the Website.

The Data Controller reserves the right to involve further data processors in the processing in the future, of which it will inform the Users by amending this Policy.

In the absence of an explicit legal provision, the Data Controller transfers personally identifiable data to third parties only with the explicit consent of the User concerned.

4. Rights of the User

Access to personal data

At the User’s request, the Data Controller provides information on whether it processes the User’s personal data and, if so, grants access to the personal data and informs the User of the following:

  • the purpose(s) of the processing;
  • the categories of personal data concerned;
  • in the event of a transfer of the User’s personal data, the legal basis and the recipient(s) of the transfer;
  • the envisaged duration of the processing;
  • the User’s rights regarding the rectification, erasure and restriction of processing of personal data, as well as the right to object to the processing of personal data;
  • the right to lodge a complaint with the Authority;
  • the source of the data;
  • meaningful information about any profiling;
  • the name and address of the data processors and their activities related to the processing.

The Data Controller provides a copy of the personal data undergoing processing to the User free of charge. For any further copies requested by the User, the Data Controller may charge a reasonable fee based on administrative costs. Where the User makes the request by electronic means, the information shall be provided in a commonly used electronic form, unless otherwise requested by the data subject.

The Data Controller shall provide the information at the User’s request without undue delay, but no later than one month from the submission of the request, in an intelligible form. The User may submit a request for access via the contact details specified in Section 1.

Rectification of processed data

The User may request the Data Controller (via the contact details specified in Section 1) to rectify inaccurate personal data and to complete incomplete data, taking into account the purpose of the processing. The Data Controller carries out the rectification without undue delay.

Erasure of processed data (right to be forgotten)

The User may request that the Data Controller erase the personal data concerning them without undue delay, and the Data Controller is obliged to erase the personal data concerning the data subject without undue delay where one of the following grounds applies:

  1. the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
  2. the User withdraws consent and there is no other legal basis for the processing;
  3. the User objects to the processing of their personal data;
  4. the personal data have been unlawfully processed;
  5. the personal data have to be erased for compliance with a legal obligation under Union or Member State law to which the Data Controller is subject;
  6. the personal data have been collected on the basis of consent in relation to the offer of information society services to children.

Where the Data Controller has made the personal data public (made them available to a third party) and is obliged to erase them under the above, it shall, taking account of available technology and the cost of implementation, take reasonable steps and measures to inform the controllers processing the personal data concerned that the User has requested the erasure by such controllers of any links to, or copies or replications of, those personal data.

The personal data need not be erased where the processing is necessary:

  • for exercising the right of freedom of expression and information;
  • for compliance with a legal obligation which requires processing under Union or Member State law to which the Data Controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
  • for reasons of public interest in the area of public health;
  • for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, in so far as the right to erasure is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
  • for the establishment, exercise or defence of legal claims.

Restriction of processing

The User is entitled to request that the Data Controller restrict the processing instead of rectifying or erasing the personal data where one of the following applies:

  • the User contests the accuracy of the personal data, in which case the restriction applies for a period enabling the Data Controller to verify the accuracy of the personal data;
  • the processing is unlawful and the User opposes the erasure of the data and requests the restriction of their use instead;
  • the Data Controller no longer needs the personal data for the purposes of the processing, but they are required by the User for the establishment, exercise or defence of legal claims; or
  • the User has objected to the processing; in this case the restriction applies for the period pending the verification whether the legitimate grounds of the Data Controller override those of the data subject.

Where processing has been restricted, such personal data shall, with the exception of storage, only be processed with the User’s consent or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State.

The Data Controller informs the User who has obtained the restriction of processing before the restriction is lifted.

Notification obligation regarding rectification or erasure of personal data or restriction of processing

The Data Controller communicates any rectification or erasure of personal data or restriction of processing to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort. The Data Controller informs the User about those recipients if the User requests it.

Right to object

The User may object to the processing of their personal data where the processing is

  • necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
  • necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party;
  • based on profiling.

In the event of the User’s objection, the Data Controller shall no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the User, or for the establishment, exercise or defence of legal claims.

Action taken by the Data Controller on the User’s request

The Data Controller informs the User without undue delay, and in any event within one month of receipt of the request, of the action taken on a request for access, rectification, erasure, restriction, objection or data portability. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. The Data Controller informs the User of any such extension within one month of receipt of the request, together with the reasons for the delay. Where the User makes the request by electronic means, the information shall be provided by electronic means where possible, unless otherwise requested by the data subject.

If the Data Controller does not take action on the User’s request, it informs the User without delay, and at the latest within one month of receipt of the request, of the reasons for not taking action and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.

Information, communication and any action taken on the User’s request shall be provided free of charge. Where the User’s request is manifestly unfounded or excessive, in particular because of its repetitive character, the Data Controller may, taking into account the administrative costs of providing the information or communication or taking the action requested, either charge a reasonable fee or refuse to act on the request. The Data Controller bears the burden of demonstrating the manifestly unfounded or excessive character of the request.

5. Handling and notification of personal data breaches

A personal data breach is any event which, in relation to personal data processed, transferred, stored or handled by the Data Controller, results in the unlawful processing or handling of personal data, in particular unauthorised or accidental access, alteration, disclosure, erasure, loss or destruction, as well as accidental destruction or damage.

The Data Controller is obliged to notify the personal data breach to the NAIH without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the Data Controller is able to demonstrate that the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification cannot be made within 72 hours, it shall be accompanied by the reasons for the delay, and the required information may be provided in phases without undue further delay. The notification to the NAIH shall contain at least the following information:

  • the nature of the personal data breach, the number and categories of data subjects and personal data concerned;
  • the name and contact details of the Data Controller;
  • the likely consequences of the personal data breach;
  • the measures taken or proposed to address, remedy and mitigate the personal data breach.

Where the personal data breach is likely to result in a high risk, the Data Controller informs the data subjects of the personal data breach through the Data Controller’s website within 72 hours of detecting the breach. The information shall contain at least the data specified in this section.

The Data Controller keeps a record of personal data breaches for the purpose of verifying the measures taken in relation to the breach and informing the data subjects. The record contains the following data:

  • the categories of personal data concerned;
  • the categories and number of data subjects concerned;
  • the date of the personal data breach;
  • the circumstances and effects of the personal data breach;
  • the measures taken to remedy the personal data breach.

The Data Controller retains the data in the record for 5 years from the detection of the personal data breach.

6. Data security

The Data Controller undertakes to ensure the security of the data, to take the technical and organisational measures and to establish the procedural rules that ensure that the data collected, stored and processed are protected, and that prevent their destruction, unauthorised use and unauthorised alteration. It also undertakes to call upon every third party to whom it transfers or hands over data on the basis of the Users’ consent to comply with the requirements of data security.

The Data Controller ensures that unauthorised persons cannot access, disclose, transfer, modify or delete the processed data. The processed data may only be accessed by the Data Controller, its employees and the Data Processor it engages; the Data Controller does not hand them over to any third party not authorised to access the data.

The Data Controller makes every effort to ensure that the data are not accidentally damaged or destroyed. The Data Controller imposes the above undertaking on its employees involved in the processing activities.

The User acknowledges and accepts that when providing personal data on the Website, the protection of the data cannot be fully guaranteed on the Internet, even though the Data Controller has state-of-the-art security tools in place to prevent unauthorised access to or interception of the data. Should unauthorised access to or acquisition of data occur despite our efforts, the Data Controller is not liable for such acquisition of data or unauthorised access, or for any damage suffered by the User for these reasons. In addition, the User may also disclose their personal data to third parties who may use them for unlawful purposes or in an unlawful manner.

7. Legal remedies

The Data Controller makes every effort to process personal data in compliance with the law; however, if the User feels that this has not been the case, they may write to the contact details specified in Section 1.

If the User believes that their right to the protection of personal data has been violated, they may seek a remedy with the competent bodies in accordance with the applicable legislation:

  • the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság; address: 1055 Budapest, Falk Miksa utca 9-11., Hungary; ugyfelszolgalat@naih.hu; www.naih.hu)
  • the courts.

8. Miscellaneous provisions

This Policy is governed by Hungarian law, in particular Act CXII of 2011 on the Right to Informational Self-Determination and on Freedom of Information, and the provisions of the GDPR.

Budapest, 1 September 2026

Boojum Kft.
Data Controller