TooLaser Industrial Advisory
Privacy Policy
This Privacy Policy explains how TooLaser Kft. collects, uses, stores and protects personal data when you visit this website, contact us or submit a business enquiry.
Privacy at a glance
We collect only the information reasonably necessary to respond to enquiries, assess potential advisory engagements, operate the website securely and, where you consent, understand website usage through analytics.
- We do not sell personal data.
- We do not use personal data for automated decision-making.
- We do not use Meta Pixel on this website.
- Google Tag Manager and Google Analytics 4 will operate only after analytics consent has been provided.
- You may withdraw analytics consent through the website’s cookie settings.
1. Data controller
- Full legal name
- TooLaser Szolgáltató és Kereskedelmi Korlátolt Felelősségű Társaság
- Short name
- TooLaser Kft.
- Registered office
- 8000 Székesfehérvár, Mandula utca 22., Hungary
- Company registration number
- 07-09-018981
- Tax number
- 22924467-2-07
- Managing director
- Pázsi Zoltán
- Privacy contact
- mail@toolaser.com
Additional corporate information is available in our Legal Notice.
2. Scope of this policy
This Privacy Policy applies to the processing of personal data through the TooLaser website, its contact form, direct business communications and the technical services used to operate and protect the website.
It does not govern the independent processing activities of external websites, including LinkedIn and Facebook, which have their own privacy policies.
3. Personal data we process
Contact form and business enquiries
When you submit an enquiry or contact us directly, we may process:
- your name;
- your work email address;
- your company or organisation;
- your selected area of interest;
- the decision, project or challenge described by you;
- context, constraints and timing information;
- your privacy acknowledgement;
- the date and time of the submission;
- technical and security information associated with the submission.
Technical and usage data
When you visit the website, the website and its service providers may process technical information such as:
- IP address;
- browser and device type;
- operating system;
- requested page or resource;
- date and time of access;
- referring website;
- security and error logs;
- analytics identifiers and usage events, but only where analytics consent has been provided.
We receive personal data primarily from you. Certain technical data is generated automatically when your browser communicates with the website.
4. Purposes, legal bases and retention
| Processing activity | Purpose | Legal basis | Retention |
|---|---|---|---|
| Business enquiries and contact form submissions | Responding to enquiries, understanding the business context and discussing a potential engagement. | GDPR Article 6(1)(b), steps taken at the request of the data subject before entering into a contract; and GDPR Article 6(1)(f), our legitimate interest in handling B2B enquiries. | Up to 12 months after the last substantive communication if no engagement begins, unless longer retention is necessary for legal claims. |
| Client and contractual communications | Preparing, entering into and performing an advisory engagement and maintaining related business records. | GDPR Article 6(1)(b), contract performance; Article 6(1)(c), compliance with legal obligations; and Article 6(1)(f), establishment or defence of legal claims. | For the duration of the engagement and applicable statutory limitation or record-keeping periods. Accounting records are retained for the legally required period. |
| Website hosting and server logs | Operating, maintaining, troubleshooting and securing the website. | GDPR Article 6(1)(f), our legitimate interest in maintaining a secure and reliable website. | Normally up to 90 days, unless a security incident or legal obligation requires longer retention. |
| Cloudflare Turnstile | Distinguishing legitimate visitors from automated bots and protecting forms against abuse. | GDPR Article 6(1)(f), our legitimate interest in preventing spam, fraud and malicious activity. | According to the applicable Cloudflare retention practices. TooLaser does not use Turnstile data for marketing. |
| Google Analytics 4 | Understanding website usage, traffic sources, performance and visitor interactions. | GDPR Article 6(1)(a), your prior consent. | GA4 event-level data is retained for 14 months. The retention period is reset when new activity is recorded. Analytics cookies may remain for up to two years unless they are deleted or analytics consent is withdrawn earlier. |
| Cookie consent preferences | Remembering and demonstrating your privacy choices. | GDPR Article 6(1)(c), compliance with applicable legal obligations; and GDPR Article 6(1)(f), maintaining a reliable record of consent choices. | Normally up to 12 months, after which consent may be requested again. |
Where processing is based on legitimate interests, we have considered the necessity and proportionality of the processing and the reasonable expectations and rights of the affected individuals.
6. Service providers and recipients
Access to personal data is limited to authorised persons and service providers that require access for the purposes described in this policy.
| Provider | Service | Relevant data |
|---|---|---|
| Websupport Magyarország Kft. | Website hosting and technical infrastructure | Website content, form submissions and technical server data. |
| Google Ireland Limited and its subprocessors | Google Workspace email, Google Analytics 4 and Google Tag Manager | Business communications and, with consent, analytics and device data. |
| Cloudflare, Inc. and its affiliates | Cloudflare Turnstile form protection | Technical signals used to identify automated or malicious activity. |
We may also disclose data where required by law, a competent authority or a court, or where necessary to establish, exercise or defend legal claims.
7. International data transfers
Some service providers or their subprocessors may process personal data outside the European Economic Area.
Where required, such transfers are protected through an applicable European Commission adequacy decision, participation in the EU–US Data Privacy Framework, standard contractual clauses, or another legally recognised transfer mechanism.
8. LinkedIn and Facebook
The website may contain ordinary external links to TooLaser’s LinkedIn and Facebook pages. These links do not embed a social media feed or social tracking pixel on the TooLaser website.
When you click a social media link, you leave this website and the relevant platform processes information under its own terms and privacy policy:
9. Required and optional information
Fields marked as required in the contact form must be completed so that we can receive, assess and respond to your enquiry. If you do not provide the required information, we may be unable to respond or discuss a potential engagement.
You should not submit confidential technical information, trade secrets, special-category personal data or information that you are not authorised to disclose through the initial contact form. Sensitive project information should be exchanged only after appropriate confidentiality arrangements are in place.
10. Your data protection rights
Subject to the conditions of applicable data protection law, you may request:
- access to your personal data;
- correction of inaccurate or incomplete data;
- erasure of your personal data;
- restriction of processing;
- data portability where processing is automated and based on consent or contract;
- withdrawal of consent at any time, without affecting earlier lawful processing;
- the right to object to processing based on legitimate interests.
To exercise these rights, contact mail@toolaser.com. We may request information reasonably necessary to verify your identity before fulfilling the request.
11. Complaints and legal remedies
If you believe that your personal data has been processed unlawfully, please contact us first so that we can investigate the issue.
You also have the right to lodge a complaint with:
- Authority
- Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
- Address
- 1055 Budapest, Falk Miksa utca 9–11., Hungary
- Postal address
- 1363 Budapest, Pf. 9., Hungary
- ugyfelszolgalat@naih.hu
- Website
- https://www.naih.hu
You may also seek a judicial remedy before a competent court.
12. Data security
We use reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration, disclosure or destruction.
These measures include access controls, encrypted website communication, form protection, reputable hosting and email services, software updates and restricted access to business communications.
No method of internet transmission or electronic storage can be guaranteed to be completely secure.
13. Automated decision-making
TooLaser does not use personal data collected through this website for automated decision-making or profiling that produces legal or similarly significant effects.
14. Changes to this policy
We may update this Privacy Policy when our services, website technology or legal obligations change. The current version and its effective date will always be published on this page.
