PRIVACY POLICY

Privacy Policy

Privacy Policy

Information on how MIhely processes personal data provided during website use and contact.

Last updated: August 28, 2026.

Contact email: kapcsolat@mihely.hu

1. Purpose and Scope of this Notice

The purpose of this Privacy Notice is to provide clear, transparent, and comprehensive information to visitors of the mihely.hu website, persons interested in MIhely services, and users of the AI-based demonstration systems available on the website regarding the processing of their personal data.

This Privacy Notice applies, in particular, to the following data processing activities:

  • visiting the mihely.hu website;

  • submitting contact inquiries and requests for proposals;

  • using the AI customer service demonstration;

  • using the AI phone assistant demonstration;

  • recording, transcribing, and summarizing telephone conversations;

  • automated email and internal system notifications;

  • pre-contractual consultations;

  • subsequent customer relationship management and service delivery;

  • handling data protection requests and other data subject requests.

The Data Controller processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council, known as the General Data Protection Regulation (hereinafter referred to as the “GDPR”), as well as applicable Hungarian legislation.

2. Data Controller Information

Data Controller Name: Egyed Roland
Brand Name: MIhely – Az MI műhely
Website: mihely.hu
Email Address: kapcsolat@mihely.hu
Registered Office / Mailing Address: under preparation…
Phone Number: under preparation…

The establishment, determination of the final legal form, and registration of the business associated with the operation of MIhely are currently in progress.

Following the establishment of the business, this section will be updated with the Data Controller's final:

  • corporate or sole proprietorship name;

  • legal form;

  • registered office;

  • registration or company registration number;

  • tax identification number;

  • representative details.

Data Protection Contact: Egyed Roland
Email Address for Privacy Inquiries: kapcsolat@mihely.hu

Given the current size and nature of the Data Controller's data processing activities, no dedicated Data Protection Officer (DPO) has been appointed.

Should the subsequent expansion of the Data Controller's operations make the appointment of a DPO appropriate, or where such appointment becomes mandatory under applicable law, the Data Controller will appoint a Data Protection Officer and publish the relevant contact details.

3. Core Principles of Data Processing

The Data Controller processes personal data in strict accordance with the following principles:

  • lawfulness, fairness, and transparency;

  • purpose limitation;

  • data minimization;

  • accuracy;

  • storage limitation;

  • integrity and confidentiality;

  • accountability.

The Data Controller requests and processes only personal data that is necessary for the provision of the relevant service, demonstration, contact request, or other specified purpose.

Users are requested not to provide any of the following information through the demonstration systems:

  • health-related data;

  • political opinions;

  • religious or philosophical beliefs;

  • data concerning sex life or sexual orientation;

  • biometric or genetic data;

  • data relating to criminal convictions and offences;

  • credit card details, passwords, or other highly sensitive credentials;

  • unnecessary personal data relating to third parties.

4. Technical Data Processing Related to Website Visits

4.1. Scope of Personal Data Processed

When visiting the website, the IT systems used to operate the website may process certain technical information, including:

  • IP address;

  • date and time of access;

  • URL of the page visited;

  • technical information relating to the browser and device;

  • operating system type;

  • referring website;

  • system and error logs;

  • security log data.

4.2. Purpose of Processing

The purposes of such processing are to:

  • ensure the proper technical operation of the website;

  • display website content correctly;

  • maintain the security of the IT infrastructure;

  • identify and diagnose errors;

  • prevent misuse and unauthorized access;

  • monitor website availability.

4.3. Legal Basis for Processing

The legal basis for processing is the legitimate interest of the Data Controller in operating the website securely and efficiently and protecting its IT systems, pursuant to Article 6(1)(f) of the GDPR.

4.4. Retention Period

Technical log data is retained only for as long as necessary, in accordance with the technical and security settings of the relevant service provider.

The Data Controller does not use such technical data to personally identify website visitors and does not independently create individual visitor profiles based on this data.

5. Contact Inquiries and Requests for Proposals

5.1. Scope of Personal Data Processed

When a person contacts the Data Controller, the following personal data may be processed:

  • name of the contact person;

  • email address;

  • telephone number, if provided;

  • name of the business or organization;

  • subject of the inquiry;

  • content of the message;

  • any additional data voluntarily provided in connection with the inquiry;

  • related correspondence;

  • attached documents, where applicable;

  • date and time of the inquiry and response.

5.2. Purpose of Processing

The purposes of processing are to:

  • enable communication;

  • respond to inquiries;

  • assess service requirements;

  • prepare commercial proposals;

  • conduct pre-contractual negotiations;

  • maintain professional communication;

  • manage potential legal claims.

5.3. Legal Basis for Processing

Where an inquiry relates to requesting a proposal, preparing a contract, or taking steps at the request of the data subject prior to entering into a contract, the legal basis for processing is Article 6(1)(b) of the GDPR.

For other general inquiries, the legal basis for processing is the legitimate interest of the Data Controller in responding to inquiries and maintaining business communications, pursuant to Article 6(1)(f) of the GDPR.

5.4. Retention Period

Where a contact inquiry does not result in the conclusion of a contract, the Data Controller will generally retain the relevant personal data for 12 months following the closure of the inquiry.

Personal data may be retained for a longer period where:

  • retention is necessary for the establishment, exercise, or defence of legal claims;

  • applicable law requires a longer retention period;

  • a contractual relationship is subsequently established between the data subject and the Data Controller.

6. Data Processing for the AI Customer Service Demonstration

6.1. Purpose of the Demonstration

The AI customer service demonstration is designed to demonstrate how a system based on artificial intelligence and automated workflows can:

  • receive a customer inquiry;

  • analyse its content;

  • generate a suggested response;

  • display the result;

  • technically log the workflow;

  • generate email or internal notifications.

The demonstration does not constitute actual administrative processing, conclusion of a contract, or a binding business offer.

6.2. Scope of Personal Data Processed

When using the demonstration, the Data Controller may process the following data:

  • name;

  • email address;

  • type of business or industry;

  • the simulated customer inquiry submitted by the user;

  • unique technical request identifier;

  • date and time of submission;

  • response generated by the artificial intelligence or automated system;

  • technical processing statuses;

  • notification and delivery information;

  • error and security log data.

6.3. Purpose of Processing

The purposes of processing are to:

  • perform the requested demonstration;

  • generate a personalized demonstration result;

  • display or deliver the result to the user;

  • verify the correct operation of the workflow;

  • identify and resolve technical issues;

  • prevent misuse of the System;

  • demonstrate the Data Controller's services.

6.4. Legal Basis for Processing

The legal basis for processing is the freely given consent of the data subject pursuant to Article 6(1)(a) of the GDPR.

Consent is obtained before the demonstration is launched through a dedicated consent checkbox.

Participation in the demonstration is entirely voluntary. Refusal to provide consent does not result in any adverse consequences; however, the demonstration cannot be performed without the required consent.

6.5. Retention Period

Personal data provided during the demonstration, the generated response, and the related technical records are generally retained by the Data Controller for a maximum period of 30 days following completion of the demonstration.

Limited technical log data required for security or troubleshooting purposes may be retained for up to 90 days, unless a longer retention period is necessary for the establishment, exercise, or defence of legal claims or for the investigation of a security incident.

7. Data Processing for the AI Phone Assistant Demonstration

7.1. How the Demonstration Works

As part of the AI phone assistant demonstration, the user provides their telephone number and the basic information required for the simulation, after which an AI-powered voice system initiates an automated telephone call to the user.

The conversation is a simulated role-play scenario.

The call does not result in any actual:

  • appointment booking;

  • product order;

  • conclusion of a contract;

  • financial commitment;

  • medical or other professional decision;

  • official administrative procedure.

7.2. Scope of Personal Data Processed

During the phone demonstration, the Data Controller may process:

  • name;

  • email address;

  • telephone number;

  • type of business;

  • information provided for the purposes of the simulation;

  • start and end times of the call;

  • duration of the call;

  • call identifier;

  • call status;

  • voice recording;

  • text transcript of the conversation;

  • AI-generated summary of the conversation;

  • information disclosed during the call;

  • technical and security log data;

  • email and internal notification data.

7.3. Purpose of Processing

The purposes of processing are to:

  • conduct the requested telephone demonstration;

  • initiate the call to the user;

  • demonstrate the functionality of the AI-powered phone assistant;

  • record the call;

  • generate a transcript and summary;

  • display and deliver the results of the demonstration;

  • monitor system performance;

  • perform quality control;

  • identify and resolve errors;

  • prevent misuse and unauthorized use of the System.

7.4. Legal Basis for Processing

The legal basis for processing the telephone number and demonstration data, initiating the call, and recording and processing the conversation is the freely given, specific, and informed consent of the data subject pursuant to Article 6(1)(a) of the GDPR.

The data subject's consent to the creation and use of the voice recording is also based on Section 2:48 of Act V of 2013 on the Hungarian Civil Code.

Consent is obtained in two stages:

  1. before launching the demonstration through the website, the user accepts the applicable data processing terms and consents to the telephone call and voice recording;

  2. at the beginning of the telephone call, the automated system informs the user again that they are speaking with an AI system and that the conversation will be recorded, transcribed, and summarized.

If the user does not consent to the recording at the beginning of the call or terminates the call, the demonstration will not proceed.

7.5. Retention Period

The voice recording, transcript, summary, and personal data associated with the call are generally retained by the Data Controller for a maximum period of 30 days following completion of the call.

Limited technical and security log data may be retained for a maximum period of 90 days.

Where the data subject withdraws their consent before the expiry of the applicable retention period, the Data Controller will delete personal data processed on the basis of that consent without undue delay, unless another legal basis or statutory obligation permits or requires further retention.

8. Email and Internal System Notifications

During demonstrations, the automated System may send email notifications to:

  • the person using the demonstration;

  • a designated internal email address of the Data Controller;

  • authorized personnel involved in operating the relevant workflow.

Such notifications may include:

  • the user's name;

  • email address;

  • unique demonstration identifier;

  • specified business type;

  • result of the demonstration;

  • call or processing status;

  • generated summary;

  • necessary contact information.

When using internal messaging systems, such as Telegram, the Data Controller transmits only information that is strictly necessary for operational purposes and limits or partially pseudonymizes such information wherever reasonably possible.

Full voice recordings, complete transcripts, financial information, special categories of personal data, passwords, or other highly sensitive information must not be transmitted through internal messaging channels.

In the case of demonstrations, the legal basis for processing is the consent of the data subject.

For security-related and operational notifications, the legal basis is the legitimate interest of the Data Controller in providing services securely and effectively.

9. Contract Conclusion and Service Delivery

Where a contractual relationship is established between a prospective customer and the Data Controller, the Data Controller may process:

  • name of the customer or contact person;

  • professional contact details;

  • telephone number;

  • email address;

  • job title;

  • details of the represented organization;

  • contractual information;

  • performance and project-related data;

  • billing information;

  • payment and accounting records;

  • communication history;

  • system data required for the provision of the Service.

The purposes of processing are to:

  • prepare and perform the contract;

  • provide the Services;

  • maintain communication;

  • manage billing and invoicing;

  • comply with legal and accounting obligations;

  • manage receivables and legal claims.

The legal bases for processing may include:

  • performance of a contract or taking steps prior to entering into a contract;

  • compliance with a legal obligation;

  • the legitimate interest of the Data Controller in enforcing legal claims and managing business relationships.

Accounting documents and supporting records are retained for the period prescribed by applicable accounting legislation.

10. Newsletters and Marketing Communications

The Data Controller does not currently use email addresses collected through demonstrations or contact inquiries for sending newsletters or recurring promotional communications.

Consent to receive newsletters or marketing communications may only be obtained:

  • separately;

  • voluntarily;

  • in advance;

  • through an explicit opt-in action;

  • independently of the use of any Service.

Consent provided for participation in a demonstration does not constitute consent for marketing purposes.

Marketing consent may be withdrawn at any time without providing a reason and without any adverse consequences.

11. Use of Artificial Intelligence

The Data Controller may use artificial intelligence in certain demonstration and service workflows, in particular for:

  • analysing text-based inquiries;

  • generating suggested responses;

  • conducting telephone conversations;

  • speech recognition;

  • generating transcripts;

  • creating summaries;

  • structuring data;

  • coordinating automated workflows.

Content generated by artificial intelligence may be inaccurate or incomplete.

Users are requested not to enter, disclose, or communicate information during demonstrations that is unnecessary for the demonstration or prohibited from being transmitted to AI service providers.

No solely automated decision-making producing legal effects concerning the user, or similarly significantly affecting the user, takes place within the scope of the demonstrations.

Any response, assessment, or summary generated by the System is provided solely for demonstration or decision-support purposes.

12. Data Processors and Service Providers

The Data Controller may engage data processors and technical service providers for the operation of the website, demonstrations, and automated workflows.

12.1. Framer

Service Provider: Framer B.V.
Registered Office: Rozengracht 207B, 1016 LZ Amsterdam, Netherlands
Service: website creation, publishing, hosting, technical infrastructure, and website analytics.

Framer may process technical data necessary for the operation of the website.

12.2. Contabo

Service Provider: Contabo GmbH
Service: provision of virtual servers and IT infrastructure.

Certain automated MIhely workflows operate on self-managed servers hosted on Contabo infrastructure.

The Data Controller will enter into the required data processing agreements with the service provider, or activate the relevant agreements through the provider's platform, before commencing live commercial operations.

12.3. n8n

Service: execution of automated workflows.

The n8n System operates in a self-managed server environment.

n8n workflows transfer data between service providers designated by the Data Controller.

Only data that is strictly necessary for the execution of the relevant workflow is transferred through n8n.

12.4. Google Services

Services: Gmail, Google Sheets, and related Google cloud services.

Depending on the relevant service and subscription model, the applicable Google entity may act as a data processor or as an independent data controller.

Google services may be used for:

  • sending emails;

  • storing contact and demonstration information;

  • logging workflow statuses;

  • internal business administration.

12.5. Retell AI

Service Provider: Retell AI, Inc.
Service: AI-powered telephone calls, voice processing, call recording, speech-to-text processing, transcription, and call analytics.

During the voice demonstration, Retell AI may process:

  • telephone number;

  • technical call logs;

  • voice recording;

  • conversation transcript;

  • information disclosed during the call;

  • generated summary;

  • call-related log data.

The Data Controller configures the applicable data retention settings within Retell AI in order to ensure that demonstration data is not retained for longer than necessary.

12.6. OpenAI and Other AI Providers

Where a particular workflow uses OpenAI or another artificial intelligence service provider, the following information may be transferred to that provider:

  • text to be analysed;

  • simulated customer inquiry;

  • relevant portions of a conversation transcript;

  • information necessary to generate a summary;

  • technical request identifiers.

The Data Controller endeavours to remove or minimize direct identifiers from information transmitted to AI providers unless such identifiers are necessary for the relevant processing purpose.

When using enterprise or API-based services, the Data Controller applies the appropriate data processing terms and retention settings.

12.7. Telegram

Service Provider: Telegram Messenger Inc.
Service: transmission of internal technical and operational notifications.

The Data Controller limits the content of notifications transmitted through Telegram to information strictly necessary for operational purposes.

Telegram is not used for storing complete customer databases, voice recordings, or complete conversation transcripts.

12.8. Other Service Providers

As the Data Controller's operations expand, additional service providers may be engaged, including, in particular:

  • billing and invoicing platforms;

  • accounting professionals;

  • legal service providers;

  • IT operations and support providers;

  • electronic signature providers;

  • CRM or project management systems.

The Data Controller will update this Privacy Notice in the event of any material changes to the service providers used.

13. Transfers of Personal Data to Third Countries

Certain technical service providers, particularly artificial intelligence, voice, messaging, or cloud infrastructure providers, may process personal data outside the European Economic Area (EEA).

In such cases, transfers will only take place on the basis of an appropriate legal mechanism and subject to safeguards compliant with the GDPR, including, where applicable:

  • adequacy decisions adopted by the European Commission;

  • Standard Contractual Clauses (SCCs) approved by the European Commission;

  • valid data processing agreements;

  • other appropriate safeguards pursuant to Chapter V of the GDPR.

The Data Controller reviews and documents the relevant transfer arrangements applicable to service providers before commencing live commercial operations.

14. Cookies and Website Analytics

The website may use technical solutions, cookies, or similar technologies that are necessary for its proper operation.

Strictly necessary cookies may be used to:

  • enable essential technical functionality;

  • provide security features;

  • maintain user sessions;

  • remember user preferences;

  • prevent fraudulent activity.

In the current website configuration, Framer Analytics provides the Data Controller with aggregated and anonymous traffic information and is not used to create individual visitor profiles.

If the Data Controller subsequently introduces:

  • Google Analytics;

  • Meta Pixel;

  • TikTok Pixel;

  • advertising tracking systems;

  • embedded marketing tools;

  • other non-essential cookies or similar technologies,

such technologies will only be activated following the user's prior consent, and an appropriate Cookie Notice and consent management banner will be implemented on the website.

15. Data Security

The Data Controller implements technical and organizational measures appropriate to the risks associated with the processing of personal data, including:

  • restricting access permissions;

  • using strong and unique passwords;

  • multi-factor authentication (MFA);

  • encrypted transmission of data;

  • regular security backups;

  • server and application updates;

  • logging and auditing;

  • incident detection capabilities;

  • regular review of user access permissions;

  • data segregation;

  • data minimization practices;

  • protection of access keys and API credentials;

  • deletion of data following expiry of applicable retention periods;

  • contractual oversight of data processors.

The Data Controller regularly reviews its security measures in light of technological developments, the nature of the processing activities, and emerging risks.

16. Personal Data Breaches

A personal data breach means a breach of security leading to the accidental or unlawful:

  • destruction;

  • loss;

  • alteration;

  • unauthorized disclosure of;

  • or access to personal data transmitted, stored, or otherwise processed.

The Data Controller investigates and documents personal data breaches and takes appropriate measures without undue delay to mitigate their potential consequences.

Where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, the Data Controller will notify the competent supervisory authority in accordance with applicable law.

Where the breach is likely to result in a high risk to the rights and freedoms of affected individuals, the Data Controller will also notify the affected data subjects in accordance with applicable legal requirements.

17. Rights of the Data Subject

In connection with the processing of their personal data, data subjects have the following rights:

17.1. Right to Information

Data subjects may request information as to whether the Data Controller processes personal data relating to them and, where such processing takes place, information concerning the purposes of processing, the applicable legal basis, the retention period, and the recipients or categories of recipients to whom the data has been or may be disclosed.

17.2. Right of Access

Data subjects may request access to, and a copy of, the personal data relating to them that is processed by the Data Controller.

17.3. Right to Rectification

Data subjects may request the correction of inaccurate personal data and the completion of incomplete personal data.

17.4. Right to Erasure

The data subject may request the erasure of their personal data, in particular where:

  • the purpose of the processing no longer exists;

  • the data subject has withdrawn their consent;

  • the data subject objects to the processing and there are no overriding legitimate grounds for continuing the processing;

  • the personal data has been processed unlawfully;

  • erasure is required by applicable law.

The right to erasure is not absolute and shall not apply, in particular, where continued processing is necessary for compliance with a legal obligation or for the establishment, exercise, or defence of legal claims.

17.5. Right to Restriction of Processing

The data subject may request restriction of the processing of their personal data where:

  • the accuracy of the personal data is contested;

  • the processing is unlawful, but the data subject opposes erasure;

  • the Data Controller no longer requires the personal data for the original purposes of processing, but the data is required by the data subject for the establishment, exercise, or defence of legal claims;

  • the data subject has objected to the processing and verification of the overriding legitimate grounds is pending.

17.6. Right to Data Portability

Where processing is based on consent or on a contract and is carried out by automated means, the data subject may request to receive the personal data they have provided to the Data Controller in a structured, commonly used, and machine-readable format.

17.7. Right to Object

The data subject has the right to object to the processing of personal data based on legitimate interests.

Where the data subject objects to such processing, the Data Controller shall no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing that override the interests, rights, and freedoms of the data subject, or where the processing is necessary for the establishment, exercise, or defence of legal claims.

17.8. Right to Withdraw Consent

The data subject may withdraw their consent at any time without providing a reason.

Withdrawal of consent shall not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

17.9. Right to Request Human Intervention

If automated decision-making is introduced in the future, the data subject may be entitled to request human intervention, express their point of view, and contest the decision.

No solely automated decision-making that produces legal effects concerning the data subject, or similarly significantly affects the data subject, currently takes place within the scope of the demonstrations.

18. Submission and Handling of Data Subject Requests

Data subject requests may be submitted to the following email address:

kapcsolat@mihely.hu

The Data Controller shall inform the data subject of the action taken in response to the request without undue delay and, as a general rule, within one month of receipt of the request.

Where the request is complex or a large number of requests have been received, this period may be extended by a further two months.

The Data Controller shall inform the data subject of any such extension and the reasons for the delay within the original one-month period.

Before fulfilling a request, the Data Controller is entitled to take reasonable measures to verify the identity of the person making the request.

19. Remedies and Complaints

The Data Controller requests that data subjects first contact the Data Controller directly regarding any concerns relating to the processing of their personal data:

Email: kapcsolat@mihely.hu

The data subject has the right to lodge a complaint with the competent supervisory authority.

Hungarian National Authority for Data Protection and Freedom of Information
(Nemzeti Adatvédelmi és Információszabadság Hatóság – NAIH)

Registered Office: 1055 Budapest, Falk Miksa utca 9–11., Hungary
Mailing Address: 1363 Budapest, P.O. Box 9., Hungary
Email: ugyfelszolgalat@naih.hu
Telephone: +36 1 391 1400

The data subject also has the right to seek judicial remedy where they consider that the processing of their personal data is unlawful or that the Data Controller has infringed their rights relating to data protection.

20. Personal Data of Minors

The MIhely website and Services are primarily intended for businesses, organizations, and adults.

Independent use of the demonstration Systems by persons under the age of 18 is not recommended.

Where the Data Controller becomes aware that personal data relating to a minor has been entered into the System without an appropriate legal basis, such personal data shall be deleted without undue delay.

21. Personal Data Relating to Third Parties

Users may provide personal data relating to a third party only where:

  • they have an appropriate legal basis for doing so;

  • the relevant individual has been appropriately informed;

  • providing the personal data is necessary for the purposes of the demonstration or Service.

A user may not provide another person's telephone number for the purpose of having the System call that person without their prior knowledge and consent.

Only a telephone number that the person initiating the demonstration is lawfully entitled to use and to receive calls on may be used in the telephone demonstration.

22. Amendments to this Privacy Notice

The Data Controller is entitled to amend this Privacy Notice, in particular in the event of:

  • changes in applicable legislation;

  • changes in regulatory or supervisory authority practices;

  • introduction of new Services;

  • changes to data processors or technology providers;

  • formal establishment of the business;

  • changes to data processing activities;

  • security or organizational changes.

The version of this Privacy Notice currently in force shall be available at all times on the mihely.hu website.

In the event of any material amendment, the Data Controller shall inform users in an appropriate manner.

Effective Date: July 27, 2026
Last Updated: July 27, 2026