Privacy Policy

1. Controller

Parais Gergely, sole proprietor (egyéni vállalkozó), 8045 Isztimér, Jókai utca 3., Hungary, registration number 62671981, e-mail: hello@sendawick.com (the "Controller", "we"). We have not appointed a Data Protection Officer; use the e-mail above for all privacy matters.

2. Who this Policy is for

Part A applies to people who order a Page ("Customers"). Part B applies to people a Page is about or addressed to ("Recipients"), whose data we receive from the Customer, not from them (Art. 14 GDPR). Part C applies to everyone.

Part A: Customers

3. What we process, why and on what legal basis

DataPurposeLegal basis (GDPR Art. 6(1))
Your e-mail address, the card's random ID, chosen plan, link lifetime, scheduled delivery time (Extra)Creating and delivering your Page, sending you the link and the Recipient's reply, support(b) performance of a contract
Recipient's first name, your name, occasion, relationship, the free-text details, the generated textGenerating and displaying the Page(b) performance of a contract
Payment status, order reference, country (received from the Merchant of Record; we never see card details)Order fulfilment, refunds, accounting(b) contract; (c) legal obligation (accounting)
IP address and e-mail address as one-way hashes, kept for one hourLimiting the number of previews per hour to prevent abuse(f) legitimate interest in running a secure service
Technical event log (card ID, event type such as "preview created" or "paid", technical detail, time) and Cloudflare's security logsSecurity, abuse prevention, debugging(f) legitimate interest
Bot check on the order form (Cloudflare Turnstile)Stopping automated abuse of the preview generator(f) legitimate interest
Aggregated page-view and page-speed statistics (Cloudflare Web Analytics; no cookies, no fingerprinting, no cross-site tracking)Understanding which pages are used and how fast they load(f) legitimate interest
Support correspondence, abuse reportsHandling your requests and complaints(b) contract; (c) legal obligation (consumer law); (f) legitimate interest

We do not send marketing e-mails, do not create profiles, do not make automated decisions with legal effect about you, and do not sell personal data.

4. Special categories of data

Please do not include health information, information about sexual life or orientation, religion, political opinions or similar sensitive information in the details unless it is strictly necessary for the greeting. A message such as a declaration of love may indirectly reveal such information about you or the Recipient. We do not analyse or extract it, we use it only to render your Page, and we delete it according to Section 8. Where you provide sensitive information about yourself, you do so on the basis of your explicit consent (Art. 9(2)(a)), which you can withdraw by asking us to delete the Page.

Part B: Recipients

5. Notice for Recipients (Art. 14 GDPR)

Someone who knows you ("the Customer") ordered a personalised greeting page from us and gave us your first name and possibly a few details about you, such as shared memories. We received this data from the Customer, not from you. We process it only to create, host and display the Page the Customer ordered and, if you choose to reply, to send your reply to the Customer. Legal basis: our and the Customer's legitimate interest in delivering a personal greeting (Art. 6(1)(f)), balanced against your rights; the Customer confirmed to us that they were entitled to share your details. We keep the Page for the period the Customer chose (30 days for Basic; for Premium and Extra until removal or until the Service is discontinued) and then delete it. Categories of data: first name, relationship to the Customer, the details the Customer described, the generated text, and your optional reply. We do not use your data for any other purpose, do not contact you, and do not share it except with the service providers listed in Section 7.

You have the right to object to this processing and to remove the Page at any time: press "Do not show this card again" at the bottom of the Page (the Page disappears immediately and automatically) or e-mail hello@sendawick.com with the link; we act on e-mailed requests within 48 hours. You also have the rights described in Section 10.

Part C: Everyone

6. Your reply on the Page

If a Recipient sends a reply through the Page (for example "Yes" or a short message of up to 280 characters), we store the reply with the Page and e-mail it to the Customer. This is done to perform the Customer's contract and in the Recipient's interest in responding.

7. Processors and other recipients of data

We use the following service providers, which act on our documented instructions under data processing agreements (Art. 28 GDPR):

We may also disclose data if required by law, to establish, exercise or defend legal claims, and to authorities under Regulation (EU) 2022/2065 where applicable.

8. Retention

9. International transfers

Our providers are headquartered in the United States. Where personal data is transferred outside the EEA, we rely on: (i) the EU-U.S. Data Privacy Framework adequacy decision for providers certified under it; and/or (ii) the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) incorporated in each provider's DPA, together with supplementary measures (encryption in transit and at rest, EU data-location settings, data minimisation). You may request a copy of the relevant clauses at hello@sendawick.com.

10. Your rights

Under the GDPR you may: access your data; have it corrected; have it erased; restrict processing; receive the data you gave us in a portable format; object to processing based on legitimate interest (including as a Recipient); and withdraw consent at any time without affecting earlier processing. Write to hello@sendawick.com. Because there are no accounts, please quote the order e-mail address and the card link (Customers) or the card link (Recipients) so that we can identify the relevant data. We respond within one month.

11. Complaints

You may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH), 1055 Budapest, Falk Miksa utca 9-11, Hungary; postal: 1363 Budapest, Pf. 9; e-mail: ugyfelszolgalat@naih.hu; naih.hu, or with the supervisory authority of the EU country where you live or work. You may also bring a claim before the courts.

12. Security

Data is encrypted in transit (TLS) and at rest by our hosting provider; access is limited to the Controller; Page links use long random identifiers that cannot be guessed and are excluded from search engines. No system is perfectly secure; if a breach is likely to result in a high risk to you, we will inform you as required by Art. 34 GDPR.

13. Children

We do not knowingly accept orders from persons under 18. If you believe a child has provided us data, contact hello@sendawick.com and we will delete it.

14. Changes

We will post the new version here with a new version number and effective date. Material changes affecting existing Pages will be notified by e-mail to Customers.