Privacy Notice

Privacy Notice

Publication date: 2 August 2026.

This Notice explains how SensNet Kft. processes personal data in connection with the IQH Technology / IQ Home Website, accounts, orders, payments, delivery, connected products, software, cloud/connectivity services, support, safety actions and marketing.

1. Controller

Controller: SensNet Korlátolt Felelősségű Társaság
Short name: SensNet Kft.
Registered office: 1139 Budapest, Tahi utca 30, 2nd floor, door 4, Hungary
Company registration number: 01-09-180989
Tax number: 24762339-2-41
Email for privacy requests: info@sensnet.tech
Telephone: +36 1 988 9039 (English-language customer service)

If SensNet appoints or is required to appoint a data protection officer, the contact will be published here. Until then, requests go to the address above.

2. Main processing activities

2.1 Website operation and security

SensNet processes IP address, date/time, requested URL, referrer, browser and device information, session/cart identifiers, logs, errors and security events to deliver the site, maintain carts/sessions, prevent abuse, protect accounts and diagnose faults.

Basis: GDPR Article 6(1)(f), SensNet's legitimate interest in a secure and reliable store, and Article 6(1)(b) where needed for requested pre-contract steps. Essential storage is used under applicable electronic-communications law.

Routine server/security logs are kept for up to 30 days. Incident evidence may be isolated and kept for the necessary claims/security period.

2.2 Registration and account

Data can include name, email, telephone, password hash, customer/company type, company and VAT information, billing/delivery addresses, settings, devices, licences, subscriptions and order history.

Purposes: create and secure the account, authenticate the user, provide account/device/service functions and prefill future orders. Basis: Article 6(1)(b); security is also Article 6(1)(f).

An order-related account is not based on consent. The Privacy Notice checkbox is an acknowledgment. Any newsletter/marketing consent is separate, optional and unselected.

Core account data is kept while the account/service is active and then deleted or anonymised after reasonable notice, except for order, accounting, complaint, safety and claims records that require longer retention.

2.3 Enquiries, quotations and orders

Data can include contact/company data, correspondence, requested products, configuration, site/installation information, price, order ID, status, contract version and acceptance evidence.

Purpose/basis: answer the enquiry, take requested pre-contract steps and perform the contract (Article 6(1)(b)); establish/defend claims (Article 6(1)(f)); comply with consumer/e-commerce obligations (Article 6(1)(c)).

Contract evidence is normally kept for five years after performance or dispute closure. Accounting data is kept for eight years.

2.4 Billing, tax and payment

SensNet processes name/company, address, tax/VAT number, invoice/order data, amount, currency, payment status, transaction reference and refund data.

Basis: contract (Article 6(1)(b)); Hungarian accounting/tax/legal obligations (Article 6(1)(c)); fraud and claims interests (Article 6(1)(f)).

Payment is provided by Barion Payment Zrt., 1117 Budapest, Irinyi József utca 4-20, 2nd floor. Barion is an independent controller for payment, regulatory and fraud-prevention purposes. SensNet does not receive card number or security code. See https://www.barion.com/en/privacy-notice/.

SensNet uses the Barion Base Pixel for payment-fraud prevention on the basis of its documented legitimate interest. Any Full Barion Pixel marketing use is separate, consent-based and remains disabled until consent.

2.5 Delivery, installation and service partners

Data can include recipient, address, phone, email, parcel/order reference, delivery instructions, installation site/contact and relevant product data.

Purpose/basis: contract performance (Article 6(1)(b)); logistics/tax duties (Article 6(1)(c)); delivery/security claims (Article 6(1)(f)).

Only the necessary data is shared with the carrier, installer, fulfilment or service partner selected for the order. The carrier may be GLS for primary delivery within Hungary and the EU or Spring GDS for economy delivery within the EU. Delivery tracking data is retained with order evidence; operational copies follow partner retention schedules.

2.6 Software, cloud and connected products

Depending on product/service, SensNet can process account/device identifiers, serial number, IP/network data, configuration, firmware/software version, licence and subscription status, sensor readings, events, telemetry, commands, diagnostics, usage, location/installation metadata, security logs and support records.

The exact dataset, access, storage, retention, data holder and intended uses are stated in the product-specific Connected Product Data Sheet and service schedule before contract.

Purposes/bases can include:

  • provide the connected functionality/service and requested data access: Article 6(1)(b);
  • maintain security, prevent abuse and diagnose service faults: Article 6(1)(f);
  • provide required conformity/security updates and comply with safety/cybersecurity law: Article 6(1)(c);
  • optional analytics or improvement not necessary for the contract: consent where required, otherwise a specifically documented lawful basis.

The EU Data Act does not itself authorise processing of personal data. Where product data is personal data, GDPR rights and lawful-basis requirements continue to apply. SensNet verifies authority before disclosing another person's data in response to a Data Act request.

Retention is product/service-specific. Live operational data is not kept longer than the period stated in the applicable schedule and necessary for the purpose. On termination, export/deletion or anonymisation follows that schedule, subject to security, accounting, safety and claims holds.

2.7 Support, conformity and guarantee claims

Data includes identity/contact, order and product identifiers, serial/batch, description, correspondence, photos/videos, measurement/log files, repair, replacement/refund and shipping data.

Basis: contract and statutory remedies (Articles 6(1)(b) and (c)); defence of claims (Article 6(1)(f)).

Conformity/guarantee protocols are kept for three years. The underlying contract/accounting record may have a longer applicable period.

2.8 Complaints, withdrawal and conciliation

Data includes identity/contact, contract identifier, statement, timestamp, supporting information, response, delivery evidence and proceeding records.

Basis: legal obligations (Article 6(1)(c)); contract/withdrawal handling (Article 6(1)(b)); claims (Article 6(1)(f)).

Oral-complaint protocols, written complaints and substantive response copies are kept for three years. Electronic-withdrawal evidence is normally kept with contract evidence for five years after closure.

2.9 Product safety, recalls and cybersecurity

Data includes Customer/contact, delivered product/model/serial/batch, incident, vulnerability, system/log evidence, injury/damage information, corrective action and authority communications.

Basis: product-safety/cybersecurity/legal duties (Article 6(1)(c)); vital interests in exceptional emergencies (Article 6(1)(d)); security and legal claims (Article 6(1)(f)).

Records are retained for the applicable statutory traceability, reporting and claims periods. Safety notices are not marketing and can be sent without marketing consent.

2.10 Newsletter and direct marketing

Data: name where supplied, email, consent wording/version/time/source, campaign delivery/open/click data if separately consented to, unsubscribe and suppression record.

Basis: prior express consent under Article 6(1)(a) and Hungarian direct- marketing/electronic-communications rules. Consent can be withdrawn free of charge in each email or at info@sensnet.tech without affecting prior lawful processing.

Active subscription data is kept until withdrawal. A minimal suppression record is then retained to honour the opt-out and prove compliance; consent is periodically revalidated where required.

Where the Website offers Mailchimp newsletter subscription, Mailchimp/Intuit receives the subscription data as described in this Notice and the applicable transfer safeguards apply.

2.11 Optional analytics, advertising, heatmaps and social content

Google Analytics/Ads, Hotjar, Twitter/X and similar optional tools may process online identifiers, device/browser, pages/events, approximate location, campaign/referrer and interaction data only after the relevant consent. Basis: Article 6(1)(a) and the applicable storage/access consent.

If consent is refused, these tools remain blocked and the core shop remains usable. Consent can be changed at any time through Cookie settings. Current providers, purposes and lifetimes appear in the Cookie Policy.

3. Recipients and processors

Depending on the transaction and enabled choices, data may be received by:

  • BlazeArts Kft. (FORPSI Hungary), 1096 Budapest, Thaly Kálmán utca 39., Hungary, info@forpsi.hu, https://www.forpsi.hu/, for website hosting and related infrastructure;
  • other content-delivery, backup, security, email and IT support providers actually used;
  • OpenCart/store and account-support providers;
  • Barion as independent payment/fraud controller;
  • invoicing, accounting, tax and professional advisers;
  • carriers, fulfilment, installers and repair partners;
  • cloud/connectivity/software infrastructure and licensors needed for the purchased service, including the identified 1NCE or CODESYS party where applicable;
  • Mailchimp/Intuit for consented email marketing where the newsletter service is used;
  • consented analytics/advertising/heatmap/social providers; and
  • authorities, courts, conciliation bodies, Safety Gate/product-safety and cybersecurity bodies where law requires.

SensNet uses processors under GDPR Article 28 terms and discloses only the data necessary for the stated purpose. A third party is treated as a recipient only when it is actually used for the relevant transaction or enabled service.

4. International transfers

Some cloud, support, marketing or analytics providers may process data outside the EEA. SensNet uses such a transfer only with an adequacy decision or another GDPR Chapter V safeguard, normally the Commission's Standard Contractual Clauses plus a transfer assessment and supplementary measures where needed. Copies or information about safeguards are available on request, subject to lawful redactions.

Optional providers remain disabled unless the required transfer safeguards are in place.

5. Required data and consequences

Fields marked required are necessary to conclude/perform the contract or comply with law. Without them SensNet may be unable to create an account, accept/deliver an order, invoice, activate a service or handle a claim. Marketing, analytics and unrelated profiling data are optional.

SensNet does not make solely automated decisions producing legal or similarly significant effects unless the specific logic, significance, consequences and rights are separately disclosed. Barion may independently perform automated fraud assessment under its own notice.

6. Rights

Subject to conditions and exceptions, a data subject may request access, rectification, erasure, restriction, portability, object to legitimate- interest processing, withdraw consent, and obtain information about transfers. A person may also challenge an applicable solely automated decision.

Requests: info@sensnet.tech. SensNet may proportionately verify identity and normally responds within one month.

Objection to direct marketing is honoured at any time. For other legitimate-interest processing, SensNet stops unless compelling legitimate grounds or legal-claim grounds prevail.

Complaints can be lodged with:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
1055 Budapest, Falk Miksa utca 9-11, Hungary
Postal address: 1363 Budapest, P.O. Box 9
Website: https://www.naih.hu/
Email: ugyfelszolgalat@naih.hu

A data subject may also seek a judicial remedy.

7. Security

SensNet applies risk-appropriate access control, authentication, encryption in transit, logging, backup, patching, vulnerability handling, least- privilege and incident procedures. Customers must keep credentials secret, use supported software and report suspected compromise promptly.

No internet service is absolutely secure. A personal-data breach is assessed and notified to NAIH and affected persons where GDPR thresholds require.

8. Children

The shop is intended for adults and business/technical use. SensNet does not knowingly offer information-society services directly to children through child consent. A legal representative should contact SensNet if a child's data was supplied improperly.

9. Changes

SensNet publishes the current Notice with its effective date and informs affected persons of a material change where required. A new purpose is not made retroactively compatible merely by editing this page.