Privacy Policy
Version 1.2 · In force from: 7 October 2026
ColourSense — personal colour analysis service
In brief — the six things that matter most
- The Analysis is produced by artificial intelligence. Your photograph and your questionnaire answers are processed by the large language model "Claude", operated by Anthropic PBC; the text of the Report is generated by that model. No human colour expert looks at your photograph today.
- Your photograph leaves the European Union. To produce the Analysis we transfer the photograph to the servers of Anthropic PBC (United States of America), on the basis of the standard contractual clauses (SCC) adopted by the European Commission. See Chapter 8.
- We do not use your photograph to identify you uniquely. We do not create a biometric template from it, we do not train any model on it, we do not publish it and we do not sell it. See Chapter 4.
- We never see your bank card details. Payment takes place on Stripe's own interface; card data never reaches our servers.
- We load advertising measurement code (the Meta pixel, the Google Ads tag) only with your consent — without consent it is not even loaded (row 14 of Chapter 3; section 4.1 and Chapter 8 of the Cookie and Storage Notice). There is no TikTok pixel, no Google Analytics and no Tag Manager, and we do not sell your data. If you arrive by clicking an advertisement, we do record the advertising click identifier in your browser's storage, count it in our audience measurement, and — when the order is submitted — it also enters our operational log, today within a single entry together with your e-mail address — see rows 10 and 13 of Chapter 3 and Chapter 14.
- There is no registration. You order as a guest; we do not create a user account for you.
If the language versions of this notice differ from one another, the interpretation more favourable to you prevails.
1. Introduction — who and what this notice covers
This notice has been drawn up under Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council (the GDPR) and under Act CXII of 2011 on Informational Self-Determination and Freedom of Information (the Hungarian data protection act, the Infotv.).
Who it covers. Anyone who
- visits the website
colour-sense.com(the User), - completes the free colour test and asks for the result by e-mail,
- orders the paid colour analysis (the Analysis) and receives the PDF report (the Report) (the Consumer),
- contacts our customer service.
The words we use.
| Term | Meaning |
|---|---|
| the Provider / "we" | Ágnes Gróf, sole trader, the controller for the purposes of this notice |
| the Analysis | the personal, AI-assisted colour analysis you order |
| the Report | the PDF document delivered as the result of the Analysis |
| data subject / "you" | the natural person whose personal data we process |
| processor | a person who processes data on our behalf and on our instructions (Article 4(8) GDPR) |
What this notice does not contain. Cookies and the data stored in your browser are covered by a separate, detailed notice (see Chapter 14); the contractual terms are set out in the Terms of Service.
Availability and form. This notice is available on the website free of charge; you may read, print and save it at any time (Article 12(1) and (5) GDPR).
2. The controller and its contact details
| Item | Value |
|---|---|
| Name of the controller | Ágnes Gróf, sole trader |
| Business / trade name | ColourSense |
| Legal form | private entrepreneur (egyéni vállalkozó), Hungary |
| Registered seat | 2100 Gödöllő, Szabó Pál utca 32., Hungary |
| Postal address | 2100 Gödöllő, Szabó Pál utca 32., Hungary |
| Registration number | 62279046 |
| Tax number | 92036149-1-33 |
| Telephone | +36 30 460 0093 |
| General e-mail address | hello@colour-sense.com |
| Customer service, complaints | support@colour-sense.com |
| Data protection enquiries | support@colour-sense.com |
| Website | https://colour-sense.com |
2.1 Data protection officer
We have not designated a data protection officer. None of the cases listed in Article 37(1) GDPR applies: we are not a public authority, our core activities do not require regular and systematic monitoring of data subjects on a large scale, and our core activities do not consist of processing data referred to in Articles 9–10 GDPR on a large scale.
You may address any data protection question or request directly to us at support@colour-sense.com, or by post to 2100 Gödöllő, Szabó Pál utca 32., Hungary.
3. Purposes of processing, data processed, legal bases, retention and recipients
This chapter is the backbone of the notice. Each row describes one distinct purpose of processing.
| # | Purpose | Data processed | Legal basis | Retention | Recipients |
|---|---|---|---|---|---|
| 1 | Producing the Analysis you ordered | first name; e-mail address; hair, eye and skin colour; skin undertone; contrast; dominant wardrobe colours; style preference; occupation; the language of the Report; (for older orders: gender, age) | Article 6(1)(b) GDPR — performance of the contract | 5 years from the order | Anthropic PBC (USA); Studio CRM |
| 2 | Analysing the facial photograph (in detail: Chapter 4) | the facial photograph you upload (JPEG/PNG/WebP, 8 MB maximum) | Article 6(1)(a) and — out of caution — Article 9(2)(a) GDPR: your explicit consent | 30 days from delivery of the Report | Anthropic PBC (USA); embedded in the Report, the operator of the mail server and Studio CRM |
| 3 | Storing and delivering the result of the Analysis | the full AI-generated analysis text; the colour type (season) determined; the PDF of the Report | Article 6(1)(b) GDPR — performance of the contract | 5 years | Studio CRM; the operator of the mail server; you |
| 4 | Handling the payment | e-mail address; amount and currency; payment status; the Stripe checkout session identifier; the time of payment; internal order identifiers | Article 6(1)(b) GDPR; Stripe, as a controller in its own right, Article 6(1)(c) (anti-money-laundering and card scheme obligations) | 5 years | Stripe |
| 5 | Issuing and retaining the invoice | billing name; country; postcode; town; street and number; e-mail address; invoice data (number, amount, dates) | Article 6(1)(c) GDPR — legal obligation (Section 169 of Act C of 2000 on Accounting — the Accounting Act; Act CXXVII of 2007 on Value Added Tax, implementing Directive 2006/112/EC) | at least 8 years (see 9.2) | Billingo; through Billingo, the NAV Online Invoice system |
| 6 | Delivering the Report and the invoice by e-mail | recipient e-mail address; first name used in the salutation; the text of the message; the attached PDFs (Report + invoice); the palette belonging to the colour type | Article 6(1)(b) GDPR | the outbound message record and its attachment, stored in base64 form, are kept even after successful delivery — a deletion rule has yet to be built | the operator of the mail server; Studio CRM |
| 7 | Sending the result of the free colour test by e-mail, and the season-palette message (in detail: Chapter 6) | e-mail address; the colour type resulting from the test; language; subscription status; (a first-name field exists but we do not populate it today) | Article 6(1)(a) GDPR — consent, in line with Section 6 of Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activity (the Advertising Act), which implements Article 13 of Directive 2002/58/EC | until you unsubscribe or withdraw your consent; deletion upon unsubscribing | Studio CRM; the operator of the mail server |
| 8 | Customer service and complaint handling | the sender, subject and content of the message you send us; documents relating to the handling of a complaint | Article 6(1)(b) GDPR; in the case of a complaint, Article 6(1)(c) (Section 17/A of Act CLV of 1997 on Consumer Protection — the Consumer Protection Act) | incoming messages are not stored in a database; they remain in the mailbox: 3 years; complaint records: see 9.2 | — (the operator of the mail server) |
| 9 | Abuse prevention and protection of service availability (rate limiting) | IP address | Article 6(1)(f) GDPR — legitimate interest: keeping the service available and preventing automated abuse and overload | 15 minutes (the expiry set in the cache) | — |
| 10 | Operational error and event logs, and the logging of campaign attribution | IP address (on exceeding the rate limit and on unauthorised administrator login attempts); e-mail address (in technical log entries); error messages; advertising click identifiers (utm_*, gclid, fbclid, msclkid, ttclid) if you arrived from an advertisement — in the entry created when the order is submitted those identifiers stand within one and the same log entry together with your e-mail address, linked to it, so that the pseudonymous advertising identifier is tied to an identified person |
Article 6(1)(f) GDPR — legitimate interest: troubleshooting, operational security, restoring the service to working order; in the case of campaign attribution, being able to see which advertising campaign led to an order (balancing test: 3.1) | today, size-based log rotation (5 MB per log file, 5 files); a time-based rule is to be introduced: 90 days | — |
| 11 | Internal business audit log (administrator login, viewing an order, refund, fulfilment of a data protection request, configuration change) | the administrator's identifier; the operation and its time; the identifier of the order concerned | Article 6(1)(c) GDPR (accountability, Article 5(2) GDPR) and Article 6(1)(f) — legitimate interest: making access verifiable after the event | no clean-up rule today; to be introduced | — |
| 12 | Managing administrator sessions (staff of the Provider only) | administrator e-mail address; password hash; role; hash of the session identifier; the IP address used to log in | Article 6(1)(f) GDPR — legitimate interest: protecting the system against unauthorised access | the session expires after 7 days | — |
| 13 | Cookieless audience measurement | page view; the visitor's IP address and browser identifier (at the measurement provider, without storage, for statistical aggregation); event names; the advertising click identifiers above, on starting the payment and on a successful purchase. On our own server as well: the same events, plus the page path, the step number or name, the language, the device type and the referring site's domain — tied to a daily-changing, irreversible visitor identifier (a one-way, secret-salted digest of the IP address and browser identifier). The IP address and browser identifier are not stored, the digest can no longer be linked to the same visitor on the next day, and the measurement does not record any content you type (name, e-mail, the text of your answers) | Article 6(1)(f) GDPR — legitimate interest: understanding and improving the use of the website. The measurement uses no cookies, and therefore no consent is required on the ground of cookies under Section 155(4) of Act C of 2003 on Electronic Communications (the Eht., implementing Article 5(3) of Directive 2002/58/EC). The assessment of the terminal-equipment storage that serves the measurement is different: the cs-attribution and cs-purchase-<identifier> storage — although it is not a cookie — falls within the scope of Section 155(4) of the Eht., and the consent requirement arises in that respect; see Chapter 14 |
at the measurement provider in accordance with its policy; the non-identifying event data stored on our own server is retained for statistical purposes without a time limit | Plausible Analytics and our own server |
| 14 | Advertising measurement and retargeting — ONLY with your consent | page view (with the address of the page visited), the start of payment and the fact, amount and currency of the purchase, the identifier of the payment session (to filter out double counting); the identifier of the cookie set by Meta or Google (_fbp, _fbc, _gcl_au, _gcl_aw). We transmit no name, e-mail address, billing address or uploaded photograph |
Article 6(1)(a) GDPR — your consent, in conjunction with Section 155(4) of the Eht. Until consent is given the measurement code is not even loaded; consent can be withdrawn at any time via the Cookie settings link in the footer (Cookie Notice sections 4.1 and 8) | the cookies last 3 months; at the providers, according to their own policies | Meta Platforms Ireland Ltd., Google Ireland Ltd. |
| 15 | Establishment, exercise and defence of legal claims | the data relating to the order | Article 6(1)(f) GDPR — legitimate interest: defending against claims arising from the contract | the 5-year general limitation period under Section 6:22 of Act V of 2013 on the Civil Code (the Civil Code) | — |
The hosting provider and server operator is a recipient in every row. All of the processing above takes place on our servers, and the hosting provider and server operator named in row 6 of Chapter 7 is therefore, as a processor, a recipient in every processing operation. The "Recipients" column of the table lists only the further recipients specific to each purpose.
3.1 About the processing based on legitimate interests (Article 13(1)(d) GDPR)
For rows 9, 10, 11, 12, 13 and 15 our legal basis is legitimate interest. The legitimate interest is named in the table. For each such processing operation we carry out a balancing test; we will send you a summary of it on request at support@colour-sense.com. You have the right to object to these processing operations (Chapter 10).
On campaign attribution, separately. For the logging described in row 10, our legitimate interest is being able to see which advertising campaign led to an order. We do not regard the impact on you as negligible: the advertising click identifier is a pseudonymous identifier that can be linked to your particular advertisement click, and in the present implementation it stands within the same log entry, next to your e-mail address — that is, it is attached to an identified person. This is counterbalanced by the fact that we do not ourselves send the identifier back to Google, Meta, Microsoft or TikTok (if you have consented to advertising measurement, the Meta and Google measurement code may itself record the advertisement click — row 14), that we build no advertising profile from it, and that we do not link it to your questionnaire answers, your facial photograph or your Report. Proportionality, however, is achieved only once the logging is reworked: we undertake to remove the e-mail address from that log entry and to introduce a time-based retention rule. You have the right to object to this processing too. The events sent to the measurement provider are covered by row 13; their counterpart stored on your terminal equipment is covered by Chapter 14 and by section 7.4 of the Cookie and Storage Notice.
3.2 Are you obliged to provide the data? (Article 13(2)(e) GDPR)
Providing the data is not a statutory requirement; it is a requirement necessary to enter into and to perform the contract — with the exception of the billing data, which is required by law (Section 169 of the VAT Act, implementing Article 226 of Directive 2006/112/EC).
| Data | Consequence of not providing it |
|---|---|
| first name, e-mail address | we cannot produce and deliver the Report |
| questionnaire answers | the Analysis cannot be produced |
| facial photograph | the Analysis cannot be performed without the photograph; it is an essential element of the service |
| billing name and address | we cannot issue a legally compliant invoice and therefore cannot perform the order |
| e-mail address for the free test | the only consequence is that we will not send the result by e-mail — you can still complete the test and the result is displayed on screen |
3.3 What we expressly do NOT do
- We do not sell or rent your personal data.
- We load an advertising pixel (Meta, Google Ads) only with your consent — without consent it is not even loaded (row 14 of Chapter 3); we use no TikTok, LinkedIn or other social media pixel, and no Google Analytics / Tag Manager, Hotjar or Clarity type solution.
- In our applications we neither collect nor store the browser identifier (user agent); row 10 of Chapter 3 explains the access log of the reverse proxy in front of the web server.
- Our outgoing e-mails contain no tracking pixel and no click tracking.
- The visitor's browser loads no external fonts (we serve the typefaces from our own server).
- We build no advertising profile, and without your consent we carry out no behavioural targeting (retargeting only as described in row 14 of Chapter 3).
3.4 Processing for a further purpose (Article 13(3) GDPR)
We will process your personal data for a purpose other than those set out above only if we inform you of that purpose beforehand and — where required — ask for your separate consent. In particular: we do not use your photograph, your questionnaire answers or your Report to display testimonials, in case studies or marketing materials, nor to improve artificial intelligence prompts or to train a model.
4. The facial photograph — a separate chapter
This is the most sensitive item of data we process, and we therefore explain it separately and in detail.
4.1 What happens to your photograph, step by step
- In your browser. In case the process is interrupted, the order form temporarily stores the
photograph in your browser's session storage (under the key
cs-premium-flow-photo-v1), so that you do not have to upload it again if you return from the payment page. This data is deleted when you close the tab and upon successful payment. - Upload and validation. The photograph reaches our server together with the order. We check the real type of the file (only JPEG, PNG or WebP is accepted) and its size (8 MB maximum).
- Storage. We store the photograph on our server's file system, under a file name containing an unguessable random identifier. The database holds only the file path. The photograph is not publicly accessible: it has no guessable web address and we do not serve it as static content.
- Analysis. After payment, we transmit the photograph in base64 form to the Claude API of Anthropic PBC (United States of America). Chapter 8 explains this in detail.
- Embedding in the Report. The photograph is included in the PDF report produced for you, which we send by e-mail. The outgoing message — together with its attachment — is also stored in our mail-sending system.
- Access. Only a logged-in administrator of the Provider can view the photograph, through a single authenticated endpoint, with a header that prohibits caching.
4.2 The legal classification of the photograph — two independent findings
(a) We do not use your photograph to identify you uniquely. We do not create a biometric template from your photograph, we do not run facial recognition on it, we do not compare it against any facial image database and we do not use it for authentication. The definition of biometric data in Article 4(14) GDPR requires two cumulative conditions: specific technical processing and that the processing allows or confirms the unique identification of the natural person. The second condition is not met here, and the photograph therefore does not qualify as biometric data under that provision. This is supported by recital (51) GDPR, according to which the processing of photographs is not systematically to be considered as processing of special categories of personal data.
(b) Independently of that, and out of caution, we also rely on your explicit consent. As an intermediate finding, the Analysis records your skin tone and skin undertone. Article 9(1) GDPR also covers data "revealing racial or ethnic origin", and in Case C-184/20 (1 August 2022) the Court of Justice of the European Union held that Article 9 also covers data from which special category data may be deduced by an intellectual operation involving comparison or deduction. Guidelines 05/2022 of the European Data Protection Board state that Article 9 applies to systems used to categorise individuals on the basis of their biometrics into clusters according to ethnicity.
In our view the analysis of skin tone is not aimed at establishing your ethnic origin, and the output ("Spring / Summer / Autumn / Winter" and its sub-type) is an aesthetic and not an ethnic category. Because that interpretation may nevertheless be contested, for safety we also base the processing of the photograph on your explicit consent under Article 9(2)(a) GDPR, in addition to consent under Article 6(1)(a) GDPR.
4.3 What we do not do with your photograph — express undertakings
- We do not train any artificial intelligence model on it, and nor may our provider: the commercial terms of Anthropic expressly exclude the training of models on customer content.
- We do not publish it — not on the website, not on social media and not in any marketing material.
- We do not sell it and do not hand it over for advertising or data trading purposes.
- We do not use it for marketing without your separate, explicit consent.
- We do not use it to identify you or to find you in other systems.
- We draw no inference from it as to racial or ethnic origin, religious belief, health, political opinion or sexual orientation, and the Report contains no such finding.
4.4 Withdrawing your consent
You may withdraw your consent relating to the photograph at any time, without giving reasons and free of charge, at support@colour-sense.com. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal (Article 7(3) GDPR). Please note that if you withdraw your consent before the Analysis has been produced, the service cannot be performed; in that case the settlement provided for in the Terms of Service applies.
4.5 Retention period of the photograph
We delete the photograph 30 days after the Report has been delivered.
5. Use of artificial intelligence (Article 13(2)(f) GDPR and Article 50 of the AI Act)
5.1 The fact of the AI system and its role
The Analysis is produced by artificial intelligence. The text of the Report is not
written by a human colour expert but by Claude, the large language model operated by
Anthropic PBC (the claude-sonnet-4-6 model version at the time this version enters into
force; the model version used may change as the service develops, but the logic of the system
described here does not), which the Provider uses as a deployer. We give this information under
Article 50 of Regulation (EU) 2024/1689 on artificial intelligence (the AI Act).
5.2 How the system works — meaningful information about the logic involved
| Step | What happens |
|---|---|
| Input | (a) the facial photograph you upload; (b) your questionnaire answers: hair, eye and skin colour, skin undertone, contrast, dominant wardrobe colours, style preference, occupation, first name, the language of the Report |
| Intermediate findings | from the photograph and the answers, the system determines your natural skin tone, your skin undertone (cool / warm / neutral), your eye and hair colour and your contrast level |
| Classification | on the basis of the intermediate findings, the system places you in a colour type (season) and in a sub-type of it |
| Output | the colour palette belonging to that classification, colours to avoid, and make-up, wardrobe and style recommendations — all of it as the PDF of the Report |
What the AI provider does not receive: your e-mail address, your billing name and address, your order identifier, your IP address and your payment data. The request sent to the Claude API does not contain them.
Human involvement. The text of the Report is not written or reviewed by a human expert today. The system is operated and supervised by the Provider.
5.3 Information about the categorisation (Article 50(3) of the AI Act)
The system places you in categories on the basis of your facial image (hair colour, eye colour, skin tone, undertone, colour type). The AI Act uses a broader concept than the GDPR: under Article 3(34) of the AI Act a facial image constitutes biometric data even where no one is identified by it, and recital (16) of the Regulation names hair colour and eye colour among the categories. Therefore — independently of the GDPR classification set out in section 4.2 — we inform you about how the system works and record that
- the sole purpose of the system is to determine an aesthetic colour type;
- the system is not intended to deduce or infer your racial or ethnic origin, political opinions, religious beliefs, trade union membership, health, sex life or sexual orientation, and it makes no such finding;
- the system does not identify you and uses no facial recognition.
5.4 Automated decision-making (Article 22 GDPR)
The Analysis involves profiling by automated processing (Article 4(4) GDPR). It does not, however, constitute a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22(1) GDPR: the Report is aesthetic advice; it restricts no right, excludes you from no service, and is not a credit, insurance, employment or official decision.
The significance and the envisaged consequences of the Report. The Report contains suggestions as to which colours suit you. It does not constitute medical, dermatological, psychological or other professional advice, a diagnosis or a treatment recommendation, and it is not suitable for deciding any health-related question.
5.5 Human review
if you dispute the outcome of the Analysis, the Provider will review it personally at your request and reply in writing within 30 days of receiving your request
6. The free colour test and contact by e-mail (Section 6 of the Advertising Act)
6.1 What happens when you take the colour test
The free, 8-question colour test runs entirely in your browser. The answers you give
never reach our servers; the result lives in your browser's local storage (localStorage,
key cs-quiz-result) for 48 hours and is then deleted automatically, or immediately if you
use the "start again" button.
6.2 What we process if you ask for the result by e-mail
If you enter your e-mail address on the result page, we transmit three items of data to our server: your e-mail address, the colour type resulting from the test and the language. We use these to send you a season-palette message, which also draws your attention to ordering the paid Analysis and therefore qualifies as electronic advertising.
For this we ask for your prior, unambiguous and explicit consent, by way of a separate checkbox, recording the time of the consent and the version of its wording (Section 6(1)–(2) and (5) of the Advertising Act; Article 13 of Directive 2002/58/EC).
6.3 Unsubscribing
Every such message contains a one-click unsubscribe link at the bottom (and in the technical headers of the message, under the one-click unsubscribe standard). Unsubscribing is free of charge, requires no reasons and may be exercised at any time; following your unsubscription we delete your e-mail address without delay from the advertising records (Section 6(3) of the Advertising Act).
Unsubscribing does not affect non-advertising messages connected with the service you ordered (for example the delivery of the Report and the invoice).
7. Processors and recipients — itemised list
| # | Recipient | Role | What it receives | Seat | Place of processing |
|---|---|---|---|---|---|
| 1 | Anthropic PBC (Claude API) | processor | the facial photograph, the first name and the questionnaire answers (it does not receive: e-mail address, address, order identifier, IP address, payment data) | San Francisco, United States of America | USA — see 8.1 |
| 2 | Stripe — the payment service provider; the contracting entity is: Stripe Payments Europe, Limited (Ireland) (Stripe, Inc. in the United States, or Stripe Payments Europe, Ltd. in Ireland) | processor, and controller in its own right for its statutory obligations | from our server: your e-mail address, the amount, the currency, the product name and internal order identifiers. Directly from you, on Stripe's own interface: the card data, the IP address and device data | USA / Ireland | USA and EU — see 8.2 |
| 3 | Billingo — the invoicing service provider (Billingo Technologies Zrt. (Hungary), Hungary; seat: Hungary) | processor | billing name, e-mail address, country, postcode, town, address, amount, currency, dates | Hungary | EU |
| 4 | National Tax and Customs Administration of Hungary (Nemzeti Adó- és Vámhivatal, NAV — Online Invoice system) | not a processor, but the addressee of a statutory obligation | the data of the invoices issued | Hungary | EU |
| 5 | The operator of the mail server — the Provider's own mail server | processor | recipient e-mail address, salutation name, message body, the PDF attachments (Report and invoice); the messages arriving in the customer service mailboxes | the Provider's own mail server | Hungary |
| 6 | The hosting provider and server operator — Giganet Internet Szolgáltató Kft., 4400 Nyíregyháza, Vasvári Pál u. 1. fszt., Hungary (own servers operated by the Provider) | processor | all data stored in the system (database, uploaded photographs, logs) | Hungary | Hungary |
| 7 | Studio CRM — the Provider's back-office system (the Provider's own internal system) | internal system, or processor | customer data, orders, invoices, outgoing messages and their attachments, colour-test leads, the audit log | the Provider's own internal system | Hungary |
| 8 | Plausible Analytics — the provider of the cookieless audience measurement (Plausible Insights OÜ (Estonia)) — only once audience measurement is switched on | processor | page view and event data, the visitor's IP address and browser identifier, the advertising click identifiers. It receives no name, e-mail address, postal address or photograph | Plausible Insights OÜ (Estonia) | EU |
| 9 | Meta Platforms Ireland Ltd. (Dublin, Ireland) — provider of advertising measurement — only if you have consented | independent controller, and joint controller for the advertising measurement | page-view and purchase events (amount, currency), the identifier of its own cookie. It receives no name, e-mail address, address or photograph | Ireland | EU and USA — see 8.4 | | 10 | Google Ireland Ltd. (Dublin, Ireland) — Google Ads conversion measurement — only if you have consented | independent controller | the same as above | Ireland | EU and USA — see 8.4 |
Without your consent, neither Meta nor Google is a recipient of your data. In that case your browser sends them no request at all, because the measurement code is not loaded (Cookie Notice Chapter 4).
Google is not a recipient on account of the fonts either. We serve the website's typefaces from our own server, so your browser sends no request to Google. When the PDF of the Report is produced, our own server loads a font set from Google's font service; that request originates from our server and contains no data relating to you — neither your IP address nor your browser identifier.
We conclude a processing agreement under Article 28 GDPR with our processors and bind them to confidentiality and to the application of appropriate security measures. Beyond this, we disclose data to an authority or a court only where required to do so by law.
8. Transfers to a third country
8.1 Anthropic PBC (United States of America) — standard contractual clauses (SCC)
To produce the Analysis we transfer your facial photograph and your questionnaire answers to Anthropic PBC (San Francisco, United States of America), which supplies the artificial intelligence service known as Claude as a processor. The United States qualifies as a third country.
| Question | Answer |
|---|---|
| Legal basis of the transfer | Article 46(2)(c) GDPR — the standard contractual clauses (SCC) adopted by the European Commission, contained in Anthropic's Data Processing Addendum, which becomes automatically applicable upon acceptance of the commercial terms |
| Where the text of the safeguard is available | among Anthropic's legal documents at https://www.anthropic.com/legal; you may also request a copy from us at support@colour-sense.com |
| Model training | under Anthropic's commercial terms it may not use the content transferred to train its models |
| Retention at Anthropic | under Anthropic's published commercial data retention policy, inputs and outputs are deleted within 30 days of receipt or generation; where there is a safety signal (suspected abuse), however, they may be retained considerably longer — under that policy for up to two years. This processing is governed by Anthropic's own policy and is not under our direct control |
| Zero data retention (ZDR) | We have no separate agreement with Anthropic providing for zero data retention. The default retention rule set out above therefore applies |
Important. Your photograph therefore does not remain within the European Union. There is no European data residency option on Anthropic's first-party Claude API.
8.2 Stripe — adequacy decision and standard contractual clauses
Payment is handled by Stripe. Stripe is a certified participant in the EU–U.S. Data Privacy
Framework, and therefore the primary legal basis for the transfer to the United States is the
adequacy decision under Article 45 GDPR; Stripe supports this, on a supplementary basis, with
the standard contractual clauses under Article 46(2)(c) GDPR. The safeguards are available among
Stripe's legal documents at https://stripe.com/legal; you may also request a copy from us at
support@colour-sense.com.
Anthropic and Stripe rely on different safeguards: SCC in the case of Anthropic, and an adequacy decision (DPF) together with SCC in the case of Stripe. We do not conflate the two.
8.4 Meta and Google (United States of America) — only with your consent
This section applies only if you have consented to advertising cookies. Without consent your browser sends them no request at all, so no transfer takes place.
| Question | Answer |
|---|---|
| Who the contracting entities are | Meta Platforms Ireland Ltd. and Google Ireland Ltd., both of Dublin, Ireland — that is, the contracting party is in the European Union |
| Why a third country nevertheless arises | Both groups have a US parent company and may also transfer data to the United States |
| Legal basis for the transfer | Article 45 GDPR — the EU–US Data Privacy Framework under the European Commission's Implementing Decision (EU) 2023/1795, in which both groups are certified participants; in addition, their contracts also include standard contractual clauses (SCC) |
| What they receive | page-view and purchase events (amount, currency) and the identifier of their own cookie. We transmit no name, e-mail address, billing address or uploaded photograph |
| How it can be stopped | consent can be withdrawn via the Cookie settings link in the footer, whereupon the measurement code stops immediately. Cookies already set, belonging to a third-party domain, can be deleted in your browser (Cookie Notice Chapter 9) |
8.3 The other recipients
The recipients listed in rows 3 and 4 of Chapter 7 (the invoicing service provider and NAV) process the data in Hungary, that is, within the European Economic Area; no transfer to a third country takes place in their case.
The recipients listed in rows 5–8 of Chapter 7 (the operator of the mail server, the hosting provider and server operator, Studio CRM and — once switched on — the audience measurement provider) process the data in the country indicated in Chapter 7. Should any of them process the data outside the European Economic Area, we apply a safeguard under Chapter V GDPR to that transfer and supplement this chapter accordingly.
9. Retention periods
9.1 Summary table
| Data | Retention period |
|---|---|
| Order and questionnaire data, the text of the Analysis, payment metadata | 5 years |
| Facial photograph | 30 days from delivery of the Report |
| Invoices and accounting records | at least 8 years (Section 169 of the Accounting Act) |
| Sent messages and their attachments in the mail-sending system | still to be defined — today they are kept even after successful delivery |
| Messages received in the customer service mailbox | 3 years — we do not store them in a database; the system uses only a short cache of 60 and 300 seconds respectively, and always opens the mailbox read-only |
| Documents relating to a complaint | 3 years (Section 17/A(7) of the Consumer Protection Act) |
| Free-test e-mail lead | until you unsubscribe or withdraw your consent |
| IP address used for rate limiting | 15 minutes |
| Operational logs | today, size-based rotation; time-based rule: 90 days |
| Internal audit log | still to be defined — there is no clean-up rule today |
| Administrator session | 7 days |
| Data needed to enforce a legal claim | 5 years (Section 6:22 of the Civil Code) |
9.2 Statutory limits on erasure
Your erasure request does not extend to data that we are required by law to retain, or that are necessary for the establishment, exercise or defence of legal claims (Article 17(3)(b) and (e) GDPR):
| Data | Why it stays | For how long |
|---|---|---|
| Invoices, accounting records | Section 169 of the Accounting Act; the VAT Act | 8 years |
| Documents relating to a complaint | Section 17/A(7) of the Consumer Protection Act | 3 years |
| Data needed to enforce a legal claim | limitation period under Section 6:22 of the Civil Code | 5 years |
In these cases, instead of erasure — and in so far as the statutory obligation does not extend to the data concerned — we apply anonymisation or restriction of processing.
9.3 The technical limits of erasure today — stated openly
In the interest of the fair and transparent processing required by Article 5(1)(a) GDPR, we record that fulfilling an erasure request is not automated today and is subject to the following limits:
| Limit | What it means | When it ends |
|---|---|---|
| The uploaded facial photograph | there is no scheduled or self-service deletion today; we remove the photograph by a manual procedure | |
| Anonymisation in the back-office system | for a customer who has placed an order, anonymisation takes place instead of erasure; in the course of it the country field — relevant for accounting and tax purposes — is retained | — (statutory limit, see 9.2) |
| The record of outgoing messages | the record of the message sent and its attachment stored in base64 form — including the Report containing your photograph — is not deleted by the erasure operation today | |
| The copy remaining at Anthropic | the retention described in section 8.1 is governed by Anthropic's own policy; we forward your erasure request to them as well, but we cannot guarantee that it will be carried out | — |
If you request erasure, we set out these limits item by item in our reply to you.
10. Your rights and how to exercise them
10.1 What rights you have
| Right | What it means | To which processing |
|---|---|---|
| Access (Article 15 GDPR) | you may ask whether we process your data and, if so, request a copy of it | to all |
| Rectification (Article 16) | you may ask for inaccurate data to be corrected and incomplete data to be completed | to all |
| Erasure (Article 17) | you may ask for your data to be erased, subject to the limits in section 9.2 | to all |
| Restriction of processing (Article 18) | you may ask that we only store your data and otherwise not process it — for example while you contest its accuracy | to all |
| Objection (Article 21) | you may object to processing based on legitimate interests | to rows 9, 10, 11, 12, 13 and 15 of Chapter 3 |
| Data portability (Article 20) | you may request your data in a structured, commonly used, machine-readable format, or its transmission to another controller | to automated processing based on consent or on a contract — rows 1–4, 6 and 7 of Chapter 3 |
| Withdrawal of consent (Article 7(3)) | for processing based on consent (the facial photograph, the free-test e-mail lead, advertising measurement) you may withdraw your consent at any time, without giving reasons and free of charge; this does not affect the lawfulness of processing before the withdrawal | to rows 2, 7 and 14 of Chapter 3 |
| Complaint and judicial remedy (Articles 77 and 79) | see Chapter 12 | to all |
10.2 How to exercise them
You may send your request
- by e-mail to support@colour-sense.com,
- by post to 2100 Gödöllő, Szabó Pál utca 32., Hungary.
The request is free of charge. Where we have reasonable doubts concerning the identity of the person making the request, we may ask for additional information necessary to confirm your identity (Article 12(6) GDPR) — in which case we ask only for as much data as is strictly necessary for identification.
10.3 Time limits
- We inform you of the action taken on your request without undue delay and in any event within one month of receipt (Article 12(3) GDPR).
- That period may be extended by two further months where necessary, taking into account the complexity and number of the requests; we inform you of any such extension and of the reasons for it within the original one month.
- If we take no action on your request, we inform you within one month at the latest of the reasons for that and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy (Article 12(4) GDPR).
- If we rectify or erase your data or restrict the processing, we communicate this to each recipient to whom the data have been disclosed, unless this proves impossible or involves disproportionate effort (Article 19 GDPR).
10.4 What you should know about exercising your rights
We fulfil requests manually, with staff involvement; there is currently no self-service download or deletion function on the website. This does not affect the time limits for fulfilment set out above.
11. Data security (Article 32 GDPR)
The measures below describe the position today. We list only measures that are actually in operation.
11.1 What we apply
| Area | Measure |
|---|---|
| Encryption in transit | the website is available exclusively over HTTPS (TLS) with a Let's Encrypt certificate; the Claude API is called over HTTPS; mail is sent with implicit TLS on port 465, with certificate chain verification; the incoming mailbox is accessed over IMAP on port 993, likewise with certificate verification |
| Protection of the photograph | the photograph is not served statically; it has no public or guessable web address (the file name contains a random identifier); the only route to it is an endpoint requiring administrator login, which sends a header prohibiting caching (private, no-store) |
| Upload validation | the real type of the uploaded file is checked on the basis of the file content (JPEG, PNG, WebP only) and a size limit is applied |
| Passwords | administrator passwords are never stored in readable form, only as a cryptographic hash (using scrypt in the back-office system and bcrypt in the administration module of the web application) |
| Sessions | the administrator session cookie is set with HttpOnly and SameSite=Lax, and with the Secure flag in production; the session expires after 7 days |
| Protection against abuse | rate limiting on the API endpoints; at most 5 login attempts per 15 minutes |
| Application-level protections | security HTTP headers; strict, allow-list based browser-side access control (CORS); parameterised database queries |
| Network isolation | the cache and the back-end application publish no port on the public internet and are reachable only on the internal container network; the sole ingress to the website is the reverse proxy. The database runs on a separate server — the database server runs on a machine separate from the web server, in the data centre of the same provider describes how access to it is restricted |
| Internal system connections | calls to the back-office system are authenticated with an HMAC-SHA256 signature; notifications from the payment provider are accepted with signature verification |
| Data minimisation by design | incoming customer messages are not stored in a database and the mailbox is opened read-only; we collect no browser identifier; we do not send the e-mail address or the billing data to the AI provider |
11.2 What we do not apply — so as not to create a false impression
- The application uses no encryption at rest: we do not encrypt the uploaded photographs or the database fields at application level.
- Encryption of the connection between the application and the database server is not uniform today: some of the connections are encrypted but without certificate chain verification, and others are established without encryption. The introduction of a uniform database connection protected by certificate verification is in progress.
- There is no access log recording which administrator viewed which photograph, and the application has a single administrator privilege level.
11.3 Personal data breach
In the event of a personal data breach we act in accordance with Article 33 GDPR and, where the breach is likely to result in a high risk to your rights and freedoms, we also inform you under Article 34 GDPR — without undue delay.
12. Remedies: supervisory authority and courts
12.1 Complaint to the supervisory authority (Article 77 GDPR)
If you consider that the processing of your personal data infringes the GDPR, you may lodge a complaint with the supervisory authority:
| Item | Value |
|---|---|
| Name | Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) |
| Seat | 1055 Budapest, Falk Miksa utca 9–11., Hungary |
| Postal address | 1363 Budapest, Pf. 9., Hungary |
ugyfelszolgalat@naih.hu |
|
| Website | https://www.naih.hu |
If your habitual residence is in another Member State of the European Union, you may also lodge your complaint with the supervisory authority of that Member State.
12.2 Judicial remedy (Article 79 GDPR; Section 23 of the Infotv.)
If your rights are infringed you may bring an action before the courts. In Hungary such proceedings fall within the competence of the regional court (törvényszék) and may — at your choice — also be brought before the regional court of your place of residence or stay. Court proceedings are available alongside, and independently of, a complaint to the supervisory authority.
You may also claim compensation for an infringement (Article 82 GDPR).
13. Minors
Our service may be used only by persons who have reached the age of 18. We do not knowingly collect personal data from persons under the age of 18, and we do not offer the service to them.
If we become aware that we are processing the data of a person under the age of 18, we erase the data without delay — except for data that we are required by law to retain (section 9.2).
If you are a parent or legal guardian and you believe that your child has given us data without your consent, please let us know at support@colour-sense.com.
14. Cookies and data stored on your terminal equipment
For the operation of the website we use only cookies that are strictly necessary; a third-party cookie is created on our own domain only with your consent (the advertising cookies of Meta and Google — row 14 of Chapter 3, section 4.1 of the Cookie and Storage Notice). That is not the whole picture, however: the ordering process also places data in your browser's storage — including your name, your e-mail address, your billing address and the facial photograph you upload.
Cookies:
| Name | Purpose | Lifetime |
|---|---|---|
NEXT_LOCALE |
remembering the language you selected | session |
coloursense.sid |
administrator login — never created for a visitor | 7 days |
crm_admin |
administrator login to the back-office system — never created for a visitor to the webshop | 7 days |
Information stored on your terminal equipment that does not qualify as a cookie:
| Key | What it stores | For how long | Why we store it |
|---|---|---|---|
cs-premium-flow-v1 |
the full state of the order form: first name, e-mail address, questionnaire answers, full billing address | until you close the tab; deleted upon successful payment | strictly necessary for the provision of the service you expressly requested (so that the order survives the redirection to the payment page) |
cs-premium-flow-photo-v1 |
the facial photograph you uploaded (in base64 form) | until you close the tab; deleted upon successful payment and when you remove the image | as above — strictly necessary |
cs-quiz-result |
the result of the free test | 48 hours | strictly necessary to display the test result you expressly requested |
cs-attribution |
advertising click identifiers and campaign parameters | until you close the tab | ⚠️ measurement / attribution purpose — this is not storage strictly necessary for the provision of the service. Its contents do not stay on your device: when the order is submitted, your browser also sends the click identifiers to our own server, where — without being written to the database — they are recorded in the operational log, next to your e-mail address (row 10 of Chapter 3) |
cs-purchase-<identifier> |
a technical flag preventing the purchase event from being measured twice | until you close the tab | ⚠️ it serves audience measurement and therefore also belongs to storage for measurement purposes |
The consent bar asks only about advertising cookies (row 14 of Chapter 3): our own cookies
are strictly necessary for the operation of the site and audience measurement is cookieless, so
we do not ask for consent to those. The decision you make on the bar is kept in your browser's
local storage (cs-consent) (section 6.2.2 and Chapter 8 of the Cookie and Storage Notice).
However, the last two rows
of the table above (the advertising click identifiers and the measurement flag) cannot be regarded
as strictly necessary for the provision of the service, and therefore — consistently with row 13
of Chapter 3 — the consent requirement under Section 155(4) of the Eht. may arise for them
irrespective of the fact that they are not cookies. Until this is resolved, we will either make
these two storage items subject to consent or discontinue them.
During card payment, Stripe's own cookies are created on Stripe's own domain (not on ours).
The list above is based on the code of our own application. If a content delivery network or a web application firewall (CDN/WAF) is ever placed in front of the website, it may set its own cookie on our domain; in that case this chapter and the Cookie and Storage Notice will need to be supplemented.
Detailed information: Cookie and Storage Notice.
15. Changes to this notice
We may amend this notice from time to time — because of a change in the law, guidance from an authority, or a change in the service. We publish the version in force on the website, indicating the version number and the date of entry into force. In the event of a material change, we inform those data subjects whose contact details we hold before the change takes effect.
Version: 1.2 · Effective: 7 October 2026