Privacy Notice

(Noho Advisory – coaching-based strategic advisory)

1. Introduction

Trust and confidentiality are foundational to how I work. In handling personal data, I not only ensure compliance with applicable regulations, but also treat all shared information with the highest level of discretion and responsibility.


Information shared during coaching and strategic advisory engagements is considered confidential and is used solely for the purpose of delivering the service.


The purpose of this notice is to provide a clear and transparent overview of how personal data is handled.

2.Data Controller

Name: Noémi Holecz (sole proprietor)
Address: 1089 Budapest, Benyovszky Móric utca 33
Email: info@nohoadvisory.com
Tax ID: 91567110-2-42

3. Purpose, Legal Basis, and Duration of Data Processing

Processing activity

Data collected

Legal basis

Retention period

Contact (inquiry, application)

name, email, phone, message

GDPR Art. 6(1)(b)

up to 12 months

Appointment scheduling

name, email, scheduling details

GDPR Art. 6(1)(b)

up to 12 months

Coaching & advisory

information voluntarily shared by the client

GDPR Art. 6(1)(b)

5 years

Invoicing

name, address, tax data

GDPR Art. 6(1)(c)

8 years

Newsletter (if applicable)

email, name

GDPR Art. 6(1)(a)

until consent is withdrawn

Marketing & analytics

IP address, cookie data

GDPR Art. 6(1)(a) or (f)

up to 12 months

 

4. Nature of Data Processed During Coaching

During coaching and advisory engagements, clients may choose to share personal, business, or potentially sensitive information at their own discretion.


The data controller:


• treats all information with strict confidentiality
• handles personal data with heightened care
• does not disclose it to third parties

5. Data Processors

The following service providers are used to support operations:


Hosting provider – website functionality
WordPress system and related plugins (e.g., contact forms) – website and forms

Microsoft (Outlook / Microsoft 365) – email communication


Planned in the future:


Newsletter service provider (e.g., Mailchimp / Brevo)


Personal data is not shared with third parties for commercial purposes.

6. Data Transfers to Third Countries

Certain service providers (e.g., Microsoft or newsletter platforms) may process data outside the European Economic Area.


Such transfers are conducted in compliance with GDPR safeguards (e.g., standard contractual clauses).

7. Cookies

This website uses cookies to ensure proper functionality and to improve the user experience.


Legal basis:


• necessary cookies: legitimate interest (GDPR Art. 6(1)(f))
• analytics and marketing cookies: consent (GDPR Art. 6(1)(a))


Cookie preferences can be updated at any time via the website’s cookie banner or through browser settings.

8. Consent Management and Documentation

User consent (e.g., for form submissions or newsletter sign-ups) is recorded and can be demonstrated if required.


This may include:


• the date and time of consent
• the method by which consent was given

9. Data Security

Appropriate technical and organizational measures are in place to protect personal data, including:


• SSL encryption
• password protection
• restricted access controls
• regular system backups


Any data security incidents are documented, and affected individuals and authorities are notified where required.

10. Basis for Data Retention Periods

Retention periods are determined based on legal obligations (particularly accounting and tax requirements), as well as the nature of the services provided.

11. Automated Decision-Making

No automated decision-making or profiling is used.

12. Rights of Data Subjects

You have the right to:


• access your personal data
• request correction
• request deletion
• restrict processing
• object to processing
• request data portability


You also have the right to receive clear information before your data is processed.

13. Handling Requests

Requests are handled without undue delay, and no later than one month.


If necessary, this period may be extended by up to two additional months.


Identity verification may be required before fulfilling a request.


If a request is clearly unfounded or excessive, the data controller may:


• charge a reasonable administrative fee, or
• decline to act

14. Legal Remedies

If you believe your data has not been handled appropriately, you may file a complaint with:


Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9-11
Website: https://naih.hu


You also have the right to pursue legal remedies through the courts.

15. Contact Regarding Data Protection