← Back to flz.works

Privacy policy

Last updated: 10 September 2026

This policy explains what personal data flz.works and its sub-pages (such as /autosalon, /id, /uidesign and the invite-only intranet) process, why, and what rights you have under the EU General Data Protection Regulation (GDPR) and Hungarian Act CXII of 2011 (Infotv.).

1. Who is responsible

The data controller is Bence Flosz, a private individual based in Budapest, Hungary, who runs flz.works as a non-commercial personal portfolio (“FLZ Works”).

To contact the controller about privacy, use the Message me form on the home page and mention “privacy request” in your message. There is no designated data protection officer.

2. What data is processed and why

Visiting the site

When you open a page, the hosting provider necessarily processes technical connection data (your IP address, the time of the request and basic browser information) to deliver the page and keep the service secure. Legal basis: legitimate interest in operating a secure website (GDPR Art. 6(1)(f)). These logs are kept only for the provider's short-term operational retention period.

Optional analytics (only with your consent)

If you click Allow in the consent banner, the site records a random session ID, which site section and page you opened, how long the page was visible, and whether you opened a social link or the vCard. No IP address, user agent, referrer, cookie or cross-site identifier is stored. If your browser sends a Global Privacy Control or Do Not Track signal, analytics stay off. Legal basis: consent (GDPR Art. 6(1)(a)). You can withdraw at any time with the Cookies/analytics button in the page footer. Visit records are deleted after 370 days.

Message form

When you send a message, your email address, your message and (optionally) your name are stored so that the controller can read and answer it. Legal basis: taking steps at your request and the legitimate interest in replying (GDPR Art. 6(1)(b) and (f)). Messages are kept until the conversation is finished and they are deleted; you can ask for earlier deletion at any time.

Intranet access requests

The private intranet (for example the AutoPiac showroom) is invite-only. When you request access, your name, email address, IP address and the time of the request are stored, and an approval email containing these details is sent to the site owner. The IP address is also used to limit repeated requests and to block abuse. Legal basis: legitimate interest in controlling access and preventing abuse (GDPR Art. 6(1)(f)). Requests are deleted 30 days after the request or the granted access expires. An approved request sets an access cookie (see the cookie policy).

Accounts and sign-in

Some areas (the AutoPiac prototype and the site owner's Studio) require an account. For email registration your name, email address and a securely hashed password are stored; with Google Sign-In, Google shares your name and email address. Content you create there (for example listings, favourites or saved searches) is stored with your account. Legal basis: providing the service you asked for (GDPR Art. 6(1)(b)). Account data is kept until you ask for the account to be deleted.

Embedded 3D viewer

3D models are shown with a viewer from Sketchfab (Epic Games). Nothing is requested from Sketchfab until you press the play button on the model (a local image is shown until then), and the choice is not remembered; once loaded, Sketchfab receives your IP address and may set its own cookies under Epic Games' privacy policy. Legal basis: consent (GDPR Art. 6(1)(a)).

3. Service providers

Personal data is not sold and is not used for advertising. It is only shared with these providers, as needed:

  • Railway Corporation (USA): hosting, database and file storage. Privacy policy
  • Resend (USA): delivery of intranet approval emails. Privacy policy
  • Google (Ireland/USA): Google Sign-In on the sign-in and registration pages, and a fallback email service. Privacy policy
  • Sketchfab / Epic Games: only when you press play to load a 3D model.

Where a provider processes data outside the European Economic Area, the transfer relies on the safeguards that provider offers, such as the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.

Project images from the owner's own Instagram and TikTok accounts are copied to and served from flz.works, so viewing them does not contact those platforms. Links to social profiles open the external site, where that platform's own privacy policy applies.

4. Your rights

Under the GDPR you have the right to:

  • access the personal data held about you and receive a copy;
  • have inaccurate data corrected, and have data erased or its processing restricted;
  • receive data you provided in a portable format;
  • object to processing based on legitimate interest;
  • withdraw consent at any time, without affecting processing that happened before.

Send requests through the message form; they will be answered within one month. You can also lodge a complaint with the Hungarian supervisory authority, the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1055 Budapest, Falk Miksa utca 9–11, naih.hu, or with the authority where you live, or go to court.

5. Other information

No automated decision-making or profiling takes place. Providing data is voluntary, but the message form, access requests and accounts cannot work without the fields marked as required.

If this policy changes, the date at the top is updated. Cookie and browser storage details are listed in the cookie policy.