Effective date: 25th April 2026
Website: ostarakreative.com / ostarakreative.hu / kimberleyzagyva.com
Operator: Zagyva Kimberley Jo-Ann e.v.
Registered address: HUNGARY-3335 Bükkszék, Bem József utca 1.
Email: info@kimberleyzagyva.com1. Who we areThis privacy policy explains how Zagyva Kimberley Jo-Ann e.v., operating under the trading names Ostara Kreative and Kimberley Zagyva, collects, uses, and protects your personal data. Zagyva Kimberley Jo-Ann e.v. is the data controller for all personal data processed through this website and in connection with the services and digital products offered under these trading names.
We take your privacy seriously. This policy is written to be clear and readable, not to hide anything in legal language.
2. What data we collect and why2a. Website enquiries and contact formsWhen you submit a contact form on this website, we collect your name and email address, and any information you choose to include in your message. We use this data to respond to your enquiry. The legal basis is our legitimate interest in responding to people who contact us (GDPR Article 6(1)(f)).
2b. Discovery call bookingsWhen you book a discovery call, we collect your name, email address, and any additional information requested in the booking form. This is processed through 17hats and Google Calendar. The legal basis is the steps taken at your request prior to entering a contract (GDPR Article 6(1)(b)).
2c. Email subscribers and lead magnetsWhen you sign up to our email list, whether through a lead magnet, freebie, or general opt-in form, we collect your name and email address. We use this data to send you the content you requested, along with newsletters, updates, and promotional emails about our products and services. The legal basis is your consent (GDPR Article 6(1)(a)). You can withdraw your consent and unsubscribe at any time by clicking the unsubscribe link in any email.
2d. Clients — service contractsWhen you engage us for business services, we collect and process the personal and business data necessary to deliver those services. Depending on the nature of the engagement, this may include your name, email address, business name, website, and information about your business operations, team, finances, or clients. The legal basis is the performance of a contract to which you are a party (GDPR Article 6(1)(b)).
Contracts are issued and managed via 17hats or email. Client work is managed and communicated through 17hats, Google Drive, Slack, Asana, Notion, and email, depending on the project. All platforms are listed in Section 5.
2e. Digital product purchases via GumroadWhen you purchase a digital product through Gumroad, the transaction is processed entirely by Gumroad, Inc. We receive limited order information such as your name and email address to fulfil your purchase and provide customer support. Gumroad is an independent data controller for the payment and transaction data it collects.
Gumroad's privacy policy:
https://gumroad.com/privacy2f. Digital product purchases via EtsyWhen you purchase a digital product through our Etsy shop, the transaction is processed by Etsy, Inc. Etsy is an independent data controller for the data it collects. We receive the information necessary to fulfil your order.
Etsy's privacy policy:
https://www.etsy.com/legal/privacy2g. Invoicing and payment — service clientsFor contracted service clients, we issue invoices via
Számlázz.hu in compliance with Hungarian invoicing law. Payment is accepted via Wise payment links, which may process payments through Apple Pay, Google Pay, Klarna, or direct bank transfer. We do not store your payment card details. The legal basis for processing invoicing data is our legal obligation under Hungarian tax and accounting law (GDPR Article 6(1)(c)) and the performance of a contract (GDPR Article 6(1)(b)).
2h. Analytics and trackingWe use Google Analytics and Meta Pixel on this website to understand how visitors interact with our content and to improve our marketing. This data is only collected with your consent, which you provide or decline via the cookie consent banner when you first visit the site. See our Cookie Policy for full details.
2i. Social media and ManyChatWe use ManyChat to manage automated interactions via Instagram and Facebook. If you interact with our social media accounts through a ManyChat flow, your Instagram or Facebook username and message content may be processed. If you provide your email address through a ManyChat flow, it will be added to our Flodesk email list with your consent. ManyChat operates within Meta's platform and is subject to Meta's terms and privacy policy.
2j. The Klub membershipThe Klub is a low-cost membership community operated by Zagyva Kimberley Jo-Ann e.v. under the Kimberley Zagyva brand. Membership subscriptions are processed by Gumroad, Inc. on a recurring basis. When you subscribe to the Klub, your name, email address, and subscription data are processed by Gumroad as an independent data controller. We receive your name and email address to manage your membership.
Gumroad's privacy policy:
https://gumroad.com/privacyThe Klub community operates via a WhatsApp group administered by Zagyva Kimberley Jo-Ann e.v. By joining the WhatsApp group, you acknowledge and consent to the following: your phone number and WhatsApp profile name will be visible to other members of the group; your messages and participation within the group are visible to all group members; WhatsApp is operated by Meta Platforms Ireland Limited and your data is processed in accordance with WhatsApp's privacy policy at
https://www.whatsapp.com/legal/privacy-policy. We do not share your phone number with any third party other than through your participation in the WhatsApp group itself. You may leave the WhatsApp group at any time without affecting your membership subscription.
The legal basis for processing your membership and community data is the performance of a contract (GDPR Article 6(1)(b)) and your consent to joining the WhatsApp group (GDPR Article 6(1)(a)).
How long we keep your dataWe keep your data only for as long as necessary for the purpose for which it was collected, or as required by law.
Email subscribers: until you unsubscribe or request deletion.
Enquiry and booking data: up to 12 months from the date of contact if no contract follows.
Client data: for the duration of the contract and for 8 years afterward in line with Hungarian accounting and tax law requirements.
Invoicing records: 8 years as required by Hungarian law.
Analytics data: as defined by Google Analytics retention settings, maximum 26 months.
Klub membership data: for the duration of your membership and up to 12 months after cancellation, except where invoicing records require longer retention under Hungarian law.
Who we share your data withWe do not sell your personal data. We do not share it with third parties for their own marketing purposes. We share data only with the service providers listed below who help us operate our business, and only to the extent necessary.
All third-party processors are required to handle your data in accordance with GDPR. Where data is transferred outside the European Economic Area — including to the United States — this is done under Standard Contractual Clauses approved by the European Commission, unless another appropriate safeguard applies.
Third-party processors
Flodesk, Inc. — email marketingPurpose: Storing email subscriber lists and sending email communications
Data location: USA — Standard Contractual Clauses apply
Privacy policy:
https://flodesk.com/privacyGoogle LLC / Google Ireland Limited — analytics, email, calendar, file storage
Purpose: Website analytics (Google Analytics), email (Gmail), calendar management (Google Calendar), document storage and sharing (Google Drive)
Data location: EEA and USA — Standard Contractual Clauses apply
Privacy policy:
https://policies.google.com/privacyMeta Platforms Ireland Limited — advertising and social media
Purpose: Website analytics and advertising (Meta Pixel), social media interactions (Instagram, Facebook)
Data location: EEA and USA — Standard Contractual Clauses apply
Privacy policy:
https://www.facebook.com/privacy/policy/Showit, Inc. — website hosting
Purpose: Hosting this website
Data location: USA — Standard Contractual Clauses apply
Privacy policy:
https://showit.com/privacy-policy/17hats, Inc. — client management and contracts
Purpose: Contact forms, booking management, contracts, invoicing
Data location: USA — Standard Contractual Clauses apply
Privacy policy:
https://www.17hats.com/privacy-policy.htmlSlack Technologies LLC — client communication
Purpose: Project communication with clients
Data location: USA — Standard Contractual Clauses apply
Privacy policy:
https://slack.com/intl/en-gb/privacy-policyAsana, Inc. — project management
Purpose: Managing client projects and tasks
Data location: USA — Standard Contractual Clauses apply
Privacy policy:
https://asana.com/privacyNotion Labs, Inc. — documentation and client portals
Purpose: Internal documentation and client-facing portals
Data location: USA — Standard Contractual Clauses apply
Privacy policy:
https://www.notion.so/privacyWise Payments Limited — payment processing
Purpose: Processing payments for service invoices
Data location: UK and EEA — adequacy decision and Standard Contractual Clauses apply
Privacy policy:
https://wise.com/gb/legal/privacy-policySzámlázz.hu (KBOSS.hu Kft.) — invoicing
Purpose: Issuing invoices in compliance with Hungarian law
Data location: Hungary
Privacy policy:
https://www.szamlazz.hu/adatkezeles/Gumroad, Inc. — digital product sales and Klub membership subscriptions
Purpose: Processing digital product transactions and recurring Klub membership subscriptions
Note: Gumroad is an independent data controller for transaction and subscription data
Data location: USA
Privacy policy:
https://gumroad.com/privacyEtsy, Inc. — digital product sales
Purpose: Processing digital product transactions via Etsy marketplace
Note: Etsy is an independent data controller for transaction data
Data location: USA
Privacy policy:
https://www.etsy.com/legal/privacyManyChat, Inc. — social media automation
Purpose: Automated messaging flows on Instagram and Facebook
Data location: USA — Standard Contractual Clauses apply
Privacy policy:
https://manychat.com/privacyWhatsApp / Meta Platforms Ireland Limited — membership community communication
Purpose: Operating the Klub community WhatsApp group
Note: Members' phone numbers are visible to other group members within the WhatsApp group. WhatsApp is operated by Meta Platforms Ireland Limited and acts as an independent data controller for platform-level data processing.
Data location: EEA and USA — Standard Contractual Clauses apply
Privacy policy:
https://www.whatsapp.com/legal/privacy-policyYour rightsUnder GDPR and Hungarian law, you have the following rights regarding your personal data. You can exercise any of these rights by contacting us at
info@kimberleyzagyva.com. We will respond within 30 days.
- Right of access — You can request a copy of the personal data we hold about you.
- Right to rectification — You can ask us to correct inaccurate or incomplete data.
- Right to erasure — You can ask us to delete your personal data where there is no legitimate reason for us to continue holding it.
- Right to restriction — You can ask us to restrict how we use your data while a complaint or query is resolved.
- Right to data portability — You can request your data in a structured, machine-readable format.
- Right to object — You can object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent — Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
If you are not satisfied with how we handle your data, you have the right to lodge a complaint with the Hungarian data protection authority:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Email:
ugyfelszolgalat@naih.huWebsite:
www.naih.huAddress: H-1055 Budapest, Falk Miksa utca 9-11.
If you are based in the UK, you may also contact the Information Commissioner's Office (ICO) at
www.ico.org.uk.CookiesThis website uses cookies. For full details of the cookies we use and how to manage your preferences, please see our Cookie Policy.
Children's dataOur website and services are not directed at children under the age of 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at
info@kimberleyzagyva.com and we will delete it promptly.
Changes to this policyWe may update this privacy policy from time to time to reflect changes in our practices or legal requirements. The effective date at the top of this page will reflect any updates. We recommend checking this page periodically.