PRIVACY POLICY

Last updated: October 2026

Budai Compliance (“Budai Compliance”, “BC”, “we”, “us” or “our”) respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how we collect, use, store and protect personal data when you visit our website, contact us, book a meeting, enquire about our services or otherwise interact with Budai Compliance.

It also explains your rights under applicable data-protection laws, including, where applicable, the EU General Data Protection Regulation (“GDPR”).

1. WHO WE ARE

Budai Compliance is an independent compliance consultancy providing regulatory, AML/CFT, licensing, risk, responsible gaming and related advisory services, primarily to businesses operating within the iGaming and related sectors.

For the purposes of applicable data-protection legislation, the controller responsible for personal data processed through this website is:

Budai Compliance

Legal entity: Budai Gabor EV / Trading as Budai Compliance

Registered/business address: 1033. Budapest, Korhaz utca 7. VI/32. Hungary

Email: info@budaicompliance.com

Website: www.budaicompliance.com

If you have questions about this Privacy Policy or how we process your personal data, please contact us using the email address above.

2. PERSONAL DATA WE MAY COLLECT

Depending on how you interact with Budai Compliance, we may collect the following categories of personal data.

Contact and identification information

This may include:

  • your name;

  • job title;

  • company or organization;

  • email address;

  • telephone number; and

  • other contact information you voluntarily provide.

Enquiry and communication information

When you contact us, we may process:

  • the content of your enquiry;

  • correspondence between you and Budai Compliance;

  • information concerning the services you are interested in; and

  • other information you voluntarily provide.

Meeting and booking information

If you book a call or meeting with Budai Compliance, we may process:

  • your name;

  • email address;

  • company;

  • meeting date and time;

  • information submitted as part of the booking process; and

  • communications relating to the meeting.

Where third-party scheduling, calendar or video-conferencing services are used, those providers may also process personal data in accordance with their own privacy policies.

Technical and website information

Depending on the technologies used on our website, we may automatically collect certain technical information, such as:

  • IP address;

  • browser type;

  • device information;

  • operating system;

  • approximate location derived from technical information;

  • pages visited;

  • referral source;

  • date and time of access; and

  • website interaction information.

The extent of this processing depends on the hosting, analytics and cookie technologies implemented on the website.

3. HOW WE COLLECT PERSONAL DATA

We may collect personal data:

  • directly from you when you contact us;

  • when you submit an enquiry;

  • when you book a consultation or meeting;

  • when you correspond with us by email or other communication channels;

  • automatically when you interact with our website, where applicable;

  • through professional networking platforms where you choose to communicate with us; and

  • from publicly available business and professional sources where permitted by law.

4. HOW WE USE YOUR PERSONAL DATA

We may use personal data to:

  • respond to enquiries;

  • communicate with prospective and existing clients;

  • arrange meetings and consultations;

  • provide information about our services;

  • assess whether Budai Compliance can provide requested services;

  • prepare proposals and potential engagements;

  • manage client and business relationships;

  • operate and maintain our website;

  • maintain the security of our systems and website;

  • improve our website and services;

  • maintain appropriate business records;

  • comply with legal and regulatory obligations; and

  • establish, exercise or defend legal claims.

Where permitted by applicable law, we may also use business contact details to communicate with you about relevant Budai Compliance services or professional developments.

5. LEGAL BASES FOR PROCESSING

Where the GDPR applies, we process personal data only where we have an appropriate legal basis.

Depending on the circumstances, this may include:

Legitimate interests

We may process personal data where necessary for our legitimate business interests, including:

  • responding to business enquiries;

  • developing and maintaining professional relationships;

  • operating our consultancy;

  • maintaining website and information security;

  • improving our services; and

  • communicating appropriately with prospective and existing business contacts.

We consider the impact on your rights and interests when relying on legitimate interests.

Steps prior to entering into a contract

Where you enquire about engaging Budai Compliance, processing may be necessary to take steps at your request before entering into a contractual relationship.

Performance of a contract

Where you become a client, certain personal data may be processed as necessary to perform our contractual obligations.

Additional privacy information may be provided as part of the client onboarding or engagement process where appropriate.

Legal obligations

We may process personal data where necessary to comply with applicable legal, regulatory, accounting or other obligations.

Consent

Where required, we may rely on your consent, including for certain cookies, analytics technologies or marketing communications.

Where processing is based on consent, you may withdraw your consent at any time.

Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.

6. COOKIES AND ANALYTICS

Our website may use cookies and similar technologies for functionality, security, analytics and website performance.

Some cookies may be strictly necessary for the website to operate. Other cookies, including certain analytics or marketing technologies, may require your consent.

Where required, non-essential cookies will not be activated until appropriate consent has been obtained.

Further information about cookies and similar technologies used on the Budai Compliance website may be provided in our Cookie Policy and through any cookie-consent mechanism implemented on the website.

7. THIRD-PARTY SERVICE PROVIDERS

We may use trusted third-party providers to support our business and website.

These may include providers of:

  • website hosting;

  • website development;

  • email;

  • cloud storage;

  • calendar and scheduling services;

  • video conferencing;

  • analytics;

  • cybersecurity; and

  • other professional or technology services.

Such providers may process personal data on our behalf where necessary to provide their services.

We take reasonable steps to use service providers that provide appropriate protections for personal data.

8. GOOGLE SERVICES

Budai Compliance may use Google services for business communications, calendar management, meeting scheduling or video conferencing.

Where you book or participate in a meeting using such services, relevant information may be processed by Google in accordance with its applicable privacy terms.

You should review the privacy information provided by the relevant third-party service where appropriate.

9. FRAMER

The Budai Compliance website may be designed, hosted or delivered using Framer.

As a result, certain technical information relating to website access and operation may be processed through Framer’s infrastructure.

The extent of such processing depends on the configuration and functionality used on the website.

10. DISCLOSURE OF PERSONAL DATA

We do not sell your personal data.

We may disclose personal data where reasonably necessary to:

  • technology and hosting providers;

  • professional advisers;

  • contractors providing services to Budai Compliance;

  • regulatory or governmental authorities where legally required;

  • courts or law-enforcement authorities where required by law; or

  • other parties where necessary to establish, exercise or defend legal rights.

Where we use processors to handle personal data on our behalf, we seek to ensure that appropriate contractual and data-protection safeguards are in place where required.

11. INTERNATIONAL DATA TRANSFERS

Some service providers we use may process or store personal data outside the European Economic Area (“EEA”).

Where personal data is transferred internationally and the GDPR applies, we take reasonable steps to ensure that an appropriate transfer mechanism or safeguard is used where required.

This may include:

  • an adequacy decision issued by the European Commission;

  • Standard Contractual Clauses;

  • another legally recognized transfer mechanism; or

  • another applicable safeguard permitted by data-protection law.

12. DATA RETENTION

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected and to meet applicable legal, regulatory, contractual and business requirements.

Retention periods may vary depending on the nature of the information and our relationship with you.

For example, enquiry and correspondence information may be retained for a reasonable period to manage potential future communications and maintain appropriate business records.

Where a formal client relationship is established, information may be retained for longer periods in accordance with contractual, legal, regulatory and professional requirements.

When personal data is no longer required, we will delete, anonymize or securely dispose of it where reasonably practicable and legally appropriate.

13. DATA SECURITY

We take reasonable technical and organizational measures designed to protect personal data against:

  • unauthorized access;

  • unlawful processing;

  • accidental loss;

  • destruction;

  • alteration; and

  • unauthorized disclosure.

However, no internet-based service or electronic transmission can be guaranteed to be completely secure.

14. YOUR DATA-PROTECTION RIGHTS

Where the GDPR or equivalent data-protection legislation applies, you may have rights including the right to:

  • request access to your personal data;

  • request correction of inaccurate or incomplete information;

  • request deletion of personal data in certain circumstances;

  • request restriction of processing;

  • object to certain processing, including processing based on legitimate interests;

  • request portability of certain personal data;

  • withdraw consent where processing is based on consent; and

  • lodge a complaint with a competent data-protection supervisory authority.

These rights are subject to applicable legal conditions and exemptions.

To exercise your rights, please contact:

info@budaicompliance.com

We may need to verify your identity before responding to certain requests.

15. DIRECT MARKETING

Where permitted by applicable law, we may contact business contacts regarding Budai Compliance services that we reasonably believe may be relevant to them.

Where consent is required, we will seek appropriate consent before sending such communications.

You may opt out of marketing communications at any time by using any unsubscribe mechanism provided or by contacting:

info@budaicompliance.com

We will respect applicable objections and opt-out requests.

16. LINKS TO OTHER WEBSITES

Our website may contain links to websites operated by third parties.

Budai Compliance is not responsible for the privacy practices, security or content of third-party websites.

We encourage you to review the privacy policies of third-party websites before providing personal information to them.

17. CHILDREN’S PRIVACY

The Budai Compliance website and services are intended for business and professional audiences and are not directed at children.

We do not knowingly seek to collect personal data from children through this website.

18. AUTOMATED DECISION-MAKING

Budai Compliance does not use personal data collected through this website to make decisions based solely on automated processing that produce legal or similarly significant effects on individuals, unless otherwise disclosed and permitted by applicable law.

19. CHANGES TO THIS PRIVACY POLICY

We may update this Privacy Policy periodically to reflect changes in:

  • our website;

  • our services;

  • the technologies we use;

  • our data-processing activities; or

  • applicable legal requirements.

The latest version will be published on this page together with an updated revision date.

We encourage visitors to review this Privacy Policy periodically.

20. CONTACT US

If you have questions about this Privacy Policy, wish to exercise a data-protection right or have concerns about how your personal data is handled, please contact:

Budai Compliance

Email: info@budaicompliance.com

Website: budaicompliance.com

You also have the right, where applicable, to lodge a complaint with the competent data-protection supervisory authority.

© 2026 Budai Compliance. All rights reserved.