Privacy Policy & GDPR Compliance
Buy-Solar.Online | 3Buy Solar
Version: 2026.08
Effective Date: 24 August 2026
Last Updated: 24 August 2026
1. Introduction
Buy-Solar.Online by 3Buy Solar respects the privacy of customers, website visitors, professional solar installers, resellers, contractors, suppliers, business representatives and other individuals who interact with our website and services.
This Privacy Policy explains how personal data is collected, used, stored, disclosed and protected when you:
- visit Buy-Solar.Online;
- create or maintain a customer account;
- apply for B2B, installer, reseller or other trade access;
- purchase products or request quotations;
- communicate with us;
- subscribe to marketing communications;
- contact manufacturer support or request warranty assistance;
- interact with our social-media accounts;
- submit documents or information to us; or
- otherwise use services provided through the 3Buy Solar platform.
Our processing of personal data is governed primarily by Regulation (EU) 2016/679 – the General Data Protection Regulation (GDPR), together with applicable Hungarian, Slovak and European Union data-protection, electronic-communications and privacy legislation.
For corporate customers, GDPR applies to personal data relating to identifiable natural persons, including company directors, employees, representatives, sole traders, installers, authorised purchasers and other business contacts.
2. Data Controllers
Joint Controllers
Personal data processed through Buy-Solar.Online is managed by the following joint controllers where they jointly determine the purposes and means of processing.
Suncrest Kft.
Platform Operator and Commercial Operator
Registered Address:
Nemzetőr u. 9
2370 Dabas
Hungary
Office & Warehouse:
Törökbálint DEPO
Raktárvárosi út 1
2045 Törökbálint
Hungary
EU VAT Number: HU32865963
E-mail: info@buy-solar.online
Apelida s.r.o.
Content, Communications and Data-Protection Administration
Bastova Street 2301/16
94501 Komárno
Slovakia
ICO: 43965318
EU VAT Number: SK2022539002
E-mail: privacy@buy-solar.online
Joint-Controller Arrangement
Suncrest Kft. and Apelida s.r.o. have allocated their respective responsibilities under an arrangement pursuant to Article 26 GDPR.
In general:
- Suncrest Kft. is responsible for webshop operation, customer registration, account administration, commercial transactions, invoicing, payment coordination, order fulfilment and logistics;
- Apelida s.r.o. is responsible for website-content administration, customer communications, CRM activities and GDPR compliance administration;
- both entities may jointly determine the purposes and means of certain processing carried out through Buy-Solar.Online.
Apelida s.r.o. acts as the primary contact point for privacy and data-subject requests.
This allocation does not restrict your rights. Where Suncrest Kft. and Apelida s.r.o. act as joint controllers, you may exercise your GDPR rights against either controller.
Further information concerning the essential elements of the joint-controller arrangement is available on request.
3. Brand Owner and Platform Licensor
3Buy LLC
5011 Gate Parkway, Building 100
Jacksonville, Florida 32256
United States
E-mail: hello@3buy.org
3Buy LLC owns and licenses certain trademarks, branding, domain infrastructure and platform-related intellectual property used by Buy-Solar.Online.
3Buy LLC does not become a controller of Buy-Solar.Online customer information merely by acting as brand owner or licensor.
Where limited personal data is disclosed to 3Buy LLC for legitimate platform, technical, brand-protection or support purposes, such processing is subject to applicable contractual and data-protection requirements.
4. Data Protection Contact
Privacy and GDPR inquiries may be directed to:
3Buy EU Compliance Office
Bastova Street 2301/16
94501 Komárno
Slovakia
E-mail: gdpr@buy-solar.online
General privacy requests may also be sent to:
Where a formal Data Protection Officer is required or designated under applicable law, the relevant contact details will be made available through this Privacy Policy.
5. Scope of This Privacy Policy
This Privacy Policy applies to personal data processed through:
- Buy-Solar.Online;
- customer and trade accounts;
- quotation requests;
- WooCommerce transactions;
- registration and account-approval processes;
- warranty and product-support requests;
- product-safety communications;
- e-mail communications;
- newsletters and marketing communications;
- customer-service interactions;
- contact forms;
- social-media communication;
- messaging platforms;
- payment and invoicing processes;
- logistics and delivery processes; and
- associated technical, security and administrative systems.
Third-party websites and platforms operate under their own privacy policies. Where you leave Buy-Solar.Online and interact directly with another service, that service’s privacy terms may apply.
6. Personal Data We Process
The personal data we process depends on your relationship with us and the services you use.
6.1 Identification and Contact Data
We may process:
- first and last name;
- salutation;
- business position or department;
- company name;
- postal address;
- billing address;
- shipping address;
- e-mail address;
- telephone number; and
- preferred communication details.
6.2 Company and Professional Information
For B2B and professional accounts, we may process:
- company registration information;
- VAT or tax number;
- business activity;
- professional role;
- installer or contractor status;
- reseller status;
- purchasing authority;
- company website;
- company registration documents; and
- other information reasonably required to verify a professional or commercial account.
Information relating exclusively to a legal entity is not personal data under the GDPR, but information that identifies a director, employee, sole trader or other natural person may constitute personal data.
6.3 Account Data
We may process:
- customer ID;
- account username;
- account type;
- customer role;
- registration date;
- login history;
- account-status information;
- approval or rejection status;
- account preferences;
- saved addresses;
- quotation history;
- order history; and
- communications associated with the account.
Passwords are stored using appropriate technical security mechanisms and are not intended to be accessible in readable form.
6.4 Transaction and Order Data
When you place an order, request a quotation or conduct a commercial transaction, we may process:
- products ordered;
- quantities;
- prices;
- discounts;
- VAT information;
- invoice details;
- payment status;
- payment references;
- delivery instructions;
- order correspondence;
- returns;
- warranty claims;
- credit notes; and
- other information necessary to administer the transaction.
6.5 Payment Information
Payments may be handled by banks or third-party payment-service providers.
Depending on the payment method, we may receive information such as:
- payment status;
- bank-transfer reference;
- account-holder name;
- transaction identifier;
- partial payment-method information; and
- other information required to reconcile payments.
Where card or other payment details are entered directly into the systems of an external payment provider, Buy-Solar.Online does not normally receive or store complete card credentials.
6.6 Delivery and Logistics Data
For product delivery and fulfilment, we may process or transmit:
- recipient name;
- company;
- delivery address;
- telephone number;
- e-mail address;
- shipment reference;
- delivery instructions;
- order contents where required for transport or customs purposes; and
- information necessary for freight, customs or delivery administration.
6.7 Communications and Customer Support
When you contact us, we may process:
- e-mail correspondence;
- telephone-call information;
- contact-form submissions;
- support requests;
- quotation requests;
- product questions;
- warranty communications;
- complaint information;
- attachments;
- photographs;
- technical system information; and
- other information voluntarily provided in the communication.
6.8 Documents and Verification Information
Professional or trade-account applicants may be asked to provide documentation necessary to establish their commercial status or verify submitted information.
This may include:
- company extracts;
- VAT information;
- trade licences;
- installer documentation;
- authorisations;
- commercial references; and
- other documents relevant to account verification.
We request that users do not provide unnecessary personal information or sensitive information that is not relevant to the requested service.
6.9 Technical and Usage Data
When you access the website, certain technical information may be collected automatically, including:
- IP address;
- browser type;
- operating system;
- device information;
- approximate geographic information derived from IP address;
- date and time of access;
- pages visited;
- referral information;
- session identifiers;
- login events;
- security events;
- error logs;
- cookie identifiers; and
- interaction data.
IP addresses and similar online identifiers may constitute personal data under the GDPR.
6.10 Marketing and Preference Data
We may process:
- newsletter subscription status;
- marketing preferences;
- consent records;
- unsubscribe records;
- product interests;
- campaign interactions; and
- communication preferences.
6.11 Product-Safety and Warranty Information
Where necessary for warranty, product-safety, recall or regulatory purposes, we may process:
- purchased product;
- model;
- serial number;
- installation details;
- installer information;
- photographs;
- fault descriptions;
- warranty documentation;
- customer contact information; and
- communications with manufacturers or other economic operators.
7. Sources of Personal Data
We normally obtain personal data directly from you.
We may also obtain information from:
- your employer or company;
- authorised company representatives;
- payment providers;
- banks;
- logistics providers;
- manufacturers;
- warranty-service providers;
- authorised distributors;
- publicly accessible business registers;
- VAT-verification systems;
- professional directories;
- fraud-prevention or security services; and
- other parties involved in a transaction or support request.
Where personal data is obtained from another source, we process it only where we have an appropriate legal basis and provide the information required by applicable law.
8. Purposes and Legal Bases for Processing
We process personal data only where an appropriate legal basis exists.
The principal legal bases under Article 6 GDPR are:
Consent – Article 6(1)(a)
Where you have freely given consent for a specified purpose.
Contract – Article 6(1)(b)
Where processing is necessary to enter into or perform a contract with you.
Legal Obligation – Article 6(1)(c)
Where processing is necessary to comply with applicable law.
Legitimate Interests – Article 6(1)(f)
Where processing is necessary for a legitimate business interest and that interest is not overridden by your rights and freedoms.
We may process personal data for the following purposes.
| Purpose | Typical Legal Basis |
|---|---|
| Customer registration and account management | Art. 6(1)(b), Art. 6(1)(f) |
| B2B or professional account verification | Art. 6(1)(b), Art. 6(1)(f) |
| Preparing quotations | Art. 6(1)(b) |
| Processing orders | Art. 6(1)(b) |
| Payment and transaction administration | Art. 6(1)(b), Art. 6(1)(c) |
| Invoicing and accounting | Art. 6(1)(c) |
| Delivery and logistics | Art. 6(1)(b) |
| Customer service | Art. 6(1)(b), Art. 6(1)(f) |
| Warranty administration | Art. 6(1)(b), Art. 6(1)(c), Art. 6(1)(f) |
| Product-safety notices and recalls | Art. 6(1)(c), Art. 6(1)(f) |
| Website and account security | Art. 6(1)(f), where applicable Art. 6(1)(c) |
| Fraud prevention | Art. 6(1)(f), where applicable Art. 6(1)(c) |
| Establishing or defending legal claims | Art. 6(1)(f) |
| Required disclosures to authorities | Art. 6(1)(c) |
| Non-essential analytics | Art. 6(1)(a) |
| Advertising and tracking technologies | Art. 6(1)(a) |
| Newsletter marketing | Art. 6(1)(a), or another basis where specifically permitted by applicable direct-marketing law |
| Existing-customer marketing | Where permitted by applicable electronic-marketing law, subject to the right to opt out |
| AI-assisted business functions | The legal basis applicable to the underlying processing purpose |
Where we rely on legitimate interests, these may include:
- protecting the webshop and customer accounts;
- preventing fraud;
- maintaining network and information security;
- operating an efficient B2B platform;
- responding to customer inquiries;
- maintaining business records;
- establishing or defending legal claims;
- verifying professional customers;
- improving business operations; and
- maintaining customer and supplier relationships.
Where required, we assess whether our legitimate interests are overridden by the interests, fundamental rights or freedoms of the affected individual.
9. Cookies and Similar Technologies
9.1 Strictly Necessary Technologies
Buy-Solar.Online uses technologies that are necessary for the operation and security of the webshop.
These may be used for:
- website security;
- session management;
- shopping-cart operation;
- authentication;
- customer login;
- checkout functionality;
- fraud prevention;
- load balancing;
- consent-preference storage; and
- other functionality expressly requested by the user.
Where a cookie or similar technology is strictly necessary to provide a service requested by the user, separate consent may not be required under applicable electronic-communications law.
9.2 Analytics, Advertising and Other Non-Essential Technologies
Non-essential cookies and similar tracking technologies are activated only where the required consent has been obtained through our cookie-management interface.
Depending on the configuration of the website, these technologies may be used for:
- audience measurement;
- website analytics;
- advertising measurement;
- campaign attribution;
- retargeting;
- social-media integration;
- user-experience analysis; and
- marketing optimisation.
9.3 Cookie Choice
When required, visitors are provided with the ability to:
- accept non-essential cookies;
- reject non-essential cookies;
- choose individual categories; and
- change or withdraw previously given consent.
Continuing to browse the website is not treated by itself as consent to non-essential cookies.
Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
Cookie choices can be modified through the Cookie Settings or consent-management interface available on the website.
9.4 Current Cookie and Technology Information
Because website technologies and third-party integrations may change, the current consent-management interface provides the most up-to-date information regarding:
- active cookie categories;
- technology providers;
- purposes;
- cookie duration; and
- consent status.
Non-essential services are subject to the consent settings applicable to them.
10. Analytics and Advertising Services
Where enabled and permitted by your cookie preferences, Buy-Solar.Online may use analytics, advertising or social-media technologies.
These may include services associated with providers such as:
- Google;
- Microsoft;
- Meta;
- Pinterest;
- X;
- Yandex;
- Baidu; and
- other analytics or advertising providers identified in the active cookie-management interface.
The exact services currently enabled, their purposes and applicable cookie settings are shown through the website’s cookie-consent system.
Where a provider processes personal data outside the European Economic Area, the international-transfer requirements described in this Privacy Policy also apply.
Consent to advertising or analytics cookies does not by itself remove the requirement to maintain an appropriate legal mechanism for an international transfer of personal data where such a mechanism is required.
11. Anti-Spam, Fraud Prevention and Website Security
We use security technologies to protect:
- customer accounts;
- registration forms;
- contact forms;
- checkout systems;
- website infrastructure; and
- other online services.
These may include services such as:
- CleanTalk;
- Google reCAPTCHA;
- web-application firewalls;
- security logging;
- anti-bot systems;
- login protection;
- rate limiting; and
- fraud-detection mechanisms.
Such processing is based primarily on our legitimate interest in maintaining the security, availability and integrity of our services, and where applicable on legal obligations.
Where optional third-party technologies require consent under electronic-communications law, they are managed accordingly through the consent system.
12. Account and Transactional Communications
Certain communications are necessary for providing Buy-Solar.Online services.
These may include:
- registration confirmations;
- account-approval or account-status notices;
- password-reset messages;
- quotations;
- order confirmations;
- payment information;
- invoices;
- delivery notifications;
- warranty communications;
- security notices;
- contractual notices;
- product-safety notifications;
- recalls; and
- legally required communications.
These messages are not considered optional marketing communications where their purpose is necessary for the customer relationship, transaction, security, product safety or legal compliance.
A customer cannot opt out of communications that are necessary to perform an active transaction, maintain account security or meet a legal obligation.
13. Marketing Communications
Marketing communications are treated separately from necessary transactional communications.
We may send information concerning:
- solar panels;
- solar inverters;
- solar batteries;
- energy storage;
- complete solar kits;
- electrical equipment;
- new products;
- price lists;
- product availability;
- promotions;
- industry information; and
- related commercial offers.
We send electronic direct marketing where:
- you have provided the required consent;
- the communication is otherwise permitted under applicable electronic-marketing legislation; or
- another valid legal basis applies to a particular professional communication.
Where permitted by law, existing customers may receive marketing concerning similar products or services, provided that an appropriate opportunity to object was offered when contact information was obtained and is provided again with each relevant marketing communication.
For B2B communications, applicable national rules concerning marketing to professional or corporate recipients may also apply.
Right to Object to Direct Marketing
You may object at any time to the processing of your personal data for direct-marketing purposes. Where such an objection is received, we will no longer process your personal data for that direct-marketing purpose, as required by Article 21 GDPR.
Withdrawal of marketing consent or an objection to direct marketing applies only to the relevant marketing processing and does not affect communications necessary for existing orders, payments, account security, warranties, product-safety notices, recalls, contractual administration or legal obligations.
Buy-Solar.Online separately reserves the right to approve, reject, restrict, suspend or terminate customer or trade accounts and to decide whether to enter into or continue a commercial relationship, subject to applicable law and the General Terms and Conditions.
The exercise of a data-protection right does not itself determine whether Buy-Solar.Online is required to establish or continue a commercial relationship with the individual or company concerned.
14. Third-Party Service Providers and Recipients
Personal data may be disclosed where necessary to organisations involved in providing our services.
Categories of recipients may include:
Hosting and IT Providers
Including providers responsible for:
- web hosting;
- server infrastructure;
- backups;
- content delivery;
- cybersecurity;
- maintenance;
- e-mail infrastructure;
- CRM systems; and
- technical development.
Our primary website hosting infrastructure is located in the European Union, including infrastructure in Frankfurt, Germany.
Banks and Payment Providers
Data may be shared with banks and payment providers where necessary to:
- receive payments;
- reconcile transactions;
- process refunds;
- investigate payment problems; and
- comply with banking or financial obligations.
Logistics and Freight Providers
These may include carriers and freight operators such as:
- GLS;
- DPD;
- DHL;
- Dachser; and
- other logistics providers selected for a particular shipment.
Only data reasonably necessary for fulfilment is provided.
Manufacturers and Warranty Providers
Where necessary for:
- warranty administration;
- technical support;
- RMA processing;
- product-safety investigations;
- recalls;
- replacements; or
- manufacturer service,
relevant customer and product information may be shared with the manufacturer, authorised service provider, importer, responsible economic operator or distributor.
Professional Advisers
Personal data may be disclosed where necessary to:
- accountants;
- auditors;
- tax advisers;
- insurance providers;
- legal advisers; and
- other professional advisers.
Public Authorities
Personal data may be disclosed to:
- tax authorities;
- customs authorities;
- courts;
- police;
- law-enforcement agencies;
- market-surveillance authorities;
- consumer-protection authorities;
- data-protection authorities; or
- other competent public bodies,
where disclosure is required or permitted by applicable law.
Regional Fulfilment Partners
Where an order is fulfilled through an authorised regional partner, the minimum information reasonably necessary to process the relevant transaction, delivery or service may be disclosed to that partner.
15. Processors, Independent Controllers and Joint Controllers
Not every organisation receiving personal data has the same legal role.
Depending on the processing activity, a third party may act as:
- our processor;
- an independent controller;
- a joint controller; or
- another authorised recipient.
Where a service provider processes personal data on our behalf as a processor, we use appropriate contractual arrangements in accordance with Article 28 GDPR.
Where a recipient acts as an independent controller, that organisation is independently responsible for complying with the GDPR in relation to its processing.
16. International Transfers of Personal Data
We aim to process personal data within the European Economic Area wherever reasonably possible.
However, certain service providers, technology suppliers, manufacturers or support providers may be located outside the EEA or may permit access to personal data from outside the EEA.
Where personal data is transferred outside the EEA, we use a lawful transfer mechanism where required.
Depending on the recipient and destination, this may include:
- a European Commission adequacy decision;
- participation by an eligible recipient in a recognised adequacy framework;
- European Commission Standard Contractual Clauses;
- Binding Corporate Rules;
- another safeguard permitted by Article 46 GDPR; or
- an Article 49 GDPR derogation where its specific legal requirements are satisfied.
Where Standard Contractual Clauses are used, supplementary safeguards and transfer-risk considerations are assessed where required.
Consent to website cookies or analytics is not automatically treated as a substitute for the international-transfer safeguards required by Chapter V GDPR.
Where service providers in jurisdictions without an EU adequacy decision are used, we assess the applicable transfer mechanism and safeguards according to the nature of the processing.
17. AI-Assisted Processing
Buy-Solar.Online may use artificial-intelligence-assisted systems for limited business functions.
Depending on the activity, these may assist with:
- preparation and organisation of website content;
- translation;
- customer-support preparation;
- technical-document organisation;
- classification or summarisation of information;
- fraud or security analysis;
- internal research;
- administrative productivity; and
- other supporting business processes.
Use of an AI-assisted tool does not create a separate legal basis for processing personal data. The processing must remain supported by the legal basis applicable to the underlying purpose.
We apply the principles of:
- purpose limitation;
- data minimisation;
- confidentiality;
- access control;
- accuracy;
- human oversight; and
- appropriate security.
Personal information should not be submitted to AI systems indiscriminately.
Where an AI service processes personal data on our behalf, its contractual, security, processor and international-transfer arrangements are assessed according to applicable data-protection requirements.
AI-generated or AI-assisted output used in customer-facing or technical contexts may be subject to human review where appropriate.
18. Automated Decision-Making and Profiling
We may use limited automated processing for purposes such as:
- security monitoring;
- spam prevention;
- fraud detection;
- analytics;
- marketing segmentation; and
- account-risk indicators.
These activities do not necessarily constitute automated decision-making within the meaning of Article 22 GDPR.
Buy-Solar.Online does not ordinarily make decisions based solely on automated processing that produce legal effects concerning an individual or similarly significantly affect that individual.
Where such automated decision-making is introduced and Article 22 GDPR applies, it will be used only where legally permitted and with the required safeguards.
Where applicable, those safeguards may include the right to:
- obtain human intervention;
- express your point of view; and
- contest the decision.
Profiling used for advertising or marketing purposes is subject to the applicable consent and objection rights.
19. Special Categories of Personal Data
Buy-Solar.Online does not normally require special-category personal data such as information revealing:
- racial or ethnic origin;
- political opinions;
- religious or philosophical beliefs;
- trade-union membership;
- genetic data;
- biometric data used for identification;
- health information; or
- information concerning a person’s sex life or sexual orientation.
Please do not submit such information unless it is genuinely necessary for a specific lawful purpose and has been expressly requested.
If special-category information is received unexpectedly, we will assess whether there is a lawful basis for retaining it and otherwise take appropriate steps to delete or restrict it.
20. Data Retention
We retain personal data only for as long as necessary for the purpose for which it was collected and for any additional period required by applicable legal, accounting, tax, warranty, product-safety or limitation-period requirements.
Our retention criteria include:
- whether an account remains active;
- whether a transaction is still in progress;
- warranty duration;
- product-safety obligations;
- statutory accounting and tax requirements;
- possible legal claims;
- fraud-prevention requirements; and
- whether consent remains valid.
Typical retention principles include:
| Data Category | Typical Retention Approach |
| Accounting records and invoices | For the legally required accounting period; relevant Hungarian accounting records are generally retained for at least 8 years |
| Orders and transaction records | For the period required for accounting, contractual, warranty, tax and legal-claim purposes |
| Active customer-account information | For the duration of the account |
| Inactive account information | Normally deleted or anonymised when no longer necessary, subject to contractual, accounting and legal requirements |
| Account-verification documents | Only for as long as reasonably necessary for verification, fraud prevention or applicable legal obligations |
| Customer-support correspondence | Normally for the duration of the matter and a reasonable period afterwards, unless a longer period is necessary |
| Warranty and product-safety records | For the relevant warranty, product-safety, recall or legal period |
| Marketing data | Until consent is withdrawn, an objection is received, or the processing is otherwise no longer justified |
| Marketing suppression records | Minimal information may be retained to ensure an opt-out remains effective |
| Cookie and analytics data | According to the durations disclosed through the Cookie Settings interface |
| Security logs | For a proportionate security period, or longer where necessary to investigate an incident or legal claim |
Data may be retained longer where required to establish, exercise or defend legal claims or comply with a binding legal obligation.
When personal data is no longer required, it is deleted, anonymised or otherwise placed beyond ordinary use as appropriate.
21. Your GDPR Rights
Subject to the conditions and exceptions established by law, you may have the following rights.
Right of Access – Article 15 GDPR
You may request confirmation as to whether we process your personal data and obtain access to that data and related information.
Right to Rectification – Article 16 GDPR
You may request correction of inaccurate personal data or completion of incomplete information.
Right to Erasure – Article 17 GDPR
You may request deletion of personal data where the legal requirements for erasure are satisfied.
The right to erasure does not apply where continued processing is required, for example, to comply with a legal obligation or establish, exercise or defend legal claims.
Right to Restriction – Article 18 GDPR
You may request restriction of processing in circumstances established by the GDPR.
Right to Data Portability – Article 20 GDPR
Where applicable, you may obtain personal data you provided to us in a structured, commonly used and machine-readable format and request transmission to another controller where technically feasible.
Right to Object – Article 21 GDPR
Where processing is based on legitimate interests, you may object on grounds relating to your particular situation.
We will stop the relevant processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms or processing remains necessary for legal claims.
Direct Marketing
Where your personal data is processed for direct marketing, you may object at any time.
Once you object, we will no longer process your personal data for that direct-marketing purpose.
Right to Withdraw Consent – Article 7 GDPR
Where processing is based on consent, you may withdraw consent at any time.
Withdrawal does not affect the lawfulness of processing performed before withdrawal.
Rights Concerning Automated Decision-Making – Article 22 GDPR
Where Article 22 applies, you may have the right not to be subject to a decision based solely on automated processing that produces legal effects or similarly significantly affects you, subject to the exceptions and safeguards provided by law.
Right to Lodge a Complaint
You have the right to lodge a complaint with a competent data-protection supervisory authority if you believe that your personal data has been processed unlawfully.
You may in particular contact the authority in the Member State:
- of your habitual residence;
- of your place of work; or
- where the alleged infringement occurred.
You may also contact the authorities associated with our EU establishments, including:
Hungarian National Authority for Data Protection and Freedom of Information – NAIH
and
Office for Personal Data Protection of the Slovak Republic
Your right to contact another competent EU supervisory authority is not restricted.
22. Exercising Your Rights
Requests may be sent to:
or
Please provide sufficient information to allow us to identify the relevant account or processing activity.
We may request reasonable additional information where necessary to verify your identity and protect personal data against unauthorised disclosure.
We normally respond without undue delay and within one month of receiving a valid request.
Where permitted by GDPR due to the complexity or number of requests, this period may be extended by up to two additional months. If an extension is necessary, we will inform you within the initial one-month period.
Requests are generally handled free of charge.
Where a request is manifestly unfounded or excessive, particularly because of repetition, we may take the measures permitted under Article 12 GDPR.
23. Security of Personal Data
We use appropriate technical and organisational measures designed to protect personal data against:
- unauthorised access;
- unlawful processing;
- accidental loss;
- destruction;
- alteration;
- disclosure; and
- misuse.
Measures may include:
- HTTPS/TLS encryption;
- access controls;
- role-based permissions;
- secure passwords;
- authentication controls;
- security monitoring;
- anti-spam and anti-bot protection;
- firewall protection;
- backups;
- server-security controls;
- software updates;
- logging;
- incident monitoring; and
- confidentiality requirements for personnel and service providers.
No internet-based system can guarantee absolute security. Security measures are therefore reviewed and adapted according to the nature, context and risks of processing.
24. Personal Data Breaches
Suspected personal-data breaches are investigated in accordance with applicable GDPR requirements.
Where a breach is likely to result in a risk to the rights and freedoms of individuals, the competent supervisory authority will be notified as required by law.
Where a breach is likely to result in a high risk to affected individuals, those individuals will also be informed where required by the GDPR.
We maintain internal procedures for identifying, assessing, documenting and responding to security incidents.
25. Product Safety, Warranty and Recall Communications
Because Buy-Solar.Online supplies electrical products, solar inverters, solar batteries, energy storage systems, solar panels and related equipment, certain personal data may need to be retained or used for product-safety purposes.
This may include contacting customers regarding:
- safety notices;
- product recalls;
- firmware or safety-critical updates;
- warranty actions;
- corrective measures;
- manufacturer notifications; and
- market-surveillance requirements.
Where such communication is required by law or necessary to protect product safety, it is not treated as optional commercial marketing.
Relevant information may also be disclosed to manufacturers, importers, EU Responsible Persons, authorised representatives, distributors or competent authorities where necessary for a product-safety investigation or corrective action.
26. Social Media and External Communication Platforms
3Buy Solar may maintain accounts or communicate through platforms including:
- Facebook;
- Instagram;
- Messenger;
- LinkedIn;
- TikTok;
- X;
- Pinterest;
- YouTube;
- WhatsApp Business;
- WeChat;
- Google Business services; and
- other professional communication platforms.
Where you communicate with us through one of these services, we may process:
- your profile name;
- username;
- contact details;
- message content;
- photographs;
- videos;
- attachments; and
- communication metadata.
The legal basis depends on the nature of the communication and may include:
- Article 6(1)(b) GDPR for inquiries related to a contract or potential order;
- Article 6(1)(f) GDPR for customer service and legitimate business communication; or
- Article 6(1)(a) GDPR where consent is required.
The operator of the relevant social-media or messaging platform may independently process personal data under its own privacy terms and may act as an independent or, in certain situations, joint controller.
Information sent privately to us is not made public by Buy-Solar.Online unless:
- you have authorised publication;
- publication is otherwise lawful; or
- the material was already made public by you in the relevant context.
27. External Links
Buy-Solar.Online contains links to:
- manufacturers;
- technical documentation;
- warranty portals;
- logistics companies;
- payment providers;
- government services;
- social networks; and
- other third-party websites.
Once you access an external website, that third party may process personal data independently.
We recommend reviewing the privacy information of the relevant provider.
28. Children
Buy-Solar.Online is primarily intended for professional users, commercial customers and adults purchasing energy-related equipment.
Our services are not directed toward children, and we do not knowingly seek to collect personal data from children for marketing or account-registration purposes.
Persons entering into commercial transactions through the webshop must have the legal capacity required for the relevant transaction.
If we become aware that personal data relating to a child has been collected without an appropriate legal basis, we will take reasonable steps to address the situation.
29. Data Accuracy
Users are responsible for providing accurate and current information where necessary for:
- account administration;
- invoicing;
- delivery;
- tax handling;
- warranty administration; and
- commercial transactions.
Registered users should update account information when it changes.
We may also update or verify certain company information using official or publicly accessible registers where reasonably necessary.
30. Data Minimisation
We seek to collect only personal data reasonably necessary for the relevant purpose.
Customers and business partners should avoid submitting:
- unnecessary identity documents;
- passwords;
- full payment-card details;
- special-category personal information;
- confidential third-party information; or
- unrelated personal documents,
unless specifically required through an authorised process.
31. Changes to This Privacy Policy
We may update this Privacy Policy where necessary to reflect:
- legal changes;
- regulatory guidance;
- changes to our controllers or processors;
- new website functions;
- new payment or logistics providers;
- new analytics technologies;
- changes to international transfers;
- AI-related processing;
- security improvements; or
- changes in business operations.
Material changes may be communicated through appropriate means, which may include:
- an updated notice on the website;
- an account notification;
- an e-mail notification where appropriate; or
- a renewed consent request where a new consent is legally required.
The current version and effective date are displayed at the beginning of this Privacy Policy.
Changes to the Privacy Policy do not retroactively create consent for processing that legally requires consent.
32. Related Policies and Information
This Privacy Policy should be read together with other relevant Buy-Solar.Online information, including:
- General Terms and Conditions;
- Impressum / Legal Notice;
- Cookie Settings;
- GPSR Compliance & EU Product Safety information;
- Manufacturer Support & Service information; and
- applicable product-specific terms or warranty information.
Where a specific service or processing activity requires additional privacy information, a supplementary notice may be provided at the point where the relevant data is collected.
33. Contact
For questions concerning this Privacy Policy or the processing of personal data:
Privacy Contact
Apelida s.r.o.
Bastova Street 2301/16
94501 Komárno
Slovakia
E-mail: privacy@buy-solar.online
GDPR Contact
3Buy EU Compliance Office
Bastova Street 2301/16
94501 Komárno
Slovakia
E-mail: gdpr@buy-solar.online
Platform Operator
Suncrest Kft.
Nemzetőr u. 9
2370 Dabas
Hungary
E-mail: info@buy-solar.online
Final Privacy Statement
Buy-Solar.Online processes personal data only for defined and legitimate purposes and applies the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability.
We aim to maintain privacy and data-protection practices appropriate to a European solar PV, solar battery, energy storage and electrical-equipment webshop serving both professional and other authorised customers throughout the European market.
Version: 2026.08
Effective Date: 24 August 2026
Last Updated: 24 August 2026







EV Accessories and Mounting
























