Legal Information
Legal information ensures everything is transparent and clear for you.
Privacy policy
Effective date: [DATE]
Version: 1.0
1. Data controller information
Name: [COMPANY NAME]
Registered office: [REGISTERED OFFICE]
Company registration number: [COMPANY REGISTRATION NUMBER]
Tax number: [TAX NUMBER]
Email: [EMAIL]
Phone: [PHONE]
Website: [WEBSITE URL]
(hereinafter referred to as the Data Controller)
2. Purpose and scope
The purpose of this privacy policy is to inform data subjects about the data processing activities carried out on the website [WEBSITE URL] (hereinafter referred to as the Website) operated by the Data Controller, in accordance with Article 13 of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter referred to as the GDPR).
This policy covers all personal data processed in connection with the use of the Website.
3. Legal bases for data processing
The Data Controller processes personal data based on the following legal grounds:
- Consent of the data subject (Article 6(1)(a) GDPR)
- Performance of a contract or pre-contractual measures taken at the data subject's request (Article 6(1)(b) GDPR)
- Compliance with a legal obligation to which the Data Controller is subject (Article 6(1)(c) GDPR)
- Legitimate interests of the Data Controller or a third party (Article 6(1)(f) GDPR)
4. Categories of personal data, purposes, legal bases and retention periods
4.1. Contact form
Data processed: name, email address, phone number (optional), company name (optional), message content.
Purpose: responding to enquiries submitted through the Website, establishing contact.
Legal basis: consent of the data subject (Article 6(1)(a) GDPR).
Retention period: 1 year from the date of response, or until the data subject withdraws consent.
4.2. Request for proposal
Data processed: name, email address, phone number, company name, description of the requested service.
Purpose: preparation and delivery of a proposal, communication related to the proposal.
Legal basis: pre-contractual measures taken at the data subject's request (Article 6(1)(b) GDPR).
Retention period: 1 year from the date the proposal is sent. In the event of a contract being concluded, 5 years from the termination of the contract.
4.3. Newsletter subscription
Data processed: name, email address.
Purpose: providing regular updates about the Data Controller's services, news, and professional content.
Legal basis: consent of the data subject (Article 6(1)(a) GDPR).
Retention period: until consent is withdrawn. An unsubscribe option is provided in every newsletter.
4.4. Server log data
Data processed: IP address, browser type and version, operating system, referring URL, date and time of visit, pages viewed.
Purpose: secure operation of the Website, identification of technical issues, prevention of misuse.
Legal basis: legitimate interest of the Data Controller (Article 6(1)(f) GDPR).
Retention period: 90 days.
4.5. Cookies
The Website uses cookies. Detailed rules on the use of cookies are set out in the Cookie Policy, available at: [COOKIE POLICY URL]
[OPTIONAL SECTION: IF THE CLIENT OPERATES AN ONLINE STORE]
4.6. Online store purchases
Data processed: name, email address, phone number, billing address (name/company name, postal code, city, street, house number), shipping address, tax number (for business purchases), order details.
Purpose: order fulfilment, delivery, invoicing.
Legal basis: performance of a contract (Article 6(1)(b) GDPR) and compliance with accounting obligations (Article 6(1)(c) GDPR).
Retention period: 8 years for accounting records, in accordance with applicable accounting legislation.
4.7. User account (registration)
Data processed: name, email address, phone number (optional), password (stored in encrypted form), billing information.
Purpose: creation and management of user accounts, provision of services.
Legal basis: performance of a contract (Article 6(1)(b) GDPR).
Retention period: until the user account is deleted, or within 30 days of receiving a deletion request.
[/END OF OPTIONAL SECTION]
[OPTIONAL SECTION: IF THE CLIENT ACCEPTS JOB APPLICATIONS VIA THE WEBSITE]
4.8. Job applications
Data processed: name, email address, phone number, data contained in CVs, cover letters.
Purpose: evaluation of applications received, communication with applicants.
Legal basis: consent of the data subject (Article 6(1)(a) GDPR).
Retention period: 6 months from the evaluation of the application, or until the data subject withdraws consent.
[/END OF OPTIONAL SECTION]
5. Data transfers and data processors
The Data Controller engages the following data processors:
-
[HOSTING PROVIDER NAME]
Activity: Hosting services
Registered office: [REGISTERED OFFICE] -
[INVOICING SYSTEM NAME]
Activity: Invoicing
Registered office: [REGISTERED OFFICE] -
[NEWSLETTER SERVICE NAME]
Activity: Newsletter distribution
Registered office: [REGISTERED OFFICE] -
Google LLC
Activity: Web analytics (Google Analytics)
Registered office: 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA -
Microsoft Corporation
Activity: User behaviour analysis (Microsoft Clarity)
Registered office: One Microsoft Way, Redmond, WA 98052, USA
The Data Controller does not transfer personal data to third countries (outside the European Economic Area) unless an adequacy decision of the European Commission is in place or appropriate safeguards under Article 46 GDPR are applied (e.g. in the case of Google LLC and Microsoft Corporation).
The Data Controller only discloses personal data to third parties on the basis of a legal obligation, upon the request of a public authority or court.
6. Rights of data subjects
Data subjects may exercise the following rights under the GDPR:
- Right of access (Article 15 GDPR): the data subject has the right to obtain confirmation as to whether personal data concerning them is being processed, and if so, to access those data.
- Right to rectification (Article 16 GDPR): the data subject has the right to request the rectification of inaccurate personal data.
- Right to erasure (Article 17 GDPR): the data subject has the right to request the erasure of personal data where the legal basis for processing no longer applies.
- Right to restriction of processing (Article 18 GDPR): the data subject has the right to request the restriction of data processing.
- Right to data portability (Article 20 GDPR): the data subject has the right to receive personal data provided to the Data Controller in a structured, commonly used, machine-readable format.
- Right to object (Article 21 GDPR): the data subject has the right to object, on grounds relating to their particular situation, to the processing of personal data based on legitimate interest.
- Withdrawal of consent: where data processing is based on the data subject's consent, consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.
Data subjects may exercise these rights by contacting the Data Controller at [EMAIL]. The Data Controller will respond to requests within 30 days.
7. Remedies
Data subjects may address their complaints regarding data processing directly to the Data Controller ([EMAIL]).
If the data subject considers that the Data Controller has violated the applicable data protection regulations, they have the right to lodge a complaint with the National Authority for Data Protection and Freedom of Information (NAIH):
National Authority for Data Protection and Freedom of Information
Address: Falk Miksa utca 9-11, H-1055 Budapest, Hungary
Postal address: H-1363 Budapest, P.O. Box 9
Phone: +36 (1) 391-1400
Email: ugyfelszolgalat@naih.hu
Website: https://naih.hu
The data subject may also bring proceedings before a court in the event of a violation of their rights. Proceedings may be brought before the regional court of the data subject's place of residence or domicile.
8. Data security
The Data Controller ensures the security of personal data and takes all necessary technical and organisational measures to protect such data.
In particular, the Data Controller ensures that:
- personal data is accessible only to authorised personnel,
- personal data is processed through encrypted channels (SSL/TLS),
- personal data is protected against unauthorised access, alteration, transfer, disclosure, deletion, or destruction.
9. Applicable legislation
The Data Controller observes the following legislation in its data processing activities:
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR)
- Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Info Act)
- Act V of 2013 on the Civil Code (Civil Code)
- Act C of 2000 on Accounting (Accounting Act)
- Act CVIII of 2001 on Certain Aspects of Electronic Commerce Services (E-Commerce Act)
10. Amendments to this policy
The Data Controller reserves the right to amend this privacy policy. The amended policy will be published on the Website together with its effective date.
Last updated: [DATE]