PRIVACY POLICY
HENDER-MEDICAL Innovation KFT. – hereinafter referred to as the Company – through the publication of this privacy information, complies with the prior information obligation regarding the processing of personal data of data subjects, as required by REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL, which stipulates that all information according to the relevant articles of the Regulation should be made available to data subjects in a concise, transparent, intelligible, and easily accessible form, formulated clearly and in plain language.
- NAME OF DATA CONTROLLER AND DATA PROCESSOR
The Company informs the data subject that it qualifies as the data controller regarding the processing of their personal data.
COMPANY NAME: HENDER-MEDICAL Innovation KFT.
REGISTERED OFFICE: 1015 Budapest, Donáti utca 38. A. lház. fszt.
COMPANY REGISTRATION NUMBER: 01-09-298253
TAX IDENTIFICATION NUMBER: 12455074-2-41
PHONE: +36308212732
DATA PROTECTION OFFICER’S NAME: Andrea Ollári
REPRESENTATIVE’S NAME: Andrea Ollári
EMAIL: andrea.ollari@hender.hu
WEBSITE: www.gyomorballon.hu, akcio.gyomorballon.hu
The Company’s employees with access rights related to the relevant data processing purpose, as well as individuals and organizations performing data processing activities based on service contracts with the Company, may become aware of personal data to the extent determined by the Company and to the extent necessary for their activities.
- DEFINITIONS
- “Personal data”: Any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- “Data processing”: Any operation or set of operations performed on personal data or sets of data, whether by automated means or not, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- 3. “Restriction of data processing”: The marking of stored personal data with the aim of limiting their processing in the future.
- “Profiling”: Any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning job performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements.
- “Pseudonymization”: The processing of personal data in such a manner that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data cannot be attributed to an identified or identifiable natural person.
- “Record-keeping system”: Any structured set of personal data which is accessible according to specific criteria, whether centralized, decentralized, or dispersed on a functional or geographical basis.
- “Data controller”: A natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the data controller or the criteria for its designation may be provided for by Union or Member State law.
- “Data processor”: A natural or legal person, public authority, agency, or any other body that processes personal data on behalf of the data controller.
- “Recipient”: A natural or legal person, public authority, agency, or any other body to whom the personal data are disclosed, whether a third party or not. The public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be considered recipients; the processing of such data by those public authorities shall comply with the applicable data protection rules according to the purposes of the processing.
- 10. “Third party”: A natural or legal person, public authority, agency, or any other body, distinct from the data subject, data controller, data processor, and persons who, under the direct authority of the data controller or data processor, are authorized to process personal data.
- “Consent of the data subject”: The data subject’s voluntary, specific, informed, and unambiguous indication of their wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
- “Personal data breach”: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
- “Enterprise”: Any natural or legal person engaged in economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in economic activities.
III. LEGAL BASIS FOR DATA PROCESSING
- Consent of the data subject
(1) The lawfulness of processing personal data shall be based on the consent of the data subject or on any other legitimate basis provided for by law.
(2) In the case of processing based on the data subject’s consent, the data subject may provide their consent for the processing of personal data in the following forms:
- a) In writing, in the form of a declaration granting consent for personal data processing,
- b) Electronically, through explicit actions on the Company’s website by ticking a checkbox, or by making technical settings related to services of the information society, as well as any other statement or action clearly indicating the data subject’s consent to the planned processing of their personal data in the given context.
(3) Silence, pre-ticked boxes, or inaction shall not constitute consent.
(4) The consent shall apply to all processing activities performed for the same purpose or purposes.
(5) If the processing serves multiple purposes simultaneously, the consent must be given for all data processing purposes. If the data subject gives their consent following an electronic request, the request must be clear and concise, and it must not unnecessarily hinder the use of the service for which consent is requested.
(6) The data subject has the right to withdraw their consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. The data subject must be informed about this before giving consent. The withdrawal of consent must be as simple as giving consent.
- Contractual Performance
- Data processing is lawful if it is necessary for the performance of a contract in which the data subject is one of the parties, or for taking steps at the request of the data subject prior to entering into a contract.
- The data subject’s consent for the processing of personal data that is not necessary for the performance of the contract cannot be a precondition for entering into the contract.
- Fulfillment of Legal Obligations by the Data Controller, or Protection of Vital Interests of the Data Subject or Another Natural Person
- The legal basis for data processing due to the fulfillment of legal obligations is determined by the law, therefore the consent of the data subject for the processing of their personal data is not required.
- The data controller is obliged to inform the data subject about the purpose, legal basis, duration, the identity of the data controller, as well as their rights and available legal remedies.
- In cases where data processing is necessary to fulfill a legal obligation, the data controller may continue to process the data even after the withdrawal of consent by the data subject if it is required to fulfill that specific legal obligation related to the data subject.
- Execution of a Task Carried Out in the Public Interest or in the Exercise of Official Authority Vested in the Data Controller, or the Pursuance of Legitimate Interests of the Data Controller or a Third Party
- The data controller – including those to whom personal data may be disclosed – or a third party’s legitimate interest may serve as a legal basis for data processing, provided that the interests, fundamental rights, and freedoms of the data subject do not override such interests, considering the reasonable expectations of the data subject based on their relationship with the data controller. Such legitimate interest may arise, for instance, when there exists a relevant and appropriate relationship between the data subject and the data controller, such as when the data subject is a customer of the data controller or an employee thereof.
- The determination of the existence of a legitimate interest requires careful examination, including whether, at the time of personal data collection and in connection with it, the data subject can reasonably expect that data processing may occur for the stated purpose.
- The interests and fundamental rights of the data subject may prevail over the interests of the data controller if the personal data is processed under circumstances where the data subjects do not reasonably expect further processing.
- RIGHTS RELATED TO THE PROCESSING OF PERSONAL DATA
- Briefly, the Business provides the following information regarding the rights of the data subject:
The data subject has the right to:
- receive information before the start of data processing,
- obtain feedback from the data controller regarding whether the processing of personal data is ongoing, and if so, have access to their personal data and the following information,
- request correction or deletion of their data, and receive notification from the data controller upon completion of these actions,
- request restriction of processing and receive notification from the data controller upon completion of this action,
- data portability,
- object to the processing if their personal data is processed for reasons of public interest or the legitimate interest of the data controller.
- be exempt from automated decision-making, including profiling,
- file a complaint with the supervisory authority. The data subject can exercise their right to file a complaint at the following contact details: National Authority for Data Protection and Freedom of Information, Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c., Phone: +36 (1) 391-1400; Fax: +36(1)391-1410, Website: http://www.naih.hu, Email: ugyfelszolgalat@naih.hu
- seek effective judicial remedy against the supervisory authority,
- seek effective judicial remedy against the data controller or data processor,
- receive information about data breaches.
- Detailed Information on the Rights of the Data Subject
Right to Information
(1) The data subject is entitled to receive information about data processing activities before they commence.
(2) The following information must be provided if personal data is collected from the data subject:
- the identity and contact details of the data controller and, if applicable, their representative;
- contact details of the data protection officer, if there is one;
- the purpose of the intended processing of personal data and the legal basis for the processing;
- in the case of processing based on Article 6(1)(f) of the Regulation, the legitimate interests pursued by the data controller or a third party;
- where applicable, the recipients or categories of recipients of the personal data;
- where applicable, whether the data controller intends to transfer personal data to a third country or international organization, along with the existence or absence of an adequacy decision by the Commission, or in the case of data transfers referred to in Article 46, Article 47, or the second subparagraph of Article 49(1) of the Regulation, the indication of appropriate safeguards and the means to obtain a copy of them or where they have been made available.
(3) In addition to the information mentioned in paragraph (1), at the time of obtaining personal data, in order to ensure fair and transparent data processing, the data controller shall inform the data subject of the following supplementary information:
- the duration of storage of personal data or, if not possible, the criteria used to determine that period;
- the right of the data subject to request access to, rectification, erasure, or restriction of processing of their personal data, and the right to object to such processing, as well as the right to data portability;
- in the case of processing based on Article 6(1)(a) or Article 9(2)(a) of the Regulation, the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal;
- the right to lodge a complaint with the supervisory authority;
- whether the provision of personal data is based on a statutory or contractual obligation or is a requirement necessary to enter into a contract, and whether the data subject is obliged to provide the personal data, as well as the possible consequences of failing to provide such data;
- the fact of automated decision-making, including profiling, mentioned in Article 22(1) and (4) of the Regulation, and at least in those cases, meaningful information about the logic involved and the significance and envisaged consequences of such processing for the data subject.
(4) If the personal data was not obtained from the data subject, the data controller shall provide the following information to the data subject:
- The identity and contact details of the data controller and, if applicable, the data controller’s representative.
- Contact details of the data protection officer, if applicable.
- The purpose of the intended processing of personal data and the legal basis for the processing.
- The categories of personal data concerned.
- The recipients or categories of recipients of the personal data, if applicable.
- Where applicable, whether the data controller intends to transfer personal data to a recipient in a third country or international organization, along with the existence or absence of an adequacy decision by the Commission or, in the case of data transfers referred to in Article 46, Article 47, or Article 49(1) second subparagraph of the Regulation, reference to the appropriate and suitable safeguards, as well as the means to obtain a copy of them or where they are made available.
(2) In addition to the information mentioned in paragraph (1), the data controller shall provide the following supplementary information necessary to ensure fair and transparent processing for the data subject:
- The duration of storage of personal data or, if not possible, the criteria used to determine that period.
- If the processing is based on Article 6(1)(f) of the Regulation, information about the legitimate interests pursued by the data controller or a third party.
- The right of the data subject to request access to their personal data, its rectification, erasure, or restriction of processing, and the right to object to the processing, as well as the right to data portability.
- The right, in cases where the processing is based on consent pursuant to Article 6(1)(a) or Article 9(2)(a) of the Regulation, to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
- The right to lodge a complaint with a supervisory authority.
- The source of personal data and, if applicable, whether the data comes from publicly accessible sources.
- The fact of automated decision-making, including profiling, as mentioned in Article 22(1) and (4) of the Regulation, and, at least in those cases, meaningful information about the logic involved, as well as the significance and expected consequences of such processing for the data subject.
(3) If the data controller intends to further process personal data for purposes other than the purpose of obtaining it, before such further processing, the data subject must be informed about the different purpose and all relevant additional information mentioned in paragraph (2).
(4) Paragraphs (1) to (3) shall not apply to the extent that:
- The data subject already possesses the information.
- Providing such information proves impossible or would involve disproportionate effort, especially for processing carried out for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, considering the conditions and safeguards referred to in Article 89(1), or if compliance with this obligation is likely to render impossible or seriously impair the achievement of the objectives of that processing. In such cases, appropriate measures, including making the information publicly available, shall be taken by the data controller to protect the rights, freedoms, and legitimate interests of the data subject.
- The acquisition or disclosure of the data is specifically required by Union or Member State law to which the data controller is subject, which provides for suitable measures to safeguard the data subject’s legitimate interests.
- The personal data must remain confidential based on a professional secrecy obligation in Union or Member State law, including statutory secrecy obligations.
The data subject’s right of access
(1) A data subject has the right to receive feedback from the data controller regarding whether the processing of their personal data is in progress, and if such processing is in progress, they are entitled to access the following information:
- The purposes of the data processing;
- Categories of personal data concerning the data subject;
- Recipients or categories of recipients to whom the personal data have been or will be disclosed, including especially recipients in third countries or international organizations;
- Where applicable, the planned duration of storage of the personal data, or if not possible, the criteria used to determine that duration;
- The data subject’s right to request rectification, erasure, or restriction of processing of their personal data and the right to object to such processing;
- The right to lodge a complaint with a supervisory authority;
- If the data were not obtained from the data subject, all available information regarding their source;
- The existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the data subject.
(2) In case of transfer of personal data to a third country or an international organization, the data subject is entitled to receive information about the appropriate safeguards under Article 46.
(3) The data controller provides the data subject with a copy of the personal data undergoing processing. For any further copies requested by the data subject, the data controller may charge a reasonable fee based on administrative costs. If the request is made electronically, the information must be provided in a widely-used electronic format unless otherwise requested by the data subject.
The data subject’s right to rectification and erasure
Right to rectification
(1) The data subject has the right to request the data controller to correct inaccuracies concerning their personal data without undue delay. Considering the purpose of the data processing, the data subject is entitled to request the completion of incomplete personal data, including through a supplementary statement.
The right to erasure (“the right to be forgotten”):
(1) The data subject has the right to request the data controller to erase their personal data without undue delay, and the controller must erase the personal data without undue delay if one of the following grounds applies:
- The personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
- The data subject withdraws consent on which the processing is based according to Article 6(1)(a) or Article 9(2)(a) and there is no other legal ground for the processing;
- The data subject objects to the processing pursuant to Article 21(1) of the Regulation, and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2) of the Regulation, relating to direct marketing;
- The personal data have been unlawfully processed;
- The erasure of personal data is required to comply with a legal obligation under Union or Member State law to which the data controller is subject;
- The personal data have been collected in relation to the offer of information society services referred to in Article 8(1) of the Regulation.
(2) If the data controller has made personal data public and is obliged to erase it upon the data subject’s request, taking into account available technology and the cost of implementation, they shall take reasonable steps, including technical measures, to inform data processors processing the data in question to delete any links to, copies, or replications of that personal data.
(3) Paragraphs (1) and (2) shall not apply where the processing is necessary:
- for exercising the right to freedom of expression and information;
- for compliance with a legal obligation that requires the data controller to process the data, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller;
- for reasons of public interest in the area of public health as specified in Article 9(2)(h) and (i) and Article 9(3) of the Regulation;
- for archiving purposes in the public interest, for scientific or historical research purposes, or statistical purposes in accordance with Article 89(1) of the Regulation, where the right referred to in paragraph (1) is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
- for the establishment, exercise, or defense of legal claims.
The right to restriction of processing:
(1) The data subject is entitled, upon request, to request the data controller to restrict the processing if any of the following conditions are met:
- The data subject disputes the accuracy of the personal data; in this case, the restriction shall apply for the period enabling the data controller to verify the accuracy of the personal data.
- The processing is unlawful, and the data subject opposes erasure of the data, instead requesting the restriction of their use.
- The data controller no longer needs the personal data for processing purposes, but the data subject requires them for the establishment, exercise, or defense of legal claims.
- The data subject has objected to the processing pursuant to Article 21(1) of the Regulation; in this case, the restriction shall apply for the period until it is verified whether the legitimate grounds of the data controller override those of the data subject.
(2) If processing is restricted under paragraph (1), such personal data, except for storage, shall only be processed with the data subject’s consent or for the establishment, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or a Member State.
(3) The data controller shall inform the data subject in advance about the lifting of the restriction on processing, which was restricted at the request of the data subject under paragraph (1).
A notification obligation regarding the rectification or erasure of personal data or the restriction of processing
(1) The data controller informs each recipient to whom the personal data have been disclosed about any rectification, erasure, or restriction of processing, unless this proves impossible or involves disproportionate effort.
(2) Upon request, the data controller informs the data subject about these recipients.
The right to data portability
(1) The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used, and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where:
- The data processing is based on the consent of the data subject according to Article 6(1)(a) (consent of the data subject to the processing of personal data) or Article 9(2)(a) (explicit consent of the data subject to the processing) of the Regulation, or it is based on a contract according to Article 6(1)(b) of the Regulation; and
- The data processing is carried out by automated means.
(2) In exercising the right to data portability pursuant to paragraph 1, the data subject shall have the right to have the personal data transmitted directly from one controller to another, where technically feasible.
(3) The exercise of the right referred to in paragraph 1 of this Article shall be without prejudice to Article 17. That right shall not apply to processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
(4) The exercise of the right referred to in paragraph 1 of this Article shall not adversely affect the rights and freedoms of others.
The Right to Object:
- The data subject is entitled to object at any time, for reasons related to their particular situation, to the processing of their personal data which is based on the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, or where processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party (processing based on Article 6(1)(e) or (f) of the regulation), including profiling based on those provisions. In such cases, the controller shall no longer process the personal data unless they demonstrate compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject or for the establishment, exercise, or defense of legal claims.
- Where personal data is processed for direct marketing purposes, the data subject has the right to object at any time to the processing of their personal data for such marketing, including profiling related to such direct marketing.
- If the data subject objects to the processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.
- The data subject’s attention shall be explicitly drawn to the right mentioned in paragraphs (1) and (2) at the latest at the time of the first communication with the data subject, and this information should be presented clearly and separately from any other information.
- In relation to the use of information society services and without prejudice to Directive 2002/58/EC, the data subject may exercise their right to object using automated means based on technical specifications.
- Where personal data is processed for scientific or historical research purposes or statistical purposes pursuant to Article 89(1) of the regulation, the data subject shall have the right to object to the processing of personal data concerning them for reasons related to their particular situation, unless the processing is necessary for the performance of a task carried out in the public interest.
The Right to Exemption from Automated Decision-Making:
(1) The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
(2) Paragraph (1) shall not apply if the decision is:
- necessary for entering into or performance of a contract between the data subject and the data controller;
- authorized by Union or Member State law applicable to the data controller, which also lays down suitable measures to safeguard the data subject’s rights, freedoms, and legitimate interests; or
- based on the data subject’s explicit consent.
(3) In cases mentioned in points (a) and (c) of paragraph (2), the data controller shall take suitable measures to safeguard the rights, freedoms, and legitimate interests of the data subject, including the right for the data subject to obtain human intervention on the part of the controller, to express their point of view, and to contest the decision.
(4) Decisions referred to in paragraph (2) shall not be based on special categories of personal data referred to in Article 9(1) of the Regulation, unless Article 9(2)(a) or (g) applies and suitable measures to safeguard the data subject’s rights, freedoms, and legitimate interests have been taken.
The Right to Lodge Complaints and Seek Remedies:
The right to lodge a complaint with the supervisory authority:
(1) The data subject is entitled, under Article 77 of the Regulation, to lodge a complaint with the supervisory authority if the data subject considers that the processing of personal data relating to them infringes this Regulation.
(2) The data subject may exercise their right to lodge a complaint at the following contact details:
National Authority for Data Protection and Freedom of Information, Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
Phone: +36 (1) 391-1400
Fax: +36 (1) 391-1410
Website: http://www.naih.hu
Email: ugyfelszolgalat@naih.hu
(3) The supervisory authority to which the complaint has been lodged shall inform the data subject of the progress and outcome of the complaint, including the data subject’s right under Article 78 of the Regulation to seek a judicial remedy.
The right to an effective judicial remedy against a supervisory authority
(1) Without prejudice to any other administrative or non-judicial remedy, every natural or legal person shall have the right to an effective judicial remedy against a legally binding decision of a supervisory authority.
(2) Without prejudice to any other administrative or non-judicial remedy, every data subject shall have the right to an effective judicial remedy where the competent supervisory authority does not handle a complaint or does not inform the data subject within three months on the progress or outcome of the proceedings concerning a complaint lodged pursuant to Article 77 of the Regulation.
(3) Proceedings against a supervisory authority shall be brought before the courts of the Member State where the supervisory authority has its seat.
(4) Where proceedings are brought against a decision of a supervisory authority relating to which the Board has previously issued an opinion or made a decision within the consistency mechanism, the supervisory authority shall transmit that opinion or decision to the court.
The right to an effective judicial remedy against the controller or processor
(1) Without prejudice to any available administrative or non-judicial remedies – including the right to lodge a complaint with a supervisory authority as provided in Article 77 – every data subject shall have the right to an effective judicial remedy if they consider that their rights under this Regulation have been infringed as a result of the processing of their personal data that does not comply with this Regulation.
(2) Proceedings against a controller or processor shall be brought before the courts of the Member State where the controller or processor has an establishment. Such proceedings may be brought before the courts of the Member State where the data subject has their habitual residence, unless the controller or processor is a public authority acting in the exercise of its public powers in which case jurisdiction shall be determined by the laws of that Member State.
Restrictions
(1) Union or Member State law to which the controller or processor is subject may restrict the scope of the obligations and rights provided for in Articles 12 to 22 and Article 34, as well as Article 5, regarding the rights and obligations in line with Articles 12 to 22, when such restrictions respect the essence of fundamental rights and freedoms and are a necessary and proportionate measure in a democratic society to safeguard:
- National security;
- Defence;
- Public security;
- The prevention, investigation, detection, or prosecution of criminal offences or the execution of criminal penalties, including the protection against threats to public security and the prevention of such threats;
- Other important objectives of general public interest of the Union or a Member State, in particular an important economic or financial interest of the Union or a Member State, including monetary, budgetary, and taxation matters, public health, and social security;
- Judicial independence and proceedings;
- In the case of regulated professions, the prevention, investigation, detection, and sanctioning of breaches of ethics;
- In cases referred to in points (a) to (e) and (g), the performance of tasks carried out in the public interest or in the exercise of official authority;
- The protection of the data subject or the rights and freedoms of others;
- The assertion, exercise, or defence of legal claims.
(2) Where the law referred to in paragraph 1, certain detailed provisions at least include:
- The purposes of the processing or categories of processing;
- The categories of personal data;
- The scope of the restrictions introduced;
- Guarantees to prevent abuse, unauthorized access, or transmission;
- The designation of the controller or categories of controllers;
- The retention period for the data and the applicable safeguards, considering the nature, scope, and purposes of the processing or categories of processing;
- Risks to the rights and freedoms of data subjects;
- The right of data subjects to be informed about the restriction, unless it may affect the purpose of the restriction adversely.
Notification of Data Breach:
(1) If a data breach is likely to result in a high risk to the rights and freedoms of natural persons, the data controller shall inform the data subject of the breach without undue delay.
(2) The notification provided to the data subject shall clearly and understandably describe the nature of the data breach and shall communicate at least the name and contact details of the data protection officer or other contact person providing further information, the likely consequences of the data breach, the measures taken or planned by the data controller to address the data breach, including any measures aimed at mitigating potential adverse effects resulting from the breach.
(3) The data subject does not need to be notified as per the provisions of paragraph (1) if any of the following conditions are met:
- The data controller has implemented adequate technical and organizational measures and applied them to the data affected by the breach, particularly measures such as encryption that render the data unintelligible to unauthorized persons;
- Subsequent measures have been taken by the data controller to ensure that the high risk identified in paragraph (1) is unlikely to materialize;
- Notifying the data subject would require disproportionate effort. In such cases, affected individuals shall be informed through publicly available information or similar measures ensuring effective communication.
(4) If the data controller has not yet informed the data subject about the data breach, the supervisory authority, after considering whether the breach is likely to result in a high risk, may order the data subject to be informed or determine the fulfillment of any conditions mentioned in paragraph (3).
- PROCEDURE APPLICABLE TO THE DATA SUBJECT’S REQUESTS
(1) The Company facilitates the exercise of the data subject’s rights and shall not refuse to fulfill requests made by the data subject to exercise rights as stipulated in this data processing information unless it can prove that it is unable to identify the data subject.
(2) The Company informs the data subject without undue delay, and in any case within one month from the receipt of the request, about the measures taken as a result of the request. Where necessary, considering the complexity of the request or the number of requests, this period may be extended by a further two months. The data controller shall inform the data subject of any such extension within one month of receiving the request, explaining the reasons for the delay.
(3) If the data subject has submitted the request electronically, the information shall, as far as possible, be provided electronically, unless the data subject requests otherwise.
(4) If the Company does not take action on the data subject’s request, it shall inform the data subject without delay, but no later than one month from the receipt of the request, about the reasons for the lack of action and about the possibility of lodging a complaint with the supervisory authority and seeking judicial remedy.
(5) The Company provides free of charge to the data subject the following information and action: feedback on the processing of personal data, access to the processed data, correction, completion, erasure of data, restriction of processing, data portability, objection to data processing, and notification of data breaches.
(6) If the data subject’s request is clearly unfounded or, especially due to its repetitive nature, excessive, the data controller may charge a fee of 5000.- HUF for administrative costs incurred in providing the requested information or action or may refuse to act on the request.
(7) The burden of proving that the request is clearly unfounded or excessive lies with the data controller.
(8) Without prejudice to Article 11 of the Regulation, if the data controller has reasonable doubts concerning the identity of the natural person submitting a request pursuant to Articles 15–21 of the Regulation, it may request additional information necessary to confirm the data subject’s identity.
- PROCEDURE FOR HANDLING PERSONAL DATA BREACHES
(1) According to the Regulation, a personal data breach constitutes a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
(2) Examples of a personal data breach include the loss or theft of devices (e.g., laptops, mobile phones) containing personal data, loss or unavailability of a decryption key necessary for accessing encrypted files, ransomware infection rendering data inaccessible until a ransom is paid, cyber attacks on IT systems, inadvertent disclosure of personal data in emails, or exposure of mailing lists, among others.
(3) Upon detection of a data breach, the Company representative conducts an immediate investigation to identify the breach and assess potential consequences. Necessary measures must be taken to mitigate any damages.
(4) The data controller is obligated to notify the competent supervisory authority of the data breach without undue delay and, if possible, no later than 72 hours after becoming aware of the breach, except where the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If notification cannot be made within 72 hours, reasons for the delay must be provided.
(5) The data processor shall promptly notify the data controller of the data breach upon becoming aware of it.
(6) The notification mentioned in paragraph (3) must include at least:
- The nature of the breach, including, if possible, the categories and approximate number of data subjects affected, as well as the categories and approximate number of personal data records involved in the breach;
- Contact details of the data protection officer or other contact person providing further information;
- Description of potential consequences resulting from the data breach;
- Explanation of measures taken or planned by the data controller to remedy the data breach, including, where applicable, measures aimed at mitigating any potential adverse consequences arising from the data breach.
(7) If it is not possible to provide the information simultaneously, the details may be provided in stages without undue delay.
(8) The data controller maintains records of personal data breaches, noting the breach’s facts, its effects, and the remedial measures taken. This record allows the supervisory authority to verify compliance with the requirements set out in Article 33 of the Regulation.
VII. DATA HANDLING RELATED TO THE WEBSITE
Information Regarding Visitors’ Data on the Company’s Website
(1) During visits to the Company’s website, one or more cookies – small packets of information sent by the server to the browser and sent back by the browser to the server with each request made to the server – are sent to the visitor’s computer. Through these, the browser can be uniquely identified if the visitor, after clear and explicit information, gives explicit (active) consent with their behavior to continue browsing the website.
(2) Cookies serve solely to enhance user experience and automate the login process. The cookies used on the website do not store information suitable for personal identification, and the Company does not engage in personal data processing in this context.
Registration, Newsletter Subscription
(1) The legal basis for data processing in the case of registration and newsletter subscription is the consent of the individual, which they provide by ticking the checkbox next to the text “registration” or “newsletter subscription” on the Company’s website, following the information provided regarding the handling of their data.
(2) The circle of individuals concerned in the case of registration and newsletter subscription includes any natural person who wishes to subscribe to the Company’s newsletter or wishes to register on the website and consents to the handling of their personal data.
(3) Scope of processed data in the case of newsletter subscription: name, email address.
(4) Scope of processed data in the case of registration: name, address, email address, phone number, login password.
(5) Purpose of data processing in the case of newsletter subscription: informing the individual about the Company’s services, products, changes occurring in them, news, and events.
(6) Purpose of data processing in the case of registration: establishing contact for the preparation of a contract, providing free services available on the website, access to non-public content of the website.
(7) Recipients of the data (those who can access the data) in the case of newsletter subscription and registration: the Company’s manager, customer relations staff, employees responsible for operating the Company’s website as data processors.
(8) Duration of data processing in the case of newsletter subscription and registration: until unsubscribing from the newsletter for newsletter subscription, until deletion upon the individual’s request for registration.
(9) The individual can unsubscribe from the newsletter at any time or request deletion of their registration (personal data). Unsubscribing from the newsletter can be done by clicking on the unsubscribe link placed in the footer of electronic emails sent to the individual or by sending a postal letter to the Company’s headquarters.
Direct Marketing-related Data Processing
(1) The legal basis for the Company’s direct marketing data processing is the explicit and clear consent of the individual. The individual provides clear and explicit prior consent for the handling of their data for direct marketing purposes by ticking the checkbox next to the text requesting consent for direct marketing on the Company’s website, following the information provided regarding data management.
(2) The individual can also provide their consent on paper by filling out the data sheet forming Annex 2 of this regulation.
(3) The circle of individuals concerned: any natural person who gives clear and explicit consent for the Company to process their personal data for direct marketing purposes.
(4) Data processing purposes: sending advertisements, offers related to service provision, product sales, notifying about promotions through electronic or postal means.
(5) Recipients of personal data: the Company’s manager and employees performing customer service and marketing tasks based on their job roles.
(6) Scope of processed personal data: name, address, phone number, email address.
(7) Duration of data processing: the handling of personal data for direct marketing purposes continues until the individual withdraws their consent.
Webshop-related Data Processing
(1) The regulations mentioned above apply to data handling activities related to registration on the webshop, newsletter subscriptions, and informing visitors.
(2) Online, electronic contracts (purchases) on the Company’s website fall under the scope of Act CVIII of 2001 (E-commerce Act), so the purpose of data processing, in addition to the above, includes fulfilling the service provider’s obligation regarding consumer information as stipulated by the law, proving the conclusion of contracts, establishing, defining, modifying the content, monitoring performance, invoicing fees, and asserting claims related to them.
(3) The legal basis for data processing in the case of purchases made in the webshop is the fulfillment of a contract and fulfilling legal obligations.
(4) Categories of data subject to processing: buyer’s name, address, phone number, login password, bank account number.
(5) Categories of individuals affected by data processing: any natural person who registers on the Company’s webshop, subscribes to the newsletter, or makes purchases.
(6) Categories of data recipients: the Company’s manager, employees handling customer relations, sales-related tasks, employees responsible for maintaining the Company’s website, staff involved in the Company’s accounting tasks, and corresponding employees from data processing entities.
(7) The location of data processing is at the Company’s headquarters.
(8) Duration of data processing: five years from the termination of the contract.
VIII. DATA PROCESSING RELATED TO CONTRACT PERFORMANCE
(1) The Company manages the personal data of natural persons contracting with it – customers, buyers, suppliers – in connection with contractual relationships. The data subjects must be informed about the processing of their personal data.
(2) Data subjects include all natural persons establishing a contractual relationship with the Company.
(3) The legal basis for data processing is the performance of the contract. The purpose of data processing is maintaining communication, enforcing claims arising from the contract, and ensuring compliance with contractual obligations.
(4) Recipients of personal data include the Company’s management, employees responsible for customer service, accounting, and individuals involved in data processing tasks.
(5) Categories of processed personal data: name, address, registered office, phone number, email address, tax number, bank account number, entrepreneur identification number, agricultural producer identification number.
(6) Duration of data processing: five years from the termination of the contract.
- INFORMATION REGARDING DATA PROCESSING THROUGH ELECTRONIC MONITORING SYSTEM
(1) Our company operates an electronic monitoring and recording system (camera system) in the customer area/property and related units. Upon entering the monitored area (room) marked with this notice, the electronic surveillance system will record the image and actions of the individuals.
(2) The legal basis for camera surveillance is the voluntary consent of the data subject based on the informative notices placed by our Company. Express consent can also be given through conclusive behavior. Such conclusive behavior includes entering or staying within the premises/areas monitored by the electronic surveillance and recording system. If you do not wish to provide consent, please refrain from entering the areas/units marked with informative notices.
(3) The purpose of recording is to protect human life, physical integrity, personal freedom, safeguard business secrets, prevent and detect violations, document potential accidents occurring in the customer area, and ensure the protection of the public area for insurance purposes. The camera monitoring system does not record audio.
(4) The legal basis for camera surveillance is the voluntary consent of the data subject based on informative notices placed by our Company. Express consent can also be given through conclusive behavior. Such conclusive behavior includes entering or staying within the premises/areas monitored by the electronic surveillance and recording system.
(5) The location for storing recordings (personal data) captured by the electronic monitoring system is at our Company’s headquarters, and the duration of storage is three working days from the recording.
(6) The scope of processed data includes the recorded image of the data subject and other personal data captured by the operating camera system.
(7) Individuals who can access the personal data recorded through camera surveillance include the Company’s management, employees operating the camera system, and the data processors involved in the operation to investigate violations and monitor the system’s functionality.
- PROVISIONS RELATING TO DATA SECURITY
(1) The Company may process personal data only in accordance with the activities specified in this regulation and for the purpose of data processing.
(2) The Company ensures the security of data and undertakes to take all technical and organizational measures necessary to enforce data security regulations, data protection, and confidentiality rules, and establishes procedural rules necessary to comply with the above-mentioned regulations.
(3) The Company protects data with appropriate measures against unauthorized access, alteration, transmission, disclosure, deletion, or destruction, as well as against accidental destruction and damage, and against becoming inaccessible due to changes in the applied technology.
(4) The technical and organizational measures to be implemented for data security by the Company are recorded in the Company’s data protection policy.
(5) When defining and implementing measures for data security, the Company considers the current level of technology, selecting a solution that ensures a higher level of protection of personal data in case of multiple possible data handling solutions, except if it would pose disproportionate difficulties.
- RULES RELATED TO DATA PROCESSING
- General rules regarding data processing
(1) The rights and obligations of the data processor related to the processing of personal data are determined by law and within the framework of separate laws concerning data management, as defined by the data controller.
(2) The Company declares that during data processing activities, the data processor does not have the competence to make substantive decisions regarding data processing. The personal data obtained may only be processed according to the instructions of the data controller. The data processor cannot carry out data processing for its own purposes and is obliged to store and preserve personal data according to the instructions of the data controller.
(3) The Company is responsible for the legality of the instructions provided to the data processor concerning data processing operations.
(4) The Company is obliged to provide information to the data subjects about the identity of the data processor and the location of data processing.
(5) The Company does not authorize the data processor to engage further data processors.
(6) A written contract must govern the data processing. Organizations engaged in business activities that involve the use of the processed personal data cannot be entrusted with data processing.
Date: Budapest, May 25, 2018.
