GENERAL DATA MANAGEMENT  
INFORMATION  
OF COMPOFFICE-R LIMITED LIABILITY COMPANY  
COMPOFFICE-R IT Trade and Service Limited Liability Company, as a data controller,  
respects the privacy of all persons who provide personal data to it and is committed to  
protecting them.  
Based on Article 13 of the General Data Protection Regulation of the European Union  
(Regulation 679/2016, hereinafter: "GDPR"), it provides the following information:  
The Company treats the personal data recorded by it confidentially, in accordance with data  
protection legislation and international recommendations, in accordance with this Data  
Protection Notice (hereinafter: "Notice"), and takes all security, technical, and organizational  
measures that guarantee the security of the data.  
This Notice contains the principles of handling personal data provided by Users/Data Subjects.  
The purpose of this Notice is to provide detailed information to partners entering into a client  
relationship or other contracting, cooperating partners (hereinafter: "Clients") with the Data  
Controller (hereinafter: "Company" or "Data Controller") during the use of its services  
(hereinafter: "Service"), as well as visitors to the website operated by the Company  
(hereinafter: "Website") (hereinafter collectively: "Data Subjects") regarding all essential  
facts related to the processing of their personal data. This includes, in particular, the purpose  
and legal basis of data processing, the persons entitled to process and control the data, the  
duration of data processing, and who may become acquainted with the data in accordance with  
the provisions of the GDPR.  
Regarding other personal data processing, the Company provides information to the Data  
Subject in other notices, regulations, or at the time of data collection.  
The currently valid version of this Notice is continuously available on the Company's website  
and at the reception located at the Company's registered office.  
Data Controller Details:  
Company Name: COMPOFFICE-R Informatikai Kereskedelmi és Szolgáltató  
Korlátolt Felelősségű Társaság  
Registered Office: 1141 Budapest, Öv utca 29  
Company Registration Number: 01-09-434750  
Representative: Zsolt Kiss, Managing Director  
1. The Scope of Data Subjects, Scope of the Notice  
The scope of the Notice extends to everyone whose personal data is processed by the Company  
for business purposes, or whose data is made available to the Company.  
The personal scope of this Notice extends to the Company as Data Controller, as well as to  
those persons whose data are contained in the data processing covered by this Notice, and those  
persons whose rights or legitimate interests are affected by the data processing.  
The Company also processes the data of natural persons who, for example, have applied  
electronically (via data sent to the Data Controller's email address), via social media, by  
telephone, or in person for the purpose of establishing a client relationship, requested a quote,  
use or have applied for the Company's Services, or contacted the Company via its contact  
details for other reasons or purposes outside of establishing a client relationship, as well as  
those entering the Company's registered office or premises.  
The Company also processes the data provided by its natural person Clients, as well as  
representatives and contact persons of its non-natural person Clients, and potentially other  
Clients.  
In the case of personal data of Data Subjects where the Data Subject and the person providing  
the personal data regarding the Data Subject are not the same, the person providing the data is  
responsible for ensuring that they have the appropriate authorization from the Data Subject  
regarding the data provided and this person is obliged to inform the Data Subject about the  
provisions contained in this notice.  
The scope of this Notice covers all of the Company's data processing containing personal data,  
whether electronic and/or paper-based.  
This Notice is effective until further provision or revocation. The Company is entitled to  
unilaterally modify this Notice.  
2. Interpretative Provisions  
For the interpretation of this Notice, the specific definitions named below have the following  
meanings:  
"Personal data": any information relating to an identified or identifiable natural  
person.  
"Identifiable natural person": one who can be identified, directly or indirectly, in  
particular by reference to an identifier such as a name, an identification number,  
location data, an online identifier or to one or more factors specific to the physical,  
physiological, genetic, mental, economic, cultural or social identity of that natural  
person.  
"Data processing": any operation or set of operations which is performed on personal  
data or on sets of personal data, whether or not by automated means, such as collection,  
recording, organization, structuring, storage, adaptation or alteration, retrieval,  
consultation, use, disclosure by transmission, dissemination or otherwise making  
available, alignment or combination, restriction, erasure or destruction.  
"Data controller": the Company, and furthermore the natural or legal person or any  
other body which, alone or jointly with others, determines the purposes and means of  
the processing of personal data.  
"Data processor": a natural or legal person, public authority, agency or other body  
which processes personal data on behalf of the controller.  
"Recipient": a natural or legal person, public authority, agency or another body, to  
which the personal data are disclosed, whether a third party or not. Public authorities  
that may receive personal data in the framework of a particular inquiry in accordance  
with Union or Member State law shall not be regarded as recipients; the processing of  
those data by those public authorities shall be in compliance with the applicable data  
protection rules according to the purposes of the processing.  
"Third party": a natural or legal person, public authority, agency or body other than  
the data subject, controller, processor and persons who, under the direct authority of the  
controller or processor, are authorized to process personal data.  
"The data subject's consent": any freely given, specific, informed and unambiguous  
indication of the data subject's wishes by which he or she, by a statement or by a clear  
affirmative action, signifies agreement to the processing of personal data relating to him  
or her.  
"Special categories of personal data": personal data revealing racial or ethnic origin,  
political opinions, religious or philosophical beliefs, or trade union membership, and  
the processing of genetic data, biometric data for the purpose of uniquely identifying a  
natural person, data concerning health or data concerning a natural person's sex life or  
sexual orientation.  
"Data concerning health": personal data related to the physical or mental health of a  
natural person, including the provision of health care services, which reveal information  
about his or her health status.  
"Data transfer": making personal data available to a specific recipient.  
"Personal data breach": a breach of security leading to the accidental or unlawful  
destruction, loss, alteration, unauthorized disclosure of, or access to, personal data  
transmitted, stored or otherwise processed.  
Other terms defined by the GDPR are contained in Article 4 thereof.  
3. The Scope, Limitations, and Basic Principles of Data Processing  
The Company processes the personal data of Data Subjects only to the extent and for the  
duration necessary for the purposes defined above. Only personal data that is essential for the  
purpose of data processing and is suitable for achieving that purpose may be processed.  
The Company takes all necessary measures to ensure the accuracy, completeness, and up-to-  
date nature of personal data.However, considering that the Data Subjects are responsible for  
the authenticity of the data provided, Data Subjects are obliged to report any changes to their  
data as soon as possible after the change, but no later than within 3 working days, providing  
the new data to the Company at the contact details indicated in this Notice.  
The Company does not perform automated data processing or profiling.  
3.1. The source of the data: The Company receives the data of the Data Subjects either  
directly from the Data Subjects or from its Clients who provide the data of their contributors,  
employees, business partners as Data Subjects, or from the legal representatives of its Clients  
who provide the personal data of the Clients they represent to the Company.  
3.2. Duration of data processing: The duration of data processing is as follows - with the  
proviso that individual data processing purposes may establish the duration of data processing  
differently, and thus the data processing durations detailed for individual data processing  
purposes are primarily applicable.  
As a general rule, the duration of data processing lasts (i) until the specific data processing  
purpose is achieved and the personal data is deleted, (ii) until the withdrawal of consent for the  
processing of the Data Subject's data and consequently the deletion of the Data Subject's  
personal data, (iii) until the execution of the decision of the acting court/authority regarding  
deletion, (iv) in the absence of a different provision of law, until the statute of limitations for  
the enforceability of rights and obligations arising from the legal relationship grounding the  
Company's data processing, which is 5 years based on Act V of 2013 on the Civil Code.  
In the case of mandatory data processing based on laws, the relevant law determines the  
duration of data processing. Regarding issued invoices, based on the provisions of Act CL of  
2017 on the Rules of Taxation and Act C of 2000 on Accounting, a retention obligation exists  
for 8 years from the issuance of the invoice.  
The Company retains the personal data defined in this Notice – with the exceptions contained  
in the points relating to individual data processing purposes – for the time according to the  
general rule defined in this Notice, and then deletes them, or deletes them at the request of the  
Data Subject, or in the case of withdrawal of permission for the processing of the Data Subject's  
data.  
4. Description of Specific Data Processing Activities  
Contact, Request for Information, Communication  
Data Subjects can contact the Company using the form on the Website or via letters sent to the  
e-mail address (Contact menu item), and can request information from the Company by  
providing certain data. Prospective Clients of the Company can directly contact the employees  
of the Company designated for contact. Scope of Data Subjects: those natural persons who  
contact the Company and request information from the Company by providing their personal  
data.  
Scope of Data  
Persons contacting the Data Controller  
Subjects:  
Processing of personal data of persons contacting the Data  
Purpose of data  
Controller via the contact form on the Website or otherwise.  
processing:  
Identification of the natural person sending the message.  
Legal basis for  
data processing:  
The voluntary consent of the data subject [GDPR Article  
6(1)(a)]  
Scope of  
processed data:  
Purpose of data processing  
Name  
Identification  
Scope of Data  
Subjects:  
Persons contacting the Data Controller  
Phone number  
E-mail address  
Date of message  
Contact  
Contact  
Identification  
Subject and text of  
message  
Answering, providing information  
Other personal data  
provided by Data  
Subject  
The time necessary for the purpose of data processing, which  
is occasionally a maximum of 5 years from the data  
communication, or the deadline applicable for potential claim  
enforcement, but lasts at most until the withdrawal of consent.  
Duration of storage If no contract or agreement is concluded between the  
of personal data:  
Company and the Data Subject (or the company represented  
by them) following the data processing prior to the conclusion  
of the contract, the Data Controller deletes the message(s)  
after the closure of the communication - provided that no  
other data processing purpose is realized.  
Consequences of  
failure to provide  
data:  
Answering is not comprehensive or becomes impossible.  
How the data  
comes to the Data The Data Subject provides this data.  
Controller:  
Data processing related to Services provided by the Company and client relationships  
Data processing related to ordering Products/Services (survey), requests for quotes,  
concluding contracts, Product sales, and service provision  
The Data Subject may place an order regarding Products and Services. The Data Controller  
performs a survey at the installation site if necessary. It provides a preliminary quote to the  
Data Subject. Before sending the order, the Data Subject provides the data necessary for the  
purchase/use of the Service. The Data Controller confirms the order via e-mail to the Client,  
during which it may request further data necessary for the installation and use of the ordered  
Product or Service. By confirming the order, the Parties conclude the contract. The Data  
Controller processes this data until the delivery of the Product/performance of the Service.  
Scope of Data  
Subjects:  
Those who wish to purchase the Data Controller's  
Products or use its Services (Clients).  
Preparation of the conclusion of the contract with the Data  
Subjects, as well as the conclusion of the contract. In the  
case of the phone number, contact with Clients in the  
Purpose of data  
processing:  
Scope of Data  
Subjects:  
Those who wish to purchase the Data Controller's  
Products or use its Services (Clients).  
scope of sales and service organization. Identification of  
the Client.  
Data processing is necessary for taking steps at the  
request of the data subject prior to entering into a contract  
regarding Products or Services; and necessary for the  
performance of the contract after its conclusion - GDPR  
Article 6(1)(b).  
Legal basis for data  
processing:  
Scope of processed  
data:  
Purpose of data processing  
Client's name  
Identification of the Client  
Contact  
Client's residence  
Client's phone number  
Contact  
Client's e-mail address Contact, conclusion of contract  
Type of Product to be  
purchased and Service Sale of selected Product or provision of Service  
to be used  
The 5th year from data collection (statute of limitations), in  
Duration of storage of  
case of contract conclusion, the time of performance of  
personal data:  
the contract and 5 years following its termination.  
Consequences of  
failure to provide  
data:  
Conclusion of the contract between the data subject and  
the Company is not possible. Providing the data is a basic  
condition for the creation and performance of the contract.  
How the data comes  
The Client or another person acting on their behalf  
to the Data Controller: provides it.  
Data processing related to issuing invoices  
Description of activity: The Data Controller issues an invoice to the Client or another person.  
The invoice contains the personal data of the Client or another person and the service used.  
Scope of Data  
In whose name the invoice is issued.  
Subjects:  
Purpose of data  
Fulfillment of invoicing and retention obligations.  
processing:  
Fulfillment of a legal obligation of the Data Controller [GDPR  
Article 6(1)(c), Section 159(1) and Section 169(e)-(f) of Act  
Legal basis for data CXXVII of 2007 on Value Added Tax, Section 166(1)-(3),  
processing:  
Section 167 and Section 169(2) of Act C of 2000 on  
Accounting (hereinafter: Accounting Act)]. Data processing is  
not voluntary, it is independent of the Data Subject's will.  
Scope of  
processed data:  
Data content of the invoice: name of service recipient,  
address, name of service used, date of issuance.  
Scope of Data  
Subjects:  
In whose name the invoice is issued.  
Duration of storage 8 years from the issuance of the invoice (Accounting Act  
of personal data:  
169(2)).  
Consequences of  
failure to provide  
data:  
Invoice cannot be issued, service cannot be performed.  
How the data  
comes to the Data  
Controller:  
The service recipient provides it.  
Processing of contractual contact data  
The Company may process personal data during its business activity if such data is transmitted  
to it by the Data Subject or the other contracting party (legal person). The Company presumes  
that its Clients and Business Partners have the appropriate authorization or consent from the  
Data Subject regarding the data of natural persons provided by them.  
Natural persons establishing a business relationship, or  
Scope of Data  
legal persons providing natural person data, as well as  
Subjects:  
persons acting on behalf of these legal persons.  
The purpose of data processing is for the Data Controller to  
directly contact the Client, as well as the Client's employee,  
Purpose of data  
contact person – i.e., the Data Subject – if necessary, or to  
processing:  
maintain contact in matters affecting the Data Controller and  
the Client.  
Legal basis for data processing: The Data Controller  
processes the Data Subjects' data in order to maintain  
Legal basis for  
contact with the Client. The legal basis for data processing is  
data processing:  
the legitimate interest of the Data Controller (GDPR Article  
6(1)(f)).  
Scope of  
Purpose of data processing  
processed data:  
Name  
Identification of the Data Subject  
E-mail address  
Phone number  
Contact  
Contact  
The time necessary for the purpose of data processing,  
which occasionally coincides with the existence of the  
contractual legal relationship, but at most until the withdrawal  
Duration of storage of consent or the deadline applicable for potential claim  
of personal data:  
enforcement (5 years from the performance of the contract  
(limitation period)), as well as the duration determined by  
accounting laws (8 years from the preparation of the report,  
business report, or bookkeeping account for the given  
Natural persons establishing a business relationship, or  
legal persons providing natural person data, as well as  
persons acting on behalf of these legal persons.  
Scope of Data  
Subjects:  
business year from the time the personal data was provided  
by the data subject).  
Consequences of  
failure to provide  
data:  
Impossibility of contact.  
How the data  
comes to the Data  
Controller:  
Source of Data: the Data Subject, or the Company's business  
partner, the contracting party.  
4.5. Data processing related to Marketing  
Data processing related to Newsletter sending  
Description of activity: The Data Subject can subscribe to the newsletter with their data defined  
below before or during the use of Services, or in any other way. The Data Controller notifies  
subscribers about its further services, discounts, and offers in newsletters sent by phone and/or  
e-mail and/or by post. Following subscription, the Data Subject receives information about the  
subscription to the newsletter in an email message, which they must also confirm; their  
subscription becomes effective thereafter.  
Every natural person, or natural person acting on behalf  
Scope of Data  
Subjects:  
of legal persons, who wishes to be regularly informed  
about the Company's news, and therefore subscribes to  
the newsletter service by providing their personal data.  
The purpose of data processing related to newsletter  
sending is the general or personalized information of the  
Data Subject about the Company's latest services, news,  
promotions, offers, discounts.  
Purpose of data  
processing:  
The Data Subject's consent [GDPR Article 6(1)(a)]. In the  
Legal basis for data case of unsolicited marketing inquiries, the processing of  
processing:  
personal data for direct marketing purposes can be  
considered as based on the Company's legitimate interest.  
Scope of processed E-mail address and/or phone number and date of  
data: subscription.  
Duration of storage Until deletion at the Data Subject's request, i.e., until the  
of personal data:  
withdrawal of the Data Subject's consent.  
Consequences of  
failure to provide  
data:  
Newsletter cannot be sent, i.e., the Data Subject will not  
receive the Company's newsletters, commercial,  
informational letters.  
How the data comes  
to the Data  
The Data Subject provides it.  
Controller:  
Data processing related to Social Media sites  
Description of activity: The Data Controller is present on the Facebook social portal, as well  
as on other social sites (LinkedIn/Instagram). The primary purpose of the content placed on  
these sites is the presentation of the Service, sharing, publishing, and marketing of content  
found on the Website on the social site. With the help of the social site, Data Subjects can get  
information about the latest products, the Service, and potential promotions and news of the  
Company. During its activity, the Company may process the name and public data of Data  
Subjects registered on social sites:  
(Facebook / Twitter / LinkedIn / Pinterest / Youtube / Instagram / TikTok etc.) connected to  
the Website for the purpose of sharing, "liking", or promoting specific content elements,  
products, promotions of the social site or the social site itself, who "like" the Company's social  
page on the social sites. The Company communicates with Data Subjects via the social site  
exclusively if the Data Subject contacts the Company on this forum, i.e., via the social site.  
Those natural persons who follow, share, or like the  
Data Controller's social pages or their content, or  
comment on the content.  
Scope of Data  
Subjects:  
Contact and maintenance of contact between the Data  
Purpose of data  
Subject and the Data Controller within and through social  
processing:  
sites, and other operations permitted by the social site.  
The Data Subject's consent [GDPR Article 6(1)(a)]. The  
Legal basis for data  
processing:  
Data Subject voluntarily consents to following and liking  
the Company's content based on the terms of the social  
site.  
Scope of processed  
data:  
Name, e-mail address, public data, message, date of  
comment.  
Duration of storage of Until deletion at the Data Subject's request, i.e., until the  
personal data:  
withdrawal of the Data Subject's consent.  
Consequences of  
failure to provide  
data:  
Communication does not take place on the given  
platforms.  
How the data comes  
to the Data Controller:  
The Data Subject provides it.  
The Company may link the given social site with other social sites according to the rules  
applicable to the given social portal, so publication on one site must be understood as  
publication on such linked social portals as well. The Data Subject can receive information  
about the data processing of the given social site, the source of data, their handling, the method  
of transfer, and legal basis on the given social site. The relevant data processing takes place on  
the social sites, so the regulations of the given social site apply to the duration and method of  
data processing, as well as the possibilities for deleting and modifying data.  
Debt Management  
Description of activity: Debt management includes all measures taken to collect the Data  
Controller's legitimate claims and outstanding debts. Activity and process involved in data  
processing: The Data Controller contacts the representative of the Client with debt by phone  
and/or in writing, calling for payment; It makes the claims and relevant personal data related  
thereto available to an external debt collection company at its choice; During official  
proceedings, or in the case of using non-litigious or litigious proceedings, the Data Controller  
transmits the data to the competent authorities or courts to the necessary extent.  
Against whom the Data Controller has an overdue claim,  
Scope of Data  
Subjects:  
and those persons whom the debtor companies (Clients)  
provide as contact persons for the purpose of enforcing  
claims.  
Purpose of data Identification of Clients, contact, taking measures to collect  
processing:  
claims.  
The data controller's legitimate interest [GDPR Article 6(1)(f)].  
(Note: The original text mentions protecting personal items in a  
waiting room, which seems to be a copy-paste error in the  
source document, but strictly translating: "The Data Controller's  
legitimate interest is to ensure the protection of personal items  
and values left in the waiting room by patients and their  
escorts.") [Translator's note: Ideally, this should refer to the  
legitimate interest in recovering debts.]  
Legal basis for  
data  
processing:  
Scope of  
processed data:  
Name, email, address, phone number, billing or mailing address.  
Duration of  
storage of  
personal data:  
Duration of data processing: the deadline open for claim  
enforcement, or in the case of official/litigious or non-litigious  
proceedings, their duration.  
How the data  
comes to the  
Data Controller:  
The Data Subject, or the Company's Client.  
5. Persons Entitled to Access  
Only those employees and agents of the Company are entitled to access the data for whom it is  
necessary for the performance of their job duties. Persons accessing personal data at the  
Company are subject to a confidentiality obligation regarding the personal data of Data  
Subjects, i.e., they are obliged to treat personal data and other information that comes to their  
knowledge during the performance of their job duties or otherwise confidentially, and not make  
them available to third parties.  
6. Data Security  
The Company pays attention to the requirement of data security during the design of its entire  
data protection process according to the principle of "privacy-by-design", i.e., default and built-  
in data protection. The Company's goal is to minimize the processing of personal data in order  
to reduce data processing risks. The Company ensures that the data security rules prescribed in  
the relevant laws are enforced. When determining and applying measures serving the security  
of data, the Company takes into account the current state of technology and chooses from  
several possible data processing solutions the one that ensures a higher level of protection of  
personal data, unless it would represent a disproportionate difficulty.  
The Company takes the technical and organizational measures and establishes the procedural  
rules that are necessary to enforce the governing laws and data and confidentiality protection  
rules. The Company protects the data with appropriate measures against unauthorized access,  
alteration, transmission, disclosure, deletion or destruction, as well as accidental destruction  
and damage, and furthermore against becoming inaccessible due to changes in the applied  
technology.  
In its data security scope of duties, the Data Controller:  
takes technical and organizational measures regarding the security of electronically  
stored data;  
ensures the enforcement of data security rules required by law;  
ensures the enforcement of data protection and confidentiality rules;  
prevents unauthorized access to data;  
takes necessary measures to prevent damage to data;  
promotes data processing awareness regarding its employees for the purpose of  
ensuring data security;  
ensures the physical protection of data stored on paper;  
ensures the physical protection of devices used for electronically stored data;  
ensures password protection of electronically stored data;  
provides for regular backup of data;  
ensures that access to data is allowed exclusively for those entitled to it.  
The Company ensures the protection of the security of data processing with technical,  
organizational and organizational measures that provide a level of protection appropriate to the  
risks arising in connection with data processing, selecting and operating the applied IT tools in  
such a way that the processed data: a) is accessible to those authorized (availability); b) its  
authenticity and authentication are ensured (authenticity of data processing); c) its immutability  
can be verified (data integrity); d) is accessible only to those authorized, protected against  
unauthorized access (confidentiality of data).  
The Company ensures the appropriate preparation of the concerned staff in order to enforce the  
conditions of data security. The Company provides the expected level of protection during the  
processing of data - thus especially their storage, rectification, deletion - during the Data  
Subject's request for information or objection.  
7. Storage of Personal Data, General Information Related to Data Processing  
The storage of personal data takes place at the Company's registered office on paper and  
electronically, on the Company's servers.  
General information related to data processing based on the Data Controller's legitimate  
interest: Related to data processing based on the Data Controller's legitimate interest, the Data  
Controller has performed the interest balancing test. Based on legitimate interest, the Data  
Controller does not process personal data that would not be compatible with the purposes of  
the contract between the Data Controller and the Client.  
8. Data Processing, Data Transfer  
Recipients of personal data:  
Employees and contributors of the Data Controller performing financial, taxation,  
billing, controlling, auditing tasks, the managing director of the Data Controller, staff  
performing administrative tasks, the Data Controller's data processors;  
Court, police, other bodies exercising public authority, state authorities may contact  
the Data Controller in the framework of their official proceedings based on legal  
authorization for the transfer of personal data;  
National Tax and Customs Administration (http://nav.gov.hu/);  
Lawyer providing legal representation;  
Data processors used by the Data Controller: In order to achieve the data processing  
purposes defined in this Notice, to fulfill legal obligations, and to perform its tasks, the  
Company uses the services of third parties, which services may include the processing of  
personal data of Data Subjects. These third parties (hereinafter: "Data Processor") perform  
data processing in accordance with the Company's instructions and in compliance with the  
provisions of applicable laws. For the purpose of data processing, only personal data necessary  
for the realization of the given purpose are transmitted to the individual Data Processors.  
9. Management of Personal Data Breaches  
The Company does everything to avoid personal data breaches. A personal data breach is a  
breach of security leading to the accidental or unlawful destruction, loss, alteration,  
unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise  
processed. The Data Controller immediately reports the personal data breach to the National  
Authority for Data Protection and Freedom of Information, unless the personal data breach is  
unlikely to result in a risk to the rights and freedoms of natural persons. The Data Controller  
keeps a record of personal data breaches, together with measures related to the given incident.  
If the incident is severe (i.e., likely to result in a high risk to the rights and freedoms of the data  
subject), the Data Controller informs the Data Subject about the personal data breach without  
undue delay.  
10. Rights of the Data Subject Related to Data Processing  
The Company draws the attention of Data Subjects that in case of a complaint or comment, it  
is advisable primarily to contact the Company as Data Controller at one of the contact details  
indicated in this Notice.  
Rights of the Data Subject:  
a) Information/Right of access The Data Subject is entitled to receive feedback from the  
Company as to whether the processing of their personal data is in progress, and if such data  
processing is in progress, they are entitled to receive information about the processed personal  
data, the purpose of data processing, categories of data, recipients, duration of storage, their  
rights, and the source of the data. The Company provides a copy of the personal data subject  
to data processing to the Data Subject. The information is free of charge if the person requesting  
information has not yet submitted a request for information regarding the same scope of data  
to the Data Controller in the current year. In other cases - especially if the request is excessive  
or unfounded - reimbursement of costs may be established. For further copies requested by the  
Data Subject, the Company may charge a reasonable fee based on administrative costs.  
b) Rectification and completion The Data Subject is entitled to have the Company rectify  
inaccurate personal data concerning them without undue delay upon request. Taking into  
account the purpose of data processing, the Data Subject is entitled to request the completion  
of incomplete personal data – including by means of a supplementary statement.  
c) Erasure/Right to be forgotten The Data Subject is entitled to have the Company erase  
personal data concerning them without undue delay upon request if the purpose of data  
processing has ceased, the Data Subject has withdrawn their consent to data processing, and  
there is no other legal basis for data processing, or if the personal data were processed  
unlawfully.  
d) Restriction of data processing The Data Subject is entitled to have the Company restrict  
data processing upon request if one of the following is met:  
the Data Subject disputes the accuracy of the personal data, in this case the restriction  
applies to the period enabling the Data Controller to verify the accuracy of the personal  
data;  
the data processing is unlawful, and the Data Subject opposes the erasure of the data  
and requests the restriction of their use instead;  
the Company no longer needs the personal data for the purposes of the data processing,  
but the Data Subject requires them for the establishment, exercise or defense of legal  
claims;  
or the Data Subject has objected to processing; in this case the restriction applies for  
the period until it is verified whether the legitimate grounds of the Company override  
those of the Data Subject.  
If data processing falls under restriction based on the above, such personal data shall, with the  
exception of storage, only be processed with the Data Subject's consent or for the  
establishment, exercise or defense of legal claims or for the protection of the rights of another  
natural or legal person or for reasons of important public interest of the Union or of a Member  
State. The Company informs every recipient to whom the personal data has been disclosed  
about the rectification, erasure, right to be forgotten, or restriction of data processing, unless  
this proves impossible or involves disproportionate effort.  
e) Right to data portability The Data Subject is entitled to receive the personal data  
concerning them, which they have provided to the Company, in a structured, commonly used  
and machine-readable format, and have the right to transmit those data to another controller  
without hindrance from the Company, where the processing is based on consent and the  
processing is carried out by automated means. In exercising the right to data portability, the  
Data Subject is entitled to have the personal data transmitted directly from one controller to  
another, where technically feasible. The exercise of the right shall not adversely affect the right  
to erasure. The mentioned right shall not apply where processing is necessary for the  
performance of a task carried out in the public interest or in the exercise of official authority  
vested in the controller. The exercise of the right shall not adversely affect the rights and  
freedoms of others.  
f) Objection The Data Subject is entitled to object, on grounds relating to their particular  
situation, at any time to processing of personal data concerning them which is based on point  
(e) or (f) of Article 6(1) of the GDPR, including profiling based on those provisions. In this  
case, the Company shall no longer process the personal data unless it demonstrates compelling  
legitimate grounds for the processing which override the interests, rights and freedoms of the  
Data Subject or for the establishment, exercise or defense of legal claims. The Data Subject is  
further entitled not to be subject to a decision based solely on automated processing – including  
profiling – which produces legal effects concerning them or similarly significantly affects  
them. The exception to the above is if the decision:  
is necessary for entering into, or performance of, a contract between the Data Subject  
and the Company;  
is authorized by Union or Member State law to which the Company is subject and  
which also lays down suitable measures to safeguard the Data Subject's rights and  
freedoms and legitimate interests;  
or is based on the Data Subject's explicit consent.  
g) Right to withdrawal of consent If the processing of their personal data takes place based  
on the Data Subject's consent, the Data Subject is entitled to withdraw it at any time. In case of  
withdrawal of consent, the data processing is terminated with the deletion of their personal  
data, provided that there is no other legal basis for the processing of their personal data. The  
withdrawal of consent does not entail consequences for the Data Subject. However, the  
withdrawal of consent shall not affect the lawfulness of processing based on consent before its  
withdrawal.  
11. Procedure in Case of Data Subject's Request  
The Data Subject may turn to the Company's representative with their claim as above or other  
question or request concerning their personal data at any of the contact details indicated in this  
Notice. Please contact us in electronic form if possible. We inform you that the Data Controller  
answers data protection requests in electronic form if possible, unless you, as a data subject,  
explicitly request another method of contact, or the Data Controller does not know your  
electronic contact details. The Company is obliged to judge the request within 30 days from  
the receipt of the request submitted in writing. If necessary, taking into account the complexity  
of the request and the number of current requests, the Company may extend the deadline for  
judging the request by 2 months. The Data Subject must be informed about the fact of the  
extension and its reasons in advance. If the Data Subject's request is well-founded, the  
Company executes the requested measure within the procedural deadline and provides written  
information to the Data Subject regarding the execution. If the Company rejects the Data  
Subject's request, it is obliged to make a written decision about this. In its decision, it is obliged  
to indicate the facts serving as the basis for the decision, the justification of its decision by  
presenting the appropriate laws and case decisions, and is further obliged to inform the Data  
Subject about the legal remedy possibilities governing against the Company's decision. If the  
Data Subject does not agree with the Company's decision, or if the Company misses the  
relevant above procedural deadline, the Data Subject may turn to the supervisory authority or  
court. We inform you that legal representatives are entitled to act on behalf of persons under  
18 years of age.  
12. Supervisory Authority  
If the Data Subject considers that the processing of their personal data by the Company violates  
the provisions of the currently effective data protection laws, especially the GDPR, they have  
the right to lodge a complaint with the National Authority for Data Protection and Freedom of  
Information.  
Contact details of the National Authority for Data Protection and Freedom of  
Information:  
Address: 1055 Budapest, Falk Miksa utca 9-11.  
Postal address: 1363 Budapest, Pf. 9.  
Phone: +36-1-391-1400 Fax: +36-1-391-1410  
E-mail: ugyfelszolgalat@naih.hu  
The Data Subject has the right to lodge a complaint with a supervisory authority established in  
another European Union Member State, in particular of their habitual residence, place of work  
or place of the alleged infringement.  
13. Right to Judicial Remedy (Right to turn to court)  
The Data Subject - independently of their right to lodge a complaint - may turn to court if their  
rights under the GDPR have been violated during the processing of their personal data. A  
lawsuit may be initiated against the Company, as a Hungarian Data Controller, before a  
Hungarian court. If the Data Subject wishes to initiate court proceedings against the Data  
Processor, it must be initiated before the court of the Member State where the Data Processor  
has its place of activity. The Data Subject may initiate the lawsuit before the tribunal of their  
place of residence or stay. In Hungary, the contact details of tribunals can be found at the  
following link: http://birosag.hu/torvenyszekek. If the Data Subject's habitual residence is in  
another Member State of the European Union, the lawsuit may also be initiated before the court  
having jurisdiction and competence in the Member State of the habitual residence.  
14. Other Provisions  
The Company reserves the right to unilaterally modify this Notice at any time. This Notice is  
effective until further provision or revocation.