Privacy Policy
This English text is a courtesy translation, provided for convenience only. In the event of any discrepancy, the Hungarian version — Adatvédelmi irányelvek — is the legally binding one.
Entry into force: 28 January 2022 · Last amended: 25 August 2026
I. General provisions
The purpose of this notice is to ensure that interiorvibe.hu (hereinafter: the Data Controller) proceeds, in every area of the services it provides, on the basis of and in accordance with the provisions set out in this Privacy Notice when processing personal data. The Data Controller is committed to protecting the personal data of its users and clients, and furthermore regards it as especially important to respect the right of its clients to informational self-determination. The Data Controller treats personal data confidentially and takes every security, technical and organisational measure that guarantees the highest possible degree of security of the personal data processed. The Data Controller protects personal data by appropriate measures against unauthorised access, alteration, transmission, disclosure, erasure or destruction, as well as against accidental destruction and damage.
In establishing these rules the Data Controller took particular account of the provisions of the Infotv. (Act CXII of 2011 on Informational Self-Determination and Freedom of Information; hereinafter: Infotv.), as well as of Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR Regulation”; hereinafter: General Data Protection Regulation).
The scope of this Privacy Notice extends to all data processing activities of the Data Controller concerning natural persons, in particular to the data processing activities carried out on its website [https://interiorvibe.hu/] and on its social media pages [https://www.facebook.com/interiorvibestudio/] and [https://www.instagram.com/interiorvibestudio].
The Notice enters into force on the day of its publication on the website of the Data Controller. The day of publication is 28 January 2022. The day of the last amendment of the Notice: 25 August 2026. The Data Controller reserves the right to amend the Privacy Notice unilaterally, without prior notification of users.
The Data Controller processes exclusively the data provided by users or specified by law, for the purposes set out below. In the case of processing based on voluntary consent, the user may withdraw this consent at any stage of the processing. The scope of the personal data processed must be proportionate to the purpose of the processing and may not go beyond it.
The Data Controller does not verify the personal data provided to it. The user is responsible for the data provided by the User, and for the accuracy and truthfulness thereof. The Data Controller is not liable for damage arising from data provided erroneously or deliberately incorrectly, even if it could have recognised the erroneous nature of the data.
Personal data may be processed exclusively by those staff members of the Data Controller who are authorised to do so, on the basis of the provisions of this notice. The Data Controller does not transfer the personal data processed by it to any third party other than the Data Processors specified in the notice. The Data Processors are entitled to act exclusively in accordance with the contract concluded with the Data Controller and the instructions received from it. The Data Processors are entitled to engage a further data processor only with the consent of the Data Controllers.
II. Principles relating to the processing of personal data
Personal data:
- shall be processed lawfully, fairly and in a transparent manner in relation to the data subject (“lawfulness, fairness and transparency”);
- shall be collected only for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; in accordance with Article 89(1), further processing for archiving purposes in the public interest, for scientific and historical research purposes or for statistical purposes shall not be considered to be incompatible with the initial purposes (“purpose limitation”);
- shall be adequate and relevant from the point of view of the purposes of the processing, and shall be limited to what is necessary (“data minimisation”);
- shall be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate from the point of view of the purposes of the processing are erased or rectified without delay (“accuracy”);
- shall be kept in a form which permits identification of data subjects for no longer than is necessary for achieving the purposes of the processing of the personal data; personal data may be stored for a longer period only insofar as the personal data will be processed, in accordance with Article 89(1), for archiving purposes in the public interest, for scientific and historical research purposes or for statistical purposes, subject also to the implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subjects (“storage limitation”);
- shall be processed in such a manner that, through the application of appropriate technical or organisational measures, the appropriate security of the personal data is ensured, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage (“integrity and confidentiality”).
The data controller is responsible for compliance with the above and must furthermore be able to demonstrate such compliance (“accountability”).
III. Identity of the Data Controller
The data controller: Interior Info Kft. (registered office / postal address: 2161 Csomád, Kossuth Lajos út 47.; tax number: 29230660-2-13; e-mail: hello@interiorvibe.hu).
IV. Definitions
Personal data: any data on the basis of which a natural person can be identified;
“any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier, for example a name, a number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person” [General Data Protection Regulation, Article 4].
Data subject (user): any specified natural person who is identified on the basis of personal data or who is – directly or indirectly – identifiable.
Consent of the data subject: the voluntary, express and unambiguous consent of the data subject to the processing of his or her personal datum or data;
“any freely given, specific, informed and unambiguous indication of the data subject's wishes by which the data subject, by a statement or by an act unmistakably expressing affirmation, signifies agreement to the processing of personal data relating to him or her” [General Data Protection Regulation, Article 4].
Processing: any operation performed on personal data, e.g.: recording, categorisation, alteration, transmission, erasure;
“any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction” [General Data Protection Regulation, Article 4].
Data controller: the natural or legal person who determines the purposes and means of the processing – alone or jointly with others; in the case of the services referred to in this Notice, interiorvibe.hu qualifies as the data controller;
“the natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of the processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may also be provided for by Union or Member State law” [General Data Protection Regulation, Article 4].
Data processor: “the natural or legal person, public authority, agency or any other body which processes personal data on behalf of the controller” [General Data Protection Regulation, Article 4]; in the case of the services referred to in this Notice, the data processors may be the service providers listed in Chapter VI of this Notice;
Personal data breach: an unexpected event in the course of which the personal data stored by the data controller may be damaged or destroyed, and furthermore unauthorised persons may gain unauthorised access to them;
“a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed” [General Data Protection Regulation, Article 4].
Website: the https://interiorvibe.hu/ internet site operated by the Data Controller, and the subpages of this website.
Service(s): the services operated by the Data Controller and provided by the Data Controller, which are available on the website.
V. Scope, legal basis, purpose and duration of the personal data processed
1. Personal data provided in the contact, quote request and consultation forms
| Personal data | Purpose of the processing |
|---|---|
| Name | Necessary for making contact and for keeping in contact, and furthermore for identifying the user. |
| E-mail address | Necessary for making contact and for keeping in contact. |
| Telephone number (optional) | Necessary for making contact and for keeping in contact. |
| The text of the message | Necessary for understanding the request and for replying to it. |
| Data of the property (location, size, condition, planned timing) | Necessary for clarifying the design request and for personalised preparation. |
| The names of the files intended to be attached | To identify the documents indicated by the data subject. On these forms the files themselves are not uploaded, only their names. |
| Time of sending the message | Performance of a technical operation. |
| Landing page, referring page, campaign data and advertising click identifier | To establish which advertisement or which page the enquiry came from. |
Legal basis of the processing: taking steps at the request of the data subject prior to entering into a contract [Article 6(1)(b) of the General Data Protection Regulation]. The legal basis for processing the advertising click identifier and the campaign data is the legitimate interest of the Data Controller [Article 6(1)(f)] in learning whether its advertisements are effective.
Duration of the processing: until the request of the data subject for erasure, but at most for 2 years from the last contact.
2. Personal data provided when booking an appointment
| Personal data | Purpose of the processing |
|---|---|
| Name, e-mail address, telephone number | Identification of the booking, sending the confirmation and the reminder. |
| The chosen time and the format of the meeting | Creating the calendar entry and holding the slot. |
| The text of the message, the style references and the timing provided | Preparation for the meeting. |
| The uploaded files (floor plan, photo, inspiration) and their name, size and type | Preparation for the meeting. The files are stored in closed, non-public storage. |
| The unique identifier belonging to the booking | Operation of the link that allows the booking to be changed or cancelled. |
Transfer of data: The data of the booking — the name, the e-mail address, the telephone number and the message — are transferred to the Google Calendar of the Data Controller. The data subject appears as an invitee of the calendar entry, so the invitation is sent to them by Google. In the case of an online meeting, a Google Meet link is created.
Legal basis of the processing: taking steps at the request of the data subject prior to entering into a contract [Article 6(1)(b)].
Duration of the processing: until the request of the data subject for erasure, but at most for 2 years from the last contact.
3. Personal data provided in the indicative price calculator
| Personal data | Purpose of the processing |
|---|---|
| First name and e-mail address | Calculating the indicative design fee and sending it. |
| Telephone number (optional) | If the data subject asks for it, discussing the detailed quotation. |
| The answers concerning the property: type, location, floor area, planned timing, the required depth of the documentation, the planned budget and the aspects marked as important | Calculating the indicative design fee and preparing the further discussion. |
| The IP address, or rather a salted fingerprint of the IP address combined with the browser identifier | To establish that the same visitor is not shown the pop-up window more than once, and to filter out repeated, abusive submissions. The original IP address cannot be restored from the fingerprint. |
Legal basis of the processing: as regards preparing and sending the calculation, taking steps at the request of the data subject prior to entering into a contract [Article 6(1)(b)]. The legal basis for creating and storing the fingerprint is the legitimate interest of the Data Controller [Article 6(1)(f)] in not showing the pop-up window repeatedly to the same visitor and in preventing abusive use of the service.
Duration of the processing: until the request of the data subject for erasure, but at most for 2 years from the last contact.
4. Subscription to the newsletter and to the downloadable design materials
| Personal data | Purpose of the processing |
|---|---|
| Name and e-mail address | Sending the requested material and delivering the newsletter. |
| The timing provided (when the project is planned) and the grouping derived from it | So that the data subject receives content that matches their situation. |
| The source and the time of the subscription | To establish which page the subscription came from. |
| The IP address recorded at the time of subscription | Subsequent proof that consent was given. |
| Unique identifier | Operation of the unsubscribe and confirmation links. |
| The opening of the messages sent and the clicks on the links they contain | Measuring which content is useful and adjusting the message sequences accordingly. |
Legal basis of the processing: the consent of the data subject [Article 6(1)(a)]. Consent may be withdrawn at any time without giving reasons: every message sent contains an unsubscribe link at the bottom.
Duration of the processing: until unsubscription, or until the withdrawal of consent.
5. Personal data processed during the contractual cooperation
In the course of the work carried out with its clients, the Data Controller uses an intake form as well as documents that can be signed electronically.
| Personal data | Purpose of the processing |
|---|---|
| The contact, property and project data provided in the intake form | Carrying out the design work. |
| In the case of an electronic signature: the name, e-mail address and IP address of the signatory, the time and the image of the signature, and the verification code sent by e-mail | Authenticating the signature and making it subsequently verifiable. |
Legal basis of the processing: performance of the contract [Article 6(1)(b)]; as regards the data recording the circumstances of the signature, the legitimate interest of the Data Controller [Article 6(1)(f)] in establishing and defending legal claims.
Duration of the processing: 5 years from the termination of the contract (the general limitation period).
6. Technical data relating to the use of the website
| Personal data | Purpose of the processing |
|---|---|
| The address of the page visited, the referring page and the time of the visit | Preparing visitor statistics and developing the website. |
| Advertising click identifiers (gclid, gbraid, wbraid) and campaign data, where the data subject arrived by clicking on an advertisement | To establish which advertisement generated the enquiry. The Data Controller may report these identifiers back to the advertising system for conversion measurement. |
| The time spent on the site, the number of pages viewed and the choice made on the cookie banner | Developing the website and the banner. |
| Aggregated, anonymous usage data (clicks, scrolling, screen size) | Improving the usability of the website. On their own, these data are not suitable for identifying the data subject. |
Legal basis of the processing: the legitimate interest of the Data Controller [Article 6(1)(f)] in understanding the operation and the effectiveness of the website. These data are stored in the own system of the Data Controller; no cookie is placed on the device of the visitor in order to record them. Cookies placed by third parties are governed by Chapters VII and VIII.
Duration of the processing: 2 years from the recording.
VI. Data processors
The Data Controller keeps a record of its client relationships in a system it developed itself, running on its own database; it does not use an external customer relationship management (CRM) service for this. The data processors listed below provide the IT services required for the operation of that system.
1. Operation and hosting of the website
| Name of the data processor: | Vercel Inc. |
|---|---|
| Registered office: | 440 N Barranca Avenue #4133, Covina, CA 91723, United States of America |
| E-mail address: | privacy@vercel.com |
| Privacy policy: | Yes (https://vercel.com/legal/privacy-policy) |
| Activity carried out by the data processor: | Hosting of the website, serving it and running the server-side code. |
| Scope of the data processed by the data processor: | The network identity of the data subject: the IP address of their device, the identifier of the browser they use, the time of the visit and the addresses of the pages viewed, and furthermore every item of data that the data subject submits through the forms of the website, for the duration of the service. |
| Scope of the data subjects: | Natural persons visiting the website. |
| Purpose of the processing: | Ensuring the operation and the security of the website. |
| Duration of the processing: | The time required for serving the website, and the period following from the logging practice of the service provider. |
| Transfer of data to a third country: | The service provider is an undertaking registered in the United States of America. According to its declaration it complies with the EU–U.S. Data Privacy Framework, and it also applies the standard contractual clauses adopted by the European Commission to transfers of data. |
2. Database and file storage
| Name of the data processor: | Supabase, Inc. |
|---|---|
| E-mail address: | privacy@supabase.com |
| Privacy policy: | Yes (https://supabase.com/privacy) |
| Activity carried out by the data processor: | Database and file storage service. The database of the Data Controller operates within the territory of the European Union, in a data centre in Ireland. |
| Scope of the data processed by the data processor: | All the data listed in Chapter V of this notice: the data provided in the forms, in the appointment booking, in the indicative price calculator and on subscribing to the newsletter, the uploaded files, and the data of the visit log. |
| Scope of the data subjects: | Natural persons who provide data on the website or who visit it. |
| Purpose of the processing: | The secure storage of the data. |
| Duration of the processing: | The period indicated for the given processing operation in Chapter V of this notice. |
| Transfer of data to a third country: | The service provider is an undertaking registered in the United States of America; the data of the Data Controller are, however, stored within the European Union. For any transfers, the service provider applies the standard contractual clauses adopted by the European Commission. |
3. Delivery of e-mails
| Name of the data processor: | Plus Five Five, Inc. (“Resend”) |
|---|---|
| E-mail address: | support@resend.com |
| Privacy policy: | Yes (https://resend.com/legal/privacy-policy) |
| Activity carried out by the data processor: | Delivery of the messages sent by the Data Controller: confirmations, quotations, document links, reminders, and the newsletter and the downloadable materials. |
| Scope of the data processed by the data processor: | The name and e-mail address of the recipient, and the subject and the full content of the message. |
| Scope of the data subjects: | Natural persons who receive a message from the Data Controller. |
| Purpose of the processing: | Delivery of the messages. |
| Duration of the processing: | The time required for delivery, and the period following from the logging practice of the service provider. |
| Transfer of data to a third country: | The service provider is an undertaking registered in the United States of America, so the data are also transferred to the United States. |
4. Calendar and online meeting
| Name of the data processor: | Google Ireland Limited |
|---|---|
| Registered office: | Gordon House, Barrow Street, Dublin 4, Ireland |
| Privacy policy: | Yes (https://policies.google.com/privacy) |
| Activity carried out by the data processor: | Providing a calendar service (Google Calendar) and online meetings (Google Meet). |
| Scope of the data processed by the data processor: | The name, e-mail address, telephone number and message provided when booking an appointment, which are placed in the description of the calendar entry, and the e-mail address of the data subject among the invitees. |
| Scope of the data subjects: | Natural persons who book an appointment. |
| Purpose of the processing: | Recording the time of the meeting, sending the invitation and the reminder. |
| Duration of the processing: | Until the calendar entry is deleted. |
5. Domain, DNS and e-mail mailboxes
| Name of the data processor: | Tárhely.Eu Szolgáltató Kft. |
|---|---|
| Registered office: | 1144 Budapest, Ormánság utca 4. X. emelet 241. |
| Company registration number: | 01 09 909968 |
| Tax number: | 14571332242 |
| E-mail address: | support@tarhely.eu |
| Telephone number: | +36 1 789 2 789 |
| Privacy policy: | Yes (https://tarhely.eu/dokumentumok/adatvedelmi_szabalyzat.pdf) |
| Activity carried out by the data processor: | Domain and DNS service, and the operation of the e-mail mailboxes of the Data Controller. |
| Scope of the data processed by the data processor: | The content of the correspondence conducted with the Data Controller and the personal data appearing in that correspondence. |
| Scope of the data subjects: | Natural persons who correspond with the Data Controller. |
| Purpose of the processing: | Ensuring electronic correspondence. |
| Duration of the processing: | Until the correspondence is deleted. |
VII. Cookies
The meaning of a cookie: files or pieces of information that the user's internet browser downloads from a website and stores on the user's device. Cookies, on the one hand, collect information about the visitors to the website and their devices and, on the other hand, remember the individual settings of the visitors, which may also be used later.
In order to provide a customised service, the Data Controller, or the operator of the website, places on the user's computer – where the user / data subject consents to this – a small data packet, a so-called cookie, and reads it back during a subsequent visit. If the browser sends back a previously saved cookie, the service provider managing the cookie is able to link the current visit of the user with earlier ones, but exclusively with regard to its own content. Cookies therefore make the use of the website easier, as they improve the user experience. Some of the data recorded by cookies and similar technologies — in particular the advertising click identifier and the identifiers placed by the advertising systems — qualify as personal data under the General Data Protection Regulation, because they are capable of identifying the data subject indirectly. The Data Controller processes these data as described in Chapters V and VIII of this notice.
The operator of the website is able to place and analyse cookies only if the visitor (data subject) gives their consent to this in the pop-up message shown when the website loads, thereby permitting the analysis. The legal basis of the processing is therefore the voluntary consent of the data subject.
Once cookies have been accepted, the system of the Data Controllers automatically records the following data:
- IP address of the connecting computer;
- Domain name;
- Date and time of the visit;
- Login data;
- HTTP response code;
- Pages visited;
- Individual settings of the pages;
- Operating system and its version number;
- Browser program and its version number;
- Screen resolution;
The following types of cookies can be distinguished:
The purpose of session / temporary cookies (session cookies) is to allow visitors to browse the website of the Data Controller fully and smoothly, and to use its functions and the services available there. The validity period of this type of cookie lasts until the end of the session (browsing); when the browser is closed, this type of cookie is automatically deleted from the computer or from the other device used for browsing.
Stored / persistent cookies are those cookies that are used every time the user visits the site. The persistent cookies required for analysis show where the user went within the website, which pages and products they viewed, and what they did. It remains on the client machine depending on the lifetime of the cookie. Functions such as Google Analytics may use them. These cookies do not contain personal data and are not suitable for identifying the visitor.
The user is able to delete the cookie from their own computer, and may also disable the use of cookies in their browser. Cookies can generally be managed in the Tools/Settings menu of browsers, under the Privacy settings, under the designation cookie (in Hungarian: süti). By disabling the use of cookies, the user acknowledges that without cookies the operation of the given page is not fully functional. If the user consents to the placement of cookies and does not delete them subsequently, the cookies are automatically deleted after 180 days.
VIII. Google Ads, Google Analytics, Facebook, Microsoft Clarity, Metricool
The Data Controller also uses the third-party cookies of Google Analytics on its website. By using the Google Analytics statistical service, the Data Controller collects information about how visitors use the website. On the basis of the information saved by the cookies, Google evaluates how the User used the website and also prepares reports for the operator of the website in connection with website activity. It uses the data for the purpose of developing the website and improving the user experience. These cookies likewise remain on the computer of the visitor, or on the other device used for browsing, in its browser, until they expire or until the visitor deletes them. The lifetime of the cookies created by Google Analytics varies: the _ga cookie remains on the device of the visitor for up to 2 years, while the other analytics cookies remain for a shorter period.
The user can prevent the storage of cookies by setting their browser accordingly; in this case, however, it may happen that not all functions of the website will be fully usable. The user can prevent Google from collecting and processing the data generated by the cookies and relating to the user's use of the website – including the IP address – by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=hu
The Data Controller uses the Microsoft Clarity analytics service on its website for behavioural analytics. Clarity shows, by means of aggregated heatmaps and session replays, how visitors use the website (for example clicks, scrolling, pages viewed); the Data Controller uses the information thus obtained exclusively to develop the website and to improve the user experience. By default, Clarity masks and anonymises the text content entered into forms (for example name, e-mail address, telephone number), so that it is not recorded in the session recordings. During the use of the service, Microsoft may place cookies on the device of the visitor (for example: _clck, _clsk, CLID, ANONCHK, MR, MUID, SM), which serve to distinguish visitor sessions and to operate the service.
Further information about the data processing of Microsoft Clarity and about the Microsoft privacy statement: https://privacy.microsoft.com/hu-hu/privacystatement
The Data Controller also uses the web measurement code of Metricool (Metricool Software, S.L., Spain) to measure the traffic of the website. The Metricool code does not place cookies and does not store data on the visitor's device; it transmits the address of the page viewed, the referring page, the size of the browser window and the visitor's IP address to the Metricool server, where aggregated traffic statistics are compiled from them. The Data Controller uses the data obtained in this way solely to understand the traffic of the website and the effect of its social media channels. Further information about the data processing of Metricool: https://metricool.com/privacy-policy/
The Data Controller runs so-called remarketing advertisements through the advertising systems of Facebook and Google AdWords. These service providers may collect or receive data from the website of the Data Controller and from other internet locations by using cookies, web beacons and similar technologies. By using this data they provide measurement services and target advertisements. The advertisements targeted in this way may appear on further websites belonging to the partner network of Facebook and Google. The remarketing lists do not contain the name or the contact details of the data subject, but the identifiers they contain can be linked indirectly to the data subject and therefore qualify as personal data.
The Data Controller uses cookies in order to display personalised advertisements to potential users via Google and Facebook.
Further information about the privacy policies of Google and Facebook can be read at the following addresses: https://policies.google.com/privacy and https://www.facebook.com/about/privacy/
Consent is handled as follows. The measurement code of Google is downloaded when the website loads, but in accordance with the Google Consent Mode it operates in a disabled state for as long as the data subject has not given consent on the banner: in the absence of consent no analytics or advertising cookie is placed, and the IP address is processed in anonymised form. The code of Microsoft Clarity is loaded only if the data subject has consented to analytics cookies, and the measurement code of Meta (Facebook) only if the data subject has consented to advertising cookies.
The Data Controller also reports the number of enquiries back to the advertising systems in order to learn which of its advertisements are effective. This happens in two ways: through events sent from the browser, and, in the case of Meta, through an event sent from the server of the Data Controller, which also contains the IP address and the browser identifier of the data subject — the latter exclusively where the data subject has consented to advertising cookies. To Google Ads, the Data Controller reports back the click identifier received when the advertisement was clicked, in order to establish whether that click resulted in an enquiry. These reports do not contain the name or the contact details of the data subject, or the content of their message.
YouTube videos may be embedded on certain subpages of the website of the Data Controller. When the playback of an embedded video is started, the operator of YouTube (Google Ireland Limited) may place cookies on the device of the visitor and may collect data in connection with the viewing of the video; without starting the video, such data collection typically does not take place. Further information is available in the privacy policy of Google: https://policies.google.com/privacy
IX. Security of the processing
Taking into account the state of the art and the costs of implementation, as well as the nature, scope, context and purposes of the processing and the risk of varying likelihood and severity for the rights and freedoms of natural persons, the data controller and the data processor implement appropriate technical and organisational measures in order to ensure a level of data security appropriate to the risk, including inter alia, as appropriate:
- the encryption of personal data;
- ensuring the ongoing confidentiality, integrity, availability and resilience of the systems and services used for processing personal data;
- the ability to restore access to personal data and the availability of the data in a timely manner in the event of a physical or technical incident;
- a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures taken to ensure the security of the processing.
Communication of a personal data breach to the data subject:
- Where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the data controller shall inform the data subject of the personal data breach without undue delay.
- The information given to the data subject must describe, in clear and plain language, the nature of the personal data breach, and must communicate the name and contact details of the data protection officer or of the other contact point providing further information; it must describe the likely consequences arising from the personal data breach; it must describe the measures taken or planned by the data controller to address the personal data breach, including, where appropriate, measures aimed at mitigating the possible adverse consequences arising from the personal data breach.
The data subject does not have to be informed if any of the following conditions is met:
- the data controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the data affected by the personal data breach, in particular those measures – such as the use of encryption – which render the data unintelligible to persons not authorised to access the personal data;
- following the personal data breach, the data controller has taken further measures which ensure that the high risk to the rights and freedoms of the data subject is no longer likely to materialise;
- the information would require disproportionate effort. In such cases, the data subjects must be informed by means of publicly disclosed information, or a similar measure must be taken which ensures that the data subjects are informed in an equally effective manner.
If the data controller has not yet notified the data subject of the personal data breach, the supervisory authority, having considered whether the personal data breach is likely to result in a high risk, may order that the data subject be informed.
X. Data protection officer
No data protection officer has been designated. This is because the Data Controller does not qualify as a public authority or as a body performing a public task, its activities do not include any operation which requires regular and systematic monitoring of users on a large scale, and furthermore the Data Controller does not process special categories of data, nor personal data relating to decisions establishing criminal liability and to criminal offences, and therefore the Data Controller is not obliged to designate a data protection officer.
XI. The rights of data subjects in relation to data processing
The right of access
The data subject may request information as to whether the processing of their personal data is ongoing, and if so, which of their personal data the Data Controller processes, on what legal basis, for what processing purpose, from what source and for how long. Upon such a request the Data Controller shall send information without delay, but within 30 (thirty) days at the latest, to the e-mail contact address provided – or to the postal address requested by the data subject. The Data Controller provides the information in a concise, transparent, intelligibly worded and clear form.
The right to rectification
The data subject may request the Data Controller to rectify or modify any of their data, or to complete incomplete data. The Data Controller shall act on a request to that effect without delay, but within 30 (thirty) days at the latest, and shall send information to the e-mail contact address provided – or to the postal address requested by the data subject – on the fact that the modification of the data has taken place.
The right to erasure
The data subject may request the erasure of the data relating to them. If the data subject withdraws their consent in respect of the data processed on the legal basis of consent, the personal data processed shall be erased. The Data Controller shall arrange for the erasure of the data without delay, but within 30 (thirty) days at the latest, and shall send information to the e-mail contact address provided – or to the postal address requested by the data subject – on the fact that the erasure of the data has taken place.
We shall furthermore erase the personal data of the data subject if their processing is unlawful, if the purpose of the processing has ceased, if they are incomplete or incorrect and this condition cannot lawfully be corrected – provided that erasure is not precluded by law – or if the time limit laid down by law for the storage of the personal data has expired, or if erasure has been ordered by a court or by the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH, the Hungarian National Authority for Data Protection and Freedom of Information).
The right to restriction of processing
The data subject may request the data controller to restrict the processing where one of the following applies:
- the data subject contests the accuracy of the personal data, in which case the restriction applies for a period enabling the data controller to verify the accuracy of the personal data;
- the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead;
- the data controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims;
- the data subject has objected to the processing, in which case the restriction applies for the period until it is established whether the legitimate grounds of the data controller override the legitimate grounds of the data subject.
The right to data portability
The data subject has the right to receive the personal data concerning them, which they have provided to the Data Controller, in a structured, widely used, machine-readable format, and to transmit those data to another data controller.
The right to object
The data subject has the right to object to the processing. The Data Controller shall examine the objection within the shortest possible time from the submission of the request, but within 15 days at the latest, and shall take a decision on the question of whether it is well founded. It shall send information on its decision to the person submitting the request to the e-mail contact address – or to the postal address requested by the data subject.
XII. Legal remedies available in relation to data processing
In the event of an infringement of their rights, the data subject may bring court proceedings against the Data Controller or against its activities. The court shall deal with the case out of turn. The adjudication of the case falls within the competence of the törvényszék (regional court). The court shall proceed out of turn. The court with venue for the proceedings is the court of the place of the registered office of the data controller, however, the proceedings may – at the choice of the data subject – also be brought before the törvényszék of the place of residence or place of stay of the data subject.
The data subject may lodge a complaint with the Nemzeti Adatvédelmi és Információszabadság Hatóság against the Data Controller or against the data processing. The contact details of the Office are as follows:
| Nemzeti Adatvédelmi és Információszabadság Hatóság | |
|---|---|
| Registered office: | 1125 Budapest, Szilágyi Erzsébet fasor 22/C. |
| Postal address: | 1530 Budapest, Pf.: 5. |
| E-mail: | ugyfelszolgalat@naih.hu |
| Website: | http://www.naih.hu |
| Telephone: | 06 (1) 391-1400 |
| Fax: | 06 (1) 391-1410 |
