Data Privacy Policy

1. Introduction

This data privacy policy information has been prepared based on the Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, taking into account the content of Act CXII of 2011 on the right to informational self-determination and freedom of information. Service provider and data controller's name and contact details:

Name
Kövér Emese
Registered Office of the Service Provider: 9012 Győr, Hegyalja u. 44.
Tax Number
52584497 – 1 – 28
Email emese[kukac]parkapcsolatsegito.hu A szolgáltató / adatkezelő a weboldal működtetése során, az
oldalon személyek email címét kéri el abból a célból, hogy részükre
megfelelő szolgáltatást nyújthasson.

Data Privacy Policy

I handle personal data lawfully, fairly, and in a transparent manner for the data subject. The processing of personal data is carried out for specified, explicit, and legitimate purposes only. The purpose of the data processing is relevant, and the scope of the processed data is limited to what is necessary. I conduct the processing of personal data in a way that ensures the proper security of the personal data, including protection against unauthorised or unlawful processing, accidental loss, destruction, or damage, using appropriate technical or organisational measures. I apply the principles of data protection to any information related to an identified or identifiable natural person.

Definitions

GDPR (General Data Protection Regulation) is the European Union's new Data Protection Regulation.

data managementAny operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

data processorAny natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller; personal data: any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

data handlerThe natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

If the purposes and means of data processing are determined by Union or Member State law, the data controller or the specific criteria for its designation may also be provided for by Union or Member State law.

user consentthe user's 's voluntary, specific, informed, and unambiguous expression of will by which the data subject, through a statement or a clear affirmative action, indicates their consent to the processing of personal data concerning them.

data protection incidentData protection incident refers to a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.

recipient refers to a natural or legal person, public authority, agency or another body with whom or with which the personal data is communicated, regardless of whether they are a third party. Public authorities that may have access to personal data in the context of a specific investigation in accordance with Union or Member State law are not considered recipients; the processing of said data by these public authorities must comply with the applicable data protection rules in accordance with the purposes of the processing.

third party refers to a natural or legal person, public authority, agency or another body which is not the data subject, the data controller, the data processor, or persons who, under the direct authority of the data controller or data processor, are authorized to process personal data.

Data Handling Objectives

Appointment booking on the website

If the individual wishes to use this service on the website, it is necessary to provide the requested personal data. The individual is not always obliged to provide personal data (e.g., providing a phone number for an appointment is not mandatory unless the user requests a callback). However, it is not possible to use certain features of the website without providing personal data. For example, the free consultation only works by providing an email address so I can send the answer to the user.
Name
– Serves for identification and communication purposes: Email
– Serves for communication purposes: Phone
– Serves communication purposes.

The legal basis for data processing: The legal basis for data processing in the case of contacting us through the website is the performance of a contract. According to GDPR Article 6(1)(b). Booking an appointment on the website is not mandatory. You can also choose to contact us through other channels provided in our contact details. Thus, it is up to you to decide whether you choose this method of contact and consent to the processing of your personal data for this purpose.

5. Data Processing Security and Data Processors

The Service Provider, considering the current state of the art, provides protection for data processing security with technical, organizational, and procedural measures that offer an appropriate level of protection in relation to the risks associated with data processing. The computer systems and other data storage locations of the Service Provider are located at its headquarters, within the Service Provider's premises, and on storage/servers provided by a Hosting Service. Data Processors The Data Controller is entitled to use data processors to carry out its activities. Data processors do not make independent decisions and are only authorized to act based on the contract concluded with the Data Controller and the instructions received. The Data Controller monitors the work of the data processors. Data processors are only allowed to use additional data processors with the consent of the Data Controller.

Hosting Service Provider:
Versanus Kft., 1023 Budapest, Bécsi út 3-5. 5. em. 56.

6. Rights related to data processing:

6.1. Right to request information

You have the right to request information from us through the provided contact details about which of your data we process, on what legal basis, for what purpose of data processing, from what source, and for how long. Upon your request, we will provide information without delay, but within a maximum of 30 days, to the e-mail address you provided.

You have the right to request the correction of your inaccurate personal data

You have the right to request information from us through the provided contact details about which of your data we process, on what legal basis, for what purpose of data processing, from what source, and for how long. Upon your request, we will provide information without delay, but within a maximum of 30 days, to the e-mail address you provided.

6.3. The Right to Erasure

You can request the deletion of your data through the provided contact details. Upon your request, we will do this promptly, but within a maximum of 30 days, and we will send a notification to the email address you provided.

6.4. Right to restrict processing

You can request the restriction of your data through the provided contact details. The restriction lasts as long as the reason you specified requires the storage of the data. Upon your request, we will do this immediately, but within a maximum of 30 days, and we will send a notification to the e-mail address you provided. 6.5. Right to object

"You can object to the data processing through the provided contact details. We will examine the objection in the shortest time possible after the submission of the request, but within a maximum of 15 days, make a decision regarding its validity, and inform you of our decision via email.

7. Legal Remedies

The data subject may request information about the processing of their personal data and may request the correction of their personal data, or, with the exception of mandatory data processing, its deletion or blocking, in the manner indicated at the time of data collection or at the contact details of the data controller. The data controller shall provide the information in the shortest possible time from the submission of the request, but no later than 30 days, in an understandable form – in writing upon the data subject's request. This information is free of charge if the information requester has not previously submitted an information request to the data controller for the same set of data in the current year. Otherwise, the Service Provider may charge a fee. The Service Provider corrects personal data if it does not correspond to reality and the correct personal data is available to them. The Service Provider blocks personal data if requested by the data subject or if, based on available information, it can be assumed that deletion would violate the legitimate interests of the data subject. Blocked personal data can only be processed until the purpose of the data processing that prevented its deletion remains. The Service Provider marks personal data processed by them if its correctness or accuracy is disputed by the data subject, but its incorrectness or inaccuracy cannot be clearly determined. The Service Provider deletes personal data if its processing is illegal, requested by the data subject, the data processed is incomplete or incorrect – and this condition cannot legally be remedied – unless the law excludes deletion, the purpose of data processing has ceased, or the legally prescribed deadline for storing data has expired, or it was ordered by a court or the National Data Protection and Freedom of Information Authority. Personal data must be deleted, blocked, and corrected by the data controller within 30 days. If the data controller does not fulfill the data subject's request for correction, blocking, or deletion, they must communicate the reasons for the rejection in writing within 30 days. The Service Provider notifies the data subject about the correction, blocking, marking, and deletion, as well as all those to whom they previously transmitted the data for data processing purposes. Notification can be omitted if it does not violate the legitimate interest of the data subject in light of the purpose of data processing. The data subject may object to the processing of their personal data if: a) the processing or transmission of personal data is exclusively necessary to fulfill a legal obligation concerning the data controller or to enforce the legitimate interest of the data controller, the data recipient, or a third party, except when data processing is required by law; b) the use or transmission of personal data is for direct marketing, public opinion polling, or scientific research purposes; c) in other cases specified by law. The Service Provider examines the objection within the shortest possible time from the submission of the request but no later than 15 days, makes a decision on its justification, and informs the requester in writing. If the data controller determines that the data subject's objection is justified, it terminates data processing – including further data collection and data transfer – and blocks the data, and informs all those to whom the personal data affected by the objection was previously transmitted, and who are obliged to take measures to enforce the right to object. If the data subject disagrees with the decision of the data controller, they can turn to the court within 30 days of its notification. The data controller may not delete the data subject's data if its processing is prescribed by law. However, the data cannot be transferred to the data recipient if the data controller agrees with the objection or the court has established the legality of the objection. In the event of a violation of their rights, the data subject may turn to a court against the data controller. The court will act as a matter of priority in the matter. The Service Provider compensates for any damage caused to another person by the unlawful processing of the data subject's data or by violating the requirements of data security. The data controller is exempt from liability if the damage was caused by an unavoidable cause outside the scope of data processing. It does not compensate for the damage to the extent that it resulted from the deliberate or grossly negligent conduct of the injured party. You can use legal remedies or file a complaint with the National Data Protection and Freedom of Information Authority.

If, in your opinion, the lawful state cannot be restored, please notify the authority at the following contacts: National Authority for Data Protection and Freedom of Information Mailing address: 1530 Budapest, Pf.: 5. Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c Phone: +36 (1) 391-1400 Fax: +36 (1) 391-1410 E-mail: ugyfelszolgalat(at)naih.hu URL: https://naih.hu Legal basis for data processing: REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL (April 27, 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). Act CXII of 2011 on the right to informational self-determination and freedom of information." (Note: The "(at)" in the email is a representation of the "kukac" which is the Hungarian term for the "@" symbol in email addresses.)