Privacy Policy
PRIVACY POLICY
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: the Regulation) requires that the company, as data controller, take appropriate measures to provide the data subject with any information relating to the processing of personal data in a concise, transparent, intelligible and easily accessible form, using clear and plain language, and to facilitate the exercise of the data subject's rights.
Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information also requires the prior notification obligation of the data subject.
With the following notice we fulfil this statutory obligation. The terms used in this notice are to be understood as defined in the Regulation; for matters not regulated herein, the provisions of the Regulation shall apply.
This notice must be published on the company's website or otherwise made available to and delivered to the data subject. For data processing not covered by this notice, information is provided at the time the data is collected.
This notice contains data relating to the data controller and the data processor, the legal bases and purposes of the processing, your possible rights and the means of exercising them, as well as the data security measures applied.
INFORMATION ON THE DATA CONTROLLER
Name of the data controller: Kormorán Öko Kft.
Registered seat: 9932 Viszák, Fő utca 137.
Company registration number: 18-09-112703
Represented by: Tibor Halas, managing director
E-mail: halas.tibor@kormoran.hu, phone: 30/9395 395
(hereinafter: the Company)
The data controller's data protection officer:
dr. Gergely Kozma
e-mail: info@adatorom.hu
THE COMPANY'S DATA PROCESSORS
Data processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller; (Regulation, Article 4(8))
We also transfer personal data to the following data processors so that they process it for us in accordance with our instructions and our data protection policy, in line with all further relevant confidentiality and security measures.
Prior consent from the data subject is not required to engage a data processor, but notification is required. Accordingly, we provide the following information:
1. Postal services, delivery, parcel shipping
These data processors receive from our company the personal data necessary for the delivery of the ordered product (the data subject's name, address, phone number), and use it to deliver the product.
Name of the data processor:
Name: Magyar Posta Zrt.
Registered seat: 1138 Budapest, Dunavirág utca 2-6.
Company registration number: 01-10-042463
Tax number: 10901232-2-44
2. The company's accountant
Our company uses a data processor for tax, accounting and payroll tasks, and transfers data to it under a data processing agreement.
Name of the data processor:
Company name: Könyvelés Plusz Kft.
Registered seat: 8000 Székesfehérvár, Surányi utca 19.
PRINCIPLES OF DATA PROCESSING
Personal data may only be processed for a specified purpose, for the exercise of a right and the performance of an obligation. Processing must comply with this purpose at every stage.
Only personal data that is indispensable for achieving the purpose of the processing, suitable for achieving that purpose, and processed only to the extent and for the duration necessary to achieve the purpose, may be processed.
Personal data may only be processed with consent based on proper information.
The data subject must be informed – clearly, intelligibly and in detail – of all facts relating to the processing of their data, in particular the purpose and legal basis of the processing, the identity of the person authorised to carry out the processing and the data processing, the duration of the processing, and who may access the data. The information must also cover the data subject's rights in connection with the processing and their remedies.
The personal data processed must meet the following requirements:
- their collection and processing must be fair and lawful;
- they must be accurate, complete and up to date;
- the manner of their storage must be such that the data subject can only be identified for as long as necessary for the purpose of storage.
Personal data may only be transferred, and different processing operations may only be linked, if the data subject has consented to it, or the law permits it, and if the conditions of processing are met for each individual item of personal data.
Personal data may only be transferred to a controller or processor located in a third country if the data subject has expressly consented, or the law allows it, and an adequate level of protection of personal data is ensured in the third country. Data transfers to EEA states are considered domestic data transfers.
LEGAL BASIS AND PURPOSE OF THE PROCESSING
1. Processing based on the data subject's consent
In the case of consent-based processing, the company requests the data subject's consent to the processing of their personal data with the content and information set out in the consent statement specified in the data processing policy.
Consent covers all processing activities carried out for the same purpose or purposes. If the processing serves several purposes at the same time, consent must be given for all of the processing purposes.
Where the data subject gives consent in the context of a written declaration which also concerns other matters – e.g. the conclusion of a sales or service contract – the request for consent must be presented in a manner clearly distinguishable from those other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such a declaration containing the data subject's consent which infringes the Regulation shall not be binding.
The company may not make the conclusion or performance of a contract conditional on consent to the processing of personal data that is not necessary for the performance of the contract.
Withdrawing consent must be made as easy as giving it.
Where personal data was collected with the data subject's consent, in the absence of a provision to the contrary in law, the controller may process the data collected, without further separate consent, for the purpose of complying with a legal obligation applicable to it, and also after the data subject has withdrawn their consent.
2. Processing based on compliance with a legal obligation
In the case of processing based on a legal obligation, the scope of data that may be processed, the purpose of the processing, the duration of data storage and the recipients are governed by the provisions of the underlying legislation.
Processing based on the legal ground of compliance with a legal obligation does not depend on the data subject's consent, since the processing is determined by law. In such a case, the data subject must be informed before the processing begins that the processing is mandatory, and must also be informed clearly and in detail, before the processing begins, of all facts relating to the processing of their data, in particular the purpose and legal basis of the processing, the identity of the person authorised to carry out the processing and the data processing, the duration of the processing, the fact that the controller processes the data subject's personal data on the basis of a legal obligation applicable to it, and who may access the data. The information must also cover the data subject's rights in connection with the processing and their remedies. In the case of mandatory processing, the information may be provided by publicly referring to the legal provisions containing the above information.
Please be informed that courts, the public prosecutor's office, investigating authorities, misdemeanour authorities, administrative bodies, and other bodies authorised by law (hereinafter: authority) may contact the company for the purpose of providing information, disclosing or transferring data, or making documents available.
The company discloses personal data to authorities – provided that the authority has indicated the exact purpose and the scope of the data – only to the extent and to the degree that is indispensably necessary to achieve the purpose of the request.
3. Processing based on legitimate interest
The company applies separate information regarding the camera surveillance it uses. In connection with its camera system, the controller has examined and assessed the legitimate interests of itself and third parties.
In the case of processing based on the legitimate interest of the company as employer, the controller has examined and assessed the legitimate interests of the controller and the employees. The company separately informs its employees about the processing at the time their employment begins.
4. Facilitating the exercise of the data subject's rights
The company ensures the exercise of the data subject's rights in the course of all of its processing activities. To exercise their rights, the data subject can contact the company at the contact details given in the section on the data controller.
The company informs the data subject of the measures taken in response to their request within one month of receiving the request.
Fulfilment of the request may be extended by a further two months. The data subject must be informed of the reasons for the extension within one month of receipt of the request.
If the company does not act on the request, it shall inform the data subject, at the latest within one month, of the reasons for not taking action, as well as of the right to lodge a complaint with the supervisory authority and to seek judicial remedy.
The data subject may exercise the rights set out in this notice free of charge. If the data subject's request is manifestly unfounded or – in particular because of its repetitive nature – excessive, the controller may charge a reasonable fee based on administrative costs, or may refuse to act on the request.
If the purposes for which the controller processes the personal data no longer require the identification of the data subject, the company is not obliged to maintain, acquire or process additional information in order to identify the data subject for the sole purpose of complying with this Regulation.
If the company is not in a position to identify the data subject, it shall inform them accordingly. In such a case the data subject may not exercise the right of access, rectification, erasure, restriction, the right to notification related to these, and the right to data portability, unless the data subject provides additional information enabling their identification in order to exercise their rights.
Where the company has reasonable doubts concerning the identity of a data subject exercising the right of access, rectification, erasure, restriction, the right to notification related to these, and the right to data portability, as well as the right to object, it may request the provision of additional information necessary to confirm the identity of the data subject, taking into account the foregoing paragraph.
5. Purpose of processing, data processed
The company carries out data processing for the following purposes:
Data suitable for reaching data subjects (such as e-mail address and phone number) is used exclusively for the purpose of contacting them, based on their consent. We will not send marketing messages in the future to the e-mail address provided by the data subject, and we do not use it for telemarketing or remarketing purposes.
In the case of processing related to invoicing, the company processes the name and billing address of the data subjects for the purpose of complying with a legal obligation applicable to the controller. The invoices may be forwarded to the accountant handling bookkeeping and tax matters. We keep the invoices for 8 years.
In the case of processing related to the conclusion of contracts (with suppliers, customers), the data subjects are informed of the purpose and legal basis of the processing and the duration of data storage in the contract itself.
As for contact persons named in contracts, since they are employed by the contracting parties, they are informed as part of the information provided by their employer.
In the case of customer service processing (correspondence, telephone contact), processing of contractual partners takes place on the legal basis of contract performance, or following contact based on the data subject's consent to the processing of their data. We process the data of customers recorded in the contract, the data of contact persons, and data provided on the basis of consent, in the case of a contract for the duration specified in the contract, and in the case of consent, until it is withdrawn.
In the case of CVs, the company acts in accordance with its data protection policy; the job advertisement publishes a notice that consent to the processing of data must be given as part of the application, in the absence of which the company destroys the CV. In the case of CVs received without a job advertisement, if they do not contain consent to the processing of the data for a period of 3 months, the company is only entitled to examine whether it has a vacant position matching the application material; if no such position is available, at the data subject's request the company returns the paper-based documentation and destroys the electronic documentation. The purpose of the processing is the selection and screening of the company's future employees and the continuous provision of staff.
INFORMATION ON THE RIGHTS OF THE DATA SUBJECT
Summary of the data subject's rights:
- Transparent information, communication and facilitation of the exercise of the data subject's rights
- Right to be informed in advance – where personal data is collected from the data subject
- Information to be provided to the data subject and information to be made available where the personal data has not been obtained from the data subject
- The data subject's right of access
- The right to rectification
- The right to erasure ("the right to be forgotten")
- The right to restriction of processing
- Notification obligation regarding rectification or erasure of personal data, or restriction of processing
- The right to data portability (not applicable)
- The right to object
- Automated individual decision-making, including profiling (not relevant in the case of the company)
- Restrictions
- Notification of the data subject regarding a personal data breach
- The right to lodge a complaint with a supervisory authority (right to administrative remedy)
- The right to an effective judicial remedy against a supervisory authority
- The right to an effective judicial remedy against a controller or processor
To exercise their rights, the data subject can contact the company at the contact details given in the section on the data controller.
The data subject's rights in detail:
1. Transparent information, communication and facilitation of the exercise of the data subject's rights under Article 12 of the Regulation
The controller must provide the data subject with all information relating to the processing of personal data and any notification in a concise, transparent, intelligible and easily accessible form, using clear and plain language, in particular for any information addressed specifically to a child. Information must be provided in writing or by other means, including, where appropriate, by electronic means. At the request of the data subject, information may also be provided orally, provided that the identity of the data subject is proven by other means.
The controller must facilitate the exercise of the data subject's rights, on which we have provided information above in a separate section of this notice.
2. Right to be informed in advance – where personal data is collected from the data subject, under Article 13 of the Regulation
The purpose of this notice is to ensure that data subjects are informed in advance about the processing, within the framework of which the data subject is entitled to receive information about the facts and information related to the processing before the processing begins. In this regard, the data subject must be informed of:
- the identity and contact details of the controller and its representative,
- the contact details of the data protection officer (where applicable),
- the purpose of the intended processing of the personal data, as well as the legal basis for the processing,
- in the case of processing based on legitimate interest, the legitimate interests pursued by the controller or a third party,
- the recipients of the personal data – with whom the personal data is shared – or categories of recipients, if any;
- where applicable, the fact that the controller intends to transfer the personal data to a third country or an international organisation.
In order to ensure fair and transparent processing, the controller must also inform the data subject of the following additional information:
- the period for which the personal data will be stored, or, if that is not possible, the criteria used to determine that period;
- the data subject's right to request from the controller access to, rectification or erasure of, or restriction of processing of, the personal data concerning them, and to object to the processing of such personal data, as well as the data subject's right to data portability;
- where the processing is based on the data subject's consent, the existence of the right to withdraw consent at any time, which does not affect the lawfulness of processing based on consent before its withdrawal;
- the right to lodge a complaint with a supervisory authority;
- whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, as well as whether the data subject is obliged to provide the personal data and the possible consequences of failure to provide such data;
- the existence of automated decision-making, including profiling, and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
Where the controller intends to further process the personal data for a purpose other than that for which it was collected, the controller shall, prior to that further processing, provide the data subject with information on that other purpose and all relevant additional information.
3. Information to be provided to the data subject and information to be made available where the personal data has not been obtained from the data subject, under Article 14 of the Regulation
Where the controller has not obtained the personal data from the data subject, the controller must provide the data subject with the information referred to in point 2 above and information about the categories of personal data concerned, as well as the source of the personal data and, where applicable, whether the data originates from publicly accessible sources, at the latest within one month of obtaining the personal data; if the personal data is used for communication with the data subject, at the latest at the time of the first communication with the data subject; or if disclosure to another recipient is envisaged, at the latest when the personal data is first disclosed.
The further rules set out in point 2 above (right to be informed in advance) shall apply.
4. The data subject's right of access under Article 15 of the Regulation
Based on the right of access, the data subject is entitled to inquire with the controller and to receive confirmation as to whether or not personal data concerning them is being processed, and, if such processing is taking place, is entitled to receive information about the following:
- the purposes of the processing;
- the categories of personal data concerned;
- the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;
- where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
- the data subject's right to request from the controller rectification or erasure of, or restriction of processing of, the personal data concerning them, and to object to the processing of such personal data;
- the right to lodge a complaint with a supervisory authority;
- where the data has not been collected from the data subject, any available information as to its source;
- the existence of automated decision-making referred to in Article 22(1) and (4) of the GDPR, including profiling, and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject.
Where the data subject requests a copy of their own personal data, the controller shall provide it to them.
If the data subject submitted the request electronically, the company shall provide the information in electronic form, unless the data subject requests otherwise.
The company shall provide the copy of the personal data subject to processing to the data subject following their identification. The controller may charge a reasonable fee based on administrative costs for any further copies requested by the data subject.
The right to obtain a copy shall not adversely affect the rights and freedoms of others, so, for example, another person's personal data cannot be requested, except that a recording of a report made by telephone may be requested in its entirety.
5. The right to rectification under Article 16 of the Regulation
The data subject shall have the right to obtain from the controller, without undue delay, the rectification of inaccurate personal data concerning them, and shall have the right to request the completion of incomplete personal data, including by means of a supplementary statement. Any change of data, if it concerns identification data, must be verified.
Having regard to the purpose of the processing, the data subject shall also be entitled to request the completion of incomplete personal data, including by means of a supplementary statement.
6. The right to erasure ("the right to be forgotten") under Article 17 of the Regulation
The data subject shall have the right to obtain from the controller the erasure of personal data concerning them without undue delay, and the controller shall be obliged to erase personal data concerning the data subject without undue delay, where
- the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
- the data subject withdraws the consent on which the processing is based, and there is no other legal basis for the processing;
- the data subject objects to the processing, and there are no overriding legitimate grounds for the processing,
- the personal data have been unlawfully processed;
- the personal data must be erased for compliance with a legal obligation under Union or Member State law to which the controller is subject;
- the personal data have been collected in relation to the offer of information society services directly to a child.
The right to erasure shall not apply where processing is necessary
- for exercising the right of freedom of expression and information;
- for compliance with a legal obligation under Union or Member State law to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- for reasons of public interest in the area of public health;
- for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, insofar as the right to erasure is likely to render impossible or seriously impair the achievement of that processing; or
- for the establishment, exercise or defence of legal claims.
7. The right to restriction of processing under Article 18 of the Regulation
Where processing is restricted, such personal data may, with the exception of storage, only be processed with the data subject's consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State.
The data subject shall have the right to obtain from the controller restriction of processing in the following cases:
- the data subject contests the accuracy of the personal data, in which case the restriction shall apply for the period enabling the controller to verify the accuracy of the personal data;
- the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead;
- the controller no longer needs the personal data for the purposes of the processing, but the data subject requires them for the establishment, exercise or defence of legal claims.
The data subject must be informed in advance about the lifting of the restriction of processing.
8. Notification obligation regarding rectification or erasure of personal data, or restriction of processing, under Article 19 of the Regulation
The controller shall notify each recipient to whom personal data have been disclosed of any rectification, erasure or restriction of processing, unless this proves impossible or involves disproportionate effort. The controller shall inform the data subject about those recipients if the data subject requests it.
9. The right to data portability under Article 20 of the Regulation
The right to data portability: not applicable in the case of the company, because automated processing does not take place.
10. The right to object under Article 21 of the Regulation
The data subject shall have the right to object, at any time, on grounds relating to their particular situation, to the processing of personal data concerning them based on the performance of a task carried out in the public interest (Article 6(1)(e) of the Regulation) or on legitimate interest (Article 6(1)(f) of the Regulation), including profiling based on those provisions. This right may not be exercised in the case of processing based on the data subject's consent or on a legal obligation.
Following an objection, the controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.
Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to the processing of personal data concerning them for such marketing, including profiling, to the extent that it is related to such direct marketing. Where the data subject objects to the processing of personal data for direct marketing purposes, the personal data shall no longer be processed for such purposes.
The data subject's attention must be explicitly drawn to these rights at the latest at the time of the first communication with the data subject, and the related information must be presented clearly and separately from any other information.
The data subject may also exercise the right to object by automated means using technical specifications.
Where personal data are processed for scientific or historical research purposes or statistical purposes, the data subject shall have the right to object, on grounds relating to their particular situation, to the processing of personal data concerning them, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
11. Automated individual decision-making, including profiling, under Article 22 of the Regulation
The company does not carry out automated decision-making or profiling..
12. Restrictions under Article 23 of the Regulation
Union or Member State law applicable to the controller or processor may, through legislative measures, restrict the scope of the rights and obligations set out in this policy, provided that the restriction respects the essence of fundamental rights and freedoms.
13. Notification of the data subject regarding a personal data breach, under Article 34 of the Regulation
Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller must communicate the personal data breach to the data subject without undue delay. This communication must describe, in clear and plain language, the nature of the personal data breach and must contain at least the following:
- the name and contact details of the data protection officer or other contact point where more information can be obtained;
- a description of the likely consequences of the personal data breach;
- a description of the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
The data subject need not be informed if any of the following conditions are met:
- the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the data affected by the personal data breach, in particular measures – such as encryption – that render the data unintelligible to any person who is not authorised to access it;
- the controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of the data subject is no longer likely to materialise;
- it would involve disproportionate effort. In such cases, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.
14. The right to lodge a complaint with a supervisory authority (right to administrative remedy), under Article 77 of the Regulation
If you feel that you have been harmed in connection with the processing, to resolve the situation you can contact the company at the contact details given in the section on the data controller in order to exercise your rights.
You have the right to lodge a complaint with a supervisory authority – in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement – if, in your opinion, the processing of personal data relating to you infringes the Regulation. The supervisory authority with which the complaint has been lodged shall inform the complainant of the progress and the outcome of the complaint, including the possibility of a judicial remedy.
Contact details of the National Authority for Data Protection and Freedom of Information:
Postal address: 1530 Budapest, Pf.: 5.
Phone: +36 (1) 391-1400
E-mail: ugyfelszolgalat@naih.hu
Website:www.naih.hu
15. The right to an effective judicial remedy against a supervisory authority, under Article 78 of the Regulation
Without prejudice to any other administrative or non-judicial remedy, every natural and legal person shall have the right to an effective judicial remedy against a legally binding decision of a supervisory authority concerning them.
Without prejudice to any other administrative or non-judicial remedy, every data subject shall have the right to an effective judicial remedy where the competent supervisory authority does not handle a complaint or does not inform the data subject within three months on the progress or outcome of the complaint lodged.
Proceedings against a supervisory authority shall be brought before the courts of the Member State where the supervisory authority is established.
Where proceedings are brought against a decision of a supervisory authority which was preceded by an opinion or a decision of the Board in the consistency mechanism, the supervisory authority shall forward that opinion or decision to the court.
16. The right to an effective judicial remedy against a controller or processor, under Article 79 of the Regulation
Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority, every data subject shall have the right to an effective judicial remedy where they consider that their rights under this Regulation have been infringed as a result of the processing of their personal data in non-compliance with this Regulation.
Proceedings against a controller or a processor shall be brought before the courts of the Member State where the controller or processor has an establishment. Such proceedings may also be brought before the courts of the Member State where the data subject has their habitual residence, unless the controller or processor is a public authority of a Member State acting in the exercise of its public powers.
DATA SECURITY MEASURES
The company's computer systems and data storage locations are located on the IT equipment operated at its registered seat.
The company selects and operates the IT tools used for processing personal data in the course of providing its services in such a way that the data processed:
- is accessible to authorised persons;
- has adequate authenticity and authentication;
- has ensured integrity;
- is protected against unauthorised access.
The company ensures the security of processing through organisational and IT measures that provide a level of protection appropriate to the risks arising in connection with the processing.
During processing, the company preserves
- confidentiality, so that only those authorised to do so can access the data;
- integrity, so that the information and its processing are accurate and complete;
- availability, so that an authorised user can, when needed, actually access the desired information, and the related tools are available.
The company's IT system and network are protected against fraud, espionage and sabotage achievable by IT means, as well as against vandalism, fire and flood, and against computer viruses and intrusions. The operator ensures security through server-level and application-level protection procedures.
Please be informed that electronic messages transmitted over the internet are vulnerable to network threats that may lead to unfair activity, the contesting of a contract, or the disclosure or modification of information, against which the company takes every reasonable precaution. The systems are logged in order to record any security deviation and to provide evidence in the event of a security breach. System monitoring also allows the effectiveness of the precautions applied to be checked.
Legal notice:
The company's websites, and all images, graphics, logos, text content, data and information found on them, as well as their arrangement, are protected by copyright; it is prohibited to copy, store electronically or otherwise, reproduce, transfer, distribute, print or publish them, in whole or in part – beyond the extent required for their intended use – without the company's express prior written consent. Unauthorised use is against the law, and the company will initiate legal proceedings against it.
Dated, Viszák, 23 May 2018.