Introduction

EnerLogic Advisory Kft. (2800 Tatabánya, Szent Borbála út 29. A. ép. Fsz. 1. ajtó, Hungary; tax number: 32906077-2-11; company registration number: 11-09-031811) (hereinafter: the “Service Provider”, “data controller”) carries out the data processing described in this notice as set out below.

We provide the following information in accordance with REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, “GDPR”).

This privacy notice governs the data processing of the following websites/mobile applications: https://www.deyenergie.com, https://www.deyenergie.hu

This privacy notice is available at: https://www.deyenergie.com/adatvedelem

Amendments to this notice take effect upon publication at the above address.

The data controller and its contact details

Name: EnerLogic Advisory Kft.

Registered office: 2800 Tatabánya, Szent Borbála út 29. A. ép. Fsz. 1. ajtó

E-mail: sales@deyenergie.com

Phone: +36 70 254 7485

Definitions

  1. “personal data”: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
  2. “processing”: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
  3. “controller”: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
  4. “processor”: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
  5. “recipient”: a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;
  6. “consent”: of the data subject: any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
  7. “personal data breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;
  8. “profiling”: any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
  9. “third party”: a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

Principles relating to the processing of personal data

Personal data shall be:

  1. processed lawfully, fairly and in a transparent manner in relation to the data subject (“lawfulness, fairness and transparency”);
  2. collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (“purpose limitation”);
  3. adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (“data minimisation”);
  4. accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (“accuracy”);
  5. kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1), subject to implementation of the appropriate technical and organisational measures required by the GDPR in order to safeguard the rights and freedoms of the data subject (“storage limitation”);
  6. processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (“integrity and confidentiality”).

The controller shall be responsible for, and be able to demonstrate, compliance with the above (“accountability”).

The controller declares that its data processing is carried out in accordance with the principles set out in this section.

1. Fact of data collection, scope of data processed, and purpose of processing:

Personal dataPurpose of processingLegal basis
UsernameIdentification, enabling registration.Consent of the data subject, Article 6(1)(a) GDPR.
PasswordSecure access to the user account.Consent of the data subject, Article 6(1)(a) GDPR.
First and last nameNecessary for contact, purchase, issuing a compliant invoice, and exercising the right of withdrawal.Performance of a contract, Article 6(1)(b) GDPR.
E-mail addressMaintaining contact.Performance of a contract, Article 6(1)(b) GDPR.
Phone numberMaintaining contact; more efficient coordination of billing or delivery questions.Performance of a contract, Article 6(1)(b) GDPR.
Billing name and addressIssuing a compliant invoice, as well as creating, defining the content of, modifying, and monitoring performance of the contract, invoicing fees arising from it, and enforcing related claims.Performance of a legal obligation, Article 6(1)(c) GDPR. (The legal obligation arises from Section 169(2) of Act C of 2000 on Accounting.)
Delivery name and addressEnabling home delivery.Performance of a contract, Article 6(1)(b) GDPR.
Date/time of purchase or registrationCarrying out a technical operation.Performance of a contract, Article 6(1)(b) GDPR.
IP address at the time of purchase/registrationCarrying out a technical operation.Performance of a contract, Article 6(1)(b) GDPR.

2. Scope of data subjects: All data subjects who register/purchase on the webshop website. Neither the username nor the e-mail address is required to contain personal data.

3. Duration of processing, deadline for erasure of data: If any of the conditions set out in Article 17(1) GDPR applies, processing continues until the data subject’s request for erasure. The controller informs the data subject electronically of the erasure of any personal data provided by the data subject, pursuant to Article 19 GDPR. If the data subject’s erasure request also covers the e-mail address provided by them, the controller will also erase the e-mail address following the notification — with the exception of accounting records, since these must be retained for 8 years under Section 169(2) of Act C of 2000 on Accounting. The data subject’s contractual data may be erased upon the data subject’s erasure request once the civil-law limitation period has expired.

Accounting source documents that directly or indirectly support bookkeeping entries (including general ledger accounts as well as analytical and detail records) must be kept in a legible form, retrievable by reference to the bookkeeping entries, for at least 8 years.

4. Description of data subjects’ rights regarding the processing: The data subject may request from the controller access to, rectification of, erasure of, or restriction of processing of personal data concerning them, and the data subject has the right to data portability and the right to withdraw consent at any time.

5. The data subject may initiate access to, erasure, modification, or restriction of processing of personal data, as well as data portability, in the following ways:

  • by post, at 2800 Tatabánya, Szent Borbála út 29. A. ép. Fsz. 1. ajtó,
  • by e-mail, at sales@deyenergie.com,
  • by phone, at +36 70 254 7485.

6. Please note that:

  • the processing is necessary for the performance of a contract and for providing a quotation.
  • you are obliged to provide the personal data so that we can fulfil your order.
  • failure to provide the data will result in our being unable to process your order.

Use of cookies

1. Prior consent from data subjects is not required for the use of so-called “password-protected session cookies”, “shopping-cart cookies”, “security cookies”, “strictly necessary cookies”, “functional cookies”, and “cookies responsible for managing website statistics”.

2. Fact of processing, scope of data processed: Unique identifier, dates, timestamps.

3. Scope of data subjects: All visitors to the website.

4. Purpose of processing: Identification of users, tracking visitors, ensuring customised operation.

5. Duration of processing, deadline for erasure of data:

Type of cookieLegal basis of processingDuration of processing
Session cookies, or other cookies strictly necessary for the operation of the websiteNo processing takes place through the use of this cookie.The period until the end of the relevant visitor session, i.e. it remains on the computer only until the browser is closed.
Statistical, marketing cookiesArticle 6(1)(a) GDPR1 day – 2 years, in accordance with the cookie notice, or until withdrawal of the data subject’s consent.

6. Description of data subjects’ rights regarding the processing: Data subjects may delete cookies under the Tools/Settings menu of their browser, generally under the Privacy settings.

7. Most browsers used by our users allow you to configure which cookies should be saved, and allow (specific) cookies to be deleted again. If you restrict the saving of cookies on certain websites or do not allow third-party cookies, under certain circumstances this may result in our website no longer being fully usable. Here you can find information on how to customise cookie settings for common browsers:

Use of Google Analytics

  1. This website uses Google Analytics, a web analytics service provided by Google Inc. (“Google”). Google Analytics uses so-called “cookies”, text files that are saved on your computer, to help analyse how the User uses the website visited.
  2. The information generated by cookies relating to the website used by the User is generally transferred to and stored on a Google server in the USA. By activating IP anonymisation on the website, Google first shortens the User’s IP address within the territory of EU Member States or other states party to the Agreement on the European Economic Area.
  3. The full IP address is only transmitted to a Google server in the USA and shortened there in exceptional cases. On behalf of the operator of this website, Google will use this information for the purpose of evaluating the User’s use of the website, compiling reports on website activity for the website operator, and providing other services relating to website and internet usage.
  4. Within the framework of Google Analytics, the IP address transmitted by the User’s browser is not merged with other data held by Google. The User may prevent the storage of cookies through the appropriate settings of their browser; however, please note that in this case it is possible that not every function of this website will be fully usable. You may further prevent Google from collecting and processing data generated by cookies relating to your use of the website (including your IP address) by downloading and installing the browser plug-in available at the following link. https://tools.google.com/dlpage/gaoptout?hl=en

1. Pursuant to Section 6 of Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions of Economic Advertising Activities, unless a separate statute provides otherwise, advertising may only be communicated to a natural person — the User — as the addressee of the advertisement by way of direct contact (hereinafter: “direct marketing”), in particular by electronic mail or other individual means of communication of equivalent effect, if the addressee of the advertisement has given their prior, explicit and unambiguous consent.

2. Furthermore, having regard to the provisions of this notice, the User may consent to the Service Provider processing their personal data necessary for sending promotional offers.

3. The Service Provider does not send unsolicited promotional messages, and the User may unsubscribe from receiving offers free of charge and without restriction or justification at any time. In this case, the Service Provider will erase from its records all personal data necessary for sending promotional messages and will not contact the User with further promotional offers. The User may unsubscribe from promotional messages by clicking the link contained in the message.

4. Fact of data collection, scope of data processed, and purpose of processing:

Personal dataPurpose of processingLegal basis
Name, e-mail addressIdentification, enabling subscription to the newsletter/promotional coupons.Consent of the data subject, Article 6(1)(a) GDPR.
Date/time of subscriptionCarrying out a technical operation.Consent of the data subject, Article 6(1)(a) GDPR.
IP address at time of subscriptionCarrying out a technical operation.Consent of the data subject, Article 6(1)(a) GDPR.

5. Newsletters are sent in accordance with the provisions of Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions of Economic Advertising Activities.

6. Scope of data subjects: All data subjects who subscribe to the newsletter.

7. Purpose of processing: Sending electronic messages containing advertising (e-mail, SMS, push notification) to the data subject; providing information on current news, products, promotions, new features, etc.

8. Duration of processing, deadline for erasure of data: Until withdrawal of consent (unsubscription, the data subject’s erasure request), or until the newsletter is discontinued.

9. Description of data subjects’ rights regarding the processing:

  • The data subject may request from the controller access to, rectification of, erasure of, or restriction of processing of personal data concerning them, and
  • the data subject has the right to data portability and the right to withdraw consent at any time.

10. The data subject may initiate access to, erasure, modification, or restriction of processing of personal data, as well as data portability, in the following ways:

  • by post, at 2800 Tatabánya, Szent Borbála út 29. A. ép. Fsz. 1. ajtó,
  • by e-mail, at sales@deyenergie.com,
  • by phone, at +36 70 254 7485.

11. The data subject may unsubscribe from the newsletter at any time, free of charge.

12. Please note that:

  • the processing is based on your consent.
  • you are obliged to provide the personal data if you wish to receive a newsletter from us.
  • failure to provide the data will result in our being unable to send you a newsletter.
  • you may withdraw your consent at any time by clicking the unsubscribe link.
  • withdrawal of consent does not affect the lawfulness of processing based on consent carried out before the withdrawal.

Complaint handling

1. Fact of data collection, scope of data processed, and purpose of processing:

Personal dataPurpose of processingLegal basis
First and last nameIdentification, maintaining contact.Performance of a legal obligation, Article 6(1)(c) GDPR. (The relevant legal obligation: Section 17/A(7) of Act CLV of 1997 on Consumer Protection.)
E-mail addressMaintaining contact.Performance of a legal obligation, Article 6(1)(c) GDPR. (The relevant legal obligation: Section 17/A(7) of Act CLV of 1997 on Consumer Protection.)
Phone numberMaintaining contact.Performance of a legal obligation, Article 6(1)(c) GDPR. (The relevant legal obligation: Section 17/A(7) of Act CLV of 1997 on Consumer Protection.)
Billing name and addressIdentification; handling quality complaints, questions and problems arising in connection with the ordered products/services.Performance of a legal obligation, Article 6(1)(c) GDPR. (The relevant legal obligation: Section 17/A(7) of Act CLV of 1997 on Consumer Protection.)

2. Scope of data subjects: All data subjects who make a purchase on the website and raise a quality complaint or lodge a complaint.

3. Duration of processing, deadline for erasure of data: Copies of the record taken of the complaint, the transcript, and the response given to it must be retained for 3 years pursuant to Section 17/A(7) of Act CLV of 1997 on Consumer Protection.

4. Description of data subjects’ rights regarding the processing: The data subject may request from the controller access to, rectification of, erasure of, or restriction of processing of personal data concerning them, and the data subject has the right to data portability and the right to withdraw consent at any time.

5. The data subject may initiate access to, erasure, modification, or restriction of processing of personal data, as well as data portability, in the following ways:

  • by post, at 2800 Tatabánya, Szent Borbála út 29. A. ép. Fsz. 1. ajtó,
  • by e-mail, at sales@deyenergie.com,
  • by phone, at +36 70 254 7485.

6. Please note that:

  • the provision of personal data is based on a legal obligation.
  • the processing of personal data is a precondition for the conclusion of the contract.
  • you are obliged to provide the personal data so that we can handle your complaint.
  • failure to provide the data will result in our being unable to handle the complaint received from you.

Recipients with whom personal data are shared

“recipient”: a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not.

1. Processors (who process data on behalf of the controller)

The controller uses processors in order to facilitate its own data processing activities, and to fulfil its obligations under the contract concluded with the data subject and under applicable law.

The controller places great emphasis on engaging only those processors that provide sufficient guarantees to implement appropriate technical and organisational measures ensuring compliance with the requirements of the GDPR and the protection of the rights of data subjects.

The processor, and any person acting under the authority of the controller or the processor who has access to personal data, processes the personal data covered by this notice solely in accordance with the controller’s instructions.

The controller bears legal responsibility for the activities of the processor. The processor is only liable for damage caused by the processing if it has not complied with the obligations under the GDPR specifically imposed on processors, or if it has disregarded, or acted contrary to, the lawful instructions of the controller.

The processor has no substantive decision-making authority regarding the processing of the data.

The controller may engage a hosting provider to provide the IT infrastructure, and a courier service to deliver the ordered products, as processors.

2. Individual processors

Processing activityName, address, contact details
Hosting servicesDiMa.hu Kereskedelmi és Szolgáltató Kft.
4032 Debrecen, Békessy Béla u. 9. Building C, 3rd floor, Door 10
Phone: +36 52 322 121
E-mail: info@dima.hu
Other processor (e.g. online invoicing, web development, marketing)Online invoicing: Billingo
Billingo Technologies Zrt.
Registered office: 1133 Budapest, Árbóc utca 6. 3rd floor
E-mail: hello@billingo.hu

“third party”: a natural or legal person, public authority, agency or other body other than the data subject, the controller, the processor, or the persons who, under the direct authority of the controller or processor, are authorised to process personal data.

3. Transfer of data to third parties

Third-party controllers process the personal data we disclose to them in their own name and in accordance with their own privacy policy.

Controller’s activityName, address, contact details
Shipping / courierGLS General Logistics Systems Hungary Csomag-Logisztikai Kft.
2351 Alsónémedi, Európa u. 2.
info@gls-hungary.com
Phone: 06-29-88-66-94

MPL Magyar Posta Logisztika Kft.
1138 Budapest, Dunavirág utca 2-6.
ugyfelszolgalat@posta.hu
Phone: (06-1) 767-82-82
Terms & Conditions: https://www.posta.hu/ugyfelszolgalat/aszf
Privacy notice: https://www.posta.hu/adatkezelesi_tajekoztato
Online paymentSimplePay Zrt.
Registered office: 1138 Budapest, Váci út 135-139. Building B, 5th floor
E-mail: ugyfelszolgalat@simple.hu
Phone: +36 1/20/30/70 3-666-611

Social media platforms

The controller is also present on social media platforms in order to present its services and to maintain contact with interested parties and customers.

Scope of data processed: Data publicly available on the data subject’s social media profile, in particular:

  • name (username)
  • public profile picture
  • content published by the data subject and/or interactions related to the controller’s page (e.g. comments, messages).

Scope of data subjects: Natural persons who follow, interact with, or send messages through the controller’s social media page.

Purpose of processing:

  • presenting the controller’s activities and services,
  • marketing and communication on social media platforms,
  • maintaining contact with interested parties and customers.

Legal basis of processing: The data subject’s voluntary consent to the processing of their personal data on the social media platform.

Duration of processing: Processing continues for as long as the data subject’s interaction persists, or until the content published by the data subject is deleted. The controller retains messages and communications for a maximum of 2 years.

Further controllers: Social media platforms process users’ data as independent controllers, in accordance with their own privacy policies.

Facebook / Meta joint controllership

The controller maintains a Facebook / Meta profile in connection with its activities. The statistical processing carried out on the Facebook platform constitutes joint controllership between the controller and Facebook Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, D2 Dublin, Ireland). Detailed information on the joint controllership arrangement is provided in the data controller addendum to the Facebook Page Insights feature. The addendum is available at the following link: https://www.facebook.com/legal/terms/page_controller_addendum

The controller communicates via private message on the social media platform only if you contact us there.

1. Categories of data subjects

  • a data subject who has registered on the social media platform and has “liked” the controller’s profile page,
  • a data subject who contacts the controller via private message on the social media platform.

2. Purpose of processing

The purpose of the processing is to share and promote the controller’s activities and services on the Facebook platform. The controller may use data provided by the data subject in a private message in order to respond to that message; otherwise, the controller does not collect or extract data from the social media platform.

3. Legal basis of processing

The processing is based on Article 6(1)(a) GDPR; the legal basis of the processing is the data subject’s consent to the processing of their personal data on the Facebook platform.

4. Scope of data processed

  • the data subject’s registered name,
  • the data subject’s public profile picture,
  • other public data provided or shared by the data subject on the social media platform.

5. Source of the personal data processed

The source of the data processed is the data subject.

6. Withdrawal of consent

You may withdraw your consent to the processing at any time, and may delete your post or comment. The processing takes place via the social media platforms, which are operated by a third party. If you withdraw your consent, the controller will delete its conversation with you. Withdrawal of consent does not affect the lawfulness of processing based on consent carried out before the withdrawal.

The data subject may initiate access to, erasure, modification, or restriction of processing of personal data, as well as data portability, in the following ways:

  • by post, at 2800 Tatabánya, Szent Borbála út 29. A. ép. Fsz. 1. ajtó,
  • by e-mail, at sales@deyenergie.com,
  • by phone, at +36 70 254 7485.

7. Duration of processing

  • until withdrawal of the data subject’s consent;
  • where an exchange of messages takes place, 2 years.

8. Transfer, recipients, and categories of recipients of personal data

For the concept of “recipient”, see Article 4(9) GDPR. The controller discloses the data subject’s personal data to state bodies and authorities — in particular courts, prosecution services, investigating authorities and authorities responsible for regulatory offences, and the National Authority for Data Protection and Freedom of Information — only in exceptional cases and on the basis of a statutory obligation.

9. Possible consequences of failing to provide data

If you do not provide the data, the data subject will not be able to obtain information about the controller’s activities and services via the Facebook platform, or send a message to the controller via Facebook Messenger.

10. Automated decision-making (including profiling)

No automated decision-making, including profiling, takes place in the course of this processing.

11. Joint controllership agreement concluded with Facebook Ireland Ltd.

The Page Insights feature displays aggregated data that helps to illustrate how data subjects use the Facebook page. Facebook Ireland Limited (“Facebook Ireland”) and the controller are joint controllers with regard to the processing of insights data. The Page Insights addendum sets out Facebook’s responsibilities and the controller’s responsibilities in connection with the processing of insights data. Facebook Ireland undertakes primary responsibility under the GDPR for the processing of insights data, and undertakes to comply with all relevant obligations under the GDPR in connection with the processing of insights data. Facebook Ireland also makes a summary of the Page Insights addendum available to every data subject. The controller ensures that it has an appropriate legal basis under the GDPR for processing insights data, identifies the controller of the page, and complies with all other applicable legal obligations. Facebook Ireland bears sole responsibility for the processing of personal data in connection with the Page Insights feature, except for data falling within the scope of the Page Insights addendum. The Page Insights addendum does not grant the controller any right to request the personal data of Facebook users that Facebook Ireland processes in connection with Facebook, including page-insights data. The controller may not act on behalf of Facebook Ireland, and may not respond, when fulfilling data protection requests.

Customer relations and other data processing

  1. If a question arises, or the data subject experiences a problem, in connection with the use of the controller’s services, the data subject may contact the controller via the methods indicated on the website (phone, e-mail, social media platforms, etc.).
  2. The controller erases incoming e-mails, messages, and data provided by phone, via Meta, etc., together with the inquirer’s name and e-mail address and any other personal data voluntarily provided, no later than 2 years after the data were communicated.
  3. We provide notice of any processing not listed in this notice at the time the data are collected.
  4. In the case of an exceptional request from an authority, or a request from another body authorised by law, the Service Provider is obliged to provide information, disclose or transfer data, or make documents available.
  5. In such cases, the Service Provider discloses to the requesting party — provided that the precise purpose and scope of the data has been specified — only as much personal data, and only to the extent, that is strictly necessary to achieve the purpose of the request.

Rights of data subjects

1. Right of access

You have the right to obtain from the controller confirmation as to whether or not personal data concerning you are being processed, and, where that is the case, access to the personal data and the information listed in the Regulation.

2. Right to rectification

You have the right to obtain from the controller, without undue delay, the rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

3. Right to erasure

You have the right to obtain from the controller the erasure of personal data concerning you without undue delay, and the controller is obliged to erase personal data concerning you without undue delay where certain specified conditions apply.

4. Right to be forgotten

Where the controller has made the personal data public and is obliged to erase it, the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform the controllers which are processing the personal data that you have requested the erasure by such controllers of any links to, or copies or replications of, those personal data.

5. Right to restriction of processing

You have the right to obtain from the controller restriction of processing where one of the following applies:

  • you contest the accuracy of the personal data, for a period enabling the controller to verify the accuracy of the personal data;
  • the processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead;
  • the controller no longer needs the personal data for the purposes of the processing, but they are required by you for the establishment, exercise or defence of legal claims;
  • you have objected to processing; in this case the restriction applies for the period pending verification whether the controller’s legitimate grounds override your legitimate grounds.

6. Right to data portability

You have the right to receive the personal data concerning you, which you have provided to a controller, in a structured, commonly used and machine-readable format, and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided (…)

7. Right to object

In the case of processing based on legitimate interest or on the exercise of public authority as a legal basis, you have the right to object, on grounds relating to your particular situation, at any time, to the processing of personal data concerning you (…), including profiling based on those provisions.

8. Objection in the case of direct marketing

Where personal data are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing, including profiling to the extent that it is related to such direct marketing. Where you object to processing of personal data for direct marketing purposes, the personal data shall no longer be processed for such purposes.

9. Automated individual decision-making, including profiling

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

The preceding paragraph does not apply if the decision:

  • is necessary for entering into, or performance of, a contract between you and the controller;
  • is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard your rights and freedoms and legitimate interests; or
  • is based on your explicit consent.

Response deadline

The controller shall, without undue delay and in any event within one month of receipt of the request, inform you of the action taken on the above requests.

Where necessary, this period may be extended by a further two months. The controller shall inform you of any such extension, together with the reasons for the delay, within one month of receipt of the request.

If the controller does not take action on your request, it shall, without delay and at the latest within one month of receipt of the request, inform you of the reasons for not taking action and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.

Security of processing

The controller and the processor, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including, among other things, as appropriate:

  1. the pseudonymisation and encryption of personal data;
  2. the ability to ensure the ongoing confidentiality, integrity, availability and resilience of systems and services used for the processing of personal data;
  3. the ability to restore the availability of, and access to, personal data in a timely manner in the event of a physical or technical incident;
  4. a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures adopted to ensure the security of the processing.
  5. The data processed shall be stored in such a way that unauthorised persons cannot access them. For paper-based data carriers, by establishing rules for physical storage and filing; for electronic data, by applying a central access-rights management system.
  6. The method of electronic storage of the data shall be chosen so that erasure — also having regard to possibly differing erasure deadlines — can be carried out when the erasure deadline expires or when otherwise necessary. Erasure must be irreversible.
  7. Paper-based data carriers must be stripped of personal data using a document shredder, or by engaging an external organisation specialising in document destruction. For electronic data carriers, physical destruction must be carried out in accordance with the rules applicable to the decommissioning of electronic data carriers, and, where necessary, preceded by secure and irreversible erasure of the data.
  8. The controller implements the following specific data security measures:

To ensure the security of personal data processed on paper, the Service Provider applies the following measures (physical protection):

  1. Documents are kept in a secure, lockable, dry room.
  2. If personal data processed on paper are digitised, the rules applicable to digitally stored documents shall apply.
  3. In the course of their work, the Service Provider’s staff member carrying out the processing may only leave the room in which processing is taking place if they lock away the data carriers entrusted to them, or lock the room in question.
  4. Personal data may only be accessed by persons authorised to do so; third parties may not access them.
  5. The Service Provider’s building and premises are equipped with fire-protection and security equipment.

IT protection

  1. The computers and mobile devices (and other data carriers) used in the course of processing are the property of the Service Provider.
  2. The computer system containing personal data used by the Service Provider is equipped with anti-virus protection.
  3. To ensure the security of digitally stored data, the Service Provider performs backups and archiving.
  4. Only persons with appropriate authorisation, and only those specifically designated, may access the central server.
  5. Data held on computers may only be accessed using a username and password.

Notification of a personal data breach to the data subject

Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.

The communication to the data subject shall describe in clear and plain language the nature of the personal data breach, and shall include the name and contact details of the data protection officer or other contact point from which more information can be obtained; it shall describe the likely consequences of the personal data breach; and it shall describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.

Communication to the data subject is not required if any of the following conditions are met:

  • the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those measures — such as encryption — that render the data unintelligible to any person who is not authorised to access them;
  • the controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects is no longer likely to materialise;
  • it would involve disproportionate effort. In such cases, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.

Where the controller has not already notified the data subject of the personal data breach, the supervisory authority, having considered the likelihood of the personal data breach resulting in a high risk, may require it to do so.

Notification of a personal data breach to the supervisory authority

The controller shall, without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent under Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification is not made within 72 hours, it shall be accompanied by reasons for the delay.

Review in the case of mandatory data processing

Where the duration of mandatory data processing, or the periodic review of its necessity, is not determined by statute, a local government decree, or a binding legal act of the European Union, the controller shall review, at least once every three years from the commencement of the processing, whether the processing of personal data carried out by it, or by a processor acting on its instructions or on its behalf, is necessary to achieve the purpose of the processing.

The controller shall document the circumstances and outcome of this review, retain this documentation for ten years following completion of the review, and make it available to the National Authority for Data Protection and Freedom of Information (hereinafter: the “Authority”) upon the Authority’s request.

Right to lodge a complaint

Any alleged infringement by the controller may be the subject of a complaint to the National Authority for Data Protection and Freedom of Information:

National Authority for Data Protection and Freedom of Information

1055 Budapest, Falk Miksa utca 9-11.
Postal address: 1363 Budapest, Pf. 9.
Phone: +36-1-391-1400
Fax: +36-1-391-1410
E-mail: ugyfelszolgalat@naih.hu

Closing remarks

In preparing this notice, we have had regard to the following legislation and recommendations:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, GDPR);
  • Act CVIII of 2001 on certain aspects of electronic commerce services and services related to the information society (in particular Section 13/A);
  • Act XLVII of 2008 on the Prohibition of Unfair Business-to-Consumer Commercial Practices;
  • Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions of Economic Advertising Activities (in particular Section 6);
  • Act XC of 2005 on Freedom of Electronic Information;
  • Act C of 2003 on Electronic Communications (specifically Section 155);
  • Opinion 16/2011 on EASA/IAB Best Practice Recommendation on Online Behavioural Advertising;
  • the recommendation of the National Authority for Data Protection and Freedom of Information on the data protection requirements for prior information.

EnerLogic Advisory Kft. — Privacy Notice — English translation of the original Hungarian version.