Privacy Notice

GENERAL PROVISIONS

For Oander Technologies Korlátolt Felelősségű Társaság (registered office: 1134 Budapest, Váci út 47/E; company registration number: 01-09-307976; tax number: 26210443-2-41) (hereinafter: the Company or Controller), the protection of the personal data it processes is a matter of particular importance. At the same time, the Company undertakes to guarantee the right to informational self-determination of the individuals affected by the data processing, in accordance with the relevant legal provisions.

When processing personal data, the Company ensures — in line with the “principle of accountability” — that:

  • personal data is processed lawfully, fairly, and in a manner transparent to the data subject;
  • personal data is collected only for specified, explicit and legitimate purposes, and is not further processed in a manner incompatible with those purposes;
  • the personal data it processes is adequate, relevant, and limited to what is necessary in relation to the purposes of processing;
  • the personal data processed by the Company is accurate and, where necessary, kept up to date. The Company takes all reasonable steps to ensure that inaccurate personal data is erased or rectified without delay;
  • personal data is stored in a form which permits identification of data subjects for no longer than is necessary for the purposes of the processing;
  • appropriate technical and organizational measures ensure adequate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage.

Name of the Controller:
Oander Technologies Korlátolt Felelősségű Társaság (Oander Technologies Kft.)

Contact details:
Registered office: 1061 Budapest, Andrássy út 2, 3rd floor, Door 1.
Postal address: 1242 Budapest, P.O. Box 404.
Email address: office@oander.eu
Website: www.oander.eu
Phone: +36 70 622 4898

Detailed information on data processing is contained in the following privacy notices:

  • Explanation of terms used in this privacy notice
  • Further information on exercising data subject rights
  • Further information on the processors engaged by the Company
  • Information on handling personal data breaches
  • Applicable legal provisions
  • Legitimate interest assessment

Individual data processing activities

I. Data processing related to the use of the website www.oander.eu

1. Contact

1/A) Processing related to inquiries received via the “Send message” feature provided under the “CONTACT” menu item of the website www.oander.eu.

Purpose of the processing:Under the “CONTACT” menu item, the Controller offers the option to send an electronic message via the website in order to establish or maintain contact. The purpose of the processing is

  • to enable the Controller to offer interested parties the option of establishing or maintaining contact via the website,
  • to enable the Controller to answer and handle inquiries.

Data subject:

  • the person who sends the inquiry
  • third parties whose personal data is contained in the content of the inquiry

Personal data processed:

  • Your name
  • Subject of interest / reason for contact
  • How did you find us? (options: –; recommendation from an acquaintance; via Google; via Facebook; other)
  • Your email address
  • Your phone number
  • Message (content of the message)

Source of the data:

  • directly from the data subject
  • from the requesting party (where, based on the content of the inquiry, another person is also affected)

Legal basis for the processing:

  • The processing is carried out pursuant to Art. 6(1)(b) GDPR, insofar as establishing or maintaining contact is necessary for the initiation, conclusion or performance of a contract between the Controller and the data subject, or for the settlement of related claims.
  • If contact is established or maintained for a reason other than the one stated above, the legal basis for the processing is Art. 6(1)(f) GDPR, i.e. the legitimate interest of the Controller or a third party in handling and answering inquiries.

(This also covers the processing of personal data of a data subject acting as a representative/contact person of the Controller's contractual partner in connection with a contract between the Controller and that partner.) The legitimate interest assessment relating to this processing can be found in the “Legitimate Interest Assessment” chapter of the Controller's privacy notice.

Duration of the processing:

  • Inquiries processed on the basis of Art. 6(1)(f) GDPR are processed by the Controller for 3 years from receipt and then deleted. This does not apply to inquiries still being handled; in such cases, the related personal data is deleted 3 years after the matter is closed.
  • Inquiries processed on the basis of Art. 6(1)(b) GDPR are processed by the Controller, after the end of the contractual relationship between the Controller and the data subject, until the expiry of the limitation period under Sections 6:21–6:25 of the Hungarian Civil Code (Act V of 2013).

Recipients of the processing:

  • If processing is carried out under Art. 6(1)(f) GDPR: the Controller's employees responsible for customer service.
  • If processing is carried out under Art. 6(1)(b) GDPR: the Controller's employees responsible for customer service, the legal department, and the department responsible for providing the service covered by the contract.

Processor:Google.com, as the hosting provider of the G-Suite email system.

Automated decision-making, profiling:The Controller does not apply automated decision-making or profiling in this processing.

1/B) Processing related to inquiries received via the contact details provided under the “CONTACT” menu item of the website www.oander.eu.

Purpose of the processing:Under the “CONTACT” menu item, the Controller offers the option to establish or maintain contact via the contact details provided on the website (phone, email, postal address). The purpose of the processing is

  • to enable the Controller to offer interested parties the option of establishing or maintaining contact via the contact details provided on the website,
  • to enable the Controller to answer and handle inquiries.

Data subject:

  • the person making the inquiry
  • third parties whose personal data is contained in the content of the inquiry

Type of inquiryPersonal data processed
Phone callPhone number, name, personal data contained in the content of the message
EmailEmail address, name, personal data contained in the content of the message
LetterPostal address, sender's name, personal data contained in the content of the message

Source of the data:

  • directly from the data subject
  • from the requesting party (where, based on the content of the inquiry, another person is also affected)

Legal basis for the processing:

  • The processing is carried out pursuant to Art. 6(1)(b) GDPR, insofar as establishing or maintaining contact is necessary for the initiation, conclusion or performance of a contract between the Controller and the data subject, or for the settlement of related claims.
  • If contact is established or maintained for a reason other than the one stated above, the legal basis for the processing is Art. 6(1)(f) GDPR, i.e. the legitimate interest of the Controller or a third party in handling and answering inquiries.

(This also covers the processing of personal data of a data subject acting as a representative/contact person of the Controller's contractual partner in connection with a contract between the Controller and that partner.) The legitimate interest assessment relating to this processing can be found in the “Legitimate Interest Assessment” chapter of the Controller's privacy notice.

Duration of the processing:

  • Inquiries processed on the basis of Art. 6(1)(f) GDPR are processed by the Controller for 3 years from receipt and then deleted. This does not apply to inquiries still being handled; in such cases, the related personal data is deleted 3 years after the matter is closed.
  • Inquiries processed on the basis of Art. 6(1)(b) GDPR are processed by the Controller, after the end of the contractual relationship between the Controller and the data subject, until the expiry of the limitation period under Sections 6:21–6:25 of the Hungarian Civil Code (Act V of 2013).

Recipients of the processing:

  • If processing is carried out under Art. 6(1)(f) GDPR: the Controller's employees responsible for customer service.
  • If processing is carried out under Art. 6(1)(b) GDPR: the Controller's employees responsible for customer service, the legal department, and the department responsible for providing the service covered by the contract.

Processor:Google.com, as the hosting provider of the G-Suite email system. For postal mail, the data required for delivery is transmitted to the relevant delivery service provider.

Automated decision-making, profiling:The Controller does not apply automated decision-making or profiling in this processing.

2. Processing of job applications

Processing related to job applications received at the address karrier@oander.eu, provided under the “ABOUT US – CAREERS” menu item of the website www.oander.eu.

Purpose of the processing:Collecting and evaluating the CVs and other accompanying documents (e.g. cover letters) received directly for the positions advertised by the Controller as part of the selection process, and ultimately selecting the candidate best suited to the advertised position.

Data subject:

  • the person applying for the advertised position (hereinafter: applicant)
  • the sender of the application (if different from the applicant)
  • third parties whose personal data is contained in the application

Personal data processed:

  • Email address (from which the application is received)
  • all personal data contained in the application, including accompanying documents

Personal data contained in the application that is not relevant to the position to be filled, or special category data, is deleted by the Controller without delay when evaluating the application, unless processing is required to exercise rights or fulfil obligations of the Controller or the applicant under employment or social security law.

Source of the data:

  • directly from the data subject
  • from the applicant (where, based on the content of the application, another person is also affected)

Legal basis for the processing:

  • The processing is carried out pursuant to Art. 6(1)(a) GDPR, i.e. on the basis of the applicant's consent.

The applicant has the right to withdraw their consent at any time. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal; however, upon becoming aware of the withdrawal, the Controller will delete the application without delay.

  • If the application was not submitted to the Controller by the data subject themselves, the legal basis for the processing is Art. 6(1)(f) GDPR, i.e. the legitimate interest of the Controller.

The legitimate interest assessment relating to this processing can be found in the “Legitimate Interest Assessment” chapter of the Controller's privacy notice. (In this case, the Controller informs the applicant of the relevant processing upon first contact and states that the further stages of the selection process can only proceed with the applicant's consent. If the applicant does not consent to the processing, the Controller will delete the received application without delay. If the applicant consents to the processing, further processing takes place on the basis of Art. 6(1)(a) GDPR.)

Duration of the processing:

  • Applications processed on the basis of Art. 6(1)(f) GDPR are processed by the Controller until first contact with the applicant. If the applicant does not consent to the processing, the Controller will delete the received application without delay. If the applicant consents, further processing takes place under Art. 6(1)(a) GDPR, so the following provisions apply to the duration.
  • Applications processed on the basis of Art. 6(1)(a) GDPR are processed by the Controller until the selection process for the position to be filled is concluded.

An exception applies if the data subject withdraws their consent. In this case, the data is deleted at the time the Controller becomes aware of the withdrawal. If the Controller intends to retain the application of an unsuccessful applicant after the selection process has concluded, it will inform the applicant in advance, as this constitutes a new processing activity not covered by this notice.

Recipients of the processing:The persons involved in receiving, evaluating and managing applications (HR staff and managers).

Processor:Google.com, as the hosting provider of the G-Suite email system.

Automated decision-making, profiling:The Controller does not apply automated decision-making or profiling in this processing.

3. Facebook

Processing related to the use of the “Facebook” icon on the website www.oander.eu.

Purpose of the processing:Promoting the services offered by the Controller and the website itself, as well as establishing contact with interested parties via the Controller's profile at www.facebook.com (https://www.facebook.com/oandermedia).

Since the processing related to the use of the website www.facebook.com/oandermedia is carried out by Facebook — or the relevant local Facebook group company — jointly with the Controller as joint controllers, the detailed rules on data processing on www.facebook.com are governed by the platform's own terms: (http://www.facebook.com/legal/terms?ref=pf); (http://www.facebook.com/about/privacy/)

Data subject:

  • Visitors of the website oander.eu who click on the “Facebook” icon placed in the header of the page

Personal data processed:

  • the data subject's name registered on facebook.com
  • the data subject's public profile picture used on www.facebook.com
  • the activity carried out by the data subject on facebook.com/oandermedia (posts, “likes”, etc.)

Source of the data:directly from the data subject

Legal basis for the processing:The processing is carried out pursuant to Art. 6(1)(a) GDPR, i.e. on the basis of the visitor's consent.

The data subject can withdraw their consent free of charge at any time. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

Duration of the processing:

  • The duration of processing generally depends on the data subject's activity; the Controller deletes content created by the data subject while the website facebook.com/oandermedia exists, for the following reasons:
  • if the data subject withdraws their consent
  • at the request of the data subject
  • at the request of a third party, if the data subject's activity could be unlawful or ethically questionable
  • Otherwise, the provisions under “Data storage, blocking and deletion of accounts” at https://www.facebook.com/about/privacy/ apply to the duration of processing.

Automated decision-making, profiling:The Controller does not apply automated decision-making or profiling in this processing.

If content shared on facebook.com/oandermedia infringes your rights, please proceed as follows so that we can remedy the harm caused:

  • Report the incident to the Controller
  • Request the Controller to delete the data

Further information can be found in Facebook's help centre, also accessible without registration or login, under “Policies and Reporting” – “Report abuse”: https://www.facebook.com/help/1753719584844061?helpref=hc_global_nav

4. Use of the Facebook pixel

By using the Facebook pixel, the Company receives data on visitors' usage behaviour on the website. The Facebook remarketing pixel is not suitable for identifying individuals but, with the help of the tracking code, allows personalized offers to be shown to website visitors on Facebook. Detailed information on the Facebook pixel can be found at: https://www.facebook.com/business/help/742478679120153?id=1205376682832142

5. Behance

Processing related to the use of the “Behance” icon on the website www.oander.eu.

Purpose of the processing:Promoting the services offered by the Controller and the website itself, as well as establishing contact with interested parties via the Controller's page at www.behance.net (https://www.behance.net/oander/). Since Adobe is the controller for processing related to the use of the website https://www.behance.net/oander, the detailed rules and information on data processing there can be found at: https://www.adobe.com/privacy/policy.html; https://www.adobe.com/privacy.html

6. Hosting service

Purpose of the processing:Providing the technical requirements necessary for operating the website.

The processing is carried out using a processor. Activity performed by the processor: hosting services.

Name of the processor:3 in 1 Hosting Bt.

Contact details:

  • Customer service / postal address: 2310 Szigetszentmiklós, Dévai utca 10/A
  • Phone: +36/21/200-0040
  • Fax: +36/24/998-626

Privacy notice:https://megacp.com/adatvedelmi_tajekoztato.pdf

Data affected by the processing:all personal data processed on the website www.oander.eu.

Duration of the processing:the duration specified for the respective processing.

Definitions

Explanation of terms used in this privacy notice

Processor:a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller.

Processing:any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Personal data breach:a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.

Recipient:a natural or legal person, public authority, agency or other body to which personal data is disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law are not regarded as recipients; the processing of that data by those public authorities is carried out in compliance with applicable data protection rules according to the purposes of the processing.

Data subject:an identified or identifiable natural person.

Consent of the data subject:any freely given, specific, informed and unambiguous indication of the data subject's wishes, given by a statement or by a clear affirmative action, signifying agreement to the processing of personal data relating to them.

GDPR:Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

Infotv.:Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (Hungary).

NAIH:National Authority for Data Protection and Freedom of Information (Hungary).

Profiling:any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.

Personal data:any information relating to an identified or identifiable natural person (“data subject”); a natural person is regarded as identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Special categories of personal data:personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation.

“Genetic data”: personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question; “Biometric data”: personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data; “Data concerning health”: personal data related to the physical or mental health of a natural person, including the provision of healthcare services, which reveal information about their health status.

Further information on exercising data subject rights

What rights do you have regarding the personal data processed by the Controller?

Right of access:You may request confirmation as to whether the Controller processes personal data concerning you and, if so, information on how the Controller processes your personal data, including:

  • The purpose and grounds of the processing
  • Categories of personal data processed
  • Disclosure of the personal data (to which recipients)
  • The duration of processing, or the criteria for determining it
  • Your rights
  • The origin of the processed data (if the data was not provided by you)
  • whether the processing involves automated decision-making (so-called profiling)
  • if your personal data is transferred to a country outside the European Economic Area, how the Controller ensures the protection of your data

In addition, you may request a copy of the personal data processed by the Controller. However, a reasonable fee based on administrative costs may be charged for further copies.

Right to rectification:It is a basic principle that the Controller processes personal data of data subjects that is accurate, up to date and precise. Please therefore exercise your right to inform the Controller if the personal data it processes is inaccurate or no longer up to date (e.g. if your contact details have changed). The Controller will rectify or supplement the data without delay, and no later than within one month, provided the data subject can credibly demonstrate the accuracy of the data to be corrected.

Right to erasure:You have the right to request that the Controller erase personal data concerning you without undue delay, and the Controller is obliged to erase personal data concerning you without undue delay under certain conditions.

Right to be forgotten:Where the Controller has made the personal data public and is obliged to erase it, the Controller shall take reasonable steps, including technical measures, taking into account available technology and the cost of implementation, to inform other controllers processing that personal data that you have requested the erasure of any links to, or copies or replications of, that personal data.

Right to restriction of processing:If you have requested rectification of your personal data, the Controller shall restrict processing from the time your request is received until the accuracy of the data is confirmed or the corresponding change is made; the same applies if you have objected to the processing, until the objection has been reviewed. You may also request restriction of processing if:

  • the processing is unlawful but you do not want the data to be erased,
  • the Controller no longer needs the personal data for the purposes of the processing, but you need it to establish, exercise or defend legal claims.

Restriction means that, with the exception of storage, the Controller may only process your personal data with your consent, unless it is necessary to establish legal claims, to protect the rights of another person, or for reasons of important public interest.

Right to object:You have the right to object to the processing of your personal data where it is based on the Controller's legitimate interest, or to have an automated decision reviewed. In such cases, the Controller may only continue the processing if it can demonstrate compelling legitimate grounds that override your interests, rights and freedoms. However, the Controller may continue to process your personal data where necessary to establish, exercise or defend legal claims.

Right to data portability:You may request that the Controller provide you with the personal data you have supplied for processing based on consent or on the performance of a contract, in a structured, commonly used and machine-readable format. You also have the right to request that the Controller transmit that data to another controller.

Withdrawal of consent:Where a processing operation of the Controller is based on consent, you have the right to withdraw that consent. In this case, the Controller will stop the processing activities based on that legal basis and delete the data processed solely on the basis of consent.

Objection to direct marketing:Where the Controller processes your personal data for direct marketing purposes, you have the right to object at any time, free of charge, to the processing of your personal data for such purposes, including any related profiling. If you object to the processing of your personal data for direct marketing purposes, the Controller will no longer process the personal data for that purpose.

Automated individual decision-making, including profiling:You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. This does not apply where the decision

  • is necessary for entering into, or performance of, a contract between you and the Controller;
  • is authorized by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard your rights and freedoms and legitimate interests; or
  • is based on your explicit consent.

The Controller shall fulfil a request to exercise the above rights within one month of its receipt. The day the request is received is not counted when calculating the deadline. The Controller may extend this deadline by a further two months where necessary, taking into account the complexity and number of requests. In the event of an extension, the Controller shall inform the data subject of the extension and the reasons for it within one month of receiving the request.

You may exercise your rights using the Controller's contact details.

Before fulfilling a request received, the Controller must identify the requesting person in order to avoid the risk of unauthorized data processing. If the Controller cannot identify the requesting person as the data subject or as a person authorized to represent the data subject, it cannot fulfil the request.

What remedies are available to you regarding the personal data processed by the Controller?

National Authority for Data Protection and Freedom of Information (NAIH)

If you believe that the Controller or a processor engaged by it has infringed applicable law in the processing of your personal data, or that there is an imminent risk of such infringement, you may initiate a — free of charge — investigation with the National Authority for Data Protection and Freedom of Information (Hungary).

Contact:
Registered office: 1055 Budapest, Falk Miksa utca 9–11.
Postal address: 1363 Budapest, P.O. Box 9.
Email address: ugyfelszolgalat@naih.hu
Website: www.naih.hu
Phone: +36 (1) 391-1400; +36 (30) 549-6838; +36 (30) 683-5969
Fax: +36 (1) 391-1410

Court

If your rights have been infringed, you may also pursue legal action. The decision rests with the competent court (törvényszék). You may file the claim either with the court of your place of residence or your place of stay.

Contact:Website: https://birosag.hu/birosag-kereso/

Information on handling personal data breaches

The Controller takes technical and organizational measures to protect the personal data it processes, ensuring a level of protection appropriate to the identified risk. Despite the security measures applied, situations may arise leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data transmitted, stored or otherwise processed.

Should such an event occur, it is in the mutual interest of the Controller and the data subjects to detect the personal data breach and its effects as quickly as possible, so that the Controller can mitigate the resulting negative consequences as part of handling the incident. Upon becoming aware of an incident, the Controller carries out the following obligations:

  • Recording the incident in the “Register of Personal Data Breaches”
  • Reporting the incident to the supervisory authority, if it is likely to result in a risk to the rights and freedoms of natural persons
  • Notifying the data subjects, if it is likely to result in a high risk to the rights and freedoms of natural persons

We therefore ask you to inform the Controller of any personal data breach you become aware of.

Name of the Controller
Oander Technologies Korlátolt Felelősségű Társaság (Oander Technologies Kft.)

Contact details
Registered office: 1061 Budapest, Andrássy út 2, 3rd floor, Door 1.
Postal address: 1242 Budapest, P.O. Box 404.
Email address: office@oander.eu
Website: www.oander.eu
Phone: +36 70 622 4898

Further information on the processors engaged by the Controller

In carrying out its activities, OANDER TECHNOLOGIES Kft. (hereinafter: the Controller) performs technical operations and other measures for which external support is required. The Controller is entitled, in compliance with the relevant legal provisions and after informing the data subjects, to engage processors to carry out these tasks. The processors engaged act in the name and on the instructions of the Controller and process personal data in order to fulfil their tasks. The Controller only engages processors that provide sufficient guarantees that processing will be carried out in accordance with legal requirements. The Controller transfers the data subject's personal data to the processor only to the extent and for the duration necessary to fulfil the processing task; the processor is obliged to return and/or delete the data once its role as processor ends.

Legal provisions applicable to the data processing carried out by OANDER TECHNOLOGIES Kft.

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: the General Data Protection Regulation or GDPR);
  • Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (hereinafter: Infotv.);
  • Act CVIII of 2001 on certain issues of electronic commerce services and information society services (hereinafter: Ekertv.);
  • Act XLVIII of 2008 on the basic conditions of and certain restrictions on commercial advertising activity (hereinafter: Grtv.);
  • Act C of 2003 on electronic communications (hereinafter: Ehtv.);
  • Act V of 2013 on the Civil Code (hereinafter: Ptk.);
  • Act C of 2000 on Accounting (hereinafter: Számv.tv.).

Legitimate Interest Assessment (Balancing Test)

– Data processing by OANDER TECHNOLOGIES Kft. in connection with maintaining contact

General information

Subject of the processing:The data processing carried out by OANDER TECHNOLOGIES Kft. in the context of maintaining contact, insofar as establishing or maintaining contact is not necessary for the initiation, conclusion or performance of a contract between the Controller and the data subject, or for the settlement of related claims.

Legal basis for the processing:Art. 6(1)(f) GDPR – “Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.”

Scope of the data processed:the personal data contained in the content of the communication

Type of inquiryPersonal data processed
Phone callPhone number, name, personal data contained in the content of the message
EmailEmail address, name, personal data contained in the content of the message
LetterPostal address, sender's name, personal data contained in the content of the message

Categories of data subjects:

  • the person making the inquiry
  • third parties whose personal data is contained in the content of the inquiry

Assessment of legitimate interest

Legitimate interest of the Controller or a third party

Purpose of the processing:

  • to enable the Controller to offer interested parties the option of establishing or maintaining contact via the contact details provided on the website and other means,
  • to enable the Controller to answer and handle inquiries.

Existing and genuine legitimate interest of the Controller:The Controller (and also a third party) has a legitimate interest in maintaining contact with the requesting party, for reasons including, but not limited to, the following:

  • in the interest of efficient service delivery
  • for reasons of consumer protection and quality assurance
  • to ensure basic business operations

Could another legal basis apply to this processing?

Consent of the data subject:Regarding the applicability of consent, 4+1 conditions were examined: based on adequate information / freely given / specific / unambiguous / + the consequences of withdrawing consent. If the data subject is a third party different from the requesting party, consent cannot be relied upon as the legal basis, since prior information cannot be ensured. If the data subject is the requesting party itself, a lack of voluntariness must be assumed where the data subject is required to contact the Controller and has no option for personal contact.

Contract:This possibility has already been excluded in the “Subject of the processing” section.

Legal obligation of the Controller:There is no statutory or municipal provision requiring mandatory data processing for the activity examined; this legal basis therefore does not apply either.

Protection of the vital interests of the data subject or another natural person:The processing examined generally serves the interest of the data subject and, where applicable, the interest of other natural persons; however, these interests are not to be classified as vital interests.

Performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller:The Controller is not a public authority, has no official powers, and does not, in principle, carry out any task in the public interest as part of its activities. This legal basis is therefore excluded.

Determination of the fundamental right affected by the processing

Which fundamental rights, freedoms or identifiable interests of the data subject(s) are restricted by the processing examined?The data subject's right to informational self-determination is restricted. According to the settled case law of the Hungarian Constitutional Court, rights derived from human dignity — such as, in this case, the right to informational self-determination in its aspect of control over personal data — may be restricted in a necessary and proportionate manner.

To what extent are the above rights, freedoms and interests restricted by the processing examined?The processing examined restricts the data subject's right to informational self-determination only to the extent necessary for maintaining contact and for answering and handling the inquiry, which in most cases serves the data subject's own interest.

Assessment of the necessity of the processing

Why is the processing examined necessary to achieve the Controller's purpose?The processing examined enables the achievement of the above purposes, namely:

  • maintaining contact with the requesting party,
  • answering and handling inquiries.

Would the Controller suffer a disadvantage if the processing did not take place?Yes, the Controller would suffer adverse consequences from the lack of information obtained through the processing examined. Without this data, neither normal business operations nor efficient contact maintenance would be possible.

Is the processing necessary to achieve the purpose of a third party?If the data subject acts on behalf of a third party (a natural or legal person), the processing is necessary to achieve that third party's purpose.

Is the planned processing suitable for achieving the above purposes?The processing examined enables efficient maintenance of contact.

Is the restriction caused by the processing proportionate to the above benefits?The proportionality of the processing examined is supported by the following facts:

  • The personal data processed as part of the processing examined is limited exclusively to the data strictly necessary to achieve the purpose of the processing, and it is processed only for the shortest possible time needed to achieve that purpose.

Can the intended goal also be achieved in another way that is less restrictive of the fundamental rights, freedoms or interests of the data subject?All data subjects have the option of contacting the Controller in person; however, neither the data subjects nor — for reasons of infection control and resource allocation — the Controller can be expected to rely exclusively on this form of contact.

Assessment of the impact on the data subject

Does the processing examined provide a benefit to the data subject(s)?Yes, the processing represents a benefit for the data subject, as it provides them with an alternative to establishing contact in person.

How can the data subject find out about the processing examined?The Controller strives to provide sufficiently detailed, accessible information, available on the Controller's website.

How does the relationship between the Controller and the data subject affect the processing?Maintaining contact involves parties on an equal footing; there is no relationship of subordination.

Does the processing examined concern a vulnerable group?In principle, no, given the Controller's field of activity. Should the processing nevertheless concern such a group due to the nature of the inquiry, the Controller applies special safeguards in that case.

Safeguards of the processing

Assessment of the safeguards applied by the Controller:The Controller applies several safeguards:

  • Restricted access to the data:Access is granted exclusively to employees who need to know the personal data in order to perform their duties.
  • Limitation of the storage period:Due to the principle of purpose limitation, the records are processed only for as long as necessary to achieve the purpose, taking into account whether the relevant legal provisions prescribe a storage period to be set by the Controller.

Assessment and decision

Existence of a legitimate interest:Based on the assessment carried out as part of the legitimate interest assessment, it was established that the legitimate interest put forward by the Controller is real and present, as it is necessary for efficient business operations and service delivery. The processing is sufficiently specific, as its purpose is clear and easily understandable for data subjects.

Proportionality:With regard to the proportionality of the processing examined, it must be taken into account that the processing restricts the data subject's right to informational self-determination. Based on the above, it can be concluded that, although the processing restricts the data subject's right to informational self-determination, the achievement of the legitimate aims pursued tips the balance in favour of permissibility.

Conclusion:Based on the balancing test set out above, it was established that the processing is necessary and proportionate, does not constitute an unjustified interference with the data subject's privacy, and can therefore rely on the Controller's legitimate interest as the legal basis for the processing.

Date:8 July 2026