For Oander Technologies Korlátolt Felelősségű Társaság (registered office: 1134 Budapest, Váci út 47/E; company registration number: 01-09-307976; tax number: 26210443-2-41) (hereinafter: the Company or Controller), the protection of the personal data it processes is a matter of particular importance. At the same time, the Company undertakes to guarantee the right to informational self-determination of the individuals affected by the data processing, in accordance with the relevant legal provisions.
When processing personal data, the Company ensures — in line with the “principle of accountability” — that:
Name of the Controller:
Oander Technologies Korlátolt Felelősségű Társaság (Oander Technologies Kft.)
Contact details:
Registered office: 1061 Budapest, Andrássy út 2, 3rd floor, Door 1.
Postal address: 1242 Budapest, P.O. Box 404.
Email address: office@oander.eu
Website: www.oander.eu
Phone: +36 70 622 4898
Detailed information on data processing is contained in the following privacy notices:
1/A) Processing related to inquiries received via the “Send message” feature provided under the “CONTACT” menu item of the website www.oander.eu.
Purpose of the processing:Under the “CONTACT” menu item, the Controller offers the option to send an electronic message via the website in order to establish or maintain contact. The purpose of the processing is
Data subject:
Personal data processed:
Source of the data:
Legal basis for the processing:
(This also covers the processing of personal data of a data subject acting as a representative/contact person of the Controller's contractual partner in connection with a contract between the Controller and that partner.) The legitimate interest assessment relating to this processing can be found in the “Legitimate Interest Assessment” chapter of the Controller's privacy notice.
Duration of the processing:
Recipients of the processing:
Processor:Google.com, as the hosting provider of the G-Suite email system.
Automated decision-making, profiling:The Controller does not apply automated decision-making or profiling in this processing.
1/B) Processing related to inquiries received via the contact details provided under the “CONTACT” menu item of the website www.oander.eu.
Purpose of the processing:Under the “CONTACT” menu item, the Controller offers the option to establish or maintain contact via the contact details provided on the website (phone, email, postal address). The purpose of the processing is
Data subject:
| Type of inquiry | Personal data processed |
|---|---|
| Phone call | Phone number, name, personal data contained in the content of the message |
| Email address, name, personal data contained in the content of the message | |
| Letter | Postal address, sender's name, personal data contained in the content of the message |
Source of the data:
Legal basis for the processing:
(This also covers the processing of personal data of a data subject acting as a representative/contact person of the Controller's contractual partner in connection with a contract between the Controller and that partner.) The legitimate interest assessment relating to this processing can be found in the “Legitimate Interest Assessment” chapter of the Controller's privacy notice.
Duration of the processing:
Recipients of the processing:
Processor:Google.com, as the hosting provider of the G-Suite email system. For postal mail, the data required for delivery is transmitted to the relevant delivery service provider.
Automated decision-making, profiling:The Controller does not apply automated decision-making or profiling in this processing.
Processing related to job applications received at the address karrier@oander.eu, provided under the “ABOUT US – CAREERS” menu item of the website www.oander.eu.
Purpose of the processing:Collecting and evaluating the CVs and other accompanying documents (e.g. cover letters) received directly for the positions advertised by the Controller as part of the selection process, and ultimately selecting the candidate best suited to the advertised position.
Data subject:
Personal data processed:
Personal data contained in the application that is not relevant to the position to be filled, or special category data, is deleted by the Controller without delay when evaluating the application, unless processing is required to exercise rights or fulfil obligations of the Controller or the applicant under employment or social security law.
Source of the data:
Legal basis for the processing:
The applicant has the right to withdraw their consent at any time. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal; however, upon becoming aware of the withdrawal, the Controller will delete the application without delay.
The legitimate interest assessment relating to this processing can be found in the “Legitimate Interest Assessment” chapter of the Controller's privacy notice. (In this case, the Controller informs the applicant of the relevant processing upon first contact and states that the further stages of the selection process can only proceed with the applicant's consent. If the applicant does not consent to the processing, the Controller will delete the received application without delay. If the applicant consents to the processing, further processing takes place on the basis of Art. 6(1)(a) GDPR.)
Duration of the processing:
An exception applies if the data subject withdraws their consent. In this case, the data is deleted at the time the Controller becomes aware of the withdrawal. If the Controller intends to retain the application of an unsuccessful applicant after the selection process has concluded, it will inform the applicant in advance, as this constitutes a new processing activity not covered by this notice.
Recipients of the processing:The persons involved in receiving, evaluating and managing applications (HR staff and managers).
Processor:Google.com, as the hosting provider of the G-Suite email system.
Automated decision-making, profiling:The Controller does not apply automated decision-making or profiling in this processing.
Processing related to the use of the “Facebook” icon on the website www.oander.eu.
Purpose of the processing:Promoting the services offered by the Controller and the website itself, as well as establishing contact with interested parties via the Controller's profile at www.facebook.com (https://www.facebook.com/oandermedia).
Since the processing related to the use of the website www.facebook.com/oandermedia is carried out by Facebook — or the relevant local Facebook group company — jointly with the Controller as joint controllers, the detailed rules on data processing on www.facebook.com are governed by the platform's own terms: (http://www.facebook.com/legal/terms?ref=pf); (http://www.facebook.com/about/privacy/)
Data subject:
Personal data processed:
Source of the data:directly from the data subject
Legal basis for the processing:The processing is carried out pursuant to Art. 6(1)(a) GDPR, i.e. on the basis of the visitor's consent.
The data subject can withdraw their consent free of charge at any time. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
Duration of the processing:
Automated decision-making, profiling:The Controller does not apply automated decision-making or profiling in this processing.
If content shared on facebook.com/oandermedia infringes your rights, please proceed as follows so that we can remedy the harm caused:
Further information can be found in Facebook's help centre, also accessible without registration or login, under “Policies and Reporting” – “Report abuse”: https://www.facebook.com/help/1753719584844061?helpref=hc_global_nav
By using the Facebook pixel, the Company receives data on visitors' usage behaviour on the website. The Facebook remarketing pixel is not suitable for identifying individuals but, with the help of the tracking code, allows personalized offers to be shown to website visitors on Facebook. Detailed information on the Facebook pixel can be found at: https://www.facebook.com/business/help/742478679120153?id=1205376682832142
Processing related to the use of the “Behance” icon on the website www.oander.eu.
Purpose of the processing:Promoting the services offered by the Controller and the website itself, as well as establishing contact with interested parties via the Controller's page at www.behance.net (https://www.behance.net/oander/). Since Adobe is the controller for processing related to the use of the website https://www.behance.net/oander, the detailed rules and information on data processing there can be found at: https://www.adobe.com/privacy/policy.html; https://www.adobe.com/privacy.html
Purpose of the processing:Providing the technical requirements necessary for operating the website.
The processing is carried out using a processor. Activity performed by the processor: hosting services.
Name of the processor:3 in 1 Hosting Bt.
Contact details:
Privacy notice:https://megacp.com/adatvedelmi_tajekoztato.pdf
Data affected by the processing:all personal data processed on the website www.oander.eu.
Duration of the processing:the duration specified for the respective processing.
Explanation of terms used in this privacy notice
Processor:a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller.
Processing:any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Personal data breach:a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.
Recipient:a natural or legal person, public authority, agency or other body to which personal data is disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law are not regarded as recipients; the processing of that data by those public authorities is carried out in compliance with applicable data protection rules according to the purposes of the processing.
Data subject:an identified or identifiable natural person.
Consent of the data subject:any freely given, specific, informed and unambiguous indication of the data subject's wishes, given by a statement or by a clear affirmative action, signifying agreement to the processing of personal data relating to them.
GDPR:Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
Infotv.:Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (Hungary).
NAIH:National Authority for Data Protection and Freedom of Information (Hungary).
Profiling:any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
Personal data:any information relating to an identified or identifiable natural person (“data subject”); a natural person is regarded as identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Special categories of personal data:personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person's sex life or sexual orientation.
“Genetic data”: personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question; “Biometric data”: personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data; “Data concerning health”: personal data related to the physical or mental health of a natural person, including the provision of healthcare services, which reveal information about their health status.
What rights do you have regarding the personal data processed by the Controller?
Right of access:You may request confirmation as to whether the Controller processes personal data concerning you and, if so, information on how the Controller processes your personal data, including:
In addition, you may request a copy of the personal data processed by the Controller. However, a reasonable fee based on administrative costs may be charged for further copies.
Right to rectification:It is a basic principle that the Controller processes personal data of data subjects that is accurate, up to date and precise. Please therefore exercise your right to inform the Controller if the personal data it processes is inaccurate or no longer up to date (e.g. if your contact details have changed). The Controller will rectify or supplement the data without delay, and no later than within one month, provided the data subject can credibly demonstrate the accuracy of the data to be corrected.
Right to erasure:You have the right to request that the Controller erase personal data concerning you without undue delay, and the Controller is obliged to erase personal data concerning you without undue delay under certain conditions.
Right to be forgotten:Where the Controller has made the personal data public and is obliged to erase it, the Controller shall take reasonable steps, including technical measures, taking into account available technology and the cost of implementation, to inform other controllers processing that personal data that you have requested the erasure of any links to, or copies or replications of, that personal data.
Right to restriction of processing:If you have requested rectification of your personal data, the Controller shall restrict processing from the time your request is received until the accuracy of the data is confirmed or the corresponding change is made; the same applies if you have objected to the processing, until the objection has been reviewed. You may also request restriction of processing if:
Restriction means that, with the exception of storage, the Controller may only process your personal data with your consent, unless it is necessary to establish legal claims, to protect the rights of another person, or for reasons of important public interest.
Right to object:You have the right to object to the processing of your personal data where it is based on the Controller's legitimate interest, or to have an automated decision reviewed. In such cases, the Controller may only continue the processing if it can demonstrate compelling legitimate grounds that override your interests, rights and freedoms. However, the Controller may continue to process your personal data where necessary to establish, exercise or defend legal claims.
Right to data portability:You may request that the Controller provide you with the personal data you have supplied for processing based on consent or on the performance of a contract, in a structured, commonly used and machine-readable format. You also have the right to request that the Controller transmit that data to another controller.
Withdrawal of consent:Where a processing operation of the Controller is based on consent, you have the right to withdraw that consent. In this case, the Controller will stop the processing activities based on that legal basis and delete the data processed solely on the basis of consent.
Objection to direct marketing:Where the Controller processes your personal data for direct marketing purposes, you have the right to object at any time, free of charge, to the processing of your personal data for such purposes, including any related profiling. If you object to the processing of your personal data for direct marketing purposes, the Controller will no longer process the personal data for that purpose.
Automated individual decision-making, including profiling:You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. This does not apply where the decision
The Controller shall fulfil a request to exercise the above rights within one month of its receipt. The day the request is received is not counted when calculating the deadline. The Controller may extend this deadline by a further two months where necessary, taking into account the complexity and number of requests. In the event of an extension, the Controller shall inform the data subject of the extension and the reasons for it within one month of receiving the request.
You may exercise your rights using the Controller's contact details.
Before fulfilling a request received, the Controller must identify the requesting person in order to avoid the risk of unauthorized data processing. If the Controller cannot identify the requesting person as the data subject or as a person authorized to represent the data subject, it cannot fulfil the request.
What remedies are available to you regarding the personal data processed by the Controller?
National Authority for Data Protection and Freedom of Information (NAIH)
If you believe that the Controller or a processor engaged by it has infringed applicable law in the processing of your personal data, or that there is an imminent risk of such infringement, you may initiate a — free of charge — investigation with the National Authority for Data Protection and Freedom of Information (Hungary).
Contact:
Registered office: 1055 Budapest, Falk Miksa utca 9–11.
Postal address: 1363 Budapest, P.O. Box 9.
Email address: ugyfelszolgalat@naih.hu
Website: www.naih.hu
Phone: +36 (1) 391-1400; +36 (30) 549-6838; +36 (30) 683-5969
Fax: +36 (1) 391-1410
Court
If your rights have been infringed, you may also pursue legal action. The decision rests with the competent court (törvényszék). You may file the claim either with the court of your place of residence or your place of stay.
Contact:Website: https://birosag.hu/birosag-kereso/
The Controller takes technical and organizational measures to protect the personal data it processes, ensuring a level of protection appropriate to the identified risk. Despite the security measures applied, situations may arise leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data transmitted, stored or otherwise processed.
Should such an event occur, it is in the mutual interest of the Controller and the data subjects to detect the personal data breach and its effects as quickly as possible, so that the Controller can mitigate the resulting negative consequences as part of handling the incident. Upon becoming aware of an incident, the Controller carries out the following obligations:
We therefore ask you to inform the Controller of any personal data breach you become aware of.
Name of the Controller
Oander Technologies Korlátolt Felelősségű Társaság (Oander Technologies Kft.)
Contact details
Registered office: 1061 Budapest, Andrássy út 2, 3rd floor, Door 1.
Postal address: 1242 Budapest, P.O. Box 404.
Email address: office@oander.eu
Website: www.oander.eu
Phone: +36 70 622 4898
In carrying out its activities, OANDER TECHNOLOGIES Kft. (hereinafter: the Controller) performs technical operations and other measures for which external support is required. The Controller is entitled, in compliance with the relevant legal provisions and after informing the data subjects, to engage processors to carry out these tasks. The processors engaged act in the name and on the instructions of the Controller and process personal data in order to fulfil their tasks. The Controller only engages processors that provide sufficient guarantees that processing will be carried out in accordance with legal requirements. The Controller transfers the data subject's personal data to the processor only to the extent and for the duration necessary to fulfil the processing task; the processor is obliged to return and/or delete the data once its role as processor ends.
– Data processing by OANDER TECHNOLOGIES Kft. in connection with maintaining contact
Subject of the processing:The data processing carried out by OANDER TECHNOLOGIES Kft. in the context of maintaining contact, insofar as establishing or maintaining contact is not necessary for the initiation, conclusion or performance of a contract between the Controller and the data subject, or for the settlement of related claims.
Legal basis for the processing:Art. 6(1)(f) GDPR – “Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.”
Scope of the data processed:the personal data contained in the content of the communication
| Type of inquiry | Personal data processed |
|---|---|
| Phone call | Phone number, name, personal data contained in the content of the message |
| Email address, name, personal data contained in the content of the message | |
| Letter | Postal address, sender's name, personal data contained in the content of the message |
Categories of data subjects:
Legitimate interest of the Controller or a third party
Purpose of the processing:
Existing and genuine legitimate interest of the Controller:The Controller (and also a third party) has a legitimate interest in maintaining contact with the requesting party, for reasons including, but not limited to, the following:
Could another legal basis apply to this processing?
Consent of the data subject:Regarding the applicability of consent, 4+1 conditions were examined: based on adequate information / freely given / specific / unambiguous / + the consequences of withdrawing consent. If the data subject is a third party different from the requesting party, consent cannot be relied upon as the legal basis, since prior information cannot be ensured. If the data subject is the requesting party itself, a lack of voluntariness must be assumed where the data subject is required to contact the Controller and has no option for personal contact.
Contract:This possibility has already been excluded in the “Subject of the processing” section.
Legal obligation of the Controller:There is no statutory or municipal provision requiring mandatory data processing for the activity examined; this legal basis therefore does not apply either.
Protection of the vital interests of the data subject or another natural person:The processing examined generally serves the interest of the data subject and, where applicable, the interest of other natural persons; however, these interests are not to be classified as vital interests.
Performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller:The Controller is not a public authority, has no official powers, and does not, in principle, carry out any task in the public interest as part of its activities. This legal basis is therefore excluded.
Which fundamental rights, freedoms or identifiable interests of the data subject(s) are restricted by the processing examined?The data subject's right to informational self-determination is restricted. According to the settled case law of the Hungarian Constitutional Court, rights derived from human dignity — such as, in this case, the right to informational self-determination in its aspect of control over personal data — may be restricted in a necessary and proportionate manner.
To what extent are the above rights, freedoms and interests restricted by the processing examined?The processing examined restricts the data subject's right to informational self-determination only to the extent necessary for maintaining contact and for answering and handling the inquiry, which in most cases serves the data subject's own interest.
Why is the processing examined necessary to achieve the Controller's purpose?The processing examined enables the achievement of the above purposes, namely:
Would the Controller suffer a disadvantage if the processing did not take place?Yes, the Controller would suffer adverse consequences from the lack of information obtained through the processing examined. Without this data, neither normal business operations nor efficient contact maintenance would be possible.
Is the processing necessary to achieve the purpose of a third party?If the data subject acts on behalf of a third party (a natural or legal person), the processing is necessary to achieve that third party's purpose.
Is the planned processing suitable for achieving the above purposes?The processing examined enables efficient maintenance of contact.
Is the restriction caused by the processing proportionate to the above benefits?The proportionality of the processing examined is supported by the following facts:
Can the intended goal also be achieved in another way that is less restrictive of the fundamental rights, freedoms or interests of the data subject?All data subjects have the option of contacting the Controller in person; however, neither the data subjects nor — for reasons of infection control and resource allocation — the Controller can be expected to rely exclusively on this form of contact.
Does the processing examined provide a benefit to the data subject(s)?Yes, the processing represents a benefit for the data subject, as it provides them with an alternative to establishing contact in person.
How can the data subject find out about the processing examined?The Controller strives to provide sufficiently detailed, accessible information, available on the Controller's website.
How does the relationship between the Controller and the data subject affect the processing?Maintaining contact involves parties on an equal footing; there is no relationship of subordination.
Does the processing examined concern a vulnerable group?In principle, no, given the Controller's field of activity. Should the processing nevertheless concern such a group due to the nature of the inquiry, the Controller applies special safeguards in that case.
Assessment of the safeguards applied by the Controller:The Controller applies several safeguards:
Existence of a legitimate interest:Based on the assessment carried out as part of the legitimate interest assessment, it was established that the legitimate interest put forward by the Controller is real and present, as it is necessary for efficient business operations and service delivery. The processing is sufficiently specific, as its purpose is clear and easily understandable for data subjects.
Proportionality:With regard to the proportionality of the processing examined, it must be taken into account that the processing restricts the data subject's right to informational self-determination. Based on the above, it can be concluded that, although the processing restricts the data subject's right to informational self-determination, the achievement of the legitimate aims pursued tips the balance in favour of permissibility.
Conclusion:Based on the balancing test set out above, it was established that the processing is necessary and proportionate, does not constitute an unjustified interference with the data subject's privacy, and can therefore rely on the Controller's legitimate interest as the legal basis for the processing.
Date:8 July 2026