Effective date of this policy: December 1, 2024

At Cabinland Kft., we take the protection of personal data very seriously. Therefore, we would like to inform you about the data management and data processing procedures we use in connection with the provision of our services, our online booking system, and our newsletter. Below, we inform you about what we do to protect your data and what data we collect and process for what purposes.

  1. INTRODUCTION:

Cabinland Kft. (registered office: 3240 Parád, Peres utca 57.. ; company registration number: 10 09 040414;) (hereinafter referred to as the “Data Controller“), as the operator of Artam Luxury Cabins, acknowledges the content of this Privacy Policy as binding upon itself in its capacity as Data Controller in the course of providing its services.

The personal data of guests, contracting partners, personal contributors, job applicants and employees (hereinafter referred to as “Data Subjects”) who use the services of the Data Controller shall be processed by the Data Controller. The Data Controller undertakes to ensure that the data processing related to its services complies with the applicable laws and the requirements set out in this Privacy Policy.

The Data Controller reserves the right to unilaterally amend this Policy. In view of this, it is recommended that you regularly visit the https://artam.hu website in order to keep track of any changes. The current content of the Policy is available and can be downloaded at the same location. If the Data Subject’s email address is available to us, we will notify them of any changes by email upon request.

Upon request, we will send the Data Subject a copy of the Policy in force at the time.

By providing the personal data, the Data Subject declares that they have read and expressly accepted the version of this Notice valid at the time of providing the data.

The requirements set out in the Data Protection Notice are in accordance with the applicable data protection legislation:

  • The Fundamental Law of Hungary (Freedom and Responsibility, Article VI);
  • REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
  • Act CXII of 2011 on the right to self-determination and freedom of information (Infotv.);
  • Act V of 2013 on the Civil Code
  • Act CLV of 1997 on consumer protection
  1. Data controller

Cabinland Kft.

Registered office: 3240 Parád, Peres utca 57.

Contact details of the data controller through which the data subject may exercise their rights set out in this notice:

Email: hello@artam.hu

Postal address: 3240 Parád, Peres utca 57.

Phone: +36 70 679 6560

Website: www.artam.hu

  1.      BASIC CONCEPTS OF DATA PROTECTION

2.1.           Personal data:

Any information relating to an identified or identifiable natural person; conclusions about the data subject that can be drawn from the data. Personal data retains this quality during data processing for as long as its connection to the data subject can be reestablished. A person is considered identifiable in particular if they can be identified, directly or indirectly, by reference to a name, an identification number, or one or more factors specific to their physical, physiological, mental, economic, cultural, or social identity.

2.2.            Contribution:

Consent: any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a sign indicating the same, signifies agreement to the processing of personal data relating to him or her;

2.3.            Protest:

A statement by the data subject objecting to the processing of their personal data and requesting the termination of the processing or the erasure of the data processed;

2.4.          Data controller:

The natural or legal person or an organization without legal personality who determines the purposes of the processing of personal data, makes decisions regarding the processing (including the means used) and implements them or has them implemented by a data processor acting on its behalf;

2.5.            Data processing:

Any operation or set of operations performed on personal data, regardless of the procedure used, such as collection, recording, storage, organization, storage, alteration, use, transmission, disclosure, alignment or interconnection, blocking, erasure and destruction, as well as the prevention of further use of the data. Data processing also includes taking photographs, making audio or video recordings, and recording physical characteristics that can be used to identify a person (e.g., fingerprints, palm prints, DNA samples, iris images).

2.6.            Data transfer:

When data is made available to a specific third party.

2.7.            Disclosure:

When data is made accessible to anyone.

2.8.            Data erasure:

The rendering of data unidentifiable in such a way that its restoration is no longer possible.

2.9.          Data blocking:

Preventing the transfer, disclosure, publication, transformation, alteration, destruction, erasure, linking or coordination and use of data permanently or for a specified period of time;

2.10.         Data destruction:

The complete physical destruction of data or the data carriers containing them;

2.11.         Data processing:

The performance of technical tasks related to data processing operations, regardless of the method and means used to perform the operations and the location of the application;

2.12.        Data processor:

A natural or legal person or an organization without legal personality who or which processes personal data on behalf of the data controller, including on the basis of a legal provision;

2.13.          Third party:

A natural or legal person or an organization without legal personality who is not the data subject, the data controller or the data processor;

2.14.         EEA State:

A Member State of the European Union and other states party to the Agreement on the European Economic Area, and any state whose citizens enjoy the same legal status as citizens of a state party to the Agreement on the European Economic Area under an international treaty concluded between the European Community and its member states and a state not party to the Agreement on the European Economic Area;

2.15.         Third country:

Any state that is not an EEA state.

DATA PROTECTION PRINCIPLES:

Personal data:

  1. must be processed lawfully, fairly and in a transparent manner in relation to the data subject (“lawfulness, fairness and transparency”) ;
  2. shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; in accordance with Article 89(1) of the GDPR, processing for archiving purposes in the public interest, further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes (“purpose limitation”);
  3. be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (“data minimization”);
  4. they must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they were collected, are erased or rectified without delay (“accuracy”);
  5. they must be stored in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data shall be stored for longer than that period if the personal data are processed solely for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes in accordance with Article 89(1) of the GDPR (1) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, with the appropriate technical and organizational measures to safeguard the rights and freedoms of the data subject pursuant to this Regulation (“storage limitation”);
  6. processing must be carried out in a manner that ensures appropriate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage (“integrity and confidentiality”).

The data controller is responsible for compliance with the above and must be able to demonstrate such compliance (“accountability”).

DETAILED RULES FOR DATA PROCESSING

Persons with access to the data:

  • the Data Controller’s employees;
  • employees of the Data Processors specified below;
  • certain authorities in the course of official proceedings in relation to data requested by them and which the Data Controller is required by law to disclose;
  • employees of the debt collection company commissioned by the Data Controller for the purpose of managing overdue debts;
  • other persons with the express consent of the Data Subject.

The Data Controller undertakes to maintain strict confidentiality with regard to the personal data it processes, without any time limitation, and may not disclose such data to third parties without the consent of the Data Subject.

The withdrawal of consent does not affect the lawfulness of previous data processing.

  • Data processing related to registration for accommodation booking and the further use of data provided during registration:

In order to use the Data Controller’s services, the Data Subject must complete a registration form. The data processed will be used for further purposes when using certain services.

In the case of online bookings, some of the data is transferred to the Data Controller by the individual accommodation providers and travel agencies during the data transfer process.

The scope of the data processed and the detailed purposes of data processing:

  • Surname: necessary for identification, communication and contract performance
  • First name: necessary for identification, communication and contract performance

Services where this data is used for further purposes: e.g. wellness services, spa visits, welcome cards, transfer services, bicycle rental

  • Citizenship: required for identification and contract fulfillment
  • ID card number or passport number: required for identification and contract fulfillment

Services where this data set is used for other purposes: e.g., bike rental

  • Email address: required for contact purposes
  • Telephone number: required for contact purposes
  • Full address: required for contract fulfillment
  • Billing address: required for contract fulfillment

Services where this data may be used for other purposes: Provision of various accommodation services at the request of the Data Subject

  • Method of payment: required for contract fulfillment
  • Special dietary preferences: to satisfy the Data Subject’s tastes, contract fulfillment
  • Vehicle registration number: required for contract fulfillment
  • Purpose of travel: required for contract fulfillment

For guests from outside the European Union:

  • Passport number: compliance with legal obligations
  • Visa number: compliance with legal obligations
  • Time and place of entry into the country: compliance with legal obligations

Legal basis for data processing

The legal basis for data processing is the performance of a contract (GDPR Article 6(1)(b)), where the processing and transfer of data is required by law (to local authorities, police), in which case it is necessary for compliance with a legal obligation (GDPR Article 6(1)(f)).

Duration of data processing

The data will be anonymized 5 years after the termination of the relationship with the Data Subject, in accordance with Section 6:22 of the Civil Code. We will retain the data for a longer period if required by law, for example, if we are required to retain the data pursuant to Section 169 of Act C of 2000 on Accounting (the “Accounting Act”), we will delete the data 8 years after the termination of the relationship with the Data Subject. In practice, this is the case if the data forms part of the documents supporting the accounting, for example in documents relating to the conclusion of a contract (in some cases in the contract itself) or on the invoice issued, or in the case of a police report, for 8 years.

Data processing related to bank card details:

The Data Subject must provide this information during the bank card payment process in order to secure their booking and its fulfillment.

In the case of online bookings, some of the data is transferred to the Data Controller by the individual accommodation providers or travel agencies during the data transfer process.

Scope of data processed and detailed purposes of data processing:

  • Name on bank card
  • Bank card number
  • Bank card expiry date

Legal basis for data processing

The legal basis for data processing is the performance of a contract (GDPR Article 6(1)(b)).

Duration of data processing

The Data Controller shall process personal data for 8 calendar days after the departure of the data subject.

  • Data processing in connection with the conclusion of contracts with partners

The Data Controller enters into contracts with various partners in order to provide its services and ensure the provision of services.

Scope of data processed and detailed purpose of data processing

  • Surname of personal contributor: necessary for identification, communication, performance of contract
  • First name of personal contributor: necessary for identification, communication, performance of contract
  • Image: necessary for performance of contract (in the case of a contract specifically for photography)
  • Email address: necessary for identification, communication
  • Telephone number: necessary for identification and communication
  • Data relating to legal entities (name, registered office, company registration number, tax number): performance of the contract

 

Legal basis for data processing

The legal basis for data processing is the performance of the contract (GDPR Article 6(1)(b)).

Duration of data processing

The data will be blocked for 5 years after the termination of the relationship with the Data Subject, in accordance with Section 6:22 of the Civil Code. If we are required to retain the data in accordance with Section 169 of Act C of 2000 on Accounting (the “Accounting Act”), we will block the data for 8 years after the termination of the relationship with the Data Subject. In practice, this is the case if the data form part of the documents supporting the accounting, for example in documents relating to the conclusion of a contract (in the contract itself, if applicable) or on the invoice issued.

Data processing related to complaint handling:

The Data Subject has the right to lodge a complaint regarding the service provided by the Data Controller.

Scope of data processed and detailed purpose of data processing

  • Surname: required for identification and communication
  • First name: required for identification and communication
  • Address: required for identification and communication
  • Content of the complaint: for investigating the complaint
  • Email address: necessary for communication
  • Phone number: necessary for communication

 

 

 

Legal basis for data processing:

The legal basis for data processing is Section 17/A(7) of Act CLV of 1997 on consumer protection. (7) of the Act on Consumer Protection.

Duration of data processing

The Data Controller shall process the personal data related to the complaint, the recorded minutes and a copy of the response letter for 5 years from the date of the complaint, in accordance with the provisions of the Consumer Protection Act.

4.5          Data processing related to evaluation

The Data Subject has the opportunity to give an evaluation of the accommodation in question. The evaluation can be completed anonymously, i.e. only for the purpose of evaluation.

Scope of data processed and detailed purpose of data processing

  • Surname: necessary for identification and communication
  • First name: necessary for identification and communication
  • Email address: necessary for identification and communication
  • Date of stay: satisfaction measurement, statistical purposes
  • Accommodation evaluation: satisfaction measurement, statistical purposes

 

Legal basis for data processing

The legal basis for data processing is the consent of the Data Subject (GDPR Article 6(1)(a)).

Duration of data processing

The Data Controller shall process personal data until the Data Subject withdraws their consent. You may withdraw your consent at any time by sending an email to.

4.8.             Newsletter:

The Data Subject has the option to subscribe to the Data Controller’s marketing newsletter. Accordingly, the Data Controller is entitled to send newsletters for direct marketing purposes to Data Subjects who have subscribed to the newsletter to the email address provided – and, where applicable, subsequently modified – at the frequency and with the content determined by the Data Controller, for direct marketing purposes, which contain the Data Controller’s promotions and other information relevant to the Data Controller’s activities.

The Data Controller does not send unsolicited advertising messages, and the Data Subject may unsubscribe from receiving offers free of charge, without restriction or justification. In this case, we will delete all personal data necessary for sending the newsletter from our records and will not contact the Data Subject with further advertising offers. The Data Subject may unsubscribe from the newsletter at any time by clicking on the link in the message.

Scope of data processed and detailed purposes of data processing:

  • Surname: identification, contact
  • First name: identification, contact
  • Email address: we will forward the latest news to you.

Legal basis for data processing

The legal basis for data processing is your consent, and pursuant to Section 6 of Act XLVIII of 2008 on the basic conditions and certain restrictions of economic advertising activities, the Data Subject may give their prior and express consent to the Service Provider contacting them with advertising offers other communications at the contact details provided (e-mail).

Duration of data processing

The Data Controller shall retain personal data until the Data Subject withdraws their consent.

Rights of data subjects in relation to data processing

The data subject may unsubscribe from the newsletter at any time, free of charge.

4.9.             Presence of the Data Controller on social media (Facebook, Instagram, YouTube):

The accommodation operated by the Data Controller is available on Facebook and Instagram.

By clicking on the “like” link on the Data Controller’s Facebook page or the “follow” link on its Instagram page, the data subject consents to the publication of news and offers prepared by the Data Controller on their own Facebook/Instagram message board.

The operators of social media sites are independent data controllers, separate from the Data Controller, and therefore the activities carried out there are covered by data processing documents independent of the Data Controller.

Information on data processing on Facebook and Instagram can be found in the privacy policy and terms of use available on Facebook’s website at www.facebook.com.

4.10.         Data processing related to camera surveillance

The Data Controller carries out camera surveillance on the premises of the accommodation. This is done to protect property, the life and physical integrity of guests and employees, and to ensure quality assurance.

In this context, data processing serves the following purposes in particular:

  • personal protection, protection of life and physical integrity, protection of guests and employees;
  • detection of infringements and proof of infringements in order to protect machinery, tools and equipment of significant value;
  • prevention and detection of infringements, damage, theft and other crimes against property;
  • prevention, interruption and subsequent proof of infringements;
  • in connection with this, the recordings may be used as evidence in court or other official proceedings.

Scope of data processed and detailed purpose of data processing

The purpose of camera surveillance is, in particular:

  1. property protection in relation to property, equipment and devices located in the monitored area, for which monitoring of the area is particularly justified, except where it may violate human dignity;
  • the prevention of accidents occurring in the area
  • the investigation of the circumstances of accidents that have occurred
  • the clarification, investigation and proof of (legal) disputes in the event of quality assurance complaints
  • the investigation of guest complaints.

 

Camera locations

 

Camera location

Area monitored by the camera

Persons present in the monitored area

1

 

 

 

2

 

 

 

3

 

 

 

4

 

 

 

5

 

 

 

6

 

 

 

7

 

 

 

 

Legal basis for data processing

The Data Controller processes personal data in accordance with Article 6(1)(f) of the GDPR, and the processing is justified by the legitimate interest of the Data Controller in protecting the property of guests and the protection of data subjects (employees, guests) present on the premises of the accommodation. The Data Controller has carried out a balancing test to examine the legal basis.

Duration of data processing

The Data Controller shall keep the data for 3 days. In the event of an incident involving personal injury or property damage, the Data Controller is entitled to process the recordings for a period longer than 3 days.

Data processing related to found items:

The purpose of data processing: to administer items found on the premises of the Accommodation operated by the Data Controller and to notify the presumed owner or the finder.

Legal basis for data processing: Sections 5:54, 5:55, 5:59 and 5:61 of Act V of 2013 on the Civil Code.

Scope of data processed: date and place of discovery, name and contact details of the finder, details of the item found.

Duration of data processing: 1 year.

  1.  PERSONS AUTHORIZED TO PROCESS DATA:

The Data Controller uses the data processors listed in the table below to perform technical tasks related to data processing operations. The rights and obligations of the data processor in relation to the processing of personal data are determined by the Data Controller within the framework of the GDPR and the specific laws on data processing. The Data Controller is responsible for the legality of the instructions it gives. The data processor may not make any substantive decisions regarding data processing, may only process personal data that comes to its knowledge in accordance with the provisions of the Data Controller, may not process data for its own purposes, and is obliged to store and retain personal data in accordance with the provisions of the Data Controller.

Names and contact details of data processors

Activities performed during data processing

Duration of data processing

               
Zoboki-Timán Ingrid +36 30 786 0539

Has access to all personal data processed by the Data Controller on the basis of this Notice. Responsible for storing personal data processed by the Data Controller.

Based on an indefinite contract, until the termination of the contract or until 30 days after the data subject’s request for erasure is made to the Data Controller and/or data processor.

Zoboki-Timán Ingrid +36 30 786 0539

Website operation. 

Based on an indefinite contract until the termination of the contract.

Zoboki-Timán Ingrid +36 30 786 0539

Online marketing campaigns related to the www.artam.hu website, search engine optimization, SEO, Google AdWords campaigns related to the www.artam.hu website, Facebook campaigns related to the https:/ website

Based on an indefinite contract until the termination of the contract.


Zoboki-Timán Ingrid +36 30 786 0539

Provision of online room reservation services.

All data provided during the reservation process is stored on their servers. Data is transmitted via a secure HTTPS connection

.

Based on an indefinite contract until the termination of the contract.

Zoboki-Timán Ingrid +36 30 786 0539

Performing customer service tasks when using the PMS system. The service provider’s data protection policy is available at the following link: www.artam.hu

Based on an indefinite contract until the contract is terminated.

Zoboki-Timán Ingrid +36 30 786 0539

Data communication between the merchant and the payment service provider for payment transactions, customer service for users, transaction confirmation and fraud monitoring for user protection. The service provider’s privacy policy is available at the following link:

Based on an indefinite contract until the termination of the contract.

Booking.com B.V.
Székhely: Oosterdokskade 163, 1011 DL, Netherlands

rocessing of data provided during the booking process.

Based on an indefinite contract until the termination of the contract.

Szállás.hu Zrt.
Székhely: 3525 Miskolc, Régiposta utca 9.

rocessing of data provided during the booking process.

Based on an indefinite contract until the termination of the contract.

 Zoboki-Timán Ingrid +36 30 786 0539

Website development and operation. Server hosting tasks

 

Google Ireland Limited
Székhely: Gordon House, Barrow Street, Dublin 4, Ireland,

 

Based on an indefinite contract until the termination of the contract

Facebook/Instagram/ Meta Platforms Ireland Limited
Merrion Road, Dublin 4, Ireland

Social media platforms   

 

OTP Bank Nyrt. 1051 Budapest, Nádor utca 16.

Data communication necessary for payment transactions between the merchant and the payment service provider, customer service support for users, transaction confirmation and fraud monitoring for user protection.

Based on an indefinite contract until the termination of the contract

The Data Controller transfers data to the entities listed in the table below in connection with the services it provides:

Name and contact details of the recipient

Description of the data transfer

VIZA system (Guest Information Closed Database)
Magyar Turisztikai Ügynökség Zrt.
1027 Budapest, Kacsa u. 15-23.; 1525 Budapest, Postafiók 97.; Phone: +36 1 488 8700;
Email: info@mtu.gov.hu;

The Data Controller shall transfer guests’ personal data in the manner prescribed by law, i.e. it shall record them in the VIZA system. The purpose of recording and transferring the data is to protect the rights, safety and property of the data subject and others, and to ensure compliance with the provisions on the residence of third-country nationals and persons enjoying the right of free movement and residence.

NTAK (National Tourism Data Center)
Magyar Turisztikai Ügynökség Zrt.
1027 Budapest, Kacsa u. 15-23.; 1525 Budapest, Postafiók 97.; Phone: +36 1 488 8700;
E-mail: info@mtu.gov.hu;

In the system operated by the MTÜ, data from accommodation management software is analyzed to support data-driven decision-making in the tourism industry. The relevant local authorities and the NAV also have access to the data relevant to them.

Competent authorities (NAV, OEP, local authorities, investigative authorities, counter-terrorism agencies, national security services, the public prosecutor’s office and the courts)

The accommodation provider keeps a register of the arrival and stay of third-country nationals in accordance with the relevant law. These data, as well as other personal data contained in the register and guest book, shall be forwarded to the competent authorities (e.g. police, national security authorities, courts, administrative authorities, public prosecutor’s office) in the cases specified by law (e.g. in the event of a criminal offense or suspicion thereof, or in connection with specific proceedings). A report shall be made in all cases of data transfer or disclosure.

  1. DATA SECURITY MEASURES

The Data Controller shall process the personal data provided by the Data Subject in accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and the Act CXII of 2011 on the right to self-determination and freedom of information.

The Data Controller shall take all necessary measures to ensure the security of the data and shall ensure an appropriate level of protection against unauthorized access, alteration, transmission, disclosure, deletion or destruction, as well as accidental destruction and damage. The Data Controller shall ensure the security of the data by appropriate technical (e.g. logical protection, in particular encryption of passwords and communication channels) and organizational measures (physical protection, in particular data security training for the Data Controller’s employees, restriction of access to information).

Please help us protect your information by not using obvious login names or passwords and by changing your password regularly. Please also do not make your password accessible to other people.

  1. INFORMATION RELATING TO CHILDREN

Persons under the age of 16 may not provide personal data about themselves unless they have obtained permission from a parent or guardian. We do not process the data of persons under the age of 16, or we process it in an anonymized form, if the consent of the legal representative, parent, guardian or custodian cannot be obtained in connection with the data processing.

In the case of Data Subjects under the age of 14, their legal representative or guardian may provide personal data and make legal declarations on their behalf.

Data subjects who are 14 years of age but under 18 years of age may only provide personal data with the consent of their legal representative or guardian and may only make legal declarations with their consent.

By providing the information, you declare and warrant that you will act in accordance with the above and that your legal capacity to provide the information is not restricted. If you are not legally entitled to provide the information, you are required to obtain the consent of the Data Subject’s third parties (e.g., legal representative, guardian). In this regard, you are required to consider whether the consent of a third party is necessary in connection with the provision of the information. The Data Controller may not contact you personally, in which case you are responsible for ensuring compliance with this section, and the Data Controller shall not be held liable in this regard.

We will make every reasonable effort to delete any information that has been made available to us without authorization and to ensure that this information is not disclosed to others or used by us (either for advertising or other purposes). Please notify us immediately if you become aware that a child has provided information about themselves without authorization. You can contact us using the contact details provided at the beginning of this Policy.

  1. RIGHTS OF DATA SUBJECTS IN RELATION TO DATA PROCESSING

The data subject’s data protection rights and remedies, and the relevant provisions and restrictions of the GDPR in this regard, are set out in detail in the GDPR (in particular Articles 15, 16, 17, 18, 19, 20, 21, 22, 77, 78, 79 and 82 of the GDPR). The most important provisions are summarized below.

Right of access by the Data Subject

The Data Subject has the right to obtain confirmation from us as to whether personal data concerning him or her are being processed. If such processing is ongoing, the Data Subject has the right to obtain access to the personal data and the following information:

  • the purposes of the processing;
  • the categories of personal data concerned;
  • the recipients or categories of recipients to whom the personal data have been or will be disclosed, including recipients in third countries or international organizations;
  • where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period;
  • the right of the Data Subject to request from us the rectification or erasure of personal data concerning the Data Subject or the restriction of processing and to object to the processing of such personal data;
  • the right to lodge a complaint with a supervisory authority; and
  • where the data have not been collected from the Data Subject, any available information as to their source;
  • the existence of automated decision-making, including profiling, and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the Data Subject.

 

Where personal data are transferred to a third country, the Data Subject shall have the right to be informed of the appropriate safeguards relating to the transfer.

We will provide the Data Subject with a copy of the personal data undergoing processing. If the Data Subject has submitted the request by electronic means, the information shall be provided in a commonly used electronic format, unless the Data Subject requests otherwise.

Right to rectification

The Data Subject shall have the right to obtain from us the rectification of inaccurate personal data concerning him or her without undue delay. The Data Subject shall have the right to request that incomplete personal data be completed, including by means of providing a supplementary statement.

Right to erasure (“right to be forgotten”)

(1) The Data Subject shall have the right to obtain from us the erasure of personal data concerning him or her without undue delay where one of the following grounds applies:

  • the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
  • The Data Subject withdraws consent on which the processing is based and there is no other legal basis for the processing;
  • The Data Subject objects to the processing and there are no overriding legitimate grounds for the processing;
  • the personal data has been unlawfully processed;
  • the personal data must be erased to comply with a legal obligation in EU or Member State law to which we are subject; or
  • the personal data has been collected in relation to the offering of information society services.

(2) Where the Data Controller has made the personal data public and is obliged to erase it pursuant to paragraph (1), it shall take reasonable steps, taking into account available technology and the cost of implementation, to inform the Data Controller of the erasure, including by means of a notice to the Data Controller, so that the Data Controller can take the steps referred to in paragraph (1). – including technical measures – to inform the data controllers who have received the personal data of the data subject’s request to erase any links to the personal data or copies or reproductions of the personal data.

(3) Paragraphs 1 and 2 shall not apply if the processing is necessary, inter alia:

  • for exercising the right of freedom of expression and information;
  • for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject;
  • for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, insofar as the right referred to in paragraph 1 is likely to render impossible or seriously impair the processing; or
  • for the establishment, exercise or defense of legal claims.

 

Right to restriction of processing

(1) The Data Subject shall have the right to obtain restriction of processing where one of the following applies:

  • The Data Subject contests the accuracy of the personal data, in which case the restriction shall apply for a period enabling us to verify the accuracy of the personal data;
  • the processing is unlawful and the Data Subject opposes the erasure of the personal data and requests the restriction of their use instead;
  • we no longer need the personal data for the purposes of the processing, but they are required by the Data Subject for the establishment, exercise or defense of legal claims; or
  • The Data Subject has objected to the processing; in this case, the restriction applies for a period until it is determined whether the legitimate grounds of the Data Controller override those of the Data Subject.

 

If the processing is restricted pursuant to paragraph (1), such personal data shall, with the exception of storage, only be processed with the consent of the Data Subject or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.

The Data Subject shall be informed in advance of the lifting of the restriction on processing.

Notification obligation regarding rectification or erasure of personal data or restriction of processing

The Data Controller shall inform all recipients to whom the personal data have been disclosed of any rectification, erasure or restriction of data processing, unless this proves impossible or involves disproportionate effort. At the request of the Data Subject, we shall inform the Data Subject of these recipients.

Right to data portability

(1) The Data Subject shall have the right to receive the personal data concerning him or her, which he or she has provided to us, in a structured, commonly used and machine-readable format, and shall have the right to transmit those data to another controller without hindrance from the Controller, where:

  1. a) the processing is based on consent or on a contract; and
  2. b) the processing is carried out by automated means.

Right to data portability When exercising the right referred to in paragraph 1, the Data Subject shall have the right to request the direct transfer of personal data between data controllers, where technically feasible.

Right to object

The Data Subject shall have the right to object, on grounds relating to his or her particular situation, to processing of personal data concerning him or her which is based on legitimate interests, including profiling. In this case, we will no longer process the personal data unless we demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the Data Subject or for the establishment, exercise or defense of legal claims.

Where personal data are processed for direct marketing purposes, the Data Subject shall have the right to object at any time to the processing of personal data concerning him or her for such purposes, including profiling to the extent that it is related to direct marketing.

If the Data Subject objects to the processing of personal data for direct marketing purposes, the personal data shall no longer be processed for such purposes.

In relation to the use of information society services and by way of derogation from Directive 2002/58/EC, the Data Subject may exercise the right to object by means of automated technical devices.

Where personal data are processed for scientific or historical research purposes or for statistical purposes, the Data Subject shall have the right to object to the processing of personal data concerning him or her on grounds relating to his or her particular situation, unless the processing is necessary for the performance of a task carried out for reasons of public interest.

Right to lodge a complaint with a supervisory authority

The Data Subject may enforce his or her rights before a court of law in accordance with the GDPR and the Civil Code, and may also lodge a complaint with the National Authority for Data Protection and Freedom of Information (NAIH) (1055 Budapest, Falk Miksa utca 9-11.; mailing address: 1363 Budapest, Pf.: 9.; telephone: +36 1 391 1400; e-mail: ugyfelszolgalat@naih.hu) in the event of a complaint regarding the data controller’s data processing practices. Detailed rights and remedies relating to data processing are set out in Articles 77, 79 and 82 of the GDPR.

Right to effective judicial remedy against the supervisory authority

The Data Subject has the right to an effective judicial remedy against a legally binding decision of the supervisory authority concerning the Data Subject.

The Data Subject has the right to effective judicial remedy if the competent supervisory authority does not deal with the complaint or does not inform the Data Subject within three months of the progress or outcome of the complaint.

Proceedings against the supervisory authority shall be brought before the courts of the Member State where the supervisory authority has its seat.

Right to effective judicial remedy against the controller or processor

The Data Subject shall have the right to an effective judicial remedy if he or she considers that his or her rights under the GDPR have been infringed as a result of the processing of his or her personal data in breach of the GDPR.

Proceedings against the data controller or data processor shall be brought before the courts of the Member State where the data controller or data processor has its place of business. Such proceedings may also be brought before the courts of the Member State where the data subject has his or her habitual residence.

Before initiating any proceedings, it is recommended that the data subject submit a complaint to the data controller.