Privacy policy
1. Introduction
Soós Csaba EV. (hereinafter Soós Csaba EV., service provider, controller, Company), as data controller, considers the content of this legal notice binding upon itself.
The Company undertakes that every data processing related to its activity complies with the expectations set out in this policy and in the applicable legislation.
Soós Csaba EV. is the operator of the csabafoto.hu website.
Soós Csaba EV. reserves the right to change this notice at any time. Of course it will inform its audience of any changes in good time.
Soós Csaba EV. is committed to protecting the personal data of its clients and partners, and considers it particularly important to respect its clients’ right to informational self-determination. The Controller treats personal data as confidential and takes every security, technical and organisational measure that guarantees the security of the data.
Soós Csaba EV. sets out below its data-processing principles and presents the expectations it has formulated for itself as controller and observes. Its data-processing principles are in line with the applicable data-protection legislation, in particular the following:
- Act CXII of 2011 – on the Right of Informational Self-Determination and on Freedom of Information;
- Act V of 2013 – on the Civil Code (Ptk.);
- Act XLVIII of 2008 – on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities (Grt.).
- Act CVIII of 2001 (Ekertv.) – on certain issues of electronic commerce services and information society services;
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 – on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: “GDPR”)
2. Definitions
- data subject: any specified natural person identified or — directly or indirectly — identifiable on the basis of personal data;
- personal data: data that can be associated with the data subject — in particular the data subject’s name, identification mark, and one or more pieces of knowledge characteristic of their physical, physiological, mental, economic, cultural or social identity — as well as the conclusion that can be drawn from it concerning the data subject;
- consent: the data subject’s voluntary and definite expression of will, based on appropriate information, by which they give unambiguous agreement to the processing of personal data relating to them — in full or covering certain operations;
- controller: the natural or legal person, or organisation without legal personality, who or which, alone or jointly with others, determines the purposes of processing, takes and implements the decisions on processing (including the means used), or has them implemented by the processor;
- processing: regardless of the method used, any operation or set of operations performed on data, in particular collection, recording, organisation, storage, alteration, use, retrieval, transmission, disclosure, alignment or combination, blocking, erasure and destruction, as well as preventing further use of the data, taking a photograph, audio or video recording, and recording physical characteristics suitable for identifying a person (e.g. fingerprint or palm print, DNA sample, iris image);
- transmission: making the data accessible to a specified third party;
- disclosure: making the data accessible to anyone;
- erasure: making the data unrecognisable in such a way that their restoration is no longer possible;
- processing (technical): performing the technical tasks related to processing operations, regardless of the method and means used to carry out the operations and of the place of application, provided that the technical task is performed on the data;
- processor: the natural or legal person, or organisation without legal personality, who or which performs the processing of data on the basis of a contract — including a contract concluded on the basis of a legal provision.
3. Company details
Our company’s details and contact information are as follows:
- Name: Soós Csaba EV.
- Postal address: Hungary, 4600 Kisvárda, Attila utca 41.
- Registration number: 57941161
- Tax number: 59893545-1-35
- Phone number: +36 30 283 4064
- E-mail: soomy007@gmail.com
- Representative of the controller: Soós Csaba
4. Scope of personal data, purpose, legal basis and duration of processing
We draw the attention of those providing data to Soós Csaba EV. that if they do not provide their own personal data, it is the provider’s duty to obtain the data subject’s consent. The controller is not obliged to examine whether this exists. The controller draws the partner’s attention to the fact that if they fail to fulfil this obligation and the data subject asserts a claim against the controller, the controller may pass the asserted claim and the related amount of damage on to the partner.
We provide the following information in connection with our individual processing operations.
4.1. Quote request, enquiry by direct contact
Interested parties may contact our Company directly by electronic mail sent to the Company’s address, or by phone.
- Purpose of processing: keeping in contact in order to promote communication between the data subject and our Company and the closest and most efficient cooperation possible.
- Legal basis of processing: legitimate interest — GDPR Article 6(1)(f)
- Scope of personal data processed: name of the person requesting a quote / contact person; e-mail address, phone number and other information provided by the data subject,
- Duration of processing: for 3 years after the validity period of the quote, or until the data subject objects
- Recipients of personal data: The controller does not transfer the data learnt to any third party except the processor(s) indicated in section 7. The recorded data may be known only by the Controller’s employees and the designated colleagues of the processor(s).
- Indication of the legitimate interest: our Company’s legitimate interest is the processing of the data subject’s data — direct marketing
- Circle of data subjects: partners and data subjects enquiring directly (e.g. by e-mail or phone) about the Company’s services.
4.2. Quote request, enquiry via the website (csabafoto.hu)
Our company provides the opportunity for data subjects to request a quote electronically.
- Purpose of processing: keeping in contact in order to promote communication between the data subject and our Company and the closest and most efficient cooperation possible.
- Legal basis of processing: the data subject’s voluntary consent — GDPR Article 6(1)(a).
- Scope of personal data processed: enquirer’s name (first name, last name); e-mail address, phone number, company name and other information provided by the data subject.
- Duration of processing: for 3 years after the validity period of the quote, or until consent is withdrawn.
- Recipients of personal data: The controller does not transfer the data learnt to any third party except the processor(s) indicated in section 7. The recorded data may be known only by the Controller’s employees and the designated colleagues of the processor(s).
- Circle of data subjects: partners and data subjects enquiring via the website about the Company’s services and products.
4.3. Processing related to follow-up of a quote request
- Purpose of processing: the controller’s legitimate interest in keeping the data subject’s data on record beyond the quote validity period for the purpose of direct marketing
- Legal basis of processing: the controller’s legitimate interest, GDPR Article 6(1)(f),
- Scope of personal data processed: contact person’s last name and first name; phone number; e-mail address
- Recipients of personal data: The controller does not transfer the data learnt to any third party except the processor(s) indicated in section 7. The recorded data may be known only by the Controller’s employees and the designated colleagues of the processor(s).
- Duration of processing: until the data subject objects
- Indication of the legitimate interest: establishing business relations with partners and persons requesting quotes, accurate information and notification towards the data subjects. Our Company’s legitimate interest is the processing of the data subject’s data — direct marketing
- Circle of data subjects: addressees of quotes previously issued by the Company and the contact person(s) named in them.
4.4. Camera system
Cameras operate on the premises operated by the controller for the personal and property security of the data subjects and for other purposes. Information signs draw the data subjects’ attention to their operation. The activities related to operating the camera system are set out in the premises’ “Property-protection camera data-processing notice”, which is available on the premises.
4.5. Processing related to ensuring the operation of information-technology services
- Purpose of processing: Soós Csaba EV. may use so-called “cookies” (temporary markers) on its websites, which make it possible to enter them more quickly. By “cookies” we mean an information datum that is active only during the individual client session and that is placed on the Client’s computer from the website for faster identification. The Client may always request that cookies be switched off by modifying the browser settings; however, this switch-off may slow down or prevent access to some parts of the site and the use of certain functions.
The session cookies used avoid the need to resort to other IT tools that are potentially harmful to the confidentiality of clients’ navigation and do not make it possible to obtain identifying personal data.
The user can delete the cookie from their own computer, and can disable the use of cookies in their browser. Cookies can generally be managed in the Tools/Settings menu of browsers, under Privacy settings, under the name cookie or süti. - Legal basis of processing: The data subject’s (User’s) voluntary consent, GDPR Article 6(1)(a).
The User gives voluntary consent to processing by accepting the pop-up notice and statement at the start of browsing the site, or by continuing to browse.
Scope of personal data processed: information-technology processing covers the data needed for the operation of the “cookies” used to operate the site and for the use of log files applied by the web hosting provider. - Duration of processing: until the session is closed
- Recipients of personal data: The controller does not transfer the data learnt to any third party except the processor(s) indicated in section 7. The recorded data may be known only by the Controller’s employees and the designated colleagues of the processor(s).
- Circle of data subjects: every User visiting the site, regardless of whether they use the services available on the site.
5. Other processing
We provide information about processing operations not listed in this notice at the time the data is collected. We inform our clients that certain authorities, bodies performing public tasks and courts may contact our company for the purpose of disclosing personal data. Our company discloses personal data to these bodies — provided the body concerned has indicated the exact purpose and the scope of the data — only in the amount and to the extent that is indispensably necessary to achieve the purpose of the request, and if fulfilment of the request is prescribed by law.
6. Transfer of personal data to a third country or an international organisation
Our Company does not transfer your above personal data to a third country or to an international organisation.
7. Information on the use of a processor
In the course of processing the controller transfers the data to the processor(s) contracted with it for performance of the contract.
Categories of recipients: system-administration provider, accounting and payroll provider, server hosting, web hosting provider
8. Children
Our services are not intended for persons under 16, and we ask that persons under 16 do not provide Personal data to the Controller.
If we become aware that we have collected personal data from a child under 16 — except for processing of data pursuant to legal requirements — we take the steps necessary to delete the data as soon as possible.
9. Automated decision-making
Our Company does not apply automated decision-making in its processing procedures or data collection.
10. Method of storing personal data, security of processing
Our company’s IT systems and other data-storage locations are at the registered office and on servers provided by the processor. For processing personal data our company selects and operates the IT tools used in providing the service so that the processed data:
- is accessible to those authorised to access it (availability);
- its authenticity and authentication are ensured (authenticity of processing);
- its unchanged state can be verified (data integrity);
- is protected against unauthorised access (confidentiality of data).
We pay particular attention to the security of the data, and we also take the technical and organisational measures and establish the procedural rules needed to enforce the GDPR guarantees. We protect the data with appropriate measures in particular against unauthorised access, alteration, transmission, disclosure, erasure or destruction, as well as accidental destruction, damage, and becoming inaccessible due to a change in the technology applied.
The IT system and network of our company and our partners are equally protected against computer-assisted fraud, computer viruses, computer break-ins and attacks leading to denial of service. The operator also provides for security with server-level and application-level protection procedures. Daily backup of the data is in place. To avoid data-protection incidents our company takes every possible measure; if such an incident occurs — according to our incident-management policy — we act immediately to minimise the risks and avert the damage.
11. Rights of data subjects, remedies
The data subject may request information about the processing of their personal data, and may request rectification of their personal data, and — except for mandatory processing — erasure or withdrawal, and may exercise their right to data portability and to object in the manner indicated at the time of data collection, or at the controller’s contact details above.
The data subject’s rights and remedies have been determined and communicated to data subjects on the basis of Act CXII of 2011 and EU Regulation 2016/679.
The right to information, or the data subject’s “right of access”: On the basis of Act CXII of 2011 and Article 15 of EU Regulation 2016/679, at the data subject’s request the Controller provides information
- about the data it processes and the categories of personal data,
- about the purpose of processing,
- about the legal basis of processing,
- about the duration of processing,
- where applicable about the duration of storage of the data, or if this is not possible, about the criteria for determining that duration,
- where applicable if the data were not collected from the data subject, about all available information as to their source,
- where applicable about automated decision-making, including profiling, and meaningful information about the logic involved and about the significance of such processing, and
- what the expected consequences are for the data subject,
- about the processor’s data, if a processor was used, i. about the circumstances, effects of the data-protection incident and the measures taken to avert it, and
- in the event of transfer of the data subject’s personal data, about the legal basis, purpose and recipient of the transfer.
The information is free of charge if the person requesting information has not yet submitted an information request covering the same data set to the Controller in the current year. In other cases a cost reimbursement may be established. Cost reimbursement already paid must be refunded if the data were processed unlawfully, or if the request for information led to rectification.
The Controller draws the data subjects’ attention to the fact that information must be refused on the basis of Act CXII of 2011,
- if on the basis of an act, an international treaty or a binding legal act of the European Union the Controller receives personal data in such a way that the transferring controller indicates, at the same time as the transfer, a restriction of the rights of the data subject of the personal data provided in the named act, or another restriction of processing.
- in the interest of the state’s external and internal security, thus national defence, national security, the prevention or prosecution of criminal offences, the security of the execution of sentences, and also for a state or municipal economic or financial interest, a significant economic or financial interest of the European Union, and for the purpose of preventing and uncovering disciplinary and ethical offences related to the practice of professions, and labour-law and occupational-safety breaches of duty — including in every case inspection and supervision as well — and also in the interest of protecting the rights of the data subject or of others.
The Controller is obliged to notify the National Authority for Data Protection and Freedom of Information of refused information requests annually by 31 January of the year following the year in question.
The right to rectification: The data subject is entitled to obtain from the Controller without undue delay the rectification of inaccurate personal data concerning them. Taking into account the purposes of the processing, the data subject is entitled to have incomplete personal data completed, including by means of providing a supplementary statement. At the same time, if the personal data does not correspond to reality, and the personal data corresponding to reality is available to the Controller, the Controller is obliged to rectify the personal data even without the data subject’s request.
The right to erasure, or the “right to be forgotten”: The data subject is entitled to obtain from the Controller the erasure of personal data concerning them without undue delay, and the Controller is obliged to erase personal data concerning the data subject without undue delay if mandatory processing does not preclude it.
Besides the above case the Controller is obliged to erase the data on the basis of Act CXII of 2011 and Regulation (EU) 2016/679 of the European Parliament and of the Council if
- the processing of the data is unlawful;
- the data is incomplete or incorrect — and this state cannot be remedied lawfully — provided that erasure is not precluded by law;
- the purpose of processing has ceased, or the statutory deadline for storing the data has expired;
- it was ordered by the court or the Authority.
- the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
- the data subject objects to the processing and there is no overriding legitimate ground for the processing;
- the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the Controller is subject;
- the personal data have been collected in relation to the offer of information society services referred to in Article 8(1) of EU Regulation 2016/679 offered directly to a child.
If the Controller has made the personal data public and is obliged to erase it as above, taking account of available technology and the cost of implementation it takes reasonable steps — including technical measures — to inform other controllers processing the data that the data subject has requested the erasure of any links to, or copy or replication of, those personal data.
The Controller draws the data subjects’ attention to the limitations of the right to erasure or the “right to be forgotten” arising from the EU regulation, which are as follows:
- exercising the right of freedom of expression and information;
- compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- public interest in the area of public health;
- archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) of EU Regulation 2016/679, in so far as the right to erasure is likely to render impossible or seriously impair that processing; or
- the establishment, exercise or defence of legal claims.
The right to restriction of processing, or the right to blocking: The data subject is entitled to obtain from the Controller restriction of processing.
If on the basis of the information available it may be assumed that erasure would harm the data subject’s legitimate interests, the data must be blocked. Personal data blocked in this way may be processed only until the processing purpose that precluded erasure of the personal data exists.
If the data subject contests the accuracy or correctness of the personal data, but the incorrectness or inaccuracy of the contested personal data cannot be established clearly, the data are blocked. In this case the restriction relates to the period enabling the Controller to verify the accuracy of the personal data.
On the basis of the EU regulation the data must be blocked if
- the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead;
- the Controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims; or
- the data subject has objected to processing; in this case the restriction relates to the period until it is established whether the Controller’s legitimate grounds override those of the data subject.
Where processing has been restricted (blocked), such personal data shall, with the exception of storage, only be processed with the data subject’s consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.
The Controller hereby specifically draws the data subjects’ attention to the fact that the data subject’s right to rectification, erasure and blocking may be restricted by law in the interest of the state’s external and internal security, thus national defence, national security, the prevention or prosecution of criminal offences, the security of the execution of sentences, and also for a state or municipal economic or financial interest, a significant economic or financial interest of the European Union, and for the purpose of preventing and uncovering disciplinary and ethical offences related to the practice of professions, and labour-law and occupational-safety breaches of duty — including in every case inspection and supervision as well — and also in the interest of protecting the rights of the data subject or of others.
The Controller informs the data subject without undue delay, at most within 30 days of receipt of the request, of what was specified in the request, and/or rectifies the data, and/or erases and/or restricts (blocks) the data, or takes other steps in accordance with the request, if there is no excluding reason.
The Controller notifies the data subject in writing of the rectification, of the erasure, of the restriction of processing having taken place, and also all those to whom the data were previously transferred or disclosed for the purpose of processing. At the data subject’s request the Controller informs them of these recipients. Notification may be omitted if, having regard to the purpose of processing, it does not harm the data subject’s legitimate interest, or if information proves impossible or would involve a disproportionate effort. The Controller is also obliged to notify the data subject in writing if the data subject’s exercise of rights cannot take place for some reason, and is obliged to indicate precisely the factual and legal reason, as well as the remedies open to the data subject: the possibility of turning to the court and to the National Authority for Data Protection and Freedom of Information.
The “right to data portability”: The data subject is entitled
- to receive the personal data concerning them, which they have provided to the Controller, in a structured, commonly used and machine-readable format, and also entitled
- to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where:
- the processing is based on consent; and
- the processing is carried out by automated means.
In exercising the right to data portability the data subject is entitled to have the personal data transmitted directly from one controller to another, where technically feasible.
Having regard to the processing carried out by the Controller, the conditions for exercising the right to data portability are not met (there is no automated processing), therefore the data subject cannot exercise this right.
The right to object: The data subject may object to processing of their personal data — including profiling — if
- processing (transfer) of the personal data is necessary solely for the enforcement of the right or legitimate interest of the Controller or the data recipient, except in the case of mandatory processing;
- the use or transfer of the personal data takes place for the purpose of direct marketing, public-opinion research or scientific research;
- the exercise of the right to object is otherwise permitted by law.
The data subject may also object on the basis of Article 21(3) of EU Regulation 2016/679 to processing of personal data for the purpose of direct marketing; in that case the personal data may no longer be processed for this purpose.
Where personal data are processed for scientific or historical research purposes or statistical purposes, the data subject, on grounds relating to their particular situation, is entitled to object to processing of personal data concerning them, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
The Controller — with simultaneous suspension of processing — examines the objection within the shortest time after submission of the request, but at most within 30 days, and informs the applicant of the result in writing. If the applicant’s objection is well founded, the Controller terminates processing — including further data collection and transfer — and blocks the data, and notifies of the objection and of the measures taken on the basis of it all those to whom the personal data affected by the objection were previously transferred, and who are obliged to take measures to enforce the right to object.
If the data subject does not agree with the Controller’s decision, or the Controller misses the referenced deadline, they are entitled — within 30 days of its communication — to turn to the court.
The data subject has the right to object in connection with automated decision-making.
Judicial enforcement: In the event of a violation of their rights the data subject may turn to the court. The court proceeds out of turn in the matter. It is the Controller’s duty to prove that the processing complies with the provisions of the law.
In the event of a violation of their right to informational self-determination they may lodge a report or complaint with:
National Authority for Data Protection and Freedom of Information
Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
Phone: +36 (1) 391-1400, Fax: +36 (1) 391-1410
www: http://www.naih.hu
e-mail: ugyfelszolgalat@naih.hu