Privacy Policy
Dear Visitors!
We place great emphasis on protecting personal data. This naturally also applies when you use our online booking system, subscribe to a promotional offer or prize draw, or simply send us an email. We would therefore like to explain the data processing and data handling procedures we apply in connection with the provision of our services, our online booking system and our newsletter. Below, we
inform you about the measures we take to protect your data, as well as which data we record and for what purposes.
- Website operator: Fort-Bau Zrt.
- Registered office: 1074 Budapest, Dohány u. 29.
- Place of business: H-3176 Hollókő, Sport út 14.
- Postal address: H-3176 Hollókő, Sport út 14.
- Telephone: +36 21 3000 500
- Email: castellum@hotelholloko.hu
Introduction
Fort-Bau Zrt., the operator of Castellum Hotel Hollókő**** (hereinafter referred to as the service provider, data controller or Hotel), acting as data controller, acknowledges the contents of this legal notice as binding upon itself.
Fort-Bau Zrt. reserves the right to amend this notice at any time. Naturally, it will inform the public of any changes in due time.
Fort-Bau Zrt. is committed to protecting the personal data of its guests and partners and considers respect for its customers’ right to informational self-determination to be of paramount importance. The Data Controller treats personal data confidentially and implements all security, technical and organisational measures required to guarantee data security.
Below, Fort-Bau Zrt. describes its data processing principles and presents the requirements it has established for itself as a data controller and with which it complies. Its data processing principles are consistent with the applicable data protection legislation, in particular the following:
- Act CXII of 2011 on Informational Self-Determination and Freedom of Information;
- Act V of 2013 on the Civil Code;
- Act C of 2000 on Accounting;
- Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities;
- Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services;
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: “GDPR”)
1. Definitions
- data subject: any identified natural person, or any natural person who can be identified directly or indirectly on the basis of personal data;
- personal data: any data relating to the data subject, in particular the data subject’s name, identification mark and one or more factors specific to their physical, physiological, mental, economic, cultural or social identity, as well as any conclusion relating to the data subject that can be drawn from such data;
- consent: the voluntary and explicit expression of the data subject’s wishes, based on appropriate information, by which the data subject gives unambiguous agreement to the processing of personal data relating to them, either in full or for specific operations;
- data controller: the natural or legal person, or organisation without legal personality, which, alone or jointly with others, determines the purposes of processing, makes and implements decisions concerning processing, including the means used, or has such decisions implemented by a data processor;
- data processing: any operation or set of operations performed on data, irrespective of the procedure used, including in particular collection, recording, registration, organisation, storage, alteration, use, retrieval, transmission, disclosure, alignment or combination, restriction, erasure and destruction, as well as preventing further use of the data, taking photographs or making audio or video recordings, and recording physical characteristics suitable for identifying a person, such as fingerprints, palm prints, DNA samples or iris images;
- data transfer: making data accessible to a specified third party;
- disclosure: making data accessible to anyone;
- data erasure: rendering data unrecognisable in such a way that it can no longer be restored;
- data processing activities: carrying out technical tasks related to data processing operations, irrespective of the method and means used to perform the operations and the place of application, provided that the technical task is performed on the data;
- data processor: the natural or legal person, or organisation without legal personality, which processes data under a contract, including a contract concluded pursuant to a statutory provision.
2. Company details
Our company details and contact information are as follows:
- Name: Fort-Bau Zrt.
- Registered office: 1074 Budapest, Dohány u. 29.
- Company registration number: 01-10-140991
- Tax number: 28763291-2-42
- Actual place of data processing: 3176 Hollókő, Sport út 14.
- Telephone number: +36 21 3000 500
- Email: castellum@hotelholloko.hu,
fortbau@toldinet.hu - Representative of the Data Controller: Kovács József, Chief Executive Officer
- Data Protection Officer: Végh Mónika, fortbau@toldinet.hu
3. Categories of personal data, purpose, legal basis and duration of processing
We draw the attention of persons providing data to Fort-Bau Zrt. to the fact that, if they provide personal data belonging to another person, it is their responsibility to obtain the consent of the data subject.
We provide the following information regarding our individual data processing activities.
3.1. Requests for quotations and enquiries via the website
Our company enables guests to request a quotation electronically. Quotations are generated through an automated system, taking available capacity into account.
Purpose of data processing:
Maintaining contact and facilitating communication between the data subject and our Hotel in order to support closer and more effective cooperation.
The legal basis for data processing: the data subject’s voluntary consent – Article 6(1)(a) GDPR
Categories of personal data processed: name of the enquirer; email address; telephone number; planned arrival and departure dates; number of rooms; and any other information provided by the data subject
Duration of data processing: 2 years after the validity period of the quotation expires
Recipients of personal data: The Data Controller does not disclose the data obtained to third parties, except for the data processor(s) specified in Section 8. The recorded data may be accessed only by employees of the Data Controller and designated employees of the data processor(s).
Categories of data subjects affected by the processing:
Partners and data subjects making enquiries via the website in connection with the Hotel’s services.
3.2. Requests for quotations and enquiries made directly
Interested parties may contact our Hotel directly by sending an email to castellum@hotelholloko.hu or by telephone.
Purpose of data processing:
Maintaining contact and facilitating communication between the data subject and our Hotel in order to support closer and more effective cooperation.
The legal basis for data processing: legitimate interest – Article 6(1)(f) GDPR
Categories of personal data processed: name of the contact person; email address; telephone number; and any other information provided by the data subject
Duration of data processing: until the data subject objects or until the purpose of processing has been achieved
Recipients of personal data: The Data Controller does not disclose the data obtained to third parties, except for the data processor(s) specified in Section 8. The recorded data may be accessed only by employees of the Data Controller and designated employees of the data processor(s).
Identification of the legitimate interest: our Hotel has a legitimate interest in processing the data provided by the data subject for direct marketing purposes
Possible consequences of failing to provide data: Communication between the data subject and the Hotel may be impossible or limited.
Categories of data subjects affected by the processing:
Partners and data subjects making direct enquiries about the Hotel’s services, for example by email or telephone.
3.3. Newsletter
Purpose of data processing: sending email newsletters containing commercial advertising to interested parties and providing information about current news and updates
Legal basis for data processing: the data subject’s prior, voluntary consent, Article 6(1)(a) GDPR,
Categories of personal data processed: name and email address
Duration of data processing: until the voluntary consent is withdrawn or the data subject unsubscribes from the newsletter
Our Hotel processes the data you provide until you withdraw your consent. Following withdrawal, the processed data will be deleted from our newsletter database within no more than 10 days, after which we will no longer send you newsletters.
Recipients of personal data: The Data Controller does not disclose the data obtained to third parties, except for the data processor(s) specified in Section 7. The recorded data may be accessed only by employees of the Data Controller and designated employees of the data processor(s).
You may unsubscribe from the newsletter at any time by sending a message to our Hotel at castellum@hotelholloko.hu or by clicking the unsubscribe icon in the newsletter.
Categories of data subjects affected by the processing:
Partners and data subjects who subscribe to the Hotel’s electronic newsletter.
Details of the data processor:
Name of the data processor: MORGENS Design Kft.
Address of the data processor: 8800 Nagykanizsa, Magyar utca 79.
Purpose of processing carried out on behalf of the Data Controller: providing the Data Controller with storage space for the closed, online Zadír MailR system, protected by a username and password, on the servers of Tárhely.Eu Szolgáltató Kft. (1144 Budapest, Ormánság utca 4., 10th floor, unit 241), for the account specified by the Data Controller, for the purpose of sending newsletters
Name of the data processor: Mailgun Technologies, Inc.
Address of the data processor: 535 Mission St., 14th Floor, San Francisco, California 94105
Purpose of processing carried out on behalf of the Data Controller: providing an electronic mail delivery function via the mail servers of Mailgun Technologies, Inc. for the purpose of sending newsletters
Recipients of the data: the company; the company’s employees; and persons engaged for the performance of the contract, including the enforcement of claims arising from the contract;
Transfer of data to a third country or international organisation: yes
Automated decision-making / profiling: no
Rights of the data subject: The data subject may request access to, rectification or erasure of personal data concerning them, or restriction of its processing, may object to the processing of such personal data, and has the right to data portability. Where processing is based on consent, the data subject has the right to withdraw consent at any time, without affecting the lawfulness of processing carried out on the basis of consent before its withdrawal.
Possible consequences of failing to provide data: the data subject will not be able to use the service provided by the company
Complaint to a supervisory authority: A complaint may be submitted in accordance with the Privacy Notice and Data Processing Policy.
For any question, comment or problem relating to data processing, you may contact the Data Controller using the contact details provided above.
If the data subject’s rights are infringed, the data subject may bring legal proceedings.
The data subject may also submit a complaint concerning data processing directly to the Hungarian National Authority for Data Protection and Freedom of Information (address: 1055 Budapest, Falk Miksa utca 9–11; telephone: +36-1-391-1400; email: ugyfelszolgalat@naih.hu; website: www.naih.hu).
3.4. Requests for quotations and room bookings via Partner Sites
Data subjects may also book a room at Castellum Hotel Hollókő**** through Partner Sites.
Purpose of data processing: facilitating and improving the efficiency of accommodation bookings.
Legal basis for data processing: performance of a contract / order – Article 6(1)(b) GDPR;
The Hotel regards a room booking made through a Partner Site as part of the process of concluding the contract.
Categories of personal data processed: surname and first name; residential address (country, postcode, city, street and house number); telephone number; email address; number and age of children; planned arrival and departure dates; and any other information provided by the data subject.
Duration of data processing: two years following performance of the contract, calculated from the final day of the stay stated in the booking.
Recipients of personal data: The Data Controller does not disclose the data obtained to third parties, except for the data processor(s) specified in Section 7. The recorded data may be accessed only by employees of the Data Controller and designated employees of the data processor(s).
Categories of data subjects affected by the processing:
Data subjects who make room bookings through the Hotel’s Partner Sites.
Possible consequences of failing to provide data: The contract cannot be concluded and the booking cannot be made between the data subject and the Hotel.
3.5. Online room booking
Our company offers online accommodation booking so that you can reserve a room at Castellum Hotel Hollókő**** quickly, conveniently and without additional booking charges.
Purpose of data processing: facilitating accommodation bookings and making them more efficient and free of additional booking charges.
Legal basis for data processing: performance of a contract / order – Article 6(1)(b) GDPR;
The Hotel regards an online room booking as part of the process of concluding the contract.
Categories of personal data processed: surname and first name; residential address (country,
postcode, city, street and house number); telephone number; email address; number and age of children; planned arrival and departure dates; and any other information provided by the data subject.
Duration of data processing: two years following performance of the contract, calculated from the final day of the stay stated in the booking.
Recipients of personal data: The Data Controller does not disclose the data obtained to third parties, except for the data processor(s) specified in Section 7. The recorded data may be accessed only by employees of the Data Controller and designated employees of the data processor(s).
The categories of data subjects affected by the processing:
Data subjects who make room bookings through the Hotel’s website.
Possible consequences of failing to provide data: The contract cannot be concluded and the booking cannot be made between the data subject and the Hotel.
3.6. Check-in and the registration form / guest and tourism register
Purpose of data processing:
Upon arrival and before occupying the booked and confirmed room, the data subject completes a registration form.
The Data Controller processes the data specified below in order to fulfil and demonstrate compliance with its obligations under the applicable legislation, in particular legislation relating to immigration control and tourism tax, and to identify the data subject.
Legal basis for data processing: legal obligation under Section 166(1) of Act C of 2000 and the data subject’s voluntary consent – Article 6(1)(c) and Article 6(1)(a) GDPR.
Categories of personal data processed:
- surname and first name,
- residential address
- nationality (processed solely for statistical purposes in a manner that cannot be traced back to the individual)
- telephone number
- email address
- place and date of birth
- identity card / passport number
- vehicle registration number
- method of payment
- signature
- newsletter subscription
The processing of the following data concerning third-country nationals is required by law:
- surname and first name,
- name at birth
- place and date of birth
- mother’s maiden name
- residential address
- sex
- identification details of the travel document (passport)
- address of the accommodation,
- start and end dates of the use of the accommodation
- visa or residence permit number,
- date and place of entry
Third-country national: any person other than a Hungarian citizen who is not a national of a Member State of the European Economic Area, including stateless persons.
Member States of the EEA:
- Member States of the European Union,
- Iceland, Liechtenstein and Norway as participating states,
- and Switzerland as a state with equivalent status.
Duration of data processing: for data required by law, 5 years from the date of collection; for newsletter data, until deletion at the data subject’s request; for other data, until the limitation period expires for enforcing the rights and obligations arising from the legal relationship in connection with which the Data Controller processes the personal data; and for data included in documents supporting accounting records, at least 8 years pursuant to Section 169(2) of Act C of 2000.
Recipients of personal data: The Data Controller does not disclose the data obtained to third parties, except for the data processor(s) specified in Section 7. The recorded data may be accessed only by employees of the Data Controller and designated employees of the data processor(s).
Possible consequences of failing to provide data: The contract cannot be concluded between the data subject and the Hotel. Providing the data is a fundamental condition for the conclusion of the contract.
Categories of data subjects affected by the processing:
All natural persons who check in at the Hotel operated by the Data Controller by providing their personal data and completing a registration form.
By providing an email address on the registration form, guests may subscribe to the Hotel’s newsletter. In all other respects, the provisions of Section 3.3 apply to the newsletter.
3.7. Data processing related to guest satisfaction surveys
As a Hotel, our aim is to provide our guests with high-quality services, and we therefore regularly request feedback about their experiences during their stay.
Purpose of data processing:
Requesting feedback from hotel guests in order to further develop and improve our services.
The legal basis for data processing: legitimate interest – Article 6(1)(f) GDPR
Categories of personal data processed: name, sex, email address and any other information provided by the data subject
Duration of data processing: until the data subject objects, or until two years after the final day of the stay
stated in the booking.
Recipients of personal data: The Data Controller does not disclose the data obtained to third parties, except for the data processor(s) specified in Section 8. The recorded data may be accessed only by employees of the Data Controller and designated employees of the data processor(s).
Identification of the legitimate interest: our Hotel has a legitimate interest in processing the data provided by the data subject, as feedback provides information that helps us develop our services.
Categories of data subjects affected by the processing:
Data subjects who participate in the Hotel’s guest satisfaction survey.
3.8. Issuing invoices where the data subject is a natural person
Purpose of data processing: issuing an invoice to the person responsible for payment and complying with statutory requirements
Legal basis for data processing: legal obligation under Section 166(1) of Act C of 2000
Categories of personal data processed:
- name of the person responsible for payment
- billing address
- invoice amount
- services invoiced
Duration of data processing: until the expiry of the period specified in the Accounting Act – Section 169(2) of Act C of 2000
Possible consequences of failing to provide data: Providing the data is a condition for the conclusion of the contract.
Recipients of personal data: The Data Controller does not disclose the data obtained to third parties, except for the data processor(s) specified in Section 7. The recorded data may be accessed only by employees of the Data Controller and designated employees of the data processor(s).
Categories of data subjects affected by the processing:
Data subjects for whom the Data Controller issues an invoice.
3.9. CCTV system
Cameras are operated on the premises of the Hotel managed by the Data Controller to protect the personal safety and property of data subjects and for other purposes.
Information signs draw the attention of data subjects to the operation of the cameras.
Activities relating to the operation of the CCTV system are set out in the Hotel’s CCTV Privacy Notice for the Protection of Persons and Property, which is available at the Hotel reception.
3.10. Data processing related to the operation of information technology services – cookie management
To provide a personalised service, the Data Controller places a small data file, known as a cookie, on the user’s computer and reads it during subsequent visits. If the browser returns a previously stored cookie, the service provider managing the cookie can link the user’s current visit to previous visits, but only in relation to its own content.
Purpose of data processing: identifying, tracking and distinguishing users; identifying the user’s current session; storing data provided during the session; preventing data loss; performing web analytics measurements; and providing a personalised service.
Legal basis for data processing: the voluntary consent of the data subject (User), Article 6(1)(a) GDPR.
The User gives voluntary consent to data processing by accepting the notice and declaration displayed when browsing begins, or by continuing to browse the website.
Categories of data processed: identification number, date, time and the previously visited page.
Duration of data processing: maximum 90 days
Further information about data processing: Users can delete cookies from their own computers or disable the use of cookies in their browsers. Cookie settings can generally be managed in the browser’s Tools/Settings menu, under Privacy/History/Custom settings, using options labelled cookie, cookies or tracking.
Possible consequences of failing to provide data: the services displayed on the website may become unavailable.
Recipients of personal data: The Data Controller does not disclose the data obtained to third parties, except for the data processor(s) specified in Section 7. The recorded data may be accessed only by employees of the Data Controller and designated employees of the data processor(s).
Categories of data subjects affected by the processing:
All Users who visit the website, irrespective of whether they use any of the services available on it.
4. Other data processing activities
Information about data processing activities not listed in this notice will be provided when the data is collected. We inform our customers that certain authorities, public bodies and courts may contact our company to request the disclosure of personal data. Where the requesting body specifies the precise purpose and scope of the data requested, our company will disclose only the personal data that is strictly necessary to fulfil the purpose of the request and only where compliance is required by law.
5. Children
Our services are not intended for persons under the age of 16, and we ask persons under 16 not to provide Personal Data to the Data Controller. If we become aware that we have collected personal data from a child under the age of 16, we will take the necessary steps to delete the data as soon as possible.
6. Transfer of personal data to a third country or international organisation
Our Hotel does not directly transfer the personal data described above to any third country or international organisation.
7. Information on the use of data processors
During data processing, the Data Controller transfers data to data processor(s) contracted by it where this is necessary for the performance of the contract.
Categories of recipients: accounting/bookkeeping service provider, IT system operator, web hosting provider, system administration service provider and online booking system provider
The data processors used are recorded in the Hotel’s internal register.
8. Method of storing Personal Data and data security
Our company’s IT systems and other data storage locations are situated at its registered office and on servers provided by the data processor. Our company selects and operates the IT equipment used to process personal data in connection with the provision of its services in a manner that ensures that the processed data:
a) is accessible to authorised persons (availability);
b) has guaranteed authenticity and authentication (authenticity of data processing);
c) has verifiable integrity (data integrity);
d) is protected against unauthorised access (confidentiality of data).
We pay particular attention to data security and implement the technical and organisational measures and procedural rules required to give effect to the safeguards set out in the GDPR. In particular, we protect data by appropriate measures against unauthorised access, alteration, transfer, disclosure, erasure or destruction, accidental destruction or damage, and against becoming inaccessible as a result of changes in the technology used.
The IT systems and networks of our company and our partners are protected against computer-assisted fraud, computer viruses, unauthorised access and denial-of-service attacks. The operator also ensures security through server-level and application-level protection procedures. Daily data backups are in place. Our company takes every possible measure to prevent personal data breaches. If such a breach occurs, we act immediately in accordance with our incident management policy to minimise risks and prevent or mitigate damage.
9. Rights of data subjects and available remedies
The data subject may request information about the processing of their personal data and may request the rectification or, except where processing is mandatory, the erasure or withdrawal of their personal data,
and may exercise their rights to data portability and objection in the manner indicated when the data was collected or using the Data Controller’s contact details provided above.
The rights and remedies available to data subjects are defined and communicated below in accordance with Act CXII of 2011 and Regulation (EU) 2016/679.
Right to information, also known as the data subject’s “right of access”: pursuant to Act CXII of 2011 and Article 15 of Regulation (EU) 2016/679, the Data Controller provides the following information at the data subject’s request:
- the data processed and the categories of personal data,
- the purpose of processing,
- the legal basis for processing,
- the duration of processing,
- where applicable, the period for which the data will be stored or, where this is not possible,
the criteria used to determine that period, - where applicable, if the data was not collected from the data subject, all available information concerning
its source, - where applicable, the existence of automated decision-making, including profiling,
and meaningful information about the logic involved, as well as the significance
and envisaged consequences of such processing for the data subject, - details of the data processor where a data processor has been engaged; the circumstances and effects of any personal data
breach and the measures taken to remedy it; and - where the data subject’s personal data has been transferred, the legal basis, purpose and recipient of the
transfer.
The information is provided free of charge if the person requesting it has not submitted a request to the Data Controller concerning the same category of data during the current year. In other cases, a fee may be charged. Any fee already paid must be reimbursed if the data was processed unlawfully or if the request for information resulted in rectification.
6. The Data Controller draws the attention of data subjects to the fact that information must be withheld under Act CXII of 2011,
a. where, pursuant to a law, international agreement or binding legal act of the European Union, the Data Controller receives personal data in circumstances where the transferring data controller simultaneously indicates a restriction on the rights granted to the data subject under the said Act or another restriction on the processing of the data.
b. in the interests of the external and internal security of the State, including national defence, national security, the prevention or prosecution of criminal offences and the security of the penal system; for State or municipal economic or financial interests; for important economic or financial interests of the European Union; for the prevention and detection of disciplinary and ethical offences related to the practice of professions and breaches of employment and occupational safety obligations, including monitoring and supervision in all cases; and for the protection of the rights of the data subject or others.
The Data Controller is required to notify the Hungarian National Authority for Data Protection and Freedom of Information annually, by 31 January of the year following the reference year, of requests for information that have been refused.
Right to rectification: the data subject has the right to obtain from the Data Controller, without undue delay, the rectification of inaccurate personal data concerning them. Taking into account the purposes of processing, the data subject has the right to have incomplete personal data completed, including by means of a supplementary statement. In addition, where personal data does not correspond to reality and accurate personal data is available to the Data Controller, the Data Controller is required to rectify it even without a request from the data subject.
Right to erasure, also known as the “right to be forgotten”: the data subject has the right to obtain from the Data Controller the erasure of personal data concerning them without undue delay, and the Data Controller is required to erase such personal data without undue delay unless mandatory processing precludes erasure.
In addition to the case described above, the Data Controller is required to erase data pursuant to Act CXII of 2011 and Regulation (EU) 2016/679 of the European Parliament and of the Council where
- the data has been processed unlawfully;
- the data is incomplete or inaccurate and this situation cannot lawfully be remedied, provided that erasure is not prohibited by law;
- the purpose of processing has ceased to exist or the statutory retention period has expired;
- erasure has been ordered by a court or the Authority.
- the personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
- the data subject objects to the processing and there are no overriding legitimate grounds for the processing;
- the personal data must be erased to comply with a legal obligation under Union or Member State law applicable to the Data Controller;
- the personal data was collected in connection with the offer of information society services directly to children, as referred to in Article 8(1) of Regulation (EU) 2016/679.
Where the Data Controller has made personal data public for any reason and is required to erase it under the above provisions, the Data Controller, taking account of available technology and the cost of implementation, will take reasonable steps, including technical measures, to inform other data controllers processing the personal data that the data subject has requested the erasure of links to, copies of or replications of the personal data in question.
The Data Controller draws the attention of data subjects to the limitations on the right to erasure or the “right to be forgotten” arising from EU law, which apply where processing is necessary for:
- exercising the right to freedom of expression and information;
- compliance with a legal obligation under Union or Member State law applicable to the Data Controller which requires the processing of personal data, or the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
- reasons of public interest in the area of public health;
- archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) of Regulation (EU) 2016/679, where the right to erasure is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
- the establishment, exercise or defence of legal claims.
Right to restriction of processing, also known as blocking: the data subject has the right to request that the Data Controller restrict processing.
If the available information indicates that erasure could infringe the legitimate interests of the data subject, the data must be blocked. Personal data blocked in this manner may be processed only for as long as the purpose of processing that precluded erasure continues to exist.
If the data subject disputes the accuracy of personal data but the inaccuracy of the disputed personal data cannot be clearly established, the Data Controller will block the data. In this case, the restriction applies for a period enabling the Data Controller to verify the accuracy of the personal data.
Under the EU Regulation, data must be blocked where
- the processing is unlawful and the data subject opposes erasure and requests the restriction of its use instead;
- the Data Controller no longer needs the personal data for the purposes of processing, but the data subject requires it for the establishment, exercise or defence of legal claims; or
- the data subject has objected to processing, in which case the restriction applies until it has been determined whether the legitimate grounds of the Data Controller override those of the data subject.
Where processing has been restricted or the data has been blocked, such personal data may, with the exception of storage, be processed only with the data subject’s consent, for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or a Member State.
The Data Controller expressly draws the attention of data subjects to the fact that the right to rectification, erasure and blocking may be restricted by law in the interests of the external and internal security of the State, including national defence, national security, the prevention or prosecution of criminal offences and the security of the penal system; for State or municipal economic or financial interests; for important economic or financial interests of the European Union; for the prevention and detection of disciplinary and ethical offences related to the practice of professions and breaches of employment and occupational safety obligations, including monitoring and supervision in all cases; and for the protection of the rights of the data subject or others.
Without undue delay, and no later than 30 days after receipt of the request, the Data Controller informs the data subject about the matters specified in the request and/or rectifies, erases and/or restricts or blocks the data, or takes other steps in accordance with the request, unless there is a reason preventing it from doing so.
The Data Controller informs the data subject in writing of the rectification, erasure or restriction of processing, as well as all recipients to whom the data was previously transferred or disclosed for processing purposes. At the data subject’s request, the Data Controller informs the data subject of those recipients. Notification may be omitted where this does not infringe the data subject’s legitimate interests in view of the purpose of processing, or where notification proves impossible or would involve disproportionate effort. The Data Controller must also inform the data subject in writing if the exercise of the data subject’s rights cannot be fulfilled for any reason and must specify the precise factual and legal reasons, as well as the available remedies: the possibility of bringing proceedings before a court and lodging a complaint with the Hungarian National Authority for Data Protection and Freedom of Information.
The “right to data portability”: the data subject has the right to
- receive personal data concerning them which they have provided to the Data Controller in a structured, commonly used and machine-readable format, and has the right to
- transmit that data to another data controller
without hindrance from the data controller to which the personal data was provided, where:
- the processing is based on consent; and
- the processing is carried out by automated means.
When exercising the right to data portability, the data subject has the right, where technically feasible, to have the personal data transmitted directly from one data controller to another.
In view of the processing activities carried out by the Data Controller, the conditions for exercising the right to data portability are not met because no automated processing takes place; consequently, the data subject
cannot exercise this right.
Right to object: the data subject may object to the processing of their personal data, including profiling, where
- the processing or transfer of personal data is necessary solely for the enforcement of the rights or legitimate interests of the Data Controller or the recipient, except where processing is mandatory;
- the personal data is used or transferred for direct marketing, public opinion research or scientific research purposes;
- the exercise of the right to object is otherwise permitted by law.
Pursuant to Article 21(3) of Regulation (EU) 2016/679, the data subject may also object to the processing of personal data for direct marketing purposes, in which case the personal data may no longer be processed for such purposes.
Where personal data is processed for scientific or historical research purposes or statistical purposes, the data subject has the right to object, on grounds relating to their particular situation, to the processing of personal data concerning them, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
The Data Controller, while simultaneously suspending processing, examines the objection as soon as possible and no later than 30 days after the request is submitted, and informs the applicant of the outcome in writing. If the applicant’s objection is justified, the Data Controller terminates the processing, including any further collection and transfer of data, blocks the data, and informs all persons to whom the personal data concerned by the objection was previously transferred of the objection and the measures taken on its basis; those persons are required to take action to enforce the right to object.
If the data subject disagrees with the Data Controller’s decision or the Data Controller fails to comply with the stated time limit, the data subject may bring proceedings before a court within 30 days of notification of the decision.
The data subject has the right to object to automated decision-making.
Judicial enforcement: if the data subject’s rights are infringed, the data subject may bring proceedings before a court. The court will hear the case as a matter of priority. The Data Controller bears the burden of proving that the processing complies with the law.
If your right to informational self-determination is infringed, you may submit a report or complaint to:
- Hungarian National Authority for Data Protection and Freedom of Information
- Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
- Telephone: +36 (1) 391-1400, Fax: +36 (1) 391-1410
- Website: http://www.naih.hu
- Email: ugyfelszolgalat@naih.hu
If your rights are infringed in connection with content that harms minors, incites hatred or exclusion, corrections, the rights of deceased persons or damage to reputation, you may submit a report or complaint to:
- National Media and Infocommunications Authority
- 1015 Budapest, Ostrom u. 23–25.
- Postal address: 1525 Budapest, P.O. Box 75
- Telephone: (06 1) 457 7100
- Fax: (06 1) 356 5520
- Email: info@nmhh.hu