Privacy Policy
1. Introduction
Kovács, Szalay, Benyőcs és Társai Ügyvédi Iroda (hereinafter Kovács, Szalay, Benyőcs és Társai Ügyvédi Iroda, the service provider, the data controller, the Company), as data controller, recognises the content of this legal notice as binding upon itself.
The Company undertakes to ensure that all data processing related to its activities complies with the requirements set out in this policy and in the applicable legislation.
Kovács, Szalay, Benyőcs és Társai Ügyvédi Iroda is the operator of the website www.bls-cee.com.
Kovács, Szalay, Benyőcs és Társai Ügyvédi Iroda reserves the right to amend this notice at any time. It will of course notify its audience of any changes in due time.
Kovács, Szalay, Benyőcs és Társai Ügyvédi Iroda is committed to protecting the personal data of its clients and partners and considers it of paramount importance to respect its clients' right to informational self-determination. The Controller treats personal data confidentially and takes all security, technical and organisational measures that guarantee the security of the data.
Below, Kovács, Szalay, Benyőcs és Társai Ügyvédi Iroda sets out its data processing principles and presents the requirements it has formulated for, and complies with, as data controller. Its data processing principles are in line with the applicable data protection legislation, in particular the following:
- Act CXII of 2011 on Informational Self-Determination and Freedom of Information;
- Act V of 2013 on the Civil Code (Civil Code);
- Act XLVIII of 2008 on the Basic Requirements of, and Certain Restrictions on, Commercial Advertising Activity (Advertising Act).
- Act CVIII of 2001 (E-Commerce Act) on Certain Issues of Electronic Commerce Services and Information Society Services;
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: "GDPR")
2. Definitions
- data subject: any specified natural person who is identified or can be identified, directly or indirectly, on the basis of personal data;
- personal data: any data that can be associated with the data subject – in particular the data subject's name, identifier, and one or more pieces of information characteristic of their physical, physiological, mental, economic, cultural or social identity – as well as any conclusion relating to the data subject that can be drawn therefrom;
- consent: the voluntary and definite expression of the data subject's wish, based on adequate information, by which they give their unambiguous agreement to the processing – whether full or covering specific operations – of personal data relating to them;
- data controller: the natural or legal person, or organisation without legal personality, who or which, alone or jointly with others, determines the purpose of the data processing, makes and implements the decisions concerning the processing (including the means used), or has them carried out by the data processor;
- data processing: irrespective of the procedure applied, any operation or set of operations performed on data, in particular its collection, capture, recording, organisation, storage, alteration, use, querying, transfer, disclosure to the public, alignment or combination, blocking, erasure and destruction, as well as preventing the further use of the data, taking photographs, audio or video recordings, and recording physical characteristics suitable for identifying a person (e.g. fingerprint or palm print, DNA sample, iris image);
- data transfer: making the data accessible to a specified third party;
- disclosure to the public: making the data accessible to anyone;
- erasure of data: rendering data unrecognisable in such a way that its restoration is no longer possible;
- data processing on behalf of the controller: the performance of technical tasks connected with data processing operations, irrespective of the method and means applied to carry out the operations and of the place of application, provided that the technical task is performed on the data;
- data processor: the natural or legal person, or organisation without legal personality, who or which processes data under a contract – including a contract concluded pursuant to a statutory provision.
3. Company details
Our company's details and contact information are as follows:
- Name: Kovács, Szalay, Benyőcs és Társai Ügyvédi Iroda
- Postal address: 1011 Budapest, Fő u. 14-18., B ép. 2. em.
- Tax number: 18277308-2-41
- Telephone number: +36301484414
- E-mail:office@bls-cee.com
- Representative of the data controller: Kovács Gábor
4. The scope of the personal data, the purpose, legal basis and duration of the processing
We draw the attention of those providing data to Kovács, Szalay, Benyőcs és Társai Ügyvédi Iroda to the fact that, where they do not provide their own personal data, it is the data provider's obligation to obtain the data subject's consent. The data controller is not obliged to verify that such consent exists. The data controller draws the partner's attention to the fact that, should it fail to fulfil this obligation and the data subject therefore asserts a claim against the data controller, the data controller may pass on the asserted claim and the amount of any related damage to the partner.
In relation to each of our processing activities we provide the following information.
4.1. Requests for quotes and enquiries through direct contact
Interested parties may contact our Company either by using the contact form available on the Website, by sending an e-mail to the Company's designated e-mail address, or by telephone.
- Purpose of the processing: to respond to requests for quotations and other enquiries submitted by the data subject, to maintain contact and to facilitate communication between the data subject and the Company.
- Legal basis of the processing:
- where the enquiry relates to obtaining a quotation or taking steps prior to entering into a contract, the processing is necessary in order to take steps at the request of the data subject prior to entering into a contract pursuant to Article 6(1)(b) GDPR;
- for all other enquiries submitted through the contact form, by e-mail or by telephone, the processing is based on the data subject's consent pursuant to Article 6(1)(a) GDPR.
- Scope of the personal data processed: name, e-mail address, subject of the enquiry, the content of the message, and any other personal data voluntarily provided by the data subject.
- Duration of the processing:
- in the case of requests for quotations, for 5 years following the expiry of the validity period of the quotation;
- in the case of other enquiries, until the purpose of the processing has been fulfilled or until the data subject withdraws their consent, whichever occurs first.
- Recipients of the personal data: the Controller does not disclose the personal data to third parties, except for the data processors identified in Section 7. The personal data may only be accessed by authorised employees of the Controller and the designated personnel of the relevant data processors.
- Categories of data subjects: individuals requesting quotations and individuals contacting the Company through the contact form, by e-mail or by telephone regarding the Company's services.
4.6. CCTV system
The Controller operates a closed-circuit television (CCTV) system at its premises for the purposes of protecting life, physical integrity and property, preventing and investigating incidents, and safeguarding the security of persons and assets. Data subjects are informed of the operation of the CCTV system by means of appropriate signage displayed at the monitored areas.
The detailed rules governing the operation of the CCTV system, including the purposes of processing, the legal basis, the categories of personal data processed, the retention period, the rights of data subjects and other information required under the GDPR, are set out in the "CCTV Data Processing Notice", which is available at the relevant premises.
4.7. Cookies and similar technologies
The Controller uses cookies and similar technologies on the Website to ensure its proper operation, maintain the security of the Website, enable certain functional features, analyse website traffic and improve the User experience.
Strictly necessary cookies, which are essential for the operation of the Website and for the provision of the service explicitly requested by the User, are placed automatically. The processing of personal data relating to these cookies is based on the Controller's legitimate interest pursuant to Article 6(1)(f) GDPR, in conjunction with the exemption set out in Section 155(4) of Act C of 2003 on Electronic Communications, as these cookies are technically necessary for the operation of the Website.
All other cookies and similar technologies, including analytics cookies, functional cookies and third-party services that require the storage of information on or access to information stored on the User's terminal equipment, are activated only after the User has given their prior consent through the cookie management platform. The legal basis for such processing is the User's prior consent pursuant to Article 6(1)(a) GDPR.
The User may grant, refuse or withdraw their consent at any time through the cookie management platform available on the Website. The withdrawal of consent shall not affect the lawfulness of processing carried out before the withdrawal.
The User may also delete cookies or restrict their use through the settings of their web browser. Please note, however, that disabling strictly necessary cookies may adversely affect the proper functioning of certain features of the Website.
The categories of cookies and similar technologies currently used on the Website, together with their providers, purposes, retention periods and legal bases for processing, are set out in the table below.
| Category | Cookie name / service | Provider | Purpose of the processing | Duration | Legal basis |
|---|---|---|---|---|---|
| Strictly necessary cookies | neosite_session | Identifying the session and preserving the user’s state between individual page loads. | session (approx. 2 hours) | Exemption under Section 155(4) of the Electronic Communications Act; Article 6(1)(f) GDPR | |
| Strictly necessary cookies | XSRF-TOKEN | Security token providing protection against cross-site request forgery (CSRF). | session (approx. 2 hours) | Exemption under Section 155(4) of the Electronic Communications Act; Article 6(1)(f) GDPR | |
| Statistical (analytics) cookies | _ga (Google Analytics 4) | Google Ireland Ltd. | Distinguishing unique visitors for the purpose of compiling traffic statistics. | 2 years | Article 6(1)(a) GDPR – prior consent |
| Statistical (analytics) cookies | _ga_8SKCT442G3 (Google Analytics 4) | Google Ireland Ltd. | Storing the session state and session count for the given measurement data stream. | 2 years | Article 6(1)(a) GDPR – prior consent |
| Statistical (analytics) cookies | Google Tag Manager / gtag.js (not a cookie) | Google Ireland Ltd. | Loading the measurement code and transmitting the measurement data to the Google Analytics service. | – | Article 6(1)(a) GDPR – prior consent |
| Error monitoring and security | Sentry | Logging errors occurring during the operation of the application, ensuring the stability and security of the service. | session | Article 6(1)(f) GDPR – legitimate interest |
5. Other data processing
We provide information about processing activities not listed in this notice at the time the data is collected. We inform our clients that certain authorities, bodies performing public duties, and courts may contact our company for the purpose of disclosing personal data. To these bodies our company discloses – provided that the body concerned has specified the exact purpose and the scope of the data – only as much personal data, and to such an extent, as is absolutely necessary to achieve the purpose of the request, and only where the fulfilment of the request is prescribed by law.
6. Transfer of personal data to a third country or to an international organisation
As a general rule, the Controller processes personal data within the European Economic Area (EEA). However, where the Website uses third-party service providers, such as Google Analytics, Google Tag Manager, Google Maps, Google Places or Google Fonts, personal data may be transferred to or accessed from countries outside the EEA, including the United States.
Where such transfers take place, they are carried out in accordance with the requirements of Chapter V of the GDPR. Where applicable, the transfer is based on an adequacy decision adopted by the European Commission (including the EU-U.S. Data Privacy Framework where the recipient participates in that framework), or on other appropriate safeguards provided for by the GDPR, such as the European Commission's Standard Contractual Clause.
7. Information on the use of data processors
For the performance of certain technical tasks related to the processing, the Controller engages data processors. A data processor takes no independent decision concerning the processing; it acts exclusively in accordance with the Controller’s written instructions, on the basis of a contract satisfying the requirements of Article 28 GDPR, and it is bound by an obligation of confidentiality with respect to the personal data it becomes aware of.
Categories of recipients: system administration services, accounting and payroll services, server hosting and web hosting services.
The data processors engaged by the Controller are the following:
| Name of the data processor | Registered office | Processing activity performed |
|---|---|---|
| NeoSoft Kft. | 8000 Székesfehérvár, Távírda utca 2/A. | web hosting service |
The Controller engages a further data processor only on the basis of the general written authorisation given in advance, and informs data subjects of the intended change by updating this notice. Where a data processor also processes personal data outside the European Economic Area, the Controller ensures that the transfer takes place on the basis of an adequacy decision of the European Commission or subject to the appropriate safeguards set out in Article 46 GDPR.
Supplementary provisions
- The data processors listed above have access to personal data only to the extent necessary for the performance of the task entrusted to them, and only for the duration of the contract.
- Beyond the data processors indicated above, the Controller does not transfer personal data to any third party, save where the disclosure of data is prescribed by law or is necessary for the establishment, exercise or defence of legal claims.
8. Children
Our services are not intended for persons under the age of 16, and we ask that persons under the age of 16 do not provide Personal data to the Controller.
If it comes to our attention that we have collected personal data from a child under the age of 16 – with the exception of processing data as required by law – we will take the steps necessary to erase the data as soon as possible.
9. Automated decision-making
In its data processing procedures and data collection, our Company does not apply automated decision-making.
10. The manner of storing personal data and the security of the processing
Our company's IT systems and other data storage locations are located at its registered office and on the servers provided by the data processor. For processing personal data, our company selects and operates the IT tools used in providing the service in such a way that the processed data is:
- accessible to those authorised (availability);
- its authenticity and authentication are ensured (authenticity of the processing);
- its unaltered state can be verified (data integrity);
- protected against unauthorised access (confidentiality of the data).
We pay particular attention to the security of the data and, furthermore, we take the technical and organisational measures and establish the procedural rules necessary to give effect to the safeguards under the GDPR. We protect the data with appropriate measures, in particular against unauthorised access, alteration, transfer, disclosure to the public, erasure or destruction, as well as against accidental destruction or damage and against becoming inaccessible due to changes in the technology applied.
The IT system and network of our company and our partners are protected against computer-assisted fraud, computer viruses, computer intrusions and denial-of-service attacks. The operator also ensures security by means of server-level and application-level protection procedures. Daily backup of the data is in place. In order to avoid data protection incidents, our company takes every possible measure, and in the event of such an incident occurring – in accordance with our incident management policy – we act without delay to minimise the risks and remedy the damage.
11. The rights of data subjects and remedies
The data subject may request information about the processing of their personal data, and may request the rectification or – with the exception of mandatory processing – the erasure or withdrawal of their personal data, and may exercise their right to data portability and their right to object in the manner indicated at the collection of the data, or via the data controller's contact details given above.
The rights and remedies of the data subject under Regulation (EU) 2016/679 are set out below and communicated to data subjects.
The right to information, otherwise known as the data subject's "right of access": on the basis of Article 15 of Regulation (EU) 2016/679, upon the data subject's request the Controller provides information on
- the data it processes and the categories of personal data,
- the purpose of the processing,
- the legal basis of the processing,
- the duration of the processing,
- where applicable, the duration of the storage of the data or, if this is not possible, the criteria for determining that duration,
- where applicable, where the data was not collected from the data subject, all available information as to its source,
- where applicable, automated decision-making, including profiling, as well as meaningful information about the logic involved and the significance of such processing, and
- the likely consequences of such processing for the data subject,
- the data processor's details, if a data processor was used; the circumstances and effects of the data protection incident and the measures taken to address it; and furthermore
- in the case of a transfer of the data subject's personal data, the legal basis, purpose and recipient of the transfer.
The information is free of charge if the requesting party has not yet submitted a request for information concerning the same scope of data to the Controller in the current year. In other cases a cost reimbursement may be established. Any cost reimbursement already paid must be refunded if the data was processed unlawfully or if the request for information led to a rectification.
The right to rectification: the data subject has the right to obtain from the Controller, without undue delay, the rectification of inaccurate personal data concerning them. Taking into account the purpose of the processing, the data subject has the right to request that incomplete personal data be completed – including by means of a supplementary statement. At the same time, if the personal data does not correspond to reality and the personal data corresponding to reality is available to the Controller, the Controller rectifies the personal data as a matter of obligation, even without the data subject's request.
The right to erasure, otherwise known as the "right to be forgotten": the data subject has the right to obtain from the Controller, without undue delay, the erasure of personal data concerning them, and the Controller is obliged to erase the personal data concerning the data subject without undue delay, unless mandatory processing precludes this.
In addition to the above case, the Controller is obliged to erase the data, on the basis Regulation (EU) 2016/679 of the European Parliament and of the Council, if
- the processing of the data is unlawful;
- the data is incomplete or erroneous – and this state of affairs cannot lawfully be remedied – provided that erasure is not precluded by law;
- the purpose of the processing has ceased, or the statutory time limit for storing the data has expired;
- it has been ordered by a court or the Authority.
- the personal data is no longer necessary for the purpose for which it was collected or otherwise processed;
- the data subject objects to the processing and there is no overriding legitimate ground for the processing;
- the personal data must be erased in order to comply with a legal obligation under the law applicable to the Controller;
- the personal data was collected in relation to the offering of information society services referred to in Article 8(1) of Regulation (EU) 2016/679 directly to children.
Where the Controller has, for some reason, made the personal data public and is obliged to erase it pursuant to the above, taking account of available technology and the cost of implementation it takes the reasonably expectable steps – including technical measures – to inform other controllers processing the data that the data subject has requested the erasure of any links to, or copies or replications of, the personal data in question.
The Controller draws the attention of data subjects to the limits, arising from the EU regulation, of the right to erasure or the "right to be forgotten", which are as follows:
- the exercise of the right to freedom of expression and information;
- compliance with an obligation under Union or Member State law applicable to the controller which requires the processing of personal data, or the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- public interest in the area of public health;
- in accordance with Article 89(1) of Regulation (EU) 2016/679, archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, in so far as the right to erasure is likely to render impossible or seriously impair the achievement of that processing; or
- the establishment, exercise or defence of legal claims.
The right to restriction of processing, otherwise known as the right to blocking: the data subject has the right to obtain from the Controller restriction of the processing upon their request.
If, on the basis of the information available, it can be assumed that erasure would harm the legitimate interests of the data subject, the data must be blocked. Personal data blocked in this way may be processed only for as long as the processing purpose that precluded the erasure of the personal data subsists.
If the data subject contests the accuracy or correctness of the personal data, but the incorrectness or inaccuracy of the contested personal data cannot be clearly established, the data is blocked. In this case the restriction relates to the period that enables the Controller to verify the accuracy of the personal data.
On the basis of the EU regulation, the data must be blocked if
- the processing is unlawful and the data subject opposes the erasure of the data and requests instead the restriction of its use;
- the Controller no longer needs the personal data for the purpose of the processing, but the data subject requires it for the establishment, exercise or defence of legal claims; or
- the data subject has objected to the processing; in this case the restriction relates to the period until it is established whether the legitimate grounds of the Controller override the legitimate grounds of the data subject.
Where the processing is subject to restriction (blocking), such personal data may, with the exception of storage, be processed only with the data subject's consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for important public-interest reasons of the Union or of a Member State.
The Controller hereby expressly draws the attention of data subjects to the fact that the data subject's right to rectification, erasure and blocking may be restricted by law in the interest of the external and internal security of the State, such as national defence, national security, the prevention or prosecution of criminal offences, and the security of the enforcement of penalties, as well as for State or municipal economic or financial interests, for a significant economic or financial interest of the European Union, and for the purpose of preventing and detecting disciplinary and ethical breaches related to the practice of professions and breaches of labour-law and occupational-safety obligations – including in every case monitoring and supervision – and furthermore in the interest of protecting the rights of the data subject or others.
The Controller, without undue delay and at most within 30 days of receipt of the request, informs the data subject of the matters specified in their request, and/or rectifies the data, and/or erases and/or restricts (blocks) the data, or takes other steps in accordance with the request, where there is no ground precluding this.
The Controller notifies the data subject in writing of the rectification, the erasure or the restriction of the processing having taken place, as well as all those to whom the data was previously transferred or handed over for the purpose of processing. Upon the data subject's request, the Controller informs them of these recipients. The notification may be omitted if, having regard to the purpose of the processing, it does not harm the data subject's legitimate interest, or if providing the information proves impossible or would require a disproportionate effort. The Controller is also obliged to notify the data subject in writing if the exercise of the data subject's rights cannot be realised for some reason, and is obliged to indicate precisely the factual and legal grounds, as well as the remedies available to the data subject: the possibility of turning to the court and to the Hungarian National Authority for Data Protection and Freedom of Information.
The "right to data portability": the data subject has the right to
- receive the personal data concerning them, which they have provided to the Controller, in a structured, commonly used, machine-readable format, and they also have the right to
- transmit this data to another data controller without hindrance from the data controller to which the personal data was provided, where:
- the processing is based on consent; and
- the processing is carried out by automated means.
In exercising the right to data portability, the data subject has the right – where this is technically feasible – to request the direct transmission of the personal data between controllers.
In view of the processing activities carried out by the Controller, the conditions for exercising the right to data portability are not met (there is no automated processing), and therefore the data subject cannot exercise this right.
The right to object: the data subject may object to the processing – including profiling – of their personal data if
- the processing (transfer) of the personal data is necessary solely for the enforcement of a right or legitimate interest of the Controller or the data recipient, except in the case of mandatory processing;
- the use or transfer of the personal data is for the purpose of direct marketing, opinion polling or scientific research;
- the exercise of the right to object is otherwise permitted by law.
The data subject may also object, on the basis of Article 21(3) of Regulation (EU) 2016/679, to the processing of personal data for the purposes of direct marketing, in which case the personal data may no longer be processed for this purpose.
Where personal data is processed for scientific and historical research purposes or statistical purposes, the data subject has the right, on grounds relating to their particular situation, to object to the processing of personal data concerning them, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
The Controller – while simultaneously suspending the processing – examines the objection within the shortest possible time from the submission of the request, but at most within 30 days, and informs the applicant in writing of the outcome. If the applicant's objection is well founded, the Controller terminates the processing – including any further data collection and data transfer – and blocks the data, and notifies of the objection and of the measures taken on its basis all those to whom the personal data affected by the objection was previously transferred and who are obliged to take measures in order to enforce the right to object.
If the data subject does not agree with the Controller's decision, or the Controller fails to meet the referenced deadline, the data subject is entitled – within 30 days of being notified thereof – to turn to the court.
The data subject has the right to object in relation to automated decision-making.
Judicial enforcement of rights: in the event of a violation of their rights, the data subject may turn to the court. The court deals with the case as a priority. It is for the Controller to prove that the processing complies with the provisions laid down in law.
In the event of a violation of their right to informational self-determination, you may file a report or complaint with:
Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság)
Registered office: 1055 Budapest, Falk Miksa utca 9-11., Hungary
Postal address: 1363 Budapest, Pf.: 9., Hungary
Telephone: +36 (1) 391-1400
Website: https://naih.hu
E-mail: ugyfelszolgalat@naih.hu
Contact Us
Contact Us
If you’d like to explore how we can work together, send an enquiry or write to us at:
office@bls-cee.com
Google Maps
