Privacy Statement
1. Introduction
Mobelito Tanácsadó és Szolgáltató Kft. (hereinafter Mobelito Tanácsadó és Szolgáltató Kft., service provider, data controller, the Company), as data controller, acknowledges the content of this legal notice as binding upon itself.
The Company undertakes that all data processing related to its activities complies with the requirements set out in this policy and in the applicable legislation.
Mobelito Tanácsadó és Szolgáltató Kft. is the operator of the website szormenteselet.hu.
Mobelito Tanácsadó és Szolgáltató Kft. reserves the right to change this notice at any time. Naturally, it will inform its audience of any changes in due time.
Mobelito Tanácsadó és Szolgáltató Kft. is committed to protecting the personal data of its customers and partners, and considers it particularly important to respect its customers' right to informational self-determination. The Data Controller treats personal data confidentially and takes all security, technical and organisational measures that guarantee the security of the data.
Mobelito Tanácsadó és Szolgáltató Kft. sets out below its data processing principles and the requirements it has formulated for itself as a data controller and which it observes. Its data processing principles are in line with the applicable data protection legislation, in particular the following:
- Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information;
- Act V of 2013 on the Civil Code;
- Act XLVIII of 2008 on the Basic Conditions and Certain Limitations of Commercial Advertising Activities;
- Act CVIII of 2001 on Certain Aspects of Electronic Commerce Services and Information Society Services;
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: "GDPR").
2. Definitions
- data subject: any natural person identified or identifiable, directly or indirectly, by reference to a specific personal data;
- personal data: any data that can be linked to the data subject – in particular the data subject's name, identification number, and one or more factors specific to their physical, physiological, mental, economic, cultural or social identity – as well as any conclusion drawn from such data that relates to the data subject;
- consent: a freely given, specific indication of the data subject's wishes, based on adequate information, by which the data subject signifies their unambiguous agreement to the processing of personal data relating to them, whether in full or in respect of specific operations;
- data controller: the natural or legal person, or organisation without legal personality, that alone or jointly with others determines the purposes of the processing of data, makes and implements decisions concerning the processing (including the means used), or has such decisions implemented by a data processor;
- data processing: any operation or set of operations performed on data, irrespective of the procedure applied, in particular collection, recording, organisation, storage, alteration, use, retrieval, transfer, disclosure, alignment or combination, blocking, erasure and destruction of data, as well as preventing the further use of the data, taking photographs, audio or video recordings, and recording physical characteristics suitable for identifying a person (e.g. fingerprint or palm print, DNA sample, iris image);
- data transfer: making data accessible to a specified third party;
- disclosure: making data accessible to anyone;
- data erasure: rendering data unrecognisable in such a way that it can no longer be restored;
- data processing (technical): performing the technical tasks connected with data processing operations, irrespective of the method and means used to carry out the operations, and the place of application, provided that the technical task is performed on the data;
- data processor: the natural or legal person, or organisation without legal personality, that processes data under a contract – including a contract concluded pursuant to a legal provision.
3. Company details
Our company's details and contacts are as follows:
- Name: Mobelito Tanácsadó és Szolgáltató Kft.
- Postal address: 8082 Gánt, hrsz. 1601/4, Hungary
- Company registration number: 07-09-028767
- Tax number: 26268518-1-07
- Phone number: +36 30 439 5662
- E-mail: info@szormenteselet.hu
- Representative of the data controller: Erzsébet Bévárdi, managing director
4. The scope of personal data, the purpose, legal basis and duration of processing
We would like to draw the attention of those who provide data to Mobelito Tanácsadó és Szolgáltató Kft. that if they provide data that is not their own, it is the data provider's responsibility to obtain the data subject's consent. The data controller is not obliged to verify the existence of such consent. The data controller draws the partner's attention to the fact that if it fails to meet this obligation and the data subject asserts a claim against the data controller as a result, the data controller may pass on the asserted claim and the amount of the related damages to the partner.
We provide the following information regarding our individual data processing activities.
4.1. Requests for quotations, inquiries via direct contact
Interested parties have the opportunity to contact our Company directly by e-mail sent to the Company's address, or by telephone.
- Purpose of processing: to maintain contact and to promote communication between the data subject and our Company, in the interest of the closest and most effective possible cooperation.
- Legal basis of processing: legitimate interest – GDPR Article 6(1)(f).
- Scope of personal data processed: name of the person requesting the quotation/contact person; e-mail address, phone number, and any other information provided by the data subject.
- Duration of processing: 3 years following the expiry of the validity of the quotation, or until the data subject objects.
- Recipients of personal data: the data controller does not transfer the data obtained to any third party, except for the data processor(s) referred to in point 7. The recorded data may only be accessed by the employees of the Data Controller and the designated staff of the data processor(s).
- Statement of legitimate interest: our Company's legitimate interest in processing the data subject's data is direct marketing.
- Scope of data subjects affected by the processing: partners and data subjects who make direct inquiries (e.g. by e-mail or phone) regarding the Company's services.
4.2. Requests for quotations, inquiries via the website (szormenteselet.hu)
Our company provides the opportunity for data subjects to request a quotation electronically.
- Purpose of processing: to maintain contact and to promote communication between the data subject and our Company, in the interest of the closest and most effective possible cooperation.
- Legal basis of processing: the voluntary consent of the data subject – GDPR Article 6(1)(a).
- Scope of personal data processed: the name of the inquirer (first name, last name); e-mail address, phone number, company name, and any other information provided by the data subject.
- Duration of processing: 3 years following the expiry of the validity of the quotation, or until consent is withdrawn.
- Recipients of personal data: the data controller does not transfer the data obtained to any third party, except for the data processor(s) referred to in point 7. The recorded data may only be accessed by the employees of the Data Controller and the designated staff of the data processor(s).
- Scope of data subjects affected by the processing: partners and data subjects who make inquiries via the website regarding the Company's services and products.
4.3. Data processing related to the follow-up of quotation requests
- Purpose of processing: the data controller's legitimate interest in keeping records of the data subject's data beyond the period of validity of the quotation, for the purpose of direct marketing.
- Legal basis of processing: the data controller's legitimate interest, GDPR Article 6(1)(f).
- Scope of personal data processed: the contact person's last name and first name; phone number; e-mail address.
- Recipients of personal data: the data controller does not transfer the data obtained to any third party, except for the data processor(s) referred to in point 7. The recorded data may only be accessed by the employees of the Data Controller and the designated staff of the data processor(s).
- Duration of processing: until the data subject objects.
- Statement of legitimate interest: establishing business relationships with partners and those requesting quotations, and providing accurate information to data subjects. Our Company's legitimate interest in processing the data subject's data is direct marketing.
- Scope of data subjects affected by the processing: recipients of quotations previously issued by the Company, and the contact person(s) named therein.
4.4. Newsletter registration
- Purpose of processing: sending e-mail newsletters, which may also contain commercial advertising, to interested parties, and informing them of current information.
- Legal basis of processing: the data subject's prior, voluntary consent, GDPR Article 6(1)(a).
- Scope of personal data processed: name, e-mail address.
- Duration of processing: until the voluntary consent is withdrawn, or until unsubscribing from the newsletter. Our Company processes the data provided by the data subject until consent is withdrawn. Following withdrawal of consent, the processed data will be deleted from our newsletter database within 7 days at the latest, after which we will no longer send you a newsletter.
- Recipients of personal data: the data controller does not transfer the data obtained to any third party, except for the data processor(s) referred to in point 7. The recorded data may only be accessed by the employees of the Data Controller and the designated staff of the data processor(s). You may unsubscribe from the newsletter at any time by sending a letter to our Company at info@szormenteselet.hu, or by clicking the unsubscribe icon in the newsletter.
- Scope of data subjects affected by the processing: partners and data subjects who subscribe to the Company's electronic newsletter.
4.5. Newsletter data (for newsletters registered before 25 May 2018)
- Purpose of processing: sending e-mail newsletters, which may also contain commercial advertising, to interested parties, and informing them of current information.
- Legal basis of processing: the data controller's legitimate interest, GDPR Article 6(1)(f).
- Scope of personal data processed: name, e-mail address.
- Duration of processing: until the data subject objects.
- Statement of legitimate interest: providing information containing commercial advertising and business offers to data subjects who have subscribed to the newsletter. Our Company's legitimate interest in processing the data subject's data is direct marketing.
- Recipients of personal data: the data controller does not transfer the data obtained to any third party, except for the data processor(s) referred to in point 7. The recorded data may only be accessed by the employees of the Data Controller and the designated staff of the data processor(s). You may unsubscribe from the newsletter at any time by sending a letter to our Company at info@szormenteselet.hu, or by clicking the unsubscribe icon in the newsletter.
- Scope of data subjects affected by the processing: partners and data subjects who subscribed to the Company's electronic newsletter before 25 May 2018.
4.6. Camera system
Cameras operate on the premises operated by the data controller for the personal and property security of data subjects and for other purposes. Signs informing data subjects draw attention to their operation. The activities related to the operation of the camera system for the data subject are set out in the "Information Notice on Security Camera Data Processing", which is available on the premises.
4.7. Data processing related to ensuring the operation of information technology services
- Purpose of processing: Mobelito Tanácsadó és Szolgáltató Kft. may use so-called "cookies" (temporary markers) on its websites, which allow faster access to them. By "cookies" we mean an information item that is only active during a given customer session and that is transferred from the website to the Customer's computer for the purpose of faster identification. The Customer may always request that cookies be disabled by changing their browser settings; however, disabling them may slow down or prevent access to certain parts of the site or the use of certain features.
The session cookies used avoid the need to resort to other IT tools that could potentially compromise the confidentiality of customers' navigation and that would allow the acquisition of the identifying personal data.
The user is able to delete the cookie from their own computer, or may disable the use of cookies in their browser. Cookies can generally be managed in the browser's Tools/Settings menu, under Privacy settings, under the name cookie. - Legal basis of processing: the voluntary consent of the data subject (User), GDPR Article 6(1)(a).
The User gives their voluntary consent to the processing by accepting the pop-up notice and statement when they begin browsing the website, or by continuing to browse.
Scope of personal data processed: the information technology data processing concerns the data necessary for the operation of the "cookies" used to operate the website and the use of the log files applied by the web hosting provider. - Duration of processing: until the end of the session.
- Recipients of personal data: the data controller does not transfer the data obtained to any third party, except for the data processor(s) referred to in point 7. The recorded data may only be accessed by the employees of the Data Controller and the designated staff of the data processor(s).
- Scope of data subjects affected by the processing: every User visiting the website, regardless of whether they use the services available on the website.
5. Other data processing
We will provide information about any data processing not listed in this notice at the time the data is collected. We inform our customers that certain authorities, bodies performing public duties, and courts may contact our company for the purpose of disclosing personal data. Our company will only disclose personal data to such bodies – provided the requesting body has specified the exact purpose and scope of the data – to the extent strictly necessary to achieve the purpose of the request, and only if the request is required by law.
6. Transfer of personal data to a third country or international organisation
Our Company does not transfer your above personal data to any third country or international organisation.
7. Information on the use of a data processor
In the course of processing, the data controller transfers the data to the data processor(s) contracted with it for the performance of the contract.
Categories of recipients: system administration service provider, accounting and payroll service provider, server hosting, web hosting provider.
8. Children
Our services are not intended for persons under 16 years of age, and we ask that persons under 16 do not provide Personal Data to the Data Controller.
If we become aware that we have collected personal data from a child under 16 – with the exception of data processed pursuant to legal requirements – we will take the necessary steps to delete the data as soon as possible.
9. Automated decision-making
Our Company does not apply automated decision-making in its data processing procedures or data collection.
10. Method of storing personal data, security of processing
Our company's IT systems and other data storage locations are located at the registered office and on the servers provided by the data processor. Our company selects and operates the IT tools used for processing personal data in providing the service in such a way that the processed data is:
- accessible to those authorised to access it (availability);
- authentic and its authentication is ensured (authenticity of processing);
- verifiable as unchanged (data integrity);
- protected against unauthorised access (confidentiality of data).
We pay particular attention to the security of the data, and we also take the technical and organisational measures and establish the procedural rules necessary to give effect to the guarantees under the GDPR. We protect the data with appropriate measures, in particular against unauthorised access, alteration, transfer, disclosure, erasure or destruction, as well as against accidental destruction and damage, and against becoming inaccessible due to changes in the technology applied.
Our company's and our partners' IT systems and networks are protected against computer-assisted fraud, computer viruses, computer break-ins and denial-of-service attacks. The operator also ensures security through server-level and application-level protection procedures. Daily backup of the data is in place. In order to avoid data protection incidents, our company takes every possible measure, and in the event of such an incident – in accordance with our incident management policy – we act immediately to minimise risks and remedy any damage.
11. Rights of data subjects and remedies
The data subject may request information about the processing of their personal data, and may request the rectification of their personal data or – except in the case of mandatory data processing – the erasure or withdrawal thereof, and may exercise their right to data portability and to object, in the manner indicated when the data was collected, or via the data controller's contact details above.
The rights and remedies of data subjects under Act CXII of 2011 and EU Regulation 2016/679 are set out below and are communicated to data subjects accordingly.
The right to information, or in other words the data subject's "right of access": Pursuant to Act CXII of 2011 and Article 15 of EU Regulation 2016/679, at the request of the data subject the Data Controller shall provide information on
- the data processed by it and the categories of personal data,
- the purpose of the processing,
- the legal basis of the processing,
- the duration of the processing,
- where applicable, the period for which the data is stored, or, if this is not possible, the criteria used to determine that period,
- where applicable, if the data was not collected from the data subject, any available information as to its source,
- where applicable, information about automated decision-making, including profiling, as well as comprehensible information about the logic involved and the significance of such processing, and
- the expected consequences for the data subject,
- information about the data processor, if a data processor was used, including the circumstances and effects of any data protection incident and the measures taken to remedy it, and
- in the case of the transfer of the data subject's personal data, the legal basis, purpose and recipient of the data transfer.
The information is provided free of charge if the person requesting it has not already submitted a request for information on the same set of data to the Data Controller in the current year. In other cases, a cost reimbursement may be charged. Any cost reimbursement already paid must be refunded if the data was processed unlawfully or if the request for information led to a rectification.
The Data Controller draws the attention of data subjects to the fact that, under Act CXII of 2011, the provision of information must be refused
- if, pursuant to a law, an international treaty or a binding legal act of the European Union, the Data Controller receives personal data in such a way that the transferring data controller indicates, at the time of the transfer, a restriction of the data subject's rights under the said law, or another restriction on processing.
- for the protection of the state's external and internal security, including national defence, national security, the prevention or prosecution of criminal offences, the security of penal enforcement, as well as for state or local government economic or financial interests, the significant economic or financial interest of the European Union, and for the prevention and detection of disciplinary and ethical offences related to the exercise of occupations, and breaches of labour law and occupational safety obligations – including, in every case, control and supervision – as well as for the protection of the rights of the data subject or others.
The Data Controller is obliged to notify the National Authority for Data Protection and Freedom of Information of rejected requests for information annually, by 31 January of the year following the reference year.
The right to rectification: The data subject has the right to have the Data Controller rectify inaccurate personal data concerning them without undue delay, upon request. Taking into account the purpose of the processing, the data subject has the right to request the completion of incomplete personal data – including by means of a supplementary statement. At the same time, if the personal data does not correspond to the truth and the Data Controller has the personal data corresponding to the truth at its disposal, the Data Controller must rectify the personal data even without a request from the data subject.
The right to erasure, or in other words the "right to be forgotten": The data subject has the right to have the Data Controller erase personal data concerning them without undue delay upon request, and the Data Controller is obliged to erase personal data concerning the data subject without undue delay, unless mandatory data processing precludes this.
In addition to the above case, the Data Controller is obliged to erase the data under Act CXII of 2011 and Regulation (EU) 2016/679 of the European Parliament and of the Council if
- the processing of the data is unlawful;
- the data is incomplete or incorrect – and this cannot be lawfully remedied –, provided that erasure is not excluded by law;
- the purpose of the processing has ceased, or the statutory time limit for storing the data has expired;
- this has been ordered by a court or the Authority.
- the personal data is no longer necessary for the purpose for which it was collected or otherwise processed;
- the data subject objects to the processing and there is no overriding legitimate ground for the processing;
- the personal data must be erased in order to comply with a legal obligation applicable to the Data Controller;
- the personal data was collected in connection with the offer of information society services referred to in Article 8(1) of Regulation (EU) 2016/679, offered directly to children.
If the Data Controller has made the personal data public for any reason and is obliged to erase it under the above, it shall, taking into account the available technology and the cost of implementation, take reasonable steps – including technical measures – to inform other data controllers processing the data that the data subject has requested the erasure of links to, or copies or replicas of, the personal data in question.
The Data Controller draws the attention of data subjects to the restrictions on the right to erasure or the "right to be forgotten" arising from EU regulation, which are as follows:
- exercise of the right to freedom of expression and information;
- compliance with a legal obligation which requires processing under Union or Member State law applicable to the data controller, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller;
- reasons of public interest in the area of public health;
- archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) of Regulation (EU) 2016/679, in so far as the right to erasure is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
- the establishment, exercise or defence of legal claims.
The right to restriction of processing, or in other words the right to "blocking": The data subject has the right to have the Data Controller restrict the processing at their request.
If, based on the information available, it can be assumed that erasure would harm the legitimate interests of the data subject, the data must be blocked. Personal data thus blocked may only be processed for as long as the purpose of processing that precluded the erasure of the personal data persists.
If the data subject disputes the accuracy or correctness of the personal data, but the inaccuracy or incorrectness of the disputed personal data cannot be clearly established, the data will be blocked. In this case, the restriction applies for the period that allows the Data Controller to verify the accuracy of the personal data.
Under the EU regulation, the data must be blocked if
- the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of its use instead;
- the Data Controller no longer needs the personal data for the purposes of the processing, but the data subject requires it for the establishment, exercise or defence of legal claims; or
- the data subject has objected to the processing; in this case the restriction applies for the period until it is established whether the Data Controller's legitimate grounds override those of the data subject.
Where processing is restricted (blocked), such personal data may, with the exception of storage, only be processed with the data subject's consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or a Member State.
The Data Controller expressly draws the attention of data subjects to the fact that the data subject's right to rectification, erasure or blocking may be restricted by law for the protection of the state's external and internal security, including national defence, national security, the prevention or prosecution of criminal offences, the security of penal enforcement, as well as for state or local government economic or financial interests, the significant economic or financial interest of the European Union, and for the prevention and detection of disciplinary and ethical offences related to the exercise of occupations, and breaches of labour law and occupational safety obligations – including, in every case, control and supervision – as well as for the protection of the rights of the data subject or others.
The Data Controller shall, without undue delay, and no later than 30 days from receipt of the request, inform the data subject of the matters specified in their request and/or rectify the data and/or erase and/or restrict (block) the data, or take other steps in accordance with the request, unless there are grounds precluding this.
The Data Controller shall notify the data subject in writing of the rectification, erasure or restriction of processing, as well as all those to whom the data was previously transferred or disclosed for the purposes of processing. At the data subject's request, the Data Controller shall inform them of these recipients. Notification may be omitted if it does not harm the data subject's legitimate interest with regard to the purpose of processing, or if providing the information proves impossible or requires a disproportionate effort. The Data Controller is also obliged to notify the data subject in writing if the data subject's exercise of a right cannot be fulfilled for any reason, and is obliged to specify precisely the factual and legal reason, as well as the remedies available to the data subject: the possibility of turning to the court and to the National Authority for Data Protection and Freedom of Information.
The "right to data portability": The data subject has the right
- to receive the personal data concerning them, which they have provided to the Data Controller, in a structured, commonly used, machine-readable format, and
- to transmit that data to another data controller without hindrance from the data controller to which the personal data was provided, where:
- the processing is based on consent; and
- the processing is carried out by automated means.
In exercising the right to data portability, the data subject has the right to request – where technically feasible – the direct transmission of personal data between data controllers.
In view of the processing activities carried out by the Data Controller, the conditions for exercising the right to data portability are not met (there is no automated processing), and therefore the data subject cannot exercise this right.
The right to object: The data subject may object to the processing of their personal data – including profiling – if
- the processing (transfer) of personal data is necessary solely for the purpose of enforcing the right or legitimate interest of the Data Controller or the data recipient, except in the case of mandatory data processing;
- the personal data is used or transferred for the purposes of direct marketing, public opinion polling or scientific research;
- the exercise of the right to object is otherwise permitted by law.
The data subject may also object, pursuant to Article 21(3) of EU Regulation 2016/679, to the processing of personal data for direct marketing purposes, in which case the personal data may no longer be processed for that purpose.
Where personal data is processed for scientific and historical research purposes or for statistical purposes, the data subject has the right to object to the processing of personal data concerning them on grounds relating to their particular situation, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
The Data Controller shall – while simultaneously suspending the processing – examine the objection within the shortest possible time from the submission of the request, but within a maximum of 30 days, and shall inform the requester in writing of the outcome. If the requester's objection is well-founded, the Data Controller shall terminate the processing – including further data collection and transfer – and shall block the data, and shall notify all those to whom the personal data concerned by the objection was previously transferred, and who are obliged to take action to give effect to the right to object, of the objection and the measures taken on the basis thereof.
If the data subject does not agree with the Data Controller's decision, or if the Data Controller fails to meet the above deadline, the data subject is entitled to turn to the court within 30 days of being notified thereof.
The data subject has the right to object in connection with automated decision-making.
Judicial enforcement: The data subject may turn to the court in the event of a violation of their rights. The court shall deal with the case as a matter of priority. The Data Controller is obliged to prove that the processing complies with the requirements set out in the legislation.
In the event of a violation of the right to informational self-determination, a complaint may be lodged as follows:
National Authority for Data Protection and Freedom of Information
Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c, Hungary
Phone: +36 (1) 391-1400, Fax: +36 (1) 391-1410
www: http://www.naih.hu
e-mail: ugyfelszolgalat@naih.hu