Privacy Policy

Definitions:

  1. “Personal data”: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
  2. “Processing”: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
  3. “Restriction of processing”: the marking of stored personal data with the aim of limiting their processing in the future;
  4. “Profiling”: any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning work performance, economic situation, health status, personal preferences, interests, reliability, behavior, location or movements;
  5. “Pseudonymisation”: the processing of personal data in such a manner that the personal data can no longer be attributed to a specific natural person without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that the personal data are not attributed to an identified or identifiable natural person;
  6. “Filing system”: any structured set of personal data which are accessible according to specific criteria, whether centralized, decentralized or dispersed on a functional or geographical basis;
  7. “Controller”: the natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its designation may be provided for by Union or Member State law;
  8. “Processor”: a natural or legal person, public authority, agency or any other body which processes personal data on behalf of the controller;
  9. “Recipient”: a natural or legal person, public authority, agency or any other body, to which the personal data are disclosed, whether a third party or not. Public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall comply with the applicable data protection rules according to the purposes of the processing;
  10. “Third party”: a natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data;
  11. “Consent of the data subject”: any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
  12. “Personal data breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed;

 

1. Purpose of this Privacy Policy

Industrial Project Solutions Kft. (hereinafter: Controller), as data controller, acknowledges the content of this legal notice as binding upon itself. It undertakes that all data processing related to its activities shall comply with the expectations set out in this policy and in the applicable national legislation and legal acts of the European Union.

The data protection guidelines relating to the Controller’s data processing activities are continuously available at:
https://ips-kft.hu/adatkezelesi-tajekoztato/

The Controller reserves the right to amend this policy at any time. Naturally, it shall notify its audience of any possible changes in due time.

The Controller is committed to protecting the personal data of its clients and partners and considers it particularly important to respect the right to informational self-determination of its clients. The Controller handles personal data confidentially and takes all security, technical and organizational measures that guarantee the security of the data.

 

2. Details of the Data Controller

Név: Industrial Project Solutions Kft.
Székhely: 9030 Győr Örvény utca 7/a
Nyilvántartási szám: 08-09-037033
A bejegyző bíróság megnevezése: Győri Törvényszék
Adószám: 32625004-2-08
E-mail: info@ips-kft.hu

3. Scope of Processed Personal Data

3.1 Personal Data Provided During Request for Quotation

  • Name
  • Email address
  • Phone number

3.2 Technical Data

The Controller selects and operates the IT tools used for providing the service in such a way that the processed data:

• are accessible to those entitled to access them (availability);
• their authenticity and authentication are ensured (authenticity of data processing);
• their integrity can be verified (data integrity);
• are protected against unauthorized access (confidentiality of data).

The Controller protects the data with appropriate measures against unauthorized access, alteration, transmission, disclosure, deletion or destruction, as well as against accidental destruction.

The Controller ensures the protection of the security of data processing by technical, organizational and organizational measures that provide a level of protection appropriate to the risks arising in connection with data processing.

During data processing the Controller preserves:

• confidentiality: it protects the information so that only those authorized can access it;
• integrity: it protects the accuracy and completeness of the information and the method of processing;
• availability: it ensures that when the authorized user needs it, they can actually access the desired information and the related tools are available.

 

3.3 Cookies

3.3.1 The purpose of cookies

In order to provide customized service, a small data package, so-called cookie, is placed on the user’s computer and read back during a subsequent visit. If the browser sends back a previously saved cookie, the service provider managing the cookie has the opportunity to link the user’s current visit with previous ones, but exclusively in respect of its own content.

• collect information about visitors and their devices;
• remember visitors’ individual settings which may be used;
• facilitate the use of the website;
• provide a quality user experience.

3.3.2 Strictly necessary, session cookies

The purpose of these cookies is to enable visitors to browse the Controller’s website fully and smoothly, use its functions and the services available there. The validity period of this type of cookie lasts until the end of the session (browsing), and by closing the browser this type of cookie is automatically deleted from the computer or other device used for browsing.

3.3.3 Cookies placed by third parties (analytics)

The Controller may use Google Analytics as a third-party cookie on its website. By using the statistical service of Google Analytics, the Controller may collect information regarding how visitors use the website. The data may be used for the purpose of developing the website and improving the user experience. These cookies also remain on the visitor’s computer or other device used for browsing, in its browser, until their expiration or until the visitor deletes them.

4. Purpose, Method and Legal Basis of Processing

4.1 General Data Processing Principles

The data processing activities of the Controller are based on voluntary consent or statutory authorization. In the case of data processing based on voluntary consent, data subjects may withdraw their consent at any stage of the processing.

In certain cases, the processing, storage and transmission of a set of provided data are made mandatory by law, about which our clients are informed separately.

We draw the attention of data providers to the fact that if they do not provide their own personal data, it is the obligation of the data provider to obtain the consent of the data subject.

The Controller’s data processing principles are in accordance with the applicable data protection legislation, in particular with the following:

• Act CXII of 2011 – on the Right of Informational Self-Determination and on Freedom of Information (Infotv.);
• Regulation (EU) 2016/679 of the European Parliament and of the Council (27 April 2016) – on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation – GDPR);
• Act V of 2013 – on the Civil Code (Ptk.);
• Act C of 2000 – on Accounting (Accounting Act);
• Act LIII of 2017 – on the Prevention and Combating of Money Laundering and Terrorist Financing (Pmt.);
• Act CCXXXVII of 2013 – on Credit Institutions and Financial Enterprises (Hpt.).

 

5. Data Transfer, Data Processing, and Persons Entitled to Access the Data

Hosting provider, email system provider:

Name / company name: Microsoft Ireland Operations Limited
Registered office: One Microsoft Place, South County Business Park, Leopardstown, Dublin 18 D18 P521
Telephone: –
E-mail: –
Contact: https://support.microsoft.com/contactus

 

Name / company name: Rackhost Zrt.
Registered office: 6722 Szeged, Tisza Lajos körút 41.
Telephone: –
E-mail: info@rackhost.hu
Contact: https://www.rackhost.hu/contact

 

Web Developer:

Name / company name: Balázs Mészáros, sole trader
Registered office: 9245 Mosonszolnok, Szabadság út 18.
Telephone: –
E-mail: info@badekdesign.com
Contact: https://badekdesign.com/

The data provided by you are stored on a server operated by the hosting provider. The data may only be accessed by our employees and the employees operating the server, all of whom are responsible for the secure handling of the data.

The purpose of the data processing is to fulfill requests for information / quotation or other inquiries, and to ensure the operation of the website. The processed data are the personal data provided by you.

Data processing takes place until the termination of the website’s operation, or for the period specified in the contractual agreement between the website operator and the hosting provider.

If necessary, you may request the deletion of your data directly from the hosting provider.

The legal basis of data processing is your consent and/or data processing based on legal obligation.

 

6. Rights of the Data Subject

The Data Subject may request information regarding the processing of their personal data and may request the rectification of their personal data, or — except for mandatory data processing — the erasure or withdrawal thereof, and may exercise their right to data portability and objection in the manner indicated at the time of data collection or via the contact details of the Data Controller provided above.

6.1 Right to Information

The Data Controller shall take appropriate measures to provide the Data Subject with all information referred to in Articles 13 and 14 of the GDPR and all communications under Articles 15–22 and 34 in a concise, transparent, intelligible and easily accessible form, using clear and plain language.

6.2 Right of Access by the Data Subject

The Data Subject shall have the right to obtain confirmation from the Data Controller as to whether or not personal data concerning them are being processed, and, where that is the case, access to the personal data and the following information:

  • the purposes of the processing;
  • the categories of personal data concerned;
  • the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organizations;
  • the envisaged period for which the personal data will be stored;
  • the right to request rectification, erasure or restriction of processing and to object to processing;
  • the right to lodge a complaint with a supervisory authority;
  • information as to the source of the data;
  • the existence of automated decision-making, including profiling, meaningful information about the logic involved, and the significance and envisaged consequences of such processing for the Data Subject.

The Data Controller shall provide the requested information within one month from receipt of the request.

6.3 Right to Rectification

The Data Subject may request the correction of inaccurate personal data concerning them processed by the Data Controller and the completion of incomplete data.

6.4 Right to Erasure (“Right to be Forgotten”)

The Data Subject shall have the right to obtain from the Data Controller the erasure of personal data concerning them without undue delay where one of the following grounds applies:

  • the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
  • the Data Subject withdraws consent and there is no other legal ground for processing;
  • the Data Subject objects to the processing and there are no overriding legitimate grounds;
  • the personal data have been unlawfully processed;
  • the personal data must be erased for compliance with a legal obligation under Union or Member State law;
  • the personal data were collected in relation to the offer of information society services.

Erasure shall not apply where processing is necessary:

  • for exercising the right of freedom of expression and information;
  • for compliance with a legal obligation;
  • for reasons of public interest;
  • for archiving, scientific or historical research or statistical purposes;
  • for the establishment, exercise or defense of legal claims.

6.5 Right to Restriction of Processing

The Data Subject shall have the right to obtain restriction of processing where:

  • the accuracy of the personal data is contested (for a period enabling verification);

  • the processing is unlawful and the Data Subject opposes erasure;

  • the Data Controller no longer needs the data but they are required for legal claims;

  • the Data Subject has objected to processing pending verification of overriding grounds.

Where processing has been restricted, personal data may only be processed, with the exception of storage, with consent or for legal claims, protection of rights of another person, or important public interest.

6.6 Right to Object

The Data Subject shall have the right to object, on grounds relating to their particular situation, at any time to processing necessary for:

  • the performance of a task carried out in the public interest;
  • the exercise of official authority;
  • legitimate interests pursued by the Data Controller or a third party, including profiling.

In such case, personal data shall no longer be processed unless compelling legitimate grounds override the interests, rights and freedoms of the Data Subject or for legal claims.

 

6.7 Automated Individual Decision-Making, Including Profiling

The Data Subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.

6.8 Right to Withdraw Consent

The Data Subject shall have the right to withdraw their consent at any time.

6.9 Data Protection Authority Procedure

Panasszal a Nemzeti Adatvédelmi és Információszabadság Hatóságnál lehet élni:
Név: Nemzeti Adatvédelmi és Információszabadság Hatóság
Székhely: 1125 Budapest, Szilágyi Erzsébet fasor 22/C. Levelezési cím: 1530 Budapest, Pf.: 5.
Telefon: +3613911400
Fax: +3613911410
E-mail: ugyfelszolgalat@naih.hu

Honlap: http://www.naih.hu

7. Miscellaneous Provisions

Information regarding data processing not listed in this Policy shall be provided at the time of data collection.

We inform our clients that courts, prosecutors, investigating authorities, misdemeanor authorities, administrative authorities, the National Authority for Data Protection and Freedom of Information, the Hungarian National Bank, as well as other bodies authorized by law may contact the Controller for the purpose of providing information, communicating data, transferring data or making documents available.

The Controller shall provide personal data to authorities — provided that the authority has specified the exact purpose and the scope of the data — only to the extent and in such amount as is strictly necessary for the realization of the purpose of the request.