Privacy Policy
In effect from
Data Protection and Data Processing Policy
Name of the organisation: GG Development Kft.
Registered office: 1115 Budapest, Ildikó utca 8., Hungary
Company registration number: 01-09-458529
Tax number: 25972696-2-43
Contact: info@gg.dev
This policy sets out the rules governing the protection of natural persons with regard to the processing of personal data and the free movement of personal data. The provisions of this policy shall apply to specific data processing activities and to the preparation and issuance of instructions and information notices governing data processing.
The obligation to appoint a data protection officer applies to public authorities and bodies carrying out public tasks, regardless of the types of personal data they process, as well as to organisations whose core activities involve the regular and systematic monitoring of individuals on a large scale or the processing of special categories of personal data on a large scale. The organisation has not appointed a data protection officer.
1. Scope of this policy
This policy remains in force until revoked and applies to the officers and employees of the organisation.
2. Purpose of this policy
The purpose of this policy is to harmonise the organisation's internal policies relating to data processing in order to protect the fundamental rights and freedoms of natural persons and to ensure the proper handling of personal data.
In carrying out its activities, the organisation is committed to complying fully with the legal requirements applicable to the processing of personal data, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council.
A further important purpose of this policy is to ensure that, by understanding and following it, the organisation's employees are able to process personal data lawfully.
3. Key terms and definitions
GDPR (General Data Protection Regulation): Regulation (EU) 2016/679 of the European Union on the protection of natural persons with regard to the processing of personal data.
Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by Union or Member State law, that law may also determine the controller or the specific criteria applicable to its designation.
Processing: any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Processor: the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Personal data: any information relating to an identified or identifiable natural person (the "data subject"). A natural person is considered identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data or an online identifier, or to one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity.
Third party: a natural or legal person, public authority, agency or body other than the data subject, the controller, the processor, or persons who, under the direct authority of the controller or processor, are authorised to process personal data.
Consent of the data subject: any freely given, specific, informed and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify their agreement to the processing of personal data relating to them.
Restriction of processing: the marking of stored personal data with the aim of limiting its processing in the future.
Pseudonymisation: the processing of personal data in such a manner that the personal data can no longer be attributed to a specific natural person without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data cannot be attributed to an identified or identifiable natural person.
Filing system: any structured set of personal data which is accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis.
Personal data breach: a breach of security leading to the accidental or unlawful destruction, loss or alteration of, or unauthorised disclosure of or access to, personal data transmitted, stored or otherwise processed.
4. Principles of data processing
Personal data must be processed lawfully, fairly and transparently in relation to the data subject.
Personal data may only be collected for specified, explicit and legitimate purposes.
The processing of personal data must be adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed.
Personal data must be accurate and kept up to date where necessary. Inaccurate personal data must be erased or rectified without undue delay.
Personal data must be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which it is processed. Personal data may be stored for longer periods only where the processing is for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, subject to the applicable legal requirements.
Personal data must be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical and organisational measures.
The principles of data protection apply to any information relating to an identified or identifiable natural person.
Employees of the organisation who carry out data processing may be subject to disciplinary, civil, administrative or criminal liability for unlawful processing of personal data. Where an employee becomes aware that personal data they process is inaccurate, incomplete or out of date, they must correct it or request that it be corrected by the colleague responsible for recording the data.
5. Processing of personal data
Natural persons may be associated with the online identifiers made available by the devices, applications, tools and protocols they use, such as IP addresses and cookie identifiers. When combined with other information, such data may be capable of identifying individuals or contributing to the creation of profiles.
Where processing is based on consent, it may only take place if the data subject has given voluntary, specific, informed and unambiguous consent to the processing of their personal data by means of a clear affirmative action, such as a written statement, including one made electronically, or an oral statement.
Ticking a relevant box while using a website may constitute consent. Silence, pre-ticked boxes and inactivity do not constitute consent. Consent may also be given where a user makes the relevant technical settings while using electronic services or makes a statement or takes an action which, in the circumstances, clearly indicates the data subject's consent to the processing of their personal data.
The organisation does not process health data.
The personal data of children deserves particular protection because children may be less aware of the risks, consequences, safeguards and rights associated with the processing of personal data. This particular protection applies especially to the use of children's personal data for marketing purposes or for creating personality or user profiles. The organisation's website is aimed at businesses and is not directed at children.
Personal data must be processed in a manner that ensures an appropriate level of security and confidentiality, including protection against unauthorised access to, or unauthorised use of, personal data and the equipment used for processing. Every reasonable step must be taken to rectify or erase inaccurate personal data.
6. Cookies, tracking and other technologies
The Statistics cookies listed above are only placed if you have given your consent through the consent-management platform. You can withdraw or change your consent at any time through the settings of the consent-management platform above.
7. Lawfulness of data processing
The processing of personal data is lawful where one of the following applies:
- the data subject has given consent to the processing of their personal data for one or more specific purposes;
- processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract;
- processing is necessary for compliance with a legal obligation to which the controller is subject;
- processing is necessary to protect the vital interests of the data subject or another natural person;
- processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; or
- processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, except where those interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
In line with the above, processing may be lawful where it is necessary in the context of a contract or in order to take steps at the request of the data subject before entering into a contract.
Where processing is necessary for compliance with a legal obligation to which the controller is subject, or is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, the processing must be based on Union or Member State law.
Processing may be lawful where it is necessary to protect the life of the data subject or the vital interests of another natural person. Processing based on the vital interests of another natural person should in principle only be used where the processing cannot reasonably be based on another legal basis.
The legitimate interests of the controller, including a controller to which personal data may be disclosed, or of a third party may provide a legal basis for processing. Such a legitimate interest may exist where there is a relevant and appropriate relationship between the data subject and the controller, for example where the data subject is a customer or employee of the controller.
The processing of personal data that is strictly necessary to prevent fraud may constitute a legitimate interest of the controller.
In determining whether a legitimate interest exists, careful consideration must be given, among other things, to whether the data subject could reasonably expect, at the time and in the context of the collection of the personal data, that processing for the relevant purpose might take place. The interests and fundamental rights and freedoms of the data subject may override the interests of the controller where personal data is processed in circumstances in which the data subject does not reasonably expect such further processing.
The processing of personal data that is strictly necessary and proportionate to ensure network and information security may constitute a legitimate interest of the controller concerned.
Processing personal data for a purpose other than the purpose for which it was originally collected is permitted only where the new processing is compatible with the original purposes. In such cases, no separate legal basis is required where the original legal basis also covers the further processing.
For the website of the organisation, the main legal bases used are consent, pre-contractual steps, legal obligations and legitimate interests, depending on the particular processing activity described in this policy. Where we rely on legitimate interests, these include responding to business enquiries, maintaining the security and availability of the website, preventing abuse and maintaining reliable IT systems.
8. Consent of the data subject and conditions for consent
Where processing is based on consent, the controller must be able to demonstrate that the data subject has consented to the processing of their personal data.
Where consent is given in the context of a written statement which also concerns other matters, the request for consent must be presented in a manner that is clearly distinguishable from those other matters.
The data subject has the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. The data subject must be informed of this before giving consent. It must be as easy to withdraw consent as it is to give it.
In assessing whether consent is freely given, particular consideration must be given to whether the performance of a contract, including the provision of a service, has been made conditional on consent to the processing of personal data that is not necessary for the performance of that contract.
Where consent is required for optional statistics, you can accept or refuse statistics separately from the necessary operation of the website. You can withdraw your consent to statistics at any time through the privacy settings provided by our consent-management platform.
Where consent is required for processing relating to information society services offered directly to children, the applicable requirements of Article 8 GDPR and Hungarian law shall apply.
The processing of special categories of personal data is prohibited unless an applicable legal basis under Article 9 GDPR applies, including where the data subject has given explicit consent for one or more specified purposes.
The processing of personal data relating to criminal convictions and offences or related security measures may take place only in accordance with Article 10 GDPR and applicable law.
9. Processing not requiring identification
Where the purposes for which the controller processes personal data do not, or no longer, require the identification of the data subject, the controller is not obliged to maintain additional information solely for the purpose of identifying the data subject.
Where the controller can demonstrate that it is not in a position to identify the data subject, the data subject will be informed accordingly where possible.
10. Information provided to the data subject and their rights
The principle of fair and transparent processing requires that data subjects be informed about the fact that their personal data is being processed and about the purposes of that processing.
Where personal data is collected directly from the data subject, the data subject must also be informed whether they are obliged to provide the personal data and of the consequences of failing to provide it. This information may be supplemented with standardised icons so that the data subject receives clear, easily understandable and legible information about the intended processing.
Information relating to the processing of personal data must be provided at the time the personal data is collected. Where personal data is obtained from a source other than the data subject, the information must be provided within a reasonable period, taking the circumstances of the case into account.
For processing carried out through our website, the relevant information is provided at or before the point of collection, including through the information accompanying our enquiry form and our consent-management mechanism.
The data subject has the right to access their personal data and to exercise that right easily and at reasonable intervals in order to establish and verify the lawfulness of the processing. Data subjects must also be informed, in particular, about the purposes of processing and, where possible, the period for which the personal data will be processed.
The data subject has the right to have their personal data erased and no longer processed where the applicable requirements for erasure are met, including where the personal data is no longer necessary for the purposes for which it was collected or where consent has been withdrawn and no other legal basis applies.
Where personal data is processed for direct marketing purposes, the data subject has the right to object at any time and free of charge to the processing of their personal data for that purpose. We do not currently carry out direct marketing through our website.
11. Review and retention of personal data
To ensure that personal data is retained only for as long as necessary, the controller shall establish erasure or regular review periods. The regular review period established by the head of the organisation is: 1 year.
12. Duties of the controller
In order to ensure lawful processing, the controller maintains appropriate internal data protection rules and procedures. These rules cover the controller's responsibilities and areas of authority.
The controller must implement appropriate and effective measures and be able to demonstrate that its processing activities comply with applicable legislation.
These measures and procedures must take into account the nature, scope, context and purposes of the processing and the risks to the rights and freedoms of natural persons.
The controller or processor must maintain appropriate records of processing activities where required by law and must cooperate with the competent supervisory authority.
13. Rights relating to data processing
Right to request information
Any person may, using the contact details provided, request information about what personal data the organisation processes about them, the legal basis and purpose of the processing, the source of the data, and the period for which it is processed.
The organisation shall provide the requested information without undue delay and, in any event, within one month of receiving the request. Where necessary, taking into account the complexity and number of requests, this period may be extended by a further two months. The organisation shall inform the data subject of any such extension within the first month.
Right to rectification
Any person may, using the contact details provided, request the correction or completion of their personal data. The organisation shall take the necessary action without undue delay and, in any event, within one month of receiving the request. Where necessary, this period may be extended by a further two months in accordance with the GDPR.
Right to erasure
Any person may, using the contact details provided, request the erasure of their personal data where the applicable legal conditions are met. The organisation shall act without undue delay and, in any event, within one month of receiving the request. Where necessary, this period may be extended by a further two months in accordance with the GDPR.
Right to restriction of processing
Any person may, using the contact details provided, request the restriction of the processing of their personal data where the applicable legal conditions are met. The organisation shall act without undue delay and, in any event, within one month of receiving the request. Where necessary, this period may be extended by a further two months in accordance with the GDPR.
Right to object
Any person may, using the contact details provided, object to the processing of their personal data where the applicable legal conditions are met. The organisation shall examine the objection without undue delay and, in any event, within one month of receiving it. Where necessary, this period may be extended by a further two months in accordance with the GDPR, taking into account the complexity and number of requests.
14. Remedies relating to data processing
If you believe that your rights have been infringed or that your personal data is being processed unlawfully, you may lodge a complaint with the competent data protection supervisory authority or bring court proceedings against the controller in accordance with applicable law.
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH — Hungarian National Authority for Data Protection and Freedom of Information)
Postal address: 1363 Budapest, Pf. 9., Hungary
Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
Phone: +36 (1) 391-1400
Email: ugyfelszolgalat@naih.hu
Website: naih.hu
A data subject may also have the right, under applicable law, to bring an action before the competent court against the controller. The data subject may, where permitted by law, bring the action before the court competent for their place of residence or habitual residence.
15. Duties of the organisation in relation to appropriate data protection
The organisation shall take appropriate measures to ensure the professional knowledge and awareness necessary for compliance with data protection legislation.
The processing activities, their purposes and the relevant data protection arrangements shall be reviewed as necessary to ensure that processing remains lawful.
Where processing is based on consent, the organisation must be able to demonstrate that valid consent has been obtained.
Information provided to data subjects must be concise, easily accessible and easy to understand and must therefore be written and presented in clear and plain language.
Transparent processing requires that data subjects be informed about the fact and purposes of processing. Information must be provided before or at the time processing begins and must remain available for as long as necessary.
The principal rights of data subjects include:
- access to their personal data;
- rectification of personal data;
- erasure of personal data;
- restriction of processing;
- objection to processing, including objection to profiling and automated decision-making where applicable; and
- data portability where the GDPR requirements are met.
The controller shall provide the data subject with information without undue delay and, in any event, within one month of receiving the request. Where necessary, taking into account the complexity and number of requests, this period may be extended by a further two months. The obligation to provide information may be fulfilled by operating a secure online system through which the data subject can easily and quickly access the necessary information.
The organisation shall review the data processing activities it carries out and ensure that the right to informational self-determination is respected. At the request of the data subject, their personal data shall be erased without undue delay where the data subject withdraws the consent on which the processing is based. It must be clear and unambiguous from the data subject's consent that they agree to the processing of their personal data. Where processing is based on the data subject's consent, the controller shall be responsible for demonstrating, in the event of doubt, that the data subject consented to the processing operation.
Where children's personal data is processed, particular attention shall be paid to compliance with the applicable data protection rules. In relation to information society services offered directly to children, the processing of personal data is lawful where the child has reached the age of 16. Where the child is under 16, processing of the child's personal data is lawful only to the extent that consent is given or authorised by the person who has parental responsibility for the child.
Where personal data is processed or handled unlawfully, an obligation to notify the supervisory authority may arise. The controller shall notify the supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of the personal data breach, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.
In certain circumstances, it may be necessary for the controller to carry out a data protection impact assessment before commencing processing. The assessment shall examine how the proposed processing operations affect the protection of personal data. Where the data protection impact assessment indicates that the processing is likely to result in a high risk, the controller shall consult the supervisory authority before commencing the processing, as required by applicable law.
Where the controller's core activities consist of processing operations which, by virtue of their nature, scope or purposes, require regular and systematic monitoring of data subjects on a large scale, a data protection officer shall be appointed. The appointment of a data protection officer is intended to strengthen data protection and security.
16. Data security
Personal data must be protected by appropriate measures against, in particular, unauthorised access, alteration, transmission, disclosure, erasure or destruction, as well as against accidental destruction or damage and loss of accessibility resulting from changes in the technology used.
In order to protect electronically processed personal data held in filing systems, appropriate technical measures must be implemented to ensure that the data stored in those filing systems cannot be directly linked to or attributed to the data subjects.
When designing and implementing data security measures, the current state of technology must be taken into account. Where several possible data processing solutions are available, the solution that provides a higher level of protection for personal data should be selected, unless doing so would impose a disproportionate burden on the controller.
17. Personal data breaches
A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss or alteration of, or unauthorised disclosure of or access to, personal data transmitted, stored or otherwise processed.
A personal data breach may cause physical, material or non-material damage to natural persons, including loss of control over their personal data, limitation of their rights and freedoms, discrimination, identity theft or fraud.
Where required by the GDPR, a personal data breach shall be notified to the competent supervisory authority without undue delay and, where feasible, within 72 hours after the organisation becomes aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the affected data subject shall be informed without undue delay where required by the GDPR.
18. Processing for administrative and record-keeping purposes
The organisation may process personal data as necessary for administrative and record-keeping purposes connected with its activities.
Such processing may be based on a legal obligation, contractual necessity or legitimate interest, depending on the circumstances.
Administrative and record-keeping processing may include:
- the processing of data relating to employees and other personnel where required by law or necessary for the employment relationship;
- the processing of data relating to persons in a contractual relationship with the organisation for contact, accounting and record-keeping purposes; and
- the processing of contact and identification details of representatives and contact persons of organisations, institutions and businesses with which the organisation has a business relationship.
The applicable legal basis depends on the particular processing activity and may include a statutory obligation, contractual necessity or legitimate interest.
Where documents containing personal data are submitted to the organisation, such as a CV, job application or other submission, the data may be processed for the purpose for which the document was provided and for as long as necessary for that purpose or as required by law.
Administrative and record-keeping data shall be retained only for as long as necessary for the relevant purpose or legal obligation and shall be reviewed periodically.
19. Processing for other purposes
Where the organisation intends to carry out processing that is not described in this policy, the relevant processing activities and legal basis shall be assessed before the new processing begins.
Where a new processing activity is introduced through the website that is materially different from the processing described in this policy, we will update this policy as required and provide any additional information or obtain any consent required by law before the new processing begins.
20. Other documents relating to this policy
Where appropriate, this policy shall be supplemented by other documents and information governing specific processing activities, including information provided at the point of collection and consent records relating to website processing.
Where appropriate, additional information may be provided directly at the point of collection, including through the enquiry form and our consent-management platform.
21. Legislation forming the basis of the processing
REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
Act CXII of 2011 on Informational Self-Determination and Freedom of Information.
Act LXVI of 1995 on Public Records, Public Archives, and the Protection of Private Archives.
Government Decree No. 335/2005 (XII. 29.) on the general requirements for records management by public bodies.
Act CVIII of 2001 on certain issues relating to electronic commerce services and information society services.
Act C of 2003 on Electronic Communications.