Privacy notice

1. Introduction

Péter Horváth, sole trader (hereinafter Péter Horváth sole trader, service provider, controller, the Company), as data controller, regards the contents of this legal notice as binding on himself.
The Company undertakes that all processing related to its activity will meet the expectations set out in this policy and in the applicable legislation.
Péter Horváth, sole trader, operates the albaenergetika.hu website.

Péter Horváth, sole trader, reserves the right to change this notice at any time. Naturally, the public will be informed of any changes in good time.

Péter Horváth, sole trader, is committed to protecting the personal data of his clients and partners and considers it especially important to respect their right to informational self-determination. The Controller treats personal data as confidential and takes every security, technical and organisational measure that guarantees the security of the data.

Below, Péter Horváth, sole trader, sets out his data-processing principles and the expectations he has defined for himself as controller and which he observes. His data-processing principles are in line with the legislation in force on data protection, in particular:

  • Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information;
  • Act V of 2013 on the Civil Code (Ptk.);
  • Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities (Grt.);
  • Act CVIII of 2001 (Ekertv.) on certain issues of electronic commerce services and information society services;
  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter “GDPR”).

2. Definitions

  • data subject: any specified natural person identified or — directly or indirectly — identifiable on the basis of personal data;
  • personal data: data that can be associated with the data subject — in particular the data subject’s name, identifier, and one or more pieces of information characteristic of the data subject’s physical, physiological, mental, economic, cultural or social identity — as well as any conclusion that can be drawn from the data concerning the data subject;
  • consent: the data subject’s voluntary and definite expression of will, based on appropriate information, by which they give unambiguous agreement to the processing of personal data relating to them — in full or limited to certain operations;
  • controller: the natural or legal person, or organisation without legal personality, which, alone or jointly with others, determines the purposes of processing, takes the decisions concerning processing (including the means used) and implements them, or has them implemented by a processor;
  • processing: regardless of the method used, any operation or set of operations performed on data, in particular collection, recording, organisation, storage, alteration, use, retrieval, transmission, disclosure, alignment or combination, restriction, erasure and destruction, as well as preventing further use of the data, taking photographs, audio or video recordings, and recording physical characteristics suitable for identifying a person (e.g. fingerprint or palm print, DNA sample, iris image);
  • transmission: making the data available to a specified third party;
  • disclosure: making the data available to anyone;
  • erasure: making the data unrecognisable in such a way that they can no longer be restored;
  • processing (technical): carrying out technical tasks related to processing operations, regardless of the method and means used to perform the operations and of the place of application, provided that the technical task is performed on the data;
  • processor: the natural or legal person, or organisation without legal personality, which processes data on the basis of a contract — including a contract concluded pursuant to legislation.

3. Company details

The controller’s details and contact information are as follows:

  • Name: Péter Horváth, sole trader
  • Registered office / mailing address: 8000 Székesfehérvár, Gáz utca 9, buildings A–C, 6th floor, door 20
  • Registration number: 52562590
  • Tax number: 69006494-1-27
  • Statistical number: 69006494711223107
  • Main activity: 711209 – Engineering design and consultancy related to industrial activity
  • Other activity: 712003 – Energy performance certification
  • Phone: +36 70 516 3968
  • E-mail:  peter.horvath.ev@gmail.com
  • Controller / representative: Péter Horváth

4. Scope of personal data, purpose, legal basis and duration of processing

We draw the attention of those providing data to Péter Horváth, sole trader, that if they do not provide their own personal data, it is the provider’s duty to obtain the data subject’s consent. The controller is not obliged to verify this. The controller notes that if the partner fails to meet this obligation and the data subject asserts a claim against the controller, the controller may pass on the asserted claim and related damage to the partner.

We provide the following information in connection with our individual processing activities.

4.1. Quote requests and enquiries by direct contact

Interested parties may contact the Company directly by electronic mail sent to the Company’s address, or by phone.

  • Purpose of processing: maintaining contact in order to facilitate communication between the data subject and the Company and to achieve closer and more effective cooperation.
  • Legal basis: legitimate interest — GDPR Article 6(1)(f)
  • Personal data processed: name of the person requesting a quote / contact person; e-mail address, phone number and any other information provided by the data subject
  • Duration of processing: for 3 years after the quote validity period, or until the data subject objects
  • Recipients: except for the processor(s) named in section 7, the controller does not transfer the data learned to third parties. Only the Controller’s staff and the designated colleagues of the processor(s) may access the recorded data.
  • Legitimate interest: the Company’s legitimate interest in processing the data subject’s data — direct business acquisition
  • Data subjects: partners and data subjects who enquire directly (e.g. by e-mail or phone) about the Company’s services

4.2. Quote requests and enquiries via the website (albaenergetika.hu)

Our company provides the option for data subjects to request a quote electronically.

  • Purpose of processing: maintaining contact in order to facilitate communication between the data subject and the Company and to achieve closer and more effective cooperation.
  • Legal basis: the data subject’s voluntary consent — GDPR Article 6(1)(a).
  • Personal data processed: enquirer’s name (first name, last name); e-mail address, phone number, company name and any other information provided by the data subject.
  • Duration of processing: for 3 years after the quote validity period, or until consent is withdrawn.
  • Recipients: except for the processor(s) named in section 7, the controller does not transfer the data learned to third parties. Only the Controller’s staff and the designated colleagues of the processor(s) may access the recorded data.
  • Data subjects: partners and data subjects who enquire about the Company’s services or products via the website.

4.3. Processing related to following up quote requests

  • Purpose of processing: the controller’s legitimate interest in keeping the data subject’s data on record beyond the quote validity period for direct business acquisition
  • Legal basis: the controller’s legitimate interest, GDPR Article 6(1)(f)
  • Personal data processed: contact person’s last name and first name; phone number; e-mail address
  • Recipients: except for the processor(s) named in section 7, the controller does not transfer the data learned to third parties. Only the Controller’s staff and the designated colleagues of the processor(s) may access the recorded data.
  • Duration of processing: until the data subject objects
  • Legitimate interest: establishing business relations with partners and quote requesters, providing accurate information to data subjects. The Company’s legitimate interest in processing the data subject’s data — direct business acquisition
  • Data subjects: addressees of quotes previously issued by the Company and the contact person(s) named therein.

4.4. Newsletter registration

  • Purpose of processing: sending e-mail newsletters that may also contain commercial advertising to interested parties, and providing information about current news
  • Legal basis: the data subject’s prior, voluntary consent, GDPR Article 6(1)(a)
  • Personal data processed: name, e-mail address
  • Duration of processing: until voluntary consent is withdrawn, or until unsubscription from the newsletter. The Company processes the data provided by the data subject until consent is withdrawn. Based on withdrawal of consent we delete the processed data from our newsletter database within 7 days at the latest, and we will not send you newsletters thereafter.
  • Recipients: except for the processor(s) named in section 7, the controller does not transfer the data learned to third parties. Only the Controller’s staff and the designated colleagues of the processor(s) may access the recorded data. You may unsubscribe from the newsletter at any time by writing to the Company at peter.horvath.ev@gmail.com, or by clicking the unsubscribe icon in the newsletter.
  • Data subjects: partners and data subjects who subscribe to the Company’s electronic newsletter.

4.5. Newsletter data (newsletters registered before 25 May 2018)

  • Purpose of processing: sending e-mail newsletters that may also contain commercial advertising to interested parties, and providing information about current news
  • Legal basis: the controller’s legitimate interest, GDPR Article 6(1)(f)
  • Personal data processed: name, e-mail address
  • Duration of processing: until the data subject objects
  • Legitimate interest: providing information that may also contain commercial advertising and business offers to data subjects who subscribed to the newsletter. The Company’s legitimate interest in processing the data subject’s data, direct business acquisition.
  • Recipients: except for the processor(s) named in section 7, the controller does not transfer the data learned to third parties. Only the Controller’s staff and the designated colleagues of the processor(s) may access the recorded data. You may unsubscribe from the newsletter at any time by writing to the Company at peter.horvath.ev@gmail.com, or by clicking the unsubscribe icon in the newsletter.
  • Data subjects: partners and data subjects who subscribed to the Company’s electronic newsletter before 25 May 2018.

4.6. Camera system

The controller currently does not operate a camera system at its premises or registered office, and therefore does not process personal data in connection with camera surveillance.

4.7. Processing related to ensuring the operation of information technology services

  • Purpose of processing: Péter Horváth, sole trader, may use so-called “cookies” (temporary markers) on his websites, which allow faster access. A “cookie” means an information item that is active only during the given client session and is placed from the website onto the Client’s computer for faster identification. The Client may always request that cookies be disabled by changing the browser settings; this disablement may, however, slow down or prevent access to some parts of the site and the use of certain functions.
    The session cookies used avoid the need to resort to other IT tools that could potentially harm the confidentiality of clients’ navigation and do not allow personal identifying data to be obtained.
    The user can delete the cookie from their own computer and can disable the use of cookies in their browser. Cookies can generally be managed in the browser’s Tools/Settings menu under Privacy settings, under the name cookie.
  • Legal basis: the data subject’s (User’s) voluntary consent, GDPR Article 6(1)(a).
    The User gives voluntary consent to processing by accepting the information and declaration that appears when they start browsing the site, or by continuing to browse.
    Personal data processed: information-technology processing covers the data required for the operation of the “cookies” used to operate the site and for the use of log files applied by the web hosting provider.
  • Duration of processing: until the end of the session
  • Recipients: except for the processor(s) named in section 7, the controller does not transfer the data learned to third parties. Only the Controller’s staff and the designated colleagues of the processor(s) may access the recorded data.
  • Data subjects: every User who visits the website, regardless of whether they use the services available on the site.

5. Other processing

We provide information about processing not listed in this notice at the time the data are collected. We inform our clients that certain authorities, bodies performing public tasks and courts may contact our company for the communication of personal data. Our company discloses personal data to these bodies — if the requesting body has specified the exact purpose and the scope of the data — only to the extent indispensable for achieving the purpose of the request, and only if fulfilment of the request is prescribed by law.

6. Transfer of personal data to a third country or international organisation

The Company does not transfer your personal data above either to a third country or to an international organisation.

7. Information on the use of a processor

In the course of processing, the controller transfers the data to the processor(s) contracted with it for performance of the contract.
Categories of recipients: system administration provider, accounting and payroll provider, server hosting, web hosting provider

8. Children

Our services are not intended for persons under 16, and we ask that persons under 16 do not provide Personal data to the Controller.
If we become aware that we have collected personal data from a child under 16 — except for processing of data required by law — we will take the steps necessary to delete the data as soon as possible.

9. Automated decision-making

The Company does not apply automated decision-making in its processing procedures or data collection.

10. Method of storing personal data, security of processing

Our company’s IT systems and other data-storage locations are at the registered office and on servers provided by the processor. In providing the service, our company selects and operates the IT equipment used for processing personal data so that the processed data:

  1. are accessible to those authorised (availability);
  2. their authenticity and authentication are ensured (authenticity of processing);
  3. their unaltered state can be verified (data integrity);
  4. are protected against unauthorised access (confidentiality of data).

We pay particular attention to the security of the data, and we also take the technical and organisational measures and establish the procedural rules necessary to enforce the GDPR safeguards. We protect the data with appropriate measures in particular against unauthorised access, alteration, transmission, disclosure, erasure or destruction, as well as accidental destruction, damage, and becoming inaccessible due to a change in the technology applied.

The IT system and network of our company and our partners are protected against computer-assisted fraud, computer viruses, computer break-ins and denial-of-service attacks. The operator also provides for security with server-level and application-level protection procedures. Daily backup of the data is in place. To avoid personal data breaches, our company takes every possible measure; if such an incident occurs — according to our incident-management policy — we act without delay to minimise risks and remedy damage.

11. Rights of data subjects, remedies

The data subject may request information about the processing of their personal data, and may request rectification of their personal data and — except for mandatory processing — erasure or withdrawal, and may exercise their right to data portability and to object, in the manner indicated when the data were collected, or via the controller’s contact details above.

The data subject’s rights and remedies have been defined and communicated to data subjects on the basis of Act CXII of 2011 and EU Regulation 2016/679.

Right to information, also known as the data subject’s “right of access”: pursuant to Act CXII of 2011 and Article 15 of EU Regulation 2016/679, at the data subject’s request the Controller provides information about

  • the data processed by it and the categories of personal data,
  • the purpose of processing,
  • the legal basis of processing,
  • the duration of processing,
  • where applicable, the period for which the data will be stored, or if that is not possible, the criteria used to determine that period,
  • where applicable, if the data were not collected from the data subject, any available information as to their source,
  • where applicable, automated decision-making, including profiling, and meaningful information about the logic involved and the significance and envisaged consequences of such processing for the data subject,
  • the processor’s details if a processor is used,
  • the circumstances, effects and measures taken to remedy a personal data breach, and
  • in the event of transmission of the data subject’s personal data, the legal basis, purpose and recipient of the transmission.

The information is free of charge if the person requesting it has not yet submitted a request for information on the same set of data to the Controller in the current year. In other cases a fee may be charged. Any fee already paid must be refunded if the data were processed unlawfully, or if the request for information led to rectification.

The Controller draws data subjects’ attention to the fact that information must be refused pursuant to Act CXII of 2011

  1. if, on the basis of an act, an international treaty or a binding legal act of the European Union, the Controller receives personal data in such a way that the transferring controller indicates, at the time of transfer, a restriction of the data subject’s rights provided in the said act, or another restriction of processing;
  2. in the interest of the state’s external and internal security, including national defence, national security, the prevention or prosecution of criminal offences, the security of the execution of sentences, and also in the interest of a state or municipal economic or financial interest, a significant economic or financial interest of the European Union, and for the purpose of preventing and detecting disciplinary and ethical offences related to the practice of professions and breaches of labour-law and occupational-safety obligations — including in every case inspection and supervision — and also in the interest of protecting the rights of the data subject or of others.

The Controller must notify the National Authority for Data Protection and Freedom of Information of refused requests for information each year by 31 January of the year following the year concerned.

Right to rectification: the data subject is entitled to obtain from the Controller without undue delay the rectification of inaccurate personal data concerning them. Taking into account the purposes of processing, the data subject is entitled to have incomplete personal data completed, including by means of providing a supplementary statement. At the same time, if the personal data do not correspond to reality and the Controller has the accurate personal data, the Controller is obliged to rectify the personal data even without the data subject’s request.

Right to erasure, also known as the “right to be forgotten”: the data subject is entitled to obtain from the Controller the erasure of personal data concerning them without undue delay, and the Controller is obliged to erase personal data concerning the data subject without undue delay if mandatory processing does not preclude this.

In addition to the above case, the Controller is obliged to erase the data pursuant to Act CXII of 2011 and Regulation (EU) 2016/679 of the European Parliament and of the Council if

  • processing of the data is unlawful;
  • the data are incomplete or incorrect — and this state cannot be lawfully remedied — provided that erasure is not excluded by law;
  • the purpose of processing has ceased, or the statutory time limit for storing the data has expired;
  • it has been ordered by a court or the Authority;
  • the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
  • the data subject objects to processing and there is no overriding legitimate ground for the processing;
  • the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the Controller is subject;
  • the personal data have been collected in relation to the offer of information society services referred to in Article 8(1) of EU Regulation 2016/679, offered directly to a child.

If the Controller has made the personal data public and is obliged to erase them as above, taking account of available technology and the cost of implementation it shall take reasonable steps, including technical measures, to inform other controllers processing the data that the data subject has requested the erasure of any links to, or copy or replication of, those personal data.

The Controller draws data subjects’ attention to the limits of the right to erasure or to be forgotten arising from the EU regulation, which are as follows:

  1. exercising the right of freedom of expression and information;
  2. compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  3. public interest in the area of public health;
  4. archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) of EU Regulation 2016/679, in so far as the right to erasure is likely to render impossible or seriously impair that processing; or
  5. the establishment, exercise or defence of legal claims.

Right to restriction of processing, also known as blocking: the data subject is entitled to obtain from the Controller restriction of processing.
If, on the basis of the information available, it may be assumed that erasure would harm the data subject’s legitimate interests, the data must be blocked. Personal data blocked in this way may be processed only for as long as the processing purpose that excluded erasure of the personal data persists.

If the data subject contests the accuracy or correctness of the personal data, but the inaccuracy of the contested personal data cannot be clearly established, the data are blocked. In this case the restriction applies for a period enabling the Controller to verify the accuracy of the personal data.

Pursuant to the EU regulation, the data must be blocked if

  1. the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead;
  2. the Controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims; or
  3. the data subject has objected to processing; in this case the restriction applies pending the verification whether the legitimate grounds of the Controller override those of the data subject.

Where processing has been restricted (blocked), such personal data shall, with the exception of storage, only be processed with the data subject’s consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.

The Controller hereby specifically draws data subjects’ attention to the fact that the data subject’s right to rectification, erasure and blocking may be restricted by law in the interest of the state’s external and internal security, including national defence, national security, the prevention or prosecution of criminal offences, the security of the execution of sentences, and also in the interest of a state or municipal economic or financial interest, a significant economic or financial interest of the European Union, and for the purpose of preventing and detecting disciplinary and ethical offences related to the practice of professions and breaches of labour-law and occupational-safety obligations — including in every case inspection and supervision — and also in the interest of protecting the rights of the data subject or of others.
The Controller informs the data subject without undue delay, at the latest within 30 days of receipt of the request, of the matters specified in the request, and/or rectifies the data, and/or erases and/or restricts (blocks) the data, or takes other steps in accordance with the request, if there is no excluding reason.

The Controller notifies the data subject in writing of the rectification, erasure and restriction of processing, and also all those to whom the data were previously transmitted or disclosed for processing purposes. At the data subject’s request the Controller informs the data subject of these recipients. Notification may be omitted if, having regard to the purpose of processing, it does not harm the data subject’s legitimate interest, or if notification proves impossible or would involve a disproportionate effort. The Controller is also obliged to notify the data subject in writing if the data subject’s exercise of rights cannot be realised for some reason, and is obliged to state precisely the factual and legal reasons, as well as the remedies available to the data subject: the possibility of turning to the court and to the National Authority for Data Protection and Freedom of Information.

The “right to data portability”: the data subject is entitled

  1. to receive the personal data concerning them, which they have provided to the Controller, in a structured, commonly used and machine-readable format, and
  2. to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where:
  3. the processing is based on consent; and
  4. the processing is carried out by automated means.

In exercising their right to data portability, the data subject is entitled to have the personal data transmitted directly from one controller to another, where technically feasible.
Having regard to the processing carried out by the Controller, the conditions for exercising the right to data portability are not met (there is no automated processing), therefore the data subject cannot exercise this right.

Right to object: the data subject may object to processing of their personal data — including profiling — if

  • processing (transmission) of the personal data is necessary solely for the enforcement of the Controller’s or the recipient’s right or legitimate interest, except in the case of mandatory processing;
  • the personal data are used or transmitted for the purpose of direct marketing, public opinion polling or scientific research;
  • the exercise of the right to object is otherwise permitted by law.

The data subject may also object, pursuant to Article 21(3) of EU Regulation 2016/679, to processing of personal data for the purpose of direct marketing; in that case the personal data may no longer be processed for that purpose.

Where personal data are processed for scientific or historical research purposes or statistical purposes, the data subject, on grounds relating to their particular situation, is entitled to object to processing of personal data concerning them, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
The Controller — while simultaneously suspending processing — examines the objection within the shortest time but no later than 30 days from submission of the request, and informs the applicant of the result in writing. If the applicant’s objection is well founded, the Controller terminates processing — including further collection and transmission of data — and blocks the data, and notifies the objection and the measures taken on the basis thereof to all those to whom the personal data affected by the objection were previously transmitted, who are obliged to take measures to enforce the right to object.

If the data subject does not agree with the Controller’s decision, or the Controller misses the referred deadline, they are entitled — within 30 days of its communication — to turn to a court.
The data subject has the right to object in connection with automated decision-making.

Enforcement before a court: if their rights are infringed, the data subject may turn to a court. The court proceeds out of turn in the case. It is for the Controller to prove that the processing complies with the law.

In the event of an infringement of the right to informational self-determination, a report or complaint may be lodged with:

National Authority for Data Protection and Freedom of Information
Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
Phone: +36 (1) 391-1400, Fax: +36 (1) 391-1410
www: http://www.naih.hu
e-mail: ugyfelszolgalat@naih.hu