PRIVACY POLICY
Version: 1.0. Effective: January 1, 2025
Privacy Notice
1. Purpose, Scope, and Governing Laws of the Privacy Notice
The purpose of this Notice is to set forth the data processing practices of Back and Rosta Limited Liability Company (registered office: 1021 Budapest, Bognár utca 5/A, tax ID: 14243927-2-41, company registration number: 01-09-895296, represented by Miklós Rosta, managing director; hereinafter: the Company), as well as the Company’s data protection and processing policy, which the Company, as the data controller, acknowledges as binding upon itself.
In drafting the provisions of this Notice, the Company paid particular attention to Regulation (EU) 2016/679 of the European Parliament and of the Council (“General Data Protection Regulation” or “GDPR”), Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (“Infotv.”), Act V of 2013 on the Civil Code (“Civil Code”), and Act XLVIII of 2008 on the Fundamental Conditions and Certain Restrictions of Commercial Advertising Activities (“Commercial Advertising Act”).
The scope of this Privacy Notice covers data processing carried out in the course of the Company’s activities, and in particular, but not exclusively, data processing related to the website available at https://www.the-magic-wall.com/hu (hereinafter: “Website”).
This Privacy Policy also governs data processing carried out by the Company, provided that the Company generally acts as the data controller of personal data. However, there are cases in which the Company does not act as a data controller but rather as a sub-processor to another data controller; in such cases, the Company is considered a data processor (acting on behalf of another data controller in the processing of personal data) In such cases, the Company acts in accordance with the data controller’s instructions and processes the data only to the extent required by the data controller.
Unless otherwise specified, the scope of this Privacy Notice does not extend to services and data processing activities related to third-party services or content that may appear on the Website.
This Privacy Notice does not apply to the processing of personal data related to employment relationships.
2. Definitions
Data processing: any operation or set of operations performed on Personal Data, regardless of the method used, including, in particular, the collection, recording, organizing, classifying, storing, adapting, altering, using, retrieving, consulting, disclosing, transmitting, disseminating, or otherwise making available, publishing, aligning, or combining (including profiling), restricting, deleting, and destroying.
Data Controller: the legal entity defined in Section 3 that determines the purposes and means of data processing—either independently or jointly with others.
Data Processor: the service provider that processes Personal Data on behalf of the Data Controller.
Recipient: a natural or legal person, public authority, agency, or any other body to whom or which personal data is disclosed, regardless of whether it is a third party. Public authorities that have access to personal data in the context of a specific investigation in accordance with Union or Member State law are not considered recipients; the processing of such data by these public authorities must comply with the applicable data protection rules in accordance with the purposes of the data processing.
Data Subject: a natural person who, either on their own behalf or on behalf of their employer or client, expresses interest in the Data Controller’s services or events, and/or enters into a contract with the Data Controller, or contacts the Data Controller for any other reason, and in connection with these activities, the Data Controller processes the Data Subject’s Personal Data listed in Sections 8 and 9 below.
GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and Directive 95/46/EC of the European Parliament and of the Council of October 24, 1995) on the protection of individuals with regard to the processing of personal data and on the free movement of such data.
Third party: a natural or legal person, public authority, agency, or any other body other than the data subject, the data controller, the data processor, or those persons who, under the direct authority of the data controller or data processor, are authorized to process personal data.
Consent: an expression of the will of the data subject, which is in all cases voluntary, unambiguous, and based on adequate information. The purpose of consent is for the data subject to give their unambiguous consent to the processing of their personal data.
Personal data: any information relating to an identified or identifiable natural person (i.e., the Data Subject); An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
Privacy Notice: the Data Controller’s current privacy notice.
Natural person: a living human being (an individual) who may be the holder of personal rights—such as the right to the protection of personal data.
3. Identity, Contact Information, and Activities of the Data Controller
The Data Controller is the Company, namely:
-
Company name: Back és Rosta Limited Liability Company;
-
registered office: 1021 Budapest, Bognár utca 5/A;
-
tax ID number: 14243927-2-41;
-
company registration number: 01-09-895296;
-
represented by: Miklós Rosta, Managing Director;
-
Email: info@backandrosta.com
-
Phone number: +36703215779
The Data Controller processes the Personal Data of Data Subjects in connection with the operation of the Website in accordance with this notice.
The Data Controller is a business entity registered in Hungary.
This Privacy Notice applies to visitors to our Website, our customers, users of our products and services, and our guests, whose personal data we process, and who are or have been in a contractual relationship with the Company, as well as any other individuals with whom we may come into contact in the course of our business activities.
4. Principles and Methods of Data Processing, and Applicable Laws
4.1. The Data Controller acts in accordance with the requirements of good faith, fairness, and transparency, and cooperates with the Data Subjects during data processing. The Data Controller processes only the data specified by law or provided by the Data Subjects, for the purposes set forth below. The scope of the Personal Data processed is proportionate to the purpose of data processing and may not exceed it (“data minimization”).
4.2. In any case where the Data Controller intends to use Personal Data for a purpose other than the original purpose of data collection, it shall inform the Data Subject thereof and obtain the Data Subject’s prior, explicit consent, or provide the Data Subject with the opportunity to prohibit such use.
4.3. The Data Controller does not verify the Personal Data provided to it. The person providing the Personal Data is solely responsible for its accuracy.
4.4. The Data Controller shall not disclose the Personal Data it processes to any third party other than the Data Processors specified in this Notice or, in certain cases referred to in this Notice, to External Service Providers.
An exception to the provision set forth in this section is the use of data in statistically aggregated form, which may not contain any other data capable of identifying the Data Subject in any form; as such, it does not constitute either Data Processing or data transfer.
In certain cases—such as official requests from courts or law enforcement, legal proceedings, copyright or property infringements, or other legal violations, or where there is reasonable suspicion of such violations, harm to the Data Controller’s interests, or a threat to the provision of services, etc.—the Data Controller may make the Data Subject’s accessible Personal Data available to third parties.
4.5. The Data Controller shall notify the Data Subject, as well as all parties to whom the Personal Data was previously transferred for the purposes of Data Processing, of any rectification, restriction, or erasure of the Personal Data it processes. This notification may be omitted if, in light of the purpose of the data processing, it does not infringe upon the Data Subject’s legitimate interests.
4.6. The Data Controller shall process Personal Data in a manner that ensures the appropriate security of the Personal Data, including protection against unauthorized or unlawful processing, as well as against accidental loss, destruction, or damage, by applying appropriate technical or organizational measures (“integrity and confidentiality”).
4.7. The Data Controller is responsible for complying with the above principles (“accountability”) and for demonstrating such compliance.
4.8. Pursuant to Article 37 of the GDPR, the Data Controller has assessed whether it is necessary to appoint a data protection officer and has concluded that, in light of the criteria for the mandatory appointment of a data protection officer, it is not required to appoint one. The reason for this is that the Company’s main activities do not involve data processing operations that, due to their nature, scope, and/or purpose, would require large-scale, regular, and systematic monitoring of Data Subjects.
4.9. The Data Controller processes personal data in accordance with applicable laws. The laws governing data processing include, in particular:
-
Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (hereinafter: “Infotv.”);
-
Act XLVIII of 2008 on the Fundamental Conditions and Certain Restrictions of Commercial Advertising Activities (hereinafter: “Grtv.”);
-
GDPR.
5. Possible Legal Bases for Data Processing
5.1. Consent of the Data Subject:
Given the nature of the Data Controller’s activities, the legal basis for data processing is, in most cases, the Data Subjects’ voluntary, explicit consent based on adequate information (Article 6(1)(a) of the GDPR). Data Subjects voluntarily contact the Data Controller in person, electronically, or through the Website; they voluntarily register and voluntarily use the Data Controller’s services. The Data Subject may give consent to the processing of their personal data for one or more specific purposes by signing a form or electronically (e.g., via email, by clicking the registration or consent button, by clicking a hyperlink, or by participating in an online meeting (e.g., Teams, Zoom, etc.)).
The Data Subject has the right to withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of data processing based on consent prior to withdrawal.
5.2. Legitimate Interest:
Data processing is necessary for the legitimate interests pursued by the Data Controller or a third party, unless the interests or fundamental rights and freedoms of the Data Subject that require the protection of personal data override those interests, in particular where the Data Subject is a minor (Article 6(1)(f) of the GDPR).
Legitimate interest means that, in the course of providing our services and managing our business operations, our goal is to enable us to provide you with the best possible service or product and the best and safest user experience. We assure you that we will take into account and weigh any impact that data processing may have on you (whether positive or negative) and your rights before we begin processing your data based on our legitimate interests. We do not use your personal data in activities where the impact of data processing on you outweighs our legitimate interests (unless you have consented to the data processing or it is otherwise required or mandated by law). Before commencing data processing, the Data Controller conducts a balancing test in accordance with the GDPR to ensure that a legitimate interest exists. Please contact us at the email address provided in Section 3 above or by submitting the “Contact Form” available on the Website if you need further information.
5.3. Compliance with a Legal Obligation:
If the Data Controller is required to comply with a legal requirement applicable to it, such as tax or other regulatory obligations and requirements, then the legal basis for data processing is compliance with a legal obligation pursuant to Article 6(1)(c) of the GDPR.
5.4. Performance of a contract:
Data processing is necessary for the performance of a contract to which the Data Subject is a party, or the data processing is aimed at entering into a contract at the Data Subject’s prior request; that is, if you are in a contractual relationship with the Company or wish to enter into a contract with the Company, and the processing of your data is necessary for the performance of the contract. Please note that in this case, no separate consent is required on your part, and your data will be processed for the duration and to the extent necessary to fulfill the contract.
5.5. Data Transfer to Data Processors
Please note that the transfer of data to the data processors specified in this Notice may be carried out without the Data Subject’s separate consent. The disclosure of personal data to third parties or authorities—unless otherwise provided by law—is possible only on the basis of a final and binding official decision or with the Data Subject’s prior, explicit consent.
5.6. By providing their data, each Data Subject assumes responsibility for ensuring that only they use the service via the provided email address or using the data they have provided. In light of this assumption of responsibility, all liability related to logins made using a provided email address and/or data rests solely with the Data Subject who provided the data.
6. Possible Purposes of Data Processing
The Data Controller processes personal data exclusively for a specific purpose, for the exercise of rights and the fulfillment of obligations. At every stage of data processing, the processing is consistent with the purpose of data processing. The collection and processing of data are carried out fairly and lawfully. The Data Controller strives to process only such personal data as is essential to achieving the purpose of data processing and suitable for achieving that purpose. Personal data may be processed only to the extent and for the duration necessary to achieve the purpose.
The primary purpose of data processing is to operate the Website, to facilitate contact through the Website regarding the provision of the Data Controller’s business services, and to enable participation in the Data Controller’s events.
Based on the above, the purposes of data processing are:
-
Identifying the Data Subject and maintaining contact with the Data Subject or the organization represented by the Data Subject;
-
Recording the Data Subject’s registration for an event;
-
Establishing connections among the Data Controller’s clients, potential clients, and partners; identifying and facilitating cooperation with partners; and establishing such connections;
-
Sending direct sales and marketing communications (e.g., newsletters) to Data Subjects;
-
Organizing and conducting events for Data Subjects;
-
Compliance with legal obligations incumbent upon the Data Controller and the exercise of the Data Controller’s rights;
-
Preparing analyses and statistics, and improving services—for this purpose, the data controller uses only anonymized data and aggregated data that cannot be used to identify individuals
-
For marketing and sales purposes
7. Source of Data
The Data Controller processes only personal data provided by the Data Subjects and does not collect data from other sources.
Data is provided by the Data Subject. During initial contact, contract negotiations, or registration, the Data Subject provides their name, the organization on whose behalf they are acting, their country, email address, and phone number.
8. Scope of Processed Personal Data
The Data Controller processes only the personal data provided by the Data Subject. The data processed are as follows:
-
full name,
-
email address,
-
phone number,
-
organization represented, and
-
position.
In addition to the above, the Data Controller processes technical data, including the IP address, as described in Section 13.
9. Description of the Data Processing Procedure
The Data Controller processes personal data exclusively on the basis of information provided by the Data Subject. The source of the data is therefore the Data Subject, who provides the personal data by contacting the Data Controller.
10. Data Processing for Communication Purposes
In order to provide information regarding the Company’s services to prospective clients and existing customers, as well as to offer assistance or information, it is necessary to process contact information.
Legal basis for data processing: If a natural person expresses interest in our services or otherwise contacts us, the legal basis for data processing is the preparation of a contract, the performance of a concluded contract, the provision of information related to the contract, and the improvement of our services (Article 6(1)(b) of the GDPR). If the Data Subject contacts us as a representative or contact person of an organization, the legal basis for data processing is the legitimate interest of the Data Controller, which consists of the preparation of a contract with the organization represented by the Data Subject, the performance of the concluded contract, providing information related to the contract, and improving our services (Article 6(1)(f) of the GDPR).
Data retention period: 3 years from the last contact.
Using the contact form on the Website:
If you would like to contact our Company, you can do so using the forms found in the “Contact Us” menu (https://www.the-magic-wall.com/contact) on the Website. The contact form requires you to provide personal data (name, organization name, country, email address, phone number) for the purposes of establishing contact, responding to your inquiry, and scheduling a meeting.
By using the form, you may request general information about the services provided by the Company and make statements regarding the Company’s newsletters.
Purpose of data processing: to provide information about the Company’s services.
The legal basis for data processing—depending on the case—is the performance of a contract pursuant to Article 6(1)(b) of the GDPR for current or prospective individual customers, and Article 6(a) of the GDPR in all other cases.
Duration of data processing (retention period for personal data provided on the form):
-
in the case of a one-time exchange of information, the Company will delete the data immediately;
-
if the inquiry relates to the conclusion of a contract for a service provided by the Company or to the preparation thereof, the duration of data processing is 5 years from the termination of the contract. The data provided on the form will be deleted if the contract is not concluded or following the termination of the contract.
11. Data Processing for Marketing Purposes, Sending Newsletters
If the Data Subject expressly consents, the Data Controller will contact the Data Subject using the contact information provided and send them information regarding current updates and promotions related to the Company’s products and services. We primarily send marketing materials via email (newsletter) or by phone (including text messages).
The basis for data processing is always the Data Subject’s consent (Article 6(1)(a) of the GDPR). The Data Subject may withdraw their consent at any time, without providing a reason, by sending an email to the data controller’s email address provided in Section 3 above.
Duration of data processing: The Company will store the personal data provided by the Data Subject for the purpose of sending the newsletter only until the Data Subject withdraws their consent to data processing, in which case the Company will no longer contact the Data Subject with further newsletters or offers. The Data Subject may withdraw their consent at any time, free of charge. The personal data will be deleted without undue delay, no earlier than ten business days after the withdrawal of consent.
12. Data Processing Related to Events
The Data Controller regularly organizes events aimed at introducing the Data Controller’s services to prospective clients and customers and fostering professional relationships among them.
The legal basis for data processing is the Data Subject’s consent and the performance of a contract (Article 6(1)(a) and (b) of the GDPR), provided that the Data Subject is a natural person. If the Data Subject applies to attend the event or registers to participate in the event, provides their data, and consents to the processing of their data, as set forth in this Notice. If the Data Subject applies to our event as a representative or contact person of an organization, the legal basis for data processing is the Data Controller’s legitimate interest, which consists of preparing to enter into a contract with the organization represented by the Data Subject, fulfilling the terms of the concluded contract, providing information related to the contract, and improving our services (Article 6(1)(f) of the GDPR).
The purpose of data processing is to organize the event, improve our services, issue invoices (if applicable), and maintain contact.
Data retention period: 5 years from the date of last participation.
13. Processing of Technical Data and Cookies
The Data Controller’s system automatically records the IP address of the Data Subject’s computer, the start time of the visit, and, in some cases—depending on the computer’s settings—the type of browser and operating system. The data recorded in this manner cannot be linked to any other personal data. The processing of this data serves exclusively statistical purposes.
Cookies enable the Website to recognize previous visitors. Cookies help the Data Controller, as the operator of the Website, to optimize the Website and tailor its services to the Data Subjects’ habits. Cookies are also useful for
-
remember settings, so the Data Subject does not have to re-enter them when navigating to a new page,
-
remember previously entered data, so it does not need to be re-entered,
-
analyze the use of the Website so that, as a result of improvements made using the information obtained, it functions as closely as possible to the Data Subject’s expectations, allowing the Data Subject to easily find the information they are seeking.
If the Data Controller displays various types of content on the Website using external web services, this may result in the storage of certain cookies that are not controlled by the Data Controller; therefore, the Data Controller has no influence over what data these websites or external domains collect. Information about these cookies is provided in the policies applicable to the respective services.
The Data Controller uses cookies to display advertisements to Data Subjects via Google and Facebook. Data processing occurs without human intervention.
Data Subjects can configure their web browser to accept all cookies, reject all cookies, or notify them when a cookie is sent to their device. These settings are typically found in the browser’s “Options” or “Settings” menu. By disabling cookies, the Data Subject acknowledges that the Website will not function to its full extent without them.
The detailed information available on the English-language websites , www.aboutcookies.org, and also provides guidance on how to configure settings in various browsers.
14. Data Transfer
The Data Controller will transfer personal data to a third party for the purpose of data processing only if the Data Subject has unambiguously consented to such transfer—with knowledge of the scope of the data being transferred and the recipient of the transfer—or if the Data Controller is authorized by law to do so.
The Data Controller is entitled and obligated to transfer to the competent authorities any Personal Data at its disposal and lawfully stored by it, where the Data Controller is required by law or a final and binding official order to transfer such Personal Data. The Data Controller shall not be held liable for such data transfers or the consequences arising therefrom.
The Data Controller shall document all data transfers and maintain a record of such transfers.
15. Data Processing
The Data Controller is entitled to engage data processors to carry out its activities. Data processors do not make independent decisions; they are authorized to act solely in accordance with the contract concluded with the Data Controller and the instructions received. The Data Controller supervises the work of the data processors. Data processors may engage additional data processors only with the Data Controller’s consent.
The Data Controller identifies the data processors it engages in this Notice.
Data processors engaged by the Data Controller:
COMPANY NAME
REGISTERED OFFICE
SERVICE PROVIDED
Back and Rosta Information Technology (Shanghai) Ltd.
No. 111–113 Huashi Road, Xuhui District, 200235 Shanghai, China
Website operation
Shanghai Back & Rosta Cultural Development Co. Ltd.
NO.111-113, Huashi Road Xuhui District, 200235 Shanghai, China
Exhibition coordination
Magic Wall LLC
30 N Gould St #42881
Sheridan, WY 82801 USA
Sales and marketing
Back and Rosta GmbH
Schumanngasse 22/7.
Vienna 1180 Austria
Sales and marketing
16. Third-Party Service Providers
In the course of operating the Website, the Data Controller engages Third-Party Service Providers, with whom the Data Controller cooperates.
With regard to Personal Data processed in the systems of Third-Party Service Providers, the provisions set forth in the Third-Party Service Providers’ own privacy policies shall apply. The Data Controller will do everything in its power to ensure that the External Service Provider processes the Personal Data transferred to it in accordance with the law and uses such data exclusively for the purposes specified by the Data Subject or set forth below in this Notice.
The Data Controller shall inform Data Subjects about data transfers to Third-Party Service Providers within the framework of this Notice.
17. Data Security and Access to Data
The Data Controller ensures the security of the data, takes the technical and organizational measures, and establishes the procedural rules necessary to enforce applicable laws and data and confidentiality protection rules. The Data Controller protects the data with appropriate measures against unauthorized access, alteration, transmission, disclosure, deletion, or destruction, as well as against accidental destruction or damage, and against becoming inaccessible due to changes in the technology used.
The Data Controller maintains records of the data it processes in accordance with applicable laws, ensuring that the data is accessible only to those employees and other persons acting on behalf of the Data Controller (data processors) who need it to perform their job duties or tasks. The Data Controller’s employees shall perform individual searches or specific operations on the data only at the request of the Data Subject or when necessary for the provision of the service.
When defining and implementing measures to ensure data security, the Data Controller takes into account the current state of the art. The Data Controller selects, from among several possible data processing solutions, the one that ensures a higher level of protection for personal data, unless this would entail disproportionate difficulty.
As part of its IT security responsibilities, the Data Controller shall ensure, in particular:
-
Measures to protect against unauthorized access, including the protection of software and hardware devices, as well as physical security (access control, network security);
-
Measures to ensure the recoverability of data files, including regular backups and the separate, secure management of copies (mirroring, backup);
-
Protection of data files against viruses (virus protection);
-
The physical protection of data files and the devices on which they are stored, including protection against fire, water damage, lightning strikes, and other natural disasters, as well as the recoverability of data damaged as a result of such events (archiving, fire protection).
Employees and other persons acting on behalf of the Data Controller are required to securely store and protect data storage media containing personal data that they use or possess—regardless of the method of data recording—against unauthorized access, alteration, transmission, disclosure, deletion, or destruction, as well as against accidental destruction and damage.
The Data Controller operates the electronic registry using software that complies with data security requirements. The software ensures that data is accessed only for specific purposes, under controlled conditions, and only by those individuals who need it to perform their duties.
18. Duration of Data Processing
In addition to the specific provisions described above for each data processing operation, the Data Controller shall delete personal data if
a) the processing is unlawful;
If it becomes apparent that the data is being processed unlawfully, the Data Controller shall delete it without delay.
b) the Data Subject requests the erasure of their data (except for data processing based on law);
The Data Subject may request the erasure of data processed on the basis of the Data Subject’s voluntary consent. In this case, the Data Controller shall erase the data. Erasure may be refused only if the processing of the data is authorized by law. The Data Controller shall in all cases provide information regarding the refusal of the erasure request and the legal basis permitting the data processing.
c) the data is incomplete or incorrect—and this condition cannot be lawfully remedied—provided that the law does not preclude erasure;
d) the purpose of data processing has ceased to exist, or the statutory retention period for the data has expired;
Erasure may be refused (i) for the purpose of exercising the right to freedom of expression and the right to information, or (ii) if the processing of Personal Data is authorized by law; and (iii) for the purpose of asserting, exercising, or defending legal claims.
In all cases, the Data Controller shall notify the Data Subject of the refusal of a request for erasure, specifying the reason for the refusal. Once a request for the erasure of personal data has been fulfilled, the previous (erased) data cannot be restored.
Since the Data Controller provides ongoing services to the Data Subject, the relationship between the parties is not subject to a time limit. Based on the foregoing—in the absence of a request from the Data Subject—the Data Controller will process the data for as long as the relationship between the Data Controller and the Data Subject exists and for as long as the Data Controller is able to provide services to the Data Subject.
The Data Controller will delete all other data if it is clear that the data will not be used in the future, meaning that the purpose of data processing has ceased to exist.
e) it has been ordered by a court or the National Authority for Data Protection and Freedom of Information:
If a court or the National Authority for Data Protection and Freedom of Information issues a final and binding order to delete the data, the Data Controller shall carry out the deletion.
Instead of erasure, the Data Controller—after informing the Data Subject—shall block the personal data if the Data Subject so requests, or if, based on the information available to the Data Controller, it can be presumed that erasure would harm the Data Subject’s legitimate interests. Personal data blocked in this manner may be processed only for as long as the purpose of data processing that precluded the erasure of the personal data remains valid. The Data Controller shall mark the personal data it processes if the Data Subject disputes its correctness or accuracy, but the incorrectness or inaccuracy of the disputed personal data cannot be clearly established.
In the case of data processing required by law, the provisions of the applicable law shall govern the erasure of data.
In the event of erasure, the Data Controller shall render the data unfit for identification. If required by law, the Data Controller shall destroy the data medium containing the personal data.
19. Rights of Data Subjects and Their Enforcement
19.1. Upon initial contact, the Data Controller shall inform the Data Subject about the processing of their data by drawing their attention to this privacy notice and providing access to it on the Website. The Data Subject is also entitled at any time to request information regarding the processing of their data.
At the Data Subject’s request, the Data Controller shall provide information regarding the Data Subject’s data processed by the Data Controller or by a data processor commissioned by the Data Controller or in accordance with its instructions, including the source of such data, the purpose, legal basis, and duration of the data processing, as well as the name, address, and activities of the data processor related to the data processing, the circumstances and effects of a data breach and the measures taken to address it; and—in the event of a transfer of the Data Subject’s Personal Data—the legal basis for the transfer and the recipient of the data. The Data Controller is obligated to provide the information in writing, in an easily understandable form, at the Data Subject’s request, as soon as possible after the request is submitted, but no later than 25 days thereafter. This information is provided free of charge if the person requesting the information has not previously submitted a request for information regarding the same set of data in the current year. In other cases, a fee may be charged. Any fee already paid must be refunded if the data was processed unlawfully or if the request for information led to a correction.
19.2. The Data Subject may request that the Data Controller correct any inaccurate personal data. If the data to be corrected is used for regular data disclosures, the Data Controller shall, if necessary, notify the recipient of the data disclosure of the correction and shall inform the Data Subject that they must also request the correction from other data controllers.
19.3. Except for data processing required by law, the Data Subject may request the erasure of their personal data. The Data Controller shall inform the Data Subject of the erasure.
19.4. The Data Subject may object to the processing of their personal data as specified in the GDPR.
19.5. The Data Subject may submit a request for access, rectification, or erasure in writing, by mail addressed to the Data Controller’s registered office or business location, or by email sent to the email address provided in Section 3 above.
19.6. The Data Subject may request that the Data Controller restrict the processing of their Personal Data if the Data Subject disputes the accuracy of the Personal Data being processed. In this case, the restriction shall apply for a period that allows the Data Controller to verify the accuracy of the Personal Data. The Data Controller shall mark the Personal Data it processes if the Data Subject disputes its correctness or accuracy, but the incorrectness or inaccuracy of the disputed Personal Data cannot be clearly established.
The Data Subject may request that the Data Controller restrict the processing of their Personal Data even if the processing is unlawful, but the Data Subject objects to the erasure of the processed Personal Data and instead requests that its use be restricted.
The Data Subject may also request that the Data Controller restrict the processing of their Personal Data if the purpose of the processing has been fulfilled, but the Data Subject requires the Data Controller to continue processing such data for the purpose of asserting, exercising, or defending legal claims.
19.7. The Data Subject may request that the Data Controller provide the Data Subject with the Personal Data provided by the Data Subject and processed by the Data Controller by automated means in a structured, commonly used, machine-readable format and/or transfer such data to another data controller.
19.8. If the data controller does not comply with the Data Subject’s request for rectification, blocking, or erasure, it shall, within 25 days of receiving the request, provide in writing the reasons for rejecting the request for rectification, blocking, or erasure. In the event of a rejection of a request for rectification, erasure, or blocking, the data controller shall inform the Data Subject of the possibility of seeking judicial remedy and of filing a complaint with the National Authority for Data Protection and Freedom of Information.
19.9. The Data Subject may submit the above statements regarding the exercise of their rights using the contact information for the data controller provided in Section 2.
19.10. The Data Subject may also file a complaint directly with the National Authority for Data Protection and Freedom of Information (address: 1055 Budapest, Falk M. u. 9-11; phone: +3630 683-5969; email: ugyfelszolgalat@naih.hu; website: www.naih.hu). In the event of a violation of the Data Subject’s rights, the Data Subject is entitled to bring a lawsuit before a court pursuant to Section 22(1) of the Information Act. The court has jurisdiction over the case. The lawsuit may also be filed—at the Data Subject’s discretion—before the court having jurisdiction over the Data Subject’s place of residence or place of stay. Upon request, the Data Controller shall provide the Data Subject with detailed information regarding the possibilities and means of legal remedy.
20. Scope and Amendment of the Privacy Notice
20.1. This Privacy Notice enters into force on the date indicated in the header for an indefinite period. Previous versions may be obtained from the Data Controller by sending a message to the email address provided in Section 3 above.
20.2. The Data Controller reserves the right to amend this Notice at any time by its unilateral decision, which it will publish on the Website. Therefore, please visit the Website periodically to stay up to date.
* * *
*