» Privacy

Privacy

Privacy policy

– processing of personal data within the scope of the operation of kozepdunakor.pipkft.hu subpage of the Company’s website

 

PIP Central Danube Regional Development Nonprofit Limited Liability Company (hereinafter: Company) within the framework of the “Paks Open Gates” tender ID number 2.2.16/7-2019-00001 created a subpage on its website aiming to provide third-country nationals with detailed information about the sights and programs of Paks, Szekszárd, Kalocsa and their surrounding settlements and to offer them assistance in administrative matters.

The purpose of this Privacy Policy (hereinafter: Policy) is to lay down the principles of personal data protection and management of natural persons thus the data subjects can properly be informed of the data processed by the Company the purpose, legal basis, duration of data processing, also the name, address, and activities of the data processor involved in data processing, furthermore – in case of the transfer of the data subject’s personal data– about the legal basis and the recipient of the data transfer.

Provisions and abbreviations that have been taken into account during the preparation of the Policy:

Infotv.   Act CXII.  of 2011 on Informational Self-Determination and Freedom of Information (“Privacy Act”)

GDPR   Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)

Definitions

The definitions of the Policy comply with the definitions of Article 4. of GDPR:

personal data: means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

processing:     means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

controller:       means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;

processor:       means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller;

data breach:   means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed;

consent of the  

data subject:  means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;

recipient:        means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not.

third party:     means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorized to process personal data.

If the definitions of the GDPR differ from the definitions of the Policy the definitions of GDPR shall prevail.

I. Data processor, data controller

  Data processor Data controller
name: PIP Central Danubian Regional Development Nonprofit Limited Liability Company Personal data will not be transferred to any data controller.
address: 7030 Paks, Ipari Park 4703/39.

7031 Paks, Pf.: 80.

email: piptitkarsag@pipkft.hu
phone number: +36 20 437 15 20
registration number: 17-09-003039
representative: dr. Tari István managing director
contact information: adatvedelem@pipkft.hu

II. Data subjects, purpose, legal basis, method, duration of data storage, recipients of data processing

Data subject:                          natural persons posing questions to the Data Controller on the kozepdunakor.pipkft.hu subpage

Processed personal data:        name, email address, and additional data voluntarily provided by the data subject

Purpose of data processing:   providing a response for the data subject’s question

Legal basis for processing:                the consent of the data subject

Declaration on (1) f) to

Article 13. of GDPR:             personal data are not transferred to a third country or international organizations

Recipients of the personal data: the personal data of the data subject will not be transferred

Method of data processing:    electronically

Duration of data processing: until the purpose of the data processing is achieved, ceased or the consent of the data subject is withdrawn

Declaration on (2) e) to

Article 13 of GDPR: the provision of personal data is not based on statutory or contractual obligations, not a precondition of entering into a contract, the data subject is not obliged to provide personal data

Declaration on (2) f) to Article 13 of GDPR:              automated decision-making, profiling is not carried out

III. Principles of data processing

  1. The Company shall process personal data in accordance with the principles of good faith, fairness, transparency as well as the provisions of this Policy and the applicable law.
  2. The Company shall process personal data in accordance with the principles of good faith, fairness, transparency as well as the provisions of this Policy and the applicable law.
  3. In case the Company intends to use personal data for a purpose other than the purpose for which the original data have been collected, the Company shall inform that data subject about the intention – if the processing has no other legal basis defined by the provisions of the GDPR – and shall preliminarily obtain the consent of the data subject to ensure the right to object to processing.
  4. The Company does not verify the accuracy of the personal data and its compliance is solely the responsibility of the person who provided it.
  5. The Company shall only transfer the personal data it processes to a third party if the data subject gave– in the knowledge of the scope of the transferred data and the recipient of the data transfer – his or her explicit consent. The Company has the right and obligation to forward any personal data available, to the competent authorities if the Company is obliged to transfer and exchange personal data by the law or a binding decision of authorities. The Company is not responsible for any consequences resulting from such data transfer.
  6. The Company shall ensure personal data security, take technical and organizational measures, and establish procedural rules to ensure the data collected, stored, or processed and prevent accidental loss, destruction, unauthorized access, unauthorized use, unauthorized alteration, and unauthorized dissemination.

The Company records the data it handles according to the applicable law, ensuring that the data can only be known to employees and other persons acting in the Company’s interest who need the data to perform their duties or carry out their tasks. All persons acting in the Company’s interest are entitled to know only the data necessary to manage the named person’s job.

IV. Rights of the data subject

  1. The data subject may exercise his or her rights in the following ways
    • email
    • post
    • in person
  1. The Company draws attention to the fact that – in the course of processing based on consent – the data subject is entitled to withdraw the consent at any time; however, this does not affect the lawfulness of the processing carried out based on consent prior to the withdrawal.
  2. The Company draws attention to the fact that at the request of the proprietor exercising the ownership rights, the managing director of the Company pursuant to Section 3:23 of Act V of 2013 on the Civil Code is obliged to provide the proprietor with the opportunity to access documents and records generated by the Company. Access to the processed personal data by the proprietor for the reason mentioned in this section does not constitute a violation of the rules on data processing.
  3. Detailed information about the rights of the data subject can be found in the Company’s General Privacy Policy on the following link: https://pipkft.hu/kozzeteendo-adatok/

 V. Notification of personal data breach

  1. In the case of a personal data breach, the Company shall without undue delay after having become aware of it, notify the personal data breach to the Hungarian National Authority for Data Protection and Freedom of Information unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. The Controller shall document any personal data breaches and the remedial action taken. When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Controller shall communicate the personal data breach to the data subject. When the personal data breach is serious (likely to result in a high risk to the rights and freedoms of natural persons), the controller shall communicate the personal data breach to the data subject without undue delay.
  2. Amendment of the Policy
  3. The Company reserves the right to amend this Policy at any time by unilateral decision by informing the data subject through its provided contact details.
  4. If the data subject does not agree with the amendment, he or she may request the erasure of his or her personal data pursuant to article V.

VII. Enforcement and remedies

  1. In case any questions or comments related to data processing may arise, the Company (as the data controller) may be contacted. Contact details are to be found on section I.
  2. The data subject shall have the right to lodge a complaint with the competent data protection supervisory authority in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her is in infringement.
    In Hungary a complaint can be lodged, at the Hungarian National Authority for Data Protection and Freedom of Information. („NAIH”, address: 1055 Budapest, Falk Miksa utca 9-11., postal address: 1363 Budapest, Pf.: 9.; phone: +36-1-391-1400; email: ugyfelszolgalat@naih.hu; website: www.naih.hu).
  3. The data subject shall have the right to an effective judicial remedy in case of:
    • an infringement
    • when seeking an effective judicial remedy against a legally binding decision of a supervisory authority concerning them.
    • where the supervisory authority does not handle a complaint or does not inform the data subject within three months on the progresses or outcome of the complaint lodged.

The Regional Courts (https://birosag.hu/torvenyszekek) have jurisdiction in data protection cases. The case may – by the choice of the data subject – be heard before the court of his or her place of residence.