Skip links

Data Protection Policy

The purpose of this Privacy Notice is to:

The controller acknowledges that it is bound by the contents of this legal notice. This Privacy Notice is intended to inform your customers, partners and clients about the processing of their personal data. The Data Controller shall process personal data only in accordance with the provisions of applicable law and in strict compliance with the provisions of the data management and data protection regulations, taking into account the principles of lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy and limited storage.

The data controller shall take all technical and organisational measures to ensure that the personal data of its partners are processed in a secure manner as required by Regulation (EU) 2016/679 of the European Parliament and of the Council.

The data controller has developed its day-to-day activities, rules, records, standard documents and information in accordance with the above.

The data protection policies relating to the data processing of the controller are permanently available on the controller’s headquarters and websites. The controller reserves the right to change this policy at any time. It will of course inform its audience of any changes in due time.

The data controller is committed to protecting the personal data of its customers and partners, and attaches the utmost importance to respecting the right to information self-determination of its customers. The data controller keeps personal data confidential and takes all reasonable security measures to ensure that personal data are treated confidentially,

technical and organisational measures to guarantee the security of the data. The controller describes its data management practices below.

The personal, material and temporal scope of the Privacy Notice:

The personal scope of this Privacy Notice extends to the controller and to the natural persons whose data are included in the processing covered by this Notice, as well as to persons whose rights or legitimate interests are affected by the processing.

The scope of this Policy covers all processing in the course of the controller’s activities, except for so-called internal processing (e.g. relating to employees), which is regulated in the Controller’s Privacy Policy.This Policy shall enter into force on the date of approval and shall remain in force indefinitely until further notice.

Important definitions:

Personal data: any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Special category of personal data: any data that fall within a special category of personal data, namely personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, health data and personal data concerning the sex life or sexual orientation of a natural person.

Data processing: any operation or set of operations which is performed upon personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure, transmission, dissemination or otherwise making available, alignment or combination, restriction or destruction.

Controller: a natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

Processor: a natural or legal person, public authority, agency or any other body which processes personal data on behalf of the controller.

Joint controllers: where the purposes and means of processing are jointly determined by two or more controllers, they are considered to be joint controllers.

Third party: a natural or legal person, public authority, agency or any other body other than the data subject, the controller, the processor or the persons who, under the direct authority of the controller or processor, are authorised to process personal data.

Consent of the data subject: a voluntary, specific, informed and unambiguous indication of the data subject’s wishes by which he or she signifies his or her agreement to the processing of personal data concerning him or her by means of a statement or an unambiguous act of affirmation.

Data breach: a breach of security that results in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

Lawful processing by the controller:

Personal data are processed by the controller only in the following cases:

1. where the data subject has given his or her consent to the processing of his or her personal data for one or more specific purposes,

2. the processing is necessary for the performance of a contract to which the data subject is a party,

3. the processing is necessary for compliance with a legal obligation to which the controller is subject,

4. the processing is necessary for the protection of the vital interests of the data subject or of another natural person,

5. the processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party.

The controller examines the lawfulness of data processing at all stages of its activities, and only processes data for which it can justify the purpose and legal basis. In the event that the conditions of a legal basis cease to apply, the processing may only be resumed if the controller can demonstrate an adequate alternative legal basis.

As a general rule, the way of proving the legal basis is in writing, but even in the case of a legal basis created by implied conduct, it must be examined whether it can be clearly proved ex post. In case of doubt, written confirmation of the imputability of the processing should be sought, having regard to considerations of reasonableness and economy.

In the case of consent-based processing, the data subject gives his or her written consent to the processing of his or her personal data. Consent is not formally required, but subsequent evidence requires written consent on paper or in electronic form.

Processing based on a legal basis to fulfil a legal obligation is independent of the data subject’s consent, as the processing is defined by law.

Irrespective of the mandatory nature of the processing, the private individual concerned must be informed before the processing starts that the processing is mandatory and cannot be avoided, and must be provided with clear and detailed information on all relevant facts concerning the processing of his or her data before the processing starts.

According to the GDPR (General Data Protection Regulation), personal data may also be processed if the processing is necessary for the performance of a contract to which the individual concerned is a party or if the processing is necessary for the purposes of taking steps at the request of the data subject prior to entering into a contract. The controller may process personal data for the purposes of the conclusion, performance or termination of the contract on the basis of the legal basis for performance of the contract.

Processing of personal data by the controller:

The data controller carries out passenger transport activities. It provides passengers and partners with airport transfer services and passenger transport for events (festivals, weddings, corporate events, stag and hen parties). Personal data are also processed in connection with these activities:

1. The contractual partners of the controller may be both individuals and legal persons. The conclusion of a contract is preceded by a request for a proposal, in the form of an e-mail, a telephone call or a message sent via the controller’s websites. The requesting party will provide his name, telephone number and e-mail address to which the controller will send his offer. If the offer is rejected, the personal data of the interested party will be deleted without delay and at the latest within 3 working days. In relation to children, the data controller will only ask the interested party for the number and age of the children, this information is necessary in order to ensure the child’s seating. The data controller will invoice its customers after the contractual service has been provided. The invoice will contain the name, address and possibly the tax number of the data subject. The issuing of the invoice is a statutory obligation of the controller. The legal basis for processing the personal data on the invoice is therefore the fulfilment of a legal obligation. The personal data on the invoice are stored by the controller for a period of 8 years, in compliance with the retention obligation laid down in Article 169 of the Accounting Act.

2. In the performance of its tasks, the Data Controller processes the e-mail addresses and telephone numbers of its partners and customers, in the performance of its contractual obligations or pursuant to their individual consent.

3. In the course of its work, the controller may also have contractual relations with subcontractors, suppliers and service providers, which also provide a basis for the processing of personal data. In such cases, the legal basis for the processing of personal data (in the case of a natural person or sole trader) is the performance of a contractual obligation, and in the case of personal data of a contact person of a legal person, the explicit, prior informed consent of the data subject.

4. Natural persons applying to the controller may submit a curriculum vitae to the company. The data subject also has the possibility to send his/her CV by filling in a form on the websites of the controller BFTG Hungary Kft. In the form, the data controller asks for the name and e-mail address of the data subject, as well as for the CV to be uploaded. Personal data are also processed in relation to the personal data provided on the website and the personal data contained in the CV. The legal basis for processing in both cases is the consent of the data subject.

5. The controller presents its activities and services primarily through its own websites and its mobile application available on Android and iOS. The websites and mobile applications provide visitors with information about the prices of the controller’s services, the content of the services, contact details and the possibility to contact the controller. The websites use cookies in their operation, which also collect personal data about visitors. The legal basis for the processing is the consent of the data subject.

6. Through the websites and the mobile application, users have the possibility to contact the controller by means of a contact form. In the form, the name, e-mail address and telephone number of the interested party must be provided. The purpose of processing personal data is to contact the site visitor and the person interested in the services of the controller. If, after the contact, the service is not ordered, the personal data of the interested party will be deleted immediately, but within 3 working days at the latest. The controller shall process the personal data for the purpose of concluding the contract. By filling in the form, the data subject declares that he/she has read and accepted the Data Controller’s Privacy Policy.

7. On the controller’s websites, it is also possible to contact the controller by filling in a form with a request for a quote for the controller’s services. The form must contain the name, e-mail address and telephone number of the interested party. The purpose of the processing of personal data is to contact the visitor of the site and the person interested in the services of the data controller, as well as to clarify the terms of future cooperation and to make an offer.

If the service is not ordered after the contact has been made, the personal data of the interested party will be deleted immediately, but within 3 working days at the latest. The data controller shall process the personal data for the purpose of concluding the contract. By filling in the form, the data subject declares that he/she has read and accepted the Data Controller’s Privacy Policy.

8. The data controller also offers the possibility to subscribe to a newsletter by providing your name and e-mail address. When subscribing to the newsletter, the data subject declares that he/she has read the Data Controller’s Privacy Policy and that he/she gives his/her consent to the processing of his/her personal data for marketing purposes. The data subject shall have the rights set out in the Data Protection Notice and shall be able to exercise those rights in the manner and at the places indicated therein. Accordingly, the legal basis for the processing of personal data in the course of sending the newsletter is the explicit and written informed consent of the subscriber.

9. The data controller also operates Facebook and Instagram pages for marketing purposes to present its activities and services. The data controller also promotes its activities and services on social networking sites. Occasionally, a prize draw may be organised on social networking sites. The personal data of the winner (name, address, telephone number, e-mail address) will be processed in this case. The legal basis for the processing is the consent of the data subject

10. The purpose of data processing in the course of complaint handling in relation to the activities of the data controller is to enable the communication of the complaint, to identify the data subject and his/her complaint, to record the data required to be recorded by law, to investigate the complaint and to maintain contact in connection with its resolution.

In case of a complaint, the processing of the complaint and thus of personal data is mandatory under Act CLV of 1997 on Consumer Protection. The legal basis for the processing of personal data is therefore the fulfilment of a legal obligation.

The Data Controller shall keep a record of the processing described above. The register shall also include the time limits for the deletion of personal data. The register is annexed to this Privacy Notice.

Processors connected to the controller:

Where the processing is carried out on behalf of the controller, the controller may only use processors that offer adequate guarantees of compliance with the requirements of the General Data Protection Regulation or implement appropriate technical and organisational measures to ensure the protection of the rights of data subjects.

The Data Controller hereby declares that in the course of its work, it will only deal with data processors that have adequate guarantees of compliance with the GDPR Regulation and that they implement appropriate technical and organisational measures to ensure the protection of the rights of data subjects. The relevant declarations of the data processors are available to you.

By reading and acknowledging this Privacy Notice, data subjects accept that the controller transfers their personal data to the processors and joint controllers listed below.

● The company hosting the websites of the data controller: https://www.websupport.hu/

Additional data processor in connection with the sending of the newsletter:

● Name: Oroszlány Tibor e.v.

● Registered office: 1089 Budapest, Orczy út 17-19. 4/24.

● Tax number: 56553783-1-42

Data processor due to the use of Google Analytics by the websites operated by the data controller (see GTC):

● Google Ireland Limited

● Gordon House, Barrow Street, Dublin 4, Ireland

● Use Facebook and Instagram pages and

https://bftgtravel.com

● is a data processing and joint data controller partner due to the use of a social plug-in embedded in the website:

● Facebook Ireland Ltd.

● 4 Grand Canal Square, Grand Canal Harbour, Dublin 2 Ireland ● The controller also transfers personal data of its customers to the National Revenue and Customs.

The contracted data processing and data management partners will process the personal data of partners only on the basis of instructions given by the data controller (except where required by law) and under an obligation of confidentiality.

Processing of data relating to contracts concluded by the controller:

Customer contracts:

The contractual partners of the controller may be both individuals and legal persons. The conclusion of a contract is preceded by a request for a proposal, in the form of an e-mail, a telephone call or a message sent via the controller’s websites. The applicant provides his/her name, telephone number and e-mail address to which the controller sends his/her offer. If the offer is rejected, the personal data of the interested party will be deleted without delay and at the latest within 3 working days. The legal basis for the processing of personal data is the establishment of a contract (Article 6(1)(b) of the General Data Protection Regulation). If the data subject orders the offered service, a contractual relationship is established between the parties. The legal basis for the processing is the performance of the contractual obligation (Article 6(1)(b) of the General Data Protection Regulation), and in the case of a contact person of a legal person, the consent of the data subject (Article 6(1)(a) of the General Data Protection Regulation). In relation to children, the controller only asks the number and age of the children from the enquirer, this information is necessary to ensure the seating of the child. The controller will invoice its customers after the contractual service has been provided. The invoice will contain the name, address and possibly the tax number of the data subject. The issuing of the invoice is a statutory obligation of the controller. The legal basis for the processing of personal data on the invoice is therefore the fulfilment of a legal obligation (Article 6(1)(c) of the General Data Protection Regulation). The personal data on the invoice are stored by the controller for 8 years in compliance with the retention obligation laid down in Article 169 of the Accounting Act.

Supplier contracts:

The data controller may also process the contact details of suppliers (name, e-mail address, telephone number) and may also contact service providers and subcontractors. In order to maintain contact with partners in these cases as well

personal data may be processed (personal data of the contact person or of the natural person, individual entrepreneur). The legal basis for the processing of personal data is the performance of a contractual obligation (Article 6(1)(b) of the General Data Protection Regulation) or the consent of the contact person (Article 6(1)(a) of the General Data Protection Regulation).

The data controller will fill in a consent form with the contact persons of the companies, informing them of their rights in relation to personal data and asking for their consent to process their data. In such cases, the legal basis for the processing of personal data shall be the explicit, written and informed consent of the data subject to the processing. If the contract with the partner has been terminated and the legal obligation to retain data and documents no longer applies, telephone numbers and e-mail addresses will be deleted. With regard to the retention of personal data contained in the contract and invoice, the data controller shall also act in compliance with the retention obligation laid down in Article 169 of the Accounting Act and shall store them for 8 years.

Processing invoices issued to customers and the personal data contained therein:

The data controller issues an invoice for the services provided. The invoice shall contain the name, address and, where applicable, the tax number of the data subject. The issuing of the invoice is a legal obligation of the controller. The legal basis for processing the personal data on the invoice is therefore the fulfilment of a legal obligation. Personal data recorded in this way are stored by the controller for a period of 8 years, in compliance with the retention obligation laid down in Article 169 of the Accounting Act.

Children’s data, processing of special categories of personal data:

The data controller intends to provide its services to persons over the age of 18.

The data subject declares that he or she has reached the age of 16 years by filling in the form for sending the login, subscribing to the newsletter and consenting to the operation of cookies on the websites of the controller. A person under 16 years of age may not fill in the form, subscribe to the newsletter or consent to the collection of data by the cookies used by the websites, given that the validity of his/her declaration of consent to the processing of data requires the consent of his/her legal representative. The data controller is not in a position to verify the age and entitlement of the person giving consent, and the data subject therefore guarantees that the data he or she has provided are accurate.

Special data brought to the attention of the controller or which have come to the attention of the controller shall not be recorded by the controller. If such data has been entered into any of the controller’s systems without the controller’s knowledge, the controller shall delete it from the system immediately upon its detection.

Procedure for the retention of e-mail addresses and telephone numbers:

In the course of its activities, the data controller also obtains the e-mail addresses and telephone numbers of its partners, clients and customers. The personal data thus entered into its system is processed primarily for the purpose of fulfilling its contractual obligations. If the contract with the partner has been terminated and the legal obligation to keep the data and documents no longer applies, the telephone numbers and e-mail addresses will be deleted. In some cases, the data controller will still have a legitimate interest in retaining the data, in which case it will ask for the explicit and written consent of the data subject to retain his or her personal data.

Processing of applications and CVs received by the data controller:

Natural persons applying to the controller may submit a CV to the company. If the resume is submitted because the controller is looking for an employee and has advertised the job, the resume may only be used in connection with that job.

If the applicant does not meet the conditions for the vacancy and another candidate is selected, the CV will be immediately destroyed. The controller may only retain the application on the basis of the explicit, unambiguous and voluntary consent of the data subject, provided that its retention is necessary for the purposes of the processing.

The data controller does not post “anonymous” job advertisements (job advertisements in which the employer does not disclose its name, so that at the time of sending the job application, applicants may not be aware of the employer to which they are applying for the job), as this is contrary to the requirement of prior information about the identity of the data controller. In any case, the controller shall inform the data subjects of the identity of the job advertiser when advertising a job.

If the applicant has voluntarily sent a CV to the controller without an advertisement, he/she declares whether he/she consents to the controller’s processing of his/her personal data. Submitting a CV does not imply that the data subject consents to the controller keeping his/her application file. It is also important to note that the controller may use the CV only in relation to vacancies indicated by the job applicant. As a general rule, CVs will be kept for 3 months, unless the data subject specifies a longer period in his/her consent.

The data controller will only check and obtain information from the applicant’s profile page on the social networking site when assessing the job application if it has informed the data subjects beforehand. Even in such cases, only public data are consulted and only information that is relevant to the job application or the job is taken into account in the selection process. Under no circumstances will the job applicant’s profile page be saved or stored and transmitted to third parties.

If the data subject is not selected for the job in question, the controller will inform him or her of this and of the reasons for the refusal.

The website of the controller:

https://fexi.hu

The data controller presents its activities and services primarily on its own websites. The websites provide visitors with information about the contact details of the controller, the

prices of services and the possibility to contact.

The websites of the data controller use cookies in their operation. The legal basis for the processing of personal data obtained from them is the consent of the visitor.

The websites operated by us use the following cookies:

● _fbp

● Duration: 3 months

● Type: marketing – Facebook

● fr

● Duration: 3 months

● Type: marketing – Facebook

● _ga

● Duration: 2 years

● Type: statistical – Google Analytics

● _gat

● Duration: 1 minute

● Type: statistical – Google Analytics

● _gid

● Duration: 1 day

● Type: statistical – Google Analytics

● XSRF-TOKEN

● Duration: 2 hours

● Type: absolutely necessary

● homanweblocal_session

● Duration: 2 hours

● Type: absolutely necessary

● __cfduid

● Duration: 1 month

● Type: absolutely necessary

Cookies (cookies):

What cookies do:

● collect information about visitors and their devices;

● remember visitors’ individual preferences, which are used;

● make websites easier to use;

● provide a quality user experience.

In order to provide a personalised service, a small piece of data, a cookie, is placed on the user’s computer and read back during a subsequent visit. When the browser returns a previously saved cookie, the cookie provider has the possibility to link the user’s

your current visit with previous visits, but only for your own content.

Session cookies are strictly necessary:

The purpose of these cookies is to allow visitors to browse the websites, use their features and services fully and smoothly. This type of cookie is valid until the end of the session (browsing) and is automatically deleted from the computer or other browsing device when the browser is closed.

The data subject’s choice about the cookie:

Web browser cookies:

In the browser settings, the data subject can accept or reject new cookies and delete existing cookies. You can also set your browser to notify you each time a new cookie is placed on your computer or other device. You can find more information about cookie management in the “help” function of your browser.

If the visitor chooses to disable some or all cookies, he or she will not be able to use all the features of the websites.

Third party cookies (analytics, statistics, marketing): Google Analytics:

The websites of the controller also use Google Analytics as a third party cookie. By using Google Analytics, a web analytics service for statistical purposes, the controller collects information about how visitors use the website. The data is used to improve the website and the user experience. These cookies will also remain on the visitor’s computer or other browsing device, their browser until they expire or until they are deleted by the visitor.

When websites or apps use Google Analytics in combination with other Google advertising products, such as Google Ads, they may also collect other advertising identifiers. Users can turn this service off or change their cookie settings in their Ad Settings.

Google Analytics collects users’ IP addresses in order to protect the security of the service and to allow website owners to get a picture of which country, state or city their visitors are coming from (also known as “IP geolocation”). Google Analytics offers the possibility to mask the collected IP addresses, but website owners can still see users’ IP addresses even if they do not use Google Analytics.

In the context of Google Analytics, the IP address transmitted by the visitor’s browser is not merged with other Google data. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website.

In addition, the visitor can prevent the collection of data (including his IP address) generated by cookies and relating to the use of the website by the visitor and the processing of this data by Google by downloading and installing the browser plug-in under the link below.

The current link is http://www.google.com/policies/privacy/ads/.

Google acts as a data processor for Google Analytics and thus as the data controller.

Under the provisions of the General Data Protection Regulation (GDPR), Google Analytics is a data processor because Google Analytics collects and processes data on behalf of its clients (such as the data controller), under the instructions of those clients. Google may only use the data in accordance with the terms of the contracts with Google Analytics customers and the settings provided by the customers in the interface of its products.

Google Analytics collects internal cookies, device/browser information, IP addresses and activity on the website/application. This data is collected so that it can be used to measure and statistically report on the actions taken by users on websites and/or applications that use Google Analytics. Customers can customize the cookies and the scope of data collected through features such as Cookie Settings, User ID, Import Data and Measurement Protocol.

For customers using the SDK for Google Analytics applications, Google collects an application instance identifier. This is a number generated randomly by the system when a user installs an application for the first time.

Google Analytics uses IP addresses to determine the geographical location of visitors and to protect the service and its customers. Clients can enable a feature called IP masking, which allows Google Analytics to use only a subset of the IP address instead of the entire IP address collected. In addition, customers can also override IP addresses on demand using the IP override feature.

Google uses the data processed in Google Analytics to provide the Google Analytics measurement service to its customers. It uses identifiers, such as cookies and application instance identifiers, to measure what actions users take on customers’ websites and/or applications. It uses IP addresses to keep the service secure and to give website owners an overview of where their users come from around the world.

Social plug-in application:

The controller’s websites also use embedded content from the social networking site. In this case, the data is processed jointly with the operator of the social networking site. The legal basis for the processing is the consent of the data subject, which is given by accepting the information on the collection of data on cookies, by consenting to the collection of data.

Facebook pixel (Facebook cookie):

A Facebook pixel is a code that allows the website to report conversions, create audiences and provide the site owner with detailed analytics on how visitors use the site. The Facebook pixel is used on the Facebook interface to provide website visitors with personalised offers, ads

may appear. The websites of the data controller use the Facebook pixel. The legal basis for the processing is the consent of the data subject, which is given by accepting the information on the collection of data on cookies, by consenting to the collection of data.

The data subject declares on the websites of the data controller that he or she has reached the age of 16 years in relation to the acceptance of the use of cookies. A person under the age of 16 may not make a declaration of acceptance or refusal of cookies used by the websites, given that, pursuant to Article 8(1) of the General Data Protection Regulation (GDPR), the validity of his/her declaration of consent to processing requires the consent of his/her legal representative. The controller is not in a position to verify the age and entitlement of the person giving consent, so the data subject warrants that the data he or she has provided are accurate.

Processing of personal data when using the contact form:

Visitors to the websites have the possibility to contact the data controller via a contact form. The form should include the name, e-mail address and telephone number of the interested party. The purpose of processing personal data is to contact the site visitor and the person interested in the services of the controller. If, after the contact, the service is not ordered, the personal data of the interested party will be deleted immediately, but within 3 working days at the latest. The controller shall process the personal data for the purpose of concluding the contract on this legal basis. By filling in the form, the data subject declares that he/she has read and accepted the Data Controller’s Privacy Policy.

Processing of personal data when using the application form:

On the controller’s websites, it is also possible to contact the controller by filling in a form with a request for a quote for the controller’s services. The form must contain the name, e-mail address and telephone number of the interested party. The purpose of the processing of personal data is to contact the visitor of the site and the person interested in the services of the data controller, as well as to clarify the terms of future cooperation and to make an offer. In case the service is not ordered after the contact, the personal data of the interested party will be deleted immediately, but within 3 working days at the latest. The data controller processes the personal data for the purpose of the conclusion of the contract on this legal basis. By filling in the form, the data subject declares that he/she has read and accepted the Data Controller’s Privacy Policy.

Booking on the website:

The contractual partners of the controller may be both individuals and legal persons. The conclusion of a contract is preceded by a request for a proposal, in the form of an e-mail, a telephone call or a message through the controller’s websites. The applicant provides his/her name, telephone number and e-mail address to which the controller sends his/her offer. If the offer is rejected, the personal data of the interested party will be deleted without delay and at the latest within 3 working days. The legal basis for the processing of personal data is the creation of a contract. If the data subject orders the offered service, a contractual relationship is established between the parties. The legal basis for the processing is the fulfilment of the contractual obligation, in the case of a contact person of a legal person, the consent of the data subject. In relation to children, the data controller only asks for the number and age of the children of the enquirer, this information is necessary to ensure the child’s seating. The data controller issues invoices to its customers after the contractual service has been provided. The invoice will contain the name, address and possibly the tax number of the data subject. The issuing of the invoice is a statutory obligation of the controller. The legal basis for processing the personal data on the invoice is therefore the fulfilment of a legal obligation. The personal data on the invoice are stored by the controller for a period of 8 years, in compliance with the retention obligation laid down in Article 169 of the Accounting Act.

Processing of personal data when using the form to send a CV:

Natural persons applying to the controller may submit a CV to the company. The data subject also has the possibility to send his/her CV via a form on the controller’s website. In the form, the data controller asks for the name and e-mail address of the data subject and for the CV to be uploaded. Personal data provided on the website will be processed in relation to the personal data provided. The legal basis for the processing is the consent of the data subject.

The data subject declares on the website of the controller that he or she is at least 16 years of age when using the form for sending a CV. A person under the age of 16 may not fill in the form, given that, pursuant to Article 8(1) of the General Data Protection Regulation (GDPR), the validity of his/her consent to the processing of personal data requires the consent of his/her legal representative. The controller is not in a position to verify the age and entitlement of the person giving consent, so the data subject warrants that the data he or she has provided are accurate.

Subscribe to the newsletter:

The data controller also offers the possibility to subscribe to a newsletter. By subscribing to the newsletter, the data subject declares that he or she has read the Data Controller’s Privacy Policy and that he or she gives his or her consent to the processing of his or her personal data for marketing purposes (sending the newsletter). The data subject shall have the rights set out in the Data Protection Notice and shall be able to exercise those rights in the manner and at the places indicated therein. Accordingly, the legal basis for the processing of personal data in the context of sending the newsletter is the explicit and written consent of the subscriber.

The purpose of data processing in connection with the sending of newsletters is to provide the recipient with complete general or personalised information about the latest news and news items published by the controller, in accordance with the applicable and valid legislation. Subscription to the newsletter and/or DM mailing is based on voluntary consent, the controller will of course give the data subject the opportunity to withdraw his or her consent and unsubscribe from the newsletter at any time.

The data subject declares on the controller’s website that he or she is 16 years of age or older when subscribing to the newsletter. A person under the age of 16 may not subscribe to the newsletter, given that, under the General Data Protection Regulation, the validity of his/her declaration of consent to the processing of personal data requires the consent of his/her legal representative. The data controller is not in a position to verify the age and entitlement of the person giving his/her consent, so the data subject guarantees that the data he/she has provided are accurate.

The social networking sites of the controller:

The data controller also operates a Facebook page, where personal data are also processed. The controller also promotes its activities and services on Facebook. This page is used by the controller for marketing purposes.

The controller also provides comprehensive personal support through Facebook. If you ask a question via Facebook, we will try to answer it as soon as possible. You will use the data you receive on Facebook only to answer your question and not for any other promotional purposes.

The purpose of using the Facebook page is to advertise and provide information on social media. Facebook may also use the data for its own purposes, including profiling and targeting the data subject with advertising.

In order to contact the controller via Facebook, you must be logged in. To do this, Facebook may also request, store and process personal data. The controller has no control over the type, scope and processing of this data and does not receive personal data from the Facebook operator. For more information on this, please visit the Facebook page.

The controller also occasionally organises a prize draw on its social networking sites. In such cases, the winner’s personal data will be processed for the purpose of forwarding the prize. The data controller will process the winner’s data on the basis of the data subject’s consent and will keep it for the legal retention period.

The personal data of Facebook page followers is processed by the data controller on the basis of their consent, which is deemed to be given by the fact that the person likes, follows or comments on the page and its posts.

The data controller is also present on the Instagram social networking site with the following profile:

Personal data of followers is processed on the Instagram page. The data is processed on the basis of the consent given by the follower.

Handling of complaints about the controller’s activities:

The purpose of data processing in the course of complaint handling in relation to the activities of the data controller is to enable the communication of the complaint, to identify the data subject and his/her complaint, to record the data required by law to be recorded, to investigate the complaint and to maintain contact in connection with its resolution.

In case of a complaint, the processing of the complaint and thus of personal data is mandatory under Act CLV of 1997 on Consumer Protection. The legal basis for the processing of personal data is therefore the fulfilment of a legal obligation.

The data controller will keep the record of the complaint and a copy of the response for 5 years, and will also process the personal data on that basis for that period.

Security of data processing:

The data controller undertakes to ensure the security of the data, to take technical and organisational measures and to maintain procedural rules to ensure that the data recorded, stored or processed are protected and to prevent their destruction, unauthorised use or unauthorised alteration. It also undertakes to require any third party to whom it transfers or discloses the data to comply with the requirements of data security.

The controller shall ensure that the data processed cannot be accessed, disclosed, transmitted, modified or deleted by unauthorised persons. The data processed may only be accessed by the data controller and its data processor(s) and shall not be disclosed to third parties not entitled to access the data.

The data controller takes great care to ensure the security of the personal data of its partners, clients and customers. It acts in full compliance with the legal provisions and requires all its partners to do the same. The protection of personal data includes physical protection (storage of documents in a lockable room protected by an alarm) and IT protection.

The controller shall store the personal data provided by the data subject primarily on the servers of the data processor(s) specified in this Privacy Notice, equipped with the usual protection systems, and partly on its own IT equipment, or, in the case of paper media, at its headquarters, in an appropriately locked manner.

The data subjects acknowledge and accept that, if they provide their personal data, the data protection cannot be fully guaranteed on the Internet and in the computer system. In the event of unauthorised access or disclosure, despite the efforts of the controller, it is necessary to proceed as described in this notice.

Rights of data subjects:

● Transparent information:

The purpose of this Privacy Notice is also to provide clear, concise, transparent and understandable information about the processing activities of the controller.

● Right of access:

The data subject shall have the right to obtain from the controller feedback as to whether or not his or her personal data are being processed and, if such processing is taking place, the right to access the personal data and the following information:

● the purpose of the processing,

● the categories of personal data concerned,

● the recipients to whom the personal data have been disclosed,

● the intended duration of the storage of personal data.

You can request information about the above data from the data controller at the following address, e-mail address:

BFTG Hungary Kft. 2481 Velence, Balatoni út 2210/2

E-mail: info@bftghungary.hu

The controller hereby informs you that it will respond to your request within 30 days. Information requests sent by post will be answered by post, requests sent by e-mail will be answered by e-mail.

● Right to rectification:

The data subject shall have the right to obtain from the controller, at his or her request, the rectification of inaccurate personal data relating to him or her.

You can request information about the above data from the data controller at the following address, e-mail address:

BFTG Hungary Kft. 2481 Velence, Balatoni út 2210/2

E-mail: info@bftghungary.hu

The controller hereby informs you that it will respond to your request within 30 days. Information requests sent by post will be answered by post, requests sent by e-mail will be answered by e-mail.

● Right to erasure:

The data subject shall have the right to obtain, at his or her request, the erasure of personal data relating to him or her. The controller shall, on the basis of such a request, erase the personal data if one of the following grounds applies:

● the personal data are no longer necessary for the purposes for which they were collected,

● the data subject withdraws his or her previously given consent and there is no other legal basis for the processing,

● the data subject objects to the processing and there are no overriding legitimate grounds for the processing,

● the personal data have been unlawfully processed,

● necessary to comply with a legal obligation under EU or national law.

You can request information about the above data from the data controller at the following address, e-mail address:

BFTG Hungary Kft. 2481 Velence, Balatoni út 2210/2

E-mail: info@bftghungary.hu

The controller hereby informs you that it will respond to your request within 30 days. Information requests sent by post will be answered by post, requests sent by e-mail will be answered by e-mail.

● Right to restriction of processing:

The data subject has the right to request the controller to restrict processing, in particular if:

● disputes the accuracy of the data,

● you consider the processing to be unlawful, but for some reason you do not request the deletion of the data.

You can request information about the above data from the data controller at the following address, e-mail address:

BFTG Hungary Kft. 2481 Velence, Balatoni út 2210/2

E-mail: info@bftghungary.hu

The controller hereby informs you that it will respond to your request within 30 days. Information requests sent by post will be answered by post, requests sent by e-mail will be answered by e-mail.

● Right to data portability:

The data subject has the right to receive personal data concerning him or her in a structured, commonly used, machine-readable format and the right to transmit such data to another controller.

You can request information about the above data from the data controller at the following address, e-mail address:

BFTG Hungary Kft. 2481 Velence, Balatoni út 2210/2

E-mail: info@bftghungary.hu

The controller hereby informs you that it will respond to your request within 30 days. Information requests sent by post will be answered by post, requests sent by e-mail will be answered by e-mail.

● Right to object:

The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to the processing of his or her personal data, as provided for in Article 21 of Regulation (EU) 2016/679 of the European Parliament and of the Council.

You can request information about the above data from the data controller at the following address, e-mail address:

BFTG Hungary Kft. 2481 Velence, Balatoni út 2210/2

E-mail: info@bftghungary.hu

The controller hereby informs you that it will respond to your request within 30 days. Information requests sent by post will be answered by post, requests sent by e-mail will be answered by e-mail.

● The right of the data subject in case of automated decision-making:

The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or significantly affects him or her. Automated decision-making is any process or methodology whereby a technical automatism evaluates personal aspects relating to the data subject and which produces legal effects concerning him or her or significantly affects him or her. The controller shall not use IT automated mechanisms, including profiling, which have a significant impact on the rights of the data subject.

You can request information about the above data from the data controller at the following address, e-mail address:

BFTG Hungary Kft. 2481 Velence, Balatoni út 2210/2

E-mail: info@bftghungary.hu

The controller hereby informs you that it will respond to your request within 30 days. Information requests sent by post will be answered by post, requests sent by e-mail will be answered by e-mail.

The controller undertakes to inform all recipients to whom it has disclosed personal data of requests sent to it in connection with the above rights, unless this has proved impossible. It further undertakes to notify the data subject (applicant) of the decision on the processing of the above requests within 30 days at the latest.

Data protection incident:

A personal data breach is a breach of security that results in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

In the event of a data breach, the level of data breach must be at a serious risk level, i.e. the breach must be of a degree that personal data:

● destruction of,

● with the loss of,

● by changing,

● by unauthorised disclosure or

● involves unauthorised access to.

An incident is considered to occur if any one of the above occurs, but this does not exclude that more than one of the above may occur at the same time. This includes not only intentional malicious conduct but also negligent injuries. An incident therefore occurs when it is caused by an accidental or unlawful act.

Examples of data breaches include:

● the unlawful transmission of personal data on a document, portable device, storage medium or computer system (e.g. by mail),

● unauthorised access to an IT system or application that processes personal data,

● damage to or loss of part or all of a database containing personal data,

● part or all of the IT system

rendered unusable by a virus or other malware, etc.

A personal data breach may cause physical, material or non-material damage to natural persons, including loss of control over their personal data or restriction of their rights, discrimination, identity theft, if not addressed in an appropriate and timely manner, or misuse of identity, financial loss, unauthorised impersonation, damage to reputation, damage to the confidentiality of personal data protected by professional secrecy, or other significant economic or social disadvantages suffered by the natural persons concerned.

In the event of a potential data breach (unless the data breach is unlikely to pose a risk to the rights and freedoms of natural persons), the controller shall immediately notify the National Authority for Data Protection and Freedom of Information. As soon as the controller becomes aware of the incident, it shall notify it without undue delay and, if possible, no later than 72 hours after becoming aware of the personal data breach.

If the notification cannot be made within 72 hours, the notification must state the reason for the delay and provide the required information in detail without further undue delay.

The National Authority for Data Protection and Freedom of Information operates a dedicated system on its website for the notification of data breaches, through which notifications can be made electronically.

The data controller shall keep a record of the data breaches, indicating the facts relating to the data breach, its effects and the measures taken to remedy it. The controller shall keep records of the data relating to the incidents, including the causes, the events and the personal data involved. In addition, the record should also include the effects and consequences of the incidents and the measures taken to remedy them, and the conclusions of the controller (for example, why it thinks the incident is not reportable, or if the notification is delayed, the reason for the delay).

An incident that is unlikely to pose a risk to the rights and freedoms of natural persons does not need to be notified to the supervisory authority.

If the data breach is likely to result in a high risk to the rights and freedoms of the data controller’s partners or customers, we will inform the partner concerned without delay. The information provided to the data subject shall clearly and plainly describe the nature of the personal data breach and shall include the most relevant information and measures.

The data subject need not be informed as described above if any of the following conditions are met:

● the controller has implemented appropriate technical and organisational protection measures and these measures have been applied to the data affected by the personal data breach, in particular measures to render the data unintelligible to persons who are not authorised to access the personal data;

● the controller has taken additional measures following the personal data breach to ensure that the high risk to the rights and freedoms of the data subject is no longer likely to materialise;

● information would require a disproportionate effort. In such cases, the data subjects should be informed by means of publicly disclosed information or a similar measure should be taken to ensure that the data subjects are informed in an equally effective manner.

Information on the relevant legislation:

● Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Regulation (EC) No 95/46/EC (General Data Protection Regulation, GDPR);

● Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (Info. tv.);

● Act V of 2013 on the Civil Code (Civil Code); ● Act C of 2000 on Accounting (Accounting Act);

Right to apply to the courts:

The data subject may take the controller to court if his or her rights are infringed. The court shall rule on the case out of turn.

Data protection authority procedure:

You can lodge a complaint with the National Authority for Data Protection and Freedom of Information:

Name: National Authority for Data Protection and Freedom of Information Headquarters: 1055 Budapest, Falk Miksa u. 9-11.

Address for correspondence: 1363 Budapest, Pf. 9.

Phone: 0613911400

Fax: 0613911410

E-mail: ugyfelszolgalat@naih.hu

Website: http://www.naih.hu

Other provisions:

The data controller shall provide information on data processing not listed in this notice at the time of recording the data. In such cases, the provisions of the applicable legislation shall prevail.

The Data Controller hereby informs its customers that the court, the prosecutor, the investigating authority, the administrative authority, the National Authority for Data Protection and Freedom of Information, the National Bank of Hungary, or other bodies authorized by law may contact the Data Controller to provide information, to disclose or transfer data, or to provide documents. The data controller shall disclose to the authorities – if the authority has indicated the precise purpose and scope of the data – personal data only to the extent and to the extent strictly necessary for the purpose of the request.

The website of the Data Protection Authority contains further information on the data protection rights referred to in this Privacy Notice.

Venice, 25 April 2024.

HONNANHOVAÁR
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál
VéNégy FesztiválVéNégy FesztiválVéNégy Fesztivál