Principles relating to the processing of personal data
Our Company processes personal data lawfully, fairly and transparently in relation to the Data Subject, for specified purposes only and in accordance with the principle of data minimisation. We process only personal data that is necessary and adequate for the purpose of the processing.
Personal data is processed only to the extent and for the time necessary to achieve the relevant purpose and in accordance with applicable legal requirements.
Our Company is committed to processing personal data in accordance with applicable data protection laws and guidelines, and to respecting the rights of Data Subjects. The security of personal data is our priority.
This Privacy Policy provides information about our data processing activities in relation to the provision of our services and the operation and use of the website.
Data processing for marketing purposes related to the website
When a Data Subject visits the prolocate.eu website operated by the Company, the website places cookies—short data files—on the visitor's device. This allows the website to recognise the device when a connection is established between the device and the website.
Temporary cookies are placed on the visitor's device only during a particular session and are deleted when that session ends. The website also uses persistent cookies, which remain on the device until the visitor deletes them. The website uses cookies that collect information about the Data Subject's internet browsing habits in order to provide personalised advertising.
Consent of the Data Subject under Article 6(1)(a) GDPR, Section 5(1)(a) Infotv., and Section 13/A(4) of Hungarian Act CVIII of 2001.
Messages and enquiries received through the website
Through the website, the Company receives messages from visitors who may provide the following personal data:
- Name
- Email address
- Telephone number
- Subject and content of the message
Purpose and retention. The legal basis for processing is the consent of the Data Subject. The purpose is to process messages and enquiries, answer questions, and provide a quotation on request. The Company processes the data for a maximum of five years or until the Data Subject requests its deletion.
Other data processing activities
Contact details of business partners
The Company processes the following personal data of contact persons acting on behalf of its business partners:
- Name
- Position
- Email address
- Telephone number
These personal data are provided to the Company by the business partner or the Data Subject and are processed pursuant to Article 6(1)(b) and (f) GDPR for the duration of the existing business relationship.
The Company ensures the Data Subject's rights and remedies in this regard and takes the necessary measures to delete the personal data if the Data Subject objects to the processing.
Recruitment and job applications
The Company processes application materials, including CVs, of persons applying for a job, based on the Data Subject's consent until the selection process is completed or consent is withdrawn.
Where application material has not been received directly from the Data Subject, the Company ensures that the Data Subject has consented to the processing or transfer of personal data for this purpose. If necessary, the Data Subject is informed of the processing by the Company as Controller and is enabled to exercise the rights set out in this policy.
The Company may use a competency test during the selection process based on the consent of the person concerned. The Company uses only tests that assess the candidate's skills or abilities to perform the role applied for. It does not use competency tests that would reveal information belonging to special categories of personal data under the GDPR.
If the Company wishes to retain application files after the selection process, it obtains the written consent of the candidates concerned. If a Data Subject does not respond to the request within 15 days, the processing is terminated and the personal data is deleted.
During and after the selection process, the Company ensures that Data Subjects can exercise their rights in relation to the processing.
Data security measures applied by the Company
The Company protects personal data through the following organisational and technical measures:
- 01Controlled access
Under internal rules, access to personal data is limited to employees whose work requires the processing of that data.
- 02Physical records
Paper-based personal data is stored under strict internal rules designed to prevent unauthorised access.
- 03Electronic safeguards
Electronically stored personal data is protected through continuous virus protection, firewalls and logging that enables the Company to verify who accessed personal data and when. These measures protect the IT system against computer fraud and intrusion.
- 04Internal systems
The Company stores personal data in its internal IT system.
- 05Server protection
The physical protection of servers storing personal data is ensured through security management solutions.
Information and rights of Data Subjects
Right to information
Under the principles of fair and transparent processing, Data Subjects must be informed about the fact, legal basis, purpose and duration of the processing and whether the Company, as Controller, uses a processor.
If personal data is collected from the Data Subject, the Data Subject must be informed whether providing it is a statutory or contractual requirement, or a requirement necessary to enter into a contract; whether the Data Subject is obliged to provide it; and the possible consequences of failing to provide it.
Information about personal data processing must be provided when the personal data is collected. If the personal data was obtained from another source, the information must be provided within a reasonable time, taking the circumstances of the case into account.
A Data Subject may ask whether the Company processes their personal data and may request information about the legal basis, purpose, source and period of the processing. The information must be sent without delay and no later than 30 days to the contact address provided by the Data Subject.
If necessary, taking into account the complexity and number of requests, this deadline may be extended by a further two months. The Company informs the Data Subject of the extension within one month of receiving the request and states the reasons for the delay.
If the Company does not act on a request, it informs the Data Subject without delay and no later than one month after receiving the request of the reasons for not acting and of the possibility of lodging a complaint with the supervisory authority and seeking a judicial remedy.
Information and related action are provided free of charge. Where requests are manifestly unfounded or excessive, particularly because they are repetitive, the Company may:
- charge a reasonable fee reflecting the administrative cost of providing the information, communication or requested action; or
- refuse to act on the request.
The Controller bears the burden of demonstrating that a request is manifestly unfounded or excessive. If the Controller has reasonable doubts about the identity of the natural person making the request, it may request additional information necessary to confirm the identity of the Data Subject.
Right of access
The Data Subject has the right to obtain confirmation from the Company as to whether personal data concerning them is being processed.
The Data Subject is entitled to access the data collected about them and to exercise this right simply and at reasonable intervals in order to verify whether the data is processed lawfully.
Where processing concerning the Data Subject is ongoing, the Data Subject has the right to access personal data and the following information:
- the purposes of the processing;
- the categories of personal data concerned;
- the recipients or categories of recipients to whom the personal data has been or will be disclosed, particularly recipients in third countries or international organisations;
- where possible, the envisaged duration of storage, or otherwise the criteria used to determine that duration;
- the right to request rectification, erasure or restriction of processing and to object to processing;
- the right to lodge a complaint with the supervisory authority;
- where the data was not collected from the Data Subject, any available information about its source; and
- the existence of automated decision-making, including profiling, and meaningful information about the logic involved, the significance of the processing and its likely consequences.
The Controller provides a copy of the personal data undergoing processing. For further copies requested by the Data Subject, the Controller may charge a reasonable fee based on administrative costs. Where a request is made electronically, and unless otherwise requested, the information is provided in a commonly used electronic form.
Right to rectification
The Data Subject has the right to obtain from the Controller, without undue delay, the rectification of inaccurate personal data concerning them. Taking into account the purposes of processing, the Data Subject also has the right to have incomplete personal data completed, including by providing a supplementary statement.
Rectification must be arranged without delay and no later than 30 days, and notice must be sent to the contact address provided by the Data Subject.
The Controller informs each recipient to whom personal data has been disclosed of the rectification unless this proves impossible or involves disproportionate effort. Upon request, the Controller informs the Data Subject of those recipients.
Right to erasure (“right to be forgotten”)
The Data Subject is entitled to request the erasure of personal data and that the data no longer be processed where:
- the personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
- the Data Subject withdraws consent and there is no other legal ground for processing;
- the Data Subject objects to processing and there are no overriding legitimate grounds for processing;
- the personal data has been unlawfully processed; or
- the personal data must be erased to comply with a legal obligation under Union or Member State law to which the Controller is subject.
The right to erasure does not apply where processing is necessary:
- to comply with a legal obligation under Union or Member State law, to perform a task carried out in the public interest, or in the exercise of official authority vested in the Controller; or
- for the establishment, exercise or defence of legal claims.
Where personal data is processed for direct marketing, the Data Subject has the right to object at any time to processing for that marketing.
If an erasure request is well founded, erasure is carried out without delay and no later than 30 days, and notice is sent to the contact address provided by the Data Subject. The Controller informs each recipient to whom personal data has been disclosed of the erasure unless this proves impossible or involves disproportionate effort. Upon request, the Controller informs the Data Subject of those recipients.
Right to restriction of processing
The Data Subject is entitled to request restriction of processing where:
- the accuracy of the personal data is contested by the Data Subject, for a period enabling the Controller to verify its accuracy;
- the processing is unlawful and the Data Subject opposes erasure and requests restriction instead;
- the Controller no longer needs the personal data for processing, but the Data Subject requires it for the establishment, exercise or defence of legal claims; or
- the Data Subject has objected to processing, pending verification of whether the Controller's legitimate grounds override those of the Data Subject.
Restriction continues until the reason requiring it no longer applies. Restriction must be implemented without delay and no later than eight days, and notice must be sent to the contact address provided by the Data Subject.
Where processing is restricted, the personal data may—apart from storage—be processed only with the Data Subject's consent; for the establishment, exercise or defence of legal claims; for the protection of the rights of another natural or legal person; or for an important public interest of the Union or a Member State.
The Data Subject is informed before a restriction is lifted. The Controller informs each recipient to whom personal data has been disclosed of the restriction unless this proves impossible or involves disproportionate effort. Upon request, the Controller informs the Data Subject of those recipients.
Right to object
The Data Subject may object to processing where the legal basis is the legitimate interest of the Controller or a third party. In that case, the Controller no longer processes the personal data unless it demonstrates compelling legitimate grounds that override the interests, rights and freedoms of the Data Subject, or the processing is required for the establishment, exercise or defence of legal claims.
Where personal data is processed for direct marketing, the Data Subject has the right to object at any time to processing for that purpose, including profiling related to direct marketing. If the Data Subject objects, the personal data may no longer be processed for direct marketing.
The objection must be examined within 15 days of submission. A decision must be made on its merits and sent to the contact address provided by the Data Subject.
Right to data portability
The Data Subject has the right to receive personal data concerning them that they provided to a Controller in a structured, commonly used and machine-readable format, and to transmit that data to another Controller without hindrance, where:
- the processing is based on consent or on a contract; and
- the processing is carried out by automated means.
When exercising the right to data portability, the Data Subject has the right to have personal data transmitted directly from one Controller to another where technically feasible.
Enforcement possibilities connected to data processing
The Data Subject may submit a complaint or request to the Company as Data Controller through either of the following channels:
If rights connected to personal data processing are infringed, the Data Subject may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information.
The Data Subject may submit a claim to the competent court if their rights are infringed. The court proceeds as a matter of priority. At the Data Subject's choice, the claim may be submitted to the court competent according to the Data Subject's permanent or temporary residence.
The Controller must compensate damage caused by unlawful processing or by a breach of data security requirements by the Controller or processor. If the Controller infringes privacy rights by unlawfully processing data or breaching data security requirements, the Data Subject may claim damages.