HunTracker

Privacy Notice

This Privacy Notice sets out the following: Léman Gábor Imre individual contractor as Data controller hereinafter referred to as: Data controller and by him operated HunTracker mobile app the processing of data, the order in which the records and databases are kept and used.

The HunTracker is a mobile application (hereinafter referred to as: Application) is an application for use on mobile devices which, depending on the operating system used, Apple app storeand Google Play Store is also available. It can be downloaded and installed through application warehouses.

When downloading the Application and using the App Store, personal data may also be processed in connection with Apple's or Google's own services. The terms, purpose and conditions for such data processing shall be determined by the relevant platform provider, which are not covered by this Privacy Notice.

That's on data processing related to the use of the Apple App Store Apple's own privacy policy provides detailed information on:

Apple App Store and Privacy

The Data processing related to the use of the Google Play Store Google's privacy and data processing guidelines. Information on the handling of Google Play user data and the privacy requirements of the applications can be found on the following page:

Google Play User data / privacy policy

This Privacy Notice specifically applies to individual data processing in connection with the use of the HunTracker Application, i.e. the data processing operations for which the Application Operator determines the purpose and means of processing of personal data and for which it is responsible as controller.

When operating the HunTracker Application, the controller shall take into account, in addition to the applicable data protection legislation, the platforms for the dissemination of the Application in particular: Apple App Store and Google Play Store Data protection, data security and user data processing requirements I'm sure you are.

Apple and Google shall establish their own data protection requirements for applications, including, in particular, requirements for the data collected and processed by applications, the transparency of data processing, access to individual device functions and data, and adequate information for users.

The purpose of this Privacy Notice is therefore to ensure that users of HunTracker receive transparent and comprehensible information on the data processing carried out during the use of the Application, in particular about what personal data the Application processes, for what purposes and on what grounds it uses it, how long it keeps it, who can access the data and what rights users have in relation to the processing of their personal data.

This leaflet contains only the following information: HunTracker for data processing under the responsibility of the Application Manager Apple, Google or other independent data controllers who may be involved in the operation of the Application are subject to their own privacy policy and data processing conditions.

The data processing information sheet is available on a continuous basis to the HunTracker in the mobile application, changes published within the applicationshall enter into force on the date of entry into force of this Agreement.

I. Details of the Data Controller

Léman Gábor Imre individual contractor

registered office: 8440 Herend, Ady Endre utca 11/A, Door 4.

Tax number: 92306552-1-51

Registration number: 62712277

Telephone: 30-5489660

E-mail: saborz@gmail.com

II. Processing of personal data

The data controller shall: HunTracker mobile app the processing of data is carried out on the basis of the voluntary consent of the data subjects or on the basis of a legal authorisation.

The Contact Group shall be informed clearly and in detail of: any facts relating to the processing of your data, in particular the purpose and legal basis for the processing, the person authorised to process and process the data, the duration of the processing and who may know the data.

In the event of voluntary consent you can request information at any time about the scope of the personal data processed and how they are used. you can withdraw your consent if you voluntarily consent, except in cases where the data processing is carried out under a legal obligation. in such cases we will provide information on the further processing of the data.

The When registering for the HunTracker mobile app and using the service, you must provide your personal data if: not provide your personal data, thus obtaining the consent of the Data Subject.

The HunTracker mobile application does not perform profiling.

III. Processing of personal data entered in the HunTracker mobile application

1. Processing of data entered during registration

To access certain functions of the HunTracker application, a user account is created and registration is required. The purpose of registration is to identify the user, to create and maintain individual user accounts and to ensure that the user can access the application's registration-related functions.

When registering, the provision of certain data is mandatory, while the provision of additional data may be decided by the user at his own discretion.

Categories of personal data processed:

mandatory data: first name, surname, e-mail address, individual username,

data that can be provided selectively:name, gender (male, female, unwilling to give); age - in band definition; expectation

Compulsory data processing is used to create a user account, to identify the user, to secure the rights associated with the account and to use the services associated with the application's registration.

The provision of optional data is voluntary. The user can decide whether to provide this data during the use of the application. The purpose of managing the optional data is to supplement the user profile, or if the data is related to the operation of an application function to ensure a more personalized use of that function.

Legal basis for processing:

Article 6(1)(a) GDPR: “the data subject has given consent to the processing of his or her personal data for one or more specific purposes.”

Article 6(1)(b) GDPR: “processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.”

Retention period:

the registration period until the termination of the registration/user account (Article 17 (1) GDPR)

Method of processing:

in electronic form

The controller shall transfer the data of the data subject to a third party only in the following cases:

Apple/Google: subscription and rights management. Cloud and background service provider: account and application data storage, synchronization and restoration. Map/location service provider: map and location functions. Weather data source: weather data. Email/push service provider: system messages and notifications. Error diagnostics/analytics only according to the final technical solution selected and user consent.

2. Processing of the USER ACCOUNT

When using the HunTracker application, the user can use various functions of the application after registration, including recording data, uploading content, connecting with other users, and using location-related functions, depending on 's choice and the permissions granted to the application.

The scope of the data processed during the use of the application therefore also depends on which functions the Applicant uses, which data and content it records or uploads, and which optional functions it allows to be used.

Categories of personal data processed:

Registration and profile data; photos and videos; optional location and GPS tracking data;

Data Subjects: persons using the HunTracker mobile application

Purpose of processing: support for the service provided by the application

The purpose of data processing shall include, in particular, the operation and making available of the functions of the application, the management of data and content related to the user profile, the storage and display of information related to hunting activities, recorded by the user, the provision of user interactions and community functions, the storage and display of photographs and videos, and at the option of the affected person

The processing of personal data relating to the optional function is not conditional on the use of application functions that can be provided without the processing of the data.

Legal basis for processing:

Article 6(1)(a) GDPR: “the data subject has given consent to the processing of his or her personal data for one or more specific purposes.”

Article 6(1)(b) GDPR: “processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.”

Retention period:

until the termination of the user account (Article 17 (1) GDPR)

In regular backups, data may be retained for up to 6 months as a result of the backup cycle.

Data and content created or uploaded by the Applicant during the use of the Application shall, as a general rule, be processed until the user account is established.

Where a function of the application allows the user to automatically delete certain data or content, the affected party may initiate the removal through that function.

Following the termination of the user account, the Controller shall delete personal data and content relating to the account, unless further retention of any data is required by law or further processing is necessary to fulfil a legal obligation or to bring, enforce or protect a legal claim.

Due to the specificities of the backups, technical copies of the deleted data may still be retained until the end of the backup cycle; these data will not be used in normal operation and will be deleted or rewritten at the end of the backup cycle.

Method of processing: in electronic form

The controller shall transfer the data of the data subject to a third party only in the following cases:

The the operation of the application store, cloud and background services, maps/location, weather data source, e-mail/push service and possible error detection service.

Supabase Inc. (cloud/background system, database, authentication); Cloudflare, Inc. (photo and video storage); OneSignal, Inc. (push interpretations); Google Ireland Limited / Google LLC (location and location service, Google Play store and payment service); Apple Distribution International Ltd. (App Store store and payment service); Deutscher Wetterdienst (DWD) and the Norwegian Meteorological Institute (MET Norway) (weather data source).

Data shall be transmitted only to the extent necessary for the performance of the service to data processors and platform providers for account management, cloud storage and synchronization, subscription, email/push notification, map/location function, weather and error detection purposes.

3. Processing of location data

Access to locations shall be granted with the consent of the user after authorisation on the device used. The application may access the device's location function within the framework of the authorisation system provided by the operating system.

The user may manage the location allowances granted to the application between the settings of the device's operating system; blocking or restricting access to the locations may restrict or impede the operation of the particular location-based function.

Categories of personal data processed:

the place registered on the device after authorisation on the device used, with the consent of the user.The management of locations shall be carried out only to the extent necessary to ensure a location-based function used by the Applicant.

Data Subjects: the individual ordering the Application and the contact person of a business entity

Purpose of processing:

Own GPS trace recording; sharing the live location of the participants during a joint hunt; optional recording of the hunting or landing location; presentation of current weather data related to the location.

Based on location, the mobile app does not send notifications.

The controller shall not use the locations to send automatic notifications to the user solely in view of the user's geographical position or entry into or exit from a specific geographical area.

Legal basis for processing:

Article 6 (1) (b) of the GDPR provides that 'the processing of data is necessary for the performance of a contract in which the data subject is required to take action at the request of one of the parties or before the conclusion of the contract;'.

Retention period:

until the termination of the user account (Article 17 (1) GDPR)

In regular backups, data may be retained for up to 6 months as a result of the backup cycle.

Reservations in connection with user accounts shall be dealt with until the user accounts are deleted and, given the specificities of the backups, technical copies of deleted locations may be retained until the end of the backup cycle for up to 6 months.

Method of processing: in electronic form

4. Processing of data provided when ORDERING THE SERVICE

When ordering a service available under HunTracker, the Controller shall process the personal data necessary for the use of the service, the creation and performance of the contract.

The ordering of the service is linked to the user account that has already been created, so that the user does not have to repeatedly provide the data that is already available to the controller during registration.

Categories of personal data processed:

the mandatory registration data: mandatory data: first name, surname, e-mail address, individual username,

no separate billing details are required

Circles affected: contacts of individuals and companies using the application

Purpose of processing:

Identification of the contractual partner, conclusion of a contract, fulfilment of a contractual obligation, fulfilment of a billing obligation, recoverability and verification of data in the event of any legal disputes or claims.

The primary purpose of the processing is accordingly to manage the ordering of the service, to establish and execute the contract, to ensure the user's right to use the service and to fulfil the obligations under the contract.

After the performance of the contract, the controller may also process the data in order to handle any contractual claims, prove the existence and performance of the contract in the event of a legal dispute and to enforce the rights of the controller or the data subject.

Legal basis for processing:

(a) Article 6 (1) (b) of the GDPR provides that 'the processing of data is necessary for the performance of a contract in which the data subject is required to take action at the request of one of the parties or before the conclusion of the contract;'.

(b) Article 6 (f) of the GDPR provides the legal basis for the processing of data following the performance of the contract, which states: The processing is necessary for the legitimate interests of the controller or of a third party

Retention period:

The data referred to above shall be stored by the controller for a period of 5 years + 1 year from the performance of the contract or the failure to perform it (until the maturity of the claims arising from the contract).

The purpose of the data retention period is to ensure that the controller can retrieve and use the data necessary to enforce any contractual or other legal claims or to protect against such claims during the period open for enforceable claims.

After the expiry of the retention period, the Controller shall delete personal data, unless further retention is required by law or further processing of the data is necessary for the purpose of presenting, validating or protecting a legal claim that has already been initiated.

The controller shall transfer the data of the data subject to a third party only in the following cases:

The transfer of data is necessary in order to fulfil the legal obligation of the Controller GDPR 6. in accordance with Article 1 (1) (c),

The controller may transfer personal data to the authorised authority, court or other body authorised by law to request data where the transfer is necessary for the fulfilment of a legal obligation to the controller.

Such data transmission shall be carried out solely for the purposes laid down in law, to the addressee entitled and within the scope of the data necessary to fulfil that legal obligation.

5. DATA PROCESSING DURING PURCHASE, PAYMENT AND RECEIPT ISSUANCE

The application does not contain a separate billing data field and the user does not have to provide HunTracker with separate billing data when making a purchase.

Purchases of paid services available on the HunTracker application depending on the location of the application download Apple app storeand Google Play Store is also available. It's done through your system.

Purchases, payment processing and proof-of-purchase shall be carried out in the respective App Store, i.e. Apple or Google's own system. The personal data necessary for the purchase and proof-of-purchase shall be processed by Apple or Google or the payment and billing service providers used by them.

The HunTracker does not directly receive or process the user's bank card details.

Management of payment and billing data

The scope of the personal data processed in the payment process shall be determined by Apple or Google in accordance with their own service and the data provided by the Applicant on that platform.

The processing of payment and credentials data by Apple or Google is governed by the platform's own data protection and payment conditions.

Apple App Store and Privacy

Google Play User data / privacy policy

Accordingly, the HunTracker Data Controller does not specify the purpose and means of data processing for the purposes of payment and verification of data processing carried out by Apple or Google for its own purposes and on its own system.

Period of processing

The period of retention of payment and credentials data is determined by Apple and Google's own data processing rules and their legal obligations.

The HunTracker Data Controller shall not specify the retention period for payment and verification data processed by the platform.

Data processing of application stores

In the case of purchases, payments and proofs, Apple and Google shall act in accordance with their own data protection rules with regard to the data processing they define.

Detailed information on the processing of data of the Apple App Store and Google Play Store is contained in the data protection notices of Apple and Google in force at all times, which are also referred to in the introductory provisions of this Privacy Notice.

The HunTracker Data Controller shall not be responsible for the independent data processing activities of Apple, Google or any payment or billing service provider used by them.

6. MANAGEMENT OF SUBSCRIPTIONS AND SUBSCRIPTION ENTITLEMENTS

Some of the services and functions of the HunTracker application are subject to a subscription.

Purchases and payment transactions are handled by Apple or Google's own systems.

However, in order to determine whether a given user is entitled to subscription services and functions, HunTracker may receive and process technical data relating to the subscription and its current status from the App Store.

The processing does not cover the user's credit card details. HunTracker does not directly receive or process the user's credit card details.

Circles affected

Users of the HunTracker application who use its paid subscription services.

Scope of personal data processed

HunTracker is responsible for administering the subscriber entitlement to: Registration data related to the user account, in particular the user name, e-mail address and individual username.

Purpose of data processing

The purpose of data processing is to verify the existence and existence of a subscription, establish the current status of the subscription, manage the subscriber's entitlement and ensure that the user has access to the services and functions corresponding to the subscription.

Legal basis for data processing

Article 6 (1) (b) of the GDPR provides that 'processing is necessary to fulfil a contract,

where, at the request of one of the parties or before the conclusion of the contract, the

steps necessary to take;'.

Period of processing

The Controller shall process the technical data relating to the subscription during the subscription and for as long as they are necessary to establish the subscriber's entitlement, to perform the subscription-related service or to treat the subscription's status in an appropriate manner.

Following the termination of the subscription, the Controller shall delete the data or if further retention of any data is necessary to enforce any contractual claims or to protect against them he may process it until the end of the applicable limitation period.

The method of data processing - in electronic form

Subscription rights shall be checked and managed electronically on the basis of technical information provided by the Apple App Store or the Google Play Store.

Source of the data

Source of personal data of the App Store used by the Applicant:

The Apple app store: Apple Distribution International Ltd. or the Apple subscription management system;

The Google Play store: Google Ireland Limited / Google LLC or the subscription management system of Google Play.

App stores shall process data related to purchases, payments and the operation of their own services on the basis of their own data protection rules.

Transmission of data to recipients

The technical information relating to the subscription shall be made available to HunTracker from the systems of Apple and Google to the extent necessary to verify and manage the subscriber's rights.

HunTracker does not receive or process bank card information provided during the payment process.

Technical data related to the subscription shall be accessible to the cloud and background service provider used to operate the application to the extent necessary to provide the service.

7. Processing of data entered during contacting

In relation to the use of the HunTracker application, the operation of the application, the subscription and the services available, the Data Subject may contact the Controller.

In the course of the contact, the Controller shall only process personal data necessary to respond to a request, to contact Contact or to handle the case in question.

Categories of personal data processed: Name, telephone number, email address, content of message

The content of the message shall contain information freely expressed by the Data Subject and, where possible, the Data Subject shall provide only the personal data in the message that is necessary to respond to his request or to handle the case in question.

Data Subjects: persons contacting the operator through the HunTracker application

Purpose of processing:

Receiving and responding to a request from the affected person, contacting the affected person, answering questions about the use of the application or the service used, handling any error reports, comments and other requests.

Where the request relates to an existing contractual relationship, subscription or service provided by the Controller, the purpose of data processing shall also be to provide the administration of that service and the communication necessary for the performance of the contract.

Legal basis for processing:

Article 6(1)(a) GDPR: “the data subject has given consent to the processing of his or her personal data for one or more specific purposes.” The Data Subject may withdraw consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

Article 6(1)(b) GDPR: “processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.”

Retention period: 6 months or until the Data Subject requests erasure (Article 17(1) GDPR)

Method of processing: in electronic form

IV. Method of storing personal data and security of data processing

Data shall only be accessed by the Controller, processed by the Controller and used solely in the manner and for the purposes set out in this Privacy Notice.

The data controller's computer systems and other data storage facilities are located at its headquarters and on its server.

The controller shall select and operate the IT tools used in the provision of the service to manage personal data in such a way that the data processed:

The controller and the data processor shall take appropriate technical and organisational measures, taking into account the current state of science and technology and the costs of implementation, the nature, scope, circumstances and objectives of the processing of the data and the changing probability and severity of the risk to the rights and freedoms of natural persons, in order to guarantee an adequate level of data security, including, where appropriate:

(a)the pseudonymisation and encryption of personal data;
(b)ensuring the continuous confidentiality, integrity, availability and resilience of the systems and services used to process personal data;
(c)in the event of a physical or technical incident, the ability to restore access to and availability of personal data in a timely manner;
(d)the procedure for the regular testing, evaluation and evaluation of the effectiveness of technical and organisational measures taken to ensure the security of data processing.

In determining an adequate level of security, specific consideration shall be given to the risks arising from the processing of personal data, in particular those arising from the accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access to personal data transmitted, stored or otherwise processed.

The controller shall take measures to ensure that natural persons under his control who have access to personal data may only process such data in accordance with the controller's instructions, unless they are obliged to do so by Union or Member State law.

The controller shall take appropriate measures to protect the data, in particular against unauthorised access, alteration, transmission, disclosure, deletion or destruction, as well as accidental destruction, damage and unavailability resulting from a change in the technique used.

The controller shall ensure that, in order to protect the electronically processed data in its various records, the relevant technical solution ensures that the stored data , except where permitted by law cannot be directly linked and assigned to the data subject.

The controller shall take technical, organisational and organisational measures to ensure the security of the processing of the data in the light of current technological developments, providing a level of protection appropriate to the risks associated with the processing.

During processing, the Data Controller shall preserve:

The IT system and network of the controller and its partners are both protected against computer-assisted fraud, espionage, sabotage, vandalism, fire and flood, as well as computer viruses, computer hacks and denial-of-service attacks.

V. Rights of data subjects

Personal data may only be processed for a specific purpose, for the exercise of a right and for the fulfilment of an obligation, and at all stages of the processing must comply with that purpose and the data must be collected and processed fairly.

Only personal data which are essential for the achievement of the purpose of the processing, which are suitable for the achievement of the purpose, and only to the extent and for the time necessary for the achievement of the purpose may be processed.

The controller shall take appropriate measures to provide all information to the data subject in a concise, transparent, understandable and easily accessible form, in a clear and comprehensible manner.

Information shall be provided in writing or by electronic means.

Oral information may also be provided at the request of the data subject, provided that the identity of the data subject has been otherwise verified.

1. Right to information:

The Data Subject may request information on the processing of his or her personal data and may request the correction of his or her personal data or, except for mandatory data processing, the deletion or withdrawal thereof, he or she may exercise his or her right to data retention and objection in the manner indicated at the time of receipt of the data or at the addresses of the Data Controller as set out in this Data Processing Notice.

The data subject shall be informed in a clear, comprehensible and detailed manner of all the facts relating to the processing of his data, in particular the purpose and legal basis for the processing, the person authorised to process and process the data, the duration of the processing, whether the personal data is processed by the controller with the consent of the data subject and for the purpose of fulfilling a legal obligation to the controller or the legitimate interest of a third party, and who may know the data.

2. Right of access:

The Data Subject shall be entitled to receive feedback from the Controller as to whether the processing of his or her personal data is ongoing and, if such processing is ongoing, to have access to the personal data and to the information set out in the Regulation.

The controller shall provide the data subject with information on the ongoing processing of the data relating to the data subject in relation to:

- your personal data

- the purposes of the processing;

- the categories of personal data concerned;

- the persons to whom the data concerned have been communicated or will be communicated;

- the duration of storage of the data;

- the right to rectification, erasure, restriction and objection to data processing;

- the right to lodge a complaint with the supervisory authority;

- the source of the data processed;

- the details and practical effects of profiling and/or automated decision-making and its application;

- the transfer of the processed data to a third country or an international organisation.

In the event of a request for data by the Data Subject, the Controller shall provide a copy of the data processed by the Data Subject in accordance with the request.

3. Right to rectification:

The Data Subject shall be entitled, at the request of the Controller, to correct any inaccurate personal data relating to him without undue delay, taking into account the purpose of the processing, to request the supplementation of the missing personal data by means of, inter alia, a supplementary declaration.

4. Right to erasure:

The Data Subject shall be entitled, at the request of the Controller, to erase the personal data relating to him without undue delay and the Controller shall be obliged to erase the personal data relating to the Data Subject without undue delay under the following specified conditions:

5. The right to restrict the processing of data:

The Data Subject shall be entitled, at the request of the Controller, to restrict processing if one of the following conditions is fulfilled:

6. Right to data portability:

The Data Subject shall be entitled to receive the personal data concerning him which he has made available to the Controller in a widely used, machine-readable format and shall be entitled to transfer that data to another controller without being prevented by the controller to whom the personal data were made available, where the processing is based on consent or contract, where the data is processed in an automated manner and where the right to data portability is exercised, the data subject shall be entitled, if technically feasible, to request the direct transfer of the personal data between the controllers.

7. Right to object:

Where personal data are processed for the purpose of direct business acquisition, the Data Subject shall be entitled at any time to object to the processing of personal data relating to him for that purpose, including profiling, where this relates to direct business acquisition.

If the Data Subject objects to the processing of personal data for direct business purposes, the personal data may no longer be processed for that purpose.

The data subject shall have the right to object at any time, for reasons relating to his or her own situation, to the processing of personal data necessary for the performance of a task in the public interest or in the exercise of a public authority granted to the controller, or to the processing necessary to enforce the legitimate interests of the controller or of a third party, including profiling based on those provisions.

In the event of an objection, the Controller may no longer process personal data unless justified by compelling legitimate reasons which take precedence over the interests, rights and freedoms of the Data Subject or which relate to the presentation, enforcement or protection of legal claims.

8. Automated individual decision-making, including profiling:

The Data Subject shall be entitled not to be affected by a decision based solely on automated data processing including profiling which would have legal effect on him or her or would otherwise significantly affect him or her.

The preceding paragraph shall not apply where the decision:

9. Right of withdrawal:

The Data Subject shall have the right to withdraw his consent at any time and the withdrawal of consent shall be without prejudice to the lawfulness of the processing of data prior to withdrawal.

VI. Information to the data subject on the data protection incident

Reporting a data protection incident to the supervisory authority

The data protection incident shall be reported to the competent supervisory authority by the controller without undue delay and, where possible, no later than 72 hours after becoming aware of the data protection incident, unless the data protection incident is unlikely to pose a risk to the rights and freedoms of natural persons.

The notification shall contain at least:

    the nature of the data protection incident, including where possible the categories and approximate number of data subjects and the categories and approximate number of data relevant to the incident;
 the name and address of the data protection officer or other contact person providing further information;
 a description of the likely consequences of the data protection incident;
 a description of the measures taken or planned by the controller to remedy the data protection incident, including, where appropriate, measures to mitigate any adverse consequences resulting from the data protection incident.

Where and where it is not possible to communicate information simultaneously, it may be communicated in further detail at a later date without further undue delay.

The controller shall record data protection incidents, indicating the facts related to the data protection incident, its effects and the measures taken to remedy it, enabling the supervisory authority to verify compliance with the requirements of this Article.

Where the data protection incident is likely to present a high risk to the rights and freedoms of natural persons, the controller shall inform the data subject of the data protection incident without undue delay.

The information provided to the data subject shall clearly and comprehensively describe the nature of the data protection incident and communicate at least the information and measures set out above.

The data subject does not need to be informed of the data protection incident if any of the following conditions are met:

 the controller has implemented appropriate technical and organisational safeguards and those safeguards have been applied to the data affected by the data protection incident, in particular those measures such as the use of encryption which render the data incomprehensible to persons not authorised to access personal data;
 the controller has taken additional measures following the data protection incident to ensure that the high risk to the rights and freedoms of the data subject is no longer likely to occur;
 information would require a disproportionate effort; in such cases, data subjects should be informed by means of publicly disclosed information or similar measures should be taken to ensure that data subjects are equally effectively informed.

If the controller has not yet notified the data subject of the data protection incident, the supervisory authority, after considering whether the data protection incident is likely to present a high risk, may order the data subject to be informed or determine whether one of the conditions that does not require the information is met.

VII. Concepts and interpretations relating to personal data

personal data: any information relating to an identified or identifiable natural person (s); identifiable natural person who can be identified directly or indirectly, in particular by one or more factors relating to an identifier, such as name, number, location data, online identifier or physical, physiological, genetic, intellectual, economic, cultural or social identity of the natural person;

the processing of data: the aggregate of any operation or operations on personal data or databases carried out in an automated or non-automated manner, such as collection, recording, sequencing, tagging, storing, transforming or changing, querying, viewing, using, communicating or otherwise making available through transmission, dissemination, coordination or interconnection, restriction, deletion or destruction;

restriction of data processing: marking the personal data stored in order to limit their future processing;

Profiling: any form of automated processing of personal data in which personal data is used to assess certain personal characteristics of a natural person, in particular those relating to performance at work, economic situation, health status, personal preferences, interests, reliability, behaviour, place of residence or movement;

recording system: any centralized, decentralized or functionally or geographically segregated stations of personal data that are accessible under specified identifiers;

data controller: the natural or legal person, public authority, agency or any other body that determines the purposes and means of processing of personal data, either individually or together with others; where the purposes and means of processing are defined by Union or Member State law, specific criteria for the designation of the controller or controller may also be defined by Union or Member State law;

data processor: the natural or legal person, public authority, agency or any other body handling personal data on behalf of the controller;

addressed: the natural or legal person, public authority, agency or any other body to which or to which personal data are communicated, whether or not a third party. Public authorities which may have access to personal data in the context of a specific investigation in accordance with Union or Member State law shall not be deemed to be the addressee; the processing of such data by such public authorities shall comply with the applicable data protection rules in accordance with the purposes of the processing;

third party: a natural or legal person, public authority, agency or any other body which is not the same as the data subject, controller, processor or persons authorised to process personal data under the direct control of the controller or processor;

the contribution of the data subject;: a voluntary, specific and explicit declaration of the data subject's will, based on adequate information, in which the declaration or confirmation in question indicates in an unambiguous manner that he or she agrees to the processing of personal data concerning him or her;

data protection incidents: a breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure or unauthorised access of personal data transmitted, stored or otherwise processed;

the objection concerned: the data subject's declaration that he objects to the processing of his personal data and requests that the processing be terminated or that the data processed be deleted;

data transmission: making the data available to a specified third party;

to be made public: making the data accessible to everyone;

data deletion: rendering the data unrecognizable in such a way that it is no longer possible to recover them;

data marking: the identification of the data in order to distinguish it;

data encryption: the identification of the data for the purpose of limiting its further processing to a definitive or definite period;

destruction of data: the complete physical destruction of the data carrier containing the data;

third country: all States which are not EEA States.

VIII. Principles for the processing of personal data

The processing of personal data shall be carried out in a way that is lawful and fair and transparent to the data subject. (Lawfulness, fairness of procedure and transparency);

Personal data shall only be collected for specified, clear and lawful purposes and shall not be processed in a manner incompatible with those purposes; in accordance with Article 89 (1), further processing for archival purposes of public interest, scientific and historical research or statistical purposes shall not be considered incompatible with the original purpose. (bonding to the target);

Personal data shall be appropriate and relevant to the purposes of the processing and shall be limited to what is necessary. (data saving)

Personal data shall be accurate and, if necessary, up-to-date; all reasonable measures shall be taken to ensure that personal data which are inaccurate for the purposes of data processing are immediately deleted or corrected (Precision)

Personal data shall be stored in a form allowing the identification of data subjects only for the time necessary to achieve the purposes for which they are processed; further storage of personal data may take place only where the processing of personal data is carried out for archiving purposes of public interest, scientific and historical research or statistical purposes in accordance with Article 89 (1), taking into account the implementation of the appropriate technical and organisational measures provided for in this Regulation to protect the rights and freedoms of data subjects. (limited storage capacity);

The processing of personal data shall be carried out in such a way as to ensure adequate security of personal data, including protection against unauthorised or unlawful processing, accidental loss, destruction or damage, by the application of appropriate technical or organisational measures, including: (Integrity and confidentiality)

The controller shall be responsible for and able to demonstrate compliance with the above. (Accountability).

The controller shall declare that the processing of personal data is carried out in accordance with the principles set out in this paragraph.

IX. Procedural rules

Transparent information, communication and measures for the exercise of the rights of the data subject

Where the controller receives a request from the data subject, the controller shall inform the data subject in writing as soon as possible, but no later than 30 days, of the measures taken on the basis of the request.

Where the complexity of the request or other objective circumstances justify it, the 30-day time limit may be extended once, up to a maximum of 60 days. The data controller shall inform the data subject, indicating the reasons for the delay, within one month of receipt of the request.

Where the controller fails to take action at the request of the data subject, it shall inform the data subject without delay, but at the latest within one month of receipt of the request, of the reasons for the failure to take action and of the possibility for the data subject to lodge a complaint with a supervisory authority and to exercise the right to a judicial remedy.

Information under Articles 13 and 14 of the GDPR and information and measures under Articles 1522 and 34 shall be provided free of charge. Where the request concerned is clearly unfounded or exceeds by reason of its particularly repetitive nature, the controller shall take into account the administrative costs of providing the requested information or information or taking the requested action:

(a)may charge a reasonable fee; or
(b)refuse to take action on the basis of the request.

It is the responsibility of the controller to demonstrate that the request is clearly unfounded or excessive.

If the controller has reasonable doubts about the identity of the natural person making the request, he or she may request further information necessary to confirm the identity of the data subject.

If the applicant requests data on a paper basis or on an electronic medium (CD or DVD), the Data Controller shall provide a copy of the data concerned in PDF format free of charge on an electronic medium. Transmitting data on a paper basis would be technically disproportionate and the Data Controller would, in any case, provide the requested data on an electronic medium in one copy.

The controller shall inform all persons to whom the data concerned have been previously communicated of the correction, deletion or restriction carried out by him, unless the information is impossible or requires disproportionate effort.

The controller shall reply to the request in electronic form, unless:

Exercise of the right of objection:

The controller shall examine the objection within the shortest period from the date of submission of the application, but not more than 15 days, take a decision on its basis and inform the applicant in writing of its decision.

Where the User's objection is found to be justified, the Controller shall terminate the processing of the data, including further collection and transmission of the data, and block the data, and shall notify the objection and the measures taken on the basis thereof to all those to whom the personal data concerned by the objection were previously transmitted and who are obliged to take measures to enforce the right to object.

X. Legal remedies

If you have an objection or problem with Data Processing, please contact the following address:

Léman Gábor Imre individual contractor

registered office: 8440 Herend, Ady Endre utca 11/A, Door 4.

Telephone: 30-5489660

E-mail: saborz@gmail.com

Compensation and damages for infringement of personality rights

Any person who has suffered material or non-material damage as a result of a breach of the GDPR shall be entitled to compensation from the controller for the damage suffered.

All controllers involved in the processing shall be liable for any damage caused by the processing in breach of this Regulation.

The controller shall be exempt from liability if he proves that he is not liable in any way for the event causing the damage.

Right to seek judicial remedy:

If the data subject considers that his or her rights have been infringed by the controller , he or she is entitled to appeal to a court with jurisdiction and competence according to Pp.

Proceedings before the data protection authority:

Any complaint may be lodged with the Hungarian National Authority for Data Protection and Freedom of Information:

Name: National Data Protection and Freedom of Information Authority

Registered office: 1125 Budapest, Szilágyi Erzsébet fasor 22/C.

Mailing address: 1530 Budapest, P.O. Box 5.

Telephone number: 06-1/391-1400; fax number: 06-1/391-1410

E-mail: ugyfelszolgalat@naih.hu

Website: http://www.naih.hu

Official cooperation

Where the controller receives a formal request from the competent authorities, it shall communicate the specified personal data in a binding manner.

The controller shall transmit only data which are strictly necessary to achieve the purpose indicated by the requesting authority.

5. Legislation forming the basis of data processing

Closing provisions

This information sheet is intended to provide data subjects with an introduction to the controller's data processing practices, and the controller reserves the right to modify this information sheet.

The controller recognises that the content of this legal notice is binding on it and undertakes to ensure that all data processing relating to its activities complies with the requirements set out in this Regulation and in the applicable legislation and legal acts of the European Union.

In order to protect the personal data of its committed customers and partners, the Controller shall keep personal data confidential and take all security, technical and organisational measures to ensure the security of the data.

The controller undertakes to notify the data subjects in advance of any changes to the principles and practices of the processing of personal data in any way. The changes should also be published on the controller's website.

The controller declares that it fulfils its data processing obligations as set out in this Regulation from the date of acceptance of this Privacy Notice.

The controller shall inform the data subjects of the modification and publish the modified Privacy Notice on the website.

This Privacy Notice shall enter into force on 5 September 2026.