Privacy Policy
1. Introduction
Fógel and Papp Law Firm (hereinafter Fógel and Papp Law Firm, service provider, data controller, the Firm), as data controller, acknowledges the content of this legal notice as binding upon itself.
The Firm undertakes that all data processing related to its activities complies with the requirements set out in this policy and in the applicable legislation.
Fógel and Papp Law Firm is the operator of the fogelpapp.hu website.
Fógel and Papp Law Firm reserves the right to amend this notice at any time. Naturally, it will inform its audience of any changes in good time.
Fógel and Papp Law Firm is committed to protecting the personal data of its clients and partners and considers respect for its clients' right to informational self-determination to be of the utmost importance. The Data Controller treats personal data confidentially and takes every security, technical and organizational measure that guarantees the security of the data.
Below, Fógel and Papp Law Firm sets out its data processing principles and the requirements it has formulated for itself as data controller and complies with. Its data processing principles are in line with the applicable data protection legislation, in particular the following:
- Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information;
- Act V of 2013 on the Civil Code (Civil Code);
- Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activity.
- Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services;
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: "GDPR")
2. Definitions
- data subject: any specified natural person identified on the basis of personal data or identifiable, directly or indirectly;
- personal data: data that can be associated with the data subject — in particular the data subject's name, identification number and information characteristic of one or more of their physical, physiological, mental, economic, cultural or social identity — as well as any conclusion about the data subject that can be drawn from such data;
- consent: the voluntary and definite expression of the data subject's wish, based on adequate information, by which they give their unambiguous agreement to the processing of their personal data, either in full or in respect of specific operations;
- data controller: the natural or legal person, or organization without legal personality, who or which alone or together with others determines the purpose of the data processing, makes and implements the decisions concerning the processing (including the means used), or has them implemented by a data processor;
- data processing: irrespective of the procedure applied, any operation or set of operations performed on the data, in particular collecting, recording, registering, organizing, storing, altering, using, querying, transferring, disclosing, aligning or combining, blocking, erasing and destroying the data, as well as preventing their further use, taking photographs, audio or video recordings, and recording physical characteristics suitable for identifying a person (e.g. fingerprints or palm prints, DNA samples, iris images);
- data transfer: making the data accessible to a specified third party;
- disclosure: making the data accessible to anyone;
- data erasure: rendering the data unrecognizable in such a way that their restoration is no longer possible;
- data processing (technical): performing the technical tasks related to data processing operations, irrespective of the method and means applied and of the place of application, provided that the technical task is performed on the data;
- data processor: the natural or legal person, or organization without legal personality, who or which processes the data on the basis of a contract, including a contract concluded pursuant to a statutory provision.
3. Company details
Our company's details and contact information are as follows:
- Name: Fógel and Papp Law Firm
- Mailing address: 4026 Debrecen, Darabos utca 37., Hungary
- Tax number: 19319997-2-09
- Phone number: +36 30 313 8645
- E-mail: iroda@fogelpapp.hu
- Representatives of the data controller: Dr. Fógel Norbert, managing lawyer, Dr. Papp Tímea Erika, managing lawyer
4. The scope of personal data, and the purpose, legal basis and duration of the processing
We draw the attention of those providing data to Fógel and Papp Law Firm to the fact that if they provide personal data other than their own, it is the obligation of the person providing the data to obtain the data subject's consent. The data controller is not obliged to verify that such consent exists. The data controller draws the partner's attention to the fact that if the partner fails to meet this obligation and, as a result, the data subject asserts a claim against the data controller, the data controller may pass on the claim asserted and the amount of the related damage to the partner.
We provide the following information in relation to our individual data processing activities.
4.1. Requests for quotes and inquiries made by direct contact
Interested parties may contact our Firm directly by e-mail sent to the Firm's address or by telephone.
- Purpose of the processing: keeping in contact, in order to promote communication between the data subject and our Firm and to achieve the closest and most effective cooperation possible.
- Legal basis of the processing: legitimate interest — Article 6(1)(f) GDPR
- Scope of personal data processed: the name of the person requesting a quote / contact person; their e-mail address, phone number, and any other information provided by the data subject,
- Duration of the processing: for 3 years following the expiry of the validity of the quote, or until the data subject objects
- Recipients of the personal data: apart from the data processor(s) indicated in point 7, the data controller does not transfer the data obtained to any third party. The recorded data may be accessed only by the employees of the Data Controller and the designated colleagues of the data processor(s).
- Indication of the legitimate interest: it is our Firm's legitimate interest to process the data subject's data — direct marketing
- Scope of data subjects concerned: partners and data subjects making direct inquiries (e.g. by e-mail or telephone) about the Firm's services.
4.2. Requests for quotes and inquiries through the website (fogelpapp.hu)
Our company allows data subjects to request a quote electronically.
- Purpose of the processing: keeping in contact, in order to promote communication between the data subject and our Firm and to achieve the closest and most effective cooperation possible.
- Legal basis of the processing: the data subject's voluntary consent — Article 6(1)(a) GDPR.
- Scope of personal data processed: the name of the inquirer (first name, surname); their e-mail address, phone number, company name, and any other information provided by the data subject.
- Duration of the processing: for 3 years following the expiry of the validity of the quote, or until consent is withdrawn.
- Recipients of the personal data: apart from the data processor(s) indicated in point 7, the data controller does not transfer the data obtained to any third party. The recorded data may be accessed only by the employees of the Data Controller and the designated colleagues of the data processor(s).
- Scope of data subjects concerned: partners and data subjects inquiring about the Firm's services and products through the website.
4.3. Processing related to the follow-up of quote requests
- Purpose of the processing: it is the data controller's legitimate interest to keep a record of the data subject's data beyond the validity period of the quote for direct marketing purposes
- Legal basis of the processing: the data controller's legitimate interest, Article 6(1)(f) GDPR,
- Scope of personal data processed: contact person's surname and first name; phone number; e-mail address
- Recipients of the personal data: apart from the data processor(s) indicated in point 7, the data controller does not transfer the data obtained to any third party. The recorded data may be accessed only by the employees of the Data Controller and the designated colleagues of the data processor(s).
- Duration of the processing: until the data subject objects
- Indication of the legitimate interest: building business relationships with partners and those requesting quotes, and providing precise information to data subjects. It is our Firm's legitimate interest to process the data subject's data — direct marketing
- Scope of data subjects concerned: the addressees of quotes previously issued by the Firm and the contact person(s) named in them.
4.4. Newsletter registration
- Purpose of the processing: sending e-mail newsletters that also contain commercial advertising to interested parties, and providing information about current matters
- Legal basis of the processing: the data subject's prior, voluntary consent, Article 6(1)(a) GDPR,
- Scope of personal data processed: name, e-mail address
- Duration of the processing: until the voluntary consent is withdrawn or the data subject unsubscribes from the newsletter. Our Firm processes the data provided by the data subject until consent is withdrawn. On the basis of the withdrawal of consent, we delete the processed data from our newsletter database within 7 days at the latest, after which we will not send you any newsletters.
- Recipients of the personal data: apart from the data processor(s) indicated in point 7, the data controller does not transfer the data obtained to any third party. The recorded data may be accessed only by the employees of the Data Controller and the designated colleagues of the data processor(s). You may unsubscribe from the newsletter at any time by sending a message to our Firm at iroda@fogelpapp.hu, or by clicking the unsubscribe icon in the newsletter.
- Scope of data subjects concerned: partners and data subjects who have subscribed to the Firm's electronic newsletter.
4.5. Newsletter data (for newsletter registrations made before 25 May 2018)
- Purpose of the processing: sending e-mail newsletters that also contain commercial advertising to interested parties, and providing information about current matters
- Legal basis of the processing: the data controller's legitimate interest, Article 6(1)(f) GDPR,
- Scope of personal data processed: name, e-mail address
- Duration of the processing: until the data subject objects
- Indication of the legitimate interest: providing information that also contains commercial advertising and business offers to data subjects who have subscribed to the newsletter. It is our Firm's legitimate interest to process the data subject's data, direct marketing.
- Recipients of the personal data: apart from the data processor(s) indicated in point 7, the data controller does not transfer the data obtained to any third party. The recorded data may be accessed only by the employees of the Data Controller and the designated colleagues of the data processor(s). You may unsubscribe from the newsletter at any time by sending a message to our Firm at iroda@fogelpapp.hu, or by clicking the unsubscribe icon in the newsletter.
- Scope of data subjects concerned: partners and data subjects who subscribed to the Firm's electronic newsletter before 25 May 2018.
4.6. Camera system
Cameras operate on the premises operated by the data controller in the interest of the personal and property security of data subjects and for other purposes. Information signs draw the attention of data subjects to their operation. The activities related to the operation of the camera system are set out in the premises' "Property protection camera data processing notice", which is available at the premises.
4.7. Processing related to ensuring the operation of the information technology service
- Purpose of the processing: the websites of Fógel and Papp Law Firm may use so-called "cookies" (temporary markers) that make faster access to them possible. By "cookies" we mean an item of information that is active only for the duration of an individual client session and that is transferred from the website to the Client's computer for the purpose of faster identification. The Client may request the disabling of cookies at any time by changing their browser settings; this disabling may, however, slow down or prevent access to some parts of the site and the use of certain functions.
The session cookies used avoid the need to resort to other IT tools that are potentially harmful to the confidentiality of clients' navigation and that do not make it possible to obtain the data subject's identifying personal data.
Users can delete cookies from their own computer or disable the use of cookies in their browser. Cookies can generally be managed under the Privacy settings of the Tools/Settings menu of browsers, under the name cookie. - Legal basis of the processing: the voluntary consent of the data subject (User), Article 6(1)(a) GDPR.
The User gives their voluntary consent to the processing by accepting the pop-up notice and declaration when they begin browsing the website, or by continuing to browse.
Scope of personal data processed: information technology processing concerns the scope of data necessary for the operation of the "cookies" used to run the website and for the use of the log files applied by the web hosting provider. - Duration of the processing: until the session is closed
- Recipients of the personal data: apart from the data processor(s) indicated in point 7, the data controller does not transfer the data obtained to any third party. The recorded data may be accessed only by the employees of the Data Controller and the designated colleagues of the data processor(s).
- Scope of data subjects concerned: every User visiting the website, irrespective of their use of the services available on the website.
5. Other data processing
We provide information about data processing activities not listed in this notice at the time the data are collected. We inform our clients that certain authorities, bodies performing public duties and courts may contact our company for the purpose of disclosing personal data. Our company discloses personal data to such bodies — provided that the body concerned has indicated the precise purpose and the scope of the data — only to the extent and in the volume that is strictly necessary to achieve the purpose of the request, and only where the fulfilment of the request is prescribed by law.
6. Transfer of personal data to a third country or to an international organization
Our Firm does not transfer your personal data referred to above either to a third country or to an international organization.
7. Information on the use of data processors
During the processing, the data controller transfers the data to the data processor(s) contracted with it for the performance of the contract.
Categories of recipients: system administration service provider, accounting and payroll service provider, server hosting, web hosting provider
8. Children
Our services are not intended for persons under the age of 16, and we ask that persons under 16 do not provide personal data to the Data Controller.
If it comes to our attention that we have collected personal data from a child under the age of 16 — with the exception of the processing of data required by law — we will take the steps necessary to delete the data as soon as possible.
9. Automated decision-making
Our Firm does not apply automated decision-making in its data processing procedures or data collection.
10. The manner of storing personal data, and the security of the processing
Our company's IT systems and other data retention locations are at its registered seat and on the servers provided by the data processor. Our company selects and operates the IT tools used for processing personal data in the course of providing the service in such a way that the processed data are:
- accessible to those authorized (availability);
- authentic and their authentication is ensured (authenticity of the processing);
- verifiable as unchanged (data integrity);
- protected against unauthorized access (confidentiality of the data).
We pay particular attention to the security of the data, and we also take the technical and organizational measures and establish the procedural rules necessary to give effect to the guarantees under the GDPR. We protect the data with appropriate measures, in particular against unauthorized access, alteration, transfer, disclosure, erasure or destruction, as well as against accidental destruction or damage and against becoming inaccessible as a result of changes in the technology applied.
The IT systems and networks of our company and of our partners are equally protected against computer-assisted fraud, computer viruses, computer intrusions and denial-of-service attacks. The operator ensures security with server-level and application-level protection procedures as well. Daily backups of the data are in place. Our company takes every possible measure to avoid data protection incidents, and should such an incident occur we act without delay — in accordance with our incident management policy — to minimize the risks and remedy the damage.
11. The rights of data subjects and the available remedies
The data subject may request information about the processing of their personal data, and may request the rectification or — with the exception of mandatory processing — the erasure or withdrawal of their personal data, and may exercise their right to data portability and their right to object, in the manner indicated at the time of the data collection or through the contact details of the data controller given above.
The rights and remedies of data subjects are set out below and communicated to data subjects on the basis of Act CXII of 2011 and Regulation (EU) 2016/679.
The right to information, otherwise known as the data subject's "right of access": on the basis of Act CXII of 2011 and Article 15 of Regulation (EU) 2016/679, at the data subject's request the Data Controller provides information about
- the data it processes and the categories of personal data,
- the purpose of the processing,
- the legal basis of the processing,
- the duration of the processing,
- where applicable, the period for which the data will be stored, or if that is not possible, the criteria used to determine that period,
- where applicable, if the data were not collected from the data subject, all available information about their source,
- where applicable, automated decision-making, including profiling, and comprehensible information about the logic involved, as well as the significance of such processing, and
- the consequences it is expected to have for the data subject,
- the details of the data processor, if a data processor has been used, i. the circumstances and effects of the data protection incident and the measures taken to remedy it, and furthermore
- in the case of a transfer of the data subject's personal data, the legal basis, purpose and recipient of the transfer.
The information is free of charge if the person requesting it has not yet submitted a request for information relating to the same set of data to the Data Controller in the current year. In other cases a cost reimbursement may be set. Any cost reimbursement already paid must be refunded if the data were processed unlawfully or if the request for information led to rectification.
The Data Controller draws the attention of data subjects to the fact that information must be refused pursuant to Act CXII of 2011,
- if, on the basis of a provision of an act, an international treaty or a binding legal act of the European Union, the Data Controller receives personal data in such a way that the transferring data controller indicates, at the same time as the transfer, that the rights of the data subject guaranteed under the said act are restricted, or that the processing is otherwise restricted.
- in the interest of the external and internal security of the state, such as national defense, national security, the prevention or prosecution of criminal offenses, the security of penal enforcement, and furthermore on grounds of state or municipal economic or financial interest, a significant economic or financial interest of the European Union, as well as for the purpose of preventing and detecting disciplinary and ethical offenses related to the practice of professions and breaches of employment and occupational safety obligations — in every case including inspection and supervision — and furthermore in the interest of protecting the rights of the data subject or of others.
The Data Controller is obliged to notify the National Authority for Data Protection and Freedom of Information of rejected requests for information annually, by 31 January of the year following the year concerned.
The right to rectification: the data subject has the right to obtain from the Data Controller, at their request, the rectification without undue delay of inaccurate personal data concerning them. Taking into account the purpose of the processing, the data subject has the right to request the completion of incomplete personal data, among other things by means of a supplementary statement. At the same time, if personal data do not correspond to reality and the personal data corresponding to reality are available to the Data Controller, the Data Controller is obliged to rectify the personal data, even without a request from the data subject.
The right to erasure, otherwise known as the "right to be forgotten": the data subject has the right to obtain from the Data Controller, at their request, the erasure without undue delay of personal data concerning them, and the Data Controller is obliged to erase the personal data concerning the data subject without undue delay, provided that mandatory processing does not preclude this.
Apart from the above case, the Data Controller is obliged to erase the data pursuant to Act CXII of 2011 and Regulation (EU) 2016/679 of the European Parliament and of the Council if
- the processing of the data is unlawful;
- the data are incomplete or inaccurate — and this situation cannot lawfully be remedied — provided that erasure is not precluded by law;
- the purpose of the processing has ceased, or the statutory time limit for storing the data has expired;
- it has been ordered by a court or by the Authority.
- the personal data are no longer necessary for the purpose for which they were collected or otherwise processed;
- the data subject objects to the processing and there is no overriding lawful ground for the processing;
- the personal data must be erased in order to comply with a legal obligation under the law applicable to the Data Controller;
- the personal data were collected in relation to the offer of information society services directly to children, as referred to in Article 8(1) of Regulation (EU) 2016/679.
Where the Data Controller has for some reason made the personal data public and is obliged to erase them in accordance with the above, it takes the reasonably expected steps — including technical measures — taking into account the available technology and the cost of implementation, in order to inform other data controllers processing the data that the data subject has requested the erasure of links to, or copies or replications of, the personal data in question.
The Data Controller draws the attention of data subjects to the limits of the right to erasure or the "right to be forgotten" arising from the EU regulation, which are as follows:
- the exercise of the right to freedom of expression and information;
- compliance with an obligation under Union or Member State law applicable to the data controller which requires the processing of personal data, or the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller;
- public interest in the area of public health;
- archiving purposes in the public interest, scientific and historical research purposes or statistical purposes in accordance with Article 89(1) of Regulation (EU) 2016/679, in so far as the right to erasure is likely to render impossible or seriously impair the achievement of that processing; or
- the establishment, exercise or defense of legal claims.
The right to restriction of processing, otherwise known as the right to blocking: the data subject has the right to obtain from the Data Controller, at their request, the restriction of processing.
If, on the basis of the available information, it can be assumed that erasure would prejudice the legitimate interests of the data subject, the data must be blocked. Personal data blocked in this way may be processed only for as long as the processing purpose that precluded the erasure of the personal data continues to exist.
If the data subject disputes the accuracy or correctness of the personal data but the incorrectness or inaccuracy of the disputed personal data cannot be established unambiguously, the data are blocked. In this case the restriction applies for the period that enables the Data Controller to verify the accuracy of the personal data.
Pursuant to the EU regulation, the data must be blocked if
- the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead;
- the Data Controller no longer needs the personal data for the purposes of the processing, but the data subject requires them for the establishment, exercise or defense of legal claims; or
- the data subject has objected to the processing; in this case the restriction applies for the period until it is established whether the Data Controller's legitimate grounds override those of the data subject.
Where the processing is subject to restriction (blocking), such personal data may, with the exception of storage, be processed only with the data subject's consent, or for the establishment, exercise or defense of legal claims, or for the protection of the rights of another natural or legal person, or on grounds of important public interest of the Union or of a Member State.
The Data Controller hereby expressly draws the attention of data subjects to the fact that the data subject's right to rectification, erasure and blocking may be restricted by law in the interest of the external and internal security of the state, such as national defense, national security, the prevention or prosecution of criminal offenses, the security of penal enforcement, and furthermore on grounds of state or municipal economic or financial interest, a significant economic or financial interest of the European Union, as well as for the purpose of preventing and detecting disciplinary and ethical offenses related to the practice of professions and breaches of employment and occupational safety obligations — in every case including inspection and supervision — and furthermore in the interest of protecting the rights of the data subject or of others.
The Data Controller informs the data subject of the matters set out in their request, and/or rectifies the data, and/or erases and/or restricts (blocks) the data, or takes other steps in accordance with the request, without undue delay and within 30 days of receipt of the request at the latest, provided that there is no ground precluding this.
The Data Controller notifies the data subject in writing of the rectification, the erasure and the restriction of processing, and also notifies all those to whom the data were previously transferred or handed over for the purpose of processing. At the data subject's request, the Data Controller provides information about these recipients. The notification may be omitted if, having regard to the purpose of the processing, it does not prejudice the legitimate interests of the data subject, or if providing the information proves impossible or would require disproportionate effort. The Data Controller is also obliged to notify the data subject in writing if the exercise of the data subject's rights cannot be realized for some reason, and is obliged to indicate precisely the factual and legal grounds, as well as the remedies available to the data subject: the possibility of turning to the court and to the National Authority for Data Protection and Freedom of Information.
The "right to data portability": the data subject has the right
- to receive the personal data concerning them which they have provided to the Data Controller in a structured, commonly used, machine-readable format, and furthermore has the right
- to transmit those data to another data controller without hindrance from the data controller to which the personal data have been provided, where:
- the processing is based on consent; and
- the processing is carried out by automated means.
When exercising the right to data portability, the data subject has the right to request — where this is technically feasible — the direct transmission of the personal data between data controllers.
In view of the processing activities carried out by the Data Controller, the conditions for exercising the right to data portability are not met (there is no automated processing), and therefore the data subject cannot exercise this right.
The right to object: the data subject may object to the processing of their personal data — including profiling — if
- the processing (transfer) of the personal data is necessary solely for the enforcement of a right or legitimate interest of the Data Controller or of the recipient of the data, except in the case of mandatory processing;
- the personal data are used or transferred for the purposes of direct marketing, public opinion polling or scientific research;
- the exercise of the right to object is otherwise permitted by law.
The data subject may also object, on the basis of Article 21(3) of Regulation (EU) 2016/679, to the processing of their personal data for direct marketing purposes; in that case the personal data may no longer be processed for such purposes.
Where personal data are processed for scientific and historical research purposes or statistical purposes, the data subject has the right to object, on grounds relating to their own situation, to the processing of personal data concerning them, unless the processing is necessary for the performance of a task carried out in the public interest.
The Data Controller examines the objection — suspending the processing at the same time — within the shortest possible time from the submission of the request, but within 30 days at the latest, and informs the applicant in writing of the outcome. If the applicant's objection is well founded, the Data Controller terminates the processing — including any further data collection and data transfer — and blocks the data, and notifies of the objection and of the measures taken on its basis all those to whom it previously transferred the personal data affected by the objection and who are obliged to take action in order to give effect to the right to object.
If the data subject does not agree with the Data Controller's decision, or if the Data Controller fails to meet the time limit referred to above, they are entitled to turn to the court within 30 days of the communication of the decision.
The data subject has the right to object in relation to automated decision-making.
Enforcement before the courts: in the event of an infringement of their rights, the data subject may turn to the court. The court deals with the case as a priority. It is for the Data Controller to prove that the processing complies with the statutory requirements.
In the event of an infringement of your right to informational self-determination, you may submit a report or complaint to:
National Authority for Data Protection and Freedom of Information
Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c, Hungary
Phone: +36 (1) 391-1400, Fax: +36 (1) 391-1410
www: http://www.naih.hu
e-mail: ugyfelszolgalat@naih.hu