1.) Use of the website
General information
This Privacy Notice — hereinafter: the “Notice” — concerns the processing of personal data provided to www.grsvnr.hu — hereinafter: the “Data Controller”.
By this statement, the Data Controller informs Visitors who come into contact with it about its data processing practices, the measures taken to protect the personal data obtained by it, and the legal remedies available to Visitors.
Applicable law
The Data Controller processes the data of Visitors primarily on the basis of Act CXII of 2011 on Informational Self-Determination and Freedom of Information — hereinafter: the “Info Act” — and Regulation (EU) 2016/679 of the European Union, the General Data Protection Regulation — GDPR.
The text of the Info Act is available here:
https://net.jogtar.hu/jogszabaly?docid=A1100112.TV
The text of the Regulation is available here:
http://eur-lex.europa.eu/legal-content/HU/TXT/HTML/?uri=CELEX:32016R0679&from=EN
Purpose of the Privacy Notice
The purpose of this Notice is to ensure that Visitors receive appropriate information about their rights and obligations related to the processing of their personal data.
On the basis of this Notice, Visitors may become familiar with the circumstances of the processing of their personal data, allowing them to make an informed decision about providing their data.
This Notice is based on Section 20(2) of the Info Act, according to which the data subject must be clearly and thoroughly informed, prior to the commencement of data processing, about all facts relating to the processing of their data, in particular the purpose and legal basis of the data processing, the person entitled to carry out data processing and data processing operations, the duration of data processing, whether the personal data of the data subject is processed by the Data Controller pursuant to the provisions of the GDPR and Section 6(5) of the Info Act, and who may access the data.
Identification and contact details of the Data Controller
Name: Grosvenor Associates Kft.
Registered office: 1097 Budapest, Gubacsi út 30.
Tax number: 32354841-2-43
Company registration number: 01 09 422113
Representative: Catalin-Constantin Naidin
Data protection contact of the Data Controller:
+36 70 607 2721
Definitions used in this Notice
The definitions applicable to this Notice are set out in Article 4 of the Regulation. Accordingly, the main terms are as follows:
“Personal data” means any information relating to an identified or identifiable natural person — “data subject”. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, number, location data, online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
“Data processing” means any operation or set of operations performed on personal data or data files, whether by automated or non-automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
“Restriction of processing” means the marking of stored personal data with the aim of limiting their processing in the future.
“Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements.
“Data controller” means the natural or legal person, public authority, agency, or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
“Data processor” means the natural or legal person, public authority, agency, or any other body which processes personal data on behalf of the data controller.
“Recipient” means a natural or legal person, public authority, agency, or any other body to whom or to which personal data are disclosed, whether or not a third party. Public authorities that may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of such data by those public authorities must comply with the applicable data protection rules according to the purposes of the processing.
“Third party” means a natural or legal person, public authority, agency, or any other body other than the data subject, the data controller, the data processor, or persons who, under the direct authority of the data controller or data processor, are authorised to process personal data.
“Consent of the data subject” means any freely given, specific, informed, and unambiguous indication of the data subject’s wishes, by which the data subject, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to them.
“Personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data transmitted, stored, or otherwise processed.
Persons affected by the data processing
Website browsers: persons who visit and obtain information from the website www.grsvnr.hu.
Name of the data processing
Improving the user experience for visitors to the website.
Purpose
To support the efficient operation of the website, improve the user experience, and increase the security of website visitors.
Legal basis of data processing
Section 13/A(3) of Act CVIII of 2001 on certain issues of electronic commerce services and information society services.
Method of giving consent
Persons visiting the website are affected solely by data processing arising from the operation of the cookies used by the website. They consent to such processing by accepting the pop-up notice appearing when they start browsing the website or by continuing to browse the website.
Scope of processed data
Date, time, IP address of the user’s computer, address of the visited page, address of the previously visited page, and data relating to the user’s operating system and browser.
Duration of data processing
30 days from the viewing of the website.
Persons entitled to access the data
The Data Controller.
2.) Notice on the use of “cookies”
What are cookies?
Cookies are small text files that store data and may be placed on your browser device — for example, computer, smartphone, or tablet — when websites are opened.
A cookie usually contains the name of the domain from which it originates, its lifetime — how long it remains on your device — and the stored data. You can find more detailed information about cookies on the following website:
http://www.allaboutcookies.org
The website uses cookies in order to distinguish you from other visitors, thereby allowing us to provide you with a better and more personalised user experience.
Cookies are not harmful to your browser device. Cookies themselves do not contain information that personally identifies you.
What categories of cookies may we use?
Essential cookies:
Without these, certain services of the website cannot function properly.
Functional cookies:
These allow the website to remember certain previously set data.
Performance monitoring cookies:
These collect information about how visitors use the website. These cookies are used for statistical purposes in order to improve and maintain the user experience.
Third-party cookies:
On our website, we may also use some popular external web services, such as Google Analytics or Google Search Console, which may result in the storage of cookies that are not controlled by us. These services have their own privacy and cookie policies:
https://support.google.com/analytics/answer/9019185?hl=hu#zippy=%2Ca-cikk-tartalma
https://policies.google.com/privacy?hl=hu
Managing cookies
Most browsers accept cookies by default. You can configure your browser to notify you whenever a cookie is received, or to block all cookies. This can be done through your browser settings, where you can find further information in your browser’s help section.
You can also read more detailed information about cookies when first entering the site by pressing the “details” button in the pop-up window.
On the website, the Data Controller uses only session cookies, which, among other things, make it possible to remember the actions performed by the visitor on a given page, function, or service during a visit.
The validity period of these cookies applies only to the current visit. At the end of the session, or when the browser is closed, this type of cookie is automatically deleted from the computer.
The website does not use behavioural cookies, that is, cookies suitable for profiling the website browser or identifying their browsing habits.
The cookies used do not contain personal data that would enable anyone to contact the Visitor by email, telephone, or traditional postal mail.
Cookies themselves are not capable of identifying the person browsing the website; they are only capable of identifying the visitor’s computer.
The data recorded by cookies may be accessed by the employees of the Data Controller in order to ensure the purposes detailed in this section.
The recorded data may only be transmitted in cases, for purposes, and to persons authorised by law — typically for law enforcement or national security purposes.
Anonymised data relating to the use of the website may be used for statistical purposes.
If the person browsing the website does not wish to accept the use of cookies on the website, they may configure the web browser they use so that the program informs them of the placement of cookies, or prevents the placement of cookies.
These settings are usually available in the browser’s “settings” or “preferences” menu.
The website also contains links from external servers that are independent of the website and point to external servers. Due to the direct connection to their own servers, the provider of such links may be able to collect customer data. The Data Controller has no influence over such data collection and therefore assumes no responsibility for it.
3.) Rights of the Visitor in relation to data processing
Information
The Visitor may request the Data Controller to provide information about the processing of their personal data.
The Data Controller is obliged to provide the processed personal data in writing, in an intelligible form, upon the request of the data subject, within the shortest possible time from the submission of the request, but no later than within 30 days.
The Visitor may send their request for information to the Data Controller in writing by post or by email.
In the request, the Visitor is obliged to provide identification data on the basis of which the Data Controller can determine their entitlement to access the personal data.
The Visitor is also obliged to indicate in the request an electronic or postal contact address to which the Data Controller can provide the information.
The Visitor may request information about the scope of the personal data processed, the source of the personal data, the purpose of processing the personal data, the legal basis on which the Data Controller processes the personal data, the duration of processing, and the Data Controller’s activities related to the processing of personal data.
If a personal data breach occurs during data processing, the Visitor may also request information about the circumstances and effects of the breach and the measures taken by the Data Controller to remedy it.
A personal data breach means that the processing or handling of personal data is carried out in violation of the law. Such cases include, in particular, unauthorised access to personal data, unlawful alteration, transmission, or disclosure of personal data, or unlawful deletion or destruction of personal data.
A personal data breach also occurs if personal data is destroyed or damaged as a result of an accidental event.
The Data Controller provides the information to the Visitor by email.
If the Customer submitting the request has not indicated an electronic contact address in the request, or expressly requests postal delivery, the Data Controller shall provide the information in writing by post.
The Data Controller provides the information free of charge once a year in respect of the scope of personal data specified in the request. Thereafter, the provision of the information may involve a fee on each occasion, proportionate to the costs incurred. The Data Controller shall inform the person requesting the data of the amount of such costs before fulfilling the request.
If the Data Controller refuses to provide the information pursuant to this section, it shall also notify the Visitor in writing of the reason for refusing the information, specifying the exact legal basis for the refusal.
In this case, the Data Controller shall also inform the Customer of the possibility of judicial remedy and of turning to the Authority — see the section on legal remedies below.
Erasure of data — right to be forgotten
The Visitor may request at any time the termination of data processing and that the Data Controller delete or block their personal data.
In this case, the Visitor acknowledges the possible consequences of the termination of the Data Controller’s right to process the data.
The Visitor may request at any time that the Data Controller delete their personal data.
The request for erasure or blocking may be sent by the Visitor to the Data Controller in writing by post or by email.
The Data Controller shall delete personal data if:
- it has been processed unlawfully;
- the Visitor requests the deletion or blocking of their personal data;
- the data processing is incomplete or inaccurate, and this situation cannot lawfully be remedied, provided that deletion is not excluded by law;
- the purpose of the data processing has ceased to exist, or the statutory retention period for the data has expired;
- deletion has been ordered by a court or the Authority.
If the Data Controller does not comply with the Visitor’s request for erasure, it shall communicate the reasons for the refusal in writing, or electronically with the Visitor’s consent, within 25 days of receipt of the request, indicating the legal basis for the refusal.
In this case, the Data Controller shall also inform the Customer of the possibility of judicial remedy and of turning to the Authority.
Objection to the processing of personal data
The Visitor has the right to object to the processing of their personal data in the following cases:
- if the processing of personal data is necessary solely for the fulfilment of a legal obligation applicable to the Data Controller, or for the enforcement of the legitimate interest of the Data Controller or a third party;
- if the purpose of processing personal data is direct marketing, public opinion polling, or scientific research;
- if the law grants the Visitor the opportunity to do so.
The objection may be sent by the Visitor to the Data Controller in writing by post or by email.
The Data Controller shall examine the objection within no more than 15 days from its submission and decide whether it is justified.
The Data Controller shall inform the Visitor of its decision in writing.
If the Visitor’s objection is justified, the Data Controller shall terminate the data processing and data transmission, block the personal data, and notify all persons to whom the Customer’s personal data affected by the objection had previously been transmitted of the objection and the measures taken on its basis, and who are obliged to take action to enforce the right of objection.
Right to data portability
The Visitor has the right to receive the personal data provided to the Data Controller in a structured and readable format, and, in certain cases, to transmit such data to another data controller without hindrance.
Right to transparent information
The Visitor is entitled to appropriate basic and free information about the circumstances of data processing and the rights available to the Customer.
Right of access
The Visitor has the right to request a copy of the personal data processed about them.
Restriction of data processing
The Visitor may request the restriction of data processing. In this case, their personal data may only be stored, and any other data processing may only take place with the consent of the data subject, for the purpose of asserting legal claims, or in the public interest.
4.) Handling of personal data breaches
Definition of a personal data breach
Personal data breach:
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data transmitted, stored, or otherwise processed.
Regulation, Article 4(12).
The most commonly reported incidents may include, for example, the loss of a laptop or mobile phone, insecure storage of personal data, insecure transmission of data, server attacks, or website hacking.
XIV.2. Handling and remedying personal data breaches
The prevention and handling of personal data breaches, as well as compliance with the relevant legal requirements, is the responsibility of the website operator.
Accesses and attempted accesses to IT systems must be logged and continuously analysed.
A personal data breach may be reported via the email address provided on the website.
In the event of a personal data breach report, the report must be examined without delay. During this process, the breach must be identified, and it must be determined whether it is a genuine incident or a false alarm.
The following must be examined and established:
- the time and place of the incident;
- the description, circumstances, and effects of the incident;
- the scope and quantity of the data compromised during the incident;
- the group of persons affected by the compromised data;
- a description of the measures taken to remedy the incident;
- a description of the measures taken to prevent, remedy, or reduce the damage.
In the event of a personal data breach, the affected systems, persons, and data must be identified and isolated, and evidence supporting the occurrence of the incident must be collected and preserved.
Only after this may the restoration of damages and the re-establishment of lawful operation begin.
Register of personal data breaches
A register must be kept of personal data breaches, containing:
- the scope of the personal data affected;
- the group and number of persons affected by the personal data breach;
- the time of the personal data breach;
- the circumstances and effects of the personal data breach;
- the measures taken to remedy the personal data breach;
- any other data specified by the legislation prescribing the data processing.
Data relating to personal data breaches recorded in the register must be retained for 5 years.
Data security measures
The Data Controller shall take all generally expected measures to ensure that, during the operation of its IT system, personal data cannot be accessed by unauthorised third parties.
The data is protected in particular against unauthorised access, alteration, transmission, disclosure, deletion or destruction, accidental destruction and damage, and against becoming inaccessible due to changes in the technology used.
5.) Legal remedies available to the Visitor
If the Visitor does not agree with the decisions of the Data Controller, or if the Data Controller fails to meet the 15-day deadline available for assessing the Visitor’s objection, the Visitor may seek legal remedy before the court within 30 days from the communication of the decision or from the last day of the deadline.
The Visitor may seek legal remedy before the National Authority for Data Protection and Freedom of Information in the event of a violation of their rights relating to the processing of personal data.
If the Authority does not take action, or if the Visitor does not agree with the decision, the Visitor may bring an action before the Regional Court competent according to the registered office of the Data Controller or the Authority.
The Visitor may also initiate court proceedings against the Data Controller before the Regional Court competent according to the Visitor’s place of residence or place of stay.
The Visitor may contact the National Authority for Data Protection and Freedom of Information at the following contact details:
Address: 1055 Budapest, Falk Miksa utca 9-11.
Postal address: 1374 Budapest, P.O. Box 603
Telephone: +36 (1) 391-1400
Fax: +36 (1) 391-1410
Email: ugyfelszolgalat@naih.hu
Website: www.naih.hu
The Visitor is entitled to consent to data processing by the Data Controller only if they have become familiar with the above privacy and data processing provisions and are aware of their rights and obligations related to the processing of their personal data.