Privacy policy
1. Introduction
DigitalizeIT (hereinafter DigitalizeIT, the service provider, the data controller, the Company), as data controller, acknowledges the content of this legal notice as binding upon itself.
The Company undertakes that all data processing connected with its activity complies with the requirements set out in this policy and in the legislation in force.
DigitalizeIT is the operator of the digitalizeit.hu website.
DigitalizeIT reserves the right to change this notice at any time. It will of course inform its audience of any changes in good time.
DigitalizeIT is committed to protecting the personal data of its clients and partners, and considers respect for its clients' right to informational self-determination to be of the highest importance. The Controller treats personal data confidentially and takes every security, technical and organisational measure that guarantees the security of the data.
Below, DigitalizeIT sets out its data processing principles and presents the requirements it has formulated for itself as data controller and observes. Its data processing principles are in accordance with the data protection legislation in force, in particular the following:
- Act CXII of 2011 on the right to informational self-determination and freedom of information;
- Act V of 2013 on the Civil Code;
- Act XLVIII of 2008 on the basic conditions of and certain restrictions on commercial advertising activity;
- Act CVIII of 2001 on certain issues of electronic commerce services and information society services;
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter the "GDPR")
2. Definitions
- data subject: any specified natural person identified, or identifiable directly or indirectly, on the basis of personal data;
- personal data: data that can be associated with the data subject, in particular the data subject's name, identification mark and information characteristic of one or more aspects of their physical, physiological, mental, economic, cultural or social identity, as well as any inference concerning the data subject that can be drawn from it;
- consent: the voluntary and definite expression of the data subject's wish, based on appropriate information, by which they give their unambiguous agreement to the processing, in full or in respect of particular operations, of personal data concerning them;
- data controller: the natural or legal person, or organisation without legal personality, who or which alone or together with others determines the purpose of the processing of the data, makes and implements the decisions concerning the processing (including the means used), or has them implemented by a data processor;
- data processing: regardless of the procedure applied, any operation or set of operations performed on the data, in particular their collection, capture, recording, organisation, storage, alteration, use, retrieval, transfer, disclosure, alignment or combination, blocking, erasure and destruction, as well as preventing the further use of the data, the taking of photographs, audio or video recordings, and the recording of physical characteristics suitable for identifying a person (for example a finger or palm print, a DNA sample or an iris image);
- data transfer: making the data accessible to a specified third party;
- disclosure: making the data accessible to anyone;
- erasure of data: rendering the data unrecognisable in such a way that their restoration is no longer possible;
- data handling: the performance of technical tasks connected with data processing operations, irrespective of the method and means used to perform the operations and of the place of application, provided that the technical task is performed on the data;
- data processor: the natural or legal person, or organisation without legal personality, who or which processes the data on the basis of a contract, including a contract concluded pursuant to a provision of law.
3. Company details
Our company's details and contact information are as follows:
- Name: DigitalizeIT
- Tax number: 51399353-1-43
- Phone number: +36 30 842 1631
- Email: hello@digitalizeit.hu
- Representative of the data controller: Tatay Timofej Gergely, sole trader, owner
4. The scope of the personal data, and the purpose, legal basis and duration of the processing
We draw the attention of those providing data to DigitalizeIT to the fact that where they supply personal data other than their own, it is the duty of the person providing the data to obtain the consent of the data subject. The data controller is not obliged to verify that such consent exists. The data controller draws the partner's attention to the fact that if the partner fails to meet this obligation and the data subject therefore asserts a claim against the data controller, the data controller may pass the claim asserted, or the amount of the related damage, on to the partner.
We provide the following information in connection with our individual processing activities.
4.1. Quote requests and enquiries by direct contact
Those interested may contact our Company directly by electronic mail sent to the Company's address or by telephone.
- Purpose of the processing: keeping in contact, in order to advance communication between the data subject and our Company and to achieve the closest and most effective cooperation possible.
- Legal basis of the processing: legitimate interest – GDPR Article 6(1)(f)
- Scope of the personal data processed: the name of the person requesting the quote or the contact person; their email address, phone number and any other information supplied by the data subject,
- Duration of the processing: for 3 years following the period of validity of the quote, or until the data subject objects
- Recipients of the personal data: the data controller does not pass the data it has obtained to any third party, with the exception of the data processor or processors named in point 7. The recorded data may be accessed only by the Controller's employees and the designated colleagues of the data processor or processors.
- Identification of the legitimate interest: it is our Company's legitimate interest to process the data subject's data – direct marketing
- Categories of data subjects: partners and data subjects making direct enquiries (for example by email or telephone) in connection with the Company's services.
4.2. Quote requests and enquiries through the website (digitalizeit.hu)
Our company gives data subjects the opportunity to request a quote electronically.
- Purpose of the processing: keeping in contact, in order to advance communication between the data subject and our Company and to achieve the closest and most effective cooperation possible.
- Legal basis of the processing: the voluntary consent of the data subject – GDPR Article 6(1)(a).
- Scope of the personal data processed: the enquirer's name (first name, surname); their email address, phone number, company name and any other information supplied by the data subject.
- Duration of the processing: for 3 years following the period of validity of the quote, or until consent is withdrawn.
- Recipients of the personal data: the data controller does not pass the data it has obtained to any third party, with the exception of the data processor or processors named in point 7. The recorded data may be accessed only by the Controller's employees and the designated colleagues of the data processor or processors.
- Categories of data subjects: partners and data subjects making enquiries through the website in connection with the Company's services and products.
4.3. Processing connected with the follow-up of quote requests
- Purpose of the processing: it is the data controller's legitimate interest to keep a record of the data subject's data beyond the period of validity of the quote for the purpose of direct marketing
- Legal basis of the processing: the data controller's legitimate interest, GDPR Article 6(1)(f),
- Scope of the personal data processed: the contact person's surname and first name; phone number; email address
- Recipients of the personal data: the data controller does not pass the data it has obtained to any third party, with the exception of the data processor or processors named in point 7. The recorded data may be accessed only by the Controller's employees and the designated colleagues of the data processor or processors.
- Duration of the processing: until the data subject objects
- Identification of the legitimate interest: establishing business relationships with partners and those requesting quotes, and providing accurate information to data subjects. It is our Company's legitimate interest to process the data subject's data – direct marketing
- Categories of data subjects: the addressees of quotes previously issued by the Company and the contact persons named in them.
4.4. Newsletter registration
- Purpose of the processing: sending email newsletters that also contain commercial advertising to those interested, and providing information on current matters
- Legal basis of the processing: the data subject's prior, voluntary consent, GDPR Article 6(1)(a),
- Scope of the personal data processed: name, email address
- Duration of the processing: until the voluntary consent is withdrawn or the data subject unsubscribes from the newsletter. Our Company processes the data supplied by the data subject until consent is withdrawn. On the basis of the withdrawal of consent we erase the processed data from our newsletter database within 7 days at the latest, and thereafter send you no further newsletters.
- Recipients of the personal data: the data controller does not pass the data it has obtained to any third party, with the exception of the data processor or processors named in point 7. The recorded data may be accessed only by the Controller's employees and the designated colleagues of the data processor or processors. You may unsubscribe from the newsletter at any time by a message sent to our Company at hello@digitalizeit.hu, or by clicking the unsubscribe icon in the newsletter.
- Categories of data subjects: partners and data subjects who have subscribed to the Company's electronic newsletter.
4.5. Newsletter data (for newsletter registrations made before 25 May 2018)
- Purpose of the processing: sending email newsletters that also contain commercial advertising to those interested, and providing information on current matters
- Legal basis of the processing: the data controller's legitimate interest, GDPR Article 6(1)(f),
- Scope of the personal data processed: name, email address
- Duration of the processing: until the data subject objects
- Identification of the legitimate interest: providing information, including commercial advertising and business offers, to data subjects who have subscribed to the newsletter. It is our Company's legitimate interest to process the data subject's data, direct marketing.
- Recipients of the personal data: the data controller does not pass the data it has obtained to any third party, with the exception of the data processor or processors named in point 7. The recorded data may be accessed only by the Controller's employees and the designated colleagues of the data processor or processors. You may unsubscribe from the newsletter at any time by a message sent to our Company at hello@digitalizeit.hu, or by clicking the unsubscribe icon in the newsletter.
- Categories of data subjects: partners and data subjects who subscribed to the Company's electronic newsletter before 25 May 2018.
4.6. Camera system
Cameras operate within the area of the premises operated by the data controller, for the personal and property security of data subjects and for other purposes. Notices draw data subjects' attention to their operation. The activities connected with the operation of the camera system are set out in the premises' "Property protection camera data processing notice", which is available at the premises.
4.7. Processing connected with ensuring the operation of the information technology service
- Purpose of the processing: DigitalizeIT's websites may use so-called "cookies" (temporary markers) which allow faster access to them. By "cookies" we mean an item of information that is active only for the duration of the individual client session and which is passed from the website to the Client's computer for the purpose of faster identification. The Client may at any time request that cookies be switched off by changing their browser settings; switching them off may, however, slow down or prevent access to some parts of the site and the use of certain functions.
The session cookies used avoid the need to resort to other information technology means that are potentially harmful to the confidentiality of clients' navigation and do not permit the acquisition of identifying personal data.
The user is able to delete cookies from their own computer and to disable the use of cookies in their browser. Cookies can generally be managed in the browser's Tools/Settings menu under the Privacy settings, under the heading cookies. - Legal basis of the processing: the voluntary consent of the data subject (User), GDPR Article 6(1)(a).
The User gives voluntary consent to the processing by accepting the notice and declaration that appears on beginning to browse the website, or by continuing to browse.
Scope of the personal data processed: the information technology processing concerns the scope of data necessary for the operation of the "cookies" used to run the website and for the use of the log files applied by the web hosting provider. - Duration of the processing: until the session is closed
- Recipients of the personal data: the data controller does not pass the data it has obtained to any third party, with the exception of the data processor or processors named in point 7. The recorded data may be accessed only by the Controller's employees and the designated colleagues of the data processor or processors.
- Categories of data subjects: every User visiting the website, regardless of whether they use the services available on it.
5. Other processing
We provide information about processing activities not listed in this notice at the time the data are collected. We inform our clients that certain authorities, bodies performing public duties and courts may contact our company for the purpose of the disclosure of personal data. Our company discloses personal data to such bodies – where the body concerned has specified the exact purpose and the scope of the data – only to the extent and in the quantity strictly necessary to achieve the purpose of the request, and only where the fulfilment of the request is prescribed by law.
6. Transfer of personal data to a third country or an international organisation
Our Company does not transfer the above personal data of yours either to a third country or to an international organisation.
7. Information on the use of data processors
In the course of the processing, the data controller transfers the data to the data processor or processors contracted for the performance of the contract.
Categories of recipients: system administration provider, bookkeeping and payroll provider, server hosting, web hosting provider
8. Children
Our services are not intended for persons under the age of 16, and we ask that persons under 16 do not provide Personal data to the Controller.
If it comes to our attention that we have collected personal data from a child under 16 – with the exception of the processing of data prescribed by law – we will take the steps necessary to erase the data as soon as possible.
9. Automated decision-making
Our Company does not apply automated decision-making in its data processing procedures or data collection.
10. The manner of storage of personal data and the security of the processing
Our company's information technology systems and other data retention locations are at its registered office and on the servers provided by the data processor. Our company selects and operates the information technology means used for the processing of personal data in the course of providing the service in such a way that the processed data are:
- accessible to those authorised (availability);
- authentic and their authentication assured (authenticity of the processing);
- demonstrably unaltered (data integrity);
- protected against unauthorised access (confidentiality of the data).
We pay particular attention to the security of the data, and we further take the technical and organisational measures and establish the procedural rules necessary to give effect to the guarantees set out in the GDPR. We protect the data with appropriate measures, in particular against unauthorised access, alteration, transfer, disclosure, erasure or destruction, as well as against accidental destruction and damage, and against becoming inaccessible as a result of changes in the technology applied.
The information technology systems and networks of our company and of our partners are protected against computer-assisted fraud, computer viruses, computer intrusions and denial-of-service attacks. The operator provides for security by means of server-level and application-level protection procedures as well. Daily backup of the data is in place. Our company takes every possible measure to avoid data protection incidents, and in the event of such an incident we act without delay – in accordance with our incident management policy – to minimise the risks and avert the damage.
11. The rights of data subjects and remedies available
The data subject may request information about the processing of their personal data, and may request the rectification or – with the exception of mandatory processing – the erasure or withdrawal of their personal data, and may exercise their right to data portability and their right to object in the manner indicated at the time the data were collected or at the data controller's contact details above.
The data subject's rights and the remedies available to them are set out below and communicated to data subjects on the basis of Act CXII of 2011 and Regulation (EU) 2016/679.
The right to information, otherwise known as the data subject's "right of access": on the basis of Act CXII of 2011 and Article 15 of Regulation (EU) 2016/679, at the data subject's request the Controller provides information about
- the data it processes and the categories of personal data,
- the purpose of the processing,
- the legal basis of the processing,
- the duration of the processing,
- where applicable, the period for which the data are stored or, where that is not possible, the criteria used to determine that period,
- where applicable, if the data were not collected from the data subject, all available information as to their source,
- where applicable, automated decision-making, including profiling, and intelligible information about the logic involved and about the significance of such processing, and
- the consequences it is expected to have for the data subject,
- the details of the data processor, if one has been used, and about the circumstances and effects of a data protection incident and the measures taken to address it, and further
- in the event of a transfer of the data subject's personal data, the legal basis, the purpose and the recipient of the transfer.
The provision of information is free of charge if the person requesting it has not yet submitted a request for information relating to the same scope of data to the Controller in the current year. In other cases a fee may be charged to cover costs. A fee already paid must be refunded if the data were processed unlawfully or if the request for information led to a rectification.
The Controller draws data subjects' attention to the fact that the provision of information must be refused, on the basis of Act CXII of 2011,
- where, on the basis of a law, an international treaty or a provision of a binding legal act of the European Union, the Controller receives personal data in such a way that the transferring controller indicates, at the same time as the transfer, a restriction of the rights guaranteed to the data subject of the personal data by the said law, or another restriction on its processing.
- in the interests of the external and internal security of the state, including national defence, national security, the prevention or prosecution of criminal offences and the security of the enforcement of penalties, and further for state or municipal economic or financial reasons, for a significant economic or financial interest of the European Union, and for the purpose of preventing and uncovering disciplinary and ethical breaches connected with the practice of professions and breaches of employment law and occupational safety obligations – including in every case inspection and supervision – and further in the interests of protecting the rights of the data subject or of others.
The Controller is obliged to notify the Hungarian National Authority for Data Protection and Freedom of Information of refused requests for information annually, by 31 January of the year following the year in question.
The right to rectification: the data subject has the right to obtain from the Controller, without undue delay, the rectification of inaccurate personal data concerning them. Taking into account the purpose of the processing, the data subject has the right to request that incomplete personal data be completed, among other things by means of a supplementary statement. At the same time, if the personal data do not correspond to reality and personal data corresponding to reality are available to the Controller, the Controller is obliged to rectify the personal data, even without a request from the data subject.
The right to erasure, otherwise known as the "right to be forgotten": the data subject has the right to obtain from the Controller, at their request and without undue delay, the erasure of personal data concerning them, and the Controller is obliged to erase personal data concerning the data subject without undue delay, unless mandatory processing precludes it.
Apart from the above case, the Controller is obliged to erase the data on the basis of Act CXII of 2011 and Regulation (EU) 2016/679 of the European Parliament and of the Council where
- the processing of the data is unlawful;
- the data are incomplete or erroneous and this state of affairs cannot lawfully be remedied, provided that erasure is not precluded by law;
- the purpose of the processing has ceased, or the period prescribed by law for the storage of the data has expired;
- it has been ordered by a court or by the Authority;
- the personal data are no longer necessary for the purpose for which they were collected or otherwise processed;
- the data subject objects to the processing and there is no overriding lawful ground for the processing;
- the personal data have to be erased in order to comply with a legal obligation under the law applicable to the Controller;
- the personal data were collected in relation to the offer of information society services directly to children, as referred to in Article 8(1) of Regulation (EU) 2016/679.
Where the Controller has for some reason made the personal data public and is obliged to erase them in accordance with the above, it will, taking account of the available technology and the cost of implementation, take the reasonably expected steps – including technical measures – to inform other controllers processing the data that the data subject has requested the erasure of links to, or copies or replications of, the personal data in question.
The Controller draws data subjects' attention to the limits on the right to erasure or the "right to be forgotten" arising from the EU regulation, which are as follows:
- the exercise of the right to freedom of expression and information;
- compliance with an obligation under Union or Member State law applicable to the controller which requires the processing of personal data, or the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- reasons of public interest in the area of public health;
- archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) of Regulation (EU) 2016/679, in so far as the right to erasure is likely to render impossible or seriously impair that processing; or
- the establishment, exercise or defence of legal claims.
The right to restriction of processing, otherwise known as the right to blocking: the data subject has the right to obtain from the Controller, at their request, restriction of the processing.
If, on the basis of the information available, it may be assumed that erasure would harm the data subject's legitimate interests, the data must be blocked. Personal data blocked in this way may be processed only for as long as the processing purpose which precluded the erasure of the personal data persists.
If the data subject disputes the accuracy or correctness of the personal data, but the incorrectness or inaccuracy of the disputed personal data cannot be established unambiguously, the data are blocked. In this case the restriction applies for the period that enables the Controller to verify the accuracy of the personal data.
Under the EU regulation the data must be blocked where
- the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead;
- the Controller no longer needs the personal data for the purposes of the processing, but the data subject requires them for the establishment, exercise or defence of legal claims; or
- the data subject has objected to the processing; in this case the restriction applies for the period until it is established whether the Controller's legitimate grounds override those of the data subject.
Where the processing is subject to restriction (blocking), such personal data may, apart from storage, be processed only with the data subject's consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State.
The Controller hereby particularly draws data subjects' attention to the fact that the data subject's right to rectification, erasure and blocking may be restricted by law in the interests of the external and internal security of the state, including national defence, national security, the prevention or prosecution of criminal offences and the security of the enforcement of penalties, and further for state or municipal economic or financial reasons, for a significant economic or financial interest of the European Union, and for the purpose of preventing and uncovering disciplinary and ethical breaches connected with the practice of professions and breaches of employment law and occupational safety obligations – including in every case inspection and supervision – and further in the interests of protecting the rights of the data subject or of others.
The Controller informs the data subject of the matters set out in their request, and/or rectifies the data, and/or erases and/or restricts (blocks) the data, or takes other steps in accordance with the request where there is no ground precluding it, without undue delay and at the latest within 30 days of receipt of the request.
The Controller notifies the data subject in writing of the rectification, the erasure and the restriction of the processing, and also all those to whom the data were previously transferred or handed over for the purposes of processing. At the data subject's request the Controller informs them of these recipients. Notification may be omitted where, having regard to the purpose of the processing, this does not harm the data subject's legitimate interest, or where providing the information proves impossible or would require disproportionate effort. The Controller is also obliged to notify the data subject in writing where the exercise of the data subject's rights cannot be given effect for some reason, and is obliged to state precisely the factual and legal grounds and the remedies available to the data subject: the possibility of applying to a court and to the Hungarian National Authority for Data Protection and Freedom of Information.
The "right to data portability": the data subject has the right
- to receive the personal data concerning them which they have provided to the Controller in a structured, commonly used, machine-readable format, and further has the right
- to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where:
- the processing is based on consent; and
- the processing is carried out by automated means.
In exercising the right to data portability the data subject has the right to request – where this is technically feasible – the direct transmission of the personal data between controllers.
Having regard to the processing carried out by the Controller, the conditions for exercising the right to data portability are not met (there is no automated processing), and therefore the data subject cannot exercise this right.
The right to object: the data subject may object to the processing of their personal data, including profiling, where
- the processing (transfer) of the personal data is necessary solely for the enforcement of a right or legitimate interest of the Controller or of the recipient of the data, except in the case of mandatory processing;
- the personal data are used or transferred for the purposes of direct marketing, opinion polling or scientific research;
- the exercise of the right to object is otherwise permitted by law.
The data subject may also object, on the basis of Article 21(3) of Regulation (EU) 2016/679, to the processing of personal data for the purposes of direct marketing, in which case the personal data may no longer be processed for that purpose.
Where personal data are processed for scientific or historical research purposes or statistical purposes, the data subject has the right, on grounds relating to their own situation, to object to the processing of personal data concerning them, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
The Controller – suspending the processing at the same time – examines the objection within the shortest possible time from the submission of the request, and at most within 30 days, and informs the applicant in writing of the outcome. If the applicant's objection is well founded, the Controller ceases the processing, including any further collection and transfer of data, and blocks the data, and notifies of the objection and of the measures taken on the basis of it all those to whom the personal data affected by the objection were previously transferred and who are obliged to act in order to give effect to the right to object.
If the data subject does not agree with the Controller's decision, or if the Controller fails to meet the said deadline, they are entitled – within 30 days of its communication – to apply to a court.
The data subject has the right to object in connection with automated decision-making.
Judicial enforcement: in the event of an infringement of their rights, the data subject may apply to a court. The court deals with the case as a matter of priority. It is for the Controller to prove that the processing complies with the provisions of law.
In the event of an infringement of your right to informational self-determination you may submit a report or complaint to:
Hungarian National Authority for Data Protection and Freedom of Information
Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
Phone: +36 (1) 391-1400, Fax: +36 (1) 391-1410
www: http://www.naih.hu
email: ugyfelszolgalat@naih.hu