Privacy Policy

Dear Partner,

On 25 May 2018, the European Parliament and the Council brought into force the General Data Protection Regulation (GDPR), which regulates the “protection of natural persons with regard to the processing of personal data and the free movement of such data”. In view of this, we hereby inform you about the data processed by Gafém Kft. (registered office: 4145 Csökmő, Alkotmány utca 15.; hereinafter: the “Controller”).

The protection of our Partners’ personal data is of particular importance to us, especially the respect of our Partners’ right to informational self-determination. Therefore, our Company, as the Controller, processes the personal data of Partners with whom we have a contractual relationship in accordance with the GDPR referred to above, Act CXII of 2011 on Informational Self-Determination and Freedom of Information (“Info Act”), and other applicable laws, as detailed in this Privacy Notice, from the submission of quotations by the Partner or the initiation of quotation requests by our Company, and following the conclusion of any contract between the Controller and the Partner relating to the performance of any activity, including but not limited to works contracts, agency contracts, delivery contracts, sales contracts or other agreements.

We inform you that we only record the amount of data necessary and use it solely for the purpose for which you have provided the data to us.

  1. Details of the Controller

Name of the Controller: Gafém Kft. (hereinafter: the “Controller”)
Registered office: 4145 Csökmő, Alkotmány utca 15.
Tax number: 14874831-2-09
Email: gafem@gafem.hu
Telephone: +36 54 400 854
Website: www.gafem.hu

  1. Purpose of this Notice

This Notice contains detailed information on the rules relating to the processing and protection of personal data concerning the contact persons, representatives and employees of the Controller’s contractual partners (hereinafter: “Data Subjects”).

The Controller ensures that personal data is processed in a manner that guarantees the appropriate security of personal data and complies with the applicable national legislation (“Info Act”) and European Union law (GDPR).

  1. Scope of Processed Data, Purpose, Legal Basis and Retention Period of Processing

We process personal data if:

a) the Data Subject has given consent to the processing voluntarily; or

b) processing is required by law or, based on statutory authorization, by a local government decree for a purpose based on public interest.

In the table below, we have summarized our information regarding the scope of the processed data, the purpose of processing, the legal basis and the retention period. We draw the attention of data providers to the fact that if they provide personal data that is not their own, it is the responsibility of the data provider to obtain the consent of the Data Subject concerned.

In the case of data processed during the preparation of the conclusion of a contract, the duration of data processing corresponds to the period during which a claim may be enforced in connection with the failure to conclude the contract. Unless otherwise provided by law, this period is 5 years. This is a limitation period, meaning that, in the cases specified in Act V of 2013 on the Civil Code, the limitation period may be interrupted, in which case the limitation period starts again from the interruption or from the final conclusion of the procedure interrupting the limitation period. Furthermore, if the entitled party is unable to enforce their claim for an excusable reason, the limitation period is suspended, in which case the claim may still be enforced within one year from the cessation of the obstacle, even if the limitation period has already expired or less than one year remains from it.

The Controller is entitled to record the Partner’s personal data and make it accessible to its employees after providing a quotation to the Partner or after the Partner has submitted a quotation to the Controller. The Partner may object to processing where the processing is based on the legitimate interest of the Controller.

For property protection, personal security and safety reasons and purposes, the Controller makes video recordings at its registered office and premises. Signs drawing the attention of Partners to this, such as notices, pictograms and stickers, can be found at the entrance or next to the cameras.

The Controller processes the recordings for the protection of personal data, the protection of persons and property, and on the basis of its legitimate interest related to protecting these interests. During processing, the retention period for video recordings recorded at the registered office and premises is 30 calendar days from the date the data is created.

No automated decision-making, including profiling, takes place during the processing of personal data.

Data stored in other paper-based documents is retained by the Controller after the expiry of the data retention period until the disposal procedure is carried out in accordance with the document management rules.

In relation to personal data stored in other paper-based documents whose retention period has already expired, the legal basis for further processing is the Controller’s legitimate interest in preserving the integrity and evidentiary value of paper-based documents. This takes into account the circumstance that deleting the data stored in paper-based documents individually would require a disproportionate increase in cost and effort compared to the Partners’ rights related to the protection of personal data. Therefore, the Controller ensures the storage of such data through appropriate data security measures and restricts access to them.

The Controller’s website uses cookies, which are small data files placed on the Data Subject’s computer through the use of the website. These are downloaded and stored by the Data Subject’s internet browser. Most commonly used internet browsers, such as Chrome and Firefox, accept and allow the downloading and use of cookies by default. However, it is up to the Data Subject to reject or disable these cookies by modifying the browser settings, or to delete cookies already stored on their computer.

Further information on the use of cookies is available in the “Help” menu of each browser.

The Controller does not use or allow cookies on its website that would enable third parties to collect data without the Data Subject’s consent.

The IT systems and other data storage locations of the website are located at the Controller’s registered office. The Controller ensures the protection of data processing security through technical, organizational and structural measures that provide a level of protection appropriate to the risks arising in connection with data processing.

The Controller’s IT system and network are protected against computer-assisted fraud, espionage, sabotage, vandalism, fire and flood, as well as against computer viruses, computer intrusions and denial-of-service attacks. The operator ensures security through server-level and application-level protection procedures.

This Notice also applies to the personal data of natural persons, i.e. Data Subjects, who are in a legal relationship with the Partner and whose personal data is disclosed by the Partner to the Controller during the preparation and performance of contracts and documents.

  1. Recipients of Personal Data

The employees of the Controller may access the processed data, in addition to the cases specified by law, for the purposes of concluding, performing and terminating contracts, enforcing claims and making contact.

The Controller ensures that only those persons may access such data who are authorized to know and use them. The Controller guarantees that all employees and other assistants who must access or may otherwise access data, information or documents in the course of performing their employment or contractual obligations will adequately ensure data protection and implement the protective and security measures necessary for data protection.

The Controller does not transfer the processed data to third parties, nor to any third country outside the Member States of the European Union or to any international organization.

  1. Data Processor

The Controller is responsible for the lawfulness of the instructions relating to the data processing operations and for the lawfulness of their implementation.

Data processors are responsible for complying with the lawful instructions of the Controller, as well as with the obligations expressly imposed on data processors under the GDPR.

  1. Rights of Data Subjects

The rights relating to the Controller’s data processing, including legal remedies, are governed by the provisions of the GDPR and the Info Act.

In connection with data processing, the natural person is entitled to:

  • request information about the processing;
  • access their personal data and request a copy of the recorded data;
  • request rectification;
  • request restriction of processing;
  • request erasure;
  • request the release and transfer of data in a portable format;
  • object to the processing of their personal data;
  • lodge a complaint with the supervisory authority.

The Controller is obliged to comply with these rights in the manner and within the deadlines specified in data protection legislation and the GDPR.

The Controller shall delete personal data if its processing is unlawful, if the Data Subject requests it, if the purpose of processing has ceased, if the statutory retention period for storing the data has expired, or if deletion has been ordered by a court or by the Hungarian National Authority for Data Protection and Freedom of Information.

The Controller shall notify the Data Subject of the rectification or deletion of personal data, as well as all those to whom the data was previously transferred for processing purposes. Notification may be omitted if this does not infringe the legitimate interest of the Data Subject, taking into account the purpose of processing.

If the Data Subject does not agree with the decision made by the Controller, the Data Subject may turn to court within 30 days of the communication of the decision.

The Controller may not delete the Data Subject’s data if processing has been ordered by law. However, the data may not be transferred to the data recipient if the Controller has agreed with the objection or if the court has established that the objection is justified.

In the event of a violation of their rights, the Data Subject may bring proceedings against the Controller before a court. The court shall act in such matters with priority.

The Controller shall compensate any damage caused to others by the unlawful processing of the Data Subject’s data or by violating the requirements of technical data protection. The Controller shall be exempt from liability if the damage was caused by an unavoidable event outside the scope of data processing. The Controller shall not compensate the damage to the extent that it resulted from the intentional or grossly negligent conduct of the injured party.

Legal remedies and complaints may be submitted to the Hungarian National Authority for Data Protection and Freedom of Information:

Registered office: 1055 Budapest, Falk Miksa utca 9-11.
Postal address: 1363 Budapest, P.O. Box 9.
Telephone: +36 1 391 1400
Mobile: +36 30 683 59 69
URL: https://naih.hu
Email: ugyfelszolgalat@naih.hu

The provision of personal data is based on a legal or contractual obligation and is also a precondition for concluding a contract. Failure to provide the data may result in the contract not being concluded or in the non-performance of concluded contracts.

  1. Updates and Amendments

The Controller acknowledges the contents of this Notice as binding upon itself, but reserves the right to amend this Notice, provided that it informs its audience of the changes in due time.