Our company follows the principles below when processing personal data:
a) We process personal data lawfully, fairly, and transparently for you.
b) We collect personal data only for specified, explicit, and legitimate purposes and do not process them in a manner incompatible with these purposes.
c) The personal data we collect and process are appropriate, relevant, and limited to what is necessary for the purposes of processing.
d) Our company takes all reasonable measures to ensure that the data we process is accurate and up-to-date when necessary; inaccurate personal data is promptly deleted or corrected.
e) We store personal data in a form that allows identification only for as long as necessary to achieve the purposes of data processing.
f) We ensure appropriate security of personal data by implementing suitable technical and organizational measures to protect against unauthorized or unlawful processing, accidental loss, destruction, or damage.
Our company processes your personal data
a) Based on your informed and voluntary consent, only to the necessary extent and always for a specific purpose. This includes collecting, recording, organizing, storing, and using your data.
b) In certain cases, processing your data is based on legal requirements and is mandatory; in such cases, we will explicitly inform you.
c) In some instances, our company or a third party has a legitimate interest in processing your personal data, such as for operating, developing, and securing our website.
Terms of Use
We respectfully request that you carefully read these terms of use, in which AIVAREX Kft. informs you on its website (www.aivarex.hu) visitors, on the management and protection of personal data and information, as well as on the conditions under which the website can be used.
Introduction
Service Provider and Data Controller Information:
Name / Company: AIVAREX Kft.
Registered Address: 1165 Budapest, Nyílpuska utca 5.
Tax Number: 12342594-2-42
Website Name and Address: www.aivarex.hu
Privacy Policy Availability: www.aivarex.hu
Data Controller Contact Information:
Name: AIVAREX Kft.
Registered Address: 1165 Budapest, Nyílpuska utca 5.
Mailing Address: 1165 Budapest, Nyílpuska utca 5.
Email: aivarex@aivarex.hu
Phone: +36 1 401 0419
Hosting Provider Contact Information:
Name / Company: Rackhost Zrt.
Registered Address: 6722 Szeged, Tisza Lajos körút 41
Mailing Address: 6722 Szeged, Tisza Lajos körút 41
Email: info@rackhost.hu
Our website only requests personal data from visitors if they wish to make an inquiry. If you have questions regarding data processing, you can request further information via **aivarex@aivarex.hu** or by postal mail. We will respond without delay, within **20 days** (but no later than **1 month**) to the contact details you provide.
Definitions
- GDPR (General Data Protection Regulation) is the European Union’s new Data Protection Regulation;
- Data processing: Any operation or set of operations performed on personal data or data sets, whether automated or not, including collection, recording, structuring, storing, modifying, retrieving, consulting, using, disclosing, transmitting, making available, aligning, combining, restricting, erasing, or destroying.
- Data processor: A natural or legal person, public authority, agency, or other entity that processes personal data on behalf of the data controller.
- Personal data: Any information relating to an identified or identifiable natural person (data subject). A natural person is identifiable if they can be identified, directly or indirectly, particularly by reference to an identifier such as a name, number, location data, online identifier, or factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- Data controller: A natural or legal person, public authority, agency, or other entity that determines the purposes and means of processing personal data, alone or jointly with others. If the purposes and means of processing are determined by EU or Member State law, the data controller may be designated according to specific criteria set by such laws.
- Data subject's consent: The data subject’s voluntary, specific, informed, and unambiguous indication of their wishes by which they signify agreement to the processing of personal data relating to them through a statement or a clear affirmative action.
- Data breach: A security breach leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed.
- Recipient: A natural or legal person, public authority, agency, or other entity to whom personal data is disclosed, whether or not they are a third party. Public authorities that may access personal data in accordance with EU or Member State law for a specific investigation are not considered recipients; processing by these public authorities must comply with applicable data protection rules.
- Third party: A natural or legal person, public authority, agency, or other entity other than the data subject, data controller, or data processor, as well as persons who, under the direct authority of the data controller or data processor, are authorized to process personal data.
Principles of Data Processing
The data controller declares that it processes personal data in accordance with this privacy policy and complies with applicable laws, paying particular attention to the following:
The processing of personal data must be lawful, fair, and transparent to the data subject.
The collection of personal data must be limited to specified, explicit, and legitimate purposes. Data processing must be appropriate and relevant and should only extend to the necessary extent.
Personal data must be accurate and up-to-date. Inaccurate personal data must be promptly deleted.
Personal data must be stored in a form that allows identification of data subjects only for as long as necessary. Storage for longer periods may only occur for public interest archiving, scientific or historical research, or statistical purposes.
Personal data processing must be carried out in a way that ensures adequate security through appropriate technical or organizational measures, protecting against unauthorized or unlawful processing, accidental loss, destruction, or damage.
The principles of data protection must be applied to any information related to an identified or identifiable natural person.
Important Data Processing Information
The primary goal of data processing is to protect the visitors of the service provider's website.
The legal basis for data processing is the consent of the data subject. The duration of data processing and the deletion of data. The duration of data processing is always dependent on the specific user purpose, but the data must be immediately deleted once the originally intended purpose has been fulfilled. The data subject can withdraw their consent for data processing at any time by sending an email to the contact email address. If there is no legal obstacle to deletion, the data will be deleted. The data processor and its employees are authorized to access the data.
The data subject may request access to their personal data, rectification, deletion, or restriction of its processing from the data controller, and may object to the processing of their personal data, as well as exercise their right to data portability. The data subject may withdraw their consent for data processing at any time, but this does not affect the lawfulness of the data processing based on the consent before withdrawal. The data subject has the right to submit a complaint to the supervisory authority. The data subject has the right to request that the data controller correct or complete inaccurate personal data without undue delay. The data subject has the right to request the deletion of inaccurate personal data without undue delay, and the data controller is obliged to delete personal data without undue delay if there is no other legal basis for data processing. Personal data modification or deletion can be initiated by email, phone, or letter using the provided contact options.
Invoice Issuance
The purpose of data processing is to issue and send an invoice, either electronic or paper, as an email attachment. The legal basis for data processing is mandatory processing based on the law. The data subjects are the service provider's customers.
Duration of data processing: Data processing takes place according to legal requirements or until the withdrawal of consent. You can withdraw your consent for data processing at any time by sending an email to the contact address. Data will be deleted once consent for data processing is withdrawn. You can withdraw your consent for data processing at any time by sending an email to the contact email address. Deletion of invoicing data may occur according to legal regulations. The data processor and its employees are authorized to access the data. Data storage method: electronic. Invoice data modification or deletion can be initiated by email, phone, or letter using the provided contact options.
Scope of processed data:
Specific purpose of the processed data:
Name: Identification, communication, invoicing. Company name: Identification, communication, invoicing.
Address: Identification, communication, invoicing.
Email: Identification, communication.
Phone: Identification, communication.
Tax number / tax identification number: Customer identification.
Invoice data: Invoice identification.
Invoice issue date: Technical informational operation.
The data subject may object to the processing of their personal data, in which case the procedures outlined in this notice and the related laws will apply.
Cookies
Cookies are small data files (hereinafter referred to as cookies) that are placed on your computer via the website when you use it, and they are saved and stored by your internet browser. Most commonly used internet browsers (Chrome, Firefox, etc.) accept and enable cookies by default, but it is up to you to refuse or disable them by modifying your browser settings, and you can also delete cookies already stored on your computer. Each browser provides more detailed information about cookies in its "Help" section.
Some cookies do not require your prior consent. We provide brief information about these cookies when you first visit our website. These include authentication, multimedia player, load balancing, session cookies that help customize the user interface, and security cookies focused on the user.
Cookie Type: The website uses Google Analytics.
Function: This cookie, used by Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA), records how users use the website. Based on the information recorded, reports can be generated to help further develop the website.
The cookie records the following information anonymously:
(i) The number of visitors to the website,
(ii) The website visitors' sources of entry, and
(iii) Which pages on the website the visitors accessed. Validity (deletion date or deadline): 1 year.
Social Media
Social media is a medium where messages are spread through social users. Social media uses the internet and online platforms to allow users to become content creators, not just consumers. Social media includes platforms like Facebook, Twitter, Instagram, TikTok, YouTube, etc., where user-generated content is shared. Social media presentations may include public speeches, presentations, product or service demonstrations. Information shared on social media can be in the form of forums, blog posts, images, videos, audios, message boards, emails, etc. Consequently, the scope of processed data may include not only personal data but also the user's public profile picture.
Data subjects: Visitors to the website. The purpose of data collection is to promote the website or associated pages. The legal basis for data processing is the voluntary consent of the data subject. The duration of data processing: As per the regulations of the respective social media platform. Data deletion deadline: As per the regulations of the respective social media platform. Those authorized to access the data: As per the regulations of the respective social media platform. Data storage method: Electronic. It's important to note that when users upload or submit personal data, they grant the social media platform operator worldwide permission to store and use such content. Therefore, it is essential to ensure that the user has full authorization to share the information.
Google Analytics: Our website does not use Google Analytics. If the aforementioned page were to use Google Analytics: Google Analytics creates reports for website operators based on internal cookies (cookies) regarding user habits.
Google uses the information to evaluate how users use the website. In addition, Google provides reports related to website activity to the website operator to enable further services.
Data is stored on Google's servers in an encrypted format to prevent misuse of the data. You can disable Google Analytics as follows. A quote from the page: Website users who do not wish for Google Analytics JavaScript to create reports about their data may install the Google Analytics opt-out browser extension. The extension prevents Google Analytics JavaScript (ga.js, analytics.js, and dc.js) from sending information to the Google Analytics system. The extension can be used in most modern browsers.
The Google Analytics opt-out browser extension does not prevent data from being sent to the website or other internet analytics services.
https://support.google.com/analytics/answer/6004245?hl=en
Google Privacy Policy:
https://policies.google.com/privacy?hl=en Detailed information about the usage and protection of data is available through the above links.
Detailed Privacy Policy:
https://static.googleusercontent.com/media/www.google.com/en//intl/en/policies/privacy/google_privacy_policy_en.pdf
Data Processors Hosting Service Provider:
Name / Company Name: Rackhost Zrt.
Headquarters: 6722 Szeged, Tisza Lajos körút 41-
Mailing Address: 6722 Szeged, Tisza Lajos körút 41
Email: info@rackhost.hu
The data you provide will be stored on a server operated by the hosting provider. Only our employees and those working for the server operators have access to the data, but they are all responsible for the secure management of the data. The activity description: hosting services, server services. The purpose of data processing: ensuring the operation of the website. The data processed: personal data provided by the data subject. The duration of data processing and the deadline for data deletion:
Data processing lasts until the operation of the website ends, or according to the agreement between the website operator and the hosting provider. The data subject may also request the deletion of their data by contacting the hosting provider if necessary. The legal basis for data processing is the consent of the data subject or processing based on legal provisions.
We can only transfer your data within the limits defined by law, and we ensure that our data processors cannot use your personal data for purposes contrary to your consent under the contractual terms. For more information, see point 2.
Our company does not transfer data abroad.
Courts, prosecutors, and other authorities (e.g., police, tax office, National Authority for Data Protection and Freedom of Information) may contact us for information, data disclosure, or the provision of documents. In such cases, we must fulfill our data provision obligation, but only to the extent necessary to achieve the purpose of the request.
Those involved in data processing and/or data management in our company and employees are entitled to learn about your personal data to a predetermined extent – under confidentiality obligations. Your personal data is protected by appropriate technical and other measures to ensure the safety, availability, and protection of data from unauthorized access, alteration, damage, or disclosure, as well as from any other unauthorized use.
As part of organizational measures, we control physical access to our buildings, provide ongoing training for our employees, and store paper-based documents securely. As part of technical measures, we use encryption, password protection, and antivirus software. However, we draw your attention to the fact that the transmission of data over the internet is not fully secure.
Our company takes all necessary measures to make the processes as secure as possible. However, we cannot fully assume responsibility for data transmission over the website, but we strictly follow regulations to ensure the security of your data and prevent unlawful access.
Processed Data
Duration of Data Processing:
The duration of the given cookie's data storage time, more information can be found here:
Google general cookie policy:
https://www.google.com/policies/technologies/types/
Google Analytics policy:
https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage?hl=en
What are your rights and remedies?
This privacy policy applies only to AIVAREX Ltd., and the company is not responsible for the content or data handling practices of any other sites that may be accessible from the website.
What are your rights and remedies?
Regarding data processing, you have the right to:
Ø request information,
Ø request the correction, modification, or supplementation of your personal data,
Ø object to data processing and request the deletion or blocking of your data (except in cases of mandatory data processing),
Ø seek judicial remedy,
Ø file a complaint with the supervisory authority and initiate proceedings (https://naih.hu/panaszuegyintezes-rendje.html).
Supervisory Authority:
National Authority for Data Protection and Freedom of Information
Ø Headquarters: 1055 Budapest, Falk Miksa utca 9-11.
Ø Mailing Address: 1530 Budapest, P.O. Box: 5.
Ø Phone: +36 (1) 391-1400
Ø Fax: +36 (1) 391-1410
Ø Email: ugyfelszolgalat@naih.hu Website: https://naih.hu/
BUDAPEST ARBITRATION BOARD
● Address: 1016 Budapest, Krisztina krt. 99.
● Phone: +36-1-488-21-31
● Fax: +36-1-488-21-86
● President: Dr. György Baranovszky
● Email: bekelteto.testulet@bkik.hu
Upon your request, we will provide information regarding your data processed by us or by our designated data processor:
Ø about your data,
Ø the source of your data,
Ø the purpose and legal basis of data processing,
Ø the duration of processing, and if this is not possible, the criteria for determining the duration,
Ø the name and address of our data processors, and the activities related to data processing,
Ø the circumstances, impacts, and measures taken to prevent data protection incidents,
Ø if your data is transferred, the legal basis and recipient of the data transfer.
We will respond to your request within the shortest possible time, within 10 days (but no later than 1 month). The information is free unless you have already made a request for the same data within the current year. If you have already paid a fee for this information, we will refund the fee if the data was processed unlawfully or if the information request led to correction. We can refuse to provide information only in cases prescribed by law, with a reference to the legal basis, and with information on judicial remedy or the possibility to contact the authority.
Our company will notify you and anyone who has previously received the data for data processing purposes about the correction, blocking, designation, or deletion of your personal data, unless this notification would violate your legitimate interest. If we do not fulfill your request for correction, blocking, or deletion, we will provide the reasons for refusal within 10 days (no later than 1 month), either in writing or electronically (with your consent), along with information on judicial remedy or the possibility to contact the authority.
If you object to the processing of your personal data, we will examine the objection and notify you in writing of our decision within 10 days (no later than 1 month).
If we find that your objection is justified, we will cease processing the data – including further data collection and transfer – and block the data. We will also notify anyone who has received the data about the objection and the actions taken based on it.
The legal basis for data processing:
- EUROPEAN PARLIAMENT AND COUNCIL (EU) 2016/679 REGULATION (April 27, 2016) on the protection of individuals regarding the processing of personal data and the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation).
- Act CXII of 2011 on the right to informational self-determination and freedom of information.
- Act CVIII of 2001 on electronic commerce services and certain issues related to information society services.
- Act C of 2003 on electronic communications.
- Act CXXVII of 2007 (VAT Act) and especially Section 169 (on receipt of receipts and invoice data content).