Privacy policy
Global Protect Hungary Kft.
globalprotect.hu
Privacy Notice
Table of Contents
Introduction
Controller and Contact Details
Definitions
Principles Relating to Processing of Personal Data
Quote Request
Customer Contact
Newsletter and Direct Marketing
Use of Google Ads Conversion Tracking
Use of Google Analytics
Use of Cookies
Processors Engaged
Social Media Pages
Customer Relations and Other Processing
Data Subject Rights
Time Limits for Action
Security of Processing
Informing the Data Subject About a Personal Data Breach
Notifying the Authority of a Personal Data Breach
Review in Case of Mandatory Processing
Right to Lodge a Complaint
Closing Remarks
Introduction
Global Protect Hungary Kft. (1133 Budapest, Pannónia utca 102., Tax No.: 32075894-2-41, Company Register No.: 01-09-405494) (hereinafter: Service Provider, Controller) is subject to the following policy:
In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation - GDPR), we provide the following information.
This privacy policy governs data processing on the following website / mobile applications: https://globalprotect.hu
The privacy policy is available at: https://globalprotect.hu/hu/adatkezelis-nyilatkozat
Amendments to this policy take effect upon publication at the above address.
Controller and Contact Details
Name: Global Protect Hungary Kft.
Registered office: 1133 Budapest, Pannónia utca 102.
Email: info@globalprotect.hu
Phone: +36 30 355 5422
Definitions
1. “personal data”: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
2. “processing”: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
3. “controller”: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
4. “processor”: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
5. “recipient”: a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular enquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;
6. “data subject’s consent”: any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
7. “personal data breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
Principles Relating to Processing of Personal Data
Personal data shall be:
1. processed lawfully, fairly and in a transparent manner in relation to the data subject (“lawfulness, fairness and transparency”);
2. collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (“purpose limitation”);
3. adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (“data minimisation”);
4. accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (“accuracy”);
5. kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (“storage limitation”);
6. processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (“integrity and confidentiality”).
The controller is responsible for, and must be able to demonstrate, compliance with the above (“accountability”).
The controller declares that its processing complies with the principles set out in this section.
Quote Request
1. Facts of data collection, scope of data processed and the purpose of processing:
| Personal data | Purpose of processing | Legal basis |
| Name | Identification | GDPR Art. 6(1)(b) |
| Phone number | Contact, coordination | GDPR Art. 6(1)(b) |
| Email address | Contact; required to send the quote (response). | GDPR Art. 6(1)(b) |
| Message | Required to prepare and customise the quote. | GDPR Art. 6(1)(b) |
| Time of the quote request | Technical operation. | GDPR Art. 6(1)(b) |
| IP address at the time of request | Technical operation. | GDPR Art. 6(1)(b) |
2. Data subjects: all individuals requesting a quote on the website.
3. Duration of processing / deadline for deletion: until the data subject’s deletion request if any of the conditions in GDPR Art. 17(1) is met.
4. Persons authorised to access the data / recipients: authorised employees of the controller.
5. Data subject rights related to processing:
The data subject may request access to, rectification or erasure of personal data concerning them, or restriction of processing, and has the right to data portability as well as the right to withdraw consent at any time.
6. Exercising access, deletion, modification, restriction and data portability can be initiated via:
By post: 1133 Budapest, Pannónia utca 102.
By email: info@globalprotect.hu
By phone: +36 30 355 5422
7. Legal basis of processing: the data subject’s consent and/or performance of a contract, GDPR Art. 6(1)(a), (b) and (c). By contacting us you consent to our processing of your personal data (name, phone number, email address) in accordance with this policy.
8. Please note that
the processing is necessary for providing a quote.
you are required to provide personal data so that we can send you a quote. If you fail to provide data, we cannot provide you with a tailored quote.
Customer Contact
1. Facts of data collection, scope of data processed and purpose of processing:
| Personal data | Purpose of processing | Legal basis |
| Name, email address, phone number | Contact, identification, performance of contracts, business purpose | GDPR Art. 6(1)(b) and (c); for enforcing claims arising from a contract: Section 6:21 of Act V of 2013 on the Civil Code |
2. Data subjects: all individuals who contact the controller by phone/email/in person, or are in a contractual relationship.
3. Duration / deletion: correspondence is retained until the deletion request of the data subject, but for a maximum of 2 years.
4. Persons authorised to access / recipients: authorised employees of the controller, in compliance with the above principles.
5. Data subject rights related to processing:
The data subject may request access to, rectification or erasure of personal data concerning them, or restriction of processing, has the right to data portability, and may withdraw consent at any time.
6. Exercising rights is possible via:
By post: 1133 Budapest, Pannónia utca 102.
By email: info@globalprotect.hu
By phone: +36 30 355 5422
7. Legal basis of processing:
Please note that
processing is necessary for the performance of a contract and to provide a quote. You are required to provide personal data so we can perform the contract / fulfil your request.
If you fail to provide data, we cannot perform the contract / process your request.
Newsletter and Direct Marketing
1. Under Section 6 of Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities, the User may give prior and explicit consent to being contacted by the Service Provider at the contact details provided at registration with promotional offers and other communications.
2. In addition, the Customer may consent, in line with this notice, to the controller processing the personal data necessary for sending promotional offers.
3. The Service Provider does not send unsolicited marketing messages, and the User may unsubscribe from receiving offers at any time, without restriction, without justification and free of charge. In this case, the Service Provider deletes all personal data necessary for sending promotional messages and will no longer contact the User with offers. The User can unsubscribe by clicking the link in the message.
4. Facts of data collection, scope of data processed and purpose of processing:
| Personal data | Purpose of processing | Legal basis |
| Name, email address | Identification; enabling subscription to newsletter/promotional coupons | Data subject’s consent, GDPR Art. 6(1)(a); Act XLVIII of 2008, Section 6(5) |
| Time of subscription | Technical operation | Data subject’s consent, GDPR Art. 6(1)(a); Act XLVIII of 2008, Section 6(5) |
| IP address at the time of subscription | Technical operation | Data subject’s consent, GDPR Art. 6(1)(a); Act XLVIII of 2008, Section 6(5) |
5. Data subjects: all individuals who subscribe to the newsletter.
6. Purpose: sending electronic messages containing advertising (email, SMS, push messages) to the data subject, providing information about current news, products, promotions, new features, etc.
7. Duration / deletion: processing continues until the consent is withdrawn (i.e., until unsubscription).
8. Persons authorised to access / recipients: the controller and its sales and marketing staff, in compliance with the above principles.
9. Data subject rights related to processing:
The data subject may request access to, rectification or erasure of personal data concerning them, or restriction of processing, and
may object to the processing of their personal data, and
has the right to data portability, as well as the right to
withdraw consent at any time.
10. Exercising access, deletion, modification, restriction, portability, or filing an objection is possible via:
By post: 1133 Budapest, Pannónia utca 102.
By email: info@globalprotect.hu
By phone: +36 30 355 5422
11. The data subject may unsubscribe from the newsletter at any time, free of charge.
12. Please note that
processing is based on your consent and on the Service Provider’s legitimate interest. You must provide personal data if you wish to receive our newsletter. If you fail to provide data, we cannot send you the newsletter.
you may withdraw your consent at any time by clicking the unsubscribe link.
withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Use of Google Ads Conversion Tracking
1. The controller uses the online advertising program “Google Ads” and within its framework the Google conversion tracking service. Google conversion tracking is an analytics service of Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”).
2. When a User reaches the website via a Google advertisement, a cookie necessary for conversion tracking is placed on the computer. These cookies have limited validity and contain no personal data, thus the User cannot be identified by them.
3. When the User browses certain pages of the website and the cookie has not yet expired, Google and the controller can see that the User clicked the ad.
4. Each Google Ads customer receives a different cookie; cookies cannot be tracked across the websites of Ads customers.
5. The information obtained through conversion cookies serves to compile conversion statistics for Ads customers who opted for conversion tracking. Customers thus learn the number of users who clicked their ad and were redirected to a page tagged for conversion tracking. However, they do not receive information that would identify any user.
6. If you do not wish to participate in conversion tracking, you can refuse it by disabling cookie storage in your browser. You will then not be included in conversion statistics.
7. Under Google Consent Mode v2, Google also uses two new consent signals:
ad_user_data and ad_personalization, which rely on the data subject’s
consent and relate to the use and sharing of data.
ad_user_data expresses consent to send user data to Google for advertising
purposes. ad_personalization controls whether data may be used for ad
personalisation (e.g., remarketing).
The Controller ensures obtaining and managing the relevant consents (and withdrawals) via its
cookie banner/panel. Withdrawal of consent does not affect the lawfulness of prior processing.
8. Further information and Google’s privacy policy are available at: https://policies.google.com/privacy
Use of Google Analytics
1. This website uses Google Analytics, a web analytics service provided by Google Inc. (“Google”). Google Analytics uses “cookies”, text files placed on your computer, to help analyze how Users use the website.
2. The information generated by the cookies about your use of the website is generally transmitted to and stored by Google on servers in the USA. With IP anonymisation activated on the website, Google truncates the User’s IP address within Member States of the European Union or in other states party to the Agreement on the European Economic Area.
3. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and truncated there. On behalf of the operator of this website, Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity and providing other services relating to website activity and internet usage.
4. The IP address transmitted by your browser within the scope of Google Analytics will not be merged with other Google data. You may refuse the use of cookies by selecting the appropriate settings on your browser; however, please note that if you do this, you may not be able to use the full functionality of this website. You can also prevent Google’s collection and processing of data generated by the cookie and relating to your use of the website (including your IP address) by downloading and installing the browser plugin available at: https://tools.google.com/dlpage/gaoptout?hl=hu
Hosting Provider
1. Activity performed by the processor: hosting services
2. Processor name and contact details:
Tárhely.Eu Szolgáltató Kft., 1097 Budapest, Könyves Kálmán körút 12-14.
+36 1 789-2-789, support@tarhely.eu
3. Facts of processing, scope of data: all personal data provided by the data subject.
4. Data subjects: all users of the website/mobile application.
5. Purpose of processing: making the website/mobile application available and ensuring its proper operation.
6. Duration / deletion: until termination of the agreement between the controller and the hosting provider or until the data subject’s deletion request addressed to the hosting provider.
7. Legal basis: GDPR Art. 6(1)(c) and (f), and Section 13/A(3) of Act CVIII of 2001 on certain issues of electronic commerce services and information society services. Legitimate interest: proper operation of the website, protection against attacks and fraud.
Social Media Pages
1. Facts of data collection, scope: name registered on social media platforms (Meta/Twitter/Pinterest/YouTube/Instagram, etc.) and public profile picture.
2. Data subjects: any individual registered on the above social platforms who “likes” the Controller’s page or contacts the Controller via the platform.
3. Purpose: sharing, liking, following and promoting certain content elements, products, promotions or the website itself on social platforms.
4. Duration, deletion, access, and rights: information on the source of data, their processing and transfer, and legal basis is available on the respective social platform. Processing takes place on the social platforms; therefore, the platform’s rules govern duration, method, and options for deletion and modification.
5. Legal basis: the data subject’s voluntary consent to the processing of personal data on social platforms.
Customer Relations and Other Processing
1. If you have any questions or issues while using our services, you may contact the Controller via the channels provided on the website (telephone, email, social media, etc.).
2. The Controller deletes emails, messages, and data provided via phone, Meta, etc. together with the inquirer’s name and email address, and any other voluntarily provided personal data, no later than 2 years from disclosure of the data.
3. For processing operations not listed in this notice, we provide information at the time of data collection.
4. In response to exceptional requests from authorities or other bodies authorised by law, the Service Provider is obliged to provide information, disclose or transfer data, or make documents available.
5. In such cases, the Service Provider will provide only that amount and type of personal data to the requesting party which is strictly necessary to achieve the purpose of the request, provided the exact purpose and scope of data are specified.
Data Subject Rights
1. Right of access
You have the right to obtain confirmation from the Controller as to whether or not personal data concerning you are being processed, and, where that is the case, access to the personal data and the information listed in the Regulation.
2. Right to rectification
You have the right to obtain from the Controller without undue delay the rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed, including by means of a supplementary statement.
3. Right to erasure
You have the right to obtain from the Controller the erasure of personal data concerning you without undue delay, and the Controller has the obligation to erase personal data without undue delay under certain conditions.
4. Right to be forgotten
Where the Controller has made the personal data public and is obliged to erase it, taking account of available technology and the cost of implementation, the Controller shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that you have requested the erasure by such controllers of any links to, or copy or replication of, those personal data.
5. Right to restriction of processing
You have the right to obtain restriction of processing where one of the following applies:
You contest the accuracy of the personal data, for a period enabling the Controller to verify the accuracy of the personal data;
the processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead;
the Controller no longer needs the personal data for the purposes of the processing, but you require them for the establishment, exercise or defence of legal claims;
you have objected to processing; in this case, the restriction applies pending verification whether the Controller’s legitimate grounds override yours.
6. Right to data portability
You have the right to receive the personal data concerning you, which you have provided to a Controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another Controller without hindrance from the Controller to which the personal data have been provided (...)
7. Right to object
Where processing is based on legitimate interest or the exercise of official authority, you have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you, including profiling based on those provisions.
8. Right to object to direct marketing
Where personal data are processed for direct marketing purposes, you have the right to object at any time to processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing. If you object to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.
9. Automated individual decision-making, including profiling
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. This shall not apply if the decision:
is necessary for entering into, or performance of, a contract between you and the Controller;
is authorised by Union or Member State law to which the Controller is subject and which also lays down suitable measures to safeguard your rights and freedoms and legitimate interests; or
is based on your explicit consent.
Time Limits for Action
The Controller shall provide information on action taken on a request under the above rights without undue delay and in any event within one month of receipt of the request.
That period may be extended by two further months where necessary. The Controller shall inform you of any such extension within one month of receipt of the request together with the reasons for the delay.
If the Controller does not take action on your request, the Controller shall inform you without delay and at the latest within one month of receipt of the request of the reasons for not taking action and on the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.
Security of Processing
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Controller and the Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia as appropriate:
1. pseudonymisation and encryption of personal data;
2. the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
3. the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
4. a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.
5. Data shall be stored so that unauthorised persons cannot access them. For paper-based media, this is ensured by physical storage/archiving rules; for electronic data, by centralised access control.
6. The storage method for electronic data shall allow deletion when the retention period expires or whenever otherwise necessary. Deletion must be irreversible.
7. Paper-based media shall be destroyed using a shredder or via a specialised external provider. For electronic media, physical destruction and/or secure, irreversible wiping must be carried out per the applicable rules.
8. Specific security measures implemented by the Controller:
For paper-based personal data, the Service Provider applies the following measures (physical protection):
1. Documents are stored in a secure, well-closing, dry room.
2. If paper-based personal data are digitised, the rules applicable to digitally stored documents shall apply.
3. During work, staff handling data may leave the room where processing takes place only after locking away the media entrusted to them or locking the room.
4. Only authorised persons may access personal data; third parties may not access them.
5. The Service Provider’s building and premises are equipped with fire and property protection systems.
IT protection
1. Computers and mobile devices (other data media) used for processing are the property of the Service Provider.
2. Systems containing personal data are protected by antivirus solutions.
3. For the security of digitally stored data, the Service Provider performs backups and archiving.
4. Access to the central server is restricted to designated persons with appropriate permissions.
5. Access to data on computers is possible only with a username and password.
Informing the Data Subject About a Personal Data Breach
Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Controller shall communicate the personal data breach to the data subject without undue delay.
The communication to the data subject shall describe in clear and plain language the nature of the personal data breach and contain at least the name and contact details of the data protection officer or other contact point where more information can be obtained; a description of the likely consequences of the personal data breach; and a description of the measures taken or proposed to be taken by the Controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
The communication to the data subject shall not be required if any of the following conditions are met:
the Controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorised to access it (such as encryption);
the Controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects is no longer likely to materialise;
it would involve disproportionate effort. In such a case, a public communication or similar measure whereby the data subjects are informed in an equally effective manner shall be issued instead.
If the data subject has not yet been informed of the personal data breach, the supervisory authority may, having considered the likelihood of a high risk, require the Controller to communicate the breach.
Notifying the Authority of a Personal Data Breach
The Controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the competent supervisory authority in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.
Review in Case of Mandatory Processing
Where the duration of mandatory processing or the need for periodic review is not determined by law, municipal regulation or a binding legal act of the European Union, the Controller shall, at least every three years from the start of processing, review whether the processing of personal data it performs, or performed on its behalf/by its instruction by a processor, is necessary to achieve the purpose of processing.
The Controller documents the circumstances and results of this review, retains the documentation for ten years after completion of the review, and makes it available to the National Authority for Data Protection and Freedom of Information upon request.
Right to Lodge a Complaint
You may lodge a complaint against a potential infringement by the Controller with the National Authority for Data Protection and Freedom of Information (NAIH):
Nemzeti Adatvédelmi és Információszabadság Hatóság
1055 Budapest, Falk Miksa utca 9-11.
Mailing address: 1363 Budapest, Pf. 9.
Phone: +36-1-391-1400
Fax: +36-1-391-1410
Email: ugyfelszolgalat@naih.hu
Closing Remarks
In preparing this notice, we took into account the following laws:
Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data;
Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information;
Act CVIII of 2001 on certain issues of electronic commerce services and information society services (in particular Section 13/A);
Act XLVII of 2008 on the Prohibition of Unfair Commercial Practices against Consumers;
Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities (in particular Section 6);
Act XC of 2005 on the Freedom of Electronic Information;
Act C of 2003 on Electronic Communications (in particular Section 155); Opinion 16/2011 on EASA/IAB Best Practice Recommendation on Online Behavioural Advertising;
The recommendation of the National Authority for Data Protection and Freedom of Information on the data protection requirements of prior information.