Privacy policy

1. Introduction

József Ungi (hereinafter József Ungi, service provider, data controller, the Company), as data controller, acknowledges that the content of this legal notice is binding upon it. 
The Company undertakes that all data processing related to its activities complies with the requirements set out in this policy and applicable legislation. 
József Ungi operates the website bozsokarosszeria.neosite.hu.

József Ungi reserves the right to amend this notice at any time. Naturally, it will inform its audience of any changes in good time.

József Ungi is committed to protecting the personal data of its customers and partners, and places particular importance on respecting customers' right to informational self-determination. The Data Controller handles personal data confidentially and implements all such security, technical and organisational measures as guarantee the security of the data.

József Ungi sets out below its data processing principles and presents the requirements it has defined for itself as data controller and undertakes to comply with. Its data processing principles are in line with applicable data protection legislation, in particular:

  • Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information;
  • Act V of 2013 on the Civil Code (Civil Code);
  • Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions of Commercial Advertising Activities (Grt.);
  • Act CVIII of 2001 (E-Commerce Act) on certain issues relating to electronic commercial services and services related to the information society;
  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: "GDPR")

2. Definitions

  • data subject: any identified or identifiable natural person, directly or indirectly, in particular by reference to personal data;
  • personal data: any data relating to the data subject — in particular the data subject's name, identifier, and one or more factors specific to their physical, physiological, mental, economic, cultural or social identity — as well as any inference drawn from such data that relates to the data subject;
  • consent: any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her — in whole or in respect of specific operations;
  • data controller: the natural or legal person, or organisation without legal personality, which alone or jointly with others determines the purposes and means of the processing of data, makes and implements decisions concerning data processing (including the means used), or has them implemented by a processor;
  • data processing: any operation or set of operations performed on data, irrespective of the procedure applied, including in particular collection, recording, organisation, storage, alteration, use, retrieval, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction, as well as preventing further use of the data, and the making of photo, sound or image recordings, and the recording of physical characteristics capable of identifying a person (e.g. fingerprints, palm prints, DNA samples, iris images);
  • data transfer: making data accessible to a specified third party;
  • disclosure: making data accessible to anyone;
  • data erasure: rendering data unrecognisable in such a way that restoration is no longer possible;
  • data processing (technical): the performance of technical tasks related to data processing operations, irrespective of the method and means used to carry out the operations and the location of application, provided that the technical task is performed on the data;
  • processor: the natural or legal person, or organisation without legal personality, which processes data on behalf of the controller on the basis of a contract — including a contract concluded on the basis of a legal provision. 

3. Company details

Our company's details and contact information are as follows:

  • Name: József Ungi
  • Registered office: 8220 Balatonalmádi, Veszprémi út 108.
  • Postal address: 8220 Balatonalmádi, Veszprémi út 108.
  • Sole trader registration number: 57648868
  • Tax number: 59601490-1-39
  • Telephone: +36 30 277 32 86
  • E-mail:  bozsokarosszeria@gmail.com
  • Representative of the Data Controller: József Ungi

4. Categories of personal data, purposes, legal bases and duration of processing

We draw the attention of those providing data to József Ungi that if they do not provide their own personal data, it is the obligation of the person providing the data to obtain the data subject's consent. The data controller is not obliged to verify that such consent has been obtained. The data controller draws its partner's attention to the fact that if it fails to fulfil this obligation and, as a result, the data subject asserts a claim against the data controller, the data controller may pass on the enforced claim and the amount of related damage to the partner.

We provide the following information in connection with our individual processing operations. 

4.1. Request for quotation, enquiry by direct contact

Interested parties may contact the Company directly by electronic mail sent to the Company's address and/or by telephone.

  • Purpose of processing: to facilitate communication between the data subject and our Company and to enable closer and more effective cooperation.
  • Legal basis for processing: legitimate interests — Article 6(1)(f) GDPR
  • Categories of personal data processed: name of requester/contact person; email address, telephone number and other information provided by the data subject,
  • Duration of processing: 3 years following the validity period of the quotation or until the data subject objects
  • Recipients of personal data: The data controller does not transfer the data obtained to third parties, except for the processor(s) indicated in Section 7. Recorded data may only be accessed by employees of the Data Controller and designated colleagues of the processor(s).
  • Specification of legitimate interest: our Company's legitimate interest is the processing of the data subject's data — direct marketing
  • Categories of data subjects concerned: partners and data subjects who enquire directly (e.g. by email, telephone) about the Company's services. 

4.2. Request for quotation, enquiry via the website (bozsokarosszeria.neosite.hu)

Our company enables data subjects to request a quotation electronically.

  • Purpose of processing: to facilitate communication between the data subject and our Company and to enable closer and more effective cooperation.
  • Legal basis for processing: the data subject's voluntary consent — Article 6(1)(a) GDPR.
  • Categories of personal data processed: name of enquirer (first name, surname); email address, telephone number, company name and other information provided by the data subject.
  • Duration of processing: 3 years following the validity period of the quotation or until withdrawal of consent.
  • Recipients of personal data: The data controller does not transfer the data obtained to third parties, except for the processor(s) indicated in Section 7. Recorded data may only be accessed by employees of the Data Controller and designated colleagues of the processor(s).
  • Categories of data subjects concerned: partners and data subjects who enquire via the website about the Company's services and products.

4.3. Request for quotation, processing related to follow-up

  • Purpose of processing: the data controller's legitimate interest in retaining the data subject's data beyond the validity period of the quotation for direct marketing purposes
  • Legal basis for processing: legitimate interests of the data controller, Article 6(1)(f) GDPR,
  • Categories of personal data processed: contact person's surname and first name; telephone number; email address
  • Recipients of personal data: The data controller does not transfer the data obtained to third parties, except for the processor(s) indicated in Section 7. Recorded data may only be accessed by employees of the Data Controller and designated colleagues of the processor(s).
  • Duration of processing: until the data subject objects
  • Specification of legitimate interest: establishing business relationships with partners and requesters, providing accurate information to data subjects. Our Company's legitimate interest is the processing of the data subject's data — direct marketing
  • Categories of data subjects concerned: recipients of quotations previously issued by the Company and/or contact person(s) listed therein.

4.4. Newsletter registration

  • Purpose of processing: sending email newsletters containing commercial advertising to interested parties, providing information on current news
  • Legal basis for processing: the data subject's prior, voluntary consent, Article 6(1)(a) GDPR,
  • Categories of personal data processed: name, email address
  • Duration of processing: until voluntary consent is withdrawn or unsubscribed from the newsletter. Our Company processes the data provided by the data subject until consent is withdrawn. Following withdrawal of consent, the processed data will be deleted from our newsletter database within 7 days at the latest, and we will no longer send you newsletters.
  • Recipients of personal data: The data controller does not transfer the data obtained to third parties, except for the processor(s) indicated in Section 7. Recorded data may only be accessed by employees of the Data Controller and designated colleagues of the processor(s). You may unsubscribe from the newsletter at any time by sending an email to our Company at bozsokarosszeria@gmail.com or by clicking the unsubscribe icon in the newsletter. 
  • Categories of data subjects concerned: partners and data subjects who subscribe to the Company's electronic newsletter.

4.5. Newsletter data (for newsletters registered before 25 May 2018)

  • Purpose of processing: sending email newsletters containing commercial advertising to interested parties, providing information on current news
  • Legal basis for processing: legitimate interests of the data controller, Article 6(1)(f) GDPR,
  • Categories of personal data processed: name, email address
  • Duration of processing: until the data subject objects
  • Specification of legitimate interest: providing data subjects who subscribed to the newsletter with information containing commercial advertising and business offers. Our Company's legitimate interest is the processing of the data subject's data, direct marketing.
  • Recipients of personal data: the data controller does not transfer the data obtained to third parties, except for the processor(s) indicated in Section 7. Recorded data may only be accessed by employees of the Data Controller and designated colleagues of the processor(s). You may unsubscribe from the newsletter at any time by sending an email to our Company at bozsokarosszeria@gmail.com or by clicking the unsubscribe icon in the newsletter. 
  • Categories of data subjects concerned: partners and data subjects who subscribed to the Company's electronic newsletter before 25.05.2018.

4.6. CCTV system

Cameras operate on the premises operated by the data controller for the personal and property security of data subjects and for other purposes. Information boards draw data subjects' attention to their operation. Activities related to the operation of the CCTV system are defined for data subjects in the premises' "Property Protection CCTV Data Processing Notice", which is available at the premises.

4.7. Processing related to ensuring the operation of information technology services

  • Purpose of processing: József Ungi may use so-called "cookies" (temporary markers) on its websites, which enable faster access to these. By "cookies" we mean an item of information that is active only during an individual customer session and which is transferred from the website to the Customer's computer for faster identification. The Customer may always request that cookies be disabled by changing browser settings; however, such disabling may slow down or prevent access to certain parts of the site and use of certain functions. 
    The session cookies used avoid the need to use other IT tools that may be potentially harmful to the confidentiality of customer navigation and do not make it possible to obtain identifying personal data.
    The user can delete cookies from their own computer and disable the use of cookies in their browser. Cookies can usually be managed in browsers under Tools/Settings in Privacy settings under the name cookie or süti.
  • Legal basis for processing: voluntary consent of the data subject (User), Article 6(1)(a) GDPR.
    The User gives voluntary consent to processing by accepting the pop-up notice and statement when beginning to browse the website, and/or by continuing to browse.
    Categories of personal data processed: IT processing relates to the data necessary for the operation of "cookies" used for the operation of the website and the use of log files applied by the web hosting provider.
  • Duration of processing: until the end of the session
  • Recipients of personal data: The data controller does not transfer the data obtained to third parties, except for the processor(s) indicated in Section 7. Recorded data may only be accessed by employees of the Data Controller and designated colleagues of the processor(s).
  • Categories of data subjects concerned: every User visiting the website, regardless of whether they use services available on the website.

5. Other processing

We will provide information about processing operations not listed in this notice at the time the data is collected. We inform our customers that certain authorities, public bodies performing public tasks, and courts may contact our company to request disclosure of personal data. Our company will disclose personal data to these bodies — provided the body concerned has specified the precise purpose and scope of the data — only to the extent strictly necessary to achieve the purpose of the request, and where the fulfilment of the request is required by law. 

6. Transfer of personal data to third countries or international organisations

Our Company does not transfer your personal data referred to above either to third countries or to international organisations.

7. Information on the use of processors

The data controller transfers data to processor(s) contracted with it for the performance of the contract during processing.
Categories of recipients: system administration service provider, accounting and payroll service provider, server hosting and web hosting provider

8. Children

Our services are not intended for persons under 16 years of age, and we ask that persons under 16 do not provide Personal Data to the Data Controller. 
If we become aware that we have collected personal data from a child under 16 — except for the processing of data required by legal provisions — we will take steps to delete the data as soon as possible.

9. Automated decision-making

Our Company does not apply automated decision-making in its data processing procedures or data collection.

10. Manner of storage of personal data, security of processing

Our company's IT systems and other data storage locations are located at the registered office and on servers provided by the processor. In handling personal data, our company selects and operates the IT tools used in providing the service so that the processed data:

  1. is accessible to those authorised to access it (availability);
  2. its authenticity and authentication are ensured (authenticity of processing);
  3. its unaltered nature can be demonstrated (data integrity);
  4. is protected against unauthorised access (confidentiality of data).

We pay particular attention to data security and also implement the technical and organisational measures and establish the procedural rules necessary to give effect to the guarantees under the GDPR. We protect data with appropriate measures, in particular against unauthorised access, alteration, transmission, disclosure, erasure or destruction, as well as accidental destruction, damage, and becoming inaccessible as a result of changes in the technology used.

Our company's and our partners' IT systems and networks are protected against computer-assisted fraud, computer viruses, computer intrusions and denial-of-service attacks. The operator also provides security through server-level and application-level protection procedures. Daily backup of data is ensured. In order to avoid data protection incidents, our company takes all possible measures, and if such an incident occurs — in accordance with our incident management policy — we act without delay to minimise risks and remedy damage.

11. Rights of data subjects, remedies

The data subject may request information about the processing of their personal data, request rectification of their personal data, and — except for mandatory processing — erasure or withdrawal, and may exercise rights of data portability and objection in the manner indicated when the data was collected, or at the data controller's contact details above.

The rights of data subjects and remedies are defined below and communicated to data subjects on the basis of Act CXII of 2011 and EU Regulation 2016/679. 

Right to information, or the data subject's "right of access": On request of the data subject, on the basis of Act CXII of 2011 and Article 15 of EU Regulation 2016/679, the Data Controller shall provide information about 

  • the data it processes and categories of personal data,
  • the purpose of processing,
  • the legal basis for processing,
  • the duration of processing,
  • where applicable, the duration of storage of the data, or if this is not possible, the criteria for determining this duration,
  • where applicable, if the data were not collected from the data subject, all available information on their source,
  • where applicable, automated decision-making, including profiling, and meaningful information about the logic involved and the significance and envisaged consequences of such processing for the data subject,
  • details of processors, where processors are used,
  • circumstances, effects and measures taken to remedy a data protection incident, and
  • where personal data of the data subject are transferred, the legal basis, purpose and recipient of the transfer.

Information is free of charge if the person requesting information has not yet submitted an information request to the Data Controller in respect of the same data in the current year. In other cases, a fee may be charged. Any fee already paid must be refunded if the data were processed unlawfully or if the request for information led to rectification.

The Data Controller draws the attention of data subjects to the fact that information must be refused on the basis of Act CXII of 2011,

  1. if, on the basis of a provision of law, international treaty or binding legal act of the European Union, the Data Controller receives personal data in such a way that, at the time of transfer, the transferring data controller indicates restrictions on the rights of the data subject of the personal data guaranteed in the said law, or other restrictions on processing.
  2. for the external and internal security of the State, including national defence, national security, prevention or prosecution of criminal offences, security of enforcement of penalties, further for State or local government economic or financial interests, for significant economic or financial interests of the European Union, and for the purpose of preventing and detecting disciplinary and ethical violations and breaches of employment and occupational safety obligations related to the practice of occupations — including in all cases monitoring and supervision — and for the protection of the rights of the data subject or others.

The Data Controller is obliged to notify the National Authority for Data Protection and Freedom of Information of refused information requests annually by 31 January of the year following the year in question.

Right to rectification: The data subject has the right to obtain from the Data Controller without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement. At the same time, if personal data do not correspond to reality and personal data corresponding to reality are available to the Data Controller, the Data Controller is obliged to rectify the personal data even without a request from the data subject.

Right to erasure, or the "right to be forgotten": The data subject has the right to obtain from the Data Controller the erasure of personal data concerning him or her without undue delay, and the Data Controller is obliged to erase personal data concerning the data subject without undue delay where this is not excluded by mandatory processing.

In addition to the above case, the Data Controller is obliged to erase data on the basis of Act CXII of 2011 and Regulation (EU) 2016/679 of the European Parliament and of the Council if

  • the data are processed unlawfully;
  • the data are incomplete or incorrect — and this condition cannot be lawfully remedied — provided that erasure is not excluded by law;
  • the purpose of processing has ceased or the statutory storage period of the data has expired;
  • erasure has been ordered by a court or the Authority.
  • the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
  • the data subject objects to processing and there are no overriding legitimate grounds for processing;
  • the personal data must be erased for compliance with a legal obligation to which the Data Controller is subject;
  • the personal data were collected in connection with the offer of information society services referred to in Article 8(1) of EU Regulation 2016/679 directly to children.

Where the Data Controller has made personal data public and is obliged to erase them in accordance with the above, taking account of available technology and the cost of implementation, it shall take reasonable steps, including technical measures, to inform data controllers processing the personal data that the data subject has requested erasure of links to, or copies or replicas of, those personal data.

The Data Controller draws the attention of data subjects to the limitations on the right to erasure or "right to be forgotten" arising from the EU regulation, which are as follows:

  1. exercise of the freedom of expression and information;
  2. compliance with a legal obligation requiring processing under Union or Member State law to which the controller is subject, or performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  3. reasons of public interest in the area of public health;
  4. for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) of EU Regulation 2016/679, where the right to erasure is likely to render impossible or seriously impair the achievement of such processing; or
  5. for the establishment, exercise or defence of legal claims.

Right to restriction of processing, or restriction (blocking): The data subject has the right to obtain restriction of processing upon request.
If, on the basis of available information, it may be assumed that erasure would harm the legitimate interests of the data subject, the data must be blocked. Such blocked personal data may be processed only for as long as the processing purpose that excluded erasure of the personal data exists.

If the data subject disputes the accuracy or correctness of personal data but the incorrectness or inaccuracy of the disputed personal data cannot be clearly established, the data shall be blocked. In this case, the restriction applies for the period enabling the Data Controller to verify the accuracy of the personal data.

Under the EU regulation, data must be blocked if

  1. processing is unlawful and the data subject opposes erasure of the data and requests instead restriction of their use;
  2. the Data Controller no longer needs the personal data for processing purposes, but the data subject requires them for the establishment, exercise or defence of legal claims; or
  3. the data subject has objected to processing; in this case, the restriction applies for the period until it is established whether the legitimate grounds of the Data Controller override those of the data subject.

Where processing is restricted (blocked), such personal data may, with the exception of storage, be processed only with the consent of the data subject, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or a Member State.

The Data Controller hereby particularly draws the attention of data subjects to the fact that the data subject's rights to rectification, erasure and restriction (blocking) may be restricted by law for the external and internal security of the State, including national defence, national security, prevention or prosecution of criminal offences, security of enforcement of penalties, further for State or local government economic or financial interests, for significant economic or financial interests of the European Union, and for the purpose of preventing and detecting disciplinary and ethical violations and breaches of employment and occupational safety obligations related to the practice of occupations — including in all cases monitoring and supervision — and for the protection of the rights of the data subject or others.
The Data Controller shall, without undue delay and within a maximum of 30 days from receipt of the request, inform the data subject about the matters specified in the request and/or rectify the data and/or erase and/or restrict (block) the data, or take other steps in accordance with the request, if there is no ground excluding this.

The Data Controller shall notify the data subject in writing of rectification, erasure and restriction of processing, and also all those to whom the data were previously transferred or disclosed for processing purposes. At the request of the data subject, the Data Controller shall provide information on these recipients. Notification may be omitted if this does not prejudice the legitimate interests of the data subject in view of the purpose of processing, or if notification proves impossible or would require disproportionate effort. The Data Controller is also obliged to notify the data subject in writing if the data subject's exercise of rights cannot be fulfilled for any reason, and must precisely state the factual and legal reasons and the remedies available to the data subject: the possibility of turning to the courts and the National Authority for Data Protection and Freedom of Information.

Right to data portability: The data subject has the right to

  1. receive the personal data concerning him or her, which he or she has provided to the Data Controller, in a structured, commonly used and machine-readable format, and has the right to
  2. transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where:
  3. processing is based on consent; and
  4. processing is carried out by automated means.

In exercising the right to data portability, the data subject has the right to have personal data transmitted directly from one controller to another, where technically feasible.
Having regard to the processing carried out by the Data Controller, the conditions for exercising the right to data portability are not met (there is no automated processing), therefore the data subject cannot exercise this right.

Right to object: The data subject may object to the processing — including profiling — of personal data concerning him or her where

  • processing (transfer) is necessary solely for the enforcement of a right or legitimate interest of the Data Controller or the recipient, except in the case of mandatory processing;
  • use or transfer of personal data is for direct marketing, public opinion research or scientific research purposes;
  • the exercise of the right to object is otherwise permitted by law.

The data subject may also object under Article 21(3) of EU Regulation 2016/679 to processing of personal data for direct marketing purposes; in such case, personal data may no longer be processed for this purpose.

Where personal data are processed for scientific or historical research purposes or statistical purposes, the data subject has the right to object, on grounds relating to his or her particular situation, to processing of personal data concerning him or her, except where processing is necessary for the performance of a task carried out for reasons of public interest.
The Data Controller shall, while suspending processing, examine the objection within the shortest possible time but no later than 30 days from submission of the request, and inform the requester in writing of the outcome. If the requester's objection is justified, the Data Controller shall cease processing — including further collection and transfer — and block the data, and notify all those to whom personal data affected by the objection were previously transferred and who are obliged to take action to vindicate the right to object.

If the data subject does not agree with the Data Controller's decision, or the Data Controller fails to meet the referred deadline, the data subject is entitled to turn to the courts within 30 days of notification.
The data subject has the right to object in connection with automated decision-making.

Judicial enforcement: In the event of infringement of their rights, the data subject may turn to the courts. The court shall hear the case as a matter of priority. It is for the Data Controller to prove that processing complies with the provisions of law.

In the event of infringement of the right to informational self-determination, a report or complaint may be lodged with:

National Authority for Data Protection and Freedom of Information
Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
Telephone: +36 (1) 391-1400, Fax: +36 (1) 391-1410
Website: http://www.naih.hu
E-mail: ugyfelszolgalat@naih.hu