Privacy policy
This policy is still awaiting approval, and its date remains to be filled in. Until then the page stays out of search engines.
Privacy policy
concerning data processing in connection with the website of Tervem Kft.
Tervem Szolgáltató Korlátolt Felelősségű Társaság, as data controller, provides the following information to data subjects regarding the processing of their personal data, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the “General Data Protection Regulation”, hereinafter: GDPR).
1. Name and contact details of the controller
Tervem Szolgáltató Korlátolt Felelősségű Társaság (registered office: 1078 Budapest, Marek József utca 15. 1. em. 16., Hungary; VAT number: 29165579-2-42).
You may contact us with any question concerning data processing at the address above or at the email address given on the Contact page.
2. Processing operations
In connection with its website at tervem.hu, the controller carries out the following processing operations.
2.1. Contact through the website form
Purpose: answering enquiries and requests for quotation received through the contact form, and handling the resulting correspondence.
Legal basis: the data subject’s consent (Article 6(1)(a) GDPR).
Data processed: the data subject’s name, email address, telephone number (optional), the text of the message, the subject of the enquiry, and any other personal data the data subject chooses to provide.
Duration: until the purpose of the processing ceases, that is, until the enquiry is closed. If a business relationship arises from the enquiry, the data are processed for as long as contractual and accounting obligations require.
2.2. Measuring website traffic
Purpose: measuring visits to the website and improving its content.
Legal basis: the data subject’s consent. The measurement code loads only if the visitor has given consent on the banner shown when the site is opened. Without consent, no measurement data are created and no request is sent to Google.
Data processed: data collected by the Google Analytics service (time of visit, pages viewed, technical data about the visitor’s device and browser, truncated IP address).
Duration: as configured in Google Analytics, at most 14 months.
Consent may be withdrawn at any time, without consequence, using the “Cookie settings” link in the footer of the website.
2.3. Protecting the form against automated abuse
Purpose: protecting the contact form against automated (robot) submissions.
Legal basis: the legitimate interest of the controller (Article 6(1)(f) GDPR) in maintaining the proper operation and security of the service. In our assessment this interest does not disproportionately restrict the rights of the data subject: the service operates only on the contact form, only while it is being used, and is not capable of identifying the data subject.
Data processed: technical data collected by the Google reCAPTCHA service, and the score returned by it. The reCAPTCHA script loads only when the visitor begins filling in the form; merely viewing the Contact page involves no transfer of data.
2.4. Processing necessary for the operation of the website
The website stores on the visitor’s device the chosen language, the choice of light or dark appearance, and the fact and time of the decision made about cookies. These data are strictly necessary to provide the service requested by the visitor, are not capable of identifying the visitor, and are not passed to any third party.
No automated decision-making, including profiling, takes place.
The service provider is not obliged to verify whether the data subject is entitled to provide the data given. Responsibility for this rests solely with the person providing the data.
3. Use of processors
The data are accessible to those staff acting within the controller’s sphere of interest who need them to carry out their duties and who are aware of their obligations regarding the processing of data.
The controller uses the following processors:
- Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) – measuring website traffic (Google Analytics), protecting the form (reCAPTCHA), and displaying the map embedded on the Contact page (Google Maps). The embedded map loads ONLY after cookies have been accepted; until then a static map image is shown in its place, served from the controller’s own hosting, which makes no request to Google. Once accepted, loading the map transmits the visitor’s IP address to Google and Google may place cookies on the visitor’s device. Use of the service may involve transfer of data outside the European Economic Area, to the United States. The legal basis for the transfer is the European Commission’s adequacy decision of 10 July 2023 concerning the EU–US Data Privacy Framework.
The website and its database run on the controller’s OWN hosting, so no separate hosting provider is engaged as a processor.
Messages received through the contact form are stored on the controller’s own hosting; they are not transferred to any third party for processing.
4. Rights of the data subject
In connection with the processing, the data subject has the following rights:
- the right to information,
- the right of access,
- the right to rectification,
- the right to erasure (“the right to be forgotten”),
- the right to restriction of processing,
- the right to object,
- the right to data portability,
- the right to withdraw consent,
- the right to lodge a complaint,
- the right to an effective judicial remedy.
Right to information. Before processing begins, and at the latest when the data subject’s personal data are obtained, the controller must inform the data subject in detail — of the information contained in this policy. Beyond this, information may be requested at any stage of the processing; in such a case the controller must respond without delay, and at the latest within 30 days. In justified cases this period may be extended by up to two months.
The controller may refuse to provide information only if it demonstrates that the data subject cannot be identified, or that the request is manifestly unfounded, repetitive or excessive. If it does not act, it must inform the data subject within 30 days of the reason, and of the right to lodge a complaint with the supervisory authority or to seek a judicial remedy.
Information and action are provided free of charge. Exceptionally — where a request is manifestly unfounded, repetitive or excessive — the controller may charge a reasonable fee or refuse to act.
Right of access. The data subject has the right to obtain confirmation as to whether their personal data are being processed and, if so, access to the data and to the following information: the purposes of the processing; the categories of personal data concerned; the recipients or categories of recipients, including recipients in third countries; the envisaged storage period; the right to rectification, erasure, restriction and objection; the right to lodge a complaint with a supervisory authority; the source of the data where they were not collected from the data subject; and the existence or absence of automated decision-making.
The controller provides a copy of the personal data undergoing processing. For further copies it may charge a reasonable fee based on administrative costs, of which the data subject is informed in advance. Where the request is made electronically, the information is provided in a commonly used electronic form, unless the data subject requests otherwise.
Right to rectification. The data subject may request the rectification without undue delay of inaccurate personal data concerning them and, taking into account the purposes of the processing, the completion of incomplete data, including by means of a supplementary statement.
Right to erasure. The data subject may request the erasure of their personal data where: the data are no longer necessary for the purposes for which they were collected; the data subject withdraws consent and there is no other legal ground; the data subject objects and there are no overriding legitimate grounds; the data have been unlawfully processed; or the data must be erased to comply with a legal obligation.
The controller is not obliged to comply with a request for erasure where processing is necessary for exercising the right of freedom of expression and information; for compliance with a legal obligation or the performance of a task carried out in the public interest; for archiving purposes in the public interest, scientific or historical research or statistical purposes; or for the establishment, exercise or defence of legal claims. In such a case the controller informs the data subject within 25 days of the circumstance and its reason.
Right to restriction of processing. The data subject may request restriction where they contest the accuracy of the data; where the processing is unlawful but they oppose erasure; where the controller no longer needs the data but the data subject requires them for legal claims; or where they have objected to the processing. Where processing is restricted, the data may — apart from storage — be processed only with the data subject’s consent, for legal claims, for the protection of the rights of others, or for reasons of important public interest. The controller informs the data subject before the restriction is lifted.
Notification obligation. The controller communicates any rectification, erasure or restriction to each recipient to whom the data have been disclosed, unless this proves impossible or involves disproportionate effort.
Right to data portability. Where processing is based on consent or on a contract and is carried out by automated means, the data subject has the right to receive the personal data they have provided in a structured, commonly used, machine-readable format, and to transmit those data to another controller. They may also request direct transmission where technically feasible. This right does not prejudice the right to erasure and must not adversely affect the rights and freedoms of others.
Right to object. The data subject may object at any time, on grounds relating to their particular situation, to the processing of their personal data. In such a case the controller may no longer process the data unless it demonstrates compelling legitimate grounds which override the interests, rights and freedoms of the data subject, or which relate to legal claims.
Right to withdraw consent. Where processing is based on consent, it may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before it. Consent to cookies may be withdrawn using the “Cookie settings” link in the footer; consent to other processing by sending a request to the email address given on the Contact page.
5. Remedies
Right to lodge a complaint. The data subject has the right to lodge a complaint with a supervisory authority — in particular in the Member State of their habitual residence, place of work or place of the alleged infringement — if they consider that the processing of their data infringes the law. In Hungary the competent supervisory authority is:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Registered office: 1055 Budapest, Falk Miksa utca 9–11., Hungary
Postal address: 1363 Budapest, Pf.: 9., Hungary
Telephone: +36 1 391 1400
Website: naih.hu
Email: [email protected]
Exercising the right to complain does not exclude other administrative or judicial remedies.
Judicial remedy against a decision of the supervisory authority. Where the authority has taken a decision, the data subject has the right to an effective judicial remedy against it. The same right applies where the authority does not handle the complaint or does not inform the data subject within three months of the progress of the proceedings. Proceedings must be brought before the courts of the Member State where the supervisory authority is established.
Judicial remedy against the controller. The data subject may bring proceedings before a court where they consider that their rights have been infringed as a result of unlawful processing of their personal data. Proceedings must be brought before the courts of the Member State where the controller has an establishment; in the case of Tervem Kft. this is Hungary, and the court with jurisdiction according to the registered office is the Budapest-Capital Regional Court (Fővárosi Törvényszék). Proceedings may also be brought before the courts of the Member State where the data subject has their habitual residence.
Compensation and damages. Where inadequate processing has caused damage to the data subject, the controller is liable for compensation. In the case of unlawful processing the data subject may also claim damages for non-material harm. Claims are to be brought primarily against the controller; a processor is liable only where it has breached the obligations specifically directed to processors, or has acted outside or contrary to lawful instructions of the controller.
6. Storage of personal data and security of processing
We select and use the information technology tools and solutions employed in our processing — in particular the security systems — so that the personal data processed are accessible to those authorised, their authenticity is assured, their integrity can be verified, and they are protected against unauthorised access.
Having regard to the current state of the art, we ensure the security of processing through technical, organisational and procedural measures that provide an appropriate level of protection. The administration interface of the website is password protected, and connections are encrypted.
7. Cookies used on the website
| Cookie / stored item | Purpose | Duration | Consent |
|---|---|---|---|
tervem_nyelv |
Remembering the chosen language | 1 year | Not required (necessary) |
tervem-tema |
Light or dark appearance | Until cleared by the visitor | Not required (necessary) |
tervem-suti-hozzajarulas |
Memory of the decision made about cookies | 12 months | Not required (necessary) |
_ga, _ga_* |
Google Analytics – traffic measurement | Up to 14 months | Required |
_GRECAPTCHA |
Google reCAPTCHA – protecting the form | 6 months | Legitimate interest, when the form is used |
TODO: to be completed – the date of this policy, as at go-live.