PRIVACY POLICY

WAM UN IT Color Gyártó, Ipari és Kereskedelmi Korlátolt Felelősségű Társaság provides information in this privacy policy regarding the data processing activities it carries out, in particular those relating to the use of the website, customer relations, business communications, marketing activities, sending newsletters, participation in events, and the processing of personal data in connection with the taking of photographs and video recordings.

The purpose of this policy is to provide data subjects with information on the processing of their personal data in a concise, transparent, understandable and easily accessible form.

WAM UN IT Color Kft. is committed to the protection of personal data and processes personal data exclusively in accordance with applicable legislation, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council – the General Data Protection Regulation, hereinafter: “GDPR” – and Act CXII of 2011 on the Right to Self-Determination in Information and Freedom of Information – hereinafter: “Info Act” –.

1. Details of the data controller

Name of the data controller: WAM UN IT Color Gyártó, Ipari és Kereskedelmi Korlátolt Felelősségű Társaság
Abbreviated name: WAM UN IT Color Kft.
Registered office: 7300 Komló, Somostető 0347.
Tax number: 13471150-2-02
Email address: info@wam-unitcolor.com
Telephone number: +36203853305
Website: https://www.unitcolor.hu/ and https://www.wam-unitcolor.com
Company registration number: 02-09-070018

In this policy, the data controller is hereinafter referred to as: Data Controller or Company.

2. Scope of this policy

This policy applies to all natural persons whose personal data is processed by the Data Controller, in particular:

  • visitors to the website(s);
  • prospective clients and enquiries;
  • customers, buyers and clients;
  • business partners’ contact persons;
  • newsletter subscribers;
  • participants in marketing campaigns, promotions and prize draws;
  • event registrants and event participants;
  • visitors to the Data Controller’s social media pages;
  • persons submitting complaints, requests or other enquiries.

3. Applicable legislation

The Data Controller’s data processing activities are governed in particular by the following legislation:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data “GDPR”;
  • Act CXII of 2011 on the right to informational self-determination and freedom of information “Info Act”;
  • Act V of 2013 on the Civil Code “Civil Code”;
  • Act C of 2000 on Accounting “Accounting Act”;
  • Act XLVIII of 2008 on the fundamental conditions and certain restrictions of commercial advertising activities “Grt.”;
  • Act CLV of 1997 on Consumer Protection “Consumer Protection Act”

The legal basis and duration of each data processing operation have been determined primarily on the basis of the following legislation:

  • “Art.” – Act CL of 2017 on the Rules of Taxation. The Data Controller is obliged to retain data serving as supporting documentation for tax records.
  • “Consumer Protection Act” means Act CLV of 1997 on consumer protection.
  • “GDPR”: the EU General Data Protection Regulation (Regulation (EU) 2016/679).
  • “Civil Code” – Act V of 2013 on the Civil Code. If the period of data processing is specified as the limitation period for enforcing the right to information, any act interrupting the limitation period extends the duration of data processing until the new date on which the limitation period expires (Civil Code, Section 6:25(2)). In the event of a suspension of the limitation period, the claim may be enforced within a period of one year from the cessation of the obstacle – or, in the case of a limitation period of one year or less, within three months – even if the limitation period has already expired or less than the above period remains (Civil Code, Section 6:24(2)).
  • “Accounting Act” – Act C of 2000 on Accounting. Certain data – for example, data forming part of the documents supporting the accounts, or contained in documents relating to the conclusion of a contract between the Data Controller and its contractual partner (e.g. in a supply contract or purchase order), appear in documents supporting the accounts or on the invoice issued – the Data Controller is obliged to retain in accordance with the Accounting Act.

4. Basic Terms

For the purposes of this policy:

Personal data: any information relating to an identified or identifiable natural person.
Data subject: the natural person whose personal data is processed by the Data Controller.
Data processing: any operation performed on personal data, in particular the collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, erasure or destruction thereof.
Data Controller: a natural or legal person who or which determines the purposes and means of data processing.
Data processor: a natural or legal person who or which processes personal data on behalf of the data controller.
Consent: a freely given, specific, informed and unambiguous indication of the data subject’s wishes.
Data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

5. Principles of data processing

The Data Controller shall observe the following principles when processing personal data:

  • lawfulness, fairness and transparency;
  • purpose limitation;
  • data minimisation;
  • accuracy;
  • storage limitation;
  • integrity and confidentiality;
  • accountability.

The Data Controller shall process personal data only for specified, explicit and legitimate purposes, and only to the extent and for the duration necessary to achieve those purposes.

6. Specific data processing activities
6.1. Data processing relating to website visits

Technical data may be processed during the use of the Data Controller’s website.

Scope of data processed:

  • IP address;
  • browser type;
  • type of device used;
  • operating system characteristics;
  • time of visit;
  • subpages visited;
  • click data;
  • cookie identifiers.

Purpose of data processing:

  • to ensure the proper functioning of the website;
  • to maintain IT security;
  • to prevent misuse;
  • compiling visitor statistics;
  • to improve the user experience.

Legal basis for data processing:

  • legitimate interest pursuant to Article 6(1)(f) of the GDPR for data technically necessary for the operation of the website;
  • in the case of non-essential cookies used for statistical or marketing purposes, the data subject’s consent pursuant to Article 6(1)(a) of the GDPR.

Duration of data processing:

  • up to 90 days for technical log data;
  • in the case of cookies, a period depending on the type of cookie in question;
  • in the case of data processing based on consent, until consent is withdrawn.

6.2. Use of cookies

The website may use cookies. A cookie is a small data file that the website places in the visitor’s browser, enabling the recognition of certain settings, sessions or visitor behaviour.

6.2.1. Technically necessary cookies

These cookies are essential for the website to function.

Purpose: to ensure the website’s basic functions, session management and secure operation.
Legal basis: legitimate interest pursuant to Article 6(1)(f) of the GDPR, and Section 13/A of the Eker. tv.
Duration: typically until the end of the browsing session or until the expiry of the relevant cookie.

6.2.2. Convenience / functional cookies

These cookies record the visitor’s settings.

Purpose: to improve the user experience and save settings.
Legal basis: consent of the data subject pursuant to Article 6(1)(a) of the GDPR.
Duration: until consent is withdrawn or the relevant cookie expires.

6.2.3. Statistical and marketing cookies

These cookies may assist in analysing and measuring website usage, as well as for advertising purposes.

Purpose: traffic analysis, remarketing, measuring the effectiveness of advertising campaigns.
Legal basis: data subject’s consent pursuant to Article 6(1)(a) of the GDPR.
Duration: until consent is withdrawn or the relevant cookie expires.

Visitors may also restrict or disable the use of cookies in their browser settings. If technically necessary cookies are disabled, certain features of the website may not function properly.

6.3. Requests for quotes, enquiries and contact

The Data Controller processes the personal data of enquirers, those requesting quotes and those initiating contact for the purpose of responding to enquiries and handling administrative matters.

Scope of data processed:

  • name;
  • email address;
  • telephone number;
  • company name;
  • job title;
  • message content;
  • request for a quote, subject of enquiry;
  • other data generated during communication.

Purpose of data processing:

  • establishing contact;
  • providing a quotation;
  • responding to enquiries;
  • business communication;
  • maintaining contact.

Legal basis for data processing:

  • taking steps prior to entering into a contract pursuant to Article 6(1)(b) of the GDPR;
  • in the case of business contacts, the Data Controller’s legitimate interest pursuant to Article 6(1)(f) of the GDPR;
  • in certain cases, the data subject’s consent pursuant to Article 6(1)(a) of the GDPR.

Duration of data processing:

  • up to 1 year from the closure of the enquiry;
  • in the event of a contract being concluded, in accordance with the contractual, accounting and legal retention periods;
  • in the case of data processing based on consent, until the consent is withdrawn.

6.4. Customer relations, purchases, fulfilment of orders

The Data Controller processes the data of buyers, customers and clients for the purposes of selling products, providing services, fulfilling orders, invoicing and maintaining contact.

Scope of data processed:

  • name;
  • home address or registered office;
  • billing address;
  • delivery address;
  • tax number;
  • email address;
  • telephone number;
  • name of the product or service purchased;
  • quantity;
  • price;
  • date and time of purchase or order;
  • payment details;
  • delivery details.

Purpose of data processing:

  • fulfilment of orders;
  • sale of products;
  • provision of services;
  • invoicing;
  • documenting payments;
  • fulfilling accounting obligations;
  • maintaining contact;
  • handling of complaints and claims;
  • submitting, enforcing or defending legal claims.

Legal basis for data processing:

  • performance of a contract pursuant to Article 6(1)(b) of the GDPR;
  • compliance with a legal obligation pursuant to Article 6(1)(c) of the GDPR;
  • legitimate interest pursuant to Article 6(1)(f) of the GDPR, in particular in the case of enforcing legal claims.

Duration of data processing:

  • in the case of contractual and contact details, until the end of the general civil law limitation period following the performance of the contract, generally 5 years;
  • in the case of accounting documents and supporting documents, for 8 years pursuant to Section 169 of the Accounting Act;
  • in the case of complaint handling data, until the retention period specified in the Fgytv., which is generally 3 years;
  • in the event of a legal claim, for the period necessary to enforce the claim.

6.5. Processing of contact details of business partners

In the course of maintaining contact with its business partners, the Data Controller processes the personal data of the partners’ contact persons.

Scope of data processed:

  • name of the contact person;
  • company name;
  • position;
  • work email address;
  • work telephone number;
  • content of correspondence.

Purpose of data processing:

  • maintaining business relations;
  • preparation and performance of contracts;
  • coordination of quotations, orders and fulfilment;
  • maintaining partner relationships.

Legal basis for data processing: the legitimate interests of the Data Controller and its business partner pursuant to Article 6(1)(f) of the GDPR.

Duration of data processing: for the duration of the business relationship or until the limitation period for any resulting legal claims expires, generally for 5 years.

6.6. Newsletter distribution and direct marketing

The data subject may subscribe to the Data Controller’s newsletter or consent to the Data Controller sending them electronic advertising messages.

Scope of data processed:

  • name;
  • email address;
  • telephone number, if contact is made via SMS or telephone;
  • date of consent;
  • source of consent;
  • date of unsubscription.

Purpose of data processing:

  • sending newsletters;
  • providing information about offers, special offers and promotions;
  • sending advertising messages relating to products and services;
  • conducting marketing campaigns.

Legal basis for data processing: the data subject’s voluntary, specific and explicit consent pursuant to Article 6(1)(a) of the GDPR and Section 6 of the Grt.

Duration of data processing: until consent is withdrawn or the data subject unsubscribes.

The data subject is entitled to unsubscribe from the newsletter or withdraw their consent for marketing purposes at any time. The withdrawal of consent does not affect the lawfulness of data processing prior to such withdrawal.

6.7. Promotions, activities, prize draws

The Data Controller may organise promotions, activities or prize draws during which it processes the personal data of participants.

Scope of data processed:

  • name;
  • email address;
  • telephone number;
  • home address or postal address;
  • company name;
  • areas of interest;
  • participation details;
  • in the event of a win, the details required to claim the prize;
  • tax identification number, if required by law;
  • documentation relating to the collection of the prize.

Purpose of data processing:

  • to organise a promotion or prize draw;
  • identification of participants;
  • maintaining contact;
  • notifying winners;
  • handing over prizes;
  • compliance with legal obligations.

Legal basis for data processing:

  • the data subject’s consent pursuant to Article 6(1)(a) of the GDPR;
  • compliance with a legal obligation pursuant to Article 6(1)(c) of the GDPR;
  • the Data Controller’s legitimate interest pursuant to Article 6(1)(f) of the GDPR, in particular for the proper conduct and documentation of the promotion.

Duration of data processing:

  • for 6 months following the conclusion of the promotion or prize draw;
  • in the case of legal or accounting obligations, for the period prescribed by law;
  • in the case of marketing data based on consent, until such consent is withdrawn.

The winner’s name and a photograph taken at the prize-giving ceremony may only be published with the data subject’s specific consent.

6.8. Registration for and participation in events

The Data Controller may organise events, professional meetings, presentations, training sessions or other events. In order to participate in an event, the data subject must provide certain personal data.

Scope of data processed:

  • full name;
  • email address;
  • telephone number;
  • company name;
  • job title;
  • name of event;
  • attendance details;
  • special requirements, if provided by the data subject.

Purpose of data processing:

  • recording registrations;
  • ensuring participation in the event;
  • keeping a register of participants;
  • maintaining contact;
  • sending information about the event;
  • carrying out admission and organisational tasks.

Legal basis for data processing:

  • the data subject’s consent pursuant to Article 6(1)(a) of the GDPR;
  • where applicable, the performance of a contract or the taking of steps prior to entering into a contract pursuant to Article 6(1)(b) of the GDPR;
  • the Data Controller’s legitimate interests pursuant to Article 6(1)(f) of the GDPR, in particular for the organisation and documentation of the event.

Duration of data processing:

  • up to 90 days from the end of the event;
  • in the event of a legal claim, until the claim becomes time-barred, generally for 5 years;
  • in the case of data processing for marketing purposes based on separate consent, until the consent is withdrawn.

If the data subject requests the erasure of the data necessary for participation prior to the event, this may render participation in the event impossible.

6.9. Taking photographs and making video recordings at events

Photographs, audio and video recordings may be made at the Data Controller’s events.

Scope of data processed:

  • the data subject’s image;
  • the data subject’s voice;
  • the data subject’s behaviour at the event;
  • name, email address and telephone number for identification and communication purposes.

Purpose of data processing:

  • documentation of the event;
  • communication regarding the Data Controller’s products, services and activities;
  • marketing and advertising activities;
  • social media posts;
  • use on the website, in publications and in information materials.

Legal basis for data processing:

  • in the case of individual or specific recordings, the data subject’s consent pursuant to Article 6(1)(a) of the GDPR and Section 2:48 of the Civil Code;
  • in the case of mass recordings or public appearances, recordings may be made and used without specific consent pursuant to Section 2:48 of the Civil Code, provided that this does not infringe the data subject’s rights to privacy.

Duration of data processing:

  • in the case of recordings made on the basis of consent, until such consent is withdrawn;
  • in the case of use for marketing purposes, until the purpose is fulfilled, but no later than the withdrawal of consent;
  • in the case of a legal claim, until the claim becomes time-barred, generally for 5 years.

The data subject acknowledges that the withdrawal of consent does not affect the lawfulness of data processing prior to the withdrawal. It is not always possible to fully recall publications, printed materials or content shared by third parties that have already been made public.

6.10. Use of social media platforms

The Data Controller may be present on social media platforms, in particular on Facebook, Instagram, YouTube, LinkedIn or other online platforms.

Scope of data processed:

  • username;
  • public profile data;
  • comments;
  • messages;
  • reactions;
  • shares;
  • other data provided publicly by the data subject.

Purpose of data processing:

  • maintaining contact;
  • providing information;
  • marketing communications;
  • management of social media pages;
  • responding to enquiries.

Legal basis for data processing:

  • the data subject’s consent through the use of the social media platform;
  • the Data Controller’s legitimate interest in maintaining social media communication pursuant to Article 6(1)(f) of the GDPR.

Social media platforms also carry out their own data processing. These are governed by the relevant platform’s own privacy policy.

6.11. Complaints handling, consumer enquiries

The Data Controller handles complaints, claims and consumer enquiries received by it.

Scope of data processed:

  • name;
  • address;
  • email address;
  • telephone number;
  • details of the complaint;
  • data relating to the purchase or service;
  • documents generated during the investigation of the complaint.

Purpose of data processing:

  • investigating the complaint;
  • handling consumer requests;
  • maintaining contact;
  • compliance with legal obligations;
  • enforcing or defending legal claims.

Legal basis for data processing:

  • compliance with a legal obligation pursuant to Article 6(1)(c) of the GDPR;
  • legitimate interest in the case of legal claims pursuant to Article 6(1)(f) of the GDPR.

Duration of data processing: in the case of a copy of the record of the complaint and the response thereto, generally 3 years under the Fgytv., or until the limitation period for the legal claim expires.

7. Data transfer

The Data Controller shall only transfer personal data to third parties in accordance with the law.

Data may be transferred in particular:

  • to authorities and courts pursuant to a legal obligation;
  • to accountants, legal advisers or other professional service providers;
  • to transport service providers;
  • to payment service providers;
  • to IT, hosting or newsletter providers;
  • to marketing or event organisation partners;
  • to third parties designated on the basis of the data subject’s specific consent.

Data transfer for newsletter or marketing purposes may only take place on the basis of the data subject’s separate, explicit consent.

Following the data transfer, the third party acting as an independent data controller shall be solely responsible for its own data processing activities.

8. Data processors

The Data Controller may engage data processors in the course of its data processing activities. Data processors may process personal data only in accordance with the Data Controller’s instructions.

Data processors may include, in particular:

  • hosting providers;
  • IT service providers;
  • website operators;
  • newsletter service providers;
  • accountants;
  • courier service or postal operator;
  • event organiser;
  • marketing agency;
  • payment service provider;
  • cloud-based service provider.

Specific list of data processors used:

Name of data processorRegistered officeActivity
UPS Magyarország Kft.2220 Vecsés, Lőrinci út 154. Airport City Logistic Park. Building G.Courier service
9. Persons authorised to access the data

Personal data may be accessed by the Data Controller’s employees, agents, senior officers and data processors to the extent necessary for the fulfilment of the specific data processing purpose.

The Data Controller treats personal data as confidential and does not make it available to unauthorised third parties.

10. Data security

The Data Controller shall ensure the security of personal data by taking appropriate technical and organisational measures.

The Data Controller shall protect the data in particular against:

  • unauthorised access;
  • alteration;
  • disclosure;
  • disclosure;
  • deletion or destruction;
  • accidental loss;
  • damage;
  • becoming inaccessible.

To ensure data security, the Data Controller, amongst other things:

  • implements access control;
  • uses password protection;
  • uses virus protection and firewalls as necessary;
  • regularly checks its IT systems;
  • requires its employees to maintain confidentiality;
  • enters into appropriate contracts with data processors;
  • endeavours to process data only for as long as necessary and within the necessary scope.

Complete security of data transmission over the internet cannot be guaranteed; however, the Data Controller shall take all reasonable measures to protect personal data.

11. Handling of data protection incidents

A data breach is any event resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data.

The Data Controller shall notify the National Authority for Data Protection and Freedom of Information of the data breach without undue delay, and where possible within 72 hours at the latest, if the breach is likely to pose a risk to the rights and freedoms of natural persons.

If the data breach is likely to pose a high risk to the rights and freedoms of data subjects, the Data Controller shall also inform the data subjects.

The Data Controller shall keep a record of data breaches. The record shall include the nature, date, circumstances and effects of the breach, the scope of the data and data subjects affected, and the measures taken.

12. Rights of data subjects

Data subjects are entitled to the following rights under the GDPR.

12.1. Right to information and access

The data subject has the right to request information as to whether the Data Controller is processing their personal data. If so, they have the right to access the personal data being processed and information relating to the processing.

The data subject is entitled to receive confirmation from the Data Controller as to whether their personal data is being processed. If such processing is taking place, the data subject is entitled to access their personal data and the following information:

  • the purposes of the processing;
  • the categories of personal data concerning the data subject;
  • the recipients or categories of recipients to whom the personal data have been or will be disclosed by the Data Controller, including, in particular, recipients in third countries or international organisations;
  • where applicable, the envisaged period for which the personal data will be stored, or, if this is not possible, the criteria used to determine that period;
  • the data subject’s right to request from the Data Controller the rectification, erasure or restriction of processing of personal data concerning him or her, and to object to the processing of such personal data;
  • the right to lodge a complaint with a supervisory authority; and
  • where the data have not been collected from the data subject, any available information as to their source.

Where personal data are transferred to a third country, the data subject shall have the right to be informed of the appropriate safeguards relating to the transfer.

The Data Controller shall provide the data subject with a copy of the personal data being processed. For any further copies requested by the data subject, the Data Controller may charge a reasonable fee based on administrative costs. If the data subject has submitted the request electronically, the information shall be provided in a commonly used electronic format, unless the data subject requests otherwise.

12.2. Right to rectification

The data subject may request the rectification of inaccurate personal data and the completion of incomplete data.

12.3. Right to erasure

The data subject may request the erasure of their personal data, in particular where:

  • the data is no longer necessary for the purposes for which it was processed;
  • the data subject withdraws their consent and there is no other legal basis;
  • the data subject objects to the processing and there are no overriding legitimate grounds;
  • the processing is unlawful;
  • the data must be erased pursuant to a legal obligation;
  • the data were collected in relation to information society services offered to children.

The right to erasure does not apply where the processing is necessary, for example:

  • the exercise of the right to freedom of expression and the right to information;
  • for compliance with a legal obligation;
  • for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes;
  • for the establishment, exercise or defence of legal claims.

12.4. The right to restriction of processing

The data subject may request the restriction of data processing if, for example:

  • they contest the accuracy of the data;
  • the processing is unlawful, but the data subject does not request the erasure of the data;
  • the Data Controller no longer needs the data, but the data subject requests its retention for legal claims;
  • the data subject has objected to the processing of the data.

12.5. Right to data portability

In the case of automated data processing based on consent or a contract, the data subject has the right to receive the personal data concerning them in a structured, commonly used and machine-readable format, or to request that it be transmitted to another data controller.

The data subject has the right to receive the personal data concerning him or her, which he or she has provided to the Data Controller, in a structured, commonly used and machine-readable format, and has the right to transmit those data to another data controller without hindrance, provided that:

  • the processing is based on consent or a contract; and
  • the processing is carried out by automated means.

In exercising the right to data portability, the data subject is also entitled – where technically feasible – to request the direct transfer of personal data from one data controller to another (i.e. from the Data Controller to another data controller).

The exercise of the above right does not affect the provisions relating to the right to erasure (‘the right to be forgotten’), and the right to data portability must not infringe upon the rights and freedoms of others.

12.6. Right to object

The data subject has the right to object to the processing of their personal data if the legal basis for the processing is the legitimate interests of the Data Controller or a third party, the performance of a task carried out in the public interest, or the exercise of official authority. In the case of data processing for direct marketing purposes, the data subject may object at any time, in which case the data may no longer be processed for that purpose.

The data subject has the right to object at any time, on grounds relating to their particular situation, to the processing of their personal data based on legitimate interests. In this case, the Data Controller shall no longer process the personal data, unless it demonstrates compelling legitimate grounds for the processing which override the data subject’s interests, rights and freedoms, or which are related to the establishment, exercise or defence of legal claims.

Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to the processing of personal data concerning him or her for such purposes, including profiling to the extent that it is related to such direct marketing.

Where the data subject objects to the processing of personal data for direct marketing purposes, the personal data shall no longer be processed for such purposes.

In relation to the use of information society services and by way of derogation from Directive 2002/58/EC, the data subject may exercise the right to object by automated means using technical specifications.

Where personal data are processed for scientific or historical research purposes or for statistical purposes, the data subject shall have the right to object, on grounds relating to his or her particular situation, to the processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out for reasons of public interest.

12.7. Right to withdraw consent

Where processing is based on consent, the data subject has the right to withdraw their consent at any time.

The withdrawal of consent does not affect the lawfulness of data processing prior to the withdrawal.

12.8. Right to object to automated decision-making

The data subject has the right not to be subject to a decision based solely on automated processing which produces legal effects concerning him or her or similarly significantly affects him or her.

As a general rule, the Data Controller does not use such automated decision-making in the data processing operations covered by this policy.

13. Handling of data subject requests

The data subject may submit their request using the contact details provided in point 1.

The Data Controller shall respond to the data subject’s request without undue delay, but no later than one month from receipt of the request.

If necessary, taking into account the complexity of the request and the number of requests, this deadline may be extended by a further two months. The Data Controller shall inform the data subject of any extension of the deadline within one month of receiving the request.

As a general rule, the exercise of data subjects’ rights is free of charge. If the request is manifestly unfounded or excessive, in particular because of its repetitive nature, the Data Controller may charge a reasonable fee or refuse to comply with the request.

14. Remedies

The data subjects’ data protection rights and remedies are set out in detail in the relevant provisions of the GDPR (in particular Articles 15, 16, 17, 18, 19, 20, 21, 22, 77, 78, 79, 80 and 82 of the GDPR). The summary below sets out the most important provisions, and the Data Controller shall accordingly provide data subjects with information regarding their rights and remedies in relation to data processing.

The Data Controller shall inform the data subject of the measures taken in response to their request without undue delay, but in any event within one month of receipt of the data subject’s request relating to the exercise of their rights (see Articles 15–22 of the GDPR). If necessary, taking into account the complexity of the request and the number of requests, this time limit may be extended by a further two months. The Data Controller shall inform the data subject of any extension of the time limit within one month of receipt of the request, stating the reasons for the delay.

The information must be provided in writing or by other means, including, where appropriate, by electronic means. At the data subject’s request, the information may also be provided orally, provided that the data subject’s identity has been verified by other means. If the data subject has submitted the request by electronic means, the information shall be provided by electronic means where possible, unless the data subject requests otherwise.

If the Data Controller does not take action in response to the data subject’s request, it shall inform the data subject without delay, and at the latest within one month of receiving the request, of the reasons for not taking action, and of the data subject’s right to lodge a complaint with a supervisory authority and to seek judicial remedy.

It may be advisable to send the complaint to the Data Controller before initiating any proceedings.

If the data subject considers that the processing of their personal data is unlawful, they may first contact the Data Controller using the contact details provided in point 1.

The data subject is entitled to lodge a complaint with the supervisory authority:

National Authority for Data Protection and Freedom of Information
Registered office: 1055 Budapest, Falk Miksa utca 9–11.
Postal address: 1363 Budapest, PO Box 9
Telephone: +36 1 391 1400
Fax: +36 1 391 1410
Email: ugyfelszolgalat@naih.hu
Website: naih.hu

You may also apply to the relevant court. You may bring the action before the court of your place of residence or domicile, at your discretion.

15. Other provisions

The Data Controller reserves the right to amend this privacy policy. The current version of the policy is available on the Data Controller’s website or on the platform designated by the Data Controller.

In matters not covered by this policy, the provisions of the GDPR, the Info Act and other relevant legislation shall apply.

WAM UN IT Color Kft.