Information on the rights of natural persons concerned (data subjects) for clients, suppliers, and partners. Notice pursuant to Act CXII of 2011 on Informational Self-Determination and Freedom of Information, and the GDPR (EU 2016/679).

01

DETAILS OF THE DATA CONTROLLER

Company name: ÁRP Tuning Kereskedelmi és Szolgáltató Korlátolt Felelősségű Társaság

Short name: ÁRP Tuning Kft.
Registered office: 8000 Székesfehérvár, Nagyszombati u. 158.
Tax number: 14601594-2-07
Company registration number: 0709015740
Representative: Balázs Árpási, Managing Director
Website: www.arptuning.hu
Email: arptuning@gmail.com
Phone: +36 70 310 1996

02

PRINCIPLES OF PERSONAL DATA PROCESSING

In order to comply with Act CXII of 2011 on Informational Self-Determination and Freedom of Information, as well as REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data (General Data Protection Regulation – GDPR), our Company provides the following privacy notice set forth in the Regulation.

Based on statutory provisions, the Data Controller processes personal data in accordance with the principles of good faith, fairness, and transparency, and uses it strictly for specified purposes and in line with its intended scope.

The Data Controller takes all organizational and technical measures necessary to prevent unauthorized access to personal data and to hinder the accidental loss, alteration, or deletion of data.

If the Data Controller intends to use personal data for purposes other than the original purpose of collection, it shall obtain the explicit consent of the data subject.

The Data Controller does not verify personal data received from external sources pursuant to contracts or data provision. Sole responsibility for the accuracy and adequacy of the personal data provided rests with the person or entity providing it.

03

DEFINITIONS

“Personal data”: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

“Processing”: any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

“Data Controller”: the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

04

CONSENT-BASED DATA PROCESSING

Our Company does not carry out consent-based data processing—with the exception of our newsletter service and postal/email correspondence systems—and does not collect, store, or process such personal data. Any correspondence submitted electronically or in paper form to the Data Controller is also deemed to constitute consent-based processing.

In the case of submitted correspondence, a separate declaration of consent does not need to be requested, as the data subject has already granted consent by voluntarily sending the letter or email.

Should business operations warrant consent-based data processing, it may only commence with the approval of the head of the organizational unit, in compliance with statutory provisions, and following the prior written consent of the data subject.

LEGAL BASIS: Article 6(1)(a) GDPR – consent of the data subject

PURPOSE: Sending newsletters to introduce and promote the Company’s products and services

RECIPIENTS: Managing Director, Marketing Manager

DATA TRANSFER: Personal data is not transferred to third parties

RETENTION PERIOD: Until the data subject’s declaration of withdrawal (opt-out)

05

DATA PROCESSING BASED ON THE PERFORMANCE OF A CONTRACT

Under the legal basis of contract performance, the Company processes personal data of business partners contracted as customers or suppliers for the purposes of entering into, executing, and terminating contracts, as well as granting contractual discounts.

Prior to commencing processing, the natural person concerned must be informed that the data processing is based on the performance of a contract; this information may also be included directly within the contract. The data subject must also be informed of the transfer of their personal data to data processors.

Service and contractor agreements contain the personal data of the contracting parties, representatives, and contact persons. Our Company, as Data Controller, does not review the underlying legal basis of the data provided by the contracting partner.

SCOPE OF PROCESSED DATA

  • Contracting individual: name, home address, tax ID, phone number, email address, signature
  • Subcontractor, supplier: name, email address, phone number, home address / registered seat, signature
  • Client representative: representative’s name, phone number, email address, signature
  • Contact person: name, phone number, email address, signature

LEGAL BASIS: Article 6(1)(b) GDPR – performance of a contract

PURPOSE: Performance of contractual provisions, identification of contracting parties and contact persons

RECIPIENT: Managing Director

DATA TRANSFER: Accountant – fulfillment of mandatory administrative, reporting, and record-keeping obligations

RETENTION PERIOD: 8 years following the completion/performance of the contract; in the event of a legal dispute, until the resolution of the dispute

06

COMPLIANCE WITH TAX AND ACCOUNTING OBLIGATIONS

On the legal basis of compliance with a legal obligation, the Company processes statutory data of natural persons entering into business relations with it as buyers or suppliers, for the purpose of meeting tax and accounting obligations prescribed by law (bookkeeping, taxation). The processed data is determined pursuant to Sections 169 and 202 of Act CXXVII of 2007 on Value Added Tax, and Section 167 of Act C of 2000 on Accounting.

SCOPE OF PROCESSED DATA

  • Name, address
  • Designation of the person or entity ordering the economic transaction
  • The person authorizing payment and certifying the execution of the order
  • Depending on organizational structure, the signature of the auditor/controller
  • On inventory movement documents and cash management receipts: the recipient’s signature; on counter-receipts: the payer’s signature

LEGAL BASIS: Article 6(1)(c) GDPR – compliance with a legal obligation

PURPOSE: Compliance with legal obligations stipulated in relevant laws applicable to the Data Controller

RECIPIENT: Managing Director

DATA TRANSFER: Accountant – fulfillment of administrative, reporting, record-keeping, and statutory data disclosure obligations

RETENTION PERIOD: 8 years following the completion of the contract; in the event of a legal dispute, until the resolution of the dispute

07

DISBURSING AGENT (PAYER) DATA PROCESSING

On the legal basis of compliance with a legal obligation, the Company processes the personal data of data subjects—employees, their family members, employed persons, and other benefit recipients—required by tax laws for statutory tax and contribution obligations (assessment of tax, tax advance, and contributions; payroll calculation; social security and pension administration) with whom it maintains a disbursing agent relationship (Act CL of 2017 on the Rules of Taxation, Section 7(31)).

The scope of processed data is defined by Section 50 of the Rules of Taxation (Art.), particularly including:

  • Natural identification data of the individual (including previous names and titles)
  • Citizenship
  • Tax identification number
  • Social Security Number (TAJ number)

Where tax laws attach legal consequences thereto, the Company may process health data (Personal Income Tax Act, Section 40) and trade union membership data (Personal Income Tax Act, Section 47(2)(b)) of employees solely for the purpose of fulfilling tax and contribution obligations.

LEGAL BASIS: Article 6(1)(c) GDPR – compliance with a legal obligation

PURPOSE: Compliance with legal obligations set forth by legislation

RECIPIENTS: Managing Director

DATA TRANSFER: Accountant – fulfillment of administrative, reporting, record-keeping, and statutory data disclosure obligations

RETENTION PERIOD: 8 years following the completion of the contract; in the event of a legal dispute, until the resolution of the dispute

08

DATA PROCESSING BASED ON LEGITIMATE INTERESTS

DATA PROCESSING RELATED TO CONTRACT PERFORMANCE

Works contracts and service agreements contain the personal details of the contracting parties and their designated contact persons. Personal data provided by the client in contracts and other project documents prepared for fulfilling the undertaken scope of work must be regarded as processing based on the client’s or principal’s legitimate interest; the legal basis for this must be ensured by the client/principal, and its lawfulness cannot be examined by our Company.

DATA PROCESSING RELATED TO ASSET PROTECTION

In operational areas open to clients, as well as in material storage and equipment depots, the Company operates a closed-circuit television (CCTV) surveillance system to protect company assets and property. Notice boards notify individuals entering the monitored premises of the ongoing surveillance. Persons entering after acknowledging the warning—with the exception of the Company’s employees—give their implied consent to this data processing through their conclusive conduct.

LEGAL BASIS: Article 6(1)(f) GDPR – legitimate interests pursued by the data controller

PURPOSE: Transfer of employee contact details to the contractual partner for communication purposes; asset and property protection

RECIPIENTS: Managing Director

DATA TRANSFER: Accountant – administrative and statutory reporting obligations; Data Protection Officer – inspection, audit

RETENTION PERIOD: Until the 30th day following the recorded event; in the event of a legal dispute, until the resolution of the dispute

09

RIGHTS OF THE DATA SUBJECT

  • Right to prior information— to receive information concerning the facts and circumstances related to data processing prior to its commencement (Articles 13–14 of the Regulation).
  • Right of access— to obtain confirmation as to whether or not personal data concerning them is being processed, and access to that data along with related information (Article 15 of the Regulation).
  • Right to rectification— to request the correction of inaccurate personal data or completion of incomplete personal data without undue delay (Article 16 of the Regulation).
  • Right to erasure (“right to be forgotten”)— to request the erasure of personal data without undue delay where one of the grounds specified in the Regulation applies (Article 17 of the Regulation).
  • Right to restriction of processing— to request restriction of processing where conditions specified in the Regulation are met (Article 18 of the Regulation).
  • Notification obligation— the Data Controller communicates any rectification, erasure, or restriction of processing to each recipient (Article 19 of the Regulation).
  • Right to data portability— to receive personal data concerning them in a structured, commonly used, and machine-readable format, and transmit it to another controller (Article 20 of the Regulation).
  • Right to object— to object, on grounds relating to their particular situation, at any time to the processing of personal data based on point (e) or (f) of Article 6(1) of the Regulation (Article 21 of the Regulation).
  • Rights concerning automated individual decision-making— the right not to be subject to a decision based solely on automated processing which produces legal effects concerning them (Article 22 of the Regulation).
  • Communication of a personal data breach— when a breach is likely to result in a high risk, the Data Controller shall communicate the breach to the data subject without undue delay (Article 34 of the Regulation).
  • Right to lodge a complaint— to lodge a complaint with a supervisory authority if the processing of personal data infringes the Regulation (Article 77 of the Regulation).
  • Right to an effective judicial remedy— to pursue judicial remedies against a supervisory authority or a controller/processor (Articles 78–79 of the Regulation).

10

HANDLING DATA SUBJECT REQUESTS

Our Company shall provide information on action taken on a request to exercise these rights without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. The Data Controller shall inform the data subject of any such extension within one month of receipt of the request, together with the reasons for the delay.

Where the data subject makes the request by electronic form means, the information shall be provided by electronic means where possible, unless otherwise requested by the data subject.

If the Data Controller does not take action on the request of the data subject, it shall inform the data subject without delay and at the latest within one month of receipt of the request of the reasons for not taking action, and on the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.

Our Company provides requested information, communications, and actions taken free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the Data Controller may charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested.

Where our Company has reasonable doubts concerning the identity of the natural person making the request, it may request the provision of additional information necessary to confirm the identity of the data subject.

11

LODGING A COMPLAINT (NAIH)

In case of a complaint, the competent supervisory authority is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):

Address: 1055 Budapest, Falk Miksa utca 9-11.

Mailing address: 1363 Budapest, Pf. 9

Email: ugyfelszolgalat@naih.hu

Phone: +36 1 391 1400

Website: www.naih.hu