Privacy Policy

Purpose of the Privacy Policy

Szilvia Jámbor sole proprietor (1029 Budapest, Máriaremetei út 137.) hereinafter referred to as service provider, data controller, acknowledges the content of this legal notice as binding. The service provider commits to ensure that all data processing related to its activities complies with the requirements set forth in this policy and the applicable national legislation, as well as the legal acts of the European Union.

The data protection guidelines related to the data controller’s processing activities are continuously available at https://www.e-steem.hu/adatkezelesi-tajekoztato/. The data controller reserves the right to modify this notice at any time. The modifications to this notice shall take effect upon publication at the above address.

Szilvia Jámbor sole proprietor is committed to protecting the personal data of its clients and partners, and considers respecting clients’ right to informational self-determination of paramount importance. Szilvia Jámbor sole proprietor treats personal data confidentially and implements all security, technical, and organizational measures that guarantee the security of the data.

Data Controller Information:

Name: Szilvia Jámbor sole proprietor
Headquarters: 1029 Budapest, Máriaremetei út 137.
Tax number: 68916125-1-41
Registration number: 52433975
Email address: jamborszilvia@e-steem.hu

Data Processing Activities

3.1 Website Contact Form

Fact of data collection, scope of processed data and purpose of processing:

Personal DataPurpose of Processing
NameContact
Email addressContact

Scope of affected individuals: All individuals who fill out the contact form on the website.
Duration of data processing, deadline for data deletion: 1 year

3.2 Orders

Fact of data collection, scope of processed data and purpose of processing:

Personal DataPurpose of Processing
NameContact, proper invoice issuance
Email addressContact
Billing addressProper invoice issuance

Scope of affected individuals: All individuals who order services.
Duration of data processing, deadline for data deletion: 8 years for accounting documents according to Section 169 (2) of Act C of 2000 on Accounting.

3.3 Cookies

Purpose of cookies:

  • Collect information about visitors and their devices
  • Remember individual settings of visitors that may be used
  • Facilitate website usage
  • Provide quality user experience

For customized service, the service provider places a small data package (cookie) on the user’s computer and reads it back during later visits. If the browser returns a previously saved cookie, the cookie handler service provider has the ability to link the user’s current visit with previous ones, but only in relation to its own content.

Essential Session Cookies

The purpose of these cookies is to enable visitors to browse the e-steem.hu website seamlessly and use its functions and available services. This type of cookie remains valid until the end of the session (browsing), and is automatically deleted from the computer or other browsing device when the browser is closed.

Third-Party Cookies (Analytics)

The e-steem.hu website uses Google Analytics cookies. Using Google Analytics statistical service, the data controller collects information about how visitors use the website. The data is used for the purpose of improving website development and user experience. These cookies also remain on the visitor’s computer or browsing device until their expiration or until the visitor deletes them.

Retention period for user and event data collected by Google Analytics: 18 months

Data Processors

4.1 Hosting Provider

Activity performed by data processor: Hosting services

Data processor details and contact information:
Name: Versanus Informatikai és Szolgáltató Kft.
Headquarters: 1138 Budapest, Mura u. 4. 9. em. 7.
Website: www.versanus.eu

Fact of data processing, scope of processed data: All personal data provided by the affected individual.
Scope of affected individuals: All individuals using the website.
Purpose of data processing: Making the website accessible and ensuring proper operation.
Duration of data processing, deadline for data deletion: Until the termination of the agreement between the data controller and the hosting provider, or until the affected individual’s request for deletion to the hosting provider.

Legal basis for data processing: User consent, Section 5(1) of the Information Act, Article 6(1)(a), and Section 13/A(3) of Act CVIII of 2001 on certain issues of electronic commerce services and information society services.

4.2 Accounting

Activity performed by data processor: Accounting

Data processor details and contact information:
Name: Emília Vágner
Headquarters: 2013 Pomáz, Toldi Miklós u. 20.
Website: www.konyvelesobudan.hu

Fact of data processing, scope of processed data: Name and billing information provided by the affected individual.
Scope of affected individuals: All individuals who order services.
Purpose of data processing: Compliance with accounting laws.
Duration of data processing, deadline for data deletion: 8 years according to Section 169(2) of Act C of 2000 on Accounting.

Rights of Data Subjects

5.1 Right of Access

The data subject has the right to receive feedback from the data controller about whether their personal data is being processed, and if such processing is ongoing, they have the right to access the personal data and information listed in the regulation.

5.2 Right to Rectification

The data subject has the right to request that the data controller rectify inaccurate personal data concerning them without undue delay. Taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.

5.3 Right to Erasure

The data subject has the right to request that the data controller erase personal data concerning them without undue delay, and the data controller shall have the obligation to erase personal data without undue delay under certain conditions.

5.4 Right to be Forgotten

If the data controller has made the personal data public and is obliged to erase it, taking account of available technology and the cost of implementation, it shall take reasonable steps, including technical measures, to inform controllers processing the personal data that the data subject has requested the erasure of any links to, or copy or replication of, those personal data.

5.5 Right to Restriction of Processing

The data subject has the right to obtain from the data controller restriction of processing where one of the following applies:

  • The accuracy of the personal data is contested by the data subject
  • The processing is unlawful and the data subject opposes the erasure
  • The data controller no longer needs the personal data but the data subject requires them for legal claims
  • The data subject has objected to processing

5.6 Right to Data Portability

The data subject has the right to receive the personal data concerning them in a structured, commonly used and machine-readable format and has the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided.

5.7 Right to Object

The data subject has the right to object to processing of personal data concerning them which is based on public interest or legitimate interests, including profiling. In case of objection, the controller shall no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defense of legal claims.

5.8 Automated Individual Decision-Making, Including Profiling

The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.

Response Time

The data controller shall provide information on action taken on a request to the data subject without undue delay and in any event within one month of receipt of the request.

If needed, this period may be extended by two months. The data controller shall inform the data subject of any such extension within one month of receipt of the request, together with the reasons for the delay.

If the data controller does not take action on the request of the data subject, it shall inform the data subject without delay and at the latest within one month of receipt of the request of the reasons for not taking action and on the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.

Security of Processing

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.

Other Provisions

We shall provide information about data processing not listed in this notice at the time of data collection.
In exceptional cases of authority requests or legal authorization by other bodies, the Service Provider is obliged to provide information, communicate data, transfer data, or make documents available.
In these cases, the Service Provider shall only disclose personal data to the requester – if they have indicated the exact purpose and scope of data – to the extent and amount that is essential for the realization of the purpose of the request.

Data Breach Management

9.1 Informing the Data Subject of a Data Breach

When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.

The communication to the data subject shall describe in clear and plain language the nature of the personal data breach and contain at least the name and contact details of the data protection officer or other contact point, the likely consequences of the personal data breach, and the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects.

The communication to the data subject shall not be required if any of the following conditions are met:

  • The controller has implemented appropriate technical and organizational protection measures
  • The controller has taken subsequent measures which ensure that the high risk is no longer likely to materialize
  • It would involve disproportionate effort

9.2 Notifying the Authority of a Data Breach

The controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.

Complaint Options

In case of any potential legal violation by the data controller, a complaint can be filed with the National Authority for Data Protection and Freedom of Information:

National Authority for Data Protection and Freedom of Information
1125 Budapest, Szilágyi Erzsébet fasor 22/C.
Mailing address: 1530 Budapest, Postafiók: 5.
Phone: +36-1-391-1400
Fax: +36-1-391-1410
Email: ugyfelszolgalat@naih.hu