Privacy policy
1. Introduction
Geostone Kft. (hereinafter Geostone Kft., service provider, controller, the Company), as controller, recognises the content of this legal notice as binding upon itself.
The Company undertakes that all data processing related to its activities shall comply with the requirements set out in this policy and in the applicable legislation.
Geostone Kft. is the operator of the geostone.hu website.
Geostone Kft. reserves the right to amend this notice at any time. Naturally, it will inform its audience of any changes in due time.
Geostone Kft. is committed to protecting the personal data of its customers and partners and considers it of particular importance to respect its customers’ right to informational self-determination. The Controller treats personal data confidentially and takes all security, technical and organisational measures that guarantee the security of the data.
Geostone Kft. sets out below its data processing principles and presents the expectations it has formulated for itself as a controller and which it observes. Its data processing principles are in line with the applicable data protection legislation, in particular the following:
- 2011. évi CXII. törvény – az információs önrendelkezési jogról és az információszabadságról;
- 2013. évi V. törvény - a Polgári Törvénykönyvről (Ptk.);
- 2008. évi XLVIII. törvény – a gazdasági reklámtevékenység alapvető feltételeiről és egyes korlátairól (Grt.).
- 2001. évi CVIII. törvény (Ekertv.) - az elektronikus kereskedelmi szolgáltatások, valamint az információs társadalommal összefüggő szolgáltatások egyes kérdéseiről;
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: “GDPR”)
2. Definitions
- data subject: any specified natural person who is identified or – directly or indirectly – identifiable on the basis of personal data;
- personal data: any data relating to the data subject – in particular the data subject’s name, identifier, and one or more factors specific to the physical, physiological, mental, economic, cultural or social identity of that person – and any inference that can be drawn from such data concerning the data subject;
- consent: a voluntary and definite expression of the data subject’s wishes, based on appropriate information, by which the data subject gives unambiguous agreement to the processing of personal data relating to him or her – either in full or limited to specific operations;
- controller: the natural or legal person or organisation without legal personality which, alone or jointly with others, determines the purposes of processing, and takes and implements decisions concerning processing (including the means used), or has them implemented by the processor;
- processing: any operation or set of operations performed on data, regardless of the procedure applied, in particular collection, recording, organisation, storage, alteration, use, retrieval, transmission, disclosure, alignment or combination, blocking, erasure and destruction, as well as preventing further use of the data, taking photographs, audio or video recordings, and recording physical characteristics suitable for identifying a person (e.g. fingerprint or palm print, DNA sample, iris image);
- transfer of data: making the data available to a specified third party;
- disclosure: making the data available to anyone;
- erasure of data: making the data unrecognisable in such a way that their restoration is no longer possible;
- data processing (technical): the performance of technical tasks related to processing operations, regardless of the method and means used to carry out the operations and of the place of application, provided that the technical task is performed on the data;
- processor: the natural or legal person or organisation without legal personality which processes data under a contract – including a contract concluded on the basis of a legal provision.
3. Company details
Our company details and contact information are as follows:
- Name: Geostone Kft.
- Postal address: 2146 Mogyoród, Berektető út 185.
- Company registration number: 13 09 240751
- Tax number: 32823051-2-13
- Phone number: +36 30 167 8377
- E-mail: info@geostone.hu
- Representative of the controller: Gyürüs-Máder Mónika, managing director
4. Scope of personal data, purpose, legal basis and duration of processing
We draw the attention of persons providing data to Geostone Kft. that if they do not provide their own personal data, it is the duty of the person providing the data to obtain the data subject’s consent. The controller is not obliged to verify that such consent exists. The controller draws the partner’s attention to the fact that if the partner fails to fulfil this obligation and the data subject asserts a claim against the controller as a result, the controller may pass on the asserted claim and the related amount of damage to the partner.
We provide the following information in relation to our individual processing operations.
4.1. Quote request, enquiry by direct contact
Interested parties may contact the Company directly by electronic mail sent to the Company’s address, or by telephone.
- Purpose of processing: to maintain contact in order to facilitate communication between the data subject and the Company and to enable closer and more efficient cooperation.
- Legal basis of processing: legitimate interest – GDPR Article 6(1)(f)
- Scope of personal data processed: name of the person requesting a quote / contact person; e-mail address, phone number and other information provided by the data subject,
- Duration of processing: for 3 years after the quote validity period, or until the data subject objects
- Recipients of personal data: Except for the processor(s) specified in section 7, the controller does not transfer the data obtained to any third party. The recorded data may be accessed only by the Controller’s employees and the designated colleagues of the processor(s).
- Specification of the legitimate interest: the Company’s legitimate interest in processing the data subject’s data – direct marketing
- Data subjects concerned: partners and data subjects who enquire directly (e.g. by e-mail or telephone) about the Company’s services.
4.2. Quote request, enquiry via the website (geostone.hu)
Our company provides the opportunity for data subjects to request a quote electronically.
- Purpose of processing: to maintain contact in order to facilitate communication between the data subject and the Company and to enable closer and more efficient cooperation.
- Legal basis of processing: the data subject’s voluntary consent – GDPR Article 6(1)(a).
- Scope of personal data processed: name of the enquirer (first name, last name); e-mail address, phone number, company name and other information provided by the data subject.
- Duration of processing: for 3 years after the quote validity period, or until consent is withdrawn.
- Recipients of personal data: Except for the processor(s) specified in section 7, the controller does not transfer the data obtained to any third party. The recorded data may be accessed only by the Controller’s employees and the designated colleagues of the processor(s).
- Data subjects concerned: partners and data subjects who enquire via the website about the Company’s services and products.
4.3. Processing related to follow-up of quote requests
- Purpose of processing: the controller’s legitimate interest in keeping records of the data subject’s data beyond the quote validity period for the purpose of direct marketing
- Legal basis of processing: the controller’s legitimate interest, GDPR Article 6(1)(f),
- Scope of personal data processed: contact person’s last name and first name; phone number; e-mail address
- Recipients of personal data: Except for the processor(s) specified in section 7, the controller does not transfer the data obtained to any third party. The recorded data may be accessed only by the Controller’s employees and the designated colleagues of the processor(s).
- Duration of processing: until the data subject objects
- Specification of the legitimate interest: establishing business relationships with partners and persons requesting quotes, providing accurate information to data subjects. The Company’s legitimate interest in processing the data subject’s data – direct marketing
- Data subjects concerned: addressees of quotes previously issued by the Company and the contact person(s) named therein.
4.4. Newsletter registration
- Purpose of processing: sending e-mail newsletters that may also contain commercial advertising to interested parties, providing information on current news
- Legal basis of processing: the data subject’s prior, voluntary consent, GDPR Article 6(1)(a),
- Scope of personal data processed: name, e-mail address
- Duration of processing: until voluntary consent is withdrawn, or until unsubscription from the newsletter. The Company processes the data provided by the data subject until consent is withdrawn. Following withdrawal of consent, we will delete the processed data from our newsletter database within 7 days at the latest, and we will not send you newsletters thereafter.
- Recipients of personal data: Except for the processor(s) specified in section 7, the controller does not transfer the data obtained to any third party. The recorded data may be accessed only by the Controller’s employees and the designated colleagues of the processor(s). You may unsubscribe from the newsletter at any time by sending a letter to the Company at info@geostone.hu, or by clicking the unsubscribe icon in the newsletter.
- Data subjects concerned: partners and data subjects who subscribe to the Company’s electronic newsletter.
4.5. Newsletter data (for newsletters registered before 25 May 2018)
- Purpose of processing: sending e-mail newsletters that may also contain commercial advertising to interested parties, providing information on current news
- Legal basis of processing: the controller’s legitimate interest, GDPR Article 6(1)(f),
- Scope of personal data processed: name, e-mail address
- Duration of processing: until the data subject objects
- Specification of the legitimate interest: providing information that may also contain commercial advertising and business offers to data subjects who subscribed to the newsletter. The Company’s legitimate interest in processing the data subject’s data, direct marketing.
- Recipients of personal data: except for the processor(s) specified in section 7, the controller does not transfer the data obtained to any third party. The recorded data may be accessed only by the Controller’s employees and the designated colleagues of the processor(s). You may unsubscribe from the newsletter at any time by sending a letter to the Company at info@geostone.hu, or by clicking the unsubscribe icon in the newsletter.
- Data subjects concerned: partners and data subjects who subscribed to the Company’s electronic newsletter before 25 May 2018.
4.6. Camera system
Cameras operate on the premises operated by the controller for the personal and property security of data subjects and for other purposes. Information signs draw the attention of data subjects to their operation. The activities related to the operation of the camera system are set out in the site’s “Property protection camera data processing notice”, which is available at the site.
4.7. Processing related to ensuring the operation of information technology services
- Purpose of processing: Geostone Kft. may use so-called “cookies” (temporary markers) on its websites, which enable faster access to them. By “cookies” we mean information data that is active only during a given customer session and that is placed from the website onto the Customer’s computer for faster identification. The Customer may always request that cookies be disabled by modifying the browser settings; however, this disabling may slow down or prevent access to some parts of the site and the use of certain functions.
The session cookies used avoid the need to resort to other IT tools that are potentially harmful to the confidentiality of customers’ navigation and do not allow the identifying personal data to be obtained.
The user can delete the cookie from their own computer and can disable the use of cookies in their browser. Cookies can generally be managed in browsers under Tools/Settings, in the Privacy settings, under the name cookie or süti. - Legal basis of processing: The data subject’s (User’s) voluntary consent, GDPR Article 6(1)(a).
The User gives voluntary consent to processing by accepting the pop-up notice and declaration at the start of browsing the website, or by continuing to browse.
Scope of personal data processed: information technology processing covers the data required for the operation of the “cookies” used to operate the website and for the use of log files applied by the web hosting provider. - Duration of processing: until the session ends
- Recipients of personal data: Except for the processor(s) specified in section 7, the controller does not transfer the data obtained to any third party. The recorded data may be accessed only by the Controller’s employees and the designated colleagues of the processor(s).
- Data subjects concerned: Every User who visits the website, regardless of whether they use the services available on the website.
5. Other processing
We provide information on processing not listed in this notice at the time the data is collected. We inform our customers that certain authorities, bodies performing public tasks and courts may contact our company for the purpose of disclosing personal data. Our company will disclose personal data to these bodies – provided that the body concerned has specified the exact purpose and the scope of the data – only to the extent indispensable for achieving the purpose of the request, and only if fulfilment of the request is required by law.
6. Transfer of personal data to a third country or international organisation
The Company does not transfer your personal data referred to above to any third country or to any international organisation.
7. Information on the use of a processor
In the course of processing, the controller transfers the data to the processor(s) contracted with it for the performance of the contract.
Categories of recipients: system administration provider, accounting and payroll provider, server hosting, web hosting provider
8. Children
Our services are not intended for persons under 16 years of age, and we ask that persons under 16 years of age do not provide Personal data to the Controller.
If we become aware that we have collected personal data from a child under 16 years of age – with the exception of processing required by law – we will take the steps necessary to delete the data as soon as possible.
9. Automated decision-making
The Company does not apply automated decision-making in its processing procedures or data collection.
10. Method of storing personal data, security of processing
Our company’s IT systems and other data storage locations are at the registered office and on servers provided by the processor. Our company selects and operates the IT equipment used in the provision of the service for processing personal data so that the data processed:
- are accessible to those authorised to have access (availability);
- their authenticity and authentication are ensured (authenticity of processing);
- their unchanged state can be verified (data integrity);
- are protected against unauthorised access (confidentiality of data).
We pay particular attention to the security of the data, and we also take the technical and organisational measures and establish the procedural rules necessary to enforce the safeguards under the GDPR. We protect the data by appropriate measures in particular against unauthorised access, alteration, transmission, disclosure, erasure or destruction, as well as against accidental destruction, damage, and becoming inaccessible as a result of a change in the technology used.
The IT system and network of our company and our partners are protected against computer-assisted fraud, computer viruses, computer break-ins and attacks leading to denial of service. The operator also provides for security through server-level and application-level protection procedures. Daily backup of the data is in place. In order to avoid personal data breaches, our company takes every possible measure; should such an incident occur – in accordance with our incident management policy – we will act immediately to minimise the risks and to avert the damage.
11. Rights of data subjects, remedies
The data subject may request information on the processing of their personal data, and may request the rectification of their personal data, and – with the exception of mandatory processing – their erasure or withdrawal, and may exercise their right to data portability and to object, in the manner indicated at the time of data collection, or using the controller’s contact details above.
The rights and remedies of the data subject have been determined and communicated to data subjects on the basis of 2011. évi CXII. törvény and EU Regulation 2016/679.
The right to information, otherwise known as the data subject’s “right of access”: On the basis of 2011. évi CXII. törvény and Article 15 of EU Regulation 2016/679, upon the data subject’s request the Controller shall provide information
- on the data processed by it and the categories of personal data,
- on the purpose of processing,
- on the legal basis of processing,
- on the duration of processing,
- where applicable, on the duration of storage of the data, or, if that is not possible, on the criteria used to determine that duration,
- where applicable, if the data were not collected from the data subject, on any available information as to their source,
- where applicable, on automated decision-making, including profiling, as well as meaningful information about the logic involved and the significance of such processing, and
- the envisaged consequences for the data subject,
- on the processor’s details, if a processor is used, i. on the circumstances, effects of the personal data breach and the measures taken to remedy it, and
- in the event of transfer of the data subject’s personal data, on the legal basis, purpose and recipient of the transfer.
The information is free of charge if the person requesting information has not yet submitted an information request to the Controller in the current year concerning the same set of data. In other cases, a fee may be charged. Any fee already paid must be refunded if the data were processed unlawfully, or if the request for information led to rectification.
The Controller draws the attention of data subjects to the fact that information must be refused on the basis of 2011. évi CXII. törvény,
- if, on the basis of an act of law, an international treaty or a binding legal act of the European Union, the Controller receives personal data in such a way that the transferring controller indicates, at the same time as the transfer, a restriction of the rights of the data subject of the personal data as provided in the said Act, or another restriction of processing.
- in the interest of the external and internal security of the State, including national defence, national security, the prevention or prosecution of criminal offences, and the security of the execution of sentences, as well as in the economic or financial interest of the State or a municipality, in a significant economic or financial interest of the European Union, and for the purpose of preventing and detecting disciplinary and ethical offences related to the practice of professions, and breaches of labour law and occupational safety obligations – including in every case inspection and supervision – and also in the interest of protecting the rights of the data subject or of others.
The Controller is obliged to notify the Nemzeti Adatvédelmi és Információszabadság Hatóság annually, by 31 January of the year following the year in question, of refused information requests.
The right to rectification: The data subject is entitled to obtain from the Controller without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the data subject is entitled to have incomplete personal data completed, including by means of providing a supplementary statement. At the same time, if the personal data do not correspond to reality and the personal data corresponding to reality are available to the Controller, the Controller shall rectify the personal data as a matter of obligation, even without the data subject’s request.
The right to erasure, otherwise known as the “right to be forgotten”: The data subject is entitled to obtain from the Controller the erasure of personal data concerning him or her without undue delay, and the Controller is obliged to erase personal data concerning the data subject without undue delay, unless mandatory processing precludes this.
In addition to the above case, the Controller is obliged to erase the data on the basis of 2011. évi CXII. törvény and Regulation (EU) 2016/679 of the European Parliament and of the Council if
- the processing of the data is unlawful;
- the data are incomplete or incorrect – and this state cannot be lawfully remedied – provided that erasure is not precluded by law;
- the purpose of processing has ceased, or the statutory time limit for storage of the data has expired;
- it has been ordered by a court or the Authority.
- the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
- the data subject objects to the processing and there is no overriding legitimate ground for the processing;
- the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the Controller is subject;
- the personal data have been collected in relation to the offer of information society services referred to in Article 8(1) of EU Regulation 2016/679 offered directly to children.
Where the Controller has made the personal data public for any reason and is obliged to erase them pursuant to the above, taking account of available technology and the cost of implementation, the Controller shall take reasonable steps, including technical measures, to inform other controllers processing the data that the data subject has requested the erasure of any links to, or copy or replication of, those personal data.
The Controller draws the attention of data subjects to the limitations of the right to erasure or the “right to be forgotten” arising from the EU Regulation, which are as follows:
- exercising the right of freedom of expression and information;
- compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject, or the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- public interest in the area of public health;
- archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) of EU Regulation 2016/679, in so far as the right to erasure is likely to render impossible or seriously impair such processing; or
- the establishment, exercise or defence of legal claims.
The right to restriction of processing, otherwise known as the right to blocking: The data subject is entitled to obtain from the Controller restriction of processing.
If, on the basis of the information available, it may be assumed that erasure would harm the data subject’s legitimate interests, the data must be blocked. Personal data thus blocked may be processed only for as long as the processing purpose that precluded erasure of the personal data exists.
If the data subject contests the accuracy or correctness of the personal data, but the inaccuracy or incorrectness of the contested personal data cannot be clearly established, the data shall be blocked. In this case, the restriction applies for a period enabling the Controller to verify the accuracy of the personal data.
On the basis of the EU Regulation, the data must be blocked if
- the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead;
- the Controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims; or
- the data subject has objected to processing; in this case, the restriction applies pending the verification whether the legitimate grounds of the Controller override those of the data subject.
Where processing is subject to restriction (blocking), such personal data shall, with the exception of storage, only be processed with the data subject’s consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.
The Controller hereby specifically draws the attention of data subjects to the fact that the data subject’s right to rectification, erasure and blocking may be restricted by law in the interest of the external and internal security of the State, including national defence, national security, the prevention or prosecution of criminal offences, and the security of the execution of sentences, as well as in the economic or financial interest of the State or a municipality, in a significant economic or financial interest of the European Union, and for the purpose of preventing and detecting disciplinary and ethical offences related to the practice of professions, and breaches of labour law and occupational safety obligations – including in every case inspection and supervision – and also in the interest of protecting the rights of the data subject or of others.
The Controller shall, without undue delay, within a maximum of 30 days of receipt of the request, inform the data subject of the matters specified in the request, and/or rectify the data, and/or erase and/or restrict (block) the data, or take other steps in accordance with the request, if there is no ground precluding this.
The Controller shall notify the data subject in writing of the rectification, the erasure and the restriction of processing, and also all those to whom the data were previously transferred or disclosed for the purpose of processing. Upon the data subject’s request, the Controller shall inform the data subject of these recipients. Notification may be omitted if, having regard to the purpose of processing, it does not harm the data subject’s legitimate interest, or if the information proves impossible or would involve a disproportionate effort. The Controller is also obliged to notify the data subject in writing if the data subject’s exercise of rights cannot be realised for any reason, and is obliged to specify precisely the factual and legal grounds, as well as the remedies available to the data subject: the possibility of turning to the court and to the Nemzeti Adatvédelmi és Információszabadság Hatóság.
The “right to data portability”: The data subject is entitled to
- receive the personal data concerning him or her, which he or she has provided to the Controller, in a structured, commonly used and machine-readable format, and is also entitled to
- transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where:
- the processing is based on consent; and
- the processing is carried out by automated means.
In exercising the right to data portability, the data subject is entitled to have the personal data transmitted directly from one controller to another, where technically feasible.
Having regard to the processing carried out by the Controller, the conditions for exercising the right to data portability are not met (there is no automated processing), therefore the data subject cannot exercise this right.
The right to object: The data subject may object to the processing of their personal data – including profiling – if
- the processing (transfer) of personal data is necessary solely for the enforcement of the right or legitimate interest of the Controller or the data recipient, except in the case of mandatory processing;
- the use or transfer of personal data is for the purpose of direct marketing, public opinion research or scientific research;
- the exercise of the right to object is otherwise permitted by law.
The data subject may also object, on the basis of Article 21(3) of EU Regulation 2016/679, to the processing of personal data for the purpose of direct marketing, in which case the personal data may no longer be processed for this purpose.
Where personal data are processed for scientific or historical research purposes or statistical purposes, the data subject is entitled to object, on grounds relating to his or her particular situation, to processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
The Controller – with simultaneous suspension of processing – shall examine the objection within the shortest possible time, but not later than 30 days from submission of the request, and shall inform the applicant of the result in writing. If the applicant’s objection is well-founded, the Controller shall terminate processing – including further collection and transfer of data – and shall block the data, and shall notify of the objection and of the measures taken on the basis thereof all those to whom the personal data affected by the objection were previously transferred, who are obliged to take measures to enforce the right to object.
If the data subject disagrees with the Controller’s decision, or the Controller misses the referenced deadline, the data subject is entitled – within 30 days of communication thereof – to turn to the court.
The data subject has the right to object in connection with automated decision-making.
Enforcement of rights before the court: In the event of a violation of their rights, the data subject may turn to the court. The court shall proceed out of turn. It is for the Controller to prove that processing complies with the provisions of the law.
In the event of a violation of the right to informational self-determination, a report or complaint may be lodged with:
Nemzeti Adatvédelmi és Információszabadság Hatóság
Cím: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
Telefon: +36 (1) 391-1400, Fax: +36 (1) 391-1410
www: http://www.naih.hu
e-mail: ugyfelszolgalat@naih.hu