Privacy and Data Processing Policy

PRIVACY AND DATA PROCESSING NOTICE

I. Purpose and Scope of the Prospectus

    1. The purpose of this Prospectus is to set forth the P-Max Technology, Limited Liability Company (12786217-2-19; company registration number: Cg. 19-09-506270), as well as the company’s data protection and processing policy, which the company, as the data controller, acknowledges as binding upon itself.

    1. The General Purpose of the GDPR the fundamental rights and freedoms of natural persons, and in particular their right to the protection of personal data, while at the same time ensuring the free flow of personal data within the EU. (Article 1) To this end, the Data Controller establishes a set of rules governing the processing of personal data and the flow of data, one of the most important elements of which is placing the responsibility of the data controller—whether a private or public entity—at the forefront. The principles of data protection must be applied to all information relating to any identified or identifiable natural person.

    1. This Privacy Notice sets forth the principles governing the processing of Personal Data provided by Customers.

    1. Scope of the Regulation It covers „the processing of personal data, whether fully or partially automated, as well as the non-automated processing of personal data that forms part of a filing system or is intended to form part of a filing system.”

    1. Legal basis for the processing of personal data: voluntary consent.

    1. In drafting the provisions of this Privacy Notice, the company paid particular attention to Regulation (EU) 2016/679 of the European Parliament and of the Council („General Data Protection Regulation” or „GDPR”), Act CXII of 2011 on the Right to Information Self-Determination and Freedom of Information („Infotv.”), Act V of 2013 on the Civil Code („Ptk.”), as well as the provisions of Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions of Commercial Advertising Activities („Grtv.”).

    1. Personal data may be processed only if the purpose of the processing cannot reasonably be achieved by other means

II. Legal Basis for Data Processing

Authorization must be assessed on a case-by-case basis according to the legal basis and the specific data; this Data Controller may have a legal basis in the following cases:

– the processing is necessary for the purposes of the legitimate interests pursued by the data controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

III. Definitions

3.1 Data Processing: regardless of the procedure used, any operation or set of operations performed on Personal Data, including, in particular, the collection, recording, organization, structuring, storage, adaptation, alteration, use, retrieval, accessing, using, disclosing, transmitting, disseminating, or otherwise making available, publishing, coordinating or linking, restricting, erasing, and destroying Personal Data.

3.2 Data Controller: who determines the purposes and means of data processing—either independently or jointly with others. The data processing activities described in this Notice constitute data processing as defined by the GDPR, and the Data Controller is responsible for the data processing it carries out.

3.3 Personal information or data: any data or information that can be used to identify a natural person—either directly or indirectly—as a Customer.

3.4 Website(s): the Facebook page operated by the Data Controller.

3.5 Service(s): Services operated by the Data Controller and services provided by the Data Controller.

3.6 Client: a natural person who registers for the Services and, as part of that process, provides the information listed in Section VI below.

3.7 Information Sheet: This Data Controller’s Privacy Notice.

3.8. right to erasure

The data subject has the right to request that the data controller erase personal data concerning him or her without undue delay, and the data controller is required to erase personal data concerning the data subject without undue delay—among other things—if

  1. the personal data is no longer necessary for the purpose for which it was collected or otherwise processed

  2. the data subject withdraws his or her consent and there is no legitimate reason for data processing that takes precedence

Such a lawful basis may include the fulfillment of an obligation under Union or Member State law applicable to the data controller that requires the processing of personal data, for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller, for archiving purposes in the public interest, for scientific or historical research purposes, or for statistical purposes.

This is only the case when This does not apply if the necessity of further data processing can be justified on one of the grounds specified in Article 17 of the Regulation. (Obligation to report and retain data for official bodies—NYUFIG, KSH, etc.)

3.9. Verifiable voluntary consent:

Consent is considered voluntary if it allows for separate consent to be given for different personal data processing operations.

IV. Scope of Processed Personal Data

    1. If the Customer uses the Service, the Data Controller will process the Customer’s data to the extent and for the duration necessary to provide the Service.

    1. In accordance with the above, the following personal data will be collected by the Data Controller during the registration process:

– ID card number (or photo ID number)

– photograph

– birth information

– address

-tax ID number

V. Provision of the Customer’s Personal Information or Data

5.1. Data processing is based on the Customer’s voluntary, prior declaration made with adequate information, which includes the Customer’s express consent to the use of the Personal Data provided by the Customer as well as the Personal Data generated about them, be used. In the case of data processing based on consent, the Customer is entitled to withdraw their consent at any time; however, this does not affect the lawfulness of the data processing that took place prior to the withdrawal.

5.2 The disclosure of personal data to third parties or public authorities—unless otherwise provided by law—is permitted only on the basis of an official decision or with the Client’s prior, express consent.

5.3. The Customer warrants that it has lawfully obtained the consent of the natural persons concerned for the processing of any personal data regarding other natural persons that the Customer provides or makes available while using the Services. The Customer bears full responsibility for any user content uploaded or shared by the Customer on the Services (social media sites).

VI. Principles and Methods of Data Processing

6.1. The Data Controller processes Personal Data in accordance with the principles of good faith, fairness, and transparency, as well as applicable laws and the provisions of this Notice.

6.2 The Data Controller uses the Personal Data that is strictly necessary for the use of the Services based on the consent of the affected Customer and solely for the specified purpose.

6.3 The Data Controller processes Personal Data only for the purposes specified in this Notice and in the applicable laws. The scope of the Personal Data processed is proportionate to the purpose of the data processing and may not exceed it. In any case where the Data Controller intends to use Personal Data for a purpose other than the original purpose of data collection, it shall inform the Customer thereof and obtain the Customer’s prior, explicit consent, or provide the Customer with the opportunity to prohibit such use.

6.4 The Data Controller does not verify the Personal Data provided. The person providing the Personal Data is solely responsible for its accuracy.

6.5 The personal data of a data subject under the age of 16 may be processed only with the consent of the adult exercising parental authority over that person.. The Data Controller is not in a position to verify the consenting individual’s eligibility or the content of their statement; therefore, the Customer or the person exercising parental authority over the Customer guarantees that the consent complies with the law. In the absence of a consent statement, the Data Controller will not collect Personal Data concerning data subjects under the age of 16.

6.6. The Plant

For security reasons, persons under the age of 14 are not permitted to be present in this area, even as accompanying persons.

6.7 The Data Controller shall not disclose the Personal Data it processes to any third party. An exception to the provision set forth in this section is the use of data in statistically aggregated form, which may not contain any other data capable of identifying the affected Customer in any form; as such, it does not constitute Data Processing or data transfer. In certain cases—such as an official court or police request, legal proceedings, a financial or other legal violation, or a well-founded suspicion thereof, a breach of the Data Controller’s interests, a threat to the provision of the Services, etc.— — may make the available Personal Data of the affected Customer accessible to third parties.

6.8 The Data Controller shall notify the affected Customer, as well as all those to whom the Personal Data was previously disclosed for the purposes of Data Processing, of any rectification, restriction, or erasure of the Personal Data it processes. Such notification may be omitted if, in light of the purpose of the Data Processing, it does not infringe upon the legitimate interests of the data subject.

6.9 The Data Controller shall ensure the security of Personal Data, take the necessary technical and organizational measures, and establish the necessary procedural rules to ensure that the data collected, stored, and processed are protected, and to prevent their accidental loss, unlawful destruction, unauthorized access, unauthorized use, unauthorized alteration, and unauthorized disclosure. To fulfill this obligation, the Data Controller requires all third parties to whom it transfers Personal Data to comply with these measures.

6.10 In light of the relevant provisions of the GDPR, the Data Controller is not required to appoint a data protection officer.

VII. Duration of Data Processing

7.1. Security camera footage:

The camera system operates 24 hours a day, seven days a week, and records data in real time.

Location where the recording is stored: The data controller's secure electronic system

Retention period: Section 31(2) of Act CXXXIII of 2005 (in the absence of use, the 3 business days from the date of admission)

Person authorized to access the data: managing director

Method of data processing: electronically and automatically.

Source of data: directly from the individual concerned.

Disclosure of Data: Data is disclosed to third parties only in cases specified by law.

Organizational and technical measures to protect the data being processed: see the camera policy for details.

7.2. The processing of Personal Data provided by the Customer shall continue until the Customer unsubscribes from the Service, ceases to use it, or otherwise requests the deletion of such Personal Data. In the latter case, the Personal Data will be deleted from the Data Controller’s systems.

7.3. In the event of unlawful or misleading use of Personal Data, or in the event of a criminal offense committed by the Customer, the Data Controller is entitled to immediately delete the Customer’s Personal Data, however, in the event of suspected criminal activity or civil liability, the Data Controller is also entitled to retain the Personal Data for the duration of the proceedings.

7.4. If the Customer has withdrawn their consent to the processing of their Personal Data or no longer wishes to use the Service, their identity —excluding investigative authorities and their experts—will no longer be identifiable.

7.5 If a court or authority issues a final order requiring the erasure of Personal Data, the Data Controller shall carry out the erasure. Instead of erasure, the Data Controller—after informing the Customer—shall restrict the use of the Personal Data if the Customer so requests, or if, based on the information available to it, it can be presumed that erasure would infringe upon the Customer’s legitimate interests. The Data Controller will not erase the Personal Data as long as the purpose of data processing that precluded the erasure of the Personal Data remains in effect.

VIII. The Client’s Rights and How to Enforce Them

8.1 The Customer may request that the Data Controller inform the Customer whether it is processing the Customer’s personal data and, if so, grant the Customer access to the personal data it is processing.

Notwithstanding the foregoing, the User may request information regarding the processing of their Personal Data at any time in writing, by registered mail or certified mail with return receipt requested sent to the Data Controller’s address, or by email sent to ……………….. The Data Controller will consider a request for information sent by mail to be authentic only if the Customer can be clearly identified based on the submitted request.

The Data Controller will consider a request for information sent by email to be valid only if it is sent from the Customer’s registered email address; however, this does not preclude the Data Controller from verifying the Customer’s identity by other means before providing the information.

The request for information may cover the Customer’s data processed by the Data Controller, the source of such data, the purpose, legal basis, and duration of the data processing, the names and addresses of any data processors, activities related to the data processing, and, in the event of the transfer of personal data, information regarding who received or will receive the Customer’s data and for what purpose.

8.2 The Customer may request the correction or modification of their Personal Data processed by the Data Controller. Taking into account the purpose of the Data Processing, the Customer may request that incomplete Personal Data be supplemented.

8.3. Once a request to modify personal data has been fulfilled, the previous (deleted) data cannot be restored.

8.4. The Customer may request the erasure of their Personal Data processed by the Data Controller. The erasure may be refused if the processing of the Personal Data is authorized by law; or if it is necessary for the establishment, exercise, or defense of legal claims. In all cases, the Data Controller shall inform the Customer of the refusal to delete the data, specifying the reason for the refusal.

8.5. The Customer may request that the Data Controller restrict the processing of his or her Personal Data if the Customer disputes the accuracy of the Personal Data being processed. In this case, the restriction applies for a period that allows the Data Controller to verify the accuracy of the Personal Data. The Data Controller shall mark the Personal Data it processes if the Customer disputes its correctness or accuracy, but the incorrectness or inaccuracy of the disputed Personal Data cannot be clearly established.

The Customer may request that the Data Controller restrict the processing of their Personal Data even if the processing is unlawful, but the Customer objects to the erasure of the processed Personal Data and instead requests that its use be restricted. The Customer may also request that the Data Controller restrict the processing of their Personal Data if the purpose of the Data Processing has been fulfilled, but the Customer requires the Data Controller to continue processing such data for the purpose of asserting, exercising, or defending legal claims.

8.6. The Customer may request that the Data Controller provide the Customer with the processed Personal Data made available by the Customer in a structured, commonly used, machine-readable format and/or transfer such data to another data controller.

8.7. The Customer may object to the processing of his or her Personal Data

– if the processing of personal data is necessary solely to comply with a legal obligation to which the data controller is subject or to protect the legitimate interests of the data controller or a third party;

– if the purpose of the data processing is direct marketing, public opinion polling, or scientific research;

– or if the Data Processing is carried out for the performance of a task carried out in the public interest. The Data Controller shall examine the lawfulness of the Customer’s objection, and if it determines that the objection is well-founded, it shall cease the Data Processing and block the Personal Data being processed, and will notify all parties to whom the Personal Data subject to the objection were previously disclosed of the objection and the measures taken in response.

IX. Data Breach

9.1 Handling Data Breaches

As soon as the Data Controller becomes aware of a data breach, it must, without undue delay and, if possible, no later than 72 hours after becoming aware of the data breach, notify the competent supervisory authority, unless, in accordance with the principle of accountability, it can demonstrate that the data breach is unlikely to pose a risk to the rights and freedoms of natural persons.

To fulfill this obligation, it is necessary to establish a policy or set of procedures for handling and reporting data breaches.

9.2. Record-keeping

To demonstrate compliance with this regulation, the data controller shall maintain records of the data processing activities carried out within the scope of its authority.

X. Data Processing

10.1. The Data Controller does not disclose its Customers’ data to a Data Processor.

XI. Third-Party Service Providers

11.1 The Data Controller does not use third-party service providers in connection with the provision of the Services.

XII. Possibility of Data Transfer

12.1 The Data Controller is entitled and obligated to disclose to the competent authorities any Personal Data in its possession that it has lawfully stored, where the Data Controller is required to disclose such Personal Data by law or by a final and binding official order. The Data Controller shall not be held liable for such data transfers or the consequences arising therefrom.

XIII. Amendments to the Privacy Policy

13.1 The Data Controller reserves the right to amend this Notice at any time by its own decision.

13.2 The Customer agrees to abide by the provisions of the Information Bulletin in effect at that time the next time the Customer uses the Service

XIV. Remedies

14.1 If you have any questions or comments regarding data processing, please contact a representative of the Data Controller at the email address ……………… .

14.2 The Customer may submit complaints regarding data processing directly to the National Authority for Data Protection and Freedom of Information (address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c; phone: +36-1-391-1400; email: ugyfelszolgalat@naih.hu; website: www.naih.hu).

14.3 In the event of a violation of the Customer’s rights, the Customer may bring a lawsuit. The court has jurisdiction over the case. The lawsuit may also be filed—at the Customer’s discretion—with the court having jurisdiction over the Customer’s place of residence or place of stay. Upon request, the Data Controller shall inform the Customer of the available legal remedies.

APPENDICES

Appendix 1

Data Request Form for the Processing of Personal Data Based on Consent

Appendix 2

Privacy Notice Regarding the Rights of Data Subjects in Connection with the Processing of Their Personal Data

Appendix 3

Notice Regarding the Processing of Employees’ Personal Data and Their Rights

Appendix 4

Information for Employees Regarding Their Fitness Evaluation

Appendix 5

Visitor Information on the Use of the Video Surveillance System

Appendix 6

Data Processing Clause for a Contract with a Natural Person

Appendix 7

Consent Form for the Processing of Contact Information for Representatives of Natural Persons of Legal Entity Contracting Parties

Appendix 8

Confidentiality Agreement for Employees of the Data Processor

Appendix 9.a

General Terms and Conditions for Data Processing Activities – Standard

Appendix 9.b

General Terms and Conditions for Data Processing Services – For Accounting Firms

Appendix 10

Employment Contract Provision Regarding Familiarization with and Compliance with the Privacy Policy and the Obligation of Confidentiality

Balatonfűzfő, ………………, 2018

P-Max Technology, Ltd.

Representative: Miklós Németh, Managing Director

__________________________________
employer

INFORMATION SHEET

Regarding the fitness examination for an employee

I.

An employee may only be subject to an aptitude test that is required by a rule governing the employment relationship or that is necessary for the exercise of a right or the fulfillment of an obligation specified in a rule governing the employment relationship. Prior to the assessment, employees must be provided with detailed information, including which skills and abilities the fitness-for-duty assessment is intended to evaluate, and what tools and methods will be used to conduct the assessment. If the assessment is required by law, employees must be informed of the title of the law and the specific statutory provision.

II.

The legislation requiring the fitness examination is Decree No. 33/1998 (VI. 24.) of the Ministry of Health on Medical Examinations and Assessments of Job, Professional, and Personal Hygiene Fitness.

For the purposes of this regulation:

a) job suitability assessment:determining the level of physical strain imposed on the person being evaluated by the activities performed in a specific job and at a specific workplace, and whether the person is capable of meeting those demands;

b) professional aptitude test:a medical examination conducted prior to beginning training in the profession, or during the training or retraining period, for the purpose of assessing fitness for the profession;

c) personal hygiene screening:to determine that an infectious disease in a person working in a high-risk area from an epidemiological perspective does not pose a threat to the health of others, or, in certain cases, that the person’s status as a carrier of a pathogen does not pose a threat to the health of others;

d) person performing work:anyone who, outside the context of organized work, carries out activities in a work area designated as a high-risk area from an epidemiological perspective;

Section 3 of the Regulation specifies which skills and abilities the aptitude test is designed to assess:

Section 3(1) Assessment of suitability:

a)in the case of job suitability, for the position specified by the employer,

b)in the case of professional qualifications, the specific occupation or vocational training; in the case of job seekers, vocational training, retraining, or the identification of occupational groups or occupations suitable for the individual,

c)in the case of personal hygiene compliance, for activities carried out in work areas of high epidemiological significance

is happening.

(2) Medical examinations of job suitability and professional fitness may be preliminary, periodic, or special. The examination and assessment of job suitability shall be supplemented by a final examination in the cases specified in Section 8. For students applying to a vocational training institution, a school medical examination may be conducted at the time of enrollment—at the request of the teacher, parent, or student—for the purpose of career counseling.

(3) Personal hygiene fitness examinations may be preliminary, periodic, or unscheduled.

(4) The purpose of the job and professional aptitude assessment is to determine whether the employee, student, or job seeker:

a)wear and tear caused by the physical demands of the work and the work environment

aa)whether it poses a risk to their health or their physical or mental well-being,

(ab)whether it adversely affects his or her health,

ac)whether it could cause harm to the physical, intellectual, or psychological development of their offspring;

b)Does any chronic illness or disability pose a risk of injury while performing the job duties or while learning and practicing the profession?;

c)whether, when working in positions or professions of high epidemiological significance, the individual’s personal hygiene and health status pose a risk to the health of others, and whether the individual is eligible for employment in that position;

d)in what type of position or occupation, and under what conditions, a person may be employed without the risk of their condition worsening, if their ability to work has changed temporarily or permanently;

e)whether they can continue to work in their current position or continue their studies in their chosen field;

f)whether the employee has a medical condition that requires regular occupational health examinations in the course of performing his or her job;

g)In the case of work performed abroad, is the individual expected to be physically fit to perform the specified professional duties in the given country?.

(5) The purpose of the personal hygiene fitness examination is to determine whether the health status of the person performing the work—when carrying out the activity—poses a risk to the health of others in work areas of high epidemiological significance, and and whether they may continue to work in that specific work area.

(6)The assessment of suitability for a job, professional competence, and personal hygiene, as well as the expert opinion on employability, does not extend to determining the extent of changes in work capacity, the degree of disability, or assessing mental capacity and mental state.

(7) The obligation to undergo screening for HIV infection as part of an extraordinary occupational or personal hygiene fitness examination, as well as the procedures for conducting such screenings, are established by separate legislation.

III.

Examination tools and methods: urinalysis, medical history, vision screening, general internal medicine examination, and additional specialized tests.

***

Clause:

I, the undersigned employee, hereby certify with my signature that I have read this Notice prior to signing it, and that I have understood and acknowledged its provisions.

Dated _______________________, 20____, _________________, ____

NAME: _________________________

SIGNATURE:_______________________

Appendix 9.a

DATA PROCESSING ACTIVITIES

GENERAL TERMS AND CONDITIONS

STANDARD

NAME OF THE DATA PROCESSOR:

Company Name:

Headquarters:

Company Registration Number:

Tax ID:

Representative:

Phone number:

Fax:

Email address:

Website:

(hereinafter referred to as the “Data Processor”)

The terms and conditions of this agreement shall apply to services provided by our Company to the client under a separate service agreement

6311 – Data processing, web hosting services

6312 – Web Portal Service

5320 – Other postal and courier services

……….

data processing activities related to the service, in the course of which our Company processes personal data on behalf of the client, as the data controller. The client under the basic service agreement is hereinafter referred to as: Data Controller.

1. PURPOSE OF DATA PROCESSING

The processing of data pertaining to natural persons who have a legal relationship with the client in connection with the performance of a separate contract of engagement. The use of a data processor does not require the data subject’s prior consent, but the data subject must be informed, which is the client’s responsibility.

2. DURATION OF DATA PROCESSING: for the duration of the contract with the client, or until the data subject withdraws their consent.

3. NATURE AND PURPOSE OF DATA PROCESSING:

6311 – Data processing, web hosting services

6312 – Web Portal Service

5320 – Other postal and courier services

…………….

4. A TYPE OF PERSONAL DATA:

Based on the natural person's name, address, phone number, and online identifier.

5. CATEGORIES OF DATA SUBJECTS: the principal's clients, customers, and clients.

6. THE OBLIGATIONS AND RIGHTS OF THE CLIENT (DATA CONTROLLER)

6.1. The Data Controller is entitled to monitor the Data Processor’s performance of the activities specified in the contract.

6.2. The Data Controller is responsible for the lawfulness of its instructions regarding the tasks specified in the contract; however, the Data Processor is obligated to notify the Data Controller immediately if the Data Controller’s instruction or its implementation would violate any law.

6. The Data Controller is obligated to inform the natural persons concerned about the data processing under this agreement and, if required by law, to obtain their consent.

7. OUR COMPANY’S OBLIGATIONS AND RIGHTS AS A DATA PROCESSOR

7.1. Right to Issue Instructions: In the course of its activities, the Data Processor acts solely on the basis of written instructions from the Data Controller.

7.2. Confidentiality: In the course of its activities, the Data Processor shall ensure that persons authorized to access the personal data in question—unless they are otherwise subject to an appropriate confidentiality obligation under applicable law— — undertake to maintain confidentiality with respect to the personal data they have become aware of.

7.3. Data Security:  The Data Processor shall take into account the state of the art and technology, the costs of implementation, as well as the nature, scope, circumstances, and purposes of the data processing, as well as the risks of varying likelihood and severity to the rights and freedoms of natural persons, in order to ensure a level of data security appropriate to the risk. The Data Processor shall take measures to ensure that natural persons acting under its control, have access to personal data may process such data only in accordance with the Data Controller’s instructions, unless required to do otherwise by Union or Member State law. The Data Processor shall ensure that access to the stored data, whether through an internal system or by direct access, is restricted to authorized persons and is limited solely to the purposes of data processing. The Data Processor shall ensure the necessary, regular maintenance and upgrading of the equipment used. The Data Processor shall place the device storing the data in a locked room equipped with adequate physical security measures and shall also ensure its physical protection. The Data Processor is required to engage individuals with the appropriate knowledge and experience to perform the tasks specified in the contract. The Data Processor is also required to ensure that the persons it engages are trained regarding the applicable data protection laws, the obligations set forth in this contract, and the purpose and method of data collection.

7.4. Use of Additional Data Processors: The Data Processor agrees to engage additional data processors only if the conditions set forth in the Regulation and the Information Act are met. The Data Controller hereby grants the Data Processor general authorization to engage additional data processors (subcontractors)1. Prior to engaging a subprocessor, the Data Processor shall inform the Data Controller of the identity of the subprocessor and the planned tasks to be performed by the subprocessor. If, based on this information, the Data Controller objects to the engagement of the additional data processor, the Data Processor shall be entitled to engage the additional data processor only if the conditions specified in the objection are met. If the data processor engages the services of an additional data processor for certain specific data processing activities carried out on behalf of the data controller, it is required to enter into a written contract for this purpose and to impose on the additional data processor the same data protection obligations as those set forth in this contract between the data controller and the data processor, in particular, the subprocessor must provide appropriate safeguards to ensure that appropriate technical and organizational measures are implemented, thereby ensuring that the processing complies with the requirements of this Regulation. If the subprocessor fails to fulfill its data protection obligations, the data processor that engaged it shall be fully liable to the data controller for the fulfillment of the subprocessor’s obligations.

7.5. Cooperation with the Data Controller:

a) In the course of its activities as a data processor, our company uses all appropriate means to assist the Data Controller in facilitating the exercise of data subjects’ rights and in fulfilling its related obligations.

b) Our company, as a Data Processor, assists the Data Controller in fulfilling the obligations set forth in Articles 32–36 of the Regulation (Data Security, Data Protection Impact Assessment, and Prior Consultation), taking into account the nature of the data processing and the information available to the data processor.

c) Our company, as a data processor, provides the data controller with all information necessary to certify compliance with the specific obligations set forth in Article 28 of the Regulation (The data processor) and that enables and facilitates audits conducted by the data controller or another auditor authorized by the data controller, including on-site inspections. In this regard, the data processor shall immediately inform the data controller if it believes that any instruction from the data controller violates this Regulation or the data protection provisions of the Member States or the European Union.

8. PROCEDURE IN THE EVENT OF CONTRACT TERMINATION: The termination of the framework agreement shall also result in the termination of this data processing agreement. Upon termination of this agreement, our Company, as the data processor, shall return all personal data and records in its possession to the data controller in accordance with the provisions of the underlying service agreement—unless otherwise agreed by the parties – it shall transfer electronically processed data, lists, and records to the data controller—if the data controller is unable to receive them electronically, it shall provide the data to the data controller in paper form (printed), and at the same time, it shall delete from its records all personal data originating from the data controller and any copies containing such data.

10. The STERMINATION OF THE AGREEMENT

The termination or expiration of a contract entered into with our Company shall be governed by the provisions of the underlying agency agreement concluded between the parties.

11. FINAL PROVISIONS

11.1. For matters not governed by this contract, Act V of 2013 on the Civil Code, as well as REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL (April 27, 2016), and Act CXII of 2011 on the Right to Data Self-Determination and Freedom of Information shall apply.

11.2. By signing this document, the client (Data Controller) certifies that he or she has read and accepted the terms and conditions of this agreement in their entirety prior to signing.

Dated, ____________________ 20 _____, ________________ month, ____ day

_____________________________ _____________________________

Data Processor (Data Controller)

1According to the draft of the Information Act, this provision requires a private document with full probative force. Section 325(1) of the Civil Procedure Code d) According to this provision, this requirement is met if the document is duly signed by a person authorized to represent the legal entity in accordance with the applicable rules. If the entity is not a legal entity, the signatures of two witnesses are required.

Appendix 9.b

DATA PROCESSING ACTIVITIES

GENERAL TERMS AND CONDITIONS

FOR ACCOUNTING FIRMS

NAME OF THE DATA PROCESSOR:

Company Name:

Headquarters:

Company Registration Number:

Tax ID:

Representative:

Phone number:

Fax:

Email address:

Website:

(hereinafter referred to as the “Data Processor”)

These contractual provisions shall apply to data processing activities related to accounting and tax services provided by our Company to the client under a separate service agreement, during which our Company processes personal data on behalf of the client, who acts as the data controller. The client under the accounting and tax services agreement is hereinafter referred to as: Data Controller.

1. PURPOSE OF DATA PROCESSING

Processing the personal data of natural persons who have a legal relationship with the client through the processing of the client’s accounting documents. An accounting document is any document issued or prepared by the client as a business entity, or by a natural person or another business entity with whom the client has a business or other relationship (invoice, contract, agreement, statement, credit institution document, bank statement, statutory provision, or other document that may be classified as such)—regardless of whether it is printed or produced by other means. (Section 166 of the Accounting Act). The use of a data processor does not require the data subject’s prior consent, but the data subject must be informed, which is the responsibility of the client.

2. DURATION OF DATA PROCESSING: for the duration of the contract with the client, but no longer than the 8-year document retention period required of the client under the Accounting Act (Section 169).

3. NATURE AND PURPOSE OF DATA PROCESSING: Fulfilling the client’s tax, social security, and accounting obligations, including maintaining general ledger records, preparing summary reports, compiling financial statements, and in the accounting records, and drawing conclusions to inform business decisions. Performing labor law and payroll tasks. The Data Processor guarantees that it will not process or use the personal data it handles under this engagement for any other purpose.

4. A TYPE OF PERSONAL DATA:

a) The natural person’s personal identification data (including former names and titles), gender, citizenship, tax identification number, social security identification number (TAJ number), tax number, sole proprietor license number, and primary producer identification number.

b) Health data and personal data indicating trade union membership, to the extent that the Labor Code attaches labor law consequences to such data or tax law attaches tax law consequences to such data—pursuant to Article 9(2)(b) of the Regulation.

5. CATEGORIES OF DATA SUBJECTS: the client’s employees, staff, beneficiaries, contracting parties (suppliers, customers), and, in cases provided for by law, the employees’ family members.

6. THE OBLIGATIONS AND RIGHTS OF THE CLIENT (DATA CONTROLLER)

6.1. The Data Controller is entitled to monitor the Data Processor’s performance of the activities specified in the contract.

6.2. The Data Controller is responsible for the lawfulness of its instructions regarding the tasks specified in the contract; however, the Data Processor is obligated to notify the Data Controller immediately if the Data Controller’s instruction or its implementation would violate any law.

6. The Data Controller is obligated to inform the natural persons concerned about the data processing under this agreement and, if required by law, to obtain their consent.

7. OUR COMPANY’S OBLIGATIONS AND RIGHTS AS A DATA PROCESSOR

7.1. Right to Issue Instructions: In the course of its activities, the Data Processor acts solely on the basis of written instructions from the Data Controller.

7.2. Confidentiality: In the course of its activities, the Data Processor shall ensure that persons authorized to access the personal data in question—unless they are otherwise subject to an appropriate confidentiality obligation under applicable law— — undertake to maintain confidentiality with respect to the personal data they have become aware of.

7.3. Data Security:  The Data Processor shall take into account the state of the art and technology, the costs of implementation, as well as the nature, scope, circumstances, and purposes of the data processing, as well as the risks of varying likelihood and severity to the rights and freedoms of natural persons, in order to ensure a level of data security appropriate to the risk. The Data Processor shall take measures to ensure that natural persons acting under its control, have access to personal data may process such data only in accordance with the Data Controller’s instructions, unless required to do otherwise by Union or Member State law. The Data Processor shall ensure that access to the stored data, whether through an internal system or by direct access, is restricted to authorized persons and is limited solely to the purposes of data processing. The Data Processor shall ensure the necessary, regular maintenance and upgrading of the equipment used. The Data Processor shall place the device storing the data in a locked room equipped with adequate physical security measures and shall also ensure its physical protection. The Data Processor is required to engage individuals with the appropriate knowledge and experience to perform the tasks specified in the contract. The Data Processor is also required to ensure that the persons it engages are trained regarding the applicable data protection laws, the obligations set forth in this contract, and the purpose and method of data collection.

7.4. Use of Additional Data Processors: The Data Processor agrees to engage additional data processors only if the conditions set forth in the Regulation and the Information Act are met. The Data Controller hereby grants the Data Processor general authorization to engage additional data processors (subcontractors)1. Prior to engaging a subprocessor, the Data Processor shall inform the Data Controller of the identity of the subprocessor and the planned tasks to be performed by the subprocessor. If, based on this information, the Data Controller objects to the engagement of the additional data processor, the Data Processor shall be entitled to engage the additional data processor only if the conditions specified in the objection are met. If the data processor engages the services of an additional data processor for certain specific data processing activities carried out on behalf of the data controller, it is required to enter into a written contract for this purpose and to impose on the additional data processor the same data protection obligations as those set forth in this contract between the data controller and the data processor, in particular, the subprocessor must provide appropriate safeguards to ensure that appropriate technical and organizational measures are implemented, thereby ensuring that the processing complies with the requirements of this Regulation. If the subprocessor fails to fulfill its data protection obligations, the data processor that engaged it shall be fully liable to the data controller for the fulfillment of the subprocessor’s obligations.

7.5. Cooperation with the Data Controller:

a) In the course of its activities as a data processor, our company uses all appropriate means to assist the Data Controller in facilitating the exercise of data subjects’ rights and in fulfilling its related obligations.

b) Our company, as a Data Processor, assists the Data Controller in fulfilling the obligations set forth in Articles 32–36 of the Regulation (Data Security, Data Protection Impact Assessment, and Prior Consultation), taking into account the nature of the data processing and the information available to the data processor.

c) Our company, as a data processor, provides the data controller with all information necessary to certify compliance with the specific obligations set forth in Article 28 of the Regulation (The data processor) and that enables and facilitates audits conducted by the data controller or another auditor authorized by the data controller, including on-site inspections. In this regard, the data processor shall immediately inform the data controller if it believes that any instruction from the data controller violates this Regulation or the data protection provisions of the Member States or the European Union.

8. RETURN OF DATA AND DOCUMENTS DURING THE TERM OF THE AGREEMENT: After completing the data processing, the Data Processor shall return the processed accounting documents to the Data Controller no later than May 31 of the year following the relevant fiscal year; the electronically processed data, lists, records until the termination of its legal relationship with the Data Controller, but no later than the document retention period prescribed by the Accounting Act—8 years—(Section 169 of the Act).

9. PROCEDURE IN THE EVENT OF CONTRACT TERMINATION: The termination of the contract for the provision of accounting and tax services shall also result in the termination of this data processing agreement. Following the termination of this agreement, our Company, as the data processor, shall return all accounting documents and records in its possession to the data controller in accordance with the terms of the contract for accounting services – unless otherwise agreed by the parties – it shall transmit electronically processed data, lists, and records to the data controller; if the data controller is unable to receive these electronically, it shall transfer the data to the data controller in paper form (printed) and, at the same time, delete from its records all personal data originating from the data controller and any copies containing such data. The data, records, and accounting documents—including their electronically stored forms and data—must be retained by the principal (data controller) following the termination of the legal relationship, as required by tax and accounting laws.

10. The STERMINATION OF THE AGREEMENT

The termination or expiration of a contract entered into with our Company shall be governed by the provisions of the accounting and tax services agreement concluded between the parties.

11. FINAL PROVISIONS

11.1. For matters not governed by this contract, Act V of 2013 on the Civil Code, as well as REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL (April 27, 2016), and Act CXII of 2011 on the Right to Data Self-Determination and Freedom of Information shall apply.

11.2. By signing this document, the client (Data Controller) certifies that he or she has read and accepted the terms and conditions of this agreement in their entirety prior to signing.

Dated, ____________________ 20 _____, ________________ month, ____ day

_____________________________ _____________________________

Data Processor (Data Controller)

1According to the draft of the Information Act, this provision requires a private document with full probative force. Section 325(1) of the Civil Procedure Code d) According to this provision, this requirement is met if the document is duly signed by a person authorized to represent the legal entity in accordance with the applicable rules. If the entity is not a legal entity, the signatures of two witnesses are required.

  1. Appendix

DATA REQUEST FORM

PROCESSING OF PERSONAL DATA BASED ON CONSENT

NAME OF THE DATA SUBJECT:

PLACE AND DATE OF BIRTH:

MOTHER'S NAME:

LAKCME:

PHONE NUMBER:

E-MAIL ADDRESS:

ADDITIONAL PERSONAL INFORMATION:

INFORMATION:

NAME OF THE DATA CONTROLLER:

P-Max Technology, Ltd.

REPRESENTATIVE:

Miklós Németh

WEBSITE:

www.pmax.hu

PURPOSE OF DATA PROCESSING:

LEGAL BASIS FOR DATA PROCESSING:

The data subject's consent.

RECIPIENTS OF PERSONAL DATA:

(those who can view it)

PERIOD OF STORAGE OF PERSONAL DATA:

INFORMATION ON THE RIGHTS OF DATA SUBJECTS:

As a data subject, you have the right to You may request from the data controller access to your personal data, its correction, erasure, or restriction of processing, and you may object to the processing of such personal data; you also have the right to data portability.

You have the right to withdraw your consent at any time, which does not affect the lawfulness of the data processing carried out on the basis of your consent prior to the withdrawal.

You have the right to file a complaint with the supervisory authority (National Authority for Data Protection and Freedom of Information)

Providing this information is not a prerequisite for entering into a contract, and you are not required to provide personal information. Possible consequences of failing to provide this information: _______________________

Further information can be found in the Privacy Policy available on the Company’s website (in the footer). ****

I have read and understood the information provided above, and I voluntarily give my consent—free from any external influence—to the processing of my personal data provided above for the purposes indicated above.

Dated, ______________________ 20 ____, _____________, _____

____________________________

signature

Appendix 2

PRIVACY NOTICE

ON THE RIGHTS OF THE INDIVIDUAL CONCERNED

REGARDING THE PROCESSING OF YOUR PERSONAL DATA

TABLE OF CONTENTS

INTRODUCTION

CHAPTER I – IDENTIFICATION OF THE DATA CONTROLLER

CHAPTER II – IDENTIFICATION OF DATA PROCESSORS

1. Our company's IT service provider

2. Our company’s accounting service provider

3. Postal Services, Delivery, and Parcel Shipping

4. Property Protection Service Provider

CHAPTER III – DATA PROCESSING RELATED TO EMPLOYMENT

1. Labor and Personnel Records

2. Data Processing Related to Aptitude Tests

3. Processing of data on job applicants, applications, and resumes

4. Data Processing Related to Verifying the Use of an Email Account

5. Data Processing Related to the Inspection of Computers, Laptops, and Tablets

6. Data Processing Related to the Monitoring of Internet Use in the Workplace

7. Data Processing Related to the Monitoring of Company Cell Phone Use

8. Data Processing Related to the Use of a GPS Navigation System

9. Data Processing Related to Checking In and Out at Work

10. Data Processing Related to Workplace Video Surveillance

CHAPTER IV – DATA PROCESSING RELATED TO THE CONTRACT

1. Management of Contracting Party Data – Maintenance of Customer and Supplier Records

2. Contact information for the representatives (natural persons) of legal entities that are clients, customers, or suppliers

3. Recording phone calls for customer service

4. Processing of Visitor Data on the Company's Website

5. Information on the Use of Cookies

6. Registration on the Company’s Website

7. Data Processing Related to the Newsletter Service

8. Community Guidelines / Data Processing on the Company’s Facebook Page

9. Data Processing in the Company’s Online Store

10. Data Processing Related to Organizing a Gift Drawing

11. Data Processing for Direct Marketing Purposes

CHAPTER V – DATA PROCESSING BASED ON LEGAL OBLIGATIONS

1. Data Processing for the Purpose of Complying with Tax and Accounting Obligations

2. Data Processing by the Payer

3. Data Processing of Records of Lasting Value Under the Archives Act

4. Data Processing for the Purpose of Complying with Anti-Money Laundering Obligations

CHAPTER VI – SUMMARY OF THE DATA SUBJECT’S RIGHTS

CHAPTER VII – DETAILED INFORMATION ON THE RIGHTS OF DATA SUBJECTS

CHAPTER VIII – SUBMISSION OF A REQUEST BY THE DATA SUBJECT, MEASURES TAKEN BY THE DATA CONTROLLER

INTRODUCTION

On the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL (hereinafter referred to as the “Regulation”) requires that the Data Controller take appropriate measures to ensure that all information regarding the processing of personal data is provided to the data subject in a concise, transparent, understandable, and easily accessible form, expressed clearly and in plain language, and that the Data Controller facilitates the exercise of the data subject’s rights.

The data subject’s obligation to provide advance notice is also stipulated in Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information.

We are complying with this legal obligation by providing the information below.

The information must be posted on the company’s website or sent to the data subject upon request.

CHAPTER I

NAME OF THE DATA CONTROLLER

The publisher of this notice, who is also the Data Controller:

Company Name: P-Max Technológia Kft.

Headquarters: 8220 Balatonalmádi, Szabadság St. 26.

Company Registration Number: 19-09-506270

Tax ID Number: 12786217-2-19

Representative: Miklós Németh

Phone number: 30/913-85-93

Fax: 88/326-644

Email address: pmax@t-email.hu

Website: www.pmax.hu

(hereinafter referred to as the “Company”)

CHAPTER II

LIST OF DATA PROCESSORS

Data processor: a natural or legal person, public authority, agency, or any other body that processes personal data on behalf of the data controller; (Article 4(8) of the Regulation)

The use of a data processor does not require the data subject’s prior consent, but the data subject must be informed. Accordingly, we provide the following information:

1. Our company's IT service provider

Our company engages a data processor to maintain and manage its website; this data processor provides IT services (web hosting) and, as part of this, processes the personal data provided on the website for the duration of our contract with it, The operation performed by the data processor consists of storing personal data on the server.

The name of this data processor is as follows:

Company Name:

Headquarters:

Company Registration Number:

Tax ID:

Representative:

Phone number:

Fax:

Email address:

Website:

2. Our company’s accounting service provider

To fulfill its tax and accounting obligations, our Company engages an external service provider under an accounting services agreement, who also processes the personal data of individuals who have a contractual or payment relationship with our Company, for the purpose of fulfilling the tax and accounting obligations incumbent upon our Company.

The name of this data processor is as follows:

Company Name: 4R Training and Services Limited Partnership.

Headquarters: 8200 Veszprém, Háncs St. 21/1

Company Registration Number: 19-06-507507

Tax ID Number: 21879766-1-19

Representatives: Henriett Klósz-Rukk, Renáta Császár-Rukk

Phone number: 30/640-27-87, 30/520-12-15

3. Postal Services, Delivery, and Parcel Shipping

These data processors receive from our Company the personal data necessary for the delivery of the ordered product (the data subject’s name, address, and phone number) and use this information to deliver the product.

These service providers are:

Hungarian Post

Courier Service

Company Name: DPD Hungária Kft.

Headquarters: 1158 Budapest, Késmárk St. 14/B

Company Registration Number:

Tax ID Number: 13034283-2-42

Representatives: Csilla Hosszú, Managing Director, and László Kovács, Deputy Managing Director

CHAPTER III

DATA PROCESSING RELATED TO EMPLOYMENT

1. Labor and Personnel Records

(1) Only the following data may be requested from employees and kept on file: and medical fitness examinations for specific job roles may be conducted only to the extent that they are necessary for the establishment, continuation, or termination of the employment relationship, or for the provision of social welfare benefits, and do not infringe upon the employee’s personal rights.

(2) The Company processes the following employee data for the purpose of establishing, fulfilling, or terminating an employment relationship, based on the legitimate interest of the employer (Article 6(1)(f) of the Regulation):

1. Name

2. birth name,,

3. date of birth,

4. his mother's name,

5. address,

6. citizenship,

7. Tax ID number,

8. TAJ number,

9. Pensioner ID number (for retired employees),

10. phone number,

11. email address,

12. ID card number,

13. Number of the official document certifying the address,

14. bank account number,

15. Online ID (if any)

16. the start and end dates of employment,

Job No. 17,

18. A copy of a document certifying the applicant’s educational background and professional qualifications,

Photo 19,

20. Resume,

21. the amount of his or her wages, as well as information regarding wage payments and other benefits,

22. any debt to be deducted from the employee’s wages pursuant to a final decision, a statutory provision, or the employee’s written consent, as well as the basis for such deduction,

23. evaluation of the employee's work,

24. the manner and reasons for the termination of the employment relationship,

25. Certificate of Good Conduct (depending on the position)

26. Summary of job suitability assessments,

27. In the case of membership in a private pension fund or a voluntary mutual insurance fund, the name of the fund, its identification number, and the employee’s membership number,

28. For foreign employees, the passport number; the name and number of the document certifying the right to work,

Data recorded in accident reports involving 29 employees;

30. the information required to use welfare services and commercial lodging;

31. the camera and access control systems used by the Company for security and property protection purposes,

as well as data recorded by positioning systems.

(3) The employer may process data regarding an employee’s illness and union membership only for the purpose of exercising a right or fulfilling an obligation as set forth in the Labor Code.

(4) Recipients of personal data: the employee’s supervisor, the person exercising the employer’s authority, and the Company’s employees and data processors responsible for human resources tasks.

(5) Only the personal data of employees in management positions may be disclosed to the Company’s owners.

(6) Retention period for personal data: 3 years following the termination of the employment relationship.

(7) The data subject must be informed, prior to the commencement of data processing, that the data processing is based on the Labor Code and the employer’s legitimate interests

2. Data Processing Related to Aptitude Tests

(1) An employee may only be subject to an aptitude test that is required by a rule governing the employment relationship or that is necessary for the exercise of a right or the fulfillment of an obligation specified in a rule governing the employment relationship. Prior to the assessment, employees must be provided with detailed information, including which skills and abilities the aptitude assessment is intended to evaluate and what tools and methods will be used in the assessment. If the test is required by law, employees must be informed of the title of the law and the specific statutory provision.

(2) The employer may have employees complete test forms assessing their fitness for work and preparedness both before the employment relationship is established and during the term of the employment relationship.

(3) Questionnaires designed to assess psychological or personality traits among a larger group of employees may be administered—solely for the purpose of more efficiently carrying out work processes and and organizing work processes may only be administered to a larger group of employees if the data revealed during the analysis cannot be linked to specific employees—that is, if the data is processed anonymously.

(4) The scope of personal data that may be processed: the fact of fitness for the position and the conditions necessary for it.

(5) Legal basis for data processing: the employer’s legitimate interest.

(6) The purpose of processing personal data: establishing and maintaining an employment relationship; filling a job position.

(7) Recipients of personal data and categories of recipients: The results of the examination may be disclosed to the employees undergoing the examination and to the professional conducting the examination. The employer may only receive information regarding whether the person examined is fit for work or not, and what conditions must be provided to ensure this. However, the employer may not access the details of the examination or its complete documentation.

(8) Duration of the processing of personal data: 3 years following the termination of the employment relationship.

3. Processing of data on job applicants, applications, and resumes

(1) The scope of personal data that may be processed: the natural person’s name, date and place of birth, mother’s name, address, educational and professional qualifications, photograph, telephone number, email address, and any employer’s notes regarding the applicant (if any).

(2) The purpose of processing personal data: application, evaluation of the application, and conclusion of an employment contract with the selected candidate. The data subject must be informed if the employer has not selected him or her for the position in question.

(3) Legal basis for data processing: the data subject’s consent.

(4) Recipients of personal data, or categories of recipients: executives authorized to exercise employer rights at the Company, and employees performing human resources duties.

(5) Retention period for personal data: Until the application or proposal has been evaluated. The personal data of applicants who are not selected must be deleted. The data of anyone who has withdrawn their application or proposal must also be deleted.

(6) An employer may retain job applications only with the data subject’s explicit, unambiguous, and voluntary consent, provided that such retention is necessary to achieve a data processing purpose consistent with applicable law. This consent must be requested from applicants after the recruitment process has been completed.

4. EData processing related to verifying the use of an email account

(1) If the Company provides an employee with an email account – the employee may use this email address and account solely for the purposes of their job duties, so that employees may communicate with one another through it or correspond with clients, other individuals, or organizations on behalf of the employer.

(2) Employees may not use their email accounts for personal purposes or store personal emails in their accounts.

(3) The employer is entitled to periodically—every three months—review the entire contents and usage of the email account; the legal basis for this data processing is the employer’s legitimate interest. The purpose of the review is to verify compliance with the employer’s policies regarding the use of the email account, as well as to verify compliance with the employee’s obligations (Labor Code, Sections 8 and 52).

(4) The employer’s manager or the person exercising the employer’s rights is authorized to conduct the inspection.

(5) Unless the circumstances of the inspection preclude it, the employee must be allowed to be present during the inspection.

(6) Prior to the inspection, the employee must be informed of the employer’s interest justifying the inspection, who on the employer’s part is authorized to conduct the inspection, – the rules governing the inspection (compliance with the principle of proportionality) and the procedure to be followed, – what rights and remedies the employee has regarding the data processing associated with the monitoring of their email account.

(7) The principle of proportionality must be applied during the review; thus, it must first be determined—based primarily on the email address and subject line—whether the email relates to the employee’s job duties and is not for personal purposes. The employer may review the content of non-personal emails without restriction.

(8) If, contrary to the provisions of these regulations, it is determined that an employee has used the email account for personal purposes, the employee must be instructed to delete the personal data immediately. In the event of the employee’s absence or failure to cooperate, the employer shall delete the personal data at the time of the inspection. The employer may impose disciplinary measures on the employee for using the email account in violation of these policies.

(9) With regard to the data processing associated with checking their email account, employees may exercise the rights set forth in the chapter of this policy concerning the rights of data subjects.

5. Data Processing Related to the Inspection of Computers, Laptops, and Tablets

(1) The employee may use any computer, laptop, or tablet provided by the Company for work purposes exclusively to perform his or her job duties; the Company prohibits their use for personal purposes; the employee may not handle or store any personal data or correspondence on these devices. The employer may inspect data stored on these devices. The provisions of Section 1.4 above shall otherwise govern the employer’s inspection of these devices and the legal consequences thereof.

6. Data Processing Related to the Monitoring of Internet Use in the Workplace

(1) Employees may only view websites related to their job duties; the employer prohibits the use of the Internet at work for personal purposes.

(2) The Company is authorized to perform online registrations on its behalf as part of its job duties; during the registration process, an identifier and password referring to the Company must be used. If the provision of personal data is also required for registration, the Company is obligated to initiate the deletion of such data upon termination of employment.

(3) The employer may monitor the employee’s use of the Internet at the workplace; the provisions of Section 1.4 govern such monitoring and its legal consequences.

7. Data Processing Related to the Monitoring of Company Cell Phone Use

(1) The employer does not permit the use of company cell phones for personal purposes; the cell phone may only be used for work-related purposes, and the employer may monitor the phone numbers and details of all outgoing calls, as well as the data stored on the cell phone.

(2) An employee is required to notify the employer if he or she has used a company cell phone for personal purposes. In such cases, the employer may conduct an audit by requesting a call log from the telephone service provider and asking the employee to indicate the numbers dialed for personal use on the document.

unrecognizable. The employer may require the employee to bear the cost of personal calls.

(3) In all other respects, thefor the audit and the provisions of Section 1.4 shall govern the legal consequences.

8. Data Processing Related to the Use of a GPS Navigation System

(1) The legal basis for the use of the GPS system is the employer’s legitimate interest; its purpose is to organize work, manage logistics, and monitor employees’ compliance with their obligations.

(2) The data processed include: the vehicle’s license plate number, the route traveled, the distance, and the duration of vehicle use.

(3) Monitoring may only take place during working hours, and employees’ geographic location may not be monitored outside of working hours. In all other respects, the provisions of Section 1.4 govern employer monitoring and its legal consequences.

9. Data Processing Related to Checking In and Out at Work

(1) When operating an access control system (non-electronic), information must be posted regarding the identity of the data controller and the method of data processing.

(2) The scope of personal data that may be processed: the natural person’s name, address, vehicle registration number, and the times of entry and exit.

(3) Legal basis for data processing: the employer’s legitimate interests.

(4) The purpose of processing personal data: protection of property, performance of a contract, and verification of compliance with employee obligations.

(5) Recipients of personal data and categories of recipients: the Company’s executive authorized to exercise employer rights, and the employees of the Company’s security officer acting as a data processor.

(6) Retention period for personal data: 6 months

10. Data Processing Related to Workplace Video Surveillance

(1) At its headquarters, business locations, and premises open to the public, our company uses an electronic surveillance system to protect human life, physical integrity, personal liberty, protecting trade secrets, and safeguarding property. Based on this, the behavior of the data subject captured by the camera may also be considered personal data.

(2) The legal basis for this data processing is the employer’s legitimate interests and the data subject’s consent.

(3) A notice or information regarding the use of an electronic surveillance system in a given area must be posted in a clearly visible and legible manner, in a way that facilitates the awareness of third parties intending to enter the area. This information must be provided for each individual camera. This information shall include the fact that surveillance is being conducted by the electronic security system; the purpose of creating and storing video and audio recordings containing personal data captured by the system; the legal basis for data processing; the location where the recordings are stored; the duration of storage; the entity operating the system, the group of persons authorized to access the data, and provisions regarding the rights of data subjects and the procedures for exercising those rights.

(4) Video and audio recordings of third parties (customers, visitors, guests) entering the monitored area may be made and processed with their consent. Consent may also be implied by conduct. Implied consent exists, in particular, when a natural person present at the location enters the monitored area despite having been informed by signs or notices posted there regarding the use of the electronic surveillance system.

(5) Recorded footage may be retained for a maximum of 3 (three) business days if it is not used. Use is deemed to have occurred if the recorded video, audio, or video and audio recordings, as well as other personal data, are intended to be used as evidence in court or other official proceedings.

(6) Any person whose rights or legitimate interests are affected by the recording of image, audio, or image-and-audio data may, within three business days of the recording of the image, sound, or image and sound recording, request—by providing evidence of their rights or legitimate interests—that the data controller not destroy or delete the data.

(7) Electronic surveillance systems may not be used in any room where such surveillance could violate human dignity, including, in particular, changing rooms, showers, restrooms, or, for example, medical examination rooms and their associated waiting areas, nor in any room designated for employees to spend their breaks.

(8) If no one is legally permitted to be on the premises—particularly outside of working hours or on non-working days—then the entire premises (such as locker rooms, restrooms, and areas designated for work breaks) may be monitored.

(9) In addition to those authorized by law to view data recorded by the electronic surveillance system, the following are authorized to do so for the purpose of detecting violations and monitoring the system’s operation: the operating staff, the employer’s manager and deputy manager, as well as the supervisor of the monitored area, are authorized to view the data recorded by the electronic surveillance system.

CHAPTER IV

DATA PROCESSING RELATED TO THE CONTRACT

1. Management of Contracting Party Data – Maintenance of Customer and Supplier Records

(1) On the grounds of contract performance, the Company processes the name, birth name, and date of birth of natural persons who have entered into a contract with it as customers or suppliers, as well as mother’s name, address, tax identification number, tax ID number, business license number, primary producer license number, ID card number, address, registered office address, business location address, phone number, email address, website address, bank account number, customer number (client number, order number), and online identifier (list of customers and suppliers, regular customer lists), This data processing is considered lawful even if it is necessary to take steps at the data subject’s request prior to entering into a contract. Recipients of personal data: the Company’s employees who perform customer service-related tasks, employees who perform accounting and tax-related tasks, and data processors. Duration of personal data processing: 5 years following the termination of the contract.

(2) The data subject must be informed, prior to the commencement of data processing, that the data processing is based on the legal basis of the performance of a contract; such information may also be provided in the contract.

(3) The data subject must be informed of the transfer of his or her personal data to a data processor.

2. Contact information for the representatives (natural persons) of legal entities that are clients, customers, or suppliers

(1) Scope of personal data that may be processed: a natural person’s name, address, phone number, email address, and online identifier.

(2) Purpose of the processing of personal data: performance of a contract concluded with the Company’s legal entity partner; maintaining business relations; legal basis: the data subject’s consent.

(3) Recipients of personal data, or categories of recipients: the Company’s employees who perform customer service-related duties.

(4) Retention period for personal data: 5 years following the termination of the business relationship or the end of the data subject’s capacity as a representative.

3. Information on the Use of Cookies

(1) In accordance with common Internet practice, our Company also uses cookies on its website. A cookie is a small file containing a string of characters that is placed on a visitor’s computer when they visit a website. When the visitor returns to that website, the cookie enables the website to recognize the visitor’s browser. Cookies can store user preferences (e.g., selected language) and other information. Among other things, they collect information about the visitor and their device, remember the visitor’s individual preferences, and can be used, for example, when filling out online shopping carts. In general, cookies make it easier to use the website, help ensure that the website provides users with a genuine web experience and serves as an effective source of information, and they also enable the website operator to monitor the site’s operation, prevent misuse, and ensure that the services provided on the website are delivered smoothly and to an appropriate standard.

(2) When you use our website, our company records and processes the following data about you and the device you use to browse the site:
• the IP address used by the visitor,
• browser type,
• the characteristics of the operating system of the device used for browsing (language setting),
• date of visit,
• the (sub)page, feature, or service visited.

(3) Accepting or allowing the use of cookies is not mandatory. You can reset your browser settings to reject all cookies or to be notified when a cookie is being sent. Although most browsers automatically accept cookies by default, these settings can generally be changed to prevent automatic acceptance and to give you the option to choose each time.

You can find information about cookie settings for the most popular browsers at the links below
• Google Chrome: https://support.google.com/accounts/answer/61416?hl=hu
• Firefox: https://support.mozilla.org/hu/kb/sutik-engedelyezese-es-tiltasa-amit-weboldak-haszn
• Microsoft Internet Explorer 11: https://windows.microsoft.com/hu-hu/internet-explorer/delete-manage-cookies#ie=ie-11
• Microsoft Internet Explorer 10: https://windows.microsoft.com/hu-hu/internet-explorer/delete-manage-cookies#ie=ie-10-win-7
• Microsoft Internet Explorer 9: https://windows.microsoft.com/hu-hu/internet-explorer/delete-manage-cookies#ie=ie-9
• Microsoft Internet Explorer 8: https://windows.microsoft.com/hu-hu/internet-explorer/delete-manage-cookies#ie=ie-8
• Microsoft Edge: https://windows.microsoft.com/hu-hu/windows-10/edge-privacy-faq
• Safari: https://support.apple.com/hu-hu/HT201265

However, we would like to point out that certain website features or services may not function properly without cookies.

(4) The cookies used on the website are not, by themselves, capable of identifying the user.

(5) Cookies used on the Company’s website:

1. Technically essential session cookies

These cookies are necessary for visitors to browse the website and to use its features and the services available through the website seamlessly and to their fullest extent, including – among other things – specifically, the recording of the actions performed by the visitor on the relevant pages during a visit. The duration of data processing for these cookies applies exclusively to the visitor’s current visit; once the session ends or the browser is closed, this type of cookie is automatically deleted from your computer.

The data set being processed: AVChatUserId, JSESSIONID, portal_referer.

The legal basis for this data processing is Section 13/A(3) of Act CVIII of 2001 on Certain Issues Concerning Electronic Commerce Services and Information Society Services (Elkertv.).

Purpose of data processing: to ensure the proper functioning of the website.

2. Cookies that require consent:

These features allow the Company to record the user’s preferences regarding the website. The visitor may opt out of this data processing at any time, both before and during the use of the service. This data cannot be linked to the user’s identifying information and may not be disclosed to third parties without the user’s consent.

2.1. Cookies that enhance the user experience:

The legal basis for data processing is the visitor's consent.

Purpose of data processing: To improve the efficiency of the service, enhance the user experience, and make the website more user-friendly.

The data retention period is 6 months.

2.2. Performance Cookies:

Google Analytics cookies—you can find more information here:

https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage

Google AdWords cookies – you can find out more about them here:

https://support.google.com/adwords/answer/2407785?hl=hu

4. Registration on the Company's Website

(1) On the website, a natural person registering may give consent to the processing of their personal data by checking the corresponding box. Pre-checking the box is prohibited.

(2) The scope of personal data that may be processed: the natural person’s name (last name, first name), address, phone number, email address, and online identifier.

(3) The purpose of processing personal data is:

1. Providing the services offered on the website.

2. Contact via email, phone, text message, or mail.

3. Information about the Company’s products, services, terms and conditions, and promotions.

4. Advertising materials may be sent electronically or by mail as part of the informational process.

5. Analysis of website usage.

(4) The legal basis for data processing is the data subject’s consent.

(5) Recipients of personal data, or categories of recipients: the Company’s employees who perform tasks related to customer service and marketing activities; and, as data processors, the employees of the Company’s IT service provider who provide hosting services.

(6) Duration of personal data storage: until the end of the registration or the provision of the service, or until the data subject withdraws their consent (or requests erasure).

5. Data Processing Related to the Newsletter Service

(1) A natural person who registers for the newsletter service on the website may give consent to the processing of their personal data by checking the corresponding box. The box must not be pre-checked. The data subject may unsubscribe from the newsletter at any time by using the „Unsubscribe” feature in the newsletter, or by submitting a written statement or an email, which constitutes a withdrawal of consent. In such cases, all data pertaining to the unsubscriber must be deleted immediately. The text of the notice to be posted on the newsletter subscription page is contained in Appendix 7 of this Policy.

(2) The scope of personal data that may be processed: the natural person’s name (last name, first name) and email address.

(3) The purpose of processing personal data is:

1. Sending newsletters regarding the Company’s products and services

2. Sending promotional materials

(4) Legal basis for data processing: the data subject’s consent.

(5) Recipients of personal data and categories of recipients: the Company’s employees performing tasks related to customer service and marketing activities; and, as data processors, the employees of the Company’s IT service provider for the purpose of providing hosting services,

(6) Duration of personal data storage: for as long as the newsletter service remains active, or until the data subject withdraws their consent (or requests deletion).

6. Community Guidelines / Data Processing on the Company’s Facebook Page

(1) The Company maintains a Facebook page for the purpose of introducing and promoting its products and services.

(2) Questions posted on the Company’s Facebook page do not constitute officially filed complaints.

(3) The Company does not process personal data posted by visitors on the Company’s Facebook page.

(4) Visitors are subject to Facebook’s Privacy Policy and Terms of Service.

(5) In the event of the publication of unlawful or offensive content, the Company may exclude the person concerned from membership or delete their post without prior notice.

(6) The Company is not liable for any content or comments posted by Facebook users that violate the law. The Company is not liable for any errors or malfunctions arising from the operation of Facebook, or for any problems resulting from changes to the system’s operation.

7. Data Processing in the Company’s Online Store

(1) A purchase made through the online store operated by the Company constitutes a contract, subject to Act CVIII of 2001 on Electronic Commerce Services, as well as Section 13/A of Act CVIII of 2001 on Certain Issues Concerning Information Society Services, and Government Decree No. 45/2014 (II. 26.) on the detailed rules governing contracts between consumers and businesses. When making a purchase in the online store, the legal basis for data processing is the contract.

(2) The Company, as the service provider, may process the personal data of users who register with the online store for the purposes of entering into a contract for the provision of information society services, determining the content of such a contract, amending it, monitoring its performance, invoicing the resulting fees, and enforcing related claims. It may process the personal identification data and address necessary to identify natural persons who register as customers in the online store pursuant to Section 13/A of Act CVIII of 2001(1) of Act CVIII of 2001; furthermore, based on the customer’s consent, it may process the customer’s phone number, email address, bank account number, and online identifier.

(3) The Company may process natural person identification data related to the use of information society services for billing purposes, residential address, as well as data regarding the date, duration, and location of service use, pursuant to Section 13/A(2) of Act CVIII of 2001.

(4) Recipients of personal data and categories of recipients: the Company’s employees who perform tasks related to customer service and marketing; employees of the company that, as a data processor, performs the Company’s tax and accounting tasks; for the purpose of fulfilling tax and accounting obligations; employees of the Company’s IT service provider for the purpose of providing hosting services; and employees of the courier service with regard to shipping information (name, address, phone number).

(5) Duration of personal data processing: until the registration or service is in effect, or until the data subject withdraws their consent (or requests erasure); in the case of a purchase, for 5 years following the year of the purchase.

8. Data Processing for Direct Marketing Purposes

(1) Unless otherwise provided by a separate law, advertising that directly targets a natural person as the recipient of the advertisement (direct marketing)—in particular, via electronic mail or other equivalent means of individual communication — with the exceptions specified in Act XLVIII of 2008 — may be communicated only if the recipient of the advertisement has given prior, clear, and explicit consent.

(2) The scope of personal data that the Company may process for the purpose of contacting advertising recipients includes: the natural person’s name, address, phone number, email address, and online identifier.

(3) The purpose of processing personal data is to conduct direct marketing activities related to the Company’s operations, namely the regular or periodic distribution of promotional materials, newsletters, and current offers in printed (by mail) or electronic (email) form, either regularly or periodically, to the contact information provided at the time of registration.

(4) Legal basis for data processing: the data subject’s consent.

(5) Recipients of personal data, or categories of recipients: the Company’s employees performing customer service-related tasks; the employees of the Company’s IT service provider who provide server services in their capacity as data processors; and, in the case of postal delivery, employees of the Hungarian Post.

(6) Retention period for personal data: until consent is withdrawn.

CHAPTER V

DATA PROCESSING BASED ON LEGAL OBLIGATIONS

1. Data Processing for the Purpose of Complying with Tax and Accounting Obligations

(1) The Company processes the data specified by law regarding natural persons who enter into a business relationship with it as customers or suppliers for the purpose of fulfilling its legal obligations and complying with statutory tax and accounting requirements (bookkeeping, taxation). The data processed, pursuant to Sections 169 and 202 of Act CXXVII of 2017 on Value-Added Tax, include in particular: tax identification number, name, address, tax status; and, pursuant to Section 167 of Act C of 2000 on Accounting: name, address, identification of the person or organization authorizing the economic transaction, the authorizing officer, and the person certifying the execution of the order, as well as, depending on the organization, the auditor’s signature; on inventory movement documents and cash management documents, the signature of the recipient; on receipt slips, the signature of the payer; pursuant to Act CXVII of 1995 on Personal Income Tax: business license number, primary producer license number, and tax identification number.

(2) Personal data shall be retained for 8 years following the termination of the legal relationship that serves as the legal basis for their processing.

(3) Recipients of personal data: the Company’s employees and data processors who perform the Company’s tax, accounting, payroll, and social security duties.

2. Data Processing by the Payer

(1) The Company processes the personal data of data subjects—employees and their family members—for the purpose of fulfilling its legal obligations, including compliance with tax and social security contribution obligations prescribed by law (assessment of taxes, tax advances, and social security contributions; payroll processing; social security and pension administration) for the purpose of fulfilling its statutory tax and contribution obligations—the personal data of data subjects—employees, their family members, other employees, and other benefit recipients—as prescribed by tax laws, with whom it has a relationship as a payer (2017: Act CL on the Rules of Taxation (Art.), Section 7(31)). The scope of the data processed is defined in Section 50 of the Act, with particular emphasis on the following: the natural person’s personal identification data (including former names and titles), gender, citizenship, tax identification number, and social security identification number (TAJ number). If tax laws attach legal consequences to this, the Company may process employees’ health-related data (Section 40 of the Personal Income Tax Act) and trade union membership data (Section 47(2)(b)) for the purpose of fulfilling tax and social security obligations (payroll processing, social security administration).

(2) Personal data shall be retained for 8 years following the termination of the legal relationship that serves as the legal basis for their processing.

(3) Recipients of personal data: the Company’s employees and data processors who perform the Company’s tax, payroll, and social security (payor) duties.

3. Data Processing of Records of Lasting Value Under the Archives Act

(1) The Company manages, for the purpose of fulfilling its legal obligations, those documents classified as having permanent value under Act LXVI of 1995 on Public Records, Public Archives, and the Protection of Private Archival Materials (Archives Act), with the aim of ensuring that the portion of the Company’s archival holdings deemed to be of lasting value remains intact and in usable condition for future generations. Data retention period: until transfer to the public archives.

(2) The Archives Act governs the recipients of personal data and other matters related to data processing.

4. Data Processing for the Purpose of Complying with Anti-Money Laundering Obligations

(1) In order to comply with its legal obligations and to prevent and combat money laundering and the financing of terrorism, the Company processes the personal data of its customers, their representatives, and beneficial owners as defined in Act LIII of 2017 on the Prevention and Combating of Money Laundering and Terrorist Financing (Pmt.): a)natural person a)first and last name, b)his or her birth surname and first name, c)citizenship, d)place and date of birth, e)her mother's maiden name, f)his or her address, or, in the absence thereof, his or her place of residence, g)the type and number of their identification document; the number of their official certificate verifying their address; and copies of the documents presented. (Section 7).

(2) Recipients of personal data: the Company’s employees who perform customer service-related tasks, the Company’s manager, and the person designated by the Company in accordance with the Pmt.

(3) Retention period for personal data: 8 years from the termination of the business relationship or the completion of the transaction. (Section 56(2) of the Personal Data Protection Act)

CHAPTER VI

SUMMARY OF INFORMATION ON THE RIGHTS OF DATA SUBJECTS

In this chapter, for the sake of clarity and transparency, we briefly summarize the rights of the data subject; detailed information on how to exercise these rights is provided in the following chapter.

Right to Receive Preliminary Information

The data subject has the right to be informed about the facts and information related to data processing prior to the commencement of such processing.

(Articles 13–14 of the Regulation)

We will provide information on the detailed rules in the next chapter.

The Data Subject's Right of Access

The data subject has the right to receive confirmation from the Data Controller as to whether his or her personal data are being processed, and if such processing is taking place, the data subject has the right to access the personal data and the related information specified in the Regulation.

(Article 15 of the Regulation).

We will provide information on the detailed rules in the next chapter.

The Right to Correction

The data subject has the right to request that the Data Controller rectify inaccurate personal data concerning him or her without undue delay. Taking into account the purpose of the data processing, the data subject has the right to request that incomplete personal data be completed, including, among other things, by means of a supplementary statement.

(Article 16 of the Regulation).

The Right to Erasure („the Right to Be Forgotten”)

1. The data subject has the right to have the Data Controller erase personal data concerning him or her without undue delay upon request, and the Data Controller is obligated to erase the personal data concerning the data subject without undue delay if any of the grounds specified in the Regulation apply.

(Article 17 of the Regulation)

We will provide information on the detailed rules in the next chapter.

The Right to Restrict Data Processing

The data subject has the right to request that the Data Controller restrict data processing if the conditions specified in the regulation are met.

(Article 18 of the Regulation)

We will provide information on the detailed rules in the next chapter.

The obligation to notify regarding the rectification or erasure of personal data, or the restriction of data processing

The Data Controller shall inform all recipients to whom the personal data has been disclosed of any rectification, erasure, or restriction of processing, unless this proves impossible or involves a disproportionate effort. At the request of the data subject, the Data Controller shall provide information about these recipients.

(Article 19 of the Regulation)

The Right to Data Portability

Subject to the conditions set forth in the Regulation, the data subject has the right to receive the personal data concerning him or her, which he or she has provided to a Data Controller, in a structured, commonly used, and machine-readable format, and is also entitled to transmit this data to another Data Controller without being prevented from doing so by the Data Controller to whom the personal data was provided.

(Article 20 of the Regulation)

We will provide information on the detailed rules in the next chapter.

The Right to Protest

The data subject has the right to object at any time, on grounds relating to his or her particular situation, to the processing of his or her personal data pursuant to Article 6(1)(e) of the Regulation (processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller) or (f) (processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party.

(Article 21 of the Regulation)

We will provide information on the detailed rules in the next chapter.

Automated decision-making in individual cases, including profiling

The data subject has the right not to be subject to a decision based solely on automated processing—including profiling—that would produce legal effects concerning him or her or similarly significantly affect him or her.

(Article 22 of the Regulation)

We will provide information on the detailed rules in the next chapter.

Restrictions

EU or Member State law applicable to the Data Controller or Data Processor may, through legislative measures, restrict the rights and obligations set forth in Articles 12–22 and Article 34, as well as those specified in Articles 12–22 as set forth in Articles 12–22

(Article 23 of the Regulation)

We will provide information on the detailed rules in the next chapter.

Notifying the Data Subject of a Data Breach

If the data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Data Controller shall notify the data subject of the data breach without undue delay.

(Article 34 of the Regulation)

We will provide information on the detailed rules in the next chapter.

The right to file a complaint with the supervisory authority (the right to administrative redress)

The data subject has the right to lodge a complaint with a supervisory authority—in particular, in the Member State of his or her habitual residence, their place of work, or the Member State where the alleged infringement occurred—if the data subject believes that the processing of their personal data violates the Regulation.

(Article 77 of the Regulation)

We will provide information on the detailed rules in the next chapter.

The right to an effective judicial remedy against the supervisory authority

Every natural and legal person is entitled to an effective judicial remedy against a legally binding decision of the supervisory authority concerning that person, or if the supervisory authority fails to address the complaint or fails to inform the data subject within three months of the procedural developments or the outcome of the complaint that was filed.

(Article 78 of the Regulation)

We will provide information on the detailed rules in the next chapter.

The right to an effective judicial remedy against the data controller or data processor

Any person concerned is entitled to an effective judicial remedy if he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in a manner inconsistent with this Regulation.

(Article 79 of the Regulation)

We will provide information on the detailed rules in the next chapter.

CHAPTER VII

DETAILED INFORMATION ON THE RIGHTS OF DATA SUBJECTS

Right to Receive Preliminary Information

The data subject has the right to be informed of the facts and information relating to data processing prior to the commencement of such processing

A) Information to Be Provided When Personal Data Is Collected From the Data Subject

1. If personal data relating to a data subject is collected from the data subject, the data controller shall provide the data subject with all of the following information at the time the personal data is obtained:

a) the identity and contact information of the data controller and, if applicable, the data controller’s representative;

b) the contact information for the data protection officer, if any;

(c) the purpose of the intended processing of personal data and the legal basis for the processing;

d) in the case of data processing based on Article 6(1)(f) of the Regulation (legitimate interests), the legitimate interests of the data controller or a third party;

e) where applicable, the recipients of the personal data or, where applicable, the categories of recipients;

(f) where applicable, the fact that the controller intends to transfer personal data to a third country or to an international organization, as well as the existence or absence of an adequacy decision by the Commission, or, in the case of a transfer referred to in Article 46, Article 47, or the second subparagraph of Article 49(1) of the Regulation, as well as a reference to the means of obtaining copies thereof or to their availability.

2. In addition to the information referred to in paragraph 1, the data controller shall, at the time of collection of personal data, provide the data subject with the following additional information in order to ensure fair and transparent data processing:

a) the period for which personal data will be stored, or, if that is not possible, the criteria used to determine that period;

b) the data subject’s right to request from the data controller access to personal data concerning him or her, the rectification or erasure of such data, or the restriction of their processing, and to object to the processing of such personal data, as well as the data subject’s right to data portability;

(c) in the case of data processing based on Article 6(1)(a) of the Regulation (consent of the data subject) or Article 9(2)(a) (the data subject’s consent), the right to withdraw consent at any time, which does not affect the lawfulness of data processing carried out on the basis of consent prior to withdrawal;

d) the right to file a complaint with the supervisory authority;

e) whether the provision of personal data is required by law or a contractual obligation, or whether it is a prerequisite for entering into a contract, and whether the data subject is required to provide the personal data, as well as the possible consequences of failing to provide such data;

f) the fact that automated decision-making, including profiling, as referred to in Article 22(1) and (4) of the Regulation, takes place, as well as, at least in those cases, the logic applied and comprehensible information regarding the significance of such processing and its likely consequences for the data subject.

3. If the data controller intends to process personal data for a purpose other than the purpose for which they were collected, it must inform the data subject of this different purpose and of all relevant additional information referred to in paragraph (2) prior to such further processing.

4. Points 1 through 3 do not apply if, and to the extent that, the data subject already possesses the information.

(Article 13 of the Regulation)

B) Information to Be Provided When Personal Data Was Not Obtained From the Data Subject

1. If the personal data were not obtained from the data subject, the data controller shall provide the data subject with the following information:

a) the identity and contact information of the data controller and, if applicable, the data controller’s representative;

b) the contact information for the data protection officer, if any;

(c) the purpose of the intended processing of personal data and the legal basis for the processing;

(d) the categories of personal data concerned;

e) the recipients of the personal data or, where applicable, the categories of recipients;

f) where applicable, the fact that the data controller intends to transfer personal data to a recipient in a third country or to an international organization, as well as the existence or absence of a Commission adequacy decision, or, in the case of a transfer referred to in Article 46 of the Regulation, Article 47, or the second subparagraph of Article 49(1), an indication of the appropriate and suitable safeguards, as well as a reference to the means of obtaining copies thereof or to their availability.

2. In addition to the information referred to in paragraph 1, the data controller shall provide the data subject with the following additional information necessary to ensure fair and transparent data processing with respect to the data subject:

a) the period for which personal data will be stored, or, if that is not possible, the criteria used to determine that period;

(b) if the processing is based on Article 6(1)(f) of the Regulation (legitimate interests), the legitimate interests of the data controller or a third party;

c) the data subject’s right to request from the data controller access to personal data concerning him or her, the rectification or erasure of such data, or the restriction of their processing, and to object to the processing of personal data, as well as the data subject’s right to data portability;

d) in the case of data processing based on Article 6(1)(a) of the Regulation (consent of the data subject) or Article 9(2)(a) (consent of the data subject), the right to withdraw consent at any time, which does not affect the lawfulness of the processing carried out on the basis of consent prior to withdrawal;

e) the right to file a complaint with a supervisory authority;

(f) the source of the personal data and, where applicable, whether the data is derived from publicly available sources; and

(g) the fact that automated decision-making, including profiling, as referred to in Article 22(1) and (4) of the Regulation, takes place, as well as, at least in these cases, the logic applied and comprehensible information regarding the significance of such data processing and its expected consequences for the data subject.

3. The data controller shall provide the information specified in paragraphs 1 and 2 as follows:

(a) taking into account the specific circumstances of the processing of personal data, within a reasonable period of time from the date of collection of the personal data, but no later than one month;

(b) if the personal data are used for the purpose of contacting the data subject, at least at the time of the first contact with the data subject; or

(c) if the data are expected to be disclosed to another recipient, no later than the first time the personal data are disclosed.

4. If the data controller intends to process personal data for a purpose other than the purpose for which the data was collected, the data controller must inform the data subject of this different purpose and provide all relevant additional information referred to in paragraph 2 prior to such further processing.

5. Points 1 through 5 do not apply if and to the extent that:

(a) the data subject already has the information;

(b) the provision of the information in question proves impossible or would require a disproportionate effort, in particular for archiving purposes in the public interest, for scientific and historical research purposes or for statistical purposes, in the case of data processing carried out in accordance with the conditions and safeguards set forth in Article 89(1) of the Regulation, or where compliance with the obligation referred to in paragraph (1) of this Article would be likely to render impossible or seriously jeopardize the achievement of the purposes of such processing. In such cases, the data controller must take appropriate measures—including making the information publicly available—to protect the rights, freedoms, and legitimate interests of the data subject;

(c) the collection or disclosure of the data is expressly required by Union or Member State law applicable to the data controller, which provides for appropriate measures to safeguard the legitimate interests of the data subject; or

(d) Personal data must remain confidential pursuant to a professional duty of confidentiality established by Union or Member State law, including a duty of confidentiality based on legislation.

(Article 14 of the Regulation)

The Data Subject's Right of Access

1. The data subject has the right to receive confirmation from the Data Controller as to whether his or her personal data are being processed, and if such processing is taking place, he or she has the right to access the personal data and the following information:

a) the purposes of data processing;

(b) the categories of personal data concerned;

c) the recipients or categories of recipients to whom the personal data have been or will be disclosed, including, in particular, recipients in third countries and international organizations;

d) where applicable, the planned duration of the storage of personal data, or, if this is not possible, the criteria for determining that duration;

e) the data subject’s right to request that the Data Controller rectify, erase, or restrict the processing of personal data concerning him or her, and to object to the processing of such personal data;

(f) the right to file a complaint with a supervisory authority;

(g) if the data were not collected from the data subject, any available information regarding their source;

(h) the fact that automated decision-making, including profiling, as referred to in Article 22(1) and (4) of the Regulation, has taken place, as well as, at least in these cases, the logic applied and understandable information regarding the significance of such data processing and its likely consequences for the data subject.

2. If personal data is transferred to a third country or to an international organization, the data subject has the right to be informed about the appropriate safeguards regarding the transfer, in accordance with Article 46 of the Regulation.

3. The Data Controller shall provide the data subject with a copy of the personal data subject to processing. For any additional copies requested by the data subject, the Data Controller may charge a reasonable fee based on administrative costs. If the data subject submitted the request electronically, the information must be provided in a widely used electronic format, unless the data subject requests otherwise. The right to request a copy shall not adversely affect the rights and freedoms of others.

(Article 15 of the Regulation)

The Right to Erasure („the Right to Be Forgotten”)

1. The data subject has the right to request that the Data Controller erase personal data concerning him or her without undue delay, and the Data Controller is obligated to erase personal data concerning the data subject without undue delay if any of the following grounds apply:

(a) the personal data is no longer necessary for the purpose for which it was collected or otherwise processed;

(b) the data subject withdraws the consent on which the processing is based pursuant to Article 6(1)(a) or Article 9(2)(a) of the Regulation, and there is no other legal basis for the processing;

(c) the data subject objects to the processing of his or her personal data pursuant to Article 21(1) of the Regulation, and there is no legitimate reason for the processing that takes precedence, or the data subject objects to the processing pursuant to Article 21(2);

(d) the personal data were processed unlawfully;

(e) the personal data must be erased to comply with a legal obligation under Union or Member State law applicable to the Data Controller;

(f) The personal data were collected in connection with the provision of information society services as referred to in Article 8(1) of the Regulation.

2. If the Data Controller has made the personal data public and is required to erase it pursuant to paragraph 1 above, it shall take all reasonably expected steps, taking into account available technology and the costs of implementation — including technical measures — to inform the Data Controllers processing the data that the data subject has requested the deletion of links to the personal data in question or the deletion of copies or duplicates of such personal data.

3. Paragraphs 1 and 2 do not apply if the data processing is necessary:

(a) for the purpose of exercising the freedom of expression and the right to information;

(b) to comply with a legal obligation under Union or Member State law to which the Data Controller is subject, or to perform a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;

(c) in accordance with Article 9(2)(h) and (i) and Article 9(3) of the Regulation, on the basis of the public interest in the field of public health;

d) in accordance with Article 89(1) of the Regulation, for archiving in the public interest, for scientific and historical research purposes or for statistical purposes, insofar as the right referred to in paragraph 1 is likely to render such processing impossible or seriously impair it; or

e) to assert, enforce, or defend legal claims.

(Article 17 of the Regulation)

The Right to Restrict Data Processing

1. The data subject has the right to request that the Data Controller restrict data processing if any of the following conditions are met:

a) the data subject disputes the accuracy of the personal data; in this case, the restriction applies for a period that allows the Data Controller to verify the accuracy of the personal data;

(b) the processing is unlawful, and the data subject objects to the erasure of the data and requests, instead, that its use be restricted;

(c) the Data Controller no longer needs the personal data for the purposes of data processing, but the data subject requires it to assert, exercise, or defend legal claims; or

d) the data subject has objected to the processing of data pursuant to Article 21(1) of the Regulation; in which case the restriction shall apply for as long as it has not been determined whether the Data Controller’s legitimate grounds take precedence over the data subject’s legitimate grounds.

2. If data processing is subject to restrictions under paragraph 1, such personal data may be processed, with the exception of storage, only with the data subject’s consent, or for the establishment, exercise, or defense of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State.

3. The Data Controller shall notify the data subject, at whose request data processing was restricted pursuant to paragraph 1, in advance of the lifting of the restriction on data processing.

(Article 18 of the Regulation)

The Right to Data Portability

1. The data subject has the right to receive the personal data concerning him or her, which he or she has provided to a Data Controller, in a structured, commonly used, and machine-readable format, and has the right to transmit those data to another Data Controller without hindrance from the Data Controller to whom the personal data were provided, if:

(a) the processing is based on consent pursuant to Article 6(1)(a) or Article 9(2)(a) of the Regulation, or on a contract pursuant to Article 6(1)(b); and

(b) the data processing is carried out by automated means.

2. In exercising the right to data portability under paragraph 1, the data subject has the right—if technically feasible—to request that personal data be transferred directly from one data controller to another.

3. The exercise of this right shall not infringe upon Article 17 of the Regulation. This right does not apply where the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller.

4. The right referred to in paragraph 1 shall not adversely affect the rights and freedoms of others.

(Article 20 of the Regulation)

The Right to Protest

1. The data subject has the right to object at any time, on grounds relating to his or her particular situation, to the processing of his or her personal data referred to in Article 6(1)(e) of the Regulation (processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller) or (f) (processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party), including profiling based on those provisions. In this case, the Data Controller may no longer process the personal data unless the Data Controller demonstrates that the processing is justified by compelling legitimate grounds that take precedence over the data subject’s interests, rights, and freedoms, or which are related to the establishment, exercise, or defense of legal claims.

2. If personal data are processed for the purpose of direct marketing, the data subject has the right to object at any time to the processing of personal data concerning him or her for this purpose, including profiling, to the extent that it is related to direct marketing.

3. If the data subject objects to the processing of personal data for direct marketing purposes, the personal data may no longer be processed for that purpose.

4. The data subject must be expressly informed of the right referred to in paragraphs 1 and 2 no later than at the time of the first contact with the data subject, and the relevant information must be presented clearly and separately from all other information.

5. With regard to the use of information society services, and by way of derogation from Directive 2002/58/EC, the data subject may exercise the right to object using automated means based on technical specifications.

6. If personal data are processed for scientific or historical research purposes or for statistical purposes in accordance with Article 89(1) of the Regulation, the data subject has the right to object, on grounds relating to his or her particular situation, to the processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out for reasons of public interest.

(Article 21 of the Regulation)

Automated decision-making in individual cases, including profiling

1. The data subject has the right not to be subject to a decision based solely on automated processing—including profiling—that would produce legal effects concerning him or her or similarly significantly affect him or her.

2. Paragraph 1 shall not apply if the decision:

(a) is necessary for the conclusion or performance of a contract between the data subject and the data controller;

(b) the processing is permitted by Union or Member State law applicable to the Data Controller, which also provides for appropriate measures to safeguard the rights, freedoms, and legitimate interests of the data subject; or

(c) is based on the data subject's explicit consent.

3. In the cases referred to in points (a) and (c) of paragraph 2, the Data Controller is required to take appropriate measures to protect the data subject’s rights, including, at a minimum, the right to request human intervention by the Data Controller, to express their point of view, and to lodge an objection to the decision.

4. The decisions referred to in paragraph 2 may not be based on special categories of personal data referred to in Article 9(1) of the Regulation, unless Article 9(2)(a) or (g) applies, and appropriate measures have been taken to protect the rights, freedoms, and legitimate interests of the data subject.

(Article 22 of the Regulation)

Restrictions

1. Union or Member State law applicable to the data controller or data processor may, through legislative measures, restrict the provisions set forth in Articles 12–22 and Article 34 of the Regulation, as well as those provisions , with respect to the rights and obligations set forth in Article 5, provided that the restriction respects the essence of fundamental rights and freedoms, and is a necessary and proportionate measure in a democratic society to protect the following:

a) national security;

b) national defense;

(c) public safety;

d) the prevention, investigation, and detection of criminal offenses, or the conduct of criminal proceedings, as well as the enforcement of criminal sanctions, including protection against and prevention of threats to public safety;

(e) other important objectives of general public interest of the Union or a Member State, in particular, an important economic or financial interest of the Union or a Member State, including monetary, budgetary, and tax matters, public health, and social security;

(f) the independence of the judiciary and the protection of judicial proceedings;

(g) in the case of regulated professions, the prevention, investigation, and detection of ethical violations, and the conduct of related proceedings;

(h) in the cases referred to in subparagraphs (a) through (e) and (g)—even on an ad hoc basis—inspection, investigation, or regulatory activities related to the performance of public authority functions;

(i) the protection of the data subject or the protection of the rights and freedoms of others;

(j) enforcement of civil claims.

2. The legislative measures referred to in paragraph 1 shall, where applicable, contain detailed provisions covering at least:

(a) the purposes of the data processing or the categories of data processing,

(b) the categories of personal data,

(c) the scope of the restrictions imposed,

(d) safeguards designed to prevent misuse, unauthorized access, or unauthorized disclosure,

e) to identify the Data Controller or to define categories of Data Controllers,

(f) the duration of data storage and the applicable safeguards, taking into account the nature, scope, and purposes of the data processing or categories of data processing,

(g) risks to the rights and freedoms of data subjects, and

(h) the right of data subjects to be informed of the restriction, unless this would undermine the purpose of the restriction.

(Article 23 of the Regulation)

Notifying the Data Subject of a Data Breach

1. If the data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Data Controller shall inform the data subject of the data breach without undue delay.

2. The information provided to the data subject referred to in paragraph 1 must clearly and comprehensibly describe the nature of the data breach and must include, at a minimum, the information and measures referred to in Article 33(3)(b), (c), and (d) of Article 33(3) of the Regulation.

3. The data subject need not be informed as described in paragraph 1 if any of the following conditions are met:

(a) the Data Controller has implemented appropriate technical and organizational security measures, and these measures were applied to the data affected by the data breach; in particular those measures—such as the use of encryption—that render the data unintelligible to any person who is not authorized to access the personal data;

(b) following the data breach, the Data Controller has taken additional measures to ensure that the high risk to the data subject’s rights and freedoms referred to in paragraph 1 is unlikely to materialize in the future;

(c) providing such information would require a disproportionate effort. In such cases, the data subjects must be informed through publicly available information, or similar measures must be taken to ensure that the data subjects are informed in an equally effective manner.

4. If the Data Controller has not yet notified the data subject of the data breach, the supervisory authority, after assessing whether the data breach is likely to result in a high risk, may order that the data subject be notified or may determine that one of the conditions mentioned in paragraph 3 has been met.

(Article 34 of the Regulation)

The right to file a complaint with the supervisory authority

1. Without prejudice to other administrative or judicial remedies, every data subject has the right to lodge a complaint with a supervisory authority—in particular in the Member State of his or her habitual residence, the Member State of his or her habitual residence, place of work, or the place where the alleged infringement occurred—if the data subject considers that the processing of personal data relating to him or her infringes this Regulation.

2. The supervisory authority to which the complaint was submitted must inform the customer of developments in the proceedings related to the complaint and its outcome, including the fact that, pursuant to Article 78 of the Regulation, the customer has the right to seek judicial remedy.

(Article 77 of the Regulation)

The right to an effective judicial remedy against the supervisory authority

1. Without prejudice to other administrative or non-judicial remedies, every natural and legal person is entitled to an effective judicial remedy against a legally binding decision of the supervisory authority that concerns them.

2. Without prejudice to other administrative or non-judicial remedies, every data subject has the right to an effective judicial remedy if the supervisory authority competent under Article 55 or 56 of this Regulation fails to address the complaint or fails to inform the data subject within three months of the progress or outcome of the proceedings regarding a complaint submitted pursuant to Article 77.

3. Proceedings against the supervisory authority must be brought before the courts of the Member State in which the supervisory authority has its seat.

4. If proceedings are initiated against a decision by a supervisory authority regarding a matter on which the Board has previously issued an opinion or made a decision within the framework of the Single Supervisory Mechanism, the supervisory authority shall be required to forward that opinion or decision to the court.

(Article 78 of the Regulation)

The right to an effective judicial remedy against the data controller or data processor

1. Without prejudice to the rights available under Article 77 of the Regulation—including the right to file a complaint with the supervisory authority— the right under Article 77 of this Regulation—all data subjects shall have the right to an effective judicial remedy if they consider that their rights under this Regulation have been infringed as a result of the processing of their personal data in a manner that does not comply with this Regulation.

2. Proceedings against the data controller or the data processor must be brought before the courts of the Member State in which the data controller or the data processor has its place of business. Such proceedings may also be brought before the courts of the Member State in which the data subject has his or her habitual residence, unless the data controller or data processor is a public authority of a Member State acting in the exercise of its public powers.

(Article 79 of the Regulation)

CHAPTER VIII

SUBMISSION OF THE APPLICANT'S REQUEST,

MEASURES TAKEN BY THE DATA CONTROLLER

1. The Data Controller shall inform the data subject, without undue delay and in any event within one month of receiving the request, of the measures taken in response to the data subject’s request to exercise his or her rights.

2. If necessary, taking into account the complexity of the request and the number of requests, this deadline may be extended by an additional two months. The Data Controller shall notify the data subject of any extension of the deadline within one month of receiving the request, specifying the reasons for the delay.

3. If the data subject submitted the request electronically, the information must be provided electronically whenever possible, unless the data subject requests otherwise.

4. If the Data Controller does not take action in response to the data subject’s request, it shall, without delay, but no later than one month from the receipt of the request, inform the data subject of the reasons for failing to act, as well as of the data subject’s right to file a complaint with a supervisory authority and to seek judicial remedy.

5. The Data Controller shall provide the information specified in Articles 13 and 14 of the Regulation, as well as information regarding the data subject’s rights (Articles 15–22 and 34 of the Regulation) and related measures, free of charge. If the data subject’s request is manifestly unfounded or excessive—in particular due to its repetitive nature—the Data Controller, taking into account the administrative costs associated with providing the requested information or taking the requested action, may:

a) may charge a fee of 6,350 HUF, or

(b) may refuse to take action based on the request.

The burden of proving that the request is clearly unfounded or excessive rests with the Data Controller.

6. If the Data Controller has reasonable doubts regarding the identity of the natural person submitting the request, it may request additional information necessary to confirm the identity of the data subject.

P-Max Technology, Ltd. 2018.

Appendix 3

__________________________________
employer

INFORMATION SHEET

On the Processing of an Employee's Personal Data
and rights related to the individual

According to the provisions of Act I of 2012 on the Labor Code (hereinafter: Mt.), an employee’s right to privacy may be restricted if the restriction is absolutely necessary for reasons directly related to the purpose of the employment relationship and is proportionate to the objective to be achieved. The employee must be informed in advance of the manner, conditions, and expected duration of any restriction on their right to privacy. An employee may not waive his or her right to privacy in advance in a general manner. An employee may validly make a legal declaration regarding his or her right to privacy only in writing. (Section 9) The employer is obligated to inform the employee about the processing of his or her personal data. For the purpose of fulfilling obligations arising from the employment relationship, the employer may transfer the employee’s personal data to a data processor—specifying the purpose of the data transfer, as provided by law. The employee must be informed of this in advance. The employer may monitor the employee only in connection with conduct related to the employment relationship. The employer’s monitoring and the tools and methods used in the process must not result in a violation of human dignity. An employee’s private life may not be monitored. The employer must inform the employee in advance of the use of any technical devices intended to monitor the employee.

The employer fulfills its obligations under the Labor Code regarding the protection of individual rights as follows.

I. Information on the Processing of Personal Data

1. The employer hereby informs the employee that, in connection with the employment relationship and pursuant to the Labor Code, the employer carries out the following data processing activities on the grounds of protecting the employer’s legitimate interests:

■ Labor and Personnel Records

■ Data Processing Related to Fitness-for-Duty Examinations

■ Data processing related to monitoring the use of email accounts

■ Data processing related to the inspection of computers, laptops, and tablets

■ Data Processing Related to the Monitoring of Internet Use at Work

■ Data Processing Related to the Monitoring of Company Cell Phone Use

■ Data Processing Related to the Use of the GPS Navigation System

■ Data Processing Related to Checking In and Out at Work

■ Data Processing Related to Workplace Video Surveillance

2. The Employer hereby informs the employee that, for the purpose of complying with a legal obligation—namely, fulfilling tax and social security contribution obligations prescribed by law (assessment of taxes, tax advances, and social security contributions; payroll processing; social security administration), the Employer processes the personal data of employees—and, based on their declarations, their family members—as required by tax laws (payor data processing).

3. The employee hereby declares that he or she has read the employer’s data processing policy, specifically the section on data processing related to the employment relationship, which covers the scope of personal data that may be processed, the purpose of data processing, the duration of data storage, the recipients of the data, as well as the provisions regarding payroll data processing, data security measures, and the employee’s rights concerning data processing, and that the employer has thereby fulfilled its obligation to provide this information.

II. Information on Data Processors

1. The employer informs the employee that it may transfer the employee’s personal data to a data processor—as provided by law—in order to fulfill tax, contribution, and social security obligations arising from the employment relationship.

Name and address of the accounting firm performing this data processing:

_________________________________

The identity of this designated data processor may change during the term of the employment relationship.

2. The employer’s security officer—acting as a data processor—may process data from the video surveillance system, as well as data regarding who enters and exits the premises.

Name and address of the security service provider:

_______________________________

The identity of this designated data processor may change during the term of the employment relationship.

3. List of additional data processors:

___________________________________________

III. Information on the Use of Technical Devices for Monitoring Employees

The employer hereby informs the employee that it uses the following technical devices to monitor the employee’s conduct in connection with the employment relationship:

1. Identity Check

The employer—or, on its behalf, the security service provider—is entitled to ask an employee entering or leaving the workplace to present their belongings, while explaining the reason and purpose of the planned measure, if

a) there are reasonable grounds to believe that the individual is in possession of property resulting from the crime or misdemeanor in question, the safekeeping of which is a contractual obligation of the security guard;

b) he refuses to hand this over despite being ordered to do so; and

c) The measure is necessary to prevent or stop the unlawful act.

For this purpose, a body search may be conducted. A body search may be conducted only by a person of the same sex as the person being searched, and only such a person may be present during the search. This provision does not apply to a physician assisting with the search.

2. Use of an electronic monitoring system

The employer may use an electronic surveillance system at the workplace to protect human life, physical integrity, personal freedom, trade secrets, and property, which may include the recording of video, audio, or both video and audio.

Electronic surveillance systems may not be used in any room where surveillance could violate human dignity, such as, in particular, changing rooms, showers, restrooms, or, for example, a medical examination room and its associated waiting area, nor in any room designated for employees to spend their breaks.

If no one is legally permitted to be on the workplace premises (particularly outside of working hours or on non-working days), then the entire workplace area (including, for example, locker rooms, restrooms, and areas designated for breaks) may be monitored.

In addition to those authorized by law, the operating staff, the employer’s manager, and the manager’s deputy are authorized to view the data recorded by the electronic monitoring system for the purpose of detecting violations and monitoring the system’s operation.

We retain recorded footage for a maximum of 3 (three) business days if it is not used. Use is defined as the intention to use recorded video, audio, or video and audio recordings, as well as other personal data, as evidence in court or other official proceedings. Any person whose rights or legitimate interests are affected by the recording of image, audio, or video and audio recordings may, within three business days of the recording of the image, audio, or image-and-audio recording, request—by providing evidence of their rights or legitimate interests—that the data controller not destroy or delete the data.

The employer shall inform the employee of the location of the installed cameras, their coverage area (field of view), and the purpose of their installation, as follows.

Camera Number

Location of the placement

Observed area

The purpose of the placement

Chamber No. 1

Retail Space

Sales Area

Asset Protection

Camera No. 2

Asset Protection, Protection of Trade Secrets

3. Access Control System

The employer uses an electronic time-and-attendance system at the workplace to monitor employees' compliance with their obligations.

The identification information (name and address) of those authorized to enter, which is processed for the operation of the electronic access control system

a) in the case of regular access, immediately upon the termination of the right to access,

b) In the case of a one-time visit, twenty-four hours after departure

It must be destroyed.

Data generated during the operation of the electronic access control system (e.g., time of entry)

a) in the case of regular access, upon the termination of the right to access, but no later than six months after the data was generated,

b) In the case of a one-time visit, twenty-four hours after departure

It must be destroyed.

Data from the access control database may be disclosed to the security service, to investigative authorities upon detection of a suspected crime or misdemeanor, or to administrative authorities upon request.

4. Information on Monitoring Cell Phone Use

The employer does not permit the use of company cell phones for personal purposes; the cell phone may only be used for work-related purposes, and the employer may monitor the phone numbers and details of all outgoing calls, as well as the data stored on the cell phone. The employee is required to notify the employer if the company cell phone was used for personal purposes. In such cases, the inspection may be conducted the employer requests a call detail record from the telephone service provider and instructs the employee to obscure the numbers dialed for personal calls on the document. The employer may require the employee to bear the costs of personal calls.

5. Information on Monitoring the Use of Company Vehicles

The employer is authorized to use a vehicle tracking system in company vehicles used by employees for the purposes of retroactive route verification, identifying unjustified detours, fuel accounting, and asset protection.

6. Information on Monitoring Computer and Internet Use

The employer does not permit employees to use workplace computers, email systems, or the Internet for personal purposes.

The employer has the right to inspect and monitor the company computer and company email account used by the employee. The employee is required to delete any files or content unrelated to work from the computer or email account upon the employer’s request.

7. Information on Restrictions on Conduct Outside of Working Hours

According to Section 8(2) of the Labor Code, „Even outside of working hours, an employee may not engage in conduct that—particularly given the nature of the employee’s position and the employee’s standing within the employer’s organization— — is directly and effectively capable of jeopardizing the employer’s reputation, legitimate economic interests, or the purpose of the employment relationship. The employee’s conduct may be restricted as provided in Section 9(2). The employee must be notified of the restriction in writing in advance.” Based on this, the employer sets forth the following expectation regarding the employee’s conduct and expression of opinions outside of working hours: the employee may not engage in any conduct or express opinions that are directly and effectively likely to cast the employer in a negative light or to jeopardize the employer’s legitimate economic interests or the purpose of the employment relationship.

EMPLOYER: ________________________________

***

Clause:

I, the undersigned employee, hereby certify with my signature that I have read this Notice prior to signing it, that I have understood and acknowledged its provisions, and that I have received a copy of it.

Dated _______________________, 20____, _________________, ____

NAME: _________________________

SIGNATURE:_______________________

Appendix 4

__________________________________
employer

INFORMATION SHEET

Regarding the fitness examination for an employee

I.

An employee may only be subject to an aptitude test that is required by a rule governing the employment relationship or that is necessary for the exercise of a right or the fulfillment of an obligation specified in a rule governing the employment relationship. Prior to the assessment, employees must be provided with detailed information, including which skills and abilities the fitness-for-duty assessment is intended to evaluate, and what tools and methods will be used to conduct the assessment. If the assessment is required by law, employees must be informed of the title of the law and the specific statutory provision.

II.

The legislation requiring the fitness examination is Decree No. 33/1998 (VI. 24.) of the Ministry of Health on Medical Examinations and Assessments of Job, Professional, and Personal Hygiene Fitness.

For the purposes of this regulation:

a) job suitability assessment:determining the level of physical strain imposed on the person being evaluated by the activities performed in a specific job and at a specific workplace, and whether the person is capable of meeting those demands;

b) professional aptitude test:a medical examination conducted prior to beginning training in the profession, or during the training or retraining period, for the purpose of assessing fitness for the profession;

c) personal hygiene screening:to determine that an infectious disease in a person working in a high-risk area from an epidemiological perspective does not pose a threat to the health of others, or, in certain cases, that the person’s status as a carrier of a pathogen does not pose a threat to the health of others;

d) person performing work:anyone who, outside the context of organized work, carries out activities in a work area designated as a high-risk area from an epidemiological perspective;

Section 3 of the Regulation specifies which skills and abilities the aptitude test is designed to assess:

Section 3(1) Assessment of suitability:

a)in the case of job suitability, for the position specified by the employer,

b)in the case of professional qualifications, the specific occupation or vocational training; in the case of job seekers, vocational training, retraining, or the identification of occupational groups or occupations suitable for the individual,

c)in the case of personal hygiene compliance, for activities carried out in work areas of high epidemiological significance

is happening.

(2) Medical examinations of job suitability and professional fitness may be preliminary, periodic, or special. The examination and assessment of job suitability shall be supplemented by a final examination in the cases specified in Section 8. For students applying to a vocational training institution, a school medical examination may be conducted at the time of enrollment—at the request of the teacher, parent, or student—for the purpose of career counseling.

(3) Personal hygiene fitness examinations may be preliminary, periodic, or unscheduled.

(4) The purpose of the job and professional aptitude assessment is to determine whether the employee, student, or job seeker:

a)wear and tear caused by the physical demands of the work and the work environment

aa)whether it poses a risk to their health or their physical or mental well-being,

(ab)whether it adversely affects his or her health,

ac)whether it could cause harm to the physical, intellectual, or psychological development of their offspring;

b)Does any chronic illness or disability pose a risk of injury while performing the job duties or while learning and practicing the profession?;

c)whether, when working in positions or professions of high epidemiological significance, the individual’s personal hygiene and health status pose a risk to the health of others, and whether the individual is eligible for employment in that position;

d)in what type of position or occupation, and under what conditions, a person may be employed without the risk of their condition worsening, if their ability to work has changed temporarily or permanently;

e)whether they can continue to work in their current position or continue their studies in their chosen field;

f)whether the employee has a medical condition that requires regular occupational health examinations in the course of performing his or her job;

g)In the case of work performed abroad, is the individual expected to be physically fit to perform the specified professional duties in the given country?.

(5) The purpose of the personal hygiene fitness examination is to determine whether the health status of the person performing the work—when carrying out the activity—poses a risk to the health of others in work areas of high epidemiological significance, and and whether they may continue to work in that specific work area.

(6)The assessment of suitability for a job, professional competence, and personal hygiene, as well as the expert opinion on employability, does not extend to determining the extent of changes in work capacity, the degree of disability, or assessing mental capacity and mental state.

(7) The obligation to undergo screening for HIV infection as part of an extraordinary occupational or personal hygiene fitness examination, as well as the procedures for conducting such screenings, are established by separate legislation.

III.

Examination tools and methods: urinalysis, medical history, vision screening, general internal medicine examination, and additional specialized tests.

***

Clause:

I, the undersigned employee, hereby certify with my signature that I have read this Notice prior to signing it, and that I have understood and acknowledged its provisions.

Dated _______________________, 20____, _________________, ____

NAME: _________________________

SIGNATURE:_______________________

Appendix 5

INFORMATION SHEET

ON THE USE OF A CAMERA-BASED SURVEILLANCE SYSTEM

Dear Visitor!

Please be advised that our company uses an electronic surveillance system in the room marked with this sign to protect human life, physical integrity, personal freedom, protection of trade secrets, and protection of property, which enables the recording and storage of video, audio, or both video and audio. The camera also records your behavior.

The legal basis for this data processing is your voluntary consent. If you enter the monitored area despite this notice, your consent to the recording of video and audio will be deemed to have been given. Please do not enter if you do not wish to give your consent.

Location where the recording is stored: our company's facility: 8184 Balatonfűzfő, Industrial Park 1/ Gate A.

Storage period: 3 business days.

Person responsible for the system (operator): Miklós Németh

Persons authorized to access the data: Managing Director, Deputy Managing Director, and administrative staff.

Your rights and the procedures for exercising them are set forth in Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information. Pursuant to this Act, subject to the conditions set forth therein, you may request information regarding our data processing, request the correction, erasure, or blocking of your personal data, object to the processing of your personal data, bring a lawsuit in the event of a violation of your rights, and claim compensation for damages and compensation for non-pecuniary harm. For further details, please read the law, which can be found here: www.njt.hu

P-Max Technology

Limited Liability Company

Headquarters: 8220 Balatonalmádi, Szabadság St. 26.

Appendix 6

DATA PROCESSING CLAUSE

CONTRACT WITH A NATURAL PERSON

1. The data controller hereby informs the contracting party (hereinafter referred to as the “data subject”) that it processes the personal data provided in the contract on the legal basis of the performance of the contract.

2. Recipients of personal data: the Company’s employees who perform customer service duties, employees who perform accounting and tax-related duties, and data processors.

3. Retention period for personal data: 5 years following the termination of the contract.

4. Personal data will be transferred for processing to the accounting firm engaged by the company for tax and accounting purposes to the accounting firm commissioned by the company; for mailing and shipping purposes to Magyar Posta or the commissioned courier service; and for property protection purposes to the company’s property protection agent.

5. Information regarding the rights of the data subject and the identities of the data processors can be found in the Privacy Policy available on the Company’s website (in the footer).

****

I have read and understood the information and notices above.

Dated, ______________________ 20 ____, _____________, _____

____________________________

Signature of the person concerned

Appendix 7

DECLARATION OF CONSENT

PROCESSING OF CONTACT INFORMATION FOR REPRESENTATIVES OF NATURAL PERSONS WHO ARE CONTRACTING PARTIES OF LEGAL ENTITIES

NAME OF THE DATA SUBJECT:

POSITION:

ADDRESS:

PHONE NUMBER:

E-MAIL ADDRESS:

ONLINE ID (if applicable):

INFORMATION:

DATA CONTROLLER:

Company name, representative:

THE DATA CONTROLLER'S WEBSITE:

www.

PURPOSE OF DATA PROCESSING:

Performance of a contract; maintaining business relationships.

LEGAL BASIS FOR DATA PROCESSING:

Consent of the Data Subject

RECIPIENTS OF PERSONAL DATA:

The Company's employees who perform customer service-related duties;

PERIOD OF STORAGE OF PERSONAL DATA:

For 5 years following the termination of the business relationship or the representative’s term of office.

Personal data may be transferred for processing to Magyar Posta or an authorized courier service for the purpose of mailing or delivery, or to the company’s security officer for the purpose of property protection.

INFORMATION ON THE RIGHTS OF DATA SUBJECTS:

You have the right to You may request from the data controller access to your personal data, its correction, erasure, or restriction of processing, and you may object to the processing of such personal data; you also have the right to data portability.

You have the right to withdraw your consent at any time, which does not affect the lawfulness of the data processing carried out on the basis of your consent prior to the withdrawal.

You have the right to file a complaint with the supervisory authority (National Authority for Data Protection and Freedom of Information)

Providing personal information is not a prerequisite for entering into a contract, and you are not required to provide it. Failure to provide personal information may make it difficult to maintain contact.

Further information can be found in the Privacy Policy available on the Company's website (in the footer).

****

I have read and understood the information provided above, and I consent to the processing of my personal data for the purposes described above.

Dated, ______________________ 20 ____, _____________, _____

____________________________

Signature

Appendix 8

_________________________________________

Name of Employer

CONFIDENTIALITY AGREEMENT

EMPLOYEE'S NAME:

JOB DESCRIPTION:

Given that my employer, 6920 — with respect to its accounting, auditing, and tax consulting activities—is subject to the EU General Data Protection Regulation (GDPR) No. 2016/679 and Act CXII of 2011 , and since, according to these laws, the data processor must ensure that persons authorized to process personal data undertake a duty of confidentiality, and having familiarized myself with the definition of „personal data” Regulation, which defines personal data as any information relating to an identified or identifiable natural person („data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person—

I hereby make the following confidentiality statement:

1. I hereby undertake to process and disclose any personal data that comes to my attention in the course of my work for the aforementioned employer solely for the purpose of performing my job duties, I will not use it for any other purpose, I will not disclose it to or transfer it to any unauthorized person, I will not permit unauthorized access to the personal data, and I will not make the personal data public.

2. I acknowledge that this confidentiality obligation shall remain in effect even after the termination of my employment or any other legal relationship involving the performance of work.

3. I acknowledge that a breach of the confidentiality obligation constitutes a material breach of the obligations arising from the employment relationship, for which the employer may impose legal consequences under labor law. I acknowledge the information regarding the criminal offense of breach of privacy under Section 223 of the Criminal Code, which states that anyone who, without good cause, discloses private information that has come to their knowledge in the course of their occupation or public office, shall be punished by imprisonment for a misdemeanor. The penalty is imprisonment for up to one year if the offense causes significant harm to interests.

Dated ___________________ 20 ____, _____________ month, _____ day

____________________________

the employee's signature

Appendix 10

_________________________________________

Name of Employer

EMPLOYMENT CONTRACT CLAUSE REGARDING FAMILIARIZATION WITH AND COMPLIANCE WITH THE DATA PROCESSING POLICY, AND THE OBLIGATION OF CONFIDENTIALITY

1. The employee hereby declares that he or she has read and understood the employer’s privacy policy.

2. In the course of performing their work, employees are required to apply and enforce the provisions of the data processing policy with respect to the processing of personal data.

3. Compliance with and enforcement of the Data Processing Policy constitute essential obligations arising from the employment relationship; any violation thereof will result in legal consequences under labor law.

4. The employee agrees to process and disclose personal data obtained in the course of his or her work for the employer solely for the purpose of performing his or her job duties, not to use it for any other purpose, not to disclose it to or transfer it to any unauthorized person, not to permit unauthorized access to such personal data, and not to make such personal data public. The employee acknowledges that this confidentiality obligation remains in effect even after the termination of my employment or any other legal relationship for the purpose of performing work. The employee acknowledges that a breach of the confidentiality obligation constitutes a material breach of the obligations arising from the employment relationship, for which the employer may impose legal consequences under labor law; the employee further acknowledges the information regarding the criminal offense of violation of private confidentiality under Section 223 of the Criminal Code, Section 223 of the Criminal Code, which states that anyone who, without good cause, discloses a private secret that has come to their knowledge by virtue of their occupation or public office shall be punished by imprisonment for a misdemeanor. The penalty is imprisonment for up to one year if the offense causes significant harm to interests.

Dated ___________________ 20 ____, _____________ month, _____ day

____________________________

the employee's signature