Privacy Policy
1. What is the purpose of this Privacy Notice?
This Notice is adopted to provide natural persons and representatives of legal persons using our services (hereinafter: Users) with all essential information and disclosures in a concise, transparent, intelligible, and easily accessible form, expressed in clear and plain language, and to assist Users in exercising their rights specified in Section 4. Our services are accessible on the webdiamond.hu website.
Our obligation to provide information is based on Article 12 of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR), applicable as of 25 May 2018; Section 16 of Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (hereinafter: Info Act); and Section 4 of Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services.
This Notice has been prepared in accordance with the GDPR, the Info Act, and other relevant legal provisions governing specific data processing operations. A list of applicable legislation is provided in Annex 10.1, key definitions are contained in Annex 10.2, and a detailed description of individual data subject rights can be found in Annex 10.3 of this Notice.
During the drafting and implementation of this Notice, we acted in compliance with the findings set out in the recommendation of the National Authority for Data Protection and Freedom of Information (NAIH) on the data protection requirements for prior information, as well as Article 5 of the GDPR, with particular regard to the principle of accountability set forth in Article 5(2).
Furthermore, we continuously monitor European Union practices regarding the protection of personal data; accordingly, we incorporate the guidelines on transparency issued by the European Commission's Article 29 Working Party into our data processing practices.
2. Data Controller
Name: Kárpáti Dávid
Registered address: 8100, Várpalota, Thököly Imre utca 25.
Email: info@webdiamond.hu
Phone number: +36 70 246 2437
3. Data Processing Activities
This section describes the main circumstances relating to the processing of personal data carried out in connection with the services and communication channels provided by Webdiamond.
3.1 Contact and Communication
Users may contact Webdiamond through the website, by e-mail, by telephone or through other communication channels made available by Webdiamond. Personal data relating to business partners and their designated contact persons may also be processed where necessary for business communication and the performance or administration of contractual relationships.
3.1.1 Personal Data Processed and Purposes of Processing
Name Purpose of processing: identification of the user or the designated contact person of a business partner. E-mail address Purpose of processing: establishing and maintaining communication with the user or business partner. Telephone number Purpose of processing: establishing and maintaining communication with the user or business partner where telephone communication is used. Publicly available social media profile information Where communication takes place through a social media platform, publicly available profile information may be visible to Webdiamond. Purpose of processing: identification of the person communicating with Webdiamond and maintaining communication. The processing of such information is limited to information made publicly available by the user or information otherwise provided by the user through the relevant communication channel.
Contact Form – Message / Comment Field
Where a user voluntarily enters personal information into the message or comment field of the website's contact form, such information may be processed for the purpose of responding to the user's enquiry, maintaining communication and handling the request. The information processed may include any personal information voluntarily included by the user in the message. The legal basis for processing depends on the nature of the enquiry and the circumstances of the communication. Where processing is necessary in order to take steps at the request of the data subject prior to entering into a contract, Article 6(1)(b) of the GDPR may apply. Where another legal basis applies, the processing will be carried out on that basis. Users should not provide sensitive personal data or other unnecessary personal information through the contact form.
Data Subject Rights
Users have the right, subject to the conditions of the GDPR and applicable law, to: request access to their personal data; request rectification of inaccurate or incomplete personal data; request erasure of personal data; request restriction of processing; object to certain processing activities; request data portability where the legal conditions are met. Requests may be submitted using the contact details provided in Section 2 of this Privacy Policy.
3.1.2 Legal Basis for Processing The legal basis for processing depends on the nature of the communication and the purpose for which the personal data are processed. Where processing is necessary in order to take steps at the request of the data subject prior to entering into a contract, or to perform a contract, the legal basis may be Article 6(1)(b) GDPR. Where processing is necessary for the purposes of the legitimate interests pursued by Webdiamond or a third party, Article 6(1)(f) GDPR may apply. This may include maintaining ordinary business communication with business partners and their designated contact persons. Where processing is based on consent, the legal basis is Article 6(1)(a) GDPR. Consent may be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. If personal data are intended to be processed for a purpose materially different from the purpose for which they were originally collected, the user will be provided with the information required by applicable data protection legislation and, where necessary, appropriate consent will be obtained.
3.1.3 Retention Period Personal data processed for communication purposes will be retained only for as long as necessary for the relevant purpose. Where the processing is based on consent, the data may be retained until the consent is withdrawn, unless another legal basis for continued processing exists. Where personal data are processed in connection with a contractual relationship, the data may be retained for as long as necessary for the performance and administration of the contractual relationship and thereafter for as long as required or permitted by applicable law. Certain accounting and business records may be subject to statutory retention periods under Hungarian law.
3.1.4 Form of Processing Personal data are primarily processed electronically.
3.1.5 Data Security in Relation to Business Partners and Users Taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of processing, and the risks to the rights and freedoms of natural persons, appropriate technical and organisational measures are implemented to ensure a level of security appropriate to the risk. Such measures may include access controls, password protection, software updates, secure connections, appropriate hosting security and other measures appropriate to the systems and services actually used by Webdiamond.
3.2 Processing of Personal Data in Connection with Complaints
Users may contact Webdiamond by e-mail or telephone with questions, complaints or requests concerning the services. Personal data provided in connection with a complaint may be processed for the purpose of identifying the complainant, investigating and handling the complaint, communicating with the complainant and fulfilling applicable legal obligations.
3.2.1 Personal Data Processed and Purpose
Name Purpose: identification of the complainant. E-mail address Purpose: communication with the complainant and providing information concerning the complaint. Telephone number Purpose: communication with the complainant where telephone communication is required or requested. Additional information provided by the complainant may also be processed where it is necessary for the investigation and handling of the complaint.
3.2.2 Legal Basis
Where the processing is necessary for compliance with a legal obligation to which the Data Controller is subject, the legal basis is Article 6(1)(c) GDPR together with the applicable provisions of Hungarian law, including the Hungarian Consumer Protection Act (Act CLV of 1997).
Where processing is not required by law but is necessary for the handling of a request or communication, another appropriate legal basis under Article 6 GDPR may apply.
3.2.3 Retention Period Complaints and the related records are retained for the period required by applicable Hungarian consumer protection legislation. Where a statutory retention period applies, the records will be retained for that period.
3.2.4 Form of Processing Personal data are primarily processed electronically.
4. Rights of Users and Data Subjects
Webdiamond respects the rights of data subjects under the GDPR and applicable Hungarian law. Depending on the circumstances and the applicable legal basis, users may exercise the following rights.
Right of Access The data subject has the right to obtain confirmation as to whether personal data concerning them are being processed and, where this is the case, to obtain access to those personal data and information concerning the processing.
Right to Rectification The data subject has the right to request the rectification of inaccurate personal data without undue delay and, taking into account the purposes of the processing, to request completion of incomplete personal data.
Right to Erasure The data subject may request the erasure of personal data where one of the conditions set out in Article 17 GDPR applies. The right to erasure is not absolute and does not apply where continued processing is required or permitted by law.
Right to be Forgotten Upon our User's request for erasure, we will make reasonable efforts to inform all data controllers who have processed or may have accessed any personal data of the User that may have been made public.
Right to Restriction of Processing The data subject may request restriction of processing in the circumstances specified in Article 18 GDPR, including where the accuracy of the personal data is contested or where the processing is considered unlawful and the data subject requests restriction instead of erasure.
Right to Data Portability Where the legal conditions of Article 20 GDPR are met, the data subject has the right to receive personal data concerning them, which they have provided to the controller, in a structured, commonly used and machine-readable format and, where technically feasible, to transmit those data to another controller.
Right to Object Where processing is based on Article 6(1)(e) or Article 6(1)(f) GDPR, the data subject has the right to object to the processing on grounds relating to their particular situation. Where personal data are processed for direct marketing purposes, the data subject has the right to object to such processing at any time.
Response to Requests Requests concerning data subject rights will normally be answered without undue delay and, in any event, within one month of receipt. Where necessary, taking into account the complexity and number of requests, this period may be extended by a further two months. The data subject will be informed of any such extension within one month of receipt of the request, together with the reasons for the delay. Information and actions relating to the exercise of data subject rights are generally provided free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, the Data Controller may, in accordance with Article 12(5) GDPR, charge a reasonable fee or refuse to act on the request. Where there are reasonable doubts concerning the identity of the person making a request, additional information may be requested to confirm the identity of the data subject.
Remedies Webdiamond encourages users to contact the Data Controller first so that any data protection concerns can be addressed directly. If the data subject considers that their rights have been infringed, they may lodge a complaint with the competent supervisory authority. In Hungary, the competent supervisory authority is: National Authority for Data Protection and Freedom of Information (NAIH) 1055 Budapest, Falk Miksa utca 9–11. Postal address: 1363 Budapest, PO Box 9 Telephone: +36 1 391 1400 E-mail: ugyfelszolgalat@naih.hu Website: https://naih.hu The data subject may also seek judicial remedy in accordance with applicable Hungarian law.
5. Procedure for Exercising Data Subject Rights
Notification of Recipients Where required under Article 19 GDPR, the Data Controller will communicate any rectification, erasure or restriction of processing to recipients to whom the relevant personal data have been disclosed, unless this proves impossible or involves disproportionate effort. Upon request, the data subject will be informed about such recipients.
Form and Time Limit of Information Information concerning measures taken in response to a data subject request will normally be provided electronically unless the data subject requests another form or applicable circumstances require otherwise. The request will be handled within the time limits specified by the GDPR. The ordinary time limit is one month from receipt of the request. This period may be extended by up to two additional months where necessary due to the complexity or number of requests.
Identity Verification Where there are reasonable doubts concerning the identity of the person making a request, additional information may be requested where this is necessary to confirm the identity of the data subject. This measure is intended to prevent unauthorised access to personal data.
Costs Requests and the actions taken in response to them are generally provided free of charge. If a request is manifestly unfounded or excessive, particularly because of its repetitive character, a reasonable administrative fee may be charged or the request may be refused, in accordance with Article 12(5) GDPR.
6. Recipients and Data Processors
6.1 Website Hosting and Infrastructure Personal data processed through the website may be accessible to the hosting and infrastructure provider acting as a data processor, where necessary for the provision and maintenance of the website and related services.
The hosting and infrastructure services used by the website are provided by Rackhost Zrt. For further information regarding Rackhost's own data processing practices, please see: https://www.rackhost.hu/privacy-policy Adatkezelési tájékoztatójukra.
Hosting provider details:
Company: Rackhost Zrt. Registered office: 6722 Szeged, Tisza Lajos körút 41. Tax number: 25333572-2-06 Company registration number: 06-10-000489 E-mail: info@rackhost.hu Customer service: +36 1 445 1200
E-mail Service Provider Service provider: Rackhost https://rackhost.hu/ Webmail: https://webmail.rackhost.hu/ Purpose of processing: sending, receiving and storing e-mail communications and maintaining communication with users and business partners. The categories of personal data processed may include the sender's and recipient's contact details, the contents of e-mail communications and technical information generated in connection with the operation of the e-mail service.
6.2 Social Media
Webdiamond maintains social media profiles, including a Facebook page.
When a user interacts with a Webdiamond social media profile, the relevant social media platform may process personal data in accordance with its own privacy policy.
Information that a user has made publicly available through their social media profile may be visible to Webdiamond when the user interacts with the Webdiamond profile.
Further information concerning such processing is available in the privacy policy of the relevant social media provider.
6.3 Joint Data Controller Relationship with Facebook The data processing carried out in cooperation with Facebook—depending on the specific purpose of the processing—is governed by the following: We are jointly responsible with Facebook for the processing of your personal data for the purposes of creating target audiences, delivering commercial and transaction-related messages, personalizing features and content, and improving and securing Facebook products. In order to comply with the GDPR, the agreement clarifying the allocation of responsibilities is available at the following link: https://www.facebook.com/legal/controller_addendum.
On this website, we use Facebook Pixel technology. This is an analytical tool that enables us to track user activity on the website, thereby optimizing our advertisements and marketing campaigns. The Facebook Pixel places cookies on your device and collects the following data:
- Page visits
- Clicks and interactions
- Other conversions
The collected data is used exclusively to improve the effectiveness of advertisements and to optimize online marketing activities. The processing of this data is carried out in accordance with Facebook's privacy policy.
Under the joint controller agreement, Facebook is primarily responsible for providing information about the data processing and for enabling data subjects to exercise their rights under the GDPR. For further information on the processing of your personal data by Facebook, as well as your rights and options in this regard, please refer to Facebook's Privacy Policy, which you can access here: https://www.facebook.com/about/privacy/. Otherwise, the parties remain independently responsible for the processing of personal data. Data processing carried out by us is based on your consent, pursuant to Article 6(1)(a) of the GDPR. You may withdraw your consent at any time for the future by changing your preferences in the cookie banner. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
7. Data Security Our employees and those of the data processors are entitled to access the User's personal data to the extent necessary for the fulfillment of their duties related to their role. We take all security, technical, and organizational measures required to guarantee data security.
Organizational Measures Access to our IT systems is strictly granted via individual user permissions. Access allocation follows the "principle of least privilege" (necessary and sufficient rights), meaning that every employee may use our IT systems and services only to the extent necessary to perform their tasks, with appropriate permissions, and for the necessary duration. Access rights to IT systems and services are granted only to individuals who are not subject to restrictions for security or other reasons (e.g., conflict of interest) and who possess the necessary professional, business, and information security knowledge required for safe usage. Technical Measures Data—excluding data stored by our data processors—is stored on our own equipment within a data center. The IT infrastructure storing data is segregated and kept in a separate, locked server room, protected by a multi-step access control system tied to authorization verification. We protect our internal network with multi-layer firewall defense. A hardware firewall (perimeter defense device) is deployed at all entry points to the public networks used. Data is stored redundantly—meaning in multiple locations—to protect it against destruction, loss, damage, or unlawful destruction resulting from IT equipment failure. We protect our internal networks from external attacks using multi-level, active, complex anti-malware protection (e.g., antivirus software). Essential external access to the IT systems and databases operated by us is implemented via encrypted data connections (VPN). We make every effort to ensure that our IT devices and software continuously comply with generally accepted technological standards in business operation. During development, we design systems where actions performed can be controlled and tracked through logging, allowing for the detection of incidents such as unauthorized access.
Our server is located in a protected, isolated environment on the hosting provider's dedicated server. In consideration of the NAIH (National Authority for Data Protection and Freedom of Information) recommendations regarding data protection requirements for political party websites, we use the HTTPS protocol on our website, which provides a higher level of data security compared to the HTTP protocol.
8. Cookies
Like most modern websites, the Webdiamond website may use cookies and similar technologies for technical functionality, preferences, security, analytics and, where applicable, marketing purposes.
Detailed information concerning the cookies used by the website and the available cookie settings can be found in the: https://webdiamond.hu/en/cookie-szabalyzat/
What is a Cookie? A cookie is a small text file that a website stores on a user's computer, smartphone or other device. Cookies can enable a website to remember certain information, such as language preferences, settings or other technical information, so that the user does not have to configure these settings each time they visit the website. Different types of cookies may serve different purposes. Some cookies are technically necessary for the operation and security of the website, while others may require the user's consent under applicable law.
Managing Cookies Users can usually delete or block cookies through their browser settings. Further information about cookies is available at: https://www.allaboutcookies.org/ Information concerning cookie management is also available for common browsers:
9. Other Provisions
Processing for a Different Purpose If personal data are intended to be processed for a purpose different from the purpose for which they were originally collected, the Data Controller will provide the information required by applicable data protection legislation before carrying out such further processing. Where the new processing requires consent, appropriate consent will be obtained.
Records of Processing Activities Where required by Article 30 GDPR, Webdiamond maintains records of processing activities under its responsibility.
Personal Data Breaches A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. In the event of a personal data breach, the Data Controller will take the measures required by Articles 33 and 34 GDPR and applicable Hungarian law. Where required, personal data breaches will be documented, including relevant facts, consequences and remedial measures.
Amendments to this Privacy Policy The Data Controller reserves the right to amend this Privacy Policy where necessary. Amendments may become necessary due to changes in applicable legislation, regulatory guidance, the services provided, the technical environment, data processing activities or other relevant circumstances. The current version of this Privacy Policy will be made available on the website.
10. Annexes
Annex 1 – Applicable Legislation
When drafting this Privacy Notice, the Data Controller took into account the relevant legislation in force, as well as key international recommendations, with particular regard to the following: Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation / GDPR);
Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (Info Act);
Act V of 2013 on the Civil Code (Civil Code);
Act CXXX of 2016 on the Code of Civil Procedure (CCP);
Act C of 2000 on Accounting (Accounting Act);
Act CLV of 1997 on Consumer Protection (Consumer Protection Act);
Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (E-Commerce Act).
Annex 2: Definitions Relating to the Processing of Personal Data
Data controller: The legal person that determines the purposes and means of the processing of personal data.
Data processing: Any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Data transfer: Making data accessible to a specific third party.
Data erasure: Rendering data unrecognizable in such a way that its recovery is no longer possible.
Data marking: Marking data with an identifier tag for the purpose of distinguishing it.
Restriction of processing: The marking of stored personal data with the aim of limiting its processing in the future.
Data destruction: The complete physical destruction of the data medium containing the data.
Data processor: The legal person that processes personal data on behalf of the data controller.
Recipient: A natural or legal person, public authority, agency, or another body to which the personal data is disclosed, whether a third party or not.
Cookie: A small data packet (text file) sent by the web server and stored on the user's computer for a specified period, which, depending on its nature, the server can append to upon subsequent visits—meaning that if the browser sends back a previously saved cookie, the service provider handling the cookie can link the user's current visit to previous ones, strictly in relation to its own content.
Data subject / User: An identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
Third party: A natural or legal person, public authority, agency, or body other than the data subject, data controller, data processor, and persons who, under the direct authority of the data controller or data processor, are authorized to process personal data.
Consent of the data subject: Any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
IP address: In all networks using the TCP/IP protocol for communication, server devices possess an IP address—a unique numerical identifier—that enables the identification of given devices across the network. Every computer connected to a network has an IP address through which it can be identified.
Personal data: Any information relating to the data subject.
Objection: A declaration by the data subject objecting to the processing of their personal data, requesting the termination of data processing and the erasure of the processed data.
Annex 3: Data Subject Rights
Right of Access The User has the right to receive access to their personal data processed by us upon request submitted via one of our contact channels. Under this right, the User shall be informed of the following: Whether or not their personal data is being processed;
The purposes of the data processing;
The categories of personal data concerned;
The recipients or categories of recipients to whom the personal data have been or will be disclosed;
The envisaged period for which the personal data will be stored;
Their rights;
Their remedies;
Information concerning the sources of data. The User may also request a copy of the personal data undergoing processing. In this case, we will provide the personal data in a structured, commonly used, machine-readable format (PDF/XML), or in a printed paper version. Requesting a copy is free of charge.
Right to Rectification The User has the right to request—via a request submitted through our contact details—the rectification of inaccurate personal data concerning them and the completion of incomplete data processed by us. If we do not possess the necessary information to rectify or complete the inaccurate information, we may request the submission of such supplementary data and proof of the accuracy of the data. Until the rectification or completion of the data can be carried out (due to a lack of supplementary information), we shall restrict the processing of the personal data concerned and temporarily suspend operations performed on them, with the exception of storage. Right to Erasure (Right to Be Forgotten) The User has the right to request—via a request submitted through our contact details—the erasure of personal data concerning them processed by us, provided that one of the following conditions applies:
We no longer need the given data for the intended purposes; The User has concerns regarding the lawfulness of our processing of their data. If, following the User's request, we determine that an obligation to erase the personal data processed by us exists, we will terminate the processing of the data and destroy the previously processed personal data. In addition, the obligation to erase personal data may also arise from the withdrawal of consent, the exercise of the right to object, or legal obligations.
Right to Restriction of Processing The User has the right to request—via a request submitted through our contact details—the restriction of the processing of their personal data processed by us in the following cases:
The User has concerns regarding the lawfulness of the processing of their personal data by us and requests restriction instead of erasure; We no longer need the given data, but the User requires them for the establishment, exercise, or defense of legal claims. We automatically restrict the processing of personal data in cases where the User contests the accuracy of the personal data, or when the User exercises their right to object. In such cases, the restriction applies for a period that enables the verification of the accuracy of the personal data or—in the case of an objection—the determination of whether the grounds for continuing data processing exist. During the restriction period, no data processing operations may be performed on the designated personal data, other than storing them. In the event of restricted processing, personal data may only be processed in the following cases: Based on the consent of the data subject;
For the establishment, exercise, or defense of legal claims;
For the protection of the rights of another natural or legal person;
For reasons of important public interest.
Users will be informed in advance before the restriction of processing is lifted.
Right to Data Portability The User has the right to request—via a request submitted through our contact details—that personal data concerning them and processed by us be made available for their further use as specified by the User. Furthermore, the User may request that we transmit their personal data directly to another data controller specified by them. This right is strictly limited to personal data provided to us by the User and processed for the performance of a contract. Portability for other data is not available. We will provide the personal data to the User in a structured, commonly used, machine-readable format (PDF/XML), or in a printed paper version. Please note that exercising this right does not automatically result in the erasure of personal data from our systems. Additionally, following data portability, the User remains entitled to re-establish contact or maintain ongoing communication with us.
Right to Object The User has the right to object at any time—via a request submitted through our contact details—to the processing of their personal data for the purposes specified in Section 3 of this Privacy Notice. In such cases, we will examine whether the data processing is justified by compelling legitimate grounds that override the interests, rights, and freedoms of the User, or that relate to the establishment, exercise, or defense of legal claims. If we determine that such grounds exist, we will continue processing the personal data. Otherwise, we will no longer process the personal data.