Privacy notice

1. Introduction

Dobos Zoltán Ügyvédi Iroda (hereinafter Dobos Zoltán Ügyvédi Iroda, the Service Provider, Data Controller, the Company), as data controller, acknowledges the content of this legal notice as binding upon itself.
The Company undertakes that all data processing related to its activities complies with the requirements set out in this policy and in the applicable legislation.
Dobos Zoltán Ügyvédi Iroda is the operator of the dzlegal.hu website.

Dobos Zoltán Ügyvédi Iroda reserves the right to amend this notice at any time. Naturally, it will inform its audience of any changes in good time.

Dobos Zoltán Ügyvédi Iroda is committed to protecting the personal data of its clients and partners, and considers it of paramount importance to respect its clients' right to informational self-determination. The Data Controller treats personal data confidentially and takes all security, technical and organisational measures that guarantee the security of the data.

Dobos Zoltán Ügyvédi Iroda sets out its data processing principles below, presenting the expectations it has formulated towards itself as a data controller and which it observes. Its data processing principles are in line with the applicable data protection legislation, in particular the following:

  • Act CXII of 2011 – on the Right to Informational Self-Determination and on Freedom of Information;
  • Act V of 2013 - on the Civil Code (Civil Code);
  • Act XLVIII of 2008 – on the Basic Conditions of and Certain Restrictions on Commercial Advertising Activity (Advertising Act).
  • Act CVIII of 2001 (E-Commerce Act) - on Certain Issues of Electronic Commerce Services and Information Society Services;
  • Regulation (EU) 2016/679 of the European Parliament and of the Council (27 April 2016) – on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: "GDPR")

2. Definitions

  • data subject: any specified natural person identified or – directly or indirectly – identifiable on the basis of personal data;
  • personal data: data that can be associated with the data subject – in particular the data subject's name, identification mark, and any information characteristic of one or more aspects of their physical, physiological, mental, economic, cultural or social identity – as well as any conclusion that can be drawn from such data concerning the data subject;
  • consent: the voluntary and definite expression of the data subject's wishes, based on adequate information, by which they give their unambiguous agreement to the processing – whether full or limited to specific operations – of personal data relating to them;
  • data controller: the natural or legal person, or organisation without legal personality, who or which, alone or jointly with others, determines the purpose of the processing of the data, makes and implements decisions concerning the processing (including the means used), or has them carried out by a data processor;
  • data processing: regardless of the procedure applied, any operation or set of operations performed on the data, in particular their collection, recording, registration, organisation, storage, alteration, use, retrieval, transmission, disclosure, alignment or combination, blocking, erasure and destruction, as well as the prevention of further use of the data, the making of photographic, audio or video recordings, and the recording of physical characteristics suitable for identifying a person (e.g. fingerprint or palm print, DNA sample, iris image);
  • data transfer: making the data accessible to a specified third party;
  • disclosure: making the data accessible to anyone;
  • data erasure: rendering the data unrecognisable in such a way that their restoration is no longer possible;
  • data handling (processing of technical tasks): the performance of technical tasks related to the data processing operations, irrespective of the method and means used to carry out the operations and the place of application, provided that the technical task is performed on the data;
  • data processor: the natural or legal person, or organisation without legal personality, who or which processes the data under a contract – including a contract concluded pursuant to a provision of law.

3. Company Details

Our company's details and contact information are as follows:

  • Name: Dobos Zoltán Ügyvédi Iroda
  • Mailing address: 1084 Budapest, Víg u. 9. III/1.
  • Registering chamber: Budapest Bar Association
  • Bar identification number: 36072682
  • Telephone number: +36 30 592 2955
  • E-mail: dr.dobos.zoltan@gmail.com
  • Representative of the Data Controller: dr. Dobos Zoltán

4. The Scope of Personal Data, the Purpose, Legal Basis and Duration of the Processing

We draw the attention of those providing data to Dobos Zoltán Ügyvédi Iroda that if they do not provide their own personal data, it is the obligation of the person providing the data to obtain the consent of the data subject. The Data Controller is not obliged to verify the existence of such consent. The Data Controller draws the partner's attention to the fact that if it fails to comply with this obligation, and as a result the data subject asserts a claim against the Data Controller, the Data Controller may pass on the asserted claim, or the amount of the associated damage, to the partner.

We provide the following information with regard to our individual data processing activities.

4.1. Requests for quotations and enquiries by direct contact

Interested parties have the opportunity to contact our Company directly by electronic mail sent to the Company's address or by telephone enquiry.

  • Purpose of the processing: maintaining contact in order to promote communication between the data subject and our Company and to ensure the closest and most efficient cooperation possible.
  • Legal basis of the processing: legitimate interest – Article 6(1)(f) GDPR
  • Scope of the personal data processed: the name of the party requesting the quotation/the contact person; their e-mail address, telephone number, and any other information provided by the data subject,
  • Duration of the processing: for 3 years following the validity period of the quotation, or until the objection of the data subject
  • Recipients of the personal data: the Data Controller does not disclose the data obtained to any third party, with the exception of the data processor(s) designated in point 7. The recorded data may be accessed only by the employees of the Data Controller and the designated colleagues of the data processor(s).
  • Specification of the legitimate interest: it is our Company's legitimate interest to process the data subject's data – direct marketing
  • Scope of those affected by the processing: partners and data subjects who enquire directly (e.g. by e-mail, by telephone) regarding the Company's services.

4.2. Requests for quotations and enquiries via the website (dzlegal.hu)

Our company provides the opportunity for data subjects to request quotations by electronic means.

  • Purpose of the processing: maintaining contact in order to promote communication between the data subject and our Company and to ensure the closest and most efficient cooperation possible.
  • Legal basis of the processing: the voluntary consent of the data subject – Article 6(1)(a) GDPR.
  • Scope of the personal data processed: the name of the interested party (first name, surname); their e-mail address, telephone number, company name, and any other information provided by the data subject.
  • Duration of the processing: for 3 years following the validity period of the quotation, or until the withdrawal of consent.
  • Recipients of the personal data: the Data Controller does not disclose the data obtained to any third party, with the exception of the data processor(s) designated in point 7. The recorded data may be accessed only by the employees of the Data Controller and the designated colleagues of the data processor(s).
  • Scope of those affected by the processing: partners and data subjects who enquire via the website regarding the Company's services and products.

4.3. Data processing related to the follow-up of quotations

  • Purpose of the processing: it is the Data Controller's legitimate interest to keep records of the data subject's data beyond the validity period of the quotation for the purpose of direct marketing
  • Legal basis of the processing: the legitimate interest of the Data Controller, Article 6(1)(f) GDPR,
  • Scope of the personal data processed: the surname and first name of the contact person; telephone number; e-mail address
  • Recipients of the personal data: the Data Controller does not disclose the data obtained to any third party, with the exception of the data processor(s) designated in point 7. The recorded data may be accessed only by the employees of the Data Controller and the designated colleagues of the data processor(s).
  • Duration of the processing: until the objection of the data subject
  • Specification of the legitimate interest: establishing business relationships with partners and parties requesting quotations, and providing accurate information to the data subjects. It is our Company's legitimate interest to process the data subject's data – direct marketing
  • Scope of those affected by the processing: the addressees of quotations previously issued by the Company and the contact person(s) named therein.

4.4. Newsletter registration

  • Purpose of the processing: sending e-mail newsletters, which also contain commercial advertising, to interested parties, and providing information on current matters
  • Legal basis of the processing: the prior, voluntary consent of the data subject, Article 6(1)(a) GDPR,
  • Scope of the personal data processed: name, e-mail address
  • Duration of the processing: until the withdrawal of the voluntary consent, until unsubscribing from the newsletter. Our Company processes the data provided by the data subject until the consent is withdrawn. On the basis of the withdrawal of consent, the processed data will be erased from our newsletter database within 7 days at the latest, and we will not send you any newsletter thereafter.
  • Recipients of the personal data: the Data Controller does not disclose the data obtained to any third party, with the exception of the data processor(s) designated in point 7. The recorded data may be accessed only by the employees of the Data Controller and the designated colleagues of the data processor(s). You may unsubscribe from the newsletter at any time by sending a message to our Company at the address dr.dobos.zoltan@gmail.com, or by clicking on the unsubscribe icon in the newsletter.
  • Scope of those affected by the processing: partners and data subjects who subscribe to the Company's electronic newsletter.

4.5. Newsletter data (for newsletters registered before 25 May 2018)

  • Purpose of the processing: sending e-mail newsletters, which also contain commercial advertising, to interested parties, and providing information on current matters
  • Legal basis of the processing: the legitimate interest of the Data Controller, Article 6(1)(f) GDPR,
  • Scope of the personal data processed: name, e-mail address
  • Duration of the processing: until the objection of the data subject
  • Specification of the legitimate interest: providing the data subjects who have subscribed to the newsletter with information that also contains commercial advertising and business offers. It is our Company's legitimate interest to process the data subject's data – direct marketing.
  • Recipients of the personal data: the Data Controller does not disclose the data obtained to any third party, with the exception of the data processor(s) designated in point 7. The recorded data may be accessed only by the employees of the Data Controller and the designated colleagues of the data processor(s). You may unsubscribe from the newsletter at any time by sending a message to our Company at the address dr.dobos.zoltan@gmail.com, or by clicking on the unsubscribe icon in the newsletter.
  • Scope of those affected by the processing: partners and data subjects who subscribed to the Company's electronic newsletter before 25 May 2018.

4.6. Camera system

Cameras operate on the premises maintained by the Data Controller in the interest of the personal and property safety of the data subjects and for other purposes. Information signs draw the attention of the data subjects to their operation. The activities related to the operation of the camera system are defined in the premises' "Information Notice on Data Processing by Property-Protection Cameras", which is available on the premises.

4.7. Data processing related to ensuring the operation of the information technology service

  • Purpose of the processing: on the websites of Dobos Zoltán Ügyvédi Iroda so-called "cookies" (temporary markers) may be used, which enable faster access to them. By "cookies" we mean an item of information that is active only during a given customer session and that is transferred from the website to the Customer's computer for the purpose of faster identification. The Customer may at any time request the disabling of cookies by modifying the browser settings; however, this disabling may slow down or prevent access to certain parts of the site and the use of certain functions.
    The session cookies used avoid the need to resort to other information technology tools that are potentially harmful to the confidentiality of customers' navigation and do not allow the acquisition of identifying personal data.
    The user is able to delete the cookie from their own computer and to disable the use of cookies in their browser. Cookies can generally be managed under the Privacy settings in the Tools/Settings menu of browsers, under the name "cookie".
  • Legal basis of the processing: the voluntary consent of the data subject (User), Article 6(1)(a) GDPR.
    The User gives their voluntary consent to the processing by accepting the pop-up information notice and statement displayed when they begin browsing the website, or by continuing to browse.
    Scope of the personal data processed: information technology data processing concerns the scope of data necessary for the operation of the "cookies" used for operating the website and for the use of the log files applied by the web hosting service provider.
  • Duration of the processing: until the session is closed
  • Recipients of the personal data: the Data Controller does not disclose the data obtained to any third party, with the exception of the data processor(s) designated in point 7. The recorded data may be accessed only by the employees of the Data Controller and the designated colleagues of the data processor(s).
  • Scope of those affected by the processing: every User visiting the website, irrespective of the use of the services available on the website.

5. Other data processing

We provide information on data processing not listed in this notice at the time the data are collected. We inform our clients that certain authorities, bodies performing public duties, and courts may contact our company for the purpose of disclosing personal data. Our company discloses personal data to these bodies – provided that the body concerned has specified the precise purpose and the scope of the data – only in the quantity and to the extent that is absolutely necessary for achieving the purpose of the request, and where the fulfilment of the request is prescribed by law.

6. Transfer of personal data to a third country or to an international organisation

Our Company does not transfer your above personal data either to a third country or to an international organisation.

7. Information on the use of data processors

During the processing, the Data Controller transfers the data to the data processor(s) with whom it has contracted for the performance of the contract.
Categories of recipients: system administration service provider, accounting and payroll service provider, server hosting, web hosting service provider

8. Children

Our services are not intended for persons under the age of 16, and we request that persons under the age of 16 do not provide any Personal data to the Data Controller.
If it comes to our attention that we have collected personal data from a child under the age of 16 – with the exception of the processing of data required by legal provisions – we will take the necessary steps to erase the data as soon as possible.

9. Automated decision-making

Our Company does not apply automated decision-making in the course of its data processing procedures and data collection.

10. The manner of storing personal data and the security of the processing

Our company's information technology systems and other data-retention locations are situated at its registered office and on the servers provided by the data processor. For the processing of personal data, our company selects and operates the information technology tools used in the course of providing the service in such a way that the processed data is:

  1. accessible to those authorised (availability);
  2. guaranteed in its authenticity and authentication (authenticity of the processing);
  3. verifiable as to its unalteredness (data integrity);
  4. protected against unauthorised access (confidentiality of the data).

We pay particular attention to the security of the data, and we further take the technical and organisational measures and establish the procedural rules that are necessary to give effect to the guarantees required by the GDPR. We protect the data with appropriate measures, in particular against unauthorised access, alteration, transmission, disclosure, erasure or destruction, as well as against accidental destruction, damage, and inaccessibility resulting from changes in the technology applied.

The information technology system and network of both our company and our partners are protected against computer-assisted fraud, computer viruses, computer intrusions and denial-of-service attacks. The operator ensures security by means of both server-level and application-level protection procedures. Daily backup of the data is in place. In order to avoid data protection incidents, our company takes every possible measure, and in the event of such an incident occurring – in accordance with our incident management policy – we act without delay to minimise the risks and remedy the damage.

11. The rights of data subjects and remedies

The data subject may request information about the processing of their personal data, and may request the rectification or – with the exception of mandatory processing – the erasure or withdrawal of their personal data, and may exercise their right to data portability and their right to object in the manner indicated at the collection of the data, or via the above contact details of the Data Controller.

The rights and remedies of the data subject have been defined below, and the data subjects informed thereof, on the basis of Act CXII of 2011 and Regulation (EU) 2016/679.

The right to information, or in other words the data subject's "right of access": pursuant to Act CXII of 2011 and Article 15 of Regulation (EU) 2016/679, at the data subject's request the Data Controller provides information on

  • the data and the categories of personal data processed by it,
  • the purpose of the processing,
  • the legal basis of the processing,
  • the duration of the processing,
  • where applicable, the duration of the storage of the data, or, if this is not possible, the criteria used to determine that duration,
  • where applicable, if the data were not collected from the data subject, all available information as to their source,
  • where applicable, the automated decision-making, including profiling, and meaningful information about the logic involved and about the significance of such processing, and
  • the expected consequences of such processing for the data subject,
  • the details of the data processor, if a data processor has been used, i. the circumstances and effects of the data protection incident and the measures taken to remedy it, and furthermore
  • in the event of the transfer of the data subject's personal data, the legal basis, purpose and recipient of the transfer.

The information is free of charge if the person requesting it has not yet submitted a request for information concerning the same scope of data to the Data Controller during the current year. In other cases, a cost reimbursement may be established. Any cost reimbursement already paid must be refunded if the data were processed unlawfully, or if the request for information led to rectification.

The Data Controller draws the data subjects' attention to the fact that the information must be refused, pursuant to Act CXII of 2011,

  1. if, pursuant to a provision of an act, an international treaty or a binding legal act of the European Union, the Data Controller receives personal data in such a way that the transferring data controller, simultaneously with the transfer, indicates a restriction of the rights guaranteed to the data subject of the personal data under the said act, or other restriction of its processing.
  2. in the interest of the external and internal security of the State, such as national defence, national security, the prevention or prosecution of criminal offences, and the security of the enforcement of penalties, and furthermore for State or local-government economic or financial reasons, for an important economic or financial interest of the European Union, as well as for the purpose of preventing and detecting disciplinary and ethical breaches connected with the exercise of professions and breaches of labour-law and occupational-safety obligations – including in every case monitoring and supervision – and furthermore in the interest of protecting the rights of the data subject or of others.

The Data Controller is obliged to notify the National Authority for Data Protection and Freedom of Information of refused requests for information annually, by 31 January of the year following the reference year.

The right to rectification: the data subject has the right to obtain, at their request, from the Data Controller without undue delay the rectification of inaccurate personal data concerning them. Taking into account the purpose of the processing, the data subject has the right to request that incomplete personal data be completed – inter alia by means of a supplementary statement. At the same time, if the personal data does not correspond to reality and the personal data corresponding to reality is available to the Data Controller, the Data Controller rectifies the personal data as a matter of obligation, even without the data subject's request.

The right to erasure, or in other words the "right to be forgotten": the data subject has the right to obtain, at their request, from the Data Controller without undue delay the erasure of personal data concerning them, and the Data Controller is obliged to erase the personal data concerning the data subject without undue delay, where mandatory processing does not preclude this.

Apart from the above case, the Data Controller is obliged to erase the data, pursuant to Act CXII of 2011 and Regulation (EU) 2016/679 of the European Parliament and of the Council, if

  • the processing of the data is unlawful;
  • the data is incomplete or erroneous - and this state cannot be lawfully remedied -, provided that erasure is not precluded by an act;
  • the purpose of the processing has ceased, or the statutory time limit for storing the data has expired;
  • it has been ordered by a court or the Authority.
  • the personal data is no longer necessary for the purpose for which it was collected or otherwise processed;
  • the data subject objects to the processing and there is no overriding legitimate ground for the processing;
  • the personal data must be erased for compliance with a legal obligation under the law applicable to the Data Controller;
  • the personal data was collected in relation to the offer of information society services referred to in Article 8(1) of Regulation (EU) 2016/679 offered directly to children.

In the event that the Data Controller has, for any reason, disclosed the personal data and is obliged to erase it pursuant to the above, taking account of available technology and the cost of implementation, it takes the reasonably expectable steps – including technical measures – in order to inform the other controllers processing the data that the data subject has requested the erasure of any links to, or copy or replication of, the personal data in question.

The Data Controller draws the data subjects' attention to the limits, arising from the EU Regulation, of the right to erasure or the "right to be forgotten", which are the following:

  1. exercising the right of freedom of expression and information;
  2. compliance with an obligation under Union or Member State law applicable to the controller which requires the processing of personal data, or the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  3. a public interest in the area of public health;
  4. in accordance with Article 89(1) of Regulation (EU) 2016/679, for archiving purposes in the public interest, for scientific and historical research purposes or for statistical purposes, in so far as the right to erasure is likely to render impossible or seriously impair the achievement of that processing; or
  5. the establishment, exercise or defence of legal claims.

The right to restriction of processing, or in other words the right to blocking: the data subject has the right to obtain, at their request, from the Data Controller restriction of the processing.
If, on the basis of the information available, it can be presumed that erasure would harm the legitimate interests of the data subject, the data must be blocked. Personal data thus blocked may be processed only for as long as the processing purpose that precluded the erasure of the personal data exists.

If the data subject disputes the accuracy or correctness of the personal data, but the incorrectness or inaccuracy of the disputed personal data cannot be established unambiguously, the data must be blocked. In this case, the restriction relates to the period that enables the Data Controller to verify the accuracy of the personal data.

Pursuant to the EU Regulation, the data must be blocked if

  1. the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead;
  2. the Data Controller no longer needs the personal data for the purposes of the processing, but the data subject requires them for the establishment, exercise or defence of legal claims; or
  3. the data subject has objected to the processing; in this case, the restriction relates to the period until it is established whether the legitimate grounds of the Data Controller override those of the data subject.

Where the processing is subject to restriction (blocking), such personal data may, with the exception of storage, be processed only with the data subject's consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State.

The Data Controller hereby expressly draws the data subjects' attention to the fact that the data subject's right to rectification, erasure and blocking may be restricted by an act in the interest of the external and internal security of the State, such as national defence, national security, the prevention or prosecution of criminal offences, and the security of the enforcement of penalties, and furthermore for State or local-government economic or financial reasons, for an important economic or financial interest of the European Union, as well as for the purpose of preventing and detecting disciplinary and ethical breaches connected with the exercise of professions and breaches of labour-law and occupational-safety obligations – including in every case monitoring and supervision – and furthermore in the interest of protecting the rights of the data subject or of others.
The Data Controller informs the data subject of the matters specified in their request without undue delay, and at most within 30 days of receipt of the request, and/or rectifies the data, and/or erases and/or restricts (blocks) the data, or takes other steps in accordance with the request, where there is no ground precluding this.

The Data Controller notifies the data subject in writing of the rectification, the erasure and the restriction of processing having taken place, as well as all those to whom the data was previously transferred or handed over for the purpose of processing. At the data subject's request, the Data Controller informs them of these recipients. The notification may be dispensed with if, having regard to the purpose of the processing, it does not harm the legitimate interest of the data subject, or if the provision of information proves impossible or would require a disproportionately great effort. The Data Controller is also obliged to notify the data subject in writing if, for any reason, the exercise of the data subject's rights cannot be realised, and is obliged to indicate precisely the factual and legal grounds, as well as the remedies available to the data subject: the possibility of turning to the court and to the National Authority for Data Protection and Freedom of Information.

The "right to data portability": the data subject has the right to

  1. receive the personal data concerning them, which they have provided to the Data Controller, in a structured, commonly used, machine-readable format, and furthermore has the right to
  2. transmit these data to another controller without hindrance from the controller to which the personal data was provided, where:
  3. the processing is based on consent; and
  4. the processing is carried out by automated means.

In exercising the right to data portability, the data subject has the right – where this is technically feasible – to request the direct transmission of the personal data between controllers.
Having regard to the data processing carried out by the Data Controller, the conditions for exercising the right to data portability are not met (there is no automated processing), and therefore the data subject is unable to exercise this right.

The right to object: the data subject may object to the processing of their personal data – including profiling – if

  • the processing (transfer) of the personal data is necessary solely for the enforcement of a right or legitimate interest of the Data Controller or of the recipient of the data, except in the case of mandatory processing;
  • the personal data is used or transferred for the purpose of direct marketing, opinion polling or scientific research;
  • the exercise of the right to object is otherwise permitted by an act.

The data subject may also object, pursuant to Article 21(3) of Regulation (EU) 2016/679, to the processing of their personal data for the purpose of direct marketing, in which case the personal data may no longer be processed for that purpose.

Where personal data is processed for scientific and historical research purposes or for statistical purposes, the data subject has the right, on grounds relating to their particular situation, to object to the processing of personal data concerning them, except where the processing is necessary for the performance of a task carried out for reasons of public interest.
The Data Controller – while simultaneously suspending the processing – examines the objection within the shortest possible time from the submission of the request, but at most within 30 days, and informs the applicant in writing of the result thereof. If the applicant's objection is well-founded, the Data Controller terminates the processing – including any further data collection and data transfer – and blocks the data, and notifies of the objection and the measures taken on its basis all those to whom the personal data affected by the objection was previously transferred, and who are obliged to take measures in order to give effect to the right to object.

If the data subject does not agree with the Data Controller's decision, or if the Data Controller fails to meet the referenced time limit, they are entitled – within 30 days of the communication thereof – to turn to the court.
The data subject has the right to object in connection with automated decision-making.

Enforcement of rights before a court: in the event of a violation of their rights, the data subject may turn to the court. The court deals with the case as a matter of priority. The Data Controller is obliged to prove that the processing complies with the provisions of the law.

In the event of a violation of your right to informational self-determination, you may lodge a report or complaint:

National Authority for Data Protection and Freedom of Information
Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
Telephone: +36 (1) 391-1400, Fax: +36 (1) 391-1410
www: http://www.naih.hu
e-mail: ugyfelszolgalat@naih.hu