Privacy policy

1. Introduction

Molnár Csaba egyéni vállalkozó (hereinafter Molnár Csaba egyéni vállalkozó, service provider, controller, Company), as controller, regards the content of this legal notice as binding upon itself.
The Company undertakes that every processing related to its activity will comply with the requirements set out in this notice and in the applicable legislation.
Molnár Csaba egyéni vállalkozó is the operator of the sidexis.hu website.

Molnár Csaba egyéni vállalkozó reserves the right to change this notice at any time. Naturally, it will notify its audience of any changes in due time.

Molnár Csaba egyéni vállalkozó is committed to protecting the personal data of its customers and partners, and considers it of particular importance to respect its customers’ right to informational self-determination. The Controller treats personal data confidentially and takes every security, technical and organisational measure that guarantees the security of the data.

Molnár Csaba egyéni vállalkozó sets out below its processing principles and presents the expectations that it has formulated for itself as controller and that it observes. Its processing principles are consistent with the applicable data protection legislation, in particular with the following:

  • 2011. évi CXII. törvény – on the right to informational self-determination and on freedom of information;
  • 2013. évi V. törvény - on the Civil Code (Ptk.);
  • 2008. évi XLVIII. törvény – on the basic conditions of and certain limitations on economic advertising activity (Grt.).
  • 2001. évi CVIII. törvény (Ekertv.) - on certain issues of electronic commerce services and information society services;
  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 – on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: “GDPR”)

2. Definitions

  • data subject: any specified natural person identified or – directly or indirectly – identifiable on the basis of personal data;
  • personal data: data that can be associated with the data subject – in particular the data subject’s name, identifier, and one or more pieces of information characteristic of the data subject’s physical, physiological, mental, economic, cultural or social identity – as well as the conclusion that can be drawn from such data concerning the data subject;
  • consent: a voluntary and definite expression of the data subject’s wish, based on appropriate information, by which the data subject gives unambiguous agreement to the processing of personal data relating to them – whether covering all operations or extending to certain operations;
  • controller: the natural or legal person, or organisation without legal personality, who or which, independently or together with others, determines the purposes of processing, takes and implements decisions concerning processing (including the means used), or has them implemented by the processor;
  • processing: irrespective of the method applied, any operation or set of operations performed on data, in particular collection, recording, organisation, storage, alteration, use, retrieval, transmission, disclosure, alignment or combination, blocking, erasure and destruction, as well as preventing further use of the data, taking a photograph, audio or video recording, and recording physical characteristics suitable for identifying a person (e.g. fingerprint or palm print, DNA sample, iris image);
  • transfer: making the data accessible to a specified third party;
  • disclosure: making the data accessible to anyone;
  • erasure: making the data unrecognisable in such a way that their restoration is no longer possible;
  • processing by a processor: performing the technical tasks related to processing operations, irrespective of the method and means applied to carry out the operations and of the place of application, provided that the technical task is performed on the data;
  • processor: the natural or legal person, or organisation without legal personality, who or which, on the basis of a contract – including a contract concluded on the basis of a provision of law – performs the processing of the data.

3. Company details

Our company’s details and contact information are as follows:

  • Name: Molnár Csaba egyéni vállalkozó
  • Registered office: 2643 Diósjenő, Jog utca 2.
  • Postal address: 2643 Diósjenő, Jog utca 2.
  • Registration number: 58987757
  • Tax number: 49306163132
  • Statistical code: 49306163331323112
  • Phone number: +36 30 548 9606
  • E-mail: csaba.molnar@sidexis.hu
  • Representative of the controller: Molnár Csaba

4. Scope of personal data, purpose, legal basis and duration of processing

We draw the attention of those providing data to Molnár Csaba egyéni vállalkozó that if they do not provide their own personal data, it is the duty of the person providing the data to obtain the data subject’s consent. The controller is not obliged to verify the existence of such consent. The controller draws the partner’s attention to the fact that if the partner fails to fulfil this obligation and the data subject therefore asserts a claim against the controller, the controller may pass on the asserted claim and the related amount of damage to the partner.

We provide the following information in connection with our individual processing operations.

4.1. Request for a quote, enquiry by direct contact

Interested parties have the opportunity to contact our Company directly by electronic mail sent to the Company’s address, or by telephone enquiry.

  • Purpose of processing: maintaining contact in order to facilitate communication between the data subject and our Company and to achieve the closest and most effective cooperation possible.
  • Legal basis of processing: legitimate interest – GDPR Article 6(1)(f)
  • Scope of personal data processed: name of the person requesting a quote / contact person; e-mail address, phone number, and other information provided by the data subject,
  • Duration of processing: for 3 years after the validity period of the quote, or until the data subject objects
  • Recipients of personal data: Except for the processor(s) indicated in point 7, the controller does not transfer the data learned to a third party. The recorded data may be known only by the Controller’s employees and the designated colleagues of the processor(s).
  • Specification of the legitimate interest: Our Company’s legitimate interest in processing the data subject’s data is direct marketing
  • Circle of data subjects: partners and data subjects who enquire directly (e.g. by e-mail or telephone) about the Company’s services.

4.2. Request for a quote, enquiry through the website (sidexis.hu)

Our company provides the opportunity for data subjects to request a quote electronically.

  • Purpose of processing: maintaining contact in order to facilitate communication between the data subject and our Company and to achieve the closest and most effective cooperation possible.
  • Legal basis of processing: the data subject’s voluntary consent – GDPR Article 6(1)(a).
  • Scope of personal data processed: name of the interested party (first name, last name); e-mail address, phone number, company name, and other information provided by the data subject.
  • Duration of processing: for 3 years after the validity period of the quote, or until consent is withdrawn.
  • Recipients of personal data: Except for the processor(s) indicated in point 7, the controller does not transfer the data learned to a third party. The recorded data may be known only by the Controller’s employees and the designated colleagues of the processor(s).
  • Circle of data subjects: partners and data subjects who enquire through the website about the Company’s services and products.

4.3. Processing related to follow-up of a request for a quote

  • Purpose of processing: it is the controller’s legitimate interest to keep a record of the data subject’s data beyond the validity period of the quote for the purpose of direct marketing
  • Legal basis of processing: the controller’s legitimate interest, GDPR Article 6(1)(f),
  • Scope of personal data processed: contact person’s last name and first name; phone number; e-mail address
  • Recipients of personal data: Except for the processor(s) indicated in point 7, the controller does not transfer the data learned to a third party. The recorded data may be known only by the Controller’s employees and the designated colleagues of the processor(s).
  • Duration of processing: until the data subject objects
  • Specification of the legitimate interest: establishing business relationships with partners and persons requesting quotes, providing accurate information to data subjects. Our Company’s legitimate interest in processing the data subject’s data is direct marketing
  • Circle of data subjects: addressees of quotes previously issued by the Company and the contact person(s) named therein.

4.4. Newsletter registration

  • Purpose of processing: sending e-mail newsletters containing economic advertising to interested parties, providing information on current news
  • Legal basis of processing: the data subject’s prior, voluntary consent, GDPR Article 6(1)(a),
  • Scope of personal data processed: name, e-mail address
  • Duration of processing: until voluntary consent is withdrawn, until unsubscription from the newsletter. Our Company processes the data provided by the data subject until consent is withdrawn. On the basis of withdrawal of consent, we erase the processed data from our newsletter database within 7 days at the latest, and thereafter we will not send you a newsletter.
  • Recipients of personal data: Except for the processor(s) indicated in point 7, the controller does not transfer the data learned to a third party. The recorded data may be known only by the Controller’s employees and the designated colleagues of the processor(s). You may unsubscribe from the newsletter at any time by sending a letter to our Company at csaba.molnar@sidexis.hu, or by clicking the unsubscribe icon in the newsletter.
  • Circle of data subjects: partners and data subjects who subscribe to the Company’s electronic newsletter.

4.5. Newsletter data (in the case of newsletters with registration before 25 May 2018)

  • Purpose of processing: sending e-mail newsletters containing economic advertising to interested parties, providing information on current news
  • Legal basis of processing: the controller’s legitimate interest, GDPR Article 6(1)(f),
  • Scope of personal data processed: name, e-mail address
  • Duration of processing: until the data subject objects
  • Specification of the legitimate interest: providing information containing economic advertising and business offers to data subjects who subscribed to the newsletter. Our Company’s legitimate interest is processing the data subject’s data, direct marketing.
  • Recipients of personal data: except for the processor(s) indicated in point 7, the controller does not transfer the data learned to a third party. The recorded data may be known only by the Controller’s employees and the designated colleagues of the processor(s). You may unsubscribe from the newsletter at any time by sending a letter to our Company at csaba.molnar@sidexis.hu, or by clicking the unsubscribe icon in the newsletter.
  • Circle of data subjects: partners and data subjects who subscribed to the Company’s electronic newsletter before 25 May 2018.

4.6. Camera system

Cameras operate on the premises operated by the controller in the interest of the personal and property security of data subjects and for other purposes. Information signs draw the attention of data subjects to their operation. Activities related to the operation of the camera system are set out in the site’s “Privacy notice on property-protection cameras”, which is available on the premises.

4.7. Processing related to ensuring the operation of information technology services

  • Purpose of processing: Molnár Csaba egyéni vállalkozó may use so-called “cookies” (temporary markers) on its websites, which enable faster access to them. By “cookies” we mean an informational datum that is active only during the individual customer session and that is placed from the website onto the Customer’s computer for faster identification. The Customer may always request that cookies be switched off by modifying the browser settings; however, switching them off may slow down or prevent access to some parts of the site and the use of certain functions.
    The session cookies used avoid the need to resort to other IT devices that are potentially harmful to the confidentiality of customers’ navigation and do not make it possible to obtain identifying personal data.
    The user is able to delete the cookie from their own computer, and may disable the use of cookies in their browser. Cookies can generally be managed in the Tools/Settings menu of browsers, under Privacy settings, under the name cookie or süti.
  • Legal basis of processing: The data subject’s (User’s) voluntary consent, GDPR Article 6(1)(a).
    The User gives voluntary consent to processing by accepting the pop-up notice and declaration at the start of browsing the site, or by continuing to browse.
    Scope of personal data processed: information technology processing concerns the scope of data necessary for the operation of the “cookies” used to operate the site and for the use of log files applied by the web hosting provider.
  • Duration of processing: until the session is closed
  • Recipients of personal data: Except for the processor(s) indicated in point 7, the controller does not transfer the data learned to a third party. The recorded data may be known only by the Controller’s employees and the designated colleagues of the processor(s).
  • Circle of data subjects: Every User visiting the site, irrespective of whether they use the services available on the site.

4.8. Purchase in the webshop

I acknowledge that the following personal data stored by the controller Molnár Csaba egyéni vállalkozó, 2643 Diósjenő, Jog utca 2. in the user database of dentalservice.neosite.hu will be transferred to SimplePay Zrt. as processor. The scope of data transferred by the controller is as follows: Name, Phone number, Shipping address, Billing address, Email address, Products purchased. The nature and purpose of the processing carried out by the processor can be viewed in the SimplePay Privacy Notice at the following link: https://simplepay.hu/adatkezelesi-tajekoztatok/

5. Other processing

We provide information about processing operations not listed in this notice at the time the data are collected. We inform our customers that certain authorities, bodies performing public tasks, and courts may contact our company for the purpose of disclosure of personal data. Our company discloses personal data to these bodies – provided that the body concerned has specified the exact purpose and the scope of the data – only to the extent and in the measure indispensably necessary to achieve the purpose of the request, and if fulfilment of the request is prescribed by law.

6. Transfer of personal data to a third country or to an international organisation

Our Company does not transfer your personal data referred to above either to a third country or to an international organisation.

7. Information on the use of a processor

In the course of processing, the controller transfers the data to the processor(s) contracted with it for the performance of the contract.
Categories of recipients: system administration provider, accounting and payroll provider, server hosting, web hosting provider

8. Children

Our services are not intended for persons under 16 years of age, and we ask that persons under 16 years of age do not provide Personal data to the Controller.
If it comes to our knowledge that we have collected personal data from a child under 16 years of age – except for processing of data according to statutory requirements – we will take the steps necessary to erase the data as soon as possible.

9. Automated decision-making

Our Company does not apply automated decision-making in the course of its processing procedures and data collection.

10. Method of storing personal data, security of processing

Our company’s IT systems and other data retention locations are at the registered office and on servers provided by the processor. For the processing of personal data, our company selects and operates the IT devices used in the course of providing the service so that the processed data:

  1. are accessible to those authorised to have access (availability);
  2. their authenticity and authentication are ensured (authenticity of processing);
  3. their unchanged state can be verified (data integrity);
  4. are protected against unauthorised access (confidentiality of data).

We pay particular attention to the security of the data, and we also take the technical and organisational measures and establish the procedural rules that are necessary to give effect to the guarantees under the GDPR. We protect the data with appropriate measures in particular against unauthorised access, alteration, transfer, disclosure, erasure or destruction, as well as accidental destruction, damage, and becoming inaccessible as a result of a change in the applied technology.

The IT system and network of our company and of our partners are equally protected against computer-aided fraud, computer viruses, computer break-ins and attacks leading to denial of service. The operator also provides for security with server-level and application-level protection procedures. Daily backup of the data is in place. In order to avoid personal data breaches, our company takes every possible measure; if such an incident occurs – according to our incident management policy – we act without delay in order to minimise the risks and to avert the damage.

11. Rights of data subjects, remedies

The data subject may request information about the processing of their personal data, and may request the rectification, and – except for mandatory processing – the erasure or withdrawal of their personal data, and may exercise their right to data portability and their right to object in the manner indicated at the time of collection of the data, or at the controller’s contact details above.

The data subject’s rights and remedies have been determined and communicated to data subjects on the basis of 2011. évi CXII. törvény and EU Regulation 2016/679.

The right to information, or otherwise the data subject’s “right of access”: On the basis of 2011. évi CXII. törvény and Article 15 of EU Regulation 2016/679, upon the data subject’s request the Controller provides information

  • about the data processed by it and the categories of personal data,
  • about the purpose of processing,
  • about the legal basis of processing,
  • about the duration of processing,
  • where applicable, about the duration of storage of the data, or if this is not possible, about the criteria for determining that duration,
  • where applicable, if the data were not collected from the data subject, about any available information as to their source,
  • where applicable, about automated decision-making, including profiling, as well as understandable information about the logic involved and about the significance of such processing, and
  • what the envisaged consequences are for the data subject,
  • about the processor’s data, if a processor was used, i. about the circumstances, effects of the personal data breach and the measures taken to avert it, and
  • in the event of transfer of the data subject’s personal data, about the legal basis, purpose and recipient of the transfer.

The information is free of charge if the person requesting information has not yet submitted an information request to the Controller in the current year concerning the same set of data. In other cases a fee may be established. The fee already paid must be reimbursed if the data were processed unlawfully, or if the request for information led to rectification.

The Controller draws the attention of data subjects to the fact that information must be refused on the basis of 2011. évi CXII. törvény,

  1. if, on the basis of a provision of an act, an international treaty or a binding legal act of the European Union, the Controller receives personal data in such a way that the transferring controller indicates, at the same time as the transfer, the restriction of the rights of the data subject of the personal data provided for in the named act, or another restriction of processing.
  2. in the interest of the external and internal security of the state, thus national defence, national security, the prevention or prosecution of criminal offences, the security of the execution of sentences, and further for a state or municipal economic or financial interest, for a significant economic or financial interest of the European Union, and for the purpose of preventing and detecting disciplinary and ethical offences related to the practice of professions, and labour-law and occupational-safety breaches of duty – including in every case inspection and supervision as well – and further in the interest of protecting the rights of the data subject or of others.

The Controller is obliged to notify the National Authority for Data Protection and Freedom of Information of refused information requests annually by 31 January of the year following the year concerned.

The right to rectification: The data subject is entitled to obtain from the Controller without undue delay the rectification of inaccurate personal data concerning them. Taking into account the purpose of processing, the data subject is entitled to have incomplete personal data completed – including by means of providing a supplementary statement. At the same time, if the personal data do not correspond to reality, and the personal data corresponding to reality are available to the Controller, the Controller is obliged to rectify the personal data even without the data subject’s request.

The right to erasure, or otherwise the “right to be forgotten”: The data subject is entitled to obtain from the Controller the erasure of personal data concerning them without undue delay, and the Controller is obliged to erase personal data concerning the data subject without undue delay, if this is not excluded by mandatory processing.

In addition to the above case, the Controller is obliged to erase the data on the basis of 2011. évi CXII. törvény and Regulation (EU) 2016/679 of the European Parliament and of the Council, if

  • the processing of the data is unlawful;
  • the data are incomplete or incorrect – and this state cannot be lawfully remedied – provided that erasure is not excluded by law;
  • the purpose of processing has ceased, or the statutory deadline for storage of the data has expired;
  • it has been ordered by the court or the Authority.
  • the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
  • the data subject objects to the processing and there is no overriding legitimate ground for the processing;
  • the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the Controller is subject;
  • the personal data have been collected in relation to the offer of information society services referred to in Article 8(1) of EU Regulation 2016/679, offered directly to a child.

Where the Controller has made the personal data public for some reason and is obliged to erase them as set out above, taking account of available technology and the cost of implementation, the Controller shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data.

The Controller draws the attention of data subjects to the limitations of the right to erasure or the “right to be forgotten” arising from the EU regulation, which are the following:

  1. exercising the right of freedom of expression and information;
  2. compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  3. public interest in the area of public health;
  4. archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) of EU Regulation 2016/679, in so far as the right to erasure is likely to render impossible or seriously impair that processing; or
  5. the establishment, exercise or defence of legal claims.

The right to restriction of processing, or otherwise the right to blocking: The data subject is entitled to obtain from the Controller restriction of processing upon request.
If, on the basis of the information available, it may be assumed that erasure would harm the data subject’s legitimate interests, the data must be blocked. Personal data blocked in this way may be processed only until the processing purpose that excluded erasure of the personal data exists.

If the data subject contests the accuracy or correctness of the personal data, but the incorrectness or inaccuracy of the contested personal data cannot be established clearly, the data are blocked. In this case the restriction applies to the period enabling the Controller to verify the accuracy of the personal data.

On the basis of the EU regulation, the data must be blocked if

  1. the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead;
  2. the Controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims; or
  3. the data subject has objected to processing; in this case the restriction applies to the period until it is established whether the legitimate grounds of the Controller override those of the data subject.

Where processing is subject to restriction (blocking), such personal data shall, with the exception of storage, only be processed with the data subject’s consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.

The Controller hereby particularly draws the attention of data subjects to the fact that the data subject’s right to rectification, erasure and blocking may be restricted by law in the interest of the external and internal security of the state, thus national defence, national security, the prevention or prosecution of criminal offences, the security of the execution of sentences, and further for a state or municipal economic or financial interest, for a significant economic or financial interest of the European Union, and for the purpose of preventing and detecting disciplinary and ethical offences related to the practice of professions, and labour-law and occupational-safety breaches of duty – including in every case inspection and supervision as well – and further in the interest of protecting the rights of the data subject or of others.
The Controller informs the data subject without undue delay, at most within 30 days of receipt of the request, about the matters specified in the request, and/or rectifies the data, and/or erases and/or restricts (blocks) the data, or takes other steps in accordance with the request, if there is no excluding reason.

The Controller notifies the data subject in writing of the rectification, the erasure and the restriction of processing having taken place, and further all those to whom the data were previously transferred or disclosed for the purpose of processing. Upon the data subject’s request the Controller informs the data subject of these recipients. The notification may be dispensed with if this does not harm the data subject’s legitimate interest having regard to the purpose of processing, or if the information proves impossible or would involve a disproportionate effort. The Controller is also obliged to notify the data subject in writing if the data subject’s exercise of rights cannot be realised for some reason, and is obliged to specify precisely the factual and legal reason, as well as the remedies available to the data subject: the possibility of turning to the court and to the National Authority for Data Protection and Freedom of Information.

The “right to data portability”: The data subject is entitled

  1. to receive the personal data concerning them, which they have provided to the Controller, in a structured, commonly used and machine-readable format, and further is entitled
  2. to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where:
  3. the processing is based on consent; and
  4. the processing is carried out by automated means.

In exercising the right to data portability, the data subject is entitled to have the personal data transmitted directly from one controller to another, where technically feasible.
Having regard to the processing carried out by the Controller, the conditions for exercising the right to data portability are not fulfilled (there is no automated processing), therefore the data subject cannot exercise this right.

The right to object: The data subject may object to the processing of their personal data – including profiling – if

  • processing (transfer) of the personal data is necessary solely for the enforcement of a right or legitimate interest of the Controller or of the recipient, except in the case of mandatory processing;
  • the use or transfer of the personal data takes place for the purpose of direct marketing, public opinion polling or scientific research;
  • the exercise of the right to object is otherwise permitted by law.

The data subject may also object, on the basis of Article 21(3) of EU Regulation 2016/679, to processing of personal data for the purpose of direct marketing; in that case the personal data may no longer be processed for that purpose.

Where personal data are processed for scientific or historical research purposes or statistical purposes, the data subject is entitled, on grounds relating to their particular situation, to object to processing of personal data concerning them, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
The Controller – with simultaneous suspension of processing – examines the objection within the shortest time after submission of the request, but at most within 30 days, and informs the applicant of the result in writing. If the applicant’s objection is well-founded, the Controller terminates the processing – including further collection and transfer of data – and blocks the data, and notifies of the objection and of the measures taken on the basis thereof all those to whom the personal data affected by the objection were previously transferred, and who are obliged to take measures in order to give effect to the right to object.

If the data subject does not agree with the Controller’s decision, or the Controller misses the referenced deadline, the data subject is entitled – within 30 days of communication of the decision – to turn to the court.
The data subject has the right to object in connection with automated decision-making.

Enforcement of rights before a court: In the event of a violation of their rights, the data subject may turn to the court. The court proceeds in the matter out of turn. It is the Controller who is obliged to prove that the processing complies with the provisions of the law.

In the event of a violation of the right to informational self-determination, a report or complaint may be submitted to:

Nemzeti Adatvédelmi és Információszabadság Hatóság
Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
Phone: +36 (1) 391-1400, Fax: +36 (1) 391-1410
www: http://www.naih.hu
e-mail: ugyfelszolgalat@naih.hu