Privacy Policy

Table of contents of the privacy policy 📖

This privacy notice starts on January 1, 2024.

1. What this Privacy Notice is About and Who it Covers

The main point of this notice is to explain the data protection and handling rules and policies that Infinite AD Limited Liability Company (our registered office is at 1026 Budapest, Pasaréti út 122-124., company registration number: 01-09-412791, tax number: 32222632-2-42) (which we'll call the Data Controller or the Company from now on) uses and is committed to following.

This privacy notice is also here to give everyone whose data we handle the information they need to understand how we process it. We want to assure you that we always respect your basic rights when it comes to managing and protecting your personal data and your privacy, no matter where you're from or where you live.

This Notice applies to all processing of data, regardless of the form in which it is presented, carried out by the Data Controller on the website available at the URL https://infinite.ad/ (hereinafter referred to as the Website).

2. Info About the Data Controller

For all the data processing activities mentioned in this notice, we are the Data Controller for your personal data. Just so you know, we haven't appointed a data protection officer.

If you have any questions or comments about how we handle your data, you can reach us using the contact details below.

Name: Infinite AD Limited Liability Company
Registered office and mailing address: 1026 Budapest, Pasaréti út 122-124.
Email address: hello@infinite.ad

3. Terms Used in This Privacy Notice

Here's a quick explanation of the terms we use in this notice:

Personal data: This means any information that can identify a person, either directly or indirectly, based on one or more identifiers, factors, or characteristics.

Data Processing: This means any action we take with your personal data, no matter how we do it. So, it includes things like collecting, recording, organizing, structuring, storing, changing, looking at, retrieving, using, sharing, sending, spreading, making available in other ways, combining, restricting, deleting, or destroying your data.

Data Controller: This is Infinite AD Kft., the company that decides why and how your personal data is handled.

Data Processing (the action): This means doing any technical tasks with your personal data that are part of data management, no matter what methods, tools, or location we use.

Data Processor: This is a person or company that handles personal data for the Data Controller, following their instructions.

Consent: This is when you freely, specifically, and clearly say 'yes' to us handling your personal data, after we've told you all about it.

GDPR: This stands for the General Data Protection Regulation (EU 2016/679) from the European Parliament and Council. It's a set of rules about how personal data should be handled and what rights people have regarding their data.

Restriction of Processing: This means we mark your stored personal data to limit how it can be used in the future.

Recipient: This is any person, company, public authority, or other body that receives your personal data.

Anonymization: This is when we take steps so that your personal data can no longer be linked back to you. It loses its personal touch, and we can't figure out who you are from it anymore.

Pseudonymization: This is when we process your personal data so it can't be linked back to you without extra information. That extra info is kept separate and secure, making sure your data can't be connected to you directly.

Supervisory Authority: This is an independent body set up to protect people's rights and freedoms when their personal data is handled, and to help personal data flow freely within the EU. In Hungary, this is the National Authority for Data Protection and Freedom of Information.

Data Breach: This happens when our data security rules are broken, leading to personal data being accidentally or unlawfully destroyed, lost, changed, shared with unauthorized people, or accessed by them.

Cookie: also known as a "cookie", a so-called anonymous visitor identifier, which is placed and read by the Data Controller on the computer, smart device or browser of the data subject when the user is visiting the website available at the URL https://infinite.ad/. A cookie is a unique piece of data that can be used to save the settings used on the website and to track how the visitor has accessed the website and what actions he or she has performed there.

Website: This is the online platform you can find at https://infinite.ad/. People visit it to check things out or to register so they can use the service we offer.

Consumer: This is a natural person who is acting for purposes outside their trade, business, craft, or profession.

4. How We Handle Data and Our Principles

To achieve the data processing goals outlined in this notice, the Data Controller handles personal data that you either provide directly or allow us to access.

The Data Controller makes sure that unauthorized people can't get to your personal data. Even those who are given permission to handle data by the Data Controller can only do so for as long as and to the extent absolutely necessary to do their jobs or activities.

Your data might also be handled by Data Processors, but only to a limited extent, as explained in Section 10 of this notice and according to our contracts. In Section 11, the Data Controller also gives detailed info on when other third parties can access your personal data (beyond just data processing), especially if official authorities contact the Data Controller and we have a legal duty to hand over your data.

The Data Controller only handles your personal data in line with relevant laws and for the specific reasons we've told you about before we even start processing it.

The Data Controller handles all personal data lawfully and fairly, making sure the whole process is clear and transparent for you. We only collect and handle your personal data for the specific, legal reasons clearly stated in this notice, and we're super careful not to use any data in a way that doesn't match those reasons.

The Data Controller wants to make it clear that we don't track you, monitor your activities or behavior, or create profiles about you when we handle your data.

When we decide how to handle data and throughout the entire process, the Data Controller puts in place all the necessary technical and organizational steps to make sure data protection rules are followed and your rights are protected. The measures we use are chosen after carefully looking at the latest technology, the costs involved, and any potential risks to your rights.

The Data Controller wants you to know that we only handle personal data that's right and relevant for each specific purpose, and only what's absolutely needed to achieve those goals. We always try to keep your data accurate and up-to-date, and we'll do our best to correct or complete any inaccurate or wrong data as soon as possible. We kindly ask you to help us with this by letting us know in writing (via email) if your data has changed or needs to be updated for any other reason.

We'll only handle your personal data for as long as it's absolutely necessary to achieve the specific purpose. While we're handling your data, the Data Controller takes all the technical and organizational steps needed to keep it safe. This includes protecting it from unlawful handling, accidental loss, destruction, or damage, and more.

If the Data Controller ever wants to use your data for a different purpose than what's stated in this notice, we'll let you know in writing beforehand. We'll tell you the new purpose and any extra details about how we'll handle your data. Plus, we'll make sure we still have a legal reason to process your data in that new way.

It's super important to the Data Controller to have technical and organizational measures in place throughout our data handling processes. This ensures that we only process data for as long as and to the extent needed for its specific purpose, and that access to your data is controlled accordingly. To meet this commitment, the Data Controller has built controls into our data processing to make sure all operations always stay within these limits.

The Data Controller pays special attention to making sure that any data where the processing purpose has been achieved, the data handling period has expired, or the individual concerned has submitted a valid request for it, is deleted immediately. If deleting the data isn't possible, it will be anonymized so that the connection between the data and the individuals can no longer be restored.

5. How we handle your data when you create and maintain a user account

We run the website at https://infinite.ad/. For our registered users, once they pay the monthly fee we set, we offer a service that lets them launch and manage ads on Meta's platforms without any human help, all through our system. Plus, they can use AI to review and evaluate their Facebook and Instagram posts, and even create new post text.

If you register on our Website, you'll need to give us the following personal details: your name, email address, company name (if it applies), and a password.

We need to process the info you give us when you register so that we can let you log into your account on the Website, use our service through the Website, and take care of all the administrative stuff that comes with providing the service (like sending you notifications and making sure you can pay online with a credit card).

The legal reason we process the personal data you provide when you register is the agreement we have with you for using our service.

If a company uses our service, the legal reason we process the personal data you provide during registration is our and the company's legitimate interest. We've carried out a 'balancing test' for this data processing, and it confirmed that our legitimate interest, along with the company's (the one you're registering for on the Website), genuinely exists and is stronger than your interest in not having your data processed. Knowing and processing this data is absolutely essential for us to give the company the access it needs to use the service. It also allows us to get in touch with the company – through you – about the service during the contract period and send them all the necessary info. If you ask us in writing, we'll be happy to let you see the detailed balancing test. Since we process your registration data based on our own and our company partner's legitimate interest, you can object to this data processing if you have reasons related to your specific situation. You can find more details about your right to object in section 12.E.

Just a heads-up: if you don't give us all your info, or if it's incomplete when you register, we won't be able to accept your registration or let you use our service. That's because we'll be missing the basic details we need to get you set up!

Beyond what we've already mentioned, we also handle data from individual users (that's you!) who use our service. This includes what's needed for billing service fees, like your billing name, billing address, tax ID (if you're a sole proprietor), and details about when, how long, and where you used the service, plus any other data that's technically super important for us to provide the service. The whole point of this data processing is so we can send you an invoice for the service fees you've paid. The legal reason we do this is because we have a legal obligation to under Section 169 of Act CXXVII of 2007 on General Sales Tax, and we're legally allowed to by Section 13/A of Act CVIII of 2001 concerning certain aspects of information society services.

Just a heads-up: because the VAT Act requires us to process the data needed for invoicing, if you don't give us your billing info, or if it's incomplete, we have the right to cancel our service agreement with you.

If you, as an individual user, pay for our services by bank transfer, we'll also process your bank account number. We do this to record and keep track of your service fee payments. The legal reason for this is our obligation under Section 169 (2) of Act C of 2000 on Accounting.

We'll keep your user data until you delete your account through our Website.

Since we're required by Section 169 (2) of Act C of 2000 on Accounting to keep invoices and customer records (which are part of our accounting) in a readable format for 8 (eight) years from when the invoice was issued or the record was created, we'll process the personal data on invoices for individual users (like your billing name, billing address, and tax ID if you're a sole proprietor) for 8 years from the invoice date. We'll also keep your bank account number for 8 years from when your service fee was credited, even if you delete your account before this period is up.

We'll process other data needed for billing service fees (like details about when, how long, and where you used the service, plus any data that's technically super important for us to provide the service) until the service agreement between you and us comes to an end.

We want to let you know that we also use the email address you provide when you register to send you important info about using our service. This includes things like letting you know your registration was successful or sending you the link you need to confirm your profile deletion. We just want to point out that these informational emails aren't newsletters or any other kind of marketing or advertising message, so we don't need your permission to send them.

6. How we handle your data when you contact us

You can get in touch with us through our Website's online form to find and use the service that's the best fit for you from what we offer.

In this case, we'll process the following personal info you give us on the online contact form: your name and email address.

The whole point of processing this data is so we can get in touch with you directly and let you know which service we think would be best for you.

The legal reason we process this data is our legitimate interest, and we've done a 'balancing test' for it. When we did this test, we weighed our legitimate interests in processing your data against your interest in not having your data processed. Based on the balancing test, we found that our legitimate interest in processing the data of people who get in touch with us genuinely exists and takes priority over your legitimate interest in not having our data processing apply to you. If you ask us in writing, we'll be happy to let you see the detailed balancing test.

Since we process the data you provide when you contact us based on our own legitimate interest, you can object to this data processing if you have reasons related to your specific situation. You can find more details about your right to object in section 12.E.

We'll keep the personal data mentioned in this section until you object to us processing it.

7. How we handle your data when you book an appointment online

We make it easy for anyone interested in our service to book an online consultation through our Website to learn more about what we offer.

If you use this option to book an online consultation through our Website, we'll process your name, email address, and the specific time you've booked for the consultation.

The whole point of processing the personal data you give us is for us to register your booking, let you know it's confirmed, and make sure you can join the online consultation. We process this data based on GDPR Article 6(1)(b) because it's necessary for us to let you participate in the online consultation, as you requested. Just a heads-up: if you don't provide your personal data, or if it's incomplete, when booking an appointment, we won't be able to offer you the online consultation.

We'll process your data for the purpose described here until the date of the online consultation you signed up for through our Website, or for 180 days from that date.

8. Using Cookies on the Website

On our Website, we use anonymous identifiers, also known as 'cookies.' These cookies make browsing easier for you and help us with things like website management, gathering statistics, and sometimes even marketing. Basically, a cookie is a small piece of data that helps our Website remember your settings and keeps track of how you use the site and what you do while you're here.

When you visit our Website, we use cookies that get placed on your device or in your browser to make sure everything works smoothly. We do this because we have a 'legitimate interest' in it, which is a legal reason. We've actually done a check to make sure our need to use this data is balanced with your privacy rights. This check confirmed that our interest in using these cookies is valid and takes priority over you not wanting your data processed this way. If you want to see the full details of this check, just let us know in writing.

Since we process the data you provide when you contact us based on our own legitimate interest, you can object to this data processing if you have reasons related to your specific situation. You can find more details about your right to object in section 12.E.

If you agree to use cookies that aren't absolutely essential for our Website to work (by clicking the buttons on the cookie pop-up when you first visit), then we'll place and read these cookies on your device or in your browser to give you a more personalized experience. In this case, we process your data based on your consent. You can always change your mind and withdraw your consent, but just so you know, this won't affect any data processing we did legally before you withdrew your consent.

The cookies we use on our Website come in different types. Here's a quick rundown of each one:

  • Essential Cookies: These cookies are super important because they make our Website usable. They enable basic functions like letting you navigate around the site and fill out online forms. Without these cookies, our Website simply can't work right.
  • Website Settings Cookies: These cookies help us remember information that changes how our Website looks or works for you. For example, they can remember your preferred language or the region you're in.
  • Statistical Cookies: These cookies help us understand how many people visit our Website, how they find us, and how they use the site. We collect this data to create statistics and improve our Website. The information gathered by these cookies is anonymous, so we can't identify you personally from it.
  • Marketing Cookies: These cookies track what you do on our Website. They help us show you ads that are more relevant to your interests when you visit, and encourage you to engage with our site. Since the data collected by marketing cookies isn't just used by us but also shared with our media, advertising, and analytics partners, we need your consent to place these cookies on your browser and device, and to process the related data.

We want to let you know that the cookies we use on our Website can also be categorized by how long they last:

  • Temporary (Session) Cookies: These cookies automatically disappear after your visit. Their main job is to help our Website run smoothly and securely. Some of them are even essential for certain features or applications on the site to work correctly.
  • Permanent (Persistent) Cookies: We typically use these cookies to make your experience better, like providing smoother navigation, keeping secure areas of the Website safe, and understanding how you use the site. These cookies stay in your browser's cookie file for a longer time. How long they stick around depends on the cookie settings you have in your own web browser.

If you want to see detailed information about the cookies we use (like their names, what they're for, who places them, when they expire, and their type), you can always find and read all about them on the cookie panel available on our Website.

When you visit our Website, we'll clearly let you know that we use cookies. We also want to point out that cookies will only be placed on your device and browser (except for those absolutely essential for the Website to work) if you specifically agree to their use and the processing of the data they collect. You can do this by adjusting the settings on the cookie pop-up panel that appears on our Website.

We also want to remind you that you can always delete cookies from your computer or any smart device you use to view our Website. You can also disable cookies in your browser. Just keep in mind that if you do this, some parts of our Website might not work at all, or only work with limitations, due to technical reasons. You can usually manage cookies in your browser's 'Tools' or 'Settings' menu, often under a 'Privacy' section, where you might see options for 'cookies' or 'tracking'.

Depending on the type of browser you use, you can get more help with these settings by clicking on the links below:

9. How We Handle Data for Complaints and Warranty Claims

We make it easy for you to file a complaint about the service we provide through our Website or how you use it.

When we look into and respond to written complaints from customers, we mainly process your name and address. But if you choose to give us more personal information, we'll also process that data.

If you, as a user of our service, exercise your warranty rights because of a problem with our service, we'll process the following personal information about you: your name, address, the name of the service you used, when and how you reported the issue, the right you want to enforce, and any other details related to resolving your claim.

When we handle complaints made against us, we process the personal data you provide to meet our legal obligations under specific sections of the 1997 Act on Consumer Protection. We need this personal data to investigate your complaint and get back to you with a response.

We also process data from users who make warranty claims against us due to a faulty service, as required by Chapter XXIV of the 2013 Civil Code. We need your personal data to properly evaluate these claims and, if they're valid, to resolve them for you.

We only process the personal data of people who file complaints with us so we can investigate and respond to their written complaints within the legal timeframe. For those making warranty claims against us, we process their personal data so we can handle their claims, get in touch with them, and let them know about the decision and any actions we've taken (if their claim is valid).

We'll hold onto any personal data you share in a written complaint, and the info in our reply, for 5 (five) years from when we get back to you. If you're exercising your warranty rights, we'll keep your data for 5 (five) years from when we look into your claim.

10. How We Use Data Processors

We want to let you know that for some data processing activities, we work with 'data processors' – these are other companies that help us, based on a written agreement. We make sure these data processors provide all the necessary guarantees to follow data protection rules and protect your rights. It's important to understand that these data processors can't make any big decisions about your data; they only process it exactly as we instruct them.

The Data Controller works with these data processors for the data handling activities we've explained in this notice:

  • A. Billingo Technologies Zártkörűen Működő Részvénytársaság (address: 1133 Budapest, Árbóc utca 6., e-mail: hello@billingo.hu)
    Personal data we handle: the billing name and address for individual users, and the tax number if you're an individual entrepreneur.
    What this data processing is for: providing the online invoicing software needed to create invoices.
  • B. Stripe (address: 354 Oyster Point Blvd South San Francisco, CA 94080 United States, e-mail: support@stripe.com)
    Personal data we handle: the billing name and address for individual users, your bank account number (but only if you choose bank transfer as your payment method), and your tax number (only if you're an individual entrepreneur).
    What this data processing is for: providing accounting services for us.
11. How We Handle Your Personal Data and Sharing It

If a legal authority or court (who are allowed to do so by law) officially asks the Data Controller for some or all of your data, and they tell us why they need it, then we have to and are allowed to share that personal data with them.

The Data Controller wants you to know that we won't share your data with other companies, international groups, or anyone else, either within the EU or in other countries, beyond what we've already told you in this notice.

12. Your Rights and How to Use Them

The Data Controller makes sure you can fully use all your rights about your personal data that our Company handles, without any unfair limits or problems.

The Data Controller also makes sure that you, as the data owner, have the right to see your data, delete it, fix it, or limit how we use it. If we're using your data because we have a good reason (legitimate interest), you can also say no to that. You can also take back your permission at any time and move your data somewhere else. And if you're not happy with how we handle your data, you can file a complaint, all as explained below.

A. Your Right to Access Your Data

You can ask the Data Controller anytime for information about what data we have about you and how we use it.

If you send us a written request, the Data Controller will give you a copy of your data. We'll also tell you why we're using it, who we share it with, how long we plan to keep it, and explain your rights and how to use them.

The Data Controller wants you to know that we can only give you the first copy of your data for free. If you ask for more copies of the same data after your first request, or if you ask for the same thing again soon, we might charge you a fee. We'll tell you the exact amount of this fee in our response to your request.

The Data Controller wants to point out that we can only give you a copy of your data if it doesn't affect the rights and privacy of other people.

B. Your Right to Fix Your Data

If you ever notice that we're handling your personal data incorrectly, you can ask us to fix it or fill in any missing information. Just send us the correct or missing details in writing to hello@infinite.ad.

C. Your Right to Delete Your Data

You can ask the Data Controller to delete your personal data right away if:

  • we no longer need your data for the reason we collected it, or
  • you've taken back your permission, and there's no other legal reason for us to keep using your data, or
  • if we're using your data because we have a good reason (legitimate interest), you've said no to it, and there's no stronger reason for us to keep using it, or
  • your data was used illegally, or
  • the law says the Data Controller has to delete your data.

The Data Controller also wants to remind you about your 'right to be forgotten.' This means your data can be made completely unavailable. If you want to use this right, we'll use every possible tech solution to make sure your data is no longer available to our Company. This includes deleting electronic files from backups and, if we can't delete it for some reason, making your data anonymous. When you ask, we'll also make sure that any other companies we work with (our data processors) also delete or destroy your data they have.

The Data Controller asks you to understand that we can't always delete your data if we need to keep using it for things like protecting legal interests, upholding freedom of speech and information, meeting legal requirements, carrying out tasks required by law, for statistics or research, or for public health reasons.

The Data Controller also wants to make it clear that once we've deleted your data based on your request, we can't get it back.

D. Your Right to Limit How We Use Your Data

You can ask us to limit how we use your data in these situations and for these lengths of time:

  • if you find out that the Data Controller is handling your data incorrectly; in this case, you can ask us to limit its use until we've checked if your personal data is accurate;
  • if you think your data was used illegally, and you specifically ask the Data Controller not to delete it;
  • if the Data Controller no longer needs your personal data for the original reason, but you need it to make, use, or defend legal claims.
  • where the data subject has objected to processing based on legitimate interests but his or her request has been rejected by the Controller; in such a case, the restriction shall apply for the period until it is established whether the legitimate interests of the Controller or of a third party prevail over the legitimate interests of the data subject.

If the data subject's request is justified, the Controller shall inform all recipients to whom the data have been disclosed of the restriction of processing. The Data Controller draws the attention of the data subjects to the fact that, in the event of such a request, the data subject of the restriction will not be processed but will continue to be stored.

However, where the data subject has consented to the further processing of the data, or where the processing is necessary for the establishment, exercise or defence of legal claims or is justified on grounds of the protection of the rights of another natural or legal person or an important public interest of the Union or of a Member State, the Controller will continue to process the personal data, notwithstanding the restriction.

If the ground for the restriction of processing indicated by the data subject no longer applies, the Data Controller shall inform the data subject in writing of the lifting of the restriction and the date of the lifting of the restriction no later than 15 days before the lifting of the restriction.

E. Your Right to Take Back Your Permission for Data Processing

If we're processing your data because you gave us permission, you can totally withdraw that permission anytime you want. Just a heads-up: to withdraw your consent, you'll need to send us a written request to hello@infinite.ad. This written rule doesn't apply to personal data collected by cookies with your permission, though. For those, you can simply use the buttons on the cookie panel to change your mind.

The Data Controller informs the data subjects that the withdrawal of their consent does not affect the lawfulness of the processing activities of the Data Controller carried out on the basis of their consent prior to the receipt of the withdrawal notice.

F. Your Right to Object to How We Use Your Data

In the event that the data subject's data are processed by the Data Controller on the basis of his or her own or a third party's legitimate interests, the data subject may object to the processing at any time on grounds relating to his or her particular situation. The Controller draws the attention of the data subject to the fact that, in such a case, the data will no longer be processed by the Controller, unless there is another legal ground for the processing which permits the processing of the data or the processing is justified by compelling legitimate grounds which override the interests, rights and freedoms of the data subject or are related to the establishment, exercise or defence of legal claims.

G. How We Handle Your Requests

When you send us a request to use any of your rights (like those in points A-F above) about your data, we'll start looking into it right away, no matter what it's about. We promise to get back to you with a clear, written answer about what we found as soon as we can, and definitely within 1 month of getting your request.

The Data Controller may extend the above time limit for response by up to 2 additional months on the grounds of the complexity of the data subject's request or the number of requests from other data subjects received by the Data Controller.

If the time limit for responding to the request is extended, the Data Controller shall inform the data subject in writing within 1 month of receipt of the request at the latest, stating the reason for the delay. No extension shall be granted if, on the basis of the data subject's request, the Controller considers that no data protection measure is necessary. In such a case, the request shall be answered without undue delay, but at the latest within 1 month of receipt, and the Controller shall inform the data subject of the reasons why no further action has been taken in his or her case and of the remedies available to the data subject against the decision of the Controller.

The Data Controller shall not charge a fee for the measures taken to respond to or comply with the request, unless the request is manifestly unfounded or is repeated by the data subject with the same content after the previous request has been dealt with; in such cases, the Data Controller may charge the data subject a reasonable fee in proportion to the administrative costs incurred in complying with the request, the exact amount of which shall be specified in the Data Controller's response to the request.

The Data Controller draws the attention of the data subjects to the fact that, in order to avoid unauthorised access to the data, it can only comply with requests to exercise the rights to the processing of personal data if it can clearly establish the identity of the data subjects. The Data Controller therefore requests data subjects to always include in their request at least their name and e-mail address, which will allow the Data Controller to verify that the request has been made by the data subject by comparing it with the data at its disposal.

H. Your Options for What to Do Next

The Data Controller always tries to handle your data in a way that's totally legal, fair, and secure. So, if you're ever unhappy with how your data is being managed, please feel free to reach out directly to the Company using any of the contact details listed in point 2 of this notice.

If the data subject considers that the processing of his or her personal data was unlawful, he or she may also lodge a complaint with the National Authority for Data Protection and Freedom of Information (registered office: 1055 Budapest, Falk Miksa utca 9-11., postal address: 1363 Budapest, Pf. 9., e-mail address: ugyfelszolgalat@naih.hu). The rules on the receipt and handling of complaints and on the conduct of official proceedings can be found at www.naih.hu. The Data Controller further informs the data subjects that if they disagree with the decision of the Authority or if the Authority does not investigate their complaint within the time limit or does not inform them within 3 months of the procedural developments concerning their complaint or of the outcome of the complaint, they may appeal to the competent court of the seat of the Authority (Fővárosi Tribunal, address: 1055 Budapest, Markó u. 27., postal address: 1363 Budapest, Pf. 16.).

If the data subject considers that the Data Controller has infringed his/her rights by improper processing of his/her data, he/she may also apply directly to the Metropolitan Court of Budapest (address: 1055 Budapest, Markó u. 27., postal address: 1363 Budapest, Pf. 16.) for legal remedies, or may also initiate proceedings before the competent court of his/her place of residence or domicile.

The contact details of the competent courts can be found at the following link: https://birosag.hu/birosag-kereso The Data Controller draws the attention of data subjects to the fact that legal representation before the courts is mandatory, therefore they can only assert their claims in court if they have access to an appropriate legal representative.

If the Data Controller or its data processor handles your data without following the current data protection rules, and this causes you any harm, you can seek compensation in court. If you experience non-financial damage, you can claim for moral damages against the Data Controller or its data processor. Just so you know, the data processor is only responsible for damages if they didn't stick to the legal rules specifically for data processors, or if they ignored or went against the Data Controller's instructions.

The data subject may also, at his or her option, pursue his or her claim for damages before the courts having jurisdiction for the place where the Controller or the infringing processor is established or where he or she resides or is domiciled. The contact details of the competent courts can be found by clicking on the following link: https://birosag.hu/birosag-kereso.

13. Data security measures

The Data Controller shall make every effort to ensure that the personal data it processes are kept at an adequate level of security. The choice of the most appropriate data security measure is made by the Data Controller on a case-by-case basis, taking into account and assessing the existing and likely risks to the data processed.

In order to ensure data security, the Data Controller shall ensure that the electronic records and programs enabling the processing of personal data are kept confidential at all times during the period of data processing, that the electronic records and files containing the data have the necessary protection and are resistant to any unauthorized interference, attack, accidental destruction or loss of data. The Data Controller guarantees that the records and programs used for data management are available to the extent necessary both for carrying out data management operations and for exercising and enforcing the rights of data subjects.

The Data Controller shall continuously monitor and evaluate the current and likely risks to the personal data, in particular the risks of accidental or unlawful destruction, alteration, loss or access by unauthorised persons of the data processed by the Data Controller, before the processing starts and throughout the processing.

14. Handling data breaches

The Data Controller draws the attention of the data subjects to the fact that, despite the data security measures implemented by the Data Controller and enforced throughout the entire process of processing personal data, unfortunate and undesirable events may occur which may compromise the protection and security of the processed data (data breaches).

In the event of an incident involving personal data processed by the Data Controller, the Data Controller shall, in accordance with the provisions of the GDPR, ensure that the incident is reported to the National Authority for Data Protection and Freedom of Information without undue delay, but no later than 72 hours from the time of its discovery.

The Data Controller asks data subjects not to be surprised if they receive a notification of a personal data breach from the Data Controller; in such cases, the Data Controller is also fulfilling its legal obligation to inform data subjects of incidents that are likely to present a high risk to their rights and freedoms.

This kind of high risk is especially true if the incident involves sensitive data (like special data categories, info about someone's financial situation, identity theft, or how people view them socially...