top of page

DATA MANAGEMENT AND DATA PROTECTION
RULES

1. Purpose of the Policy

 

1.1 Introduction 

The purpose of this Privacy and Data Protection Policy (hereinafter referred to as the “Policy”) is to ensure the protection of the rights and legitimate interests of visitors to the Data Controller’s website available at kunistvan.hu (hereinafter referred to as “Data Subjects”) in connection with the Data Controller’s online data processing activities, and to promote the security of personal data in the course of online and other data processing activities.

The Data Controller has made the provisions relating to the processing of personal data and this Privacy and Data Protection Policy available on the kunistvan.hu website.

This Privacy and Data Protection Policy is available in Hungarian and English. In the event of any discrepancy, inconsistency or difference in interpretation between the Hungarian and English versions, the Hungarian-language version shall prevail.

1.2. General Provisions

 

The Data Controller shall ensure that Data Subjects are able to exercise their rights in accordance with the provisions of this Policy and shall respect the rights of Data Subjects in the course of all data processing activities covered herein.

 

1.3 The Data Controller reserves the right to amend this Policy

 

This Policy may be amended in particular where new data processing activities become necessary, as a result of changes in legislation or regulatory practice, the emergence of new security risks, or where justified on the basis of feedback from Data Subjects.

Any amendments or changes shall be made available on the Data Controller’s website at kunistvan.hu.

 

2. Scope of the Policy


The legislation applicable to online data processing includes, among others:

  • Act CXII of 2011 on Informational Self-Determination and Freedom of Information (hereinafter: “Infotv.”);

  • Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities (hereinafter: “Grtv.”);

  • Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (hereinafter: “E-commerce Act”);

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: “GDPR”);

  • Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services;

  • Section 169 of Act C of 2000 on Accounting (retention of accounting documents)


The material scope of the Policy covers the following forms of online data processing:

  • contact and enquiries;

  • submission of complaints and other legal claims;

  • cookie management;

  • newsletter subscriptions;

  • data processing pursuant to the Pmt. (customer identification, verification of politically exposed person status, beneficial ownership structure).


The material scope of the Policy covers all data processing operations carried out by the Data Controller and therefore applies to both electronic and paper-based data processing.


The temporal scope of the Policy is from 27 February 2025 until revoked.

The personal scope of the Policy covers:

 

  • the Data Controller;

  • the Data Controller’s customers;

  • the Data Controller’s employees;

  • natural and legal persons or organisations without legal personality having a contractual relationship with the Data Controller;

  • Data Subjects in respect of whom this Policy contains provisions;

  • Data Subjects whose rights or legitimate interests are affected by the processing under this Policy;

  • visitors to the Data Controller’s website;

  • and all persons who have submitted questions or enquiries concerning the Data Controller’s services through the website.


3. The Data Controller

3.1. The Data Controller:

 

“Data Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by European Union or Member State law, the Data Controller or the specific criteria for its nomination may be provided for by European Union or Member State law.

 

3.2. DATA PROTECTION OFFICER is not required to be appointed / or contact details. This has been addressed in a separate legitimate interest assessment.


DATA CONTROLLER DETAILS

Name: Kun István egyéni vállalkozó

Registered office: 1172 Budapest IV. utca 11

Contact details: info@kunistvan.hu

Registration number: 53571955

Tax number: 69709496-1-42

Authority ordering registration: National Tax and Customs Administration of Hungary

3.3. The Data Processor

 

“Data Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Data Controller.

 

4. Data Transfers and Data Processors

4.1. We only transfer the data we collect if:

  • you have given your explicit consent pursuant to Article 6(1)(a) of the GDPR; or

  • disclosure is necessary for the establishment, exercise or defence of legal claims pursuant to Article 6(1), first sentence, point (f) of the GDPR and we have no reason to assume that your rights; or

  • we are legally obliged to disclose your data pursuant to Article 6(1), first sentence, point (c) of the GDPR; or

  • this is legally permissible and necessary pursuant to Article 6(1), first sentence, point (b) of the GDPR for the performance of a contract with you or in order to take steps at your request prior to entering into a contract.


Social media platforms:

Facebook: https://www.facebook.com/

Instagram: https://www.instagram.com/

YouTube:   https://www.youtube.com/

Linkedin:    https://hu.linkedin.com/

TikTok:       https://www.tiktok.com/hu-HU/

DATA PROCESSOR DETAILS

 

 

 

 

 

 

 

 

 

 

 

 

 

 

​​

Part of the data processing is carried out by our service providers. In addition to the service providers referred to in this Privacy Policy, these may include, in particular, data centres hosting our website, databases and applications, software providers that provide and develop the relevant applications for us, IT service providers maintaining our systems, agencies, market research companies, group companies, payment service providers, newsletter service providers, logistics service providers and consulting companies.

We reserve the right to change our Data Processors and, on the basis of the Data Controller’s legitimate interest, we keep the register of suppliers belonging to our subcontractor network confidential, and treat the list of partners contracting with us as an internal business secret. If you would like further information regarding the relevant legitimate interest assessment, please contact us at: info@kunistvan.hu

The Data Controller shall only use Data Processors that provide appropriate guarantees for the protection of the rights of Data Subjects and implement appropriate technical and organisational measures in order to comply with data protection requirements to the greatest possible extent. For this purpose, the framework of their cooperation is guaranteed by data protection agreements, under which the Data Controller ensures that personal data are processed solely on the written instructions of the Data Controller, that persons authorised to process personal data undertake confidentiality obligations, and that appropriate technical and organisational measures are used, to the extent possible, to assist the Data Controller in fulfilling its obligations. Accordingly, data processing may not result in misuse of data, may not constitute unlawful conduct and may not infringe the rights of Data Subjects.

4.3 Online Presence on Social Networks

We maintain a presence on social media platforms in order to communicate there, among others, with customers and interested parties and to inform them about our products, services and promotions.

User data are generally processed by the relevant social networks for market research and advertising purposes. In this way, usage profiles may be created based on users’ interests. For this purpose, cookies and other identifiers are stored on users’ computers. Based on these usage profiles, various advertisements are displayed to visitors according to their personal preferences and interests.

As part of operating our online presence, we may have access to information such as statistics concerning the use of our online presence provided by social networks. These statistics are aggregated and may contain, in particular, demographic information as well as data concerning interactions with our online presence and the posts and content distributed through it.

The legal basis for the processing is Article 6(1)(f) of the GDPR, based on our legitimate interest in effectively informing users and communicating with them in order to remain in contact with our customers and keep them informed.

The links below provide further information regarding the relevant data processing and the manner in which Data Subjects may exercise their rights.

 

5. Purpose and Legal Basis of Data Processing

 

The Data Controller processes the following personal data on the following legal bases:

Personal data: any information relating to an identified or identifiable natural person (“Data Subject”).

 

 

 

 

 

 

 

​​​​​​​
 

 

5.1. Principles of Data Processing

The Data Controller, in the course of its data processing activities, accepts as binding and protects the data processing principles set out in Article 5 of the General Data Protection Regulation, which are as follows:

Personal data shall be processed lawfully, fairly and in a transparent manner in relation to the Data Subject (“lawfulness, fairness and transparency”);

Personal data shall be collected only for specified, explicit and legitimate purposes and shall not be further processed in a manner that is incompatible with those purposes (“purpose limitation”);

Data processing shall be adequate, relevant and limited to what is necessary in relation to the purposes for which the data are processed (“data minimisation”);

Personal data processed shall be accurate and, where necessary, kept up to date; every reasonable step shall be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (“accuracy”);

Personal data shall be kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the personal data are processed, taking into account technical and organisational measures (“storage limitation”);

Personal data shall be processed in a manner that ensures appropriate security of the data through technical and organisational measures, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage (“integrity and confidentiality”).

In connection with partner collaborations used as Data Processors, the Data Controller also considers the data processing principles set out in this Article to be applicable to the Data Processor in respect of data transferred for processing. The Data Controller therefore stores the personal data processed responsibly and with particular care. The Data Controller maintains an internal register of the processing of personal data.

 

6. Conditions for the Applicability of Automated Decision-Making

The purpose of automated decision-making in certain activities of the Data Controller is to optimise and accelerate processes and to provide new opportunities so that prospective customers may receive the best possible proposed solution or diagnosis or may receive the best possible service. The results of automated decision-making are reviewed by the Data Controller’s employees. The Data Subject has the right, in connection with automated decision-making, to request human intervention on the part of the Data Controller, to express their point of view and to contest the decision.

The Data Subject customer has the right not to be subject to a decision based solely on automated processing – including profiling – which produces legal effects concerning them or similarly significantly affects them. As a general rule, automated decisions may not be based on the special categories of personal data referred to in Article 9(1), unless the customer has given explicit consent or this is provided for by Union or Member State law.

The Data Controller considers that the processing is proportionate to the objective pursued, respects the essence of the right to the protection of personal data and provides appropriate and specific measures to safeguard the fundamental rights and interests of the Data Subject.

The Data Controller does not use automated decision-making procedures.

 

7. COOKIES USED

A cookie is a small package of textual information that the Website transfers to a small file located on the hard drive of the relevant user’s computer or mobile device. Cookies participate in communication between website servers and internet browsers, are stored on the User’s computer and are retained for a predetermined period of validity. A cookie typically contains the name of the computer domain from which the cookie originated, the period of validity of the cookie, and a randomly generated number (value). Some cookies do not contain personal information and cannot be used to identify an individual user, while others contain a unique identifier – a secret, randomly generated sequence of numbers – stored by your device, thereby also making you identifiable. The operating period of individual cookies is specified in the relevant description of each cookie.

With regard to the cookies used on our Website, it is important to note that they change dynamically and different cookies may be used during different visits. The cookies currently in use can be found by clicking on the padlock icon before the https:// URL, selecting the cookie tab and then clicking on the cookie tab, where they will appear in the drop-down menu.

You also have the option to remove or block individual cookies there.

https://www.kunistvan.hu/

 

8. Rights of Data Subjects 

 

Data Subjects have the following rights in connection with the above processing activities:

The Data Subject has the right to access and become familiar with the personal data collected and is entitled to exercise this right at reasonable intervals to verify the lawfulness of the processing. In particular, upon the Data Subject’s request, the Data Subject shall have the rights listed below:

Rights of Data Subjects in connection with the processing of personal data

  • Right to information and to be informed;

  • Modification of access to personal data;

  • Right to rectification;

  • Right to erasure and the right to be forgotten;

  • Restriction of processing;

  • Right to object and right to lodge a complaint in connection with the processing of personal data.

 

Within 30 days of submission of the request, the Data Controller shall provide the Data Subject with written information in connection with the request concerning the data processed, their source, the purpose, legal basis and duration of processing, as well as the legal basis and recipient of any data transfer.

Where justified by the complexity of the request or other objective circumstances, the above deadline may be extended once by a maximum of 60 days, of which the Data Controller shall notify the applicant in writing.

If the Data Controller fails to comply with the above deadline, the Data Subject may apply to a court within 30 days of notification of the decision or from the last day of the deadline.

Concerning the rights available to them, Data Subjects have the following entitlements:

  • they may request information;

  • they may request the rectification, modification or supplementation of their personal data processed by us;

  • they may object to the processing and request the erasure and blocking of their data (except in the case of mandatory processing);

  • they may seek legal remedy before a court;

  • they may lodge a complaint with or initiate proceedings before the supervisory authority: naih.hu/panaszuegyintezes-rendje.html

Contact details of the supervisory authority:

Nemzeti Adatvédelmi és Információszabadság Hatóság, http://naih.hu, phone: +36 (1) 391-1400, postal address: 1363 Budapest, Pf.: 9., 1055  Budapest, Falk Miksa utca 9-11., e-mail: ugyfelszolgalat@naih.hu). 

The rights of Data Subjects are set out in a separate notice, which the Data Controller makes available to Data Subjects.

9. Data Security Measures

The Data Controller shall ensure that data security measures in accordance with the General Data Protection Regulation (GDPR) are implemented on the website and in the course of processing personal data. In this context, the Data Controller shall implement the necessary technical and organisational measures to ensure appropriate protection of electronically stored personal data.

Within this framework, the Data Controller adopts, develops, keeps up to date and regularly reviews all technical and organisational measures and procedural rules that ensure the security of the personal data processed by it and shall take all measures reasonably expected of it in order to prevent the destruction, unauthorised use or alteration of personal data, and shall ensure that unauthorised persons cannot gain access to the personal data processed, disclose or transfer them, or modify or erase them.

The Data Controller shall provide Data Subjects with the necessary information regarding data security in order to ensure that they possess the necessary knowledge concerning data protection, and shall ensure that its agents and employees comply with data security requirements in the course of their activities.

The Data Controller continuously monitors developments in science and technology in order to apply available technical, technological and organisational solutions, as well as solutions appropriate to the level of protection required by its data processing activities.

In order to prevent and manage personal data breaches, the Data Controller implements measures to raise data protection awareness and monitors compliance with such measures.

When operating IT systems, the Data Controller shall use the necessary access management, internal organisational and technical solutions to ensure that the personal data of Data Subjects do not come into the possession of unauthorised persons and that unauthorised persons cannot erase, export from the system or modify the data.

The Data Controller has a Data Breach Management Policy and maintains a Data Breach Register concerning any personal data breaches and, where necessary, informs the Data Subject of any breach that occurs.

Budapest, 27 February 2025

Név:
Tevékenység:
Elérhetőség:
Kun István ev.
Saját közreműködés
info@kunistvan.hu
Monday.com
Szoftver, CRM,
https://monday.com
Stripe
Fizetési rendszer
https://stripe.com/en-hu
Business Rise Kft.
Digitális üzletfejlesztés
1035 Budapest Szellő utca 10. 3/9
PayPal
Fizetési rendszer
https://www.paypal.com/hu
Axisdesign Kft.
Könyvelés
1037 Budapest Bécsi út 85.
Billingo, Nav alap
Számlázás
https://www.billingo.hu
Google Workspace
Levelezési rendszer
https://workspace.google.com/
Wix.com Ltd.
Tárhelyszolgáltató, Rendszer, CRM, e-mail marketing
https://www.wix.com/
ADATKEZELÉS JELLEGE:
KEZELT ADATOK
ADATKEZELÉS CÉLJA:
ADATKEZELÉS JOGALAP:
MEGŐRZÉSI IDŐ
ÉRINTETTEK/CÍMZETTEK:
Esemény létrehozása
Név, email-cím
workshop, oktatás, tréning
GDPR 6. cikk (1) bek. a) pontja szerinti adatkezelői hozzájárulás
Hozzájárulás visszavonásáig vagy törlési kérelem benyújtásáig
Honlap üzemeltetője, illetve harmadik fél
Info termék letöltése,
Név, e-mail cím
Népszerűsítés, marketing tevékenység, hasznos tippek a tartalom használatára vonatkozóan
GDPR 6. cikk (1) bek. f) pontja szerinti adatkezelői jogos érdek
1 év
Marketing intézésével megbízott személy
Online Időpontfoglalás
Név, email cím
időpont egyeztetése
GDPR 6. cikk (1) bek. a) pontja szerinti adatkezelői hozzájárulás
Hozzájárulás visszavonásáig vagy törlési kérelem benyújtásáig
Honlap üzemeltetője, illetve harmadik fél
Számviteli bizonylatok
Szolgáltatás igénybe vevőjének neve+ címe
Számla-és bizonylat megőrzési kötelezettség teljesítése
GDPR 6. cikk (1) bek. c) pontja szerinti jogi kötelezettség
8 év
Bizonylatok kezelésével megbízott személy
Hírlevélre feliratkozás
Név, e-mail cím
Reklámanyag hírlevél formájában történő megküldése
GDPR 6. cikk (1) bek. a) pontja szerinti hozzájárulás
Hozzájárulás visszavonásáig vagy törlési kérelem benyújtásáig
A reklámanyagok kezelésével megbízott személy
Kapcsolatfelvétel weboldalon keresztül Ajánlat kérés
Név, e-mail cím, telefonszám, üzenet szövege
Ügyfél érdeklődések megkeresések kezelése és nyilvántartása
GDPR 6. cikk (1) bekezdés a) pont szerinti hozzájárulás
A hozzájárulás visszavonásáig, illetve az érdeklődésre adott válasz érintett részére történő megküldéséig
A kapcsolattartásra felhatalmazott személyek
Panasz, jogi igény érvényesítése
Név, e-mail cím, v lakcím (opcionális), telefonszám (opcionális)
Panasz, jogi igény sikeres elbírálása
GDPR 6 cikk (1) bekezdés c) pont szerinti jogi kötelezettség
Panasz, jogi igény sikeres orvoslása, illetve jogi igényérvényesítés esetén a Fgytv. szerint tárgyév + 5 év
Panasz elbírálásában részt vevő személyek
Szervezetfejlesztési szolgáltatás
Szerződéskötéshez szükséges adatok: vezetéknév, keresztnév, lakcím, e-mail, telefonszám, Számlázáshoz szükséges adatok:cégnév, székhely, cégjegyzékszám, adószám, e-mail cím,
szolgáltatás igénybevétele
GDPR 6. cikk (1) bekezdés b) pont szerinti szerződés teljesítése
Szolgáltatás teljesítését, illetve a szerződés megszűnését követő 5 év
Az ügyfelekkel való kapcsolattartásra felhatalmazott személyek
Sütikezelés
Felhasználó azonosítására alkalmas adatot nem tartalmaznak
Személyre szabott tartalom, felhasználói élmény javítása
GDPR 6. cikk (1) bek. a) pont szerinti hozzájárulás
Böngészőben történő törlésig
Honlap üzemeltetője, illetve harmadik fél
Sütikezelés
Felhasználó azonosítására alkalmas adatot nem tartalmaznak (elengedhetetlen sütik)
Weblap működéséhez elengedhetetlenül szükséges
GDPR 6. cikk (1) bek. f) pont szerinti adatkezelői jogos érdek
Böngészőben történő törlésig
Honlap üzemeltetője, illetve harmadik fél

Request regarding data protection rights

Data Management Information Customer Service

Information for the affected person

COOKIE NOTICE

The website operated by the Data Controller at https://www.kunistvan.hu/  uses cookies. These files store various information in your web browser. For this, the consent of the Data Subject, i.e. your consent, is required pursuant to Article 6(1)(a) of the General Data Protection Regulation.

In this context, websites operating within the countries of the European Union are required to obtain users’ consent for the use of cookies and for storing them on the user’s computer or other device

.

In the case of strictly necessary cookies, the legal basis for data processing is the legitimate interest of the Data Controller pursuant to Article 6(1)(f) of the General Data Protection Regulation.

When using cookies, the Data Controller acts in compliance with Act C of 2003 on Electronic Communications, Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services, as well as the relevant regulations of the European Union.

​​

1. Policy on the Use of Cookies

This Policy applies to the cookies used on the  https://www.kunistvan.hu/   website.

 

2. What Are the "Cookies"?

Cookies are small files containing letters and numbers. A cookie is a means of exchanging information between a web server and the user’s browser. These data files cannot be executed, do not contain spyware or viruses, and cannot access the contents of the user’s hard drive.
 

3. What Can Cookies Be Used For?

With the help of the information sent by cookies, internet browsers can be recognised more easily, allowing users to receive relevant and “personalised” content. Cookies make browsing more convenient, particularly in relation to online data security requirements and relevant advertisements.

With the help of cookies, website operators can also create anonymous statistics about the habits of website visitors. Using these statistics, website editors can further personalise the appearance and content of the website.

 

4. Do Cookies Contain Personal Data?

 

Cookies do not contain personal data and therefore cannot be used to identify the user. The storage of data is necessary for more convenient browsing, and the data are stored in such a way that unauthorised persons cannot access them.

5. Types of Cookies Used on Websites

Websites may use two types of cookies:

  • Temporary cookies, which remain on the user’s device until the user leaves the website.

  • Persistent cookies, which, depending on the settings of the web browser, remain on the user’s device for a longer period or until they are deleted.

  • Third-party cookies, which are placed in the user’s browser by a third party (e.g. Google Analytics). These cookies are placed in the user’s browser if the visited website uses services provided by the third party.

Strictly Necessary Session Cookies

The use of these cookies is essential for navigating the website and for the operation of the website’s functions. Without accepting these cookies, the website or certain parts of it may not be displayed or may be displayed incorrectly.

Analytics or Performance Cookies

These cookies help distinguish website visitors and enable the website operator to collect data on how visitors behave on the website.

Where applicable, these cookies may ensure that the website remembers a previous login. They do not collect information that can identify the Data Subject; the data are stored in an aggregated and anonymous form.
(e.g. Google Analytics)

Functional Cookies

The purpose of these cookies is to improve the user experience.

They detect and store, for example, the type of device used by the user to access the website, or data previously provided by the user and requested to be stored, such as automatic login, selected language, text size, font type or other user-defined changes to customisable elements of the website.

These cookies do not track the user’s activities on other websites. However, the information collected by them may include personally identifiable data that the user has previously shared.

Targeting or Advertising Cookies

These cookies allow websites to provide information and marketing content that is most relevant to the user’s interests.

The user’s explicit consent is required for this. These cookies collect detailed information about browsing habits.


 

6. Cookies and Data Security

Cookies are not viruses or spyware. Since they are simple text files, they cannot be executed and therefore cannot be considered programs.

However, information may be hidden in cookies for other purposes or with malicious intent, in which case they may function as spyware. For this reason, antivirus and anti-malware programs may continuously identify cookies for deletion.

Since the device used for internet browsing and web servers continuously communicate with each other and therefore exchange data in both directions, if an attacker (hacker) interferes with this process, they may obtain information stored by cookies.

One reason for this may be, for example, an improperly encrypted internet (Wi-Fi) connection. By exploiting such a vulnerability, data may be extracted from cookies.

7. The https://www.kunistvan.hu/   website 

 

The website operator is:

On the above website, cookies are placed either by the website operator or by third parties.

 

​DATA CONTROLLER DETAILS:​

https://www.kunistvan.hu/impresszum​​​​

​​

The cookies placed on the website: https://www.kunistvan.hu/ 

 

8. Managing and Deleting Cookies

Cookies can be deleted or disabled in the browser software used.

By default, browsers allow cookies to be placed. This can be disabled in the browser settings, and existing cookies can also be deleted.

In addition, the browser can be configured to notify the user whenever a cookie is sent to the device.

However, it is important to emphasise that disabling or restricting these files may reduce the browsing experience and may also cause errors in the functioning of the website.

The relevant settings are usually available under the “Options” or “Settings” menu of the browser.

Each web browser is different, so to find the appropriate settings, use the “Help” menu of your browser or the links below to modify cookie settings:


Cookie settings in Firefox
Cookie settings in Chrome
Cookie settings in Safari 

To disable anonymous Google Analytics cookies, users may install a so-called Google Analytics plug-in / browser add-on, which prevents the website from sending information about you to Google Analytics.

Further information is available at:

Google Analytics & Privacy or Google Elvek és Irányelvek

If you would like to learn more about cookies and how they are used:

Microsoft Description of Cookies
All About Cookies
Facebook cookies

In matters not regulated by this Notice, particularly with regard to the rights of Data Subjects, the privacy notice of the Data Controller operating the website shall apply.

For further questions relating to cookies, the operators of the website shall provide information.

Adatfeldolgozó adatainak megnevezése
Adatfeldolgozó adatai
Név:
Kun István e.v.
Székhely:
1172 Budapest IV. utca 11.
Kapcsolati adatok:
info@kunistvan.hu
Nyilvántartási szám:
53571955
Adószám:
69709496-1-42
Nyilvántartásba vételt elrendelő hatóság:
Nemzeti Adó- és Vámhivatal
bottom of page