Privacy Policy

Privacy Policy

Introduction

SZI Holding Kft. provides the following privacy notice regarding the processing of personal data of natural persons, in full compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (the “Info Act”).


Data Controller:

Name: SZI Holding Kft. Registered address: 1126 Budapest, Bartha utca 8., 2nd floor, door 11 Tax number:14561735-2-43 Email: iroda [at] sziholding [dot] hu


What personal data is collected?

Consent is always voluntary and informed, given by data subjects after reading this privacy notice.

Data that comes into the possession of the data controller is processed exclusively by employees who participate in the fulfilment of the data processing purposes defined in this notice, and who are bound by a confidentiality obligation with respect to all data they access.


Purposes of data processing:

  1. Contact form Data received through the contact form is retained for 2 weeks. This information is not used for marketing purposes and is used solely to respond to the requested enquiry.

Cookies

The website operated by the data controller uses “cookies” to collect profile and status data for the identification of data subjects and the tracking of visitors. Cookies are data that are temporarily stored on the visitor’s hard drive from the browser upon visiting the website, and which are necessary for the use of the website but cannot on their own be used to identify the visitor personally. Cookies provide additional functionality for the website and help us assess website usage more accurately.


Under the Info Act, cookies may only be used with the visitor’s prior consent; the visitor therefore has the option to allow or reject cookies. However, if the visitor chooses to reject cookies, they may not be able to make full use of the interactive features of the website.


During the use of the website, the following data is recorded and processed regarding the visitor and the device used for browsing:

  • the IP address used by the visitor
  • the type of browser
  • characteristics of the operating system of the device used for browsing (language settings)
  • the time of the visit
  • the (sub)page, function or service visited

Acceptance of cookies is not mandatory. You may reset your browser settings to reject all cookies or to indicate when a cookie is being sent. Although most browsers automatically accept cookies by default, these settings can generally be changed to prevent automatic acceptance and to offer a choice each time.


Cookies used on the website operated by the data controller:


Statistical cookies: Google Analytics cookies — for more information, visit: https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage To permanently disable Google Analytics cookies, install a browser add-on available at: https://tools.google.com/dlpage/gaoptout


Retention period of personal data

Personal data will be deleted at any time upon the request of the data subject, or in the case of newsletter services, upon unsubscription. Data recorded on invoices (name, address) must be retained for at least 8 years in accordance with applicable accounting regulations.

Personal data is destroyed securely by the data controller within the specified timeframes.

You are hereby informed that you have the right to request information about data processing at any time, as well as to rectify your personal data and request its deletion. To do so, please send a message to iroda [at] sziholding [dot] hu.


With whom do we share user data?


Website data is shared with the following service providers:

  1. Hosting provider: Dotroll Kft. Email: support@dotroll.com Company registration number: 01-09-882068Tax number: 13962982-2-42 Registered address: 1148 Budapest, Fogarasi út 3–5.

What rights does the visitor have regarding their data?


As a data subject, you have the right to request access to, rectification, erasure or restriction of processing of your personal data, to object to the processing of such data, and the right to data portability.


  1. Right to information: Upon request, the data controller provides detailed information about the data processed, the purpose and duration of processing, the activities related to processing, and who receives your data and for what purpose. The information is sent by the data controller in writing, in an intelligible form, electronically to the email address provided by the data subject, within the shortest possible time and no later than 30 days from the submission of the request.

  2. Right of access: You are entitled to receive confirmation from us as to whether your personal data is being processed and, if so, to access the personal data processed by the data controller. This allows you to verify whether your personal data is being processed in accordance with data protection legislation.

  3. Right to rectification: You are entitled to request the rectification or completion of inaccurate or incomplete personal data.

  4. Right to erasure: The right to erasure, also known as the “right to be forgotten”, allows you to request the deletion of your personal data where its processing is no longer necessary for the purposes for which it was collected or processed, or in other applicable circumstances. This does not, however, constitute an unconditional obligation to delete. The data controller may refuse deletion where, for example, processing is required by law or there is another legal basis or statutory purpose for processing.

  5. Right to restriction of processing: In certain situations, you are entitled to restrict the further processing of your personal data. Where processing is restricted, your data will not be processed other than for storage purposes.

  6. Right to object: You are entitled to object to certain types of data processing. The data controller will examine the objection within the shortest possible time, but no later than 15 days from receipt, while simultaneously suspending the processing, and will inform the data subject in writing of the outcome. If the data controller finds the objection to be justified, it will cease processing, block the data, and notify all parties to whom the data in question was previously disclosed, who are required to take action to enforce the right to object.

  7. Right to data portability: You are entitled to receive a copy of certain personal data processed by the data controller and to transmit it to another data controller.


You have the right to withdraw your consent to data processing at any time; however, withdrawal of consent does not affect the lawfulness of processing carried out on the basis of consent prior to its withdrawal.


How do we protect users’ personal data?


To protect the security of your personal data, we implement technical, administrative and physical security measures to ensure that only authorised persons can access your personal data and use it for the specified purposes. To this end, we take the following measures:

  • We establish procedural rules to ensure that collected, stored and processed data is protected; data is protected by appropriate measures against accidental or unlawful destruction, loss, alteration, damage, transmission, unauthorised disclosure or unauthorised access.
  • Personal data is classified and treated as confidential; employees are bound by confidentiality obligations with respect to personal data they process.
  • Access to personal data relating to clients and financial processes is restricted by means of access levels.
  • IT systems are protected by firewalls and antivirus software.
  • Electronic data processing and record-keeping is carried out using computer software that meets data security requirements; the software ensures that data is accessible only on a purpose-bound basis, under controlled conditions, and only by those who need it to carry out their duties.
  • Appropriate technical solutions ensure that data stored in records cannot be directly linked or attributed to the data subject.
  • Appropriate physical protection is ensured for data and the devices and documents that carry it (password protection on the computers of employees handling data).

What procedures apply in the event of data protection breaches?


If the data subject disagrees with the data controller’s decision regarding an objection, or if the data controller fails to respond within the deadline, the data subject may apply to a court within 30 days of the decision being communicated or the last day of the deadline. The court will deal with the case on a priority basis. You may bring proceedings — at your choice — before the court of your place of residence or habitual residence.

We also draw your attention to the fact that you may lodge a complaint with the following supervisory authority, or initiate an investigation by way of a notification, on the grounds that a breach of your rights in connection with the processing of your personal data has occurred or is directly at risk:


National Authority for Data Protection and Freedom of Information (NAIH) Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/C. Postal address: 1530 Budapest, Pf. 5 Email: ugyfelszolgalat@naih.hu Phone: +36 1 391 1400


How can you contact us?


The operator of the sziholding.hu website can be contacted at the details provided in the “Data Controller” section above.

The data controller deletes all emails received, together with the sender’s name, email address, date and time, and any other personal data provided in the message, no later than 5 years from the date of the communication.

Visitors are informed that courts, prosecutorial authorities, investigative authorities, administrative authorities, the National Authority for Data Protection and Freedom of Information, and other bodies authorised by law may contact the data controller for the purpose of providing information, disclosures or documents. In such cases, the data controller will only disclose personal data to the extent strictly necessary for the purpose of the request, provided the authority has specified the exact purpose and scope of the data requested.


The data controller reserves the right and undertakes the obligation to amend this privacy policy in accordance with applicable laws and legal practice as they may change from time to time.


The data controller will provide notice of any changes to its data processing practices on its central website prior to their entry into force.


01.07.2026