Back

Privacy policy

1. Purpose of the Notice

  • The purpose of this Notice is to set out the data protection and processing principles applied by ÉGV Toronydaru Zártkörűen Működő Részvénytársaság, KRANSERVICE Zártkörűen Működő Részvénytársaság and Ácsgép Fuvarozó Korlátolt Felelősségű Társaság (Data Controllers) and the company’s data protection and data processing policies, which the company, as Data Controller, consider as binding.
  • This Notice summarizes the principles of processing personal data content recorded with the help of the www.acsgep.hu web interface, as well as those published on it, but not published by third parties.

2. Scope of the Notice

  • In developing the provisions of the Notice, the Data Controller took into account in particular:
    • Regulation of the European Parliament and of the Council 2016/679 (General Data Protection Regulation or ‘GDPR’),
    • Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (‘Infotv’),
    • Act V of 2013 on the Civil Code (Civil Code),
    • and Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities (‘Advertising Act’).
  • Scope of data processing: The Notice covers data collection and data sharing services initiated by the Data Controller on the website available at www.acsgep.hu.
  • Exceptions to data processing: Unless otherwise stated, the scope of this document does not cover the services and data processing of websites, service providers to which links are made on the website covered by the Notice (link to third party).
  • Such services are governed by the provisions of the personal privacy notice declared by the third party operating the service, and the Data Controller does not take any responsibility for these data processing activities.

3. Terms and Definitions

  • Data subject: The natural person whose data are processed.
  • Personal Data: data that can be linked to any identified, identified or identifiable natural person [Data Subject] and the conclusion that can be drawn from the data on the Data Subject. Personal data shall remain as such during data management as long as its connection to the person concerned can be restored. The connection with the Data Subject can be restored if the data controller has the technical conditions necessary for the recovery.
  • Data processing:any operation performed on data, regardless of the procedure used, such as collecting, recording, organising, storing, altering, using, querying, transferring, disclosing, reconciling or linking, blocking, erasing and destroying data, and to prevent further use of the data, to take photographs, sound or images and to record physical characteristics (fingerprints or palm prints, DNA samples, iris image, etc.) that can be used to identify the person.
  • Controller: who determines the purposes and means of data processing – independently or together with others.

For the services referred to in this Notice, the Data Controller is:

Name: ÉGV Toronydaru Zrt.
Registered office: 2120 Dunakeszi, Székes dűlő, topographic lot No. 8029
Postal address: 1327 Budapest, PO Box: 36.
Company registration number: 13-10-041705
Tax administration No.: 25924136-2-13; EU tax number: HU25924136
Representative of the Controller: Balázs Andrássy, data protection manager
Phone: +36 27 547 170
Contact details of the Data Controller regarding data protection: info@acsgep.hu

Name: KRANSERVICE Zrt.
Registered office: 2615 Csővár, Mikszáth Kálmán utca 3/a.
Postal address: 1327 Budapest, PO Box: 39.
Company registration number: 13-10-041689
Tax administration No.: 14333877-2-13; EU tax number: HU14333877
Representative of the Controller: Balázs Andrássy, data protection manager
Phone: +36 27 547 170
Contact details of the Data Controller regarding data protection: info@acsgep.hu

Name: Ácsgép Fuvarozó Kft.
Registered office: 2615 Csővár, Mikszáth Kálmán utca 3/a.
Postal address: 1327 Budapest, PO Box: 50.
Company registration number: 13-09-177637
Tax administration No.: 12197899-2-13; EU tax number: HU12197899
Representative of the Controller: Balázs Andrássy, data protection manager
Phone: +36 27 547 170
Contact details of the Data Controller regarding data protection: info@acsgep.hu

The Controller process data jointly.

4. Processed personal data, purposes of processing

  • The data controller uses the following data sets:
    • Registration data
    • Technical data
    • Location data
    • Browser data
  • The data controller collects data for the following purposes:
    • Online content service, advertising, offer
    • Business (core) activity support,
    • Provision of services requested by the Data Subject,
    • Brand building,
    • Statistics (Analysis)

5. Processing methods

5.1 E-mail marketing

  • Description of the activity: Using the data collected with the consent of the Data Subject, ad-hoc E-mails will be sent to the Data Subjects on a regular and individual basis. The Data Subject may unsubscribe from the mails at any time.
  • Purpose of processing: Business (core) activity support.
  • Legal ground of processing: Consent of the data subject.
  • Data source: Voluntary consent.
  • Processed data:
    • E-mail,
    • E-mail address,
    • Name.
  • Data retention period: Until consent is withdrawn.

5.2 Ordering, price offer request

  • Description of the activity: The Data Controller also enables the ordering of the rental service performed by it via the offer requesting-ordering interface. After entering their details, the users send an E-mail to the relevant competent business area, which prepares the price offer and forwards it to the E-mail address provided in the request for offer. The data is also recorded in the partner database.
  • Purpose of processing: Supporting the use of the service requested by the Data Subject.
  • Legal ground of processing: Legitimate interest. (Supporting the performance of basic business tasks.)
  • Data source: Voluntary consent.
  • Processed data:
    • Registration data: first name, last name, E-mail address, phone number, company name.
    • Location data: address, postcode.
    • Analytical data: machine category, machine type, field of application, serial number.
  • Data retention period 6 years after the last active connection.

5.3 Placement of cookies

  • Description of the activity: The Data Controller uses ‘cookie’ technology to enhance and facilitate the visiting experience on the website. A cookie is a small file containing a series of characters – which the Service Provider sends to the visitor’s computer, through which its browser becomes uniquely identifiable. These ‘cookies’ are received by the Data Subject’s computer, which makes it identifiable as an individual user and stores personal preferences and technical information.
  • ‘Cookies’ do not in themselves contain or reveal any personal information. However, if personally identifiable information is submitted through the Data Controllers’ website, the information may already be linked to the data stored in cookies.
  • Purpose of processing: Business (core) activity.
  • Legal ground of processing: Legitimate interest. (Supporting the performance of basic business tasks.)
  • Data source: User computer.
  • Processed data:
    • Technical data: Browser ID.
  • Data retention period:
    • Persistent cookie: until deleted,
    • Temporary cookie: until the browser is closed.

6. Data subjects

Those involved in data processing on the www.acsgep.hu website.

7. Children

Our products and services are not intended for persons under the age of 18 and we ask that persons under the age of 18 do not provide Personal Data to the Data Controller. If we become aware that we have collected personal data from a child under the age of 18, we will take the necessary steps to erase the information as soon as possible.

8. Automated decision-making

The data of the Data Subject will not be managed or processed in an automatic decision-making system.

9. Rights of the data subjects

The Data Subject may request the Data Controller at the contact details indicated in Section 3:

  • to provide information on the processing of their personal data,
  • to rectify their data,
  • to erase their personal data or restricting data processing,
  • they may object to data processing
  • to transfer their data to another data controller, if the data processing is based on a contract or consent and is processed by the Organisation in an automated procedure.
  • they may provide for the withdrawal of their previous consent to the processing.

The Data Subject can exercise their rights above at any time. The Data Controller will provide information related to the received request (acceptance, rejection, clarification) within 7 working days after the submission of the request. Thereafter, the Data Subject will receive information on the status of the processing of the request no later than 30 days (if necessary every 30 days). It informs the Data Subject in writing of the final result (E-mail or postal letter).

If the Data subject disagrees with the decision of the decision by the Data Controller, they may apply to the court within 30 days of the communication of such decision.

9.1 Cost of information

For the first time, the data controller shall provide the measures and the necessary information free of charge.

If the Data Subject requests the same data for the 2nd time within a month, which has not changed during this time, the Data Controller will charge an administrative fee.

  • The basis for calculating the administrative cost is the cost per hour of the current minimum wage as an hourly rate.
  • The number of hours worked for the information, calculated on the basis of the former hourly rate.
  • Furthermore, in the case of a paper-based information request, the cost of printing the response at cost and postage.

9.2 Refusal of information

  • If the data subject’s request is clearly unfounded: The applicant is not entitled to the information if the Data Controller can prove that the Data Subject has the requested information. The request will be refused.
  • If the data subject’s request is excessive, in particular because of its repetitive nature: The Controller may refuse to act on the request if they make a third request within a month to exercise the Data Subject’s rights on the same subject (pursuant to Articles 5-22 of the 1GDPR).

9.3 Right to objection

The data subject has the right to object at any time to the processing of their personal data on the legal ground of a legitimate interest or public authority.

The Controller shall no longer process the personal data unless the Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.

If it establishes that the legal ground of the objection is justified, the Data Controller shall terminate the data processing as soon as possible – including the transfer of data and further data collection. It shall notify all persons to whom it has previously transformed the data of the Data Subject of the objection.

The processing of the request is free of charge, except for unfounded or excessive requests, for the processing of which the Data Controller may charge a reasonable fee corresponding to the administrative costs. If the Data subject disagrees with the decision of the decision by the Data Controller, they may apply to the court.

10. Disclosure of Data, data transfer

Disclosure shall be made only with the express consent of the data subject.

11. Data transfer to a third country or to an international organisation

The Data Controller will NOT transfer the personal data of the Data Subject to a third country or international organisation outside the states of the European Economic Area.

12. Information on data security measures

The Data Controller processes the data in a closed system in accordance with the requirements of the Information Security Policy.

Data Controller provides default and built-in privacy. For this purpose, the Data Controller shall apply appropriate technical and organisational measures in order to:

  • precisely regulates access to data;
  • grant access only to those persons who need it for the performance of their task, which is the same as for the purpose for which the data were collected, and still only have access to the data that is the minimum necessary to perform the task;
  • carefully select the data controllers mandated by it and ensure the security of the data with an appropriate data processing contract;
  • ensures the integrity (data integrity), authenticity and protection of the data processed.

The Data Controller shall apply reasonable level of physical, technical and organisational security measures to protect the data of the Data Subject, in particular against their accidental, unauthorised, unlawful destruction, loss, alteration, transfer, use, access or processing. The Data Controller shall immediately notify the Data Subject in the event of unauthorised access to or use of personal data that is known and involves a high risk to the data subject.

The Data Controller, if the transfer of Data Subject’s data is required, shall ensure the appropriate protection of the transferred, for example by encrypting the data file. The Data Controller is fully responsible for the processing of the Data Subject’s data performed by third parties.

The Data Controller shall also ensure, through appropriate and regular backups, that the Data Subject’s data is protected against destruction or loss.

13. Analytical Services

The controller uses Google Analytics to track page statistics and user demographics, interest, and site behaviour. The Organisation also uses the Google Search Console to search engine optimise the site and measure user satisfaction. Google provides the opportunity to restrict the use of analytical services. Visit Google to unsubscribe from using Google Analytics. https://tools.google.com/dlpage/gaoptout

14. Legal remedy

The Data Controller voluntarily undertakes to provide an opportunity to complain to any Data Subject to investigate an alleged or legitimate breach of the processing of their personal data. The Data Subject may complain to any data controller at the following contact details:

Name: ÉGV Toronydaru Zrt.
Registered office: 2120 Dunakeszi, Székes dűlő, topographic lot No. 8029
Postal address: 1327 Budapest, PO Box: 36.
Company registration number: 13-10-041705
Tax administration No.: 25924136-2-13; EU tax number: HU25924136
Representative of the Controller: Balázs Andrássy, data protection manager
Phone: +36 27 547 170
Contact details of the Data Controller regarding data protection: info@acsgep.hu

Name: KRANSERVICE Zrt.
Registered office: 2615 Csővár, Mikszáth Kálmán utca 3/a.
Postal address: 1327 Budapest, PO Box: 39.
Company registration number: 13-10-041689
Tax administration No.: 14333877-2-13; EU tax number: HU14333877
Representative of the Controller: Balázs Andrássy, data protection manager
Phone: +36 27 547 170
Contact details of the Data Controller regarding data protection: info@acsgep.hu

Name: Ácsgép Fuvarozó Kft.
Registered office: 2615 Csővár, Mikszáth Kálmán utca 3/a.
Postal address: 1327 Budapest, PO Box: 50.
Company registration number: 13-09-177637
Tax administration No.: 12197899-2-13; EU tax number: HU12197899
Representative of the Controller: Balázs Andrássy, data protection manager
Phone: +36 27 547 170
Contact details of the Data Controller regarding data protection: info@acsgep.hu

The Data Subject may turn directly to the competent court (the Capital Court in the Budapest) or request an investigation at the Hungarian National Authority for Data Protection and Freedom of Information:

  • President: Dr Attila Péterfalvi,
  • Address: 1024 Budapest, Szilágyi Erzsébet fasor 22/C,
  • Contact details: ugyfelszolgalat@naih.hu, +36-1-3911400, www.naih.hu,

Dunakeszi, 25 May 2018

Call Now Button