PRIVACY NOTICE
THE PROTECTION OF NATURAL PERSONS RIGHTS WITH REGARD TO THE PROCESSING OF PERSONAL DATA
This notice is made to inform the clients of Dr. Tanács Law Firm, the visitors of https://drtanacs.hu/ website, and other partners regarding the processing and protection of personal data, and about legal professional privilege.
NAME OF DATA CONTROLLER
Dr. Tanács Law Firm
Registered Seat: 64/B Bérkert Street, Szeged, 6726 HUNGARY
Phone Number: +36 62 664 654
E-mail address: iroda@drtanacs.hu
Website: https://drtanacs.hu/
(hereinafter the “Law Firm”)
NAME OF DATA PROCESSOR
Data Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller; (Regulation2016/679 Article 4 8.)
To use a data processor, prior consent from the data subject is not required, but he or she must be notified. Accordingly, the following information is provided:
IT Services of Our Law Firm:
Data processors provide IT services (primary hosting) to our Law Firm, requiring access to personal data available on our website during the existence of the contract with it.
Name of data processor (Hosting Provider) above:
3 in 1 Hosting Számítástechnikai és Szolgáltató Betéti Iroda
Registered seat: 4/A Brassó Street, Szigetszentmiklós, 2310 HUNGARY
Contact: https://megacp.com/
Additional IT data processors:
Company name: Buza Patrik E.v. (web developer, SEO specialist)
Registered seat: 100 Petőfi Street, Sándorfalva, 6762 HUNGARY
Contact: https://www.buzapatrik.hu/
Company name: Google LLC
Registered seat: Mountain View, California, USA
(it adheres to EU-U.S. PRIVACY SHIELD FRAMEWORK)
Contact: https://www.google.com/
Company Name: Facebook, Inc.
Registered seat: Menlo Park, California, USA
(it adheres to EU-U.S. PRIVACY SHIELD FRAMEWORK)
Contact: https://www.facebook.com/
Company name: Microsoft Corporation
Registered seat: Redmond, Washington, USA
(it adheres to EU-U.S. PRIVACY SHIELD FRAMEWORK)
Contact: https://onedrive.live.com/
Postal services, delivery, parcel delivery
In regard to the above cases of data processing, our Law Firm provides personal data necessary to deliver the ordered product (name, address, phone number).
Data processor above:
Company name: Magyar Posta Zrt.
Registered seat: 2-6. Dunavirág Street, Budapest, 1138 HUNGARY
Contact: https://www.posta.hu/
LAWFULNESS OF PROCESSING
1. Data processing based on the data subject’s consent
It is considered a statement of consent, if the individual signifies agreement to the processing of personal data relating to him or her, by ticking a box (check-box) on the Law Firm’s website or on any document provided to him or her, also making any technical adjustments related to information society services. This also applies to, any other statement or action, which signifies clearly, the consent of the data subject to the purposed processing of his or her personal data.
In consent-based data collecting, the data controller may process the collected data without any further consent of the data subject, and also after the withdrawal of consent, if the processing is necessary for the performance of legal obligations.
2. Data processing based on legitimate interests
Processing shall be lawful if processing is necessary for the purposes of the legitimate interests pursued by the Law Firm or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. Processing personal data for direct marketing purpose and for communication with data subject is considered to be legitimate interest.
Legitimate interest tests have been performed related to data processing based on legitimate interests, which are part of the appendix of this privacy notice. These are available upon request by data subjects.
3. Data processing based on contractual interests
Data processing may also be based on a contractual interest if it is necessary for the performance of a contract in which the data subject is a party or if it is requested by the data subject in order to prepare the contract.
4. Data processing based on performing legal obligations
The processing of personal data for compliance with a legal obligation is based on the regulation, regardless of the consent of the data subject.
5. Data processing for other purposes
Where the controller intends to further process the personal data for a purpose other than that for which the personal data was collected, the controller shall provide the data subject prior to that further processing with information on that other purpose. If it is necessary, the Law Firm requires the consent of the data subject regarding the new purpose.
INFORMATION ABOUT DATA PROCESSING BY THE LAW FIRM
1. Message on the website of the Law Firm
On the website, in order to send a message, consent should be given by ticking the check-box. If the data subject does not give his or her consent, it results in the failure of sending the message.
Categories of processed personal data: the natural person’s surname and forename, address, phone number, e-mail address. Please, do not give any other personal data, but ask for a personal appointment.
Purpose of personal data processing: Request for information and for offer of legal services.
Legal basis of data processing: consent of the data subject.
Recipients of personal data, and categories of recipients: Attorneys, trainees and other employees of the Law Firm, and as data processor IT Service providers of the Law Firm.
Period for which the personal data are stored: Until the data subject withdraws his or her consent, maximum 8 years.
2. Cookie policy on the website of the Law Firm
Cookies are text files with small pieces of data, that are stored in the user’s computer or phone (HDD, SSD) until their expiration date, and if a user returns to that site in the future, the web browser returns that data to the web server. Their purpose is to store data regarding visiting the website, and personal adjustments, but these are not personal data of the user. Cookies help to create a user friendly website and to improve the user’s experience. If the user does not agree to use cookies, the use of the website will be intermitted.
Categories of processed personal data: the data controller stores every analytical information without name or any other personal data
Purpose of personal data processing: improvement in user’s internet experience, storage of personal adjustments
Legal basis of data processing: the data subject’s freely given consent
Period for which the personal data are stored: The data subject can delete the cookies anytime on his or her computer or phone
3. Processing of the personal data of natural persons during legal services
An engagement for legal services is made and entered into by the data controller, as attorney and by the natural person, the natural person’s employer or its interest-representation bodies. According to this engagement, the data controller processes personal data as it is represented in this document.
Purpose of personal data processing: performance of the contract
Legal basis of data processing: it is required to perform the contractual and legal obligations
Categories of processed personal data: personal data of the data subject, the party/parties with opposing interests, the experts, the witnesses and other person’s, provided in relation to the contract (especially, but not exclusively the data subject’s name, phone number, e-mail address, name by birth, mother’s name, address, place and date of birth, identity card number, tax identification number, nationality)
Period for which the personal data are stored: for the statutory retention period applicable to attorneys
Recipients of personal data, and categories of recipients: Attorneys, trainees and other employees of the Law Firm, and as data processor IT Services of the Law Firm.
4. Client identification
Obligations prescribed by the Hungarian legal acts on the prevention of money laundering and financing of terrorism requires the data controller to identify the clients and in order to perform this task, processing personal data is necessary
Categories of processed personal data: the data subject’s name, address, birth name, place and date of birth, mother’s name, address, in the absence of that, place of residence and the type and number of the identification document
Purpose of personal data processing: obligations prescribed by the Hungarian legal acts on the prevention of money laundering and financing of terrorism
Legal basis of data processing: legal obligations
Period for which the personal data are stored: 8 years from the completion of the engagement
5. Data processing of applicants’ and employers’ personal data, accordingly their CV and application
The Law Firm processes the CVs sent to it and personal data given in it, based on the consent of the data subject (even by implicit conduct)
Categories of processed personal data: the natural person’s name, place and date of birth, mother’s name, address, educational attainment, photo, phone number, e-mail address, employers’ opinion (if it is available), CV, and personal data in these documents
Purpose of personal data processing: application, assessment of the application and to make an employment contract
Recipients of personal data, and categories of recipients: the employer at the Law Firm who exercises employer’s rights, and other employees dealing with labour related tasks
Period for which the personal data are stored: 5 years from the application and assessment of the application. The personal data of applicants not chosen to contract must be removed after 5 years, this also pertains to the personal data of an applicant who has withdrawn his or her application. Storing personal data after 5 years has to be consent-based.
If the applicant does not give his or her consent, he or she shall not be chosen to make an employer contract.
6. Data processing regarding personal data of customers, contract partners and their contacts
If the Law Firm and its business partner make a contract, the parties shall name the contact person and his or her address in the contract.
Categories of processed personal data: the data subjects’ name, address, phone number, job title, and e-mail address
Purpose of personal data processing: Performance of contract, or business partnership
Legal basis of data processing: legal obligations
Period for which the personal data are stored: 5 years from the termination of contract, and/or the statutory retention period
7. Data processing according to social media (Facebook)
The data controller manages its own page on Facebook. The data subject could subscribe to the Facebook News Feed of the Law Firm by clicking the “Like” button on the page.
Purpose of personal data processing: information about the current news and information regarding the data controller Legal basis of data processing: freely given consent of the data subject (Facebook’s privacy policy)
Categories of processed personal data: name of the data subject
Period for which the personal data are stored: The data subject may unsubscribe from the Facebook News Feed of the Law Firm by clicking the “Dislike” button on the page or delete the unwanted content appearing on his or her News Feed in Settings.
INFORMATION ABOUT THE RIGHTS OF DATA SUBJECT
You can find further information about the rights of the data subject in General Data Protection Regulation (https://eur-lex.europa.eu/legal-content/HU/TXT/HTML/?uri=CELEX:32016R0679)
- Information and access to personal data (Article 13 and 14)
- Right of access by the data subject (Article 15)
- Right to rectification (Article 16)
- Right to erasure (‘right to be forgotten’ – Article 17)
- Right to restriction of processing (Article 18)
- Right to data portability (Article 20)
- Right to object (Article 21)
- Right to not be subject to automated individual decision-making, including profiling (Article 22),
- Right for remedies (Article 77-82).
Right to lodge a complaint with a supervisory authority:
Every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes General Data Protection Regulation. You can find further information about remedies under Article 77.
Contact of the supervisory authority:
The National Authority for Data Protection and Freedom of Information
Registered seat: 9-11. Falk Miksa Street, Budapest, 1055 HUNGARY
Postal address: 1363 Budapest, Pf.: 9.
Phone number: +36 (1) 391-1400
E-mail address: ugyfelszolgalat@naih.hu
Data protection officer
The data protection officer informs and advises the controller regarding data protection, monitors the data processing, and keeps contact with the data subjects, and the supervisory authorities on issues relating to data processing.
Name: dr. Ferenc József TANÁCS
Contact: office@drtanacs.hu
Confidentiality Obligations
The person practicing the professional activities of an attorney-at-law shall keep all attorney-client privileged information confidential. All facts, information and data of which the person practicing the professional activities of an attorney-at-law gained knowledge in the course of carrying out his professional activities, shall qualify as attorney-client privileged information. This confidentiality obligation shall also apply to employees of the Law Firm, but does not apply to members and data controllers in their relation.
The data controller reserves the right to change this privacy notice, and in the case of change in applicable regulation, to amend it.
Place and date: Szeged, November 17th 2020
Dr. Tanács Law Firm
Represented by: dr. Ferenc József TANÁCS chief attorney at law