PRIVACY NOTICE

THE PROTECTION OF NATURAL PERSONS RIGHTS WITH REGARD TO THE PROCESSING OF PERSONAL DATA

This notice is made to inform the clients of Dr. Tanács Law Firm, the visitors of https://drtanacs.hu/ website, and other partners regarding the processing and protection of personal data, and about legal professional privilege.  

NAME OF DATA CONTROLLER

Dr. Tanács Law Firm 

Registered Seat: 64/B Bérkert Street, Szeged, 6726 HUNGARY

Phone Number: +36 62 664 654

E-mail address: iroda@drtanacs.hu

Website: https://drtanacs.hu/ 

(hereinafter the “Law Firm”) 

NAME OF DATA PROCESSOR

Data Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller; (Regulation2016/679 Article 4 8.)

To use a data processor, prior consent from the data subject is not required, but he or she must be notified. Accordingly, the following information is provided: 

IT Services of Our Law Firm:

Data processors provide IT services (primary hosting) to our Law Firm, requiring access to personal data available on our website during the existence of the contract with it.  

Name of data processor (Hosting Provider) above:

3 in 1 Hosting Számítástechnikai és Szolgáltató Betéti Iroda 

Registered seat: 4/A Brassó Street, Szigetszentmiklós, 2310 HUNGARY

Contact: https://megacp.com/

Additional IT data processors:

Company name: Buza Patrik E.v. (web developer, SEO specialist)

Registered seat: 100 Petőfi Street, Sándorfalva, 6762 HUNGARY

Contact: https://www.buzapatrik.hu/

Company name: Google LLC 

Registered seat: Mountain View, California, USA

(it adheres to EU-U.S. PRIVACY SHIELD FRAMEWORK)

Contact: https://www.google.com/

Company Name: Facebook, Inc.

Registered seat: Menlo Park, California, USA

(it adheres to EU-U.S. PRIVACY SHIELD FRAMEWORK)

Contact: https://www.facebook.com/

Company name: Microsoft Corporation

Registered seat: Redmond, Washington, USA

(it adheres to EU-U.S. PRIVACY SHIELD FRAMEWORK)

Contact: https://onedrive.live.com/

Postal services, delivery, parcel delivery 

In regard to the above cases of data processing, our Law Firm provides personal data necessary to deliver the ordered product (name, address, phone number).

Data processor above:

Company name: Magyar Posta Zrt.

Registered seat: 2-6. Dunavirág Street, Budapest, 1138 HUNGARY

Contact: https://www.posta.hu/

LAWFULNESS OF PROCESSING

1. Data processing based on the data subject’s consent 

It is considered a statement of consent, if the individual signifies agreement to the processing of personal data relating to him or her, by ticking a box (check-box) on the Law Firm’s website or on any document provided to him or her, also making any technical adjustments related to information society services. This also applies to, any other statement or action, which signifies clearly, the consent of the data subject to the purposed processing of his or her personal data.  

In consent-based data collecting, the data controller may process the collected data without any further consent of the data subject, and also after the withdrawal of consent, if the processing is necessary for the performance of legal obligations.

2. Data processing based on legitimate interests

Processing shall be lawful if processing is necessary for the purposes of the legitimate interests pursued by the Law Firm or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. Processing personal data for direct marketing purpose and for communication with data subject is considered to be legitimate interest. 

Legitimate interest tests have been performed related to data processing based on legitimate interests, which are part of the appendix of this privacy notice. These are available upon request by data subjects. 

3. Data processing based on contractual interests

Data processing may also be based on a contractual interest if it is necessary for the performance of a contract in which the data subject is a party or if it is requested by the data subject in order to prepare the contract.

4. Data processing based on performing legal obligations 

The processing of personal data for compliance with a legal obligation is based on the regulation, regardless of the consent of the data subject.

5. Data processing for other purposes 

 Where the controller intends to further process the personal data for a purpose other than that for which the personal data was collected, the controller shall provide the data subject prior to that further processing with information on that other purpose. If it is necessary, the Law Firm requires the consent of the data subject regarding the new purpose.

INFORMATION ABOUT DATA PROCESSING BY THE LAW FIRM

1. Message on the website of the Law Firm 

On the website, in order to send a message, consent should be given by ticking the check-box. If the data subject does not give his or her consent, it results in the failure of sending the message. 

Categories of processed personal data: the natural person’s surname and forename, address, phone number, e-mail address. Please, do not give any other personal data, but ask for a personal appointment. 

Purpose of personal data processing: Request for information and for offer of legal services.

Legal basis of data processing: consent of the data subject.

Recipients of personal data, and categories of recipients: Attorneys, trainees and other employees of the Law Firm, and as data processor IT Service providers of the Law Firm.

Period for which the personal data are stored: Until the data subject withdraws his or her consent, maximum 8 years.

2. Cookie policy on the website of the Law Firm 

Cookies are text files with small pieces of data, that are stored in the user’s computer or phone (HDD, SSD) until their expiration date, and if a user returns to that site in the future, the web browser returns that data to the web server. Their purpose is to store data regarding visiting the website, and personal adjustments, but these are not personal data of the user. Cookies help to create a user friendly website and to improve the user’s experience. If the user does not agree to use cookies,  the use of the website will be intermitted. 

Categories of processed personal data: the data controller stores every analytical information without name or any other personal data 

Purpose of personal data processing: improvement in user’s internet experience, storage of personal adjustments

Legal basis of data processing: the data subject’s freely given consent  

Period for which the personal data are stored: The data subject can delete the cookies anytime on his or her computer or phone

3. Processing of the personal data of natural persons during legal services

An engagement for legal services is made and entered into by the data controller, as attorney and by the natural person, the natural person’s employer or its interest-representation bodies. According to this engagement, the data controller processes personal data as it is represented in this document.

Purpose of personal data processing: performance of the contract

Legal basis of data processing: it is required to perform the contractual and legal obligations 

Categories of processed personal data: personal data of the data subject, the party/parties with opposing interests, the experts, the witnesses and other person’s, provided in relation to the contract (especially, but not exclusively the data subject’s name, phone number, e-mail address, name by birth, mother’s name, address, place and date of birth, identity card number, tax identification number, nationality)

Period for which the personal data are stored: for the statutory retention period applicable to attorneys 

Recipients of personal data, and categories of recipients: Attorneys, trainees and other employees of the Law Firm, and as data processor IT Services of the Law Firm.

4. Client identification

Obligations prescribed by the Hungarian legal acts on the prevention of money laundering and financing of terrorism requires the data controller to identify the clients and in order to perform this task, processing personal data is necessary 

Categories of processed personal data: the data subject’s name, address, birth name, place and date of birth, mother’s name, address, in the absence of that, place of residence and the type and number of the identification document

Purpose of personal data processing: obligations prescribed by the Hungarian legal acts on the prevention of money laundering and financing of terrorism 

Legal basis of data processing: legal obligations

Period for which the personal data are stored: 8 years from the completion of the engagement

5. Data processing of applicants’ and employers’ personal data, accordingly their CV and application 

The Law Firm processes the CVs sent to it and personal data given in it, based on the consent of the data subject (even by implicit conduct) 

Categories of processed personal data: the natural person’s name, place and date of birth, mother’s name, address, educational attainment, photo, phone number, e-mail address, employers’ opinion (if it is available), CV, and personal data in these documents

Purpose of personal data processing: application, assessment of the application and to make an employment contract 

Recipients of personal data, and categories of recipients: the employer at the Law Firm who exercises employer’s rights, and other employees dealing with labour related tasks

Period for which the personal data are stored: 5 years from the application and assessment of the application. The personal data of applicants not chosen to contract must be removed after 5 years, this also pertains to the personal data of an applicant who has  withdrawn his or her application. Storing personal data after 5 years has to be consent-based. 

If the applicant does not give his or her consent, he or she shall not be chosen to make an employer contract. 

6. Data processing regarding personal data of customers, contract partners and their contacts 

If the Law Firm and its business partner make a contract, the parties shall name the contact person and his or her address in the contract. 

Categories of processed personal data: the data subjects’ name, address, phone number, job title, and e-mail address 

Purpose of personal data processing: Performance of contract, or business partnership

Legal basis of data processing: legal obligations

Period for which the personal data are stored: 5 years from the termination of contract, and/or the statutory retention period 

7. Data processing according to social media (Facebook)

The data controller manages its own page on Facebook.  The data subject could subscribe to the Facebook News Feed of the Law Firm by clicking the “Like” button on the page. 

Purpose of personal data processing: information about the current news and information regarding the data controller Legal basis of data processing: freely given consent of the data subject (Facebook’s privacy policy) 

Categories of processed personal data: name of the data subject 

Period for which the personal data are stored: The data subject may unsubscribe from the Facebook News Feed of the Law Firm by clicking the “Dislike” button on the page or delete the unwanted content appearing on his or her News Feed in Settings.

INFORMATION ABOUT THE RIGHTS OF DATA SUBJECT

You can find further information about the rights of the data subject in General Data Protection Regulation (https://eur-lex.europa.eu/legal-content/HU/TXT/HTML/?uri=CELEX:32016R0679)

  • Information and access to personal data (Article 13 and 14)
  • Right of access by the data subject (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure (‘right to be forgotten’ – Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21)
  • Right to not be subject to automated individual decision-making, including profiling (Article 22),
  • Right for remedies (Article 77-82).

Right to lodge a complaint with a supervisory authority

Every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes General Data Protection Regulation. You can find further information about remedies under Article 77. 

Contact of the supervisory authority: 

The National Authority for Data Protection and Freedom of Information

Registered seat: 9-11. Falk Miksa Street, Budapest, 1055 HUNGARY

Postal address: 1363 Budapest, Pf.: 9.

Phone number: +36 (1) 391-1400

E-mail address: ugyfelszolgalat@naih.hu

Data protection officer

The data protection officer informs and advises the controller regarding data protection, monitors the data processing, and keeps contact with the data subjects, and the supervisory authorities on issues relating to data processing.

Name: dr. Ferenc József TANÁCS

Contact: office@drtanacs.hu 

Confidentiality Obligations

The person practicing the professional activities of an attorney-at-law shall keep all attorney-client privileged information confidential. All facts, information and data of which the person practicing the professional activities of an attorney-at-law gained knowledge in the course of carrying out his professional activities, shall qualify as attorney-client privileged information. This confidentiality obligation shall also apply to employees of the Law Firm, but does not apply to members and data controllers in their relation. 

The data controller reserves the right to change this privacy notice, and in the case of change in applicable regulation, to amend it. 

Place and date: Szeged, November 17th 2020 

Dr. Tanács Law Firm

Represented by: dr. Ferenc József TANÁCS chief attorney at law