1. Purpose and Scope of the Privacy Policy, Governing Laws
The purpose of this Notice is to set out the data protection and data management principles applied by ROIworks Zrt. (hereinafter: Data Controller) and the company's data protection and management policy, which the company acknowledges as binding upon itself as the data controller. When formulating the provisions of this Notice, the Company paid particular attention to the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council („General Data Protection Regulation” or „GDPR”), Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information („Info Act”), Act V of 2013 on the Civil Code („Civil Code”), and Act XLVIII of 2008 on the Essential Conditions and Certain Restrictions of Advertising Activity („Advertising Act”). The scope of this Privacy Notice extends to (i) data processing related to the operation of the website available at https://www.roi.works/ (hereinafter collectively referred to as the „Website”); as well as (iii) Data Processing related to Clients, and data processing related to the organisation of prize draws.
2. Definition of terms
Data Processing: any operation or set of operations which is performed on Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation, alteration, use, query, consultation, use, disclosure, transmission, dissemination or otherwise making available, alignment or combination (including profiling), restriction, erasure and destruction. Data Processor: the service provider who processes personal data on behalf of the Data Controller. For the services referred to in this Notice, the Data Processors are set out in Section 11. Data Controller: the person specified in Section 3 who determines the purposes and means of the Data Processing, either independently or jointly with others. User: the natural person who (i) visits the Website and, in connection therewith, submits their enquiry/order using the data listed in Section 7. External Service Provider: third-party service provider partners used – either directly or indirectly – by the Data Controller or the operator of the Website in connection with the provision of certain services, to whom Personal Data are or may be transmitted for the purpose of providing their services, or who may transmit Personal Data to the Data Controller. External Service Providers shall also include those service providers that are not in cooperation with either the Data Controller or the operators of the services, but which, by accessing the Website, collect data from Users that may, either independently or when combined with other data, be suitable for identifying the User. Personal Data or data: any data or information based on which a natural person User can be identified – directly or indirectly. Notice: this data protection notice of the Data Controller.
3. Identity and activity of the Data Controller
Name: ROIworks Zrt.
Registered office: 2nd floor, Balance Building, Váci út 99-105, Budapest, 1139
Email: operation@roi.hu
The Data Controller is a business association registered in Hungary.
4. Principles and methods of Data Processing, applicable legislation
4.1. The Data Controller shall, in accordance with the requirements of good faith, fairness and transparency,
It acts in cooperation with Users during the Data Processing. The Data Controller only processes data defined by law or provided by Users, for the purposes set out in the Information Notice. The scope of Personal Data processed is proportionate to the purpose of the data processing and does not extend beyond it.
4.2. In all cases where the Controller wishes to use Personal Data for a purpose other than the original purpose of data collection, it shall inform the User thereof, obtain their prior, explicit consent, and provide them with the opportunity to prohibit such use.
4.3. The Data Controller does not verify the Personal Data provided to it. The person who provided the Personal Data shall bear sole responsibility for the adequacy of the provided Personal Data.
4.4. The Data Controller shall not transfer Personal Data managed by it to any third party, other than the Data Processors specified in this Notice and – in certain cases referred to in this Notice – External Service Providers. An exception to the provision set out in this section is the use of data in a statistically aggregated form, which does not contain any other data suitable for identifying the affected User in any form, and therefore does not qualify as Data Management or Data Transmission. In certain cases – such as an official court or police request, legal proceedings due to copyright, property, or other infringement or the well-founded suspicion thereof, infringement of the interests of the Data Controller, endangering the provision of the service, etc. – the Data Controller shall make the available Personal Data of the affected User accessible to third parties.
4.5. The Data Controller's systems may collect data concerning Users' activity, which cannot be linked to other data provided by Users during registration, nor to data generated when using other websites or services. Notwithstanding this, if the User consents to the Data Controller sending and publishing marketing offers (EDMs, customised banners, displays) to them, they accept that, within the framework of this service and solely for the purpose of providing the service, the data collected regarding the User's activity shall be linked to other Personal Data provided by the User during registration.
4.6. The Data Controller shall notify the data subject User, as well as all those to whom the Personal Data was previously transmitted for the purpose of Data Processing, of the rectification, restriction or erasure of the Personal Data handled by it. Such notification may be omitted if it does not prejudice the legitimate interest of the User, having regard to the purpose of the Data Processing.
4.7. Having regard to the relevant provisions of the GDPR, the Controller is not obliged to appoint a data protection officer.
4.8. The Data Controller shall process personal data in accordance with the applicable legislation. The legislation governing data processing includes, in particular:
● Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (hereinafter: „Infotv.”);
● Act XLVIII of 2008 on the Basic Requirements of and Certain Restrictions on Commercial Advertising Activities (hereinafter: „Grtv.”);
Act CVIII of 2001 on certain aspects of electronic commerce services and information society services;
Regulation (EU) 2016/679 of the European Parliament and of the Council;
● Section 169 of Act C of 2000 on Accounting (regarding the retention of accounting documents).
4.9. Personal Data of a Data Subject under the age of 16 may only be processed with the consent of the adult exercising parental supervision over them. The Data Controller is not in a position to verify the entitlement of the consenting person or the content of their declaration, therefore the User, or the person exercising parental supervision over them, warrants that the consent complies with the law. In the absence of a consenting declaration, the Data Controller shall not collect Personal Data relating to a Data Subject under the age of 16.
5. The purpose of data processing
5.1 The Data Controller shall process Personal Data exclusively for specified purposes, in order to exercise rights and fulfil obligations. At every stage of Data Processing, it shall comply with the purpose of the Data Processing. The collection and processing of data shall be carried out fairly and lawfully. The Data Controller shall endeavour to ensure that only such Personal Data is processed as is indispensable for the realisation of the purpose of the Data Processing and is suitable for achieving that purpose. Personal Data may be processed only to the extent and for the duration necessary to achieve the purpose.
5.2 The primary purpose of the Data Processing is the operation of the Website and, in the event of form completion, contacting the User. Based on the above, the purpose of the Data Processing is: In connection with the core activity of the Primary Controller:
● Identification of the User, communication with the User;
Successful contact with the User upon completing the form
Fulfilment of the obligations incumbent upon the Data Controller, and exercise of the rights due to the Data Controller;
• Preparation of analyses and statistics, and the development of services – for this purpose, the Data Controller uses only anonymised data and aggregations that are not suitable for personal identification;
● Protection of Users' rights; with regard to Users who have consented to being contacted for marketing purposes:
● Market research: assessing user needs and purchasing habits;
6. Source of personal data, scope of processed personal data
6.1 The Data Controller processes the Personal Data provided by Users in connection with its core activity. The User may modify the provided data at any time, delete the data, and decide to delete their entire registration. Personal Data is provided on the Website. Data that can be recorded by the User: full name, email address, phone number, details of interest.
6.2 In addition to the above, the Data Controller processes technical data, specifically the IP address and cookies, as described in point 9.
7. Description of the data processing procedure
7.1 The source of the personal data is the User, who provides the data on the Website when filling out the form. Providing the data on the registration form is mandatory, unless expressly stated otherwise.
7.2 The User provides the data independently; the Data Controller gives no mandatory guidelines regarding this and sets no content expectations. The User explicitly consents to the processing of the data provided by them.
8. Management of technical data and cookies
8.1 The Data Controller's system automatically records the IP address of the User's computer, the start time of the visit, and in certain cases – depending on the computer's settings – the type of browser and operating system. The data recorded in this way – except in the case of User consents regarding marketing enquiries and profiling – cannot be linked with other Personal Data, and the processing of the data serves exclusively statistical purposes.
8.2 Cookies enable the Website to recognise previous visitors. Cookies help the Data Controller, as the operator of the Website, in optimising the Website and in tailoring the services of the Website to the habits of the Users. Furthermore, cookies are suitable for
remember the settings so that the User does not have to enter them again when navigating to a new page,
remember previously entered data so you don't have to type it in again,
analyse website usage so that, as a result of the developments carried out using the information thus obtained, it operates to the greatest possible extent according to the user's expectations, the user can easily find the information they are looking for, and
● monitor the effectiveness of our advertisements. The Data Controller uses cookies to display advertisements to Users via Google and Facebook. The data processing takes place without human intervention.
In relation to Users who have consented to being contacted for marketing purposes, the Data Controller shall use the cookie information during profiling in order to develop and send personalised offers.
8.3 The User may configure their web browser to accept all cookies, reject all cookies, or notify the user when a cookie is sent to their device. These settings are generally found in the „Options” or „Preferences” menu of the browser. By disabling the use of cookies, the User acknowledges that without cookies, the operation of the Website will not be fully functional. Detailed information available on the English-language website www.aboutcookies.org also helps with the settings in various browsers.
Data transmission
9.1 The Data Controller shall only transfer Personal Data to a third party if the User has clearly consented thereto – with knowledge of the scope of data transferred and the recipient of the data transfer – with the exception set out in points 10.2 and 10.3 below, or if such data transfer is authorised by law.
9.2 If the Data Controller transfers the operation or utilisation of the service provided by it, in whole or in part, to a third party, it may transfer the Personal Data managed by it, in whole or in part, to such third party without requesting the User's separate consent, but subject to providing appropriate prior information to the Users, to the new operator, provided that such data transfer shall not place the User in a more disadvantageous position regarding the data processing rules specified in the text of this Notice in force at any given time. In the event of a data transfer pursuant to this point, the Data Controller shall provide Users with the opportunity to object to the data transfer prior to the data transfer. In the event of an objection, the transfer of the data of the User in question pursuant to this point shall not be permitted.
9.3 The Data Controller is authorised and obliged to transfer to the competent authorities all Personal Data available to it and lawfully stored by it, the transfer of which is required by law or a final official obligation. The Data Controller cannot be held liable for such Data Transfer and any consequences arising therefrom.
9.4 The Data Controller shall document all data transfers in every case and maintain a register of data transfers.
10. Data processing
10.1 The Controller is entitled to use a Data Processor to perform its activities. Data Processors shall not make independent decisions and are only entitled to act in accordance with the contract concluded with the Controller and the instructions received. The Controller shall monitor the work of the Data Processors. Data Processors may only engage a further data processor with the consent of the Controller.
10.2 The Data Controller shall specify the used Data Processors in this Notice.
Processors engaged by the Data Controller:
● Google Ireland Limited Ireland, Dublin, Barrow Street 4. (hosting, analysis)
● Facebook Limited 4 Grand Canal Square, Dublin Ireland
● ProWebGroup OÜ – Sepapaja 6, Tallinn 15551, Estonia (provision of web hosting)
11. External service providers
11.1 In the course of operating the Website, the Data Controller engages third-party service providers, with whom the Data Controller cooperates.
11.2 With regard to Personal Data processed in the systems of External Service Providers, the provisions set out in the External Service Providers’ own privacy policies shall apply. The Data Controller shall do everything in its power to ensure that the External Service Provider processes the Personal Data transferred to it in accordance with the law, and that they are used solely for the purposes specified by the User or set out below in this Notice.
11.3 The Data Controller shall inform Users of the data transfers carried out for External Providers within the framework of this Notice.
● Google Ireland Limited, Barrow Street 4, Dublin, Ireland.
● Facebook Limited 4 Grand Canal Square, Dublin Ireland
● ProWebGroup OÜ – Sepapaja 6, Tallinn 15551, Estonia (provision of web hosting)
12. Data security, Access to personal data
12.1 The Data Controller shall ensure the security of the Personal Data it processes, shall take the technical and organisational measures and establish the procedural rules necessary to comply with the applicable legislation, data protection and confidentiality rules. The Data Controller shall protect Personal Data by taking appropriate measures against unauthorised access, alteration, disclosure, disclosure, erasure or destruction, as well as against accidental loss or damage, and against becoming inaccessible as a result of changes in the technology used.
12.2 The Data Controller shall record the Personal Data managed by it in accordance with applicable legislation, ensuring that the Personal Data may only be accessed by those employees and other persons acting in the interest of the Data Controller (data processors) who need to do so in order to perform their job roles and tasks. Employees of the Data Controller shall carry out individual searches and individual operations on the data solely at the request of the User or if this is necessary for the provision of the service.
12.3 When determining and applying measures to ensure the security of Personal Data, the Controller shall take into account the state of the art. Among several possible data processing solutions, the Controller shall choose the one that ensures a higher level of protection of Personal Data, unless this would involve a disproportionate effort. In the context of its IT protection tasks, the Controller shall ensure in particular:
● Measures ensuring protection against unauthorised access, including the protection of software and hardware tools, as well as physical security (access control, network protection);
● Measures ensuring the possibility of data set restoration, including regular backup and the separate, secure handling of copies (mirroring, backup);
● On the protection of data sets against viruses (virus protection);
● The physical protection of data files and the media on which they are stored, including protection against fire, water damage, lightning strikes and other natural disasters, as well as the recoverability of data following damage caused by such events (archiving, fire protection).
12.4 Employees, and other persons acting on behalf of the Controller, are required to securely store and protect data media used or possessed by them that also contain Personal Data, regardless of the method of data recording, against unauthorised access, alteration, transmission, disclosure, deletion or destruction, as well as accidental destruction and damage.
12.5 The Data Controller shall operate the electronic registry by means of a software programme which complies with the requirements of data security. The programme shall ensure that the data are accessed only for specific purposes, under controlled conditions, and solely by those persons who need to do so in order to perform their duties.
13. Duration of Data Processing
The Data Controller shall erase the personal data if
a) the processing is unlawful; should it transpire that the data is being processed unlawfully, the Data Controller shall execute the erasure without delay.
b) the User requests it (with the exception of data processing carried out on the basis of legislation); the User may request the erasure of data processed on the basis of their voluntary consent. In this case, the Data Controller shall erase the data. Deletion may only be refused if the processing of the data is authorised by law. The Data Controller shall, in all cases, provide information regarding the refusal of the request for deletion and the legislation authorising the processing of the data.
c) the data is incomplete or incorrect – and this status cannot be lawfully remedied –, provided that erasure is not prohibited by law;
d) the purpose of the Data Processing has ceased to exist, or the statutory time limit for the storage of the data has expired; the erasure may be refused (i) for the purpose of exercising the right to freedom of expression and information, or (ii) if legislation authorises the processing of Personal Data; as well as (iii) for the establishment, exercise or defence of legal claims. The Data Controller shall in all cases inform the User of the refusal of the request for erasure, indicating the reason for the refusal of erasure. Following the fulfilment of a request for the erasure of personal data, the previous (erased) data can no longer be restored. Newsletters sent by the Data Controller can be unsubscribed from via the unsubscribe link contained within them. In the event of unsubscription, the Data Controller shall erase the User's Personal Data from the newsletter database. Since the Data Controller provides an ongoing service to the User, the relationship between the parties is not time-bound. Accordingly – in the absence of a request from the User – the Data Controller shall process the Personal Data for as long as the relationship between the Data Controller and the User exists and for as long as the Data Controller can provide services to the User. The Data Controller shall erase all other Personal Data if it is apparent that the Personal Data will not be used in the future, i.e. the purpose of the Data Processing has ceased.
(e) it has been ordered by a court or the National Authority for Data Protection and Freedom of Information. Where a court or the National Authority for Data Protection and Freedom of Information issues a final and binding order for the erasure of Personal Data, the Data Controller shall carry out the erasure. Instead of erasure, the Data Controller shall – whilst informing the User – block the Personal Data if the User so requests, or if, based on the information available to it, it can be assumed that erasure would infringe the User’s legitimate interests. Personal data blocked in this way may only be processed for as long as the purpose of data processing that precluded the erasure of the Personal Data remains valid. The Data Controller shall mark the Personal Data it processes if the User disputes its correctness or accuracy, but the incorrectness or inaccuracy of the disputed Personal Data cannot be unequivocally established. In the case of data processing required by law, the provisions of the relevant legislation shall govern the erasure of data. In the event of erasure, the Data Controller shall render the Personal Data unfit for identification. Where required by law, the Data Controller shall destroy the data medium containing the personal data.
14. Users’ rights and the enforcement of those rights
14.1. The Data Controller shall inform the User about the processing of their Personal Data simultaneously with the establishment of contact. In addition, the User is entitled to request information regarding the Data Processing at any time. Upon the User's request, the Data Controller shall provide information on the User's data processed by it or by a Data Processor entrusted by it or acting on its instructions, the source of such data, the purpose, legal basis, and duration of the Data Processing, the name, address, and activity of the Data Processor connected with the Data Processing, the circumstances, effects, and measures taken to remedy any data protection incident, and – in the event of the transfer of the User's personal data – the legal basis and recipient of the Data Transfer. The Data Controller shall provide the information in writing in an intelligible form at the User's request within the shortest possible time from the submission of the request, but at most within 25 days. The information shall be provided free of charge if the person requesting the information has not yet submitted a request for information concerning the same data category in the current year. In other cases, a fee may be established. The fee already paid shall be refunded if the Personal Data was processed unlawfully or if the request for information led to rectification.
14.2. The User may request that the Data Controller rectifies any incorrectly recorded Personal Data. In the event that regular data provision takes place on the basis of the data to be rectified, the Data Controller shall, where necessary, inform the recipient of the data provision of the rectification, or draw the User's attention to the fact that they must also initiate the rectification with another data controller.
14.3. With the exception of data processing mandated by law, the User may request the deletion of their Personal Data (by filling in the form entitled 'Request for deletion of personal data' available on the Website). The Data Controller shall inform the User of the deletion.
14.4. The User may object to the processing of their personal data as defined in the Infotv. (Privacy Act).
14.5. The User may submit their request for information, rectification or erasure in writing, via a letter addressed to the Data Controller's registered office or premises, or via an email sent to the Data Controller at operation@roi.hu.
14.6. The User may request that the Data Controller restrict the processing of their Personal Data if the User disputes the accuracy of the Personal Data being processed. In this case, the restriction shall apply for a period enabling the Data Controller to verify the accuracy of the Personal Data. The Data Controller shall mark the Personal Data it processes if the User disputes its correctness or accuracy, but the incorrectness or inaccuracy of the disputed Personal Data cannot be clearly established. The User may request that the Data Controller restrict the processing of their Personal Data even where the processing is unlawful, but the User objects to the erasure of the Personal Data being processed and instead requests that its use be restricted. Furthermore, the User may request that the Data Controller restrict the processing of their Personal Data even if the purpose of the processing has been fulfilled, but the User requires the Data Controller to continue processing such data for the purpose of establishing, exercising or defending legal claims.
14.7. The User may request that the Data Controller hands over the Personal Data made available by the User and processed in an automated manner by the User to them in a structured, commonly used, machine-readable format and/or transmits those to another data controller.
14.8. If the Data Controller does not comply with the User’s request for rectification, restriction or erasure, it shall, within 25 days of receiving the request, provide written notification of the reasons for rejecting the request for rectification, blocking or erasure. In the event of a refusal to comply with a request for rectification, erasure or blocking, the Data Controller shall inform the User of the possibility of seeking judicial redress and of the option to lodge a complaint with the National Authority for Data Protection and Freedom of Information.
14.9. The User may make the above statements relating to the exercise of their rights using the contact details of the data controller set out in point 3.
14.10. The User may lodge a complaint directly with the National Authority for Data Protection and Freedom of Information (address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c; telephone: +36-1-391-1400; email: ugyfelszolgalat@naih.hu; website: www.naih.hu). In the event of a breach of the User’s rights, the User is entitled to bring a claim before a court pursuant to Section 22(1) of the Information Act. The adjudication of the case falls within the jurisdiction of the court. The case may also be brought before the court having jurisdiction over the User’s place of residence or place of stay, at the User’s discretion. Upon request, the Data Controller shall provide the User with detailed information on the possibilities and means of seeking legal redress.
15. Amendment of the Privacy Policy
15.1. The Data Controller reserves the right to amend this Notice at any time at its sole discretion.
15.2. By using the Website following the modification, the User accepts the provisions of the Notice in force at any given time, and no further consent from individual Users is required.