DATA PROCESSING NOTICE
The LG TECHNOLOGIES Limited Liability Company (registered office: 2161 Csomád, Levente utca 14. A. building, company registration number: 13-09-231888, tax number: 24376004-2-13, statistical number: 24376004-3314-113-15, registration body: Budapest Regional Court Commercial Court, hereinafter referred to as: Company or Entrepreneur or Enterprise) by publishing this data processing policy, we comply with Regulation 2016/679 of the European Parliament and of the Council (hereinafter referred to as: GDPR) obligation prescribed by.
I. NAME OF THE DATA CONTROLLER
The LG TECHNOLOGIES Limited Liability Company informs the data subject that it is considered a data controller in relation to the processing of certain of his/her personal data. The data controller's details are as follows:
Name: LG TECHNOLOGIES Limited Liability Company
Registered office: 2161 Csomád, Levente Street 14.
Tax number: 24376004-2-13
Company registration number: 13-09-231888
Court ordering registration: Budapest District Court Commercial Court
Phone: +36 70 563 0493
E-mail: info@lgtechnologies.hu
Representative: Károly Lengyel, Managing Director
II. DEFINITIONS (Based on the relevant provisions of the GDPR)
III. NAME OF THE DATA PROCESSOR
The LG TECHNOLOGIES Limited Liability Company uses a data processor for the operation and maintenance of its website, the use of IT solutions, the performance of accounting and payroll tasks, and auditing purposes. The LG TECHNOLOGIES Limited Liability Company Data of data processors used by:
Company name: Tower Interconsult Ltd.
Headquarters: 134 Budapest, Váci Street 45. Building G., 7th floor.
Company registration number: 01-09-995297
Tax number: 24200943-2-41
Activity: 6920'08 - Accounting, auditing and tax expert activities
Company name: Websupport Hungary Ltd.
Headquarters: 1119 Budapest, Fehérvári Street 97-99.
Company registration number: 01-09-381419
Tax number: 25138205-2-43
Activity: 6311'08 - Data processing, web hosting services
IV. GENERAL DATA PROCESSING RULES
V. LG TECHNOLOGIES KFT. ACTIVITIES AS A DATA PROCESSOR
LG Technologies Ltd. processes the personal data of natural persons contracting with it and natural persons employed by legal entities necessary for the performance of the contract for the period necessary for the performance of the contract. The legal basis for data processing by LG Technologies Ltd. is the performance of the contract (GDPR Article 6 (1) b)) and the User's consent (GDPR Article 6 (1) a)), the purpose of data processing is to maintain contact with the contracting natural person, enforce the claims arising from the contract, and fulfill the obligations arising from the contract.
The personal data processed may include: natural person identification data (name, birth name, place and time of birth, mother's name, address), telephone number, e-mail address, tax number, bank account number, social security number, identity document number.
LG Technologies Ltd. processes the personal data of natural persons contracting with it for the period specified by the legal provisions requiring the retention of the contract.
The main activity of LG Technologies Ltd. is the construction, maintenance, installation of air conditioning and other equipment, as well as other construction works. LG Technologies Ltd. transfers the name, mother's name, place and date of birth, telephone number, e-mail address and residential address of the natural persons contracting with it to its employees and subcontractors if this is necessary for the performance of the contract, the purpose of the data management is to maintain contact with the customers, the duration of the data management is the duration of the contract.
LG Technologies Ltd. processes the personal data of its employees included in the employment register. These are the following: name; mother's name; home address and place of residence, as well as notification address; contact details (telephone number, e-mail address); social security number, tax identification number, type and number of personal identification document; amount of wages; name of the account-keeping financial institution and account number; amount and title of withholdings and deductions from wages, as well as the account number of the person entitled to the deductions and withholdings; names and social security numbers of children and dependents; name and contact details of the next of kin to be notified.
The purpose of data processing is: to fulfill obligations arising from the employment relationship and exercise rights arising from the employment relationship, to establish and terminate the employment relationship.
Duration of data management: 8 years after the employment relationship and termination of the employment relationship, or, if longer, the period specified in the legislation.
Legal basis for data processing: legitimate interest of the employer, fulfillment of a legal obligation, fulfillment of the employment contract. The employee must be informed of the legal basis and purpose of data processing before data processing begins.
LG Technologies Kft. processes the data necessary for the fulfillment of these legal obligations of those natural persons in a contractual relationship with it, against whom LG Technologies Kft. is subject to obligations prescribed by the legal provisions relating to accounting. The purpose of data processing is to determine the mandatory data content of the invoice, issue the invoice, and perform accounting tasks related to invoicing. Scope of the processed data: LG Technologies Kft. processes the names of the persons concerned, their registered residential and notification addresses, their electronic mailing addresses, their tax identification numbers (tax numbers) and the data related to their payment accounts (account number, account management institution data). Employees of LG Technologies Kft. who perform invoicing and related accounting activities as part of their job duties are entitled to learn about the processed personal data. LG Technologies Kft. is entitled to process the personal data recorded in the course of fulfilling the legal obligation specified above for 8 years from the termination of the contract (business relationship).
LG Technologies Kft., in accordance with the legal provisions determining the taxation regime, files an electronic return on a monthly basis, by the twelfth day of the month following the month in question, on all taxes, contributions and mandatory data related to payments and benefits made to natural persons resulting in tax and/or social security obligations.
Data management may be carried out by employees of LG Technologies Kft. performing payroll activities as a job task or by business companies and sole proprietors entrusted with these tasks. LG Technologies Kft. processes data processed in connection with the fulfillment of tax and contribution obligations for the period prescribed by the legal provisions determining the taxation system.
VI. LEGAL BASIS FOR DATA PROCESSING
The lawfulness of the processing of personal data must be based on the consent of the data subject or on some other legitimate basis established by law.
In the case of data processing based on the data subject's consent, the data subject may provide their consent to the processing of their personal data in the following form:
Silence, a pre-ticked box, or inaction does not constitute consent.
Consent covers all data processing activities carried out for the same purpose or purposes.
If the data processing serves several purposes at the same time, consent must be given for all the purposes of data processing. If the data subject gives his consent following an electronic request, the request must be clear and concise and must not unnecessarily hinder the use of the service for which consent is requested.
The data subject shall have the right to withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. The withdrawal of consent shall be made as easy as the granting of consent.
Data processing is considered lawful if it is necessary for the performance of a contract to which the data subject is a party, or if it is necessary to take steps at the data subject's request prior to entering into a contract.
The consent given by the data subject to the processing of personal data that is not necessary for the performance of the contract cannot be a condition for concluding a contract.
The legal basis for data processing is determined by law in the event of compliance with a legal obligation, so the consent of the data subject is not required for the processing of their personal data.
The data controller is obliged to inform the data subject about the purpose, legal basis, duration of data processing, the identity of the data controller, as well as their rights and legal remedies.
The data controller is entitled to process the data set necessary for the fulfillment of a legal obligation to which it is subject, after the withdrawal of the data subject's consent.
The legitimate interests of the controller, including the controller to whom the personal data may be disclosed, or of a third party may constitute a legal basis for processing, provided that the interests, fundamental rights and freedoms of the data subject are not overridden by them, taking into account the reasonable expectations of the data subject based on the relationship between the data subject and the controller. Such legitimate interests may exist, for example, where there is a relevant and appropriate relationship between the data subject and the controller, for example where the data subject is a client or employee of the controller.
In order to determine the existence of a legitimate interest, it is necessary to carefully examine, among other things, whether the data subject can reasonably expect, at the time and in the context of the collection of personal data, that data processing may take place for the given purpose.
The interests and fundamental rights of the data subject may override the interests of the controller if personal data are processed in circumstances in which the data subject does not expect further processing.
VII. RIGHTS OF THE DATA SUBJECT RELATING TO THE PROCESSING OF THEIR DATA
The data subject has the right to:
for information before starting data processing,
to receive feedback from the data controller as to whether or not personal data concerning you is being processed, and if such processing is taking place, you have the right to access the personal data and the following information:,
request the correction or deletion of your data, and receive notification from the data controller that this has occurred,
request restriction of data processing, receive notification from the data controller that this has occurred,
data portability,
to object if your personal data is processed for purposes of public interest or with reference to the legitimate interests of the data controller.
be exempt from automated decision-making, including profiling,
to file a complaint with the supervisory authority. The data subject may exercise his/her right to file a complaint at the following contact details:
National Data Protection and Freedom of Information Authority,
address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c.,
Phone: +36 (1) 391-1400; Fax: +36 (1) 391-1410.,
e-mail: ugyfelszolgalat@naih.hu
to an effective judicial remedy against the supervisory authority,
to an effective judicial remedy against the data controller or processor,
to inform about the data protection incident. b) Detailed information provided on the rights of the data subject
Right to information
the identity and contact details of the data controller and, if any, the data controller's representative;
contact details of the data protection officer, if any;
the purpose of the intended processing of personal data and the legal basis for the processing;
in the case of data processing based on point (f) of Article 6(1) of the Regulation, the legitimate interests of the controller or a third party;
where applicable, the recipients of the personal data and the categories of recipients, if any;
where applicable, the fact that the controller intends to transfer the personal data to a third country or to an international organisation, the existence or absence of an adequacy decision by the Commission, or, in the case of transfers referred to in Article 46, Article 47 or the second subparagraph of Article 49(1) of the Regulation, an indication of the appropriate and suitable safeguards and a reference to the means of obtaining a copy of them or their availability.
the duration of storage of personal data or, if this is not possible, the criteria for determining this duration;
the right of the data subject to request from the controller access to, rectification, erasure or restriction of processing of personal data concerning him or her, and to object to the processing of such personal data, as well as the right of the data subject to data portability;
in the case of processing based on Article 6(1)(a) or Article 9(2)(a) of the Regulation, the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
the right to lodge a complaint with a supervisory authority; whether the provision of personal data is based on a legal or contractual obligation or is a prerequisite for entering into a contract, and whether the data subject is obliged to provide the personal data, as well as the possible consequences of failure to provide the data;
the fact of automated decision-making referred to in Article 22(1) and (4) of the Regulation, including profiling, and at least in these cases, intelligible information on the logic involved and the significance and foreseeable consequences of such processing for the data subject.
the data subject already has the information;
providing the information in question proves impossible or would involve a disproportionate effort, in particular for archiving purposes in the public interest, scientific and historical research purposes or statistical purposes, in the case of processing carried out subject to the conditions and safeguards referred to in Article 89(1), or where the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously jeopardise the achievement of the purposes of such processing. In such cases, the controller shall take appropriate measures to safeguard the rights and freedoms and legitimate interests of the data subject, including making the information publicly available;
the collection or disclosure of the data is expressly required by Union or Member State law applicable to the controller, which provides for appropriate measures to safeguard the legitimate interests of the data subject; or
personal data must remain confidential pursuant to an obligation of professional secrecy laid down in Union or Member State law, including a statutory obligation of confidentiality.
The data subject's right of access
the purposes of data processing;
the categories of personal data concerned; the recipients or categories of recipients to whom the personal data have been or will be disclosed, including in particular recipients in third countries or international organisations;
where applicable, the planned period for which the personal data will be stored or, if this is not possible, the criteria for determining this period;
the right of the data subject to request from the controller the rectification, erasure or restriction of processing of personal data concerning him or her and to object to the processing of such personal data;
the right to lodge a complaint with a supervisory authority;
if the data were not collected from the data subject, all available information regarding their source;
the fact of automated decision-making referred to in Article 22(1) and (4) of the Regulation, including profiling, and at least in these cases, intelligible information on the logic involved and the significance and foreseeable consequences of such processing for the data subject.
The data subject's right to rectification and erasure
The right to rectification
The right to erasure („the right to be forgotten”)
the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
the data subject withdraws his or her consent which was the basis for the processing pursuant to Article 6(1)(a) of the Regulation (consent to the processing of personal data) or Article 9(2)(a) of the Regulation (granting explicit consent) and there is no other legal basis for the processing;
the data subject objects to the processing of his or her data pursuant to Article 21(1) of the Regulation (right to object) and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2) of the Regulation (objection to the processing of personal data for commercial purposes);
the personal data has been processed unlawfully;
the personal data must be erased for compliance with a legal obligation under Union or Member State law to which the controller is subject;
the personal data were collected in connection with the provision of information society services referred to in Article 8(1).
for the purpose of exercising the right to freedom of expression and information;
for compliance with an obligation to process personal data under Union or Member State law to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
on grounds of public interest in the field of public health in accordance with Article 9(2)(h) and (i) of the Regulation and Article 9(3) of the Regulation;
for archiving purposes in the public interest, scientific and historical research purposes or statistical purposes in accordance with Article 89(1) of the Regulation, where the right referred to in paragraph 1 would likely render impossible or seriously jeopardise such processing; or
to assert, enforce or defend legal claims.
Right to restriction of data processing
the data subject disputes the accuracy of the personal data, in which case the restriction shall apply for a period of time enabling the controller to verify the accuracy of the personal data;
the processing is unlawful and the data subject opposes the erasure of the data and instead requests the restriction of their use;
the controller no longer needs the personal data for the purposes of processing, but the data subject requires them for the establishment, exercise or defence of legal claims; or
the data subject has objected to the processing pursuant to Article 21(1) of the Regulation; in this case, the restriction shall apply for a period of time until it is determined whether the legitimate grounds of the controller override those of the data subject.
Notification obligation related to the rectification or erasure of personal data or the restriction of data processing
The right to data portability
the processing is based on consent pursuant to Article 6(1)(a) of the Regulation (the data subject's consent to the processing of personal data) or Article 9(2)(a) of the Regulation (the data subject's explicit consent to the processing) or on a contract pursuant to Article 6(1)(b); and
data processing is carried out in an automated manner.
The right to protest
Right to be exempt from automated decision-making
necessary for the conclusion or performance of a contract between the data subject and the data controller;
is permitted by Union or Member State law applicable to the controller and which also lays down suitable measures to safeguard the rights and freedoms and legitimate interests of the data subject; or
based on the explicit consent of the data subject.
The data subject's right to complain and seek legal redress
Right to lodge a complaint with a supervisory authority
National Data Protection and Freedom of Information Authority Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c Phone: +36 (1) 391-1400; Fax: +36 (1) 391-1410 www: www.naih.hu e-mail: ugyfelszolgalat@naih.hu
Right to an effective judicial remedy against the supervisory authority
Right to an effective judicial remedy against the controller and the processor
national security;
national defense;
public safety;
the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security; other important objectives of general public interest of the Union or of a Member State, in particular the important economic or financial interests of the Union or of a Member State, including monetary, budgetary and taxation matters, public health and social security;
the protection of judicial independence and judicial proceedings;
in the case of regulated professions, the prevention, investigation, detection and conduct of proceedings related to ethical violations;
in the cases referred to in points a)–e) and g) – even occasionally – control, investigation or regulatory activities related to the performance of public authority tasks;
the protection of the data subject or the rights and freedoms of others;
enforcement of civil law claims.
the purposes of data processing or categories of data processing,
categories of personal data,
the scope of the restrictions introduced,
guarantees to prevent misuse or unauthorized access or transmission,
to identify the data controller or to identify categories of data controllers,
the duration of data storage and the applicable safeguards, taking into account the nature, scope and purposes of the data processing or categories of data processing,
the risks to the rights and freedoms of data subjects, and
the right of data subjects to be informed about the restriction, unless this may adversely affect the purpose of the restriction.
the controller has implemented appropriate technical and organisational protection measures and these measures have been applied to the data affected by the data breach, in particular measures – such as the use of encryption – that make the data unintelligible to persons not authorised to access the personal data;
the controller has taken further measures following the data protection incident to ensure that the high risk to the rights and freedoms of the data subject referred to in paragraph (1) is no longer likely to materialise;
information would require a disproportionate effort. In such cases, the data subjects should be informed by means of publicly published information or a similar measure should be taken to ensure that the data subjects are informed in a similarly effective manner.
VIII. PROCEDURE TO BE APPLIED IN CASE OF A DATA SUBJECT'S REQUEST
IX. PROCEDURE TO BE APPLIED IN THE EVENT OF A DATA PROTECTION INCIDENT
the nature of the data breach must be described, including, where possible, the categories and approximate number of data subjects and the categories and approximate number of data affected by the breach;
közölni kell az adatvédelmi tisztviselő vagy a további tájékoztatást nyújtó egyéb kapcsolattartó nevét és elérhetőségeit;
ismertetni kell az adatvédelmi incidensből eredő, valószínűsíthető következményeket;
ismertetni kell az adatkezelő által az adatvédelmi incidens orvoslására tett vagy tervezett intézkedéseket, beleértve adott esetben az adatvédelmi incidensből eredő esetleges hátrányos következmények enyhítését célzó intézkedéseket.
X. AZ ADATBIZTONSÁGRA VONATKOZÓ RENDELKEZÉSEK
a személyes adatok kezelésére használt rendszerek és szolgáltatások folyamatos bizalmas jellegének biztosítása, integritása, rendelkezésre állása és ellenálló képességének fennállása;
fizikai vagy műszaki incidens esetén az arra való képesség, hogy a személyes adatokhoz való hozzáférést és az adatok rendelkezésre állását kellő időben vissza lehet állítani;
az adatkezelés biztonságának garantálására hozott technikai és szervezési intézkedések hatékonyságának rendszeres tesztelésére, felmérésére és értékelésére szolgáló eljárás alkalmazása,
Ellátja az általa kezelt adatállományokat számítógépes vírusok elleni állandó védelemmel (valós idejű vírusvédelmi szoftvert alkalmaz).
Gondoskodik az informatikai rendszer hardvereszközeinek fizikai védelméről, beleértve az elemi károk elleni védelmet.
Gondoskodik az informatikai rendszer jogosulatlan hozzáférés elleni védelméről, mind a szoftver-, mind a hardvereszközök tekintetében.
Megteszi mindazokat az intézkedéseket, amelyek az adatállományok helyreállításához szükségesek, a biztonsági másolatok elkülönített, biztonságos kezelését végrehajtja.
Az LG Technologies Kft. papíralapú nyilvántartásainak védelme
XI. AZ ADATFELDOLGOZÁSSAL KAPCSOLATOS SZABÁLYOK
Csomád, 2024.11.04.