Privacy policy
For the visitors of the website of HEPA Magyar Exportfejlesztési Ügynökség Nonprofit Zrt. (www.hepa.hu) and for the users of its services.
Pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation or GDPR), the controller provides the following information to the Data Subjects about the processing of their personal data.
1. Name and Contact Details of the Controller and its Data Protection Officer
The Controller’s Data:
HEPA Magyar Exportfejlesztési Ügynökség Nonprofit Zrt. (HEPA Hungarian Export Promotion Agency Non-profit Private Company Limited by Shares)
Address:
1027 Budapest, Kacsa u. 15-23., Hungary
E-mail address:
info@hepa.hu
Telephone:
+36 1 922-2600
(hereinafter: ‘Controller’)
Data Protection Officer (DPO):
Name:
dr. András György Szilágyi
Postal address:
1027 Budapest, Kacsa u. 15-23., Hungary
E-mail address:
dpo@hepa.hu
Telephone:
+36 1 922-2600
2. Definitions
‘processing’
means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
‘controller’
means the natural or legal person or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data;
‘processor’
means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller;
‘transfer’
means making the personal data available to a specific recipient;
‘personal data breach’
means a breach of security relating to the processing of personal data that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;
‘identifiable natural person’
means a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
‘recipient’
means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not;
‘data concerning health’
means personal data related to the physical or mental health of a natural person, including the provision of health care services, which reveal information about his or her health status;
‘data subject’
means a Data Subject or natural person who is identified or identifiable based on any information;
‘consent of the data subject’
means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
‘third party’
means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data;
‘sensitive data’
means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation;
‘personal data’
means any information relating to the data subject.
3. The Principles of Data Processing
The Controller follows the following principles during its processing activity:
a) Lawfulness, fairness and transparency
We process personal data lawfully, fairly and in a transparent manner.
b) Purpose limitation
We only collect personal data for specified, explicit and legitimate purposes and do not process personal data in a manner that is incompatible with those purposes.
c) Data minimisation
The personal data we collect and process are adequate, relevant and limited to what is necessary for the purposes for which they are processed.
d) Accuracy
We will take all reasonable steps to ensure that the data we process are accurate and, where necessary, kept up to date, and any personal data that are inaccurate will be erased or rectified without delay.
e) Storage limitation
Personal data are stored in a form which allows the identification of Data Subjects for no longer than is necessary to achieve the purposes for which the personal data are processed.
f) Integrity and confidentiality
We use appropriate technical and organisational measures to ensure the appropriate protection of personal data against unauthorised or unlawful processing, accidental loss, destruction or damage.
4. Information on Automated Decision-making and Profiling
No automated decision-making or profiling will take place during the processing.
5. The Scope of the Personal Data Processed, and the Purpose, Legal Basis and Duration of the Processing
Activity 1: Company registration on the website
Purpose of the processing:
- communication on business and professional matters
- communication for marketing purposes
- request for information
- sending information leaflets and invitations to our events (exhibitions, functions, training etc.)
Legal basis:
Exercise of official authority: Article 6(1)(e) of the General Data Protection Regulation, having regard to the following law: Section 1(2) of Government Decree 163/2018 (IX. 10.)
Data processed:
- telephone number
- surname of the chief executive
- first name of the chief executive
- position of the chief executive
- surname of the contact person
- first name of the contact person
- position of the contact person
Duration or termination of processing:
until the company cancels its registration (or until the company’s objection)
Activity 2: Newsletter
Purpose of the processing:
its purpose is communication in connection with the public duties of the Controller and informing you about our news and upcoming events
Legal basis:
Exercise of official authority: Article 6(1)(e) of the General Data Protection Regulation, having regard to the following law: Section 1(2) of Government Decree 163/2018 (IX. 10.)
Data processed:
- full name
- e-mail address
Duration or termination of processing:
until you unsubscribe from the newsletter