Privacy Policy

English translation for information purposes; the legally binding version is the Hungarian notice.

When you visit the humanplus.hu and marketingplus.hu websites (the "Websites") or use the services presented on them, personal data is provided to us. This document explains how such data is stored and used and what rights you have in relation to its processing. For any data protection question, contact us at info@humanplus.hu.

Details of the data controller (the Service Provider):

Name: hpmp Cégfejlesztő Korlátolt Felelősségű Társaság

Registered office: 1118 Budapest, Dayka Gábor utca 7. I. em. A. ajtó, Hungary

Company registration number: 01-09-407210

Tax number: 32111831-2-43

Electronic contact: info@humanplus.hu

Bank account: OTP Bank 11712004-22478186

Registering authority: Company Registry Court of the Budapest-Capital Regional Court · The services available on the Websites may be used by representatives of legal entities and by sole traders acting within their trade, independent occupation or business activity (together: businesses), given that under Section 2(a) of Act CLV of 1997 on Consumer Protection the Service Provider does not provide services to consumers. Company data is public information in the public interest, however during an enquiry or order a business may also provide personal data, therefore the Service Provider intends to comply in all cases with the legal requirements applicable to the processing of personal data. For the purposes of this notice, "Client" means anyone who uses the contact details published on the Websites for an enquiry about or an order of services, and who orders and uses the services.

In establishing and applying this policy the Service Provider acts in the spirit of, and in compliance with, Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (the "Info Act") and Regulation (EU) 2016/679 of the European Parliament and of the Council (the "GDPR").

Data processing when ordering and using the services and visiting the Websites

The Service Provider collects traffic data about visits to the Websites and to any other websites made available by the controller in connection with the ordered services. Data collection is carried out with Google Analytics, operated with IP anonymisation settings, so the IP address used during the visit does not appear in the visit statistics.

Enquiries and establishing the client relationship

The ordering process can be started with a message sent to the contact details listed in the contact section of the Websites.

Purpose of processing: contacting the enquirer with a confirmation e-mail. Scope of data processed: company name, contact person, business e-mail address, business phone number. Legal basis: the enquirer's consent, and taking steps leading to an offer and to the conclusion of a contract.

Duration of processing: 1 year from the submission of the order. Method of storage: electronic.

Where processing is based on consent, the data subject may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

The controller processes personal data relating to enquirers and clients that comes to its knowledge while providing the Services in accordance with the applicable data protection rules. Personal data of the Client's employees and, in the case of recruitment, of applicants, is processed in accordance with the Privacy Notice for Users.

Client communication · Data that comes to our knowledge during an enquiry about the services available on the Websites is used solely to take the steps leading to the conclusion of a contract (keeping in touch). If the enquirer does not become a contracted Client, we delete the personal data, including the e-mail correspondence. E-mail addresses and phone numbers of enquirers are used for marketing purposes only after prior consent.

Invoicing · Purpose of processing: issuing an accounting document (invoice). Scope of data processed: company name, contact person, business e-mail address, business phone number, the Client's tax number/tax identifier. Legal basis: mandatory processing based on law (Section 166(1) of Act C of 2000 on Accounting). Duration of processing: 1 year from the submission of the order. Method of storage: electronic. After the order has been fulfilled the Service Provider issues an invoice to the User.

Retention of invoices · Purpose of processing: retaining the accounting document (electronic invoice). Scope of data processed: company name, contact person, business e-mail address, business phone number, the Client's tax number/tax identifier. Legal basis: mandatory processing based on law (Section 169(1) of Act C of 2000 on Accounting). Duration of processing: 8 years from the issue of the invoice. Method of storage: electronic and paper-based.

Processing by the Service Provider · As a general rule the Service Provider does not verify the personal data provided to it. Responsibility for the accuracy of the data provided lies exclusively with the person providing it. By giving an e-mail address, every Client also accepts responsibility for ensuring that only they use the service from that address. In view of this, all liability connected with communication from a given e-mail address and with access to the services rests solely with the enquirer or client who provided the data. In case of doubt the Service Provider is entitled to verify the enquirer's or client's relationship to the represented company or sole trader on the basis of company data that is public in the public interest.

Who may access the data provided

The data is primarily accessible to the Service Provider (and its staff); it is disclosed to third parties only under the terms of the contract concluded with the Service Provider. (An exception applies where a court or authority orders the Service Provider to transfer the data.)

A third party may be involved only with the Client's consent, in order to ensure a high professional standard of the work.

Rights of the data subject · The data subject may request free information about the details of the processing of their personal data and, in the cases set out by law, may request its rectification, erasure, blocking or the restriction of processing, and may object to such processing. The Service Provider examines the request within the shortest possible time from its submission, but no later than 30 days – or 15 days in the case of an objection – and decides on its merits, informing the applicant in writing. If the Service Provider does not comply with the Client's request, it states the factual and legal grounds for the refusal in its decision.

Under Act V of 2013 on the Civil Code the data subject may enforce their rights before a court and, as set out in the Info Act, may turn to and lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (1125 Budapest, Szilágyi Erzsébet fasor 22/c.; https://www.naih.hu/panaszuegyintezes-rendje.html).

Other provisions

The Service Provider collects data about the activity of enquirers.

If the Service Provider wishes to use the data provided for a purpose other than the original purpose of collection, it informs the data subject, obtains their prior express consent, or gives them the opportunity to prohibit such use.

The Service Provider undertakes to ensure the security of the data and to take the technical measures that keep recorded, stored and processed data protected, and does everything possible to prevent its destruction, unauthorised use and unauthorised alteration. · A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data processed. In the event of a personal data breach the Service Provider acts in accordance with Articles 33 and 34 GDPR. The Service Provider keeps a record of personal data breaches, including the related facts, their effects and the remedial action taken.

The Service Provider is entitled to amend this notice unilaterally at any time. The Service Provider informs the Client about amendments by e-mail or via its website.