Privacy Policy
1. Introduction
1.1. Purpose of the Privacy Policy
The purpose of this Privacy Policy (hereinafter: “Policy”) is to present in a transparent and detailed manner how personal data is processed during the operations of RDV Audit Gazdasági Tanácsadó Kft. (hereinafter: “Data Controller”), as well as to provide information on the rights of data subjects and the ways to exercise them.
1.2. Regulatory Compliance (GDPR, Act CXII of 2011)
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR): defines uniform EU rules for the protection of personal data.
- Act CXII of 2011 (Infotv.): the Hungarian law forming the foundation of domestic data protection regulation, regarding the right to informational self-determination and freedom of information.
This Policy aims to comply with the requirements set forth in the aforementioned legislation.
2. Data controller information
2.1. Name and Contact Details of the Data Controller
- Name: RDV Audit Gazdasági Tanácsadó Kft.
- Registered Office: 5100 Jászberény, Szilvás dűlő 8. Building A
- Company Registration Number: 16-09-015176
- Tax Number: 24646709-2-16
- Representative: Rutai-Dobó Viktória
- E-mail: dobo.viktoria@rdvaudit.hu
- Phone number: +36 30 536 4202
2.2. Availability of the Privacy Policy
This Policy is available in electronic form at https://rdvaudit.hu/adatkezelesi-tajekoztato/, and can also be inspected in printed form upon request at our customer service office.
3. Definitions
3.1. Basic GDPR Concepts
- Personal Data: any information relating to an identified or identifiable natural person (“data subject”).
- Data Controller: the natural or legal person which determines the purposes and means of the processing of personal data.
- Data Processor: a natural or legal person which processes personal data on behalf of the Data Controller.
- Consent: a voluntary and explicit indication of the data subject’s wishes by which they signify agreement to the processing of personal data relating to them.
- Data Subject: any identified or identifiable natural person to whom the personal data relates.
3.2. Definition of a Personal Data Breach
A personal data breach means any event that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
4. Data Processing Principles
4.1. Legal Bases and Principles
- Lawfulness, fairness, and transparency: We process data only for specified and lawful purposes.
- Purpose limitation: Collected only for specified purposes and to the extent necessary to achieve those purposes.
- Data minimization: We collect and process only personal data that is essential for fulfilling the purpose.
- Accuracy: We ensure that processed personal data is accurate and, where necessary, kept up to date.
- Storage limitation: Personal data is stored only for as long as necessary to fulfill the purpose.
- Integrity and confidentiality: We apply appropriate technical and organizational measures to protect personal data.
4.2. Accuracy and Security of Data
- Both the Data Controller and the data subject are responsible for regular updates; the latter is required to notify any changes in their personal data.
- The Data Controller makes every effort to ensure that recorded data is accurate and protects it against unauthorized access using appropriate security measures.
5. Data Processing Purposes and Legal Bases
5.1. Registration on the Website
- Purpose: Creation of a user account and provision of related services.
- Legal basis:
- Consent (GDPR Article 6(1)(a)) in cases where registration is voluntary and requested by the data subject.
- Performance of a Contract (GDPR Article 6(1)(b)) if registration is a prerequisite for providing the service.
- Scope of Processed Data: Name, email address, password (encrypted), registration date, IP address.
5.2. Order Management
- Purpose: Processing orders, performance of the contract, invoicing, and delivery.
- Legal Basis: Performance of a Contract (GDPR Article 6(1)(b)).
- Scope of Processed Data: Name, shipping and billing address, contact details (phone number, email), order details.
5.3. Invoice
- Purpose: Compliance with applicable accounting regulations (e.g., Act C of 2000).
- Legal Basis: Compliance with a legal obligation (GDPR Article 6(1)(c)).
- Scope of Processed Data: Name/Company name, address, tax number (for legal entities), other necessary invoicing data.
5.4. Newsletter Sending
- Purpose: Marketing communication, information about new products and promotions.
- Legal Basis: Consent (GDPR Article 6(1)(a)).
- Scope of Processed Data: Name, email address.
- Note: You can unsubscribe from the newsletter at any time by clicking the link at the bottom of the newsletter or by notifying the Data Controller directly.
5.5. Use of Cookies
- Purpose: Ensuring the proper functioning of the website, improving user experience, analyzing traffic data, marketing purposes.
- Legal basis:
- Consent (GDPR Article 6(1)(a)) – for all cookies that are not essential for website operation.
- Legitimate Interest or Performance of a Contract (GDPR Article 6(1)(f) or (b)) – for technical cookies essential to operation.
- Further Description: See the “Use of Cookies” chapter of this Policy (Section 11).
Cloudflare Turnstile and Cloudflare Cookies
Our website uses the Cloudflare Turnstile service to prevent unauthorized, automated use of contact and other forms, as well as to filter out spam and malicious bot traffic.
During the operation of the service, certain technical data of the website visitor may be transmitted to Cloudflare, Inc. Transmitted and processed data may include in particular:
- the user’s IP address,
- browser and device technical data, such as User-Agent information,
- technical characteristics of the network connection,
- traffic and request data related to website use,
- and other technical information necessary to identify bot traffic.
The purpose of data processing is to determine whether the website or its forms are used by a real user or an automated system, thereby ensuring the secure operation of the website and preventing abuse.
Cloudflare may use technical cookies or similar technologies required for operation and security checks. Depending on the Cloudflare configuration used, this may include, for example, the cf_clearance cookie, which serves to store the result of a successfully completed security check. The purpose of these technologies is to maintain website security, detect automated and malicious traffic, and handle repeated security checks.
For further information on data processing by Cloudflare Turnstile, please refer to the following documents:
Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/
Cloudflare Turnstile Privacy Policy: https://www.cloudflare.com/turnstile-privacy-policy/
5.6. Social Media Data Processing
- Purpose: Contact maintenance, sharing information (Facebook, Instagram, etc.).
- Legal Basis: Voluntary decision, consent (GDPR Article 6(1)(a)).
- Note: The data processing practices of social platforms must be viewed in the privacy policy of the respective platform.
6. Scope of Processed Data
6.1. Types of Personal Data
- Identification Data: name, username, password (encrypted).
- Contact Data: email address, phone number, address.
- Technical Data: IP address, browser type, cookies, login time.
- Billing Data: billing name, address, tax number (for companies).
6.2. Storage Method and Duration
- Electronically on protected servers equipped with passwords and other security measures.
- On paper (if any) at the registered office or branch address, stored in a locked location.
- Storage Period: Until the fulfillment of legal obligations and the data processing purpose, or until consent is withdrawn. Afterwards, data is deleted or anonymized.
7. Rights of Data Subjects
7.1. Right to Information
The data subject has the right to request information on the purposes, legal bases, sources, duration, and access rights regarding their personal data processed by us.
7.2. Right to Rectification
If the data subject believes that their personal data processed is inaccurate or incomplete, they may request its correction or supplementation.
7.3. Right to Erasure (“Right to be Forgotten”)
The data subject may request the erasure of their personal data if it is no longer needed for its original purpose, or if consent is withdrawn and there is no other legal basis for processing.
7.4. Right to Data Portability
The data subject has the right to receive the personal data provided by them in a structured, commonly used, machine-readable format, or request its transfer to another data controller.
7.5. Right to Object
- The data subject may object at any time to the processing of their personal data if the legal basis is the Data Controller’s legitimate interest.
- The data subject has a specific right to object to processing for direct marketing purposes.
8. Data Security
8.1. Electronic Data Protection
- Multi-level authorization system.
- Regular security backups.
- Antivirus protection and firewall usage.
8.2. Technical and Organizational Measures
- Closed office network and secure Wi-Fi usage.
- Storing paper documents in locked cabinets.
- Regular data protection training for employees and data processors.
9. Handling Personal Data Breaches
9.1. Reporting Breaches to Authorities (72-Hour Rule)
In the event of a personal data breach, the Data Controller shall report it to the National Authority for Data Protection and Freedom of Information (NAIH) without undue delay and, where feasible, no later than 72 hours, unless it is unlikely to result in a risk to the rights and freedoms of data subjects.
9.2. Informing Data Subjects in High-Risk Cases
If the breach is likely to result in a high risk to the rights and freedoms of data subjects, the Data Controller shall inform the data subjects without undue delay, describing the nature of the breach and the measures taken.
10. Data Processors and Third Parties
10.1. Hosting Provider
- Name: Vitarex Stúdió Kft.
- Registered Office: Budapest, Aladár u. 17 Ground floor 1, 1016
- Contact: +36 1 385 1949 vitarex@vitarex.hu
- Data Processing Activity: Web server operation, technical maintenance. Processes personal data strictly under the instructions of the Data Controller.
10.2. Accountant and Other Partners
The Data Controller may engage accountants, courier services, marketing agencies, and other partners for processing personal data.
- Accountant: Accounting, payroll, and tax-related tasks are performed within the Data Controller’s own organization; no external accountant is engaged.
The Data Controller enters into written contracts with these partners (data processors) in compliance with GDPR requirements. These contracts state that partners may process data solely based on the Data Controller’s instructions, for the specified purpose, and for the required duration.
11. Use of Cookies
11.1. Purpose and Types of Cookies
- Session Cookies: essential for website functionality, deleted when the browser is closed.
- Functional Cookies: enhance user convenience, e.g., remembering login details or language selection.
- Analytical Cookies (e.g., Google Analytics): serve statistical purposes, helping to understand user behavior and improve website performance.
- Marketing Cookies: support displaying relevant ads and measuring advertising effectiveness.
11.2. Managing User Settings
- Users can control cookie settings in their browser settings, disabling or deleting them as desired.
- Modifying cookie settings may cause certain website features to function improperly.
- Upon first visiting the website, non-essential cookies (e.g., marketing) can be enabled or rejected via a pop-up banner.
12. Data Protection Officer
12.1. Designation Conditions and Duties
Under GDPR Article 37, the Data Controller is required to appoint a Data Protection Officer (DPO) if its core activities:
- consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale, or
- consist of processing special categories of data on a large scale.
The officer’s duties include:
- continuous monitoring of GDPR compliance,
- advising the Data Controller and employees,
- liaising with the supervisory authority (NAIH) and data subjects.
12.2. Status and Contact Details
The Data Protection Officer reports directly to top management and cannot be instructed regarding their duties.
- The Data Controller is not obligated to appoint a Data Protection Officer (DPO) and has not designated one.
- Contact for data protection inquiries: dobo.viktoria@rdvaudit.hu, +36 30 536 4202
Should the appointment of a DPO become mandatory or should the Data Controller voluntarily appoint one, data subjects will be duly informed in this Policy.
13. Remedies Available to Data Subjects
13.1. Filing a Complaint with the National Authority for Data Protection and Freedom of Information (NAIH)
If the data subject considers that the processing of their personal data infringes applicable laws, they may lodge a complaint with the authority:
- Address: 1055 Budapest, Falk Miksa utca 9-11.
- Phone: +36 (1) 391-1400
- Email: ugyfelszolgalat@naih.hu
13.2. Right to a Judicial Remedy
In the event of a violation of rights, the data subject may apply to the court. The lawsuit may be initiated before the regional court having jurisdiction over the data subject’s residence or place of stay, at the choice of the data subject.
14. Applicable Legislation Underlying Data Processing
14.1. GDPR (EU Regulation 2016/679)
Regulation (EU) 2016/679 of the European Parliament and of the Council aimed at protecting natural persons regarding the processing of personal data and the free movement of such data within the EU.
14.2. Act CXII of 2011 on Informational Self-Determination
The Hungarian Data Protection Act regulating the domestic principles and limitations of personal data processing.
14.3. Other Relevant Hungarian Laws
- Act C of 2000 on Accounting.
- Act V of 2013 on the Civil Code (Ptk.).
- Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities.
15. Final Provisions
15.1. Scope and Amendment of the Privacy Policy
- This Policy is effective as of August 5, 2026.
- The Data Controller reserves the right to unilaterally amend this Policy, particularly in response to legislative changes, introduction of new data processing activities, or recommendations of the supervisory authority.
- Amendments will be published on the website, and by continuing to use the services after the effective date, data subjects accept the updated rules.
Dated: Budapest, August 5, 2026
RDV Audit Gazdasági Tanácsadó Kft.
(Representative of the Data Controller)