Skip to content

Data Protection Policy

Internal Data Protection and Data Security Policy of Igloo.hu Kft.

1. PREAMBLE

The right to the protection of personal data is, as laid down in Article VI(2) of the Fundamental Law of Hungary, a fundamental constitutional right, the most essential requirement of which, according to the case law of the Constitutional Court, is that “the entire course of data processing must be made traceable and verifiable for everyone, that is, everyone has the right to know who uses their personal data, where, when and for what purpose.”

SERVICE PROVIDER DETAILS

Name: Igloo.hu Kft.
Registered office: 1115 Budapest, Bártfai utca 55. 7/23.
Tax number: 27523779-2-43
Phone: +36308265787
Email: info@igloo.hu
Bank account number: 11773494-00547651
as controller (hereinafter: Controller)

complies with this constitutional requirement and with all of its legal obligations. It further ensures compliance with the principle of accountability and, in this policy (hereinafter: Policy) and its annexes, sets out the processing activities it carries out, the conditions, purpose and legal basis of the processing operations, and the procedural rules, that is, who performs which task in the course of processing, how processing operations are planned, how data subjects can exercise their rights, what the procedure is in the event of a personal data breach, and how the Controller ensures the security of the data.

The purpose of the Policy is that, by applying the procedural rules laid down therein and by observing the principles of data processing, the Controller ensures the enforcement of the right to informational self-determination and prevents unauthorised access to personal data and the alteration and disclosure of such data, and to this end lays down the data protection and data security rules governing the processing of personal data.

2. SCOPE OF THE POLICY

PERSONAL SCOPE
The internal data protection and data security policy pursuant to Article 24(2) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter: GDPR), mandatorily applicable in the territory of the EU from 25 May 2018, covers the organisation and all employees of Igloo.hu Kft. (hereinafter: Controller), as well as the data subjects whose personal data the Controller processes.

MATERIAL SCOPE
The scope of the Policy covers the operation of the www.igloo.hu website operated by the Controller, the services available via the website, and all activities of the Controller in the course of which it processes personal data.

TEMPORAL SCOPE
The policy enters into force on 25 May 2020 and remains in force until revoked

3. DEFINITIONS

data protection: the regulation of the processing of personal data in order to enforce the data subject’s right to self-determination;
data carrier: any material containing personal data, produced in any form, using any device, by any procedure;
agent of the controller: the business entity which, on the basis of a mandate/works/intermediary/cooperation contract concluded with the controller, carries out business activities at the controller’s premises in the controller’s interest, in the course of which it processes personal data;
personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or unauthorised access to, personal data transmitted, stored or otherwise processed;
hardware device: any device whose function is to ensure the continuous operation of the IT system, or which serves for security backups or the making of copies, as well as anything that serves, electronically or otherwise, to protect the computer against external interference;
communication device: any technical device or technological procedure capable of transmitting or receiving signals, data and information for one or more receiving persons;
data subjects: the natural persons – in particular, but not exclusively, the clients and employees of the Controller – whose personal data the Controller processes;

4. LEGISLATION APPLIED IN DRAFTING THE POLICY

The Fundamental Law of Hungary (hereinafter: Fundamental Law)
Act CXII of 2011 on the Right to Informational Self-Determination and on Freedom of Information (hereinafter: Infotv.)
Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (hereinafter: Ekertv.)
the information notice of the Hungarian National Authority for Data Protection and Freedom of Information on the basic requirements of processing in the workplace (hereinafter: NAIH notice)
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter: GDPR)
Act CXXXIII of 2005 on the Rules of Personal and Property Protection and Private Investigation (hereinafter: Szvtv.)
the recommendation of the Hungarian National Authority for Data Protection and Freedom of Information on the data protection requirements of prior information (hereinafter: NAIH recommendation)

5. DATA PROTECTION PRINCIPLES

The Controller, already when determining the means of processing and throughout the processing, acts in accordance with the purpose of processing and the principles of processing, takes the technical and organisational measures appropriate to the purpose, and keeps the principle of data minimisation in mind in the course of processing. (data protection by design and by default)

The Controller processes personal data only to the extent and for the period necessary for the achievement of the individual processing purposes, and only such personal data as are indispensable for the achievement of the purpose of processing and suitable for achieving that purpose.

In the course of their activities, the Controller’s employees and agents process personal data exclusively in accordance with the provisions of the relevant legislation.

If the Controller, its employee or its agent becomes aware that personal data processed by them are inaccurate, incomplete or out of date, the Controller shall take action to have them rectified.

The Controller ensures that processing is transparent, that is, that the data subject receives concise, yet easily understandable, easily accessible and clearly worded information about the processing of their personal data.

6. THE DATA PROTECTION SYSTEM OF THE SOLE TRADER

Taking into account the specific characteristics of the company’s operations, the managing director of the Controller has determined the organisation of data protection and the related tasks and powers. The head of each autonomous organisational unit concerned is responsible, within their remit, for ensuring compliance with the provisions of the policy. In the course of their work, the company’s employees ensure that unauthorised persons cannot gain access to personal data, and that the storage and placement of personal data are arranged in such a way that the data cannot be accessed, learnt, altered or destroyed by unauthorised persons.

With regard to data protection, the managing director:
a. is responsible for ensuring the conditions necessary for the exercise of the rights of data subjects set out in the GDPR and the Infotv.;
b. is responsible for ensuring the personnel, material and technical conditions necessary for the protection of the personal data processed by the company;
c. is responsible for remedying any deficiencies or unlawful circumstances identified during an audit of processing, and for initiating and conducting the procedure necessary to establish personal liability;
d. supervises the activities of the data protection officer;
e. monitors compliance with the data protection policies and may order an investigation to that end;
f. keeps the records relating to data protection;
g. issues the company’s data protection policies;
h. monitors changes in the legislation relating to data protection;

Policies, notices

The Controller – in line with the principles of transparency and accountability – has issued the policies and notices listed below:

1. Internal data protection and data security policy;
2. Privacy notice on the processing activities of the www.IGLOO.hu website and the booking system available through it (published on the website);
3. Employment data protection policy;
4. Notice on camera surveillance for employees and visitors
5. Balancing of interests test for camera surveillance

The Controller’s IT staff member has ensured that the privacy notice is easily accessible on the website operated by the Controller by clicking a link on the home page, thereby ensuring that data subjects are informed in advance and ensuring transparency.

Impact assessment, data protection officer

Based on the assessment contained in Annex 1 to this policy, the Controller has determined that, with regard to its processing activities, it is not necessary to carry out the data protection impact assessment detailed in Article 35 of the GDPR.
Under Article 37 of the GDPR, the Controller is not obliged to designate a data protection officer.

Processors

In carrying out its processing activities, the Controller uses the following processors:

Partner offices of the Controller:
(access to the front office database system for the purpose of concluding contracts and access to the integrated enterprise resource planning system for the purpose of performing contracts)