Privacy Policy

Privacy and Data Protection Policy

1. Purpose of the Regulations

1.1. Introduction 

The purpose of this Privacy and Data Protection Policy (hereinafter: Policy) is for the Data Controller towww.dekorastudio.hu  ensure the protection of the rights and legitimate interests of the visitors (hereinafter: Data Subjects) of the website named [...] during web-based data processing activities by the Data Controller, and promote the enforcement of data security during web-based and other data processing activities.

the data protection provisions concerning the data processing operations of the Data Controller related to web-based data processing and the Privacy Policy www.dekorastudio.hu made it available on the website.  

1.2. General Provisions

The Data Controller shall ensure the exercise of the Data Subjects' rights as set forth in these Regulations, provided that it shall act in compliance with the rights of the Data Subjects during the data processing activities listed herein. 

1.3. The Data Controller reserves the right to amend the Policy. 

This Regulation may be amended, in particular, if the necessity of new data processing arises, upon changes in legislation or official practice, or if justified by new security risks or feedback from data subjects.

The modifications, changes the Data Controller www.dekorastudio.hu   are available on its website. 

2. Scope of the Regulations 

Governing laws during web-based data processing include, among others:

  • Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (hereinafter: „Info Act”)
  • Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities (hereinafter: „Grtv.”);
  • Act CVIII of 2001 on Certain Aspects of Electronic Commerce Services and Information Society Services (hereinafter: Eker tv.)
  • Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: „GDPR”);
  • Act CVIII of 2001 on certain aspects of electronic commerce services and information society services;
  • Section 169 of Act C of 2000 on Accounting (retention of accounting documents).

The Regulations material scope applies to the following forms of web-based data processing: 

  • contact, inquiry 
  • submission of a complaint or other legal claim
  • cookie handling 
  • newsletter subscription 
  • Data processing pursuant to the AML Act (customer due diligence, screening for politically exposed person status, ultimate beneficial ownership structure). 

The material scope of this Policy covers all data processing operations carried out by the Data Controller, and thus applies to both electronic and paper-based data processing. 

The Regulations temporal scope From May 8, 2026 until revocation. 

The Regulations personal scope extends

  • to the Data Controller
  • to the Data Controller's customers,
  • to the Data Controller's employees, 
  • to natural and legal persons, or organizations without legal personality, having a contractual relationship with the Data Controller,
  • those Affected Parties with respect to whom this Policy contains provisions
  • to those Data Subjects whose rights or legitimate interests are affected by the data processing under these Regulations,
  • to the visitors of the Data Controller's website,
  • and also to all those who submitted a question or inquiry through the website in connection with the Data Controller's services. 

3. The Data Controller 

3.1. The Data Controller:

natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

3.2. ADATVÉDELMI TISZTVISELŐ kinevezésére Not required.  

  DATA CONTROLLER DATA 
Name:
Registered office:
Contact information:
Company registration number:
Tax number:
Authority ordering registration
BenkEstate Kft.
2112 Veresegyház, Trombita köz 8.
benkezsofia@gmail.com
13 09 206803
25760055-2-13
Court of Registry 

3.3. The Data Processor 

„processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

4. Data transfer and data processors

4.1. We only transfer the data we collect if:

  • you have given your explicit consent pursuant to Article 6(1)(a) of the GDPR, or
  • the disclosure is necessary for the establishment, exercise, or defense of legal claims pursuant to Article 6(1), sentence 1, point (f) of the GDPR, and there is no reason to assume that your rights, or
  • under point (c) of Article 6(1) of the GDPR, we have a legal obligation to disclose your data, or
  • this is legally permitted and necessary pursuant to Article 6(1)(b) of the GDPR for the performance of a contract with you or in order to take steps at your request prior to entering into a contract.

       Social media platforms:

Facebook
https://www.facebook.com/
Instagram
https://www.instagram.com/
YouTube
https://www.youtube.com/
LinkedIn
https://hu.linkedin.com/
TikTok
https://www.tiktok.com/hu-HU/
  DATA PROCESSORS' DATA 
Name:
Availability:
Activity:
New Push / MikroVPS
https://newpush.com/
Web hosting provider
Name:
Availability:
Activity:
Google Workspace
https://mail.google.com/mail/u/0/
Email system
Name:
Activity:
Fábián Éva
Bookkeeping
Name:
Availability:
Activity:
Számlázz.hu
https://www.szamlazz.hu/szamla/main
Billing
Name:
Availability:
Activity:
WordPress
https://wordpress.com/
System
Name:
Availability:
Activity:
KGN Webdesign / Nóra Kémeri Greguss
hello@kgnwebdesign.hu
Web Development, Online Marketing

Part of the data processing is carried out by our service providers. In addition to the service providers mentioned in this Privacy Policy, these may include, in particular, data centers hosting our website, databases, and applications, software providers supplying and developing the appropriate applications for us, IT service providers maintaining our systems, agencies, market research companies, group companies, payment service providers, newsletter distributors, logistics service providers, and consulting firms.

We reserve the right to change our data processors, and the registry of suppliers belonging to our subcontractor network is handled confidentially based on the legitimate interest of the Data Controller; the list of our contracting partners is handled as an internal business secret. If you would like to receive more detailed information regarding the relevant legitimate interest assessment, please contact us at the following e-mail address: benkezsofia@gmail.com

The Data Controller shall only engage data processors that provide sufficient guarantees to protect the rights of data subjects and implement appropriate technical and organizational measures to ensure full compliance with data protection regulations. To this end, they shall guarantee the framework of their cooperation through data protection agreements, pursuant to which the Data Controller ensures that personal data are processed solely on the basis of the Data Controller's written instructions, that persons authorized to process the personal data undertake an obligation of confidentiality, and that the data processor assists the Data Controller to the maximum extent possible through appropriate technical and organizational measures in fulfilling its obligations. Accordingly, data processing must not result in the misuse of data, must not constitute unlawful conduct, and must not infringe upon the rights of data subjects.

4.3 Online presence in social networks

We are present on social media platforms to communicate with customers and prospects, among others, and to inform them about our products, services, and promotions.

User data is generally processed by the respective social networks for market research and advertising purposes. In this way, usage profiles can be created based on the users' interests. For this purpose, cookies and other identifiers are stored on the users' computers. Based on these usage profiles, various advertisements are displayed to visitors according to their personal preferences and interests.

As part of operating our online presences, we may have access to information such as statistics regarding the use of our online presences provided by social networks. These statistics are aggregated and may include, in particular, demographic information as well as data relating to interactions with our online presences and the posts and content distributed through them.

The legal basis for data processing is Article 6(1)(f) of the GDPR, which is based on our legitimate interest in providing effective information to users and communicating with them, in order to stay in touch with our customers and inform them.

The links below provide further information on the specific data processing and how to exercise data subject rights.

5. Purpose and legal basis of data processing 

The Data Controller processes the following personal data on the following legal bases:

personal data: any information relating to an identified or identifiable natural person („data subject”). 

Nature of AKMANAGED DATA AK'S GOALAK JOGALAPRETENTION PERIODAFFECTED / RECIPIENTS
  Contact via website 
Request for a quote 
Name, email address, phone number, message text   Management and recording of customer inquiries and requests consent pursuant to Article 6(1)(a) of the GDPRUntil the withdrawal of consent or until the response to the inquiry is sent to the data subject Authorized contact persons 
     Real estate agency, real estate sales service  Data required for contract conclusion: last name, first name, address, e-mail, phone number. Data required for billing: company name, registered office, company registration number, tax number, e-mail address.,  use of service performance of a contract pursuant to Article 6(1)(b) of the GDPR 5 years following the fulfillment of the service or the termination of the contract Persons authorized to liaise with clients 
  Complaint, enforcement of legal claim Name, email address, home address (optional), phone number (optional)  Successful adjudication of a complaint or legal claim     legal obligation under Article 6(1)(c) of the GDPR In the event of a successful remedy of a complaint or legal claim, or the enforcement of a legal claim, the retention period is the current year + 5 years pursuant to the Consumer Protection Act. Persons involved in handling complaints 
  Milk treatment They do not contain any data suitable for user identification. Personalized content, improving user experience  consent under Article 6(1)(a) of the GDPR   Until deleted in the browser Website operator, and third party 
  Milk treatmentThey do not contain user-identifiable data (strictly necessary cookies)Strictly necessary for the website to function controller's legitimate interest under Article 6(1)(f) of the GDPR   Until deleted in the browserWebsite operator, and third party
  Accounting documents  Name and address of the service recipient Fulfillment of the obligation to retain invoices and receipts legal obligation under Article 6(1)(c) of the GDPR 8 years  Person responsible for handling vouchers 
 Scope of processed dataLegal basis and purposeRetention period
    
   Property ownername, place and date of birth, mother's birth name, address, in the absence thereof, place of residence, phone number, email address, data provided regarding the propertyIntention to buy or sell real estate, granting a commission to a real estate agency, performance of the contract (GDPR Article 6(1)(b))5 years from the termination of the contract
   Viewername, place and date of birth, mother's birth name, address, phone number, email address, data necessary for the exact identification of the viewed propertyPerformance of a contract (Article 6(1)(b) GDPR)5 years from the termination of the contract
   Real estate findername, address, phone number, email address, and data provided by the Data Subject regarding the property soughtPurchase, lease, Performance of a contract, (Article 6(1)(b) GDPR)5 years from the termination of the contract
      Customer screened based on the AML Actfamily name and first name, birth family name and first name, citizenship, place and date of birth, mother's birth name, residential address, or in the absence thereof, place of stay, type, number and copy of identification document, declaration of politically exposed person, declaration indicating the source of the purchase priceAct LIII of 2017 on the Prevention and Combating of Money Laundering and Terrorist Financing (AML Act), in relation to the legal obligation under Article 6(1)(c) of the GDPR: risk assessment, sanctions list screening, and customer due diligencePersonal data for 8 years from the date of recording. 
   Tenderername, place and date of birth, mother's birth name, residential address, in the absence thereof, place of stay, telephone number, e-mail address, bid amount and payment conditionsData processing required for steps prior to concluding a contract (Article 6(1)(b) of the GDPR)5 years from the termination of the contract
    In case of a valuationname, place and date of birth, mother's birth name, address, in the absence thereof, place of residence, phone number, email address, data provided regarding the propertyReal estate appraisal, Performance of the contract, (Article 6(1)(b) of the GDPR)5 years from the termination of the contract,
   Compliance with Accounting RequirementsPersonal data contained in accounting documents supporting bookkeeping entriesArticle 6(1)(c) of the GDPR, compliance with a legal obligation (Article 6(1)(c) of the GDPR), and Section 169 of Act C of 2000 on Accounting.The data controller is required to retain personal data related to the fulfillment of its record-keeping obligation for eight years

5.1. Principles of Data Processing 

Data Controller In its data processing activities, it is required to accept and protect the data processing principles set forth in Article 5 of the General Data Protection Regulation, which are as follows: 

Personal data must be processed lawfully, fairly, and in a manner that is transparent to the data subject (“lawfulness, fairness, and transparency”);

Personal data may be collected only for specific, explicit, and legitimate purposes, and may not be processed in a manner incompatible with those purposes; (“purpose limitation”);

Data processing must be appropriate and relevant to the purposes for which it is carried out and must be limited to what is necessary (“data minimization”);

The personal data being processed must be accurate and, where necessary, kept up to date; all reasonable measures must be taken to ensure that personal data that are inaccurate in light of the purposes of the processing are erased or rectified without delay (“accuracy”);

Personal data must be stored in a form that allows for the identification of data subjects only for as long as is necessary to achieve the purpose, taking into account technical and organizational measures (“limited retention”);

Personal data must be processed in such a way that the security of the data is ensured through technical and organizational measures, including protection against unauthorized or unlawful processing, accidental loss, destruction, or damage (“integrity and confidentiality”).

With regard to partnerships established with data processors, the Data Controller considers the data processing principles set forth in this article to be binding on the Data Processor as well with respect to the data transferred for processing. The Data Controller safeguards the personal data it processes in this manner with due responsibility and special care. The Data Controller maintains internal records regarding the processing of personal data.

6. Conditions for the Applicability of Automated Decision-Making

The purpose of automated decision-making is to optimize and accelerate processes and to provide new opportunities in the course of the Data Controller’s various activities, so that interested customers can receive the best possible solution proposal or diagnosis, or enjoy the best possible service. The results of automated decision-making are reviewed by the Data Controller’s staff. The data subject has the right to request human intervention by the data controller regarding automated decision-making, to express his or her point of view, and to object to the decision.

The data subject has the right not to be subject to a decision based solely on automated processing—including profiling—that produces legal effects concerning him or her or similarly significantly affects him or her. As a general rule, automated decisions may not be based on the special categories of personal data referred to in Article 9(1), unless the customer expressly consents or such processing is provided for by Union or Member State law.

The data controller considers that the data processing is proportionate to the intended purpose, respects the essence of the right to the protection of personal data, and provides for appropriate and specific measures to safeguard the fundamental rights and interests of the data subject.

The data controller does not use automated decision-making processes

7. COOKIES USED

A cookie is a small text file containing information that the Website transmits to a small file stored on the hard drive of the user’s computer or mobile device. These cookies facilitate communication between the website’s server and the user’s web browser; they are stored on the user’s computer and remain there for a predetermined period of time. A cookie typically contains the name of the domain from which it originated, its expiration date, and a randomly generated number (value). Some cookies do not contain personal information and cannot be used to identify individual users; however, others contain a unique identifier—a secret, randomly generated sequence of numbers—that is stored on your device, thereby enabling your identification. The duration of each cookie is specified in the relevant description for that cookie.

It is important to note that the cookies used on our website change dynamically; we use different cookies with each visit. You can view the cookies currently in use by clicking the lock icon before the URL https://, then selecting the “Cookies” tab, and finally clicking the “Cookies” tab within that section to view them in the drop-down menu. Here, you also have the option to remove or disable individual cookies.  www.dekorastudio.hu

8. Data Subject Rights 

The data subject has the following rights in connection with the data processing described above: 

The data subject has the right to access and review the personal data collected, and has the right to exercise this right at reasonable intervals to verify the lawfulness of the data processing; in particular, the data subject is entitled to the rights listed in the following table, upon request:

Data Subject Rights Regarding the Processing of Personal Data
The Right to Information and Access to Information
Modifying Access to Personal Information
Right to Correction
Right to Erasure, Right to Be Forgotten
Restriction of Data Processing
The Right to Object and the Right to File a Complaint Regarding the Processing of Personal Data

Within 30 days of the submission of the request, the Data Controller shall provide the data subject with written information regarding the request, including the data being processed, their source, the purpose of the data processing, its legal basis, and its duration, as well as the legal basis for any data transfers and the recipients of such transfers. 

If justified by the complexity of the request or other objective circumstances, the above deadline may be extended once, by no more than 60 days, in which case the Data Controller shall notify the requester in writing. 

If the Data Controller fails to meet the above deadline, the data subject may file a lawsuit within 30 days of the date the decision was communicated or the last day of the deadline.

The data subject has the following rights with respect to the rights to which he or she is entitled: 

  • you may request information,
  • You may request the correction, modification, or supplementation of your personal data that we process, 
  • You may object to the processing of your data and request that your data be deleted or blocked (except in cases of mandatory data processing), 
  • may seek legal remedy in court, 
  • You may file a complaint with the supervisory authority or initiate proceedings https://naih.hu/panaszuegyintezes-rendje.html

Contact information for the supervisory authority: 

National Authority for Data Protection and Freedom of Information, http://naih.hu, phone: +36 (1) 391-1400, adress: 1363 Budapest, Pf.: 9., 1055  Budapest, Falk Miksa utca 9-11., e-mail: ugyfelszolgalat@naih.hu). 

The rights of data subjects are set forth in a separate notice, which the Data Controller makes available to data subjects.

9. Data Security Measures

The Data Controller ensures that data security measures in accordance with the General Data Protection Regulation (GDPR) are implemented on the website and during the processing of personal data. In this context, the Data Controller takes the necessary technical and organizational measures to ensure the adequate protection of electronically stored personal data.  

In this context, it adopts, implements, maintains up to date, and regularly reviews all technical and organizational measures and procedural rules that ensure the security of the personal data it processes, and takes all reasonable steps to prevent the destruction, unauthorized use, or alteration of personal data, and ensures that unauthorized persons cannot access, disclose, transmit, modify, or delete the personal data being processed.

The Data Controller shall provide data subjects with the necessary information regarding data security so that they possess the necessary knowledge of data protection, and shall ensure that its agents and employees act in compliance with data security requirements in the course of their duties. 

The data controller continuously monitors advances in science and technology in order to apply the available technical, technological, and organizational solutions, as well as solutions that are commensurate with the level of protection required by its data processing activities.

To prevent and manage data protection incidents, the Data Controller implements measures to raise data protection awareness and monitors compliance with them. 

When operating IT systems, the Data Controller uses the necessary access control, internal organizational, and technical measures to ensure that the personal data of data subjects does not fall into the hands of unauthorized persons and that unauthorized persons cannot delete, export, or modify the data from the system. 

The Data Controller has an Incident Management Policy in place and maintains an Incident Log of any data protection incidents; if necessary, it notifies the data subject of any incidents that occur. 

Budapest, 2026-05-08

Privacy Notice (Customer Service)

1. The Data Controller

  DATA CONTROLLER DATA 
Name:
Registered office:
Contact information:
Registration number:
Tax number:
Authority ordering registration
BenkEstate Kft.
2112 Veresegyház, Trombita köz 8.
benkezsofia@gmail.com
13 09 206803
25760055-2-13
Court of Registry 

2. Purpose and Legal Basis of Data Processing

Goal: As part of its customer service activities, the Data Controller handles and responds to customer inquiries and works to improve customer satisfaction. 

You can contact Customer Service by phone or in person.

Legal basis: Performance of a contract pursuant to Article 6(1)(b) of the General Data Protection Regulation. 

3. Scope of Processed Data

Types of data processed:

  • Name
  • Email address
  • Phone number
  • Content of a Customer Service Inquiry
  • Related posts

4. Data Retention Period

We will delete the data after the customer service issue has been successfully resolved, but no later than 30 days thereafter. After that, the data will be permanently deleted.

5. Data Processors and Data Transfers

We use the data solely for the purpose of providing customer service and do not share it with third parties. 

  • We do not use a data processor.
  • We do not transfer data outside the European Union.

6. Rights of Data Subjects

You have certain rights regarding the processing of your personal data, which are outlined in a separate notice.

7. Right to File a Complaint

If you wish to exercise your rights as a data subject or file a complaint, please follow the steps below: 

We will inform you of the actions taken in response to your complaint or request, submitted via the contact information provided in Section 8, without undue delay, but in any event within one month of receipt of the request. If necessary, taking into account the complexity of the request and the number of requests, this deadline may be extended by an additional two months. We will notify you of any extension of the deadline, specifying the reasons for the delay, within one month of receiving your request. If you submitted your request electronically, we will provide this notification electronically whenever possible, unless you request otherwise.

If we do not take action in response to your request, we will inform you without delay—but no later than one month from the date we received your request—of the reasons for not taking action, as well as of the fact that you may file a complaint with a supervisory authority and seek judicial remedy.

8. Contact

If you have any questions or requests regarding data processing, please feel free to contact us: 

Contact us at: www.dekorastudio.hu

E-mail address: benkezsofia@gmail.com

Phone number: 36204700086

Data Subject Information Notice and Website, and Data Processing in Connection with Services Provided by the Data Controller

www.dekorastudio.hu   Website operator:

  DATA CONTROLLER DATA 
Name:
Registered office:
Contact information:
Registration number:
Tax number:
Authority ordering registration
BenkEstate Kft.
2112 Veresegyház, Trombita köz 8.
benkezsofia@gmail.com
13 09 206803
25760055-2-13
Court of Registry

The purpose of this Privacy Notice is to ensure that both visitors to the above website and users of the various services provided by the Data Controller (e.g., real estate sales, rentals, property searches, energy performance certificate issuance, interior design services, real estate virtual tours, customer service) (hereinafter referred to as “data subjects”) of the various services provided by the Data Controller (e.g., real estate sales, rentals, property searches, energy performance certificate preparation, interior design services, real estate web tours, and customer service) regarding the rights to which they are entitled both during and prior to the use of such services. 

1. Data Subject Rights 

When visiting the above website and using the various services provided by the Data Controller as listed in Section 1, data subjects are entitled to the following rights: 

Data subjects include anyone who visits or uses the website operated by the Data Controller mentioned above, as well as anyone who is interested in or uses the listed services provided by the Data Controller. 

a) The data subject's right of access

The data subject has the right to receive confirmation from the Data Controller as to whether his or her personal data are being processed. If such processing is taking place, the data subject has the right to be informed of the following:

  • Purpose of data processing
  • Categories of personal data concerned
  • the group of recipients to whom the Data Controller will disclose personal data
  • the planned duration of the storage of personal data, and the criteria used to determine that duration
  • the data subject’s right to request that the Data Controller rectify, erase, or restrict the processing of personal data concerning him or her, and to object to the processing of such personal data
  • the right to file a complaint with a supervisory authority
  • if the data were not collected from the data subject, the available information regarding its source.

The Data Controller shall provide the data subject with a copy of the personal data subject to processing. For any additional copies beyond this, the Data Controller is entitled to charge a reasonable fee based on administrative costs. If the data subject submitted the request electronically, the response must also be provided by a widely used electronic means, unless the data subject requests otherwise.

The data subject’s right of access and right to obtain a copy may be exercised only in a manner that does not adversely affect the rights and freedoms of others. The period covered by a request for a copy is always limited to a reasonable duration of the relevant period. 

b) The data subject's right to rectification and to have data completed 

The data subject has the right to request, without undue delay, the correction of inaccurate personal data concerning him or her.

c) The data subject’s right to erasure (right to be forgotten)

The data subject has the right to request that the Data Controller erase personal data concerning him or her without undue delay if any of the following grounds apply:

  • the personal data is no longer necessary for the purpose for which the Data Controller collected it or otherwise processed it
  • the data subject objects to the processing of the data, and there is no legitimate reason for the processing that takes precedence 
  • the personal data was processed unlawfully
  • Personal data must be erased to comply with a Member State obligation prescribed by Union or Member State law applicable to the Data Controller.

The above provisions do not apply if data processing is necessary, including, but not limited to:

  • for the purpose of complying with an obligation under Union or Member State law applicable to the Data Controller that requires the processing of personal data
  • to assert, enforce, and defend legal claims.

d) The right to restrict data processing 

The data subject has the right to request that the Data Controller restrict data processing if any of the following conditions are met:

  • if the data subject disputes the accuracy of the personal data, in which case for the period during which the Data Controller verifies the accuracy of the personal data
  • the processing is unlawful, and the data subject objects to the erasure of the data and requests, instead, that its use be restricted
  • the Data Controller no longer needs the personal data, but the data subject considers it necessary for the establishment, exercise, or defense of legal claims
  • the data subject objects to the processing; in this case, the restriction applies for as long as it has not been determined that the Data Controller’s legitimate grounds take precedence over the data subject’s legitimate grounds

If the processing of personal data is subject to restriction, such personal data may be processed—with the exception of storage—only with the data subject’s consent, or for the purpose of asserting, exercising, or defending legal claims, or for the purpose of protecting the rights of another natural or legal person, or for reasons of substantial public interest of the Union or of a Member State.

The Data Controller will notify the data subject of the lifting of the restriction.

e) The obligation to notify regarding the rectification or erasure of personal data, or the restriction of data processing

The Data Controller shall notify all recipients to whom the personal data has been disclosed of any rectification, erasure, or restriction of processing, unless this proves impossible or involves a disproportionate effort. At the request of the data subject, the Data Controller shall provide information about these recipients.

f) The right to protest 

The data subject has the right to object at any time, on grounds relating to his or her particular situation, to the processing of his or her personal data based on legitimate interests. In this case, the Data Controller may no longer process the personal data, unless the Data Controllers demonstrate that the processing is justified by compelling legitimate grounds that override the interests, rights, and freedoms of the data subject, or that are related to the establishment, exercise, or defense of legal claims.

g) Right to data portability

If the processing of personal data is based on Article 6(1)(b) of the General Data Protection Regulation, the data subject has the right to receive the personal data concerning him or her, which he or she has provided to a data controller, in a structured, commonly used, and machine-readable format, and has the right to transmit those data to another controller without hindrance from the controller to whom the personal data were provided. 

i) The right to file a complaint with the supervisory authority 

The data subject has the right to lodge a complaint with a supervisory authority—in particular in the Member State of his or her habitual residence, place of work, or the place where the alleged infringement occurred—if the data subject believes that the processing of his or her personal data violates the provisions of the General Data Protection Regulation.

In Hungary, the National Authority for Data Protection and Freedom of Information (NAIH) serves as the supervisory authority. Contact information: 1055 Budapest, Falk Miksa u. 9-11; mailing address: 1363 Budapest, P.O. Box 9; phone: +36-1-391-1400; fax: +36-1-391-1410; email: ugyfelszolgalat@naih.hu

(j) The right to an effective judicial remedy against the supervisory authority

 The data subject has the right to an effective judicial remedy against a legally binding decision by the supervisory authority concerning the data subject. 

The data subject is entitled to an effective judicial remedy if the competent supervisory authority fails to address the complaint or fails to inform the data subject within three months of the progress or outcome of the proceedings regarding the complaint that was filed.

Proceedings against the supervisory authority must be brought before the courts of the Member State in which the supervisory authority has its seat. 

(k) The right to an effective judicial remedy against the Data Controller or the Data Processor

Any affected individual is entitled to an effective judicial remedy if he or she believes that his or her rights under the General Data Protection Regulation have been infringed as a result of the processing of his or her personal data in a manner that does not comply with the Regulation.

Proceedings against the Data Controller or Data Processor must be brought before the courts of the Member State in which the Data Controller or Data Processor has its place of business. Proceedings may also be brought before the courts of the Member State where the data subject has his or her habitual residence. The data subject may, at his or her discretion, bring the action before the court having jurisdiction over his or her place of residence or habitual residence. Contact information for the competent court is available at the www.birosag.hu You can find more information on the website. 

Budapest, 2026-05-08