General Data Protection Notice
1. General Provisions
The purpose of this General Data Protection Notice (hereinafter: Notice) is to ensure that GYÁLI ÚT 3B Ingatlanhasznosító Korlátolt Felelősségű Társaság (registered office: 1097 Budapest, Albert Flórián út 3, Building B; registration authority: Company Registry of the Metropolitan Court; company registration number: Cg. 01-09-884054; tax number: 14000807-2-43; hereinafter: Controller) fulfils its obligation of prior information in connection with the processing of personal data, as required by Articles 13 and 14 of Regulation (EU) 2016/679 (General Data Protection Regulation), with the Controller providing further detailed information on individual data processing activities as set out in this Notice.
In compiling this data protection notice, the Controller took particular account of the following legislation:
- Regulation (EU) 2016/679 on the General Data Protection Regulation (GDPR),
- Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (Info Act),
- Act V of 2013 on the Civil Code (Civil Code),
- Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (E-Commerce Act),
- Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions of Commercial Advertising Activities (Advertising Act).
Data processing operations relating to the real property available on the Controller’s website are carried out by the Controller. In order for data subjects who decide to make contact and/or request a quotation to receive all information and/or offers relevant to them, the Controller processes the personal data provided during such contact and/or request for quotation.
2. Definitions
Personal Data
Any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Data Processing
Any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Controller
A natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Data Subject
Any identified or — directly or indirectly — identifiable natural person.
Recipient
A natural or legal person, public authority, agency or another body to which the personal data are disclosed, whether a third party or not.
Data Transfer
Making personal data available to a specified third party.
Processor
Natural and legal persons who, on the basis of a contract concluded in writing with the Controller or another legal act, process personal data relating to data subjects on behalf of the Controller. Processors do not make independent decisions with respect to personal data and are authorised to act exclusively on the basis of a contract or other legal act concluded with the Controller and the instructions received.
3. Data Processing Principles
The Controller undertakes to fully comply with and enforce among its employees, partners and associates the principles set out below, while ensuring the highest level of data protection and information security standards. For the Controller, operating in compliance with the principles set out in this section is a fundamental requirement that permeates all data processing activities.
3.1 Lawfulness, Fairness and Transparency
The Controller processes data exclusively in a lawful and fair manner that is transparent and accessible to the data subjects.
Accordingly, the Controller’s employees are required to pay particular attention to ensuring that data processing activities always have a lawful legal basis (e.g. the data subject’s consent, performance of a contract, compliance with a legal obligation, the legitimate interest of the Controller), and that they conform to the principle of fair processing — for example, the Controller does not use hidden camera surveillance or any data processing that could be capable of deceiving data subjects.
The Controller pays particular attention to providing transparent information to each data subject regarding the processing of their personal data.
3.2 Purpose Limitation
The Controller respects that personal data may only be processed for specified, explicit and legitimate purposes, and that personal data must not be processed in a manner incompatible with those purposes. The Controller holds that the specific purpose of any data processing must above all be explicitly formulated and lawful, and determined already at the time of collection of personal data.
The Controller undertakes to regularly review data processing activities and, if it establishes that a particular data processing activity no longer has a purpose, to immediately take steps to discontinue it. The Controller does not collect (store) personal data in a stockpiling manner for future use, and once the purpose of processing ceases to exist, it takes steps to discontinue the processing.
3.3 Data Minimisation
The Controller processes only such personal data that is adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed. The Controller therefore requires its employees to always process (store, collect, record, etc.) only as much data as is necessary for the achievement of the specific purpose.
3.4 Accuracy
The Controller takes all reasonable steps to ensure that only accurate and up-to-date personal data is processed, and that inaccurate data is rectified or erased without delay.
The Controller undertakes to take all necessary measures to ensure that employees pay particular attention to ensuring that the personal data files they process contain only accurate and correct data. To this end, employees are required to regularly reconcile data with the individuals identifiable in the data files.
The Controller undertakes to take the necessary measures to update the relevant records and databases when a data subject notifies a change in their personal data, or when an employee is informed of a change, paying particular attention to any requirements set out in any applicable internal policy.
3.5 Storage Limitation
The Controller processes (stores) personal data only for as long as is necessary for the purpose, unless a longer retention period is required by applicable legislation. Following achievement of the processing purpose, the Controller immediately takes steps to discontinue the processing of personal data (erasure or anonymisation of data).
The Controller specifies in this Notice and in the descriptions of individual data processing activities forming Annex 1 to this Notice the duration of storage of personal data for the benefit of data subjects; where this is not possible, the Controller provides information on the criteria for determining such duration.
3.6 Integrity and Confidentiality
By applying appropriate technical and organisational measures, the Controller ensures appropriate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.
Having regard to the state of the art, the costs of implementation, the nature, scope, context and purposes of individual data processing activities, and the risks of varying likelihood and severity to the rights and freedoms of natural persons, the Controller undertakes to always implement measures designed, on the one hand, to give effect to data protection principles and, on the other hand, to integrate the guarantees necessary for the protection of legislative requirements and the rights of data subjects into the data processing process from the very outset of design.
3.7 Accountability
The Controller accepts responsibility for compliance with the above principles and for demonstrating such compliance. The Controller undertakes to comply with the fundamental principles and provisions governing the processing of personal data of natural persons who come into contact with it, with the aim of protecting the privacy and rights of natural persons in accordance with the applicable legal provisions and regulatory positions.
The Controller also undertakes to comply in all respects with the data protection provisions of applicable legislation, including in particular the requirements of the laws applicable to its operations and data processing activities. The Controller is particularly committed to ensuring that data subjects are able to properly exercise their rights and receive the necessary information to do so.
4. Legal Bases and Purposes of Data Processing
The legal basis for data processing determines the legal authorisation under which personal data may be processed. The Controller applies one of the legal bases set out in Article 6 of the GDPR in respect of each data processing activity, which, having regard to the scope of its activities, may be as follows:
4.1 Consent
The consent of the data subject — given on the basis of prior information, freely, specifically, unambiguously and in an affirmative manner — to the processing of their personal data (Article 6(1)(a) GDPR).
Where data processing serves more than one purpose simultaneously, the Controller requests the data subject’s consent separately for each data processing purpose. Example: data processing in connection with targeted outreach and direct marketing activities.
4.2 Performance of a Contract
Processing necessary for the performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract (Article 6(1)(b) GDPR).
Data processed on this legal basis is typically provided during the preparation of the contract or arises during its performance. Example: preparation, conclusion and performance of lease agreements.
4.3 Compliance with a Legal Obligation
Processing necessary for compliance with a legal obligation to which the Controller is subject (Article 6(1)(c) GDPR).
In such cases, the scope of data to be processed, the purpose and conditions of processing, accessibility of the data, the duration of processing, and the identity of the Controller are determined by the applicable legislation. Example: obligation to retain accounting documents under Act C of 2000 on Accounting.
4.4 Legitimate Interest
The legitimate interests of the Controller or of a third party (Article 6(1)(f) GDPR).
This legal basis may only be applied where processing is necessary for the purposes of the legitimate interests pursued by the Controller, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject. To determine whether the interference with the data subject’s privacy or the restriction of their rights to the protection of personal data is proportionate, the Controller carries out a legitimate interest assessment test in every case, which it makes available upon request. Example: operation of a security camera system.
The Controller’s data processing-related services cover the letting and operation of office properties and ancillary services required in connection therewith. The specific data processing purposes are determined in order to provide these services.
5. Categories of Personal Data Processed
The personal data processed by the Controller in relation to data subjects is determined by the nature of the relationship with the data subject (e.g. the existence of a contractual relationship) and the purpose of the processing.
Accordingly, the scope of personal data processed:
- in the case of processing based on or related to a contract, is determined by the subject matter of the contract and the personal data required for its performance;
- in the case of mandatory processing, is determined by legislation;
- must not, on the Controller’s decision, exceed the extent necessary to achieve the intended purpose (see the principle of data minimisation).
6. Data Storage
The Controller stores personal data with Rackhost Zrt., 1132 Budapest, Victor Hugo út 18-22.
6.1 Duration of Data Processing
As a general rule, the duration of each data processing activity is aligned with the applicable legal basis.
- In the case of processing based on consent, the Controller processes personal data until the data subject withdraws their consent or, in the absence thereof, for a period reasonably derived from the purpose of processing.
- In the case of the legal basis of performance of a contract, the Controller actively processes personal data until the termination of the contractual relationship in question and thereafter stores the data for a period of 8 years from the date of termination.
- In the case of mandatory processing, data processing takes place until the expiry of the deadline prescribed by the relevant legislation.
- The retention period for personal data processed by the Controller on the basis of legitimate interest is aligned with the existence of the legitimate interest and the limitation period for enforcing claims related to that interest.
Following the expiry of the indicated period, personal data shall be erased unless a request by the data subject or an authority inquiry/decision to the contrary is received.
7. Recipients of Data and Data Transfers
Primary access to the data is granted to the Controller and those of its employees whose duties require them to participate in the conclusion of contracts and provision of services, and to carry out tasks relating to client relations.
In the case of data transfer, personal data available to the Controller regarding the data subject is transferred to one or more recipients (natural or legal persons, public authorities, agencies or any other bodies).
The recipient of a data transfer may be a third party other than the Controller; a prerequisite for data transfer is that the Controller has an appropriate legal basis for the transfer, meaning that data may be transferred on the basis of the data subject’s consent, for compliance with a legal obligation, or pursuant to one of the other legal bases set out in Article 6(1) of the GDPR.
Where the recipient of the data transfer is located in a third country, the Controller ensures an adequate level of protection within the meaning of Article 44 of the GDPR by applying the safeguards set out in Chapter V of the GDPR, and provides detailed information in the relevant Annex 1 to this Notice.
8. Data Processing (Use of Processors)
The Controller may engage a processor for the purposes of providing its services.
Recipients of data transfers also include processors engaged by the Controller. Where processing is carried out on behalf of the Controller by another party, the Controller uses only processors that provide sufficient guarantees to implement appropriate technical and organisational measures in a manner that will meet the requirements of the GDPR and ensure the protection of the rights of data subjects. Data processing carried out by the processor is governed by the Controller in the contract or other legal act concluded with the processor (e.g. internal policy).
The names of the processors engaged in the course of each data processing activity and the totality of data processing operations carried out by them are set out in full in the notice providing information on the respective data processing activity.
The Controller regularly engages the following processors: Rackhost Zrt., 1132 Budapest, Victor Hugo út 18-22; Phlegon Kft., 1097 Budapest, Albert Flórián út 3/b.
The processor may engage another processor in accordance with the Controller’s instructions. The processor may not make substantive decisions regarding data processing, may process personal data that comes to its knowledge exclusively in accordance with the Controller’s instructions, may not carry out processing for its own purposes, and is required to store and retain personal data in accordance with the Controller’s instructions.
9. Data Security
The Controller designs and implements data processing operations in a manner that ensures the protection of the data subject’s privacy in the application of the GDPR and other rules relating to data processing.
The Controller ensures the security of data and takes the technical and organisational measures and establishes the procedural rules necessary for the enforcement of the GDPR and other data protection rules.
Data is protected by appropriate measures, in particular against unauthorised access, alteration, transfer, disclosure, erasure or destruction, as well as against accidental destruction and damage, and against inaccessibility resulting from changes in the technology used.
In the interest of the security of personal data, the Controller has introduced internal organisational and state-of-the-art technical measures, in particular the following:
- Access authorisation to personal data is determined on the basis of internal authorisation procedures, and only those employees who require access have access, and only to the data they need.
- Access to systems and devices containing or storing personal data is available only through authentication by user name and password.
- During work sessions, the use of screen savers protects against unauthorised access to data on unused computers; these require a password after a specified period of inactivity and can be locked manually.
- Internal rules on password security (length, complexity and frequency of password changes) and the use of passwords are applied.
- The use of firewalls prevents unauthorised access from the internet.
- Access to data processing systems and workstations is logged.
- Remote access via (SSL) VPN gateway is logged.
- The granting/modification of access authorisations is logged.
10. Rights of Data Subjects and Remedies
10.1 Rights in Connection with Data Processing
The data subject may request from or exercise the following rights with the Controller:
- request information regarding the processing of their personal data (prior to and during the course of processing);
- request access to their personal data (the making available of personal data by the Controller);
- request the rectification or completion of their personal data;
- request the erasure or restriction (blocking) of their personal data — except in the case of mandatory processing;
- exercise their right to data portability;
- object to the processing of their personal data;
- withdraw their consent.
| Right to prior information | Right of access | Right to rectification | Right to erasure | Right to restriction | Right to data portability | Right to object | Withdrawal of consent | |
|---|---|---|---|---|---|---|---|---|
| Consent | ✔ | ✔ | ✔ | ✔ | ✔ | ✔ | ✖ | ✔ |
| Performance of contract / pre-contractual steps | ✔ | ✔ | ✔ | ✔ | ✔ | ✔ | ✖ | ✖ |
| Legal obligation | ✔ | ✔ | ✔ | ✖ | ✔ | ✖ | ✖ | ✖ |
| Vital interests | ✔ | ✔ | ✔ | ✔ | ✔ | ✖ | ✖ | ✖ |
| Public task / public authority | ✔ | ✔ | ✔ | ✖ | ✔ | ✖ | ✔ | ✖ |
| Legitimate interest | ✔ | ✔ | ✔ | ✔ | ✔ | ✖ | ✔ | ✖ |
10.2 Right to Prior Information (Articles 13–14 GDPR)
The data subject may request in writing from the Controller information on what personal data is processed about them, on what legal basis, for what purpose, from what source, for how long, whether a processor is engaged and if so the name, address and processing-related activities of that processor, to whom, when, on what legal basis and to what personal data the Controller has granted access or to whom it has transferred personal data, and the circumstances and effects of any potential data protection incident and the measures taken to remedy it. The Controller fulfils the data subject’s request in writing to the contact details provided by the data subject within at most one month.
10.3 Right of Access (Article 15 GDPR)
The data subject is entitled to obtain from the Controller confirmation as to whether or not personal data concerning them is being processed, and, where that is the case, access to the personal data. The Controller provides the data subject with a copy of the personal data undergoing processing — unless this is precluded by another legal obstacle.
10.4 Right to Rectification and Completion (Article 16 GDPR)
The data subject may request in writing that the Controller modify any of their personal data (e.g. they may change their contact details or request that any inaccurate personal data processed by the Controller be rectified). Taking into account the purposes of processing, the data subject is entitled to request completion of any incomplete personal data processed by the Controller. The Controller fulfils the data subject’s request within at most one month and notifies the data subject thereof in writing to the contact details provided by the data subject.
10.5 Right to Erasure (Right to be Forgotten) (Article 17 GDPR)
The data subject may request in writing that the Controller erase their personal data if the processing is based on the data subject’s consent. Where the processing of the data subject’s personal data is based on a legal basis other than consent, the Controller is entitled to refuse the erasure request and to continue processing the data for the mandatory retention period. In the absence of a mandatory retention obligation, the Controller fulfils the data subject’s request within at most one month and notifies the data subject thereof in writing to the contact details provided by the data subject. The Controller is not entitled to erase the data where a statutory retention period (e.g. 8 years applicable under accounting rules) overrides the erasure request.
10.6 Right to Restriction (Blocking) of Processing (Article 18 GDPR)
The data subject may request in writing that the Controller restrict (block) their personal data (by clearly marking the restricted nature of the processing and ensuring separate storage from other data). The restriction remains in effect for as long as the reason indicated by the data subject necessitates the storage of the data. The data subject may request restriction, for example, where they believe that the data was processed unlawfully by the Controller, but that the data must not be erased by the Controller for the purposes of judicial or regulatory proceedings initiated by the data subject.
10.7 Right to Data Portability (Article 20 GDPR)
The data subject may request in writing that the personal data concerning them which they have provided to the Controller be provided in a structured, commonly used and machine-readable format, and the data subject is entitled to request the transfer of such data to another controller, provided that:
-
- the processing is based on consent pursuant to Article 6(1)(a) GDPR or Article 9(2)(a) GDPR, or
- on a contract pursuant to Article 6(1)(b) GDPR; and
10.8 Right to Object (Article 21 GDPR)
The data subject may object in writing to the processing of their personal data based on Article 6(1)(f) GDPR, necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, including profiling based on those provisions. In such case, the Controller shall no longer process the personal data unless the Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.
11. Remedies
11.1 Contacting the Controller
The data subject, if they have any questions regarding data processed by the Controller, or if they wish to seek information regarding their data, may do so through any of the Controller’s contact channels, and it is advisable to use the email address info@honighaz.hu.
In the event that the data subject seeks to exercise a right relating to data processing, requests information regarding data processing, or lodges an objection or complaint concerning data processing, the Controller shall investigate the matter without undue delay and within the time limit prescribed by applicable legislation, take action in relation to the request, and inform the data subject of the outcome. Where necessary, having regard to the complexity and number of requests, this deadline may be extended as provided by applicable legislation.
If the data subject submitted the request electronically, the information shall, where possible, be provided electronically, unless the data subject requests otherwise. If the Controller does not take action on the data subject’s request, it shall inform the data subject, without undue delay but no later than the time limit prescribed by applicable legislation, of the reasons for the failure to act and the grounds for refusing the request, and of the possibility to bring judicial or regulatory proceedings as set out below.
11.2 Judicial Proceedings
The data subject may bring a claim before a court against the Controller or its processor if they consider that the Controller or the processor acting on its behalf or instructions is processing their personal data in breach of the requirements laid down in applicable legislation or in a binding legal act of the European Union. Jurisdiction over such claims lies with the regional court (törvényszék), and at the option of the data subject, proceedings may also be brought before the regional court having jurisdiction over the data subject’s place of residence or habitual residence.
The Controller is obliged to compensate damage caused to the data subject by unlawful processing of their personal data or by breach of data security requirements; however, the Controller shall be exempt from liability if the damage was caused by an unavoidable cause beyond the scope of data processing, or if the damage resulted from the intentional or grossly negligent conduct of the data subject.
11.3 Regulatory Proceedings
The data subject may initiate an inquiry or regulatory proceedings before the National Authority for Data Protection and Freedom of Information (1055 Budapest, Falk Miksa u. 9-11.; website: http://naih.hu; postal address: 1363 Budapest, Pf.: 9.; telephone: +36-1-391-1400; fax: +36-1-391-1410; e-mail: ugyfelszolgalat@naih.hu) on the grounds that a violation of their rights has occurred or is imminently threatened in connection with the processing of their personal data — in particular if, in their view, the Controller restricts the exercise of their rights as a data subject or refuses their request (initiation of an inquiry), or if they consider that the Controller or a processor acting on its behalf or instructions has violated the requirements laid down in applicable legislation or in a binding legal act of the European Union governing the processing of personal data (application for regulatory proceedings).
12. Miscellaneous
In the course of the personal data processing detailed in this Notice, no automated decision-making, profiling, or transfer of personal data to a third country or international organisation takes place.
This Notice is available at www.honighaz.hu.
The Controller reserves the right to unilaterally amend this Notice with future effect. Data subjects will be notified of any amendments via the Controller’s website. Unless otherwise provided, amendments shall take effect immediately.
Effective from: 15 June 2026
Annex 1
Data Protection Notice on Specific Data Processing Activities
1. Data Processing Related to Maintaining Contact and Other Enquiries
| Purpose of processing | The purpose of processing is to maintain contact, perform the contract, provide services, collect and evaluate feedback on the quality of services, and respond to questions raised by data subjects. A further purpose is the continuous improvement of the quality of the Controller’s services. |
| Legal basis for processing | In the case of lease and other contracts, the legal basis for processing the personal data of contact persons designated in the contract is the legitimate interest connected with the performance of the contract, Article 6(1)(f) GDPR.In the case of other notifications, enquiries, questions and participation in customer satisfaction surveys, the consent of the data subject, given by sending the notification, enquiry or question or by completing the questionnaire, Article 6(1)(a) GDPR. |
| Categories of personal data | Identity data provided for the purposes of maintaining contact (typically: name, email address, residential address). |
| Duration of processing; erasure | For contractual contact persons, the duration of processing is 5 years from the termination of the contract; in other cases, 5 years from receipt of the enquiry, after which the data shall be erased and destroyed. |
| Categories of recipients; data transfers | The Controller transfers personal data related to maintaining contact to the following recipients: (i) authorities and courts designated by law, upon their official request, call or pursuant to applicable legislation; (ii) its processor providing document archiving and storage services, on the basis of a data processing agreement. |
| Consequence of failing to provide data | If data is not provided or is incomplete, contact cannot be maintained. |
2. Data Processing Related to Newsletter Services
| Purpose of processing | The purpose of processing is the promotion of the Controller’s services, facilitating their use, and business development. |
| Legal basis for processing | The consent of the data subject, Article 6(1)(a) GDPR.The legitimate interest of the Controller in promoting its services, Article 6(1)(f) GDPR. |
| Categories of personal data | Identity data provided for the purposes of maintaining contact (name, email address). |
| Duration of processing; erasure | The duration of processing is aligned with the consent; data shall be erased immediately upon withdrawal of consent or upon objection to processing, but no later than within 30 days thereof. |
| Categories of recipients; data transfers | The Controller transfers personal data related to maintaining contact to the following recipients: authorities and courts designated by law, upon their official request, call or pursuant to applicable legislation. |
| Consequence of failing to provide data | If data is not provided or is incomplete, the newsletter service cannot be provided. |
3. Data Processing Related to Targeted Outreach and Direct Marketing Activities
| Purpose of processing | Establishing contact with the data subject at the data subject’s initiative, for the purpose of offering products, services and events provided by the Controller. Promoting the Controller’s own services by way of direct outreach. Demonstrating the lawfulness of past outreach activities. Avoiding future contact with data subjects who have withdrawn their consent. |
| Legal basis for processing | The consent of the data subject, Article 6(1)(a) GDPR.The legitimate interest of the Controller in promoting its services, enforcing legal claims, demonstrating compliance, avoiding future contact with data subjects who have withdrawn consent, and avoiding potential complaints and reputational damage arising from unsolicited communications, Article 6(1)(f) GDPR. |
| Categories of personal data | Identity and contact data provided for the purposes of maintaining contact (name, job title likely indicating representative authority, company name, email address, telephone number). |
| Duration of processing; erasure | Until withdrawal of consent, but no longer than the general limitation period under the Civil Code (5 years) from the provision of data. The duration of processing is aligned with the consent; data shall be erased immediately upon withdrawal of consent or upon objection to processing, but no later than within 30 days thereof. |
| Categories of recipients; data transfers | The Controller transfers personal data related to maintaining contact to the following recipients: processors, and authorities and courts designated by law, upon their official request, call or pursuant to applicable legislation. |
| Consequence of failing to provide data | If data is not provided or is incomplete, targeted outreach and direct marketing activities cannot be carried out. |
4. Data Processing Related to Social Media Accounts
| Purpose of processing | The purpose of processing is to operate the Controller’s social media profiles, promote its services, facilitate their use, conduct business development, and improve their quality. |
| Legal basis for processing | The consent of the data subject through the creation of the social media account and visiting the Controller’s social media profiles, Article 6(1)(a) GDPR.The legitimate interest of the Controller in operating its social media profiles, Article 6(1)(f) GDPR. |
| Categories of personal data | Identity data and other information published by the data subject as a user at the time of creating the social media account or subsequently. |
| Duration of processing; erasure | The duration of processing is the general limitation period, 5 years. |
| Categories of recipients; data transfers | The Controller transfers personal data related to social media accounts to authorities exclusively in the event of suspicion of a criminal offence connected with the relevant social media account. |
| Consequence of failing to provide data | There is no consequence arising from the failure to provide data. |
5. Data Processing Related to Complaint Handling
| Purpose of processing | The purpose of data processing related to complaint handling is to investigate the complaint, clarify its circumstances, and continuously improve the quality of the Controller’s services. |
| Legal basis for processing | Performance of a lease or other contract, Article 6(1)(b) GDPR.The consent of the data subject, given by submitting the complaint, Article 6(1)(a) GDPR. |
| Categories of personal data | Identity data provided by the complainant in the complaint (typically: name, email address, residential address), and any personal data contained in the complaint. |
| Duration of processing; erasure | The duration of processing is 5 years from the closure of the complaint case, after which the data shall be erased and destroyed. |
| Categories of recipients; data transfers | The Controller transfers personal data related to complaints to the following recipients: (i) the Controller’s contractual partners, for the purposes of investigating the circumstances of the service affected by the complaint; (ii) authorities and courts designated by law, upon their official request, call or pursuant to applicable legislation; (iii) its processor providing document archiving and storage services, on the basis of a data processing agreement; (iv) companies carrying out delivery of correspondence, as processors, with the data necessary for delivery (name and address), on the basis of a data processing agreement. |
| Consequence of failing to provide data | All material data relating to the complaint is necessary for handling the complaint and investigating its circumstances. If data is not provided or is incomplete, the complaint cannot be handled, or cannot be handled appropriately. |