Privacy Policy - PWS Solutions

Privacy Policy

About the data processing activities carried out when using the services of PWS Solutions

Please note: this is a non-binding courtesy translation. For all legal purposes, the Hungarian-language version is authoritative and legally binding.

1. Name and contact details of the Data Controller

Data Controller details

Name: Felczán Katalin e.v.

Tax number: 91239978-1-24

Registration number: 60710279

Registered seat: 5600 Békéscsaba, Pátkai Ervin utca 2, 4/12

Contact

Phone: +36 70/319-40-21

E-mail: info@pws.hu

Website: https://pws.hu

2. Data Protection Officer

The Data Controller qualifies as a small and medium-sized enterprise, and its activities do not fall within the scope defined in Article 37(1) of the GDPR; therefore, the designation of a data protection officer is not mandatory. In data protection matters, you may contact the Data Controller directly.

3. Legal basis of the data processing

Consent (GDPR Article 6(1)(a))

The data subject has given consent to the processing of his or her personal data for one or more specific purposes.

Performance of a contract (GDPR Article 6(1)(b))

Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.

Legitimate interest (GDPR Article 6(1)(f))

Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.

4. Scope of the personal data processed

Identification data

  • • Family name and given name
  • • E-mail address
  • • Phone number
  • • Postal address
  • • IP address
  • • Company name (where relevant)

Contact data

  • • Content of messages
  • • Communication preferences
  • • Service-related requirements
  • • Project specifications
  • • Billing data

Technical data

  • • Browser type and version
  • • Operating system
  • • Referring website (referrer)
  • • Subpages visited
  • • Date and time of the visit
  • • Data collected through cookies and similar technologies

5. Purposes and legal bases of the data processing

Handling of quote requests

Purpose: Receiving and processing customer enquiries and preparing quotes

Legal basis: Consent and preparation of a contract

Provision of services

Purpose: Performance of web development, hosting and graphic design services

Legal basis: Performance of a contract

Maintaining customer relationships

Purpose: Continuous contact, customer service and support

Legal basis: Legitimate interest and consent

Billing and accounting

Purpose: Fulfilment of obligations under the Accounting Act

Legal basis: Legal obligation

Marketing activity

Purpose: Sending newsletters and promoting services

Legal basis: Consent

6. Duration of the data processing

Purpose of processing Duration of processing
Handling of quote requests 2 years after the last contact
Contractual relationship 5 years after expiry of the contract
Accounting documents 8 years (as required by the Accounting Act)
Marketing-purpose processing Until consent is withdrawn
Website usage data 2 years

7. Data transfer, data processors

General principles

The Data Controller does not disclose the personal data of the data subject to third parties, except in the cases specified in this policy or where required to do so by law.

Data processors

Hosting provider

Storage of the website and data, and creation of backups

E-mail provider

Handling of electronic correspondence

Accountant

Billing and bookkeeping tasks

Analytics providers

Analysis of website traffic (Google Analytics)

8. Rights of the data subject

Right to information

You have the right to request information about the fact and circumstances of the data processing.

Right of access

You have the right to access your data and to request a copy of it.

Right to rectification

You have the right to request the correction or completion of inaccurate data.

Right to erasure

Under certain conditions, you have the right to have your data erased.

Right to restriction

You have the right to request the restriction of processing in certain cases.

Right to data portability

You have the right to receive your data in a structured, commonly used format.

Right to object

You have the right to object to the processing on certain legal bases.

Withdrawal of consent

You may withdraw your consent at any time with effect for the future.

How to exercise your rights

You may exercise your rights using the following contact details:

Response deadline: 1 month from receipt of the request

9. Legal remedies

Lodging a complaint with the supervisory authority

If you consider that the processing of your personal data infringes the provisions of the GDPR, you may lodge a complaint with the supervisory authority:

Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) (Hungarian National Authority for Data Protection and Freedom of Information)

Address: 1055 Budapest, Falk Miksa utca 9-11.

Postal address: 1363 Budapest, Pf. 9.

Phone: +36 1 391-1400

E-mail: ugyfelszolgalat@naih.hu

Website: https://naih.hu

Court proceedings

Independently of, or following, lodging a complaint with the supervisory authority, if you have suffered harm, you may turn to the court for damages or for a grievance award.

10. Management of cookies

Our website uses cookies in order to improve the user experience and optimise the operation of the website.

Necessary cookies

Essential for the basic operation of the website. These are always active.

Functional cookies

Language selection, remembering settings. These can be disabled.

Analytics cookies

Analysis of website usage (Google Analytics). These can be disabled.

Managing cookie settings

You can manage and delete cookies in your browser. If cookies are disabled, certain functions of the website may not work properly.

Detailed information: Cookie Policy

11. Data security

Technical measures

  • SSL encryption (HTTPS)
  • Regular backups
  • Access control
  • Antivirus protection and firewall
  • Database encryption
  • Regular security updates

Organisational measures

  • Data protection policies
  • Staff training
  • Management of access rights
  • Incident management procedures
  • Confidentiality agreements
  • Documented procedures

Handling of data protection incidents

In the event of a data protection incident, we act in accordance with Articles 33 and 34 of the GDPR: we notify the supervisory authority within 72 hours and, where necessary, also inform the data subjects.

12. Profiling and automated decision-making

The Data Controller does not carry out automated decision-making, including profiling, that would produce legal effects concerning the data subject or similarly significantly affect him or her.

Exceptions

Should we carry out such activities in the future, we would provide separate information to the data subjects about the logic applied, as well as the significance and the envisaged consequences of such processing.

13. Transfer of data to third countries

Basic principle

The Data Controller strives to process the personal data of data subjects exclusively within the European Union.

Possible exceptions

In the case of certain services (e.g. Google Analytics, cloud-based services), the transfer of data to third countries may occur.

In such cases, we ensure the appropriate safeguards:

  • • On the basis of an adequacy decision
  • • Appropriate safeguards (e.g. standard contractual clauses)
  • • Exceptional situations (explicit consent of the data subject)

14. Obligations of the data subject

Accuracy of data

You are required to provide accurate and up-to-date data and to inform us without delay of any changes to your data.

Duty to inform

The Data Controller must be notified if there is any change in your data.

Lawful use

The services must be used lawfully and in a manner that does not infringe the rights of others.

Protection of confidential data

Your own access credentials (passwords) must be kept confidential.

15. Related legislation

European Union legislation

  • GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data
  • ePrivacy Directive: Directive 2002/58/EC on the processing of personal data and the protection of privacy in the electronic communications sector

Hungarian legislation

  • Infotv. (Information Act): Act CXII of 2011 on the right of informational self-determination and on freedom of information
  • Accounting Act: Act C of 2000 on accounting
  • Civil Code (Ptk.): Act V of 2013 on the Civil Code
  • Act on electronic commerce services: Act CVIII of 2001

16. Website-specific data processing

Contact forms

Data processed: name, e-mail address, phone number, message content

Purpose: receiving enquiries, preparing quotes

Legal basis: consent and preparation of a contract

Newsletter subscription

Data processed: e-mail address, name (optional)

Purpose: sending marketing content

Legal basis: consent (via double opt-in procedure)

Measuring website traffic

Data processed: IP address, browser data, pages visited

Purpose: optimising website performance

Legal basis: legitimate interest (anonymous statistics)

Management of customer relationships

Data processed: full customer profile, project data, communication history

Purpose: provision of services, customer service

Legal basis: performance of a contract, legitimate interest

17. Processing of special categories of data

General rule

The Data Controller does not, as a rule, process the special categories of data referred to in Article 9 of the GDPR (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, data concerning a natural person's sex life or sexual orientation).

Exceptional cases

Should the processing of special categories of data nevertheless become necessary (e.g. accessibility requirements), we request separate explicit consent and apply enhanced protection measures.

18. Special situations

Business-purpose data processing

Due to the nature of our services (web development, graphic design, hosting), we primarily process the data of enterprises, companies and sole traders within the framework of business relationships.

Project-based cooperation

The data processing is typically linked to specific projects, for a defined period, for the purpose of providing specific services.

B2B relationships

The overwhelming majority of our clients are businesses, so the data processing is primarily limited to business contact data (company e-mail, company phone, name of the contact person).

19. Records of data processing activities

In accordance with Article 30 of the GDPR, the Data Controller maintains records of its data processing activities, which contain:

  • The name and contact details of the controller
  • The purposes of the processing
  • A description of the categories of data subjects
  • A description of the categories of personal data
  • The categories of recipients
  • The erasure deadlines
  • A general description of the technical and organisational measures

20. Final provisions

Entry into force

This Privacy Policy enters into force on 1 January 2025.

Right to amend

The Data Controller reserves the right to amend this policy unilaterally. We inform data subjects of any amendments via the website.

Language versions

This policy is available in Hungarian, English and German. In the event of any discrepancy, the Hungarian-language version shall prevail.

Contact

In data protection matters, please feel free to contact us using the following details:

E-mail: info@pws.hu

Phone: +36 70/319-40-21