Privacy Policy
About the data processing activities carried out when using the services of PWS Solutions
1. Name and contact details of the Data Controller
Data Controller details
Name: Felczán Katalin e.v.
Tax number: 91239978-1-24
Registration number: 60710279
Registered seat: 5600 Békéscsaba, Pátkai Ervin utca 2, 4/12
Contact
2. Data Protection Officer
The Data Controller qualifies as a small and medium-sized enterprise, and its activities do not fall within the scope defined in Article 37(1) of the GDPR; therefore, the designation of a data protection officer is not mandatory. In data protection matters, you may contact the Data Controller directly.
3. Legal basis of the data processing
Consent (GDPR Article 6(1)(a))
The data subject has given consent to the processing of his or her personal data for one or more specific purposes.
Performance of a contract (GDPR Article 6(1)(b))
Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
Legitimate interest (GDPR Article 6(1)(f))
Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data.
4. Scope of the personal data processed
Identification data
- • Family name and given name
- • E-mail address
- • Phone number
- • Postal address
- • IP address
- • Company name (where relevant)
Contact data
- • Content of messages
- • Communication preferences
- • Service-related requirements
- • Project specifications
- • Billing data
Technical data
- • Browser type and version
- • Operating system
- • Referring website (referrer)
- • Subpages visited
- • Date and time of the visit
- • Data collected through cookies and similar technologies
5. Purposes and legal bases of the data processing
Handling of quote requests
Purpose: Receiving and processing customer enquiries and preparing quotes
Legal basis: Consent and preparation of a contract
Provision of services
Purpose: Performance of web development, hosting and graphic design services
Legal basis: Performance of a contract
Maintaining customer relationships
Purpose: Continuous contact, customer service and support
Legal basis: Legitimate interest and consent
Billing and accounting
Purpose: Fulfilment of obligations under the Accounting Act
Legal basis: Legal obligation
Marketing activity
Purpose: Sending newsletters and promoting services
Legal basis: Consent
6. Duration of the data processing
| Purpose of processing | Duration of processing |
|---|---|
| Handling of quote requests | 2 years after the last contact |
| Contractual relationship | 5 years after expiry of the contract |
| Accounting documents | 8 years (as required by the Accounting Act) |
| Marketing-purpose processing | Until consent is withdrawn |
| Website usage data | 2 years |
7. Data transfer, data processors
General principles
The Data Controller does not disclose the personal data of the data subject to third parties, except in the cases specified in this policy or where required to do so by law.
Data processors
Hosting provider
Storage of the website and data, and creation of backups
E-mail provider
Handling of electronic correspondence
Accountant
Billing and bookkeeping tasks
Analytics providers
Analysis of website traffic (Google Analytics)
8. Rights of the data subject
Right to information
You have the right to request information about the fact and circumstances of the data processing.
Right of access
You have the right to access your data and to request a copy of it.
Right to rectification
You have the right to request the correction or completion of inaccurate data.
Right to erasure
Under certain conditions, you have the right to have your data erased.
Right to restriction
You have the right to request the restriction of processing in certain cases.
Right to data portability
You have the right to receive your data in a structured, commonly used format.
Right to object
You have the right to object to the processing on certain legal bases.
Withdrawal of consent
You may withdraw your consent at any time with effect for the future.
How to exercise your rights
You may exercise your rights using the following contact details:
- • E-mail: info@pws.hu
- • Phone: +36 70/319-40-21
- • Postal address: 5600 Békéscsaba, Pátkai Ervin utca 2, 4/12
Response deadline: 1 month from receipt of the request
9. Legal remedies
Lodging a complaint with the supervisory authority
If you consider that the processing of your personal data infringes the provisions of the GDPR, you may lodge a complaint with the supervisory authority:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) (Hungarian National Authority for Data Protection and Freedom of Information)
Address: 1055 Budapest, Falk Miksa utca 9-11.
Postal address: 1363 Budapest, Pf. 9.
Phone: +36 1 391-1400
E-mail: ugyfelszolgalat@naih.hu
Website: https://naih.hu
Court proceedings
Independently of, or following, lodging a complaint with the supervisory authority, if you have suffered harm, you may turn to the court for damages or for a grievance award.
10. Management of cookies
Our website uses cookies in order to improve the user experience and optimise the operation of the website.
Necessary cookies
Essential for the basic operation of the website. These are always active.
Functional cookies
Language selection, remembering settings. These can be disabled.
Analytics cookies
Analysis of website usage (Google Analytics). These can be disabled.
Managing cookie settings
You can manage and delete cookies in your browser. If cookies are disabled, certain functions of the website may not work properly.
Detailed information: Cookie Policy
11. Data security
Technical measures
- SSL encryption (HTTPS)
- Regular backups
- Access control
- Antivirus protection and firewall
- Database encryption
- Regular security updates
Organisational measures
- Data protection policies
- Staff training
- Management of access rights
- Incident management procedures
- Confidentiality agreements
- Documented procedures
Handling of data protection incidents
In the event of a data protection incident, we act in accordance with Articles 33 and 34 of the GDPR: we notify the supervisory authority within 72 hours and, where necessary, also inform the data subjects.
12. Profiling and automated decision-making
The Data Controller does not carry out automated decision-making, including profiling, that would produce legal effects concerning the data subject or similarly significantly affect him or her.
Exceptions
Should we carry out such activities in the future, we would provide separate information to the data subjects about the logic applied, as well as the significance and the envisaged consequences of such processing.
13. Transfer of data to third countries
Basic principle
The Data Controller strives to process the personal data of data subjects exclusively within the European Union.
Possible exceptions
In the case of certain services (e.g. Google Analytics, cloud-based services), the transfer of data to third countries may occur.
In such cases, we ensure the appropriate safeguards:
- • On the basis of an adequacy decision
- • Appropriate safeguards (e.g. standard contractual clauses)
- • Exceptional situations (explicit consent of the data subject)
14. Obligations of the data subject
Accuracy of data
You are required to provide accurate and up-to-date data and to inform us without delay of any changes to your data.
Duty to inform
The Data Controller must be notified if there is any change in your data.
Lawful use
The services must be used lawfully and in a manner that does not infringe the rights of others.
Protection of confidential data
Your own access credentials (passwords) must be kept confidential.
15. Related legislation
European Union legislation
- GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data
- ePrivacy Directive: Directive 2002/58/EC on the processing of personal data and the protection of privacy in the electronic communications sector
Hungarian legislation
- Infotv. (Information Act): Act CXII of 2011 on the right of informational self-determination and on freedom of information
- Accounting Act: Act C of 2000 on accounting
- Civil Code (Ptk.): Act V of 2013 on the Civil Code
- Act on electronic commerce services: Act CVIII of 2001
16. Website-specific data processing
Contact forms
Data processed: name, e-mail address, phone number, message content
Purpose: receiving enquiries, preparing quotes
Legal basis: consent and preparation of a contract
Newsletter subscription
Data processed: e-mail address, name (optional)
Purpose: sending marketing content
Legal basis: consent (via double opt-in procedure)
Measuring website traffic
Data processed: IP address, browser data, pages visited
Purpose: optimising website performance
Legal basis: legitimate interest (anonymous statistics)
Management of customer relationships
Data processed: full customer profile, project data, communication history
Purpose: provision of services, customer service
Legal basis: performance of a contract, legitimate interest
17. Processing of special categories of data
General rule
The Data Controller does not, as a rule, process the special categories of data referred to in Article 9 of the GDPR (racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, data concerning a natural person's sex life or sexual orientation).
Exceptional cases
Should the processing of special categories of data nevertheless become necessary (e.g. accessibility requirements), we request separate explicit consent and apply enhanced protection measures.
18. Special situations
Business-purpose data processing
Due to the nature of our services (web development, graphic design, hosting), we primarily process the data of enterprises, companies and sole traders within the framework of business relationships.
Project-based cooperation
The data processing is typically linked to specific projects, for a defined period, for the purpose of providing specific services.
B2B relationships
The overwhelming majority of our clients are businesses, so the data processing is primarily limited to business contact data (company e-mail, company phone, name of the contact person).
19. Records of data processing activities
In accordance with Article 30 of the GDPR, the Data Controller maintains records of its data processing activities, which contain:
- The name and contact details of the controller
- The purposes of the processing
- A description of the categories of data subjects
- A description of the categories of personal data
- The categories of recipients
- The erasure deadlines
- A general description of the technical and organisational measures
20. Final provisions
Entry into force
This Privacy Policy enters into force on 1 January 2025.
Right to amend
The Data Controller reserves the right to amend this policy unilaterally. We inform data subjects of any amendments via the website.
Language versions
This policy is available in Hungarian, English and German. In the event of any discrepancy, the Hungarian-language version shall prevail.
Contact
In data protection matters, please feel free to contact us using the following details:
E-mail: info@pws.hu
Phone: +36 70/319-40-21