Privacy Notice for Contractual Partners
Date of issue: 5 October 2020
1. Preamble
The purpose of this notice is to provide data subjects with appropriate information about the data processing activities carried out by the Controller.
The Controller informs data subjects that, in the course of its data processing activities, it complies with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: GDPR), as well as Act CXII of 2011 on Informational Self-Determination and Freedom of Information (hereinafter: the Information Act).
2. Details of the Controller
3. Categories of personal data processed, purposes and legal bases of processing
The Controller processes the following personal data relating to its contractual partners and their employees, authorised representatives and other representatives:
- name, electronic contact details (email, telephone and fax number) and postal contact details;
- position/title;
- chamber registration number and other registration identifiers, where applicable.
The table below describes the purposes, legal bases and retention periods of the processing activities carried out by the Controller.
| Processing activity | Purpose of processing | Legal basis | Retention period |
|---|---|---|---|
| Personal data relating to the contractual partner and provided by the contractual partner. | Performance of contracts concluded with contractual partners and enforcement of claims arising from such contracts. | Processing necessary for the performance of a contract under Article 6(1)(b) GDPR. | For at least 5 years, but no longer than the final deadline for enforcing claims arising from the contract. |
| Personal data relating to the employees, authorised representatives and other representatives of contractual partners, provided by the contractual partners. | Performance of contracts concluded with contractual partners, maintaining contact and enforcement of claims arising from such contracts. | Processing based on legitimate interest1 under Article 6(1)(f) GDPR. | For at least 5 years, but no longer than the final deadline for enforcing claims arising from the contract. |
| Identification data provided by contractual partners. | Activities required to comply with legal obligations, such as accounting and taxation. | Compliance with a legal obligation under Article 6(1)(c) GDPR. | Accounting vouchers and documents are retained for 8 years; other documents are retained no longer than the final deadline for enforcing claims arising from the contract. |
4. Disclosure of personal data (recipients)
The Controller discloses data subjects’ personal data to the following recipients:
- contractual partners and other companies belonging to the group;
- postal and delivery service providers;
- public authorities for the purpose of complying with statutory reporting and information obligations;
- companies acting as processors.
The purposes and legal bases of disclosure are set out in the following table:
| Processing activity | Purpose of processing | Legal basis |
|---|---|---|
| Disclosure to contractual partners and within the group. | Performance of contracts concluded with contractual partners and enforcement of claims arising from such contracts. | Processing based on legitimate interest2 under Article 6(1)(f) GDPR. |
| Disclosure to postal and delivery service providers. | Proper fulfilment of cooperation and information duties and proper exercise of contractual rights during the performance of the contract. | Processing necessary for the performance of a contract under Article 6(1)(b) GDPR. |
| Disclosure for compliance with statutory reporting and information obligations. | Activities required to comply with legal obligations, such as accounting, taxation and law-enforcement obligations. | Compliance with a legal obligation under Article 6(1)(c) GDPR. |
| Disclosure to a company carrying out processing activities. | Execution and performance of processing in the systems and for the purposes determined by the Controller. | Processing necessary for the performance of a contract under Article 6(1)(b) GDPR. |
| Disclosure to an external, independent insurance broker experienced in compensation matters. | Obtaining an insurance expert opinion concerning damage events arising during construction activities. | Processing based on legitimate interest3 under Article 6(1)(f) GDPR. |
When data are disclosed to contractual partners or within the group, they are disclosed to companies participating in the relevant construction project as contracting parties, such as consortium partners or project owners, and to companies contributing to implementation under the contract.
When data are disclosed to postal or delivery service providers, the data are primarily disclosed to Magyar Posta and secondarily to other parcel delivery organisations.
Public authorities receiving data in connection with statutory reporting and information obligations are organisations that exercise public authority while performing their statutory duties. These include, without limitation, local and central tax authorities, social security bodies, and supervisory authorities and organisations.
The independent insurance broker experienced in compensation matters liaises between insurance companies and our company as the insured party to establish whether compensation is legally justified.
Processing activities are carried out by the company or companies appointed by our company for this purpose, on the basis of a contractual agreement between our company and the processor.
With reference to Article 13(f) GDPR, the Controller informs data subjects that it does not transfer the personal data it processes to a controller in a third country or to an international organisation.
5. Rights of data subjects
Data subjects may request access to, rectification or erasure of their personal data, or restriction of processing, and may also exercise their right to data portability.
These rights are described below:
- Right of access/information: the data subject may request information from the Controller about the categories of personal data processed by the Controller and the manner in which they are processed.
- Right to data portability: the data subject may request to receive personal data concerning them in a structured, commonly used and machine-readable format and has the right to transmit those data to another controller without hindrance from the original Controller.
- Right to rectification: the data subject may indicate that the data processed are inaccurate and may request the information that should replace them.
- Right to erasure/right to be forgotten: the data subject may request the erasure of their data and the removal of traces of processing. Where the Controller has made the data to be erased accessible to third parties, it must inform all recipients to whom the data were disclosed that all links to the personal data and all copies stored by them must be erased.
- Right to restriction: in certain cases, the person affected by the processing may request restriction of processing, for example in an unresolved dispute or where processing is no longer necessary but the data subject nevertheless requires the data. In such cases, the personal data may only be stored. Where processing is restricted, the Controller must also ensure that all recipients to whom the personal data were disclosed are notified.
If a data subject wishes to exercise their rights, they may contact our colleague using any of the contact details specified in Section 2 of this notice. Requests submitted electronically or on paper will be examined without undue delay and no later than one month after receipt, and the applicant will be informed of the action taken. Where the request is complex or additional information or action is required, this period may be extended by up to two months.
If a data subject disagrees with any processing activity carried out by the Controller, they may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH): address: 1055 Budapest, Falk Miksa utca 9–11., Hungary; postal address: 1363 Budapest, P.O. Box 9., Hungary; email: ugyfelszolgalat@naih.hu; telephone: +36 (1) 391-1400. Data subjects also have the right to bring an action before the competent court to enforce their rights relating to personal data.
