PRIVACY POLICY
Hamilton Project Limited Liability Company
Registered office: 2040 Budaörs, Budapesti út 87/A.
1. General provisions and contact details
This privacy policy („Policy”) is the privacy policy of Hamilton Project Kereskedelmi és Szolgáltató Korlátolt Felelősségű Társaság with company registration number Cg.13-09-113911 (2040 Budaörs, Budapesti út 87/A., hereinafter: „Company” or „Hamilton Kft.”), which applies to the personal data collected and processed about you by the Company.
Company address: 2040 Budaörs, Budapesti út 87/a
Company registration authority: Company Court of the Budapest-Capital Regional Court
Company registration number: Cg.13-09-113911
Company tax number: 13995834-2-13
If you have any questions or comments regarding this Policy, before using the http://www.hamiltonproject.hu website (hereinafter: „Website”) or providing any data in accordance with this Policy, please contact our customer service via one of the following contact details:
Phone: +36-23-444-644
Email: [email protected]
2. Updating and availability of the Policy
The Company reserves the right to unilaterally modify this Policy with effect from the time of modification. Therefore, it is recommended to regularly visit the Website in order to monitor any changes. Upon request, we will send you a copy of the current Policy.
3. Acknowledgement and acceptance of the Policy
By providing the given personal data or information, you declare that you have read and expressly accept the version of this Policy in force at the time of providing such data or information.
In the case of certain specific services, additional data protection conditions may also apply, about which you will be informed before using the given service.
4. Scope of processed data and purposes of data processing
On our website (http://www.hamiltonproject.hu) or in connection with certain services, we may request data related to you, and you may also voluntarily provide certain data to us (e.g. CV) or disclose them publicly (for example on social media platforms) during your communication with the Company. Some of the information collected by us qualifies as „personal data” under Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter: „GDPR”) and Act CXII of 2011 on the right of informational self-determination and freedom of information (hereinafter: „Infotv.”) Section 3 (2).
5. In general, the scope of processed data, purposes of processing, legal bases, duration of processing and persons entitled to access the data
Data controller details: the data controller is Hamilton Project Kft., the operator of the Website (registered office: 2040 Budaörs, Budapesti út 87/A; tax number: 13995834-2-13; phone: +36-23-44444; email: [email protected])
The Company primarily processes the following personal data:
- - Operation of customer service for complaint handling purposes – recording of phone number and email communication
- - Information collected in connection with the use of the Website
- - Data processing related to the establishment of employment relationships, storage of applications and CVs
- - Data processed via social media platforms
Persons authorized for data processing (editor, admin)
The Company does not use data processors for performing technical tasks related to data processing operations.
The scope of processed data, purposes of processing, duration of processing and persons entitled to access the data are presented in the table below:
| Purpose of data processing | Platform | Site | Processing organization | Type of personal data | Retention period |
|---|---|---|---|---|---|
| Contact with customers | email, phone | hamiltonproject.hu | HR | email address, name | Until deletion is requested |
| Record keeping of customer data | customers | hamiltonproject.hu | Sales | email address, name | Until deletion is requested |
| Record keeping of contracted partners | Contracted partners | hamiltonproject.hu | Sales | name, address, email address, phone number | 5 years from termination of the contract |
| Recruitment | Visitors of the site | hamiltonproject.hu | HR | CV | Until deletion is requested |
| Contact with customers | Visitors of the site | facebook.com | HR | User data | Until deletion is requested |
6. Statistical information collected in connection with the use of the website
By starting to use the Website, users visiting the Website (hereinafter: „User”) accept all conditions contained in this Policy, therefore please read this Privacy Policy (hereinafter: „Policy”) carefully before using the Website.
6.1. What information do we collect in connection with the use of the Website?
The User does not provide any personal data or information about themselves on the Website, therefore the Data Controller does not collect or process any personal data relating to the User in a way that would allow the User to be personally identified.
The Data Controller uses the services of Google Analytics in connection with the Website. Google Analytics helps measure Website traffic and other web analytics data through statistical traffic analysis. The collected information is transmitted to and stored on external servers operated by Google. Google primarily uses this information on behalf of the Data Controller to track Website traffic and prepare reports on Website activity. Google may transfer this information to third parties where required by law. Google may also transfer this data to third parties processing the data on its behalf. Detailed information about how Google Analytics processes data can be obtained from Google Analytics (http://www.google.com/analytics).
The Company retains the web analytics data provided by Google Analytics, but does not use it for identification or other personal data processing activities.
6.2. How do we use this information?
Data collected using the above technologies cannot be used to identify the User, and the Company, as data controller, does not link this data with any other data that may be suitable for identification.
Purpose of data processing: The primary purpose of using such data is to ensure the proper operation of the Website, which particularly requires monitoring Website traffic (creating visitor statistics) and detecting possible misuse related to Website usage. The Company’s website and the information published on it are accessible to any external visitor. During the visit, the hosting provider of the website records visitor data in order to monitor the operation of the service, prevent misuse and ensure proper functioning. The purpose of recording is to collect information about website usage, create statistics and analyses. External service providers place so-called cookies on the User’s computer, enabling them to link the User’s current visit with previous ones. The User receives information about cookies in a pop-up window on the website and may reject their use by setting their browser accordingly.
Legal basis for data processing: Voluntary consent under the GDPR and Section 5 of Act CXII of 2011 on informational self-determination and freedom of information.
Scope of processed data: Website traffic and other web analytics data, including: date, time, IP address of the User’s computer, address of visited page, address of previously visited page, data related to the User’s operating system
Duration of data processing: Until withdrawal of the User’s voluntary consent, but no longer than 2 years from the date of visiting the website. The User may withdraw their consent at any time by modifying their browser settings.
The Data Controller may also use this statistical information to analyze usage trends and improve and develop Website functions, as well as to obtain comprehensive traffic data about the overall use of the Website.
The Data Controller may use the information obtained to compile statistics and analyses related to Website usage and may transmit or publish such non-identifiable statistical data (e.g. number of visitors, most viewed topics or content) to third parties in aggregated, anonymous form.
7. Data processing related to the Rolling Tons magazine
The Company is the publisher of the monthly magazine titled Rolling Tons (hereinafter: „Magazine”).
Legal basis of data processing
Customers, advertisers and readers of the Magazine, as well as users of our other services, by providing their personal data during registration for the given service, give their consent to the registration and processing (storage and handling) of their data. During this process, the Company takes all reasonable steps to ensure secure data handling in accordance with this privacy policy.
Accordingly, the legal basis for data processing is the consent of the data subject pursuant to Section 5 (1) a) of Act CXII of 2011.
Personal data processed by the Company
During online or personal ordering, the customer provides the following data:
Our customers, readers and advertisers:
- - last name(s)
- - first name(s)
- - position at the company or institution they represent
- - email address
- - phone number
- - contact address (postal code, city, street, house number)
for invoicing and cash payment:
- - billing name (last name, first name)
- - billing address
- - tax identification number or tax number
- - email address
- - phone number
Duration of data processing
Data processing lasts from the customer’s registration until they request deletion. Upon request, the Company deletes all data from its system within 10 working days.
Rights of the customer
Our customer is entitled to the rights defined by applicable laws, thus they may request at any time by letter or electronically to the Company at the above email address:
- - information about the processing of their personal data;
- - correction of their personal data; and
- - deletion of their personal data – except for mandatory data processing;
- - statement of the Data Controller regarding objection to data processing.
The Company provides written information within 3 working days from submission of the request about the customer’s data processed by the Company, their source, purpose, legal basis, duration of processing, as well as the legal basis and recipient of any data transfer.
Correction and deletion of data
If the data does not correspond to reality and the correct data is available to the Company, the Company corrects the data.
The data must be deleted if its processing is unlawful, the Customer requests it, it is incomplete or incorrect – and this condition cannot be lawfully remedied – provided that deletion is not excluded by law, the purpose of processing has ceased, or the statutory storage period has expired, or it has been ordered by a court or authority.
The Company notifies the affected customer about any correction or deletion. Notification may be omitted if it does not violate the legitimate interest of the customer considering the purpose of data processing.
Consent of the data subject
The Customer acknowledges that their consent is voluntary, given based on appropriate information, and may be withdrawn at any time via the contact details provided in this Privacy Policy.
8. Data processing related to employment relationships, storage of applications and CVs
In the case of CVs and applications, the purpose of data processing is to fill the advertised position. Accordingly, if the Company as employer selects a candidate, the purpose of processing ceases and – pursuant to Section 17 (2) d) of the Infotv. – the personal data of non-selected applicants must be deleted.
This deletion obligation also applies if the applicant withdraws their application during the process.
The Company may only retain applications based on the explicit, clear and voluntary consent of the data subject. Sending an application does not automatically mean consent to its retention, therefore the Company requests such consent after the recruitment process is completed.
The right to informational self-determination is best ensured if applicants are also informed when they are not selected for a position.
Any conclusions drawn from data about the data subject also qualify as personal data. Therefore, any notes made by Company employees about applicants are also considered personal data. The data subject has the right to access such information and learn what conclusions were drawn. These notes must also be deleted.
8.1. In case of application via email
Purpose of data processing: Applicants may send their CV to the email address indicated on the Company’s website, containing personal and job-related data. By sending the CV, the applicant voluntarily consents to data processing under this policy.
Legal basis: Voluntary consent under the GDPR and Section 5 of Act CXII of 2011.
Scope of processed data: Name, address, education and other personal data included in the CV.
Duration: Until withdrawal of consent, but maximum 2 years from receipt of the CV.
8.2. Processing of data contained in CVs submitted by post, e-mail or in person and rules related to recruitment
Purpose of data processing: the Company provides the opportunity for prospective employees, who are informed about current job offers, to submit their applications to the Company’s HR department by postal mail or in person. The purpose of data processing is to optimize the number of employees by employing workers with appropriate competencies and expertise.
Legal basis for data processing: in the case of CVs submitted by post: GDPR and Act CXII of 2011 on informational self-determination and freedom of information, Section 6.
In the case of CVs submitted in person: GDPR and Act CXII of 2011 on informational self-determination and freedom of information, Section 5.
Scope of processed data: personal data of the data subject contained in the CV or in documents attached to it.
Duration of data processing: Until the withdrawal of the applicant’s consent, but for a maximum of 2 years from the receipt of the CV. The applicant may withdraw their consent for the storage of the CV at any time via the contact details provided in the data security and data protection policy.
9. Data processed via social media
Purpose of data processing: Presentation of the activities, structure, job opportunities, and company-related news of Rolling Tons on the facebook.com website.
Legal basis for data processing: Based on Section 5 of Act CXII of 2011 on informational self-determination and freedom of information, the voluntary consent of the data subject given by registering on the facebook.com social media site and the user’s active interaction with any content of the Company (for example liking, sharing, commenting, sending a private message to the page).
Duration of data processing: Data processing takes place on the facebook.com website. The duration, method of data processing, and options for deleting and modifying data are governed by the rules of the facebook.com social media site. (facebook.com/about/privacy )
10. Links
The Website may contain links to other websites not necessarily controlled by us, and other websites not controlled by us may also provide links to the Website. If you leave the Website, we cannot take responsibility for the security of any information you provide on other sites. It is recommended to act with caution and review the confidentiality documents on the given websites.
11. Data security
The Data Controller undertakes to ensure the security of the data, and also takes the technical and organizational measures and establishes the procedural rules that ensure that the recorded, stored, and processed data are protected, and prevent their destruction, unauthorized use, and unauthorized alteration. It also undertakes to ensure that any third party to whom the data are transferred or disclosed based on the Users’ consent complies with the requirements of data security.
The Data Controller ensures that unauthorized persons cannot access, disclose, transmit, modify, or delete the processed data. The processed data may be accessed only by the Data Controller and its employees, and the Data Controller does not transfer them to third parties who are not authorized to access the data.
The Data Controller does everything within its power to ensure that the data are not accidentally damaged or destroyed. The Data Controller requires employees involved in data processing activities to comply with the above obligations.
The User acknowledges and accepts that when providing personal data on the Website – despite the fact that the Website operator has modern security tools to prevent unauthorized access or data breaches – the protection of data cannot be fully guaranteed on the Internet. In the event of unauthorized access or data acquisition despite our efforts, the Website operator shall not be liable for such data acquisition or unauthorized access, or for any damages incurred by the User as a result. Furthermore, the User may also provide their personal data to third parties, who may use it for unlawful purposes or in an unlawful manner.
The Company, as data controller, does not collect special categories of data under any circumstances, i.e. data relating to racial origin, membership of a national or ethnic minority, political opinions or party affiliation, religious or other beliefs, trade union membership, health status, pathological addictions, sexual life, or criminal record.
12. Rights of the data subject and legal remedies in case of website visit, job application, and other voluntary contact
The Company, as the operator of the Website and also as the data controller, makes every effort to ensure that the processing of personal data complies with legal regulations. If you feel that we have not complied with this, please write to us at [email protected] email address.
In general, the data subject may request from the data controller primarily: (a) information about the processing of their personal data, (b) correction of their personal data, and (c) deletion or restriction of their personal data – except for mandatory data processing. The data controller is obliged to provide the information in writing, in an intelligible form, within the shortest possible time from the submission of the request, but no later than 25 days.
If the data controller does not comply with the request for correction, restriction, or deletion, it shall communicate the factual and legal reasons for rejecting the request in writing or, with the consent of the data subject, electronically within 25 days of receipt of the request.
The legal basis for data processing is the voluntary consent of the Users, which is given by opening the website and by entering certain parts of it requiring registration.
a.) Right to information
Users may request information about the processing of their personal data. Upon request, the data controller provides detailed information to the data subject about the data processed by it, the purpose, legal basis, and duration of the data processing, the name and address of the data processor and its activities related to data processing, and also about who receives or has received the data and for what purpose. Information may be requested at the data controller’s postal address (registered office: 2040 Budaörs, Budapesti út 87/a.) or at [email protected] email address.
The User may also initiate the correction and deletion of their personal data at the same contact details.
A User who believes that the data controller has violated their right to the protection of personal data may enforce their claim before a civil court or request the assistance of the National Authority for Data Protection and Freedom of Information (hereinafter: Authority). Detailed provisions on this and on the obligations of the data controller are contained in the Info Act.
b.) Right to rectification, deletion, restriction
If the personal data are inaccurate and the correct personal data are available to the data controller, the data controller shall rectify the personal data. Personal data must also be deleted if their processing is unlawful; the data subject requests it as described above; they are incomplete or incorrect – and this condition cannot be lawfully remedied – provided that deletion is not excluded by law; the purpose of data processing has ceased, or the statutory retention period has expired; or it has been ordered by a court or the Authority.
Instead of deletion, the data controller restricts the personal data if the data subject requests it or if, based on the available information, it can be assumed that deletion would harm the legitimate interests of the data subject. Personal data restricted in this way may only be processed as long as the purpose of data processing that excluded deletion exists. The data controller shall mark the personal data it processes if the data subject disputes their accuracy or correctness, but the inaccuracy or incorrectness cannot be clearly established.
The data subject and all those to whom the data were previously transmitted for data processing purposes must be notified of the rectification, restriction, marking, and deletion. Notification may be omitted if this does not harm the legitimate interests of the data subject with regard to the purpose of data processing.
In the event of improper use of the website services, as well as at the User’s own request, the related data will be deleted by the data controller. Deletion will take place within 8 days of receipt of the deletion request. The data controller informs the Authority annually by January 31 of the year following the reference year about rejected requests. In case of rejection of a request for rectification, deletion, or restriction, the data controller informs the data subject about the possibility of judicial remedy and of contacting the Authority.
c.) Right to object
The data subject may object to the processing of their personal data if the processing or transfer of personal data is necessary solely for the fulfillment of a legal obligation applicable to the data controller or for the enforcement of the legitimate interests of the data controller, data recipient, or a third party, except in the case of mandatory data processing; if the personal data are used or transferred for direct marketing, public opinion polling, or scientific research purposes; and in other cases specified by law.
In the cases defined in the GDPR and Section 21 of the Info Act, the data subject may object to the processing of their personal data. The data controller shall examine the objection within the shortest possible time from the submission of the request, but no later than 25 days, make a decision on its merits, and inform the applicant in writing of its decision.
If the data controller establishes that the objection of the data subject is justified, it shall terminate the data processing – including further data collection and data transfer – and restrict the data, and notify all those to whom the personal data concerned by the objection were previously transferred, and who are obliged to take measures to enforce the right of objection. If the data subject does not agree with the decision of the data controller, or if the data controller fails to meet the deadline, the data subject may turn to the court within 30 days from the communication of the decision or from the last day of the deadline.
The data subject may turn to the court in case of violation of their rights, as well as in the cases specified in Section 21 of the Info Act. The lawsuit may also be initiated – at the choice of the data subject – before the competent court according to the place of residence or stay of the data subject.
The court shall act in the case out of turn. The data controller is obliged to compensate for damages caused to another person by unlawful processing of data or by breach of data security requirements. The data controller is also liable towards the data subject for damages caused by the data processor. The data controller shall be exempt from liability if it proves that the damage was caused by an unavoidable cause outside the scope of data processing. Compensation shall not be paid to the extent that the damage resulted from the intentional or grossly negligent conduct of the injured party.
Furthermore, anyone may initiate an investigation with the National Authority for Data Protection and Freedom of Information (naih.hu; 1530 Budapest, Pf.: 5.; phone: +36-1-391-1400; fax: +36-1-391-1410; e-mail: [email protected]) on the grounds that a violation of rights has occurred or there is a direct risk thereof in connection with the processing of personal data or the exercise of the right of access to data of public interest or data public on grounds of public interest.
The rights and legal remedies related to data processing are set out in detail in Sections 13–17 and 30 of the Info Act.
Before initiating any procedure, it may be advisable to send a complaint to the data controller.
13. Public communication options, other issues
Public communication channels that form part of our services are used by all our Users at their own risk. The personal rights related to the copyright of various comments belong to the respective User; however, the User may not assert any financial rights or claims against the data controller, and the Company, as data controller, is entitled to quote them without restriction, reproduce them and/or, if necessary, moderate and/or modify them.
Users have the opportunity to submit their opinions and comments to the data controller, however, the Company, as data controller, does not publish or deletes comments that violate laws, infringe personal rights, or do not comply with the business policy and principles of the data controller. Comments may otherwise be printed, downloaded, or distributed by third parties only for personal use, and may only be used with the prior written consent of the data controller.
We draw the attention of our users to the fact that various legal regulations applicable to public communications apply to comments appearing on public communication channels and public disclosures.
The use of the Internet involves various risks to privacy. Please note that your opinion posted on the website is personal data from which special categories of data, even your origin or political opinion, may be inferred. These data become accessible to everyone. We recommend using PET technology (Privacy Enhancing Technology) to protect your personal data. You can find information about this on many websites.
Important web addresses
- National Authority for Data Protection and Freedom of Information: naih.hu
- National Media and Infocommunications Authority: nmhh.hu
- Applicable legislation: magyarorszag.hu
14. Other provisions
This Notice shall be governed directly and mandatorily by the GDPR, as well as by Hungarian law, in particular the provisions of Act CXII of 2011 on informational self-determination and freedom of information.
The Company, as data controller, reserves the right to unilaterally amend this Notice at any time with prior notice to the User. The User must accept the modification on the Website – in order to continue using the Website – in the manner provided by the Website. The amendments shall become effective towards the User upon acceptance or upon the first use of the Website.
What personal data we collect and for what purpose we collect them
Comments
When submitting a comment, in addition to the data provided in the comment form, the commenter’s IP address and browser user agent string are collected for the purpose of filtering spam content.
An anonymized string generated from the email address (commonly called a hash) may be provided to the Gravatar service if it is used on the site. The terms of the Gravatar service are available at the following address: automattic.com/privacy. After approval of the comment, the content of the comment and the profile picture will be publicly visible.
Media
If a registered user uploads images to the website, they should avoid uploading images that contain embedded EXIF data with GPS location information. Visitors to the website can download and extract location data from images on the website.
Contact forms
Cookies
If you leave a comment on the website, you may choose to save your name, email address, and website in cookies. This is for your convenience so that you do not have to fill in these details again when leaving another comment. These cookies will last for 1 year.
If you visit the login page, a temporary cookie will be set to determine whether your browser accepts cookies. These cookies do not contain personal data and are deleted when you close your browser.
When you log in to the website, several cookies are set to save your login information and screen display choices. Login cookies last for two days, and screen options cookies last for one year. If you select the "Remember Me" option, your login will persist for two weeks. If you log out of your account, the login cookies will be removed.
If you edit or publish an article, an additional cookie will be saved in your browser. This cookie does not include personal data and simply indicates the post ID of the article you just edited. It expires after one day.
Embedded content from other websites
Articles on the website may include embedded content (e.g. videos, images, articles, etc.) from external sources. Embedded content from external sources behaves in exactly the same way as if the user had visited another website.
These websites may collect data about visitors, use cookies or third-party tracking code, monitor user interaction with the embedded content, including tracking interaction if the user has an account and is logged in to that website.
How long we retain personal data
If you leave a comment, the comment and its metadata are retained indefinitely. This is so that any follow-up comments can be recognized and approved automatically instead of being held in a moderation queue.
For users that register on the website (if any), we also store the personal information they provide in their user profile. All users can see, edit, or delete their personal information at any time (except they cannot change their username). Website administrators can also see and edit that information.
What rights you have over your data
If you have an account on this site or have left comments, you can request to receive an exported file of the personal data we hold about you, including any data you have provided to us. You can also request that we delete any personal data we hold about you. This does not include any data we are obliged to keep for administrative, legal, or security purposes.
Where we send your data
Visitor comments may be checked through an automated spam detection service.