The purpose of this Information on Data Processing is to provide detailed information on the controlling and processing of personal data by Pro Concept Automotive Zrt. (hereinafter referred to as PCAutomotive).
Moreover, the purpose of this Information on Data Processing is to ensure that the PCAutomotive complies with the data protection provisions of the legislation in force, especially, but not exclusively the REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of individuals with regard to the processing of personal data and the free movement of such data, and repealing Regulation (EC) No 95/46 (hereinafter referred to as the ’GDPR regulation’) and the Act of CXII of 2011 on the right to information self-determination and freedom of information law (hereinafter referred to as the ’Info. Act’)
Personal data in the PCAutomotive
I. PCAutomotive, as data processor
The services provided by PCAutomotive are not based on the processing of personal data. In certain cases, however, during the performance of their activities, the PCAutomotive may become aware of the following personal data of private individuals in legal relationship with its clients:
- first name and last name,
- user name,
- phone number,
- mobile number,
- email address.
II. PCAutomotive, as data controller
Data controlling by the PCAutomotive is primarily related to legal compliance or the basic operation of the company, as follows:
1. Personal data of the contact persons of clients (business partners)
In order to provide services, to fulfill the contract, PCAutomotive controls the following personal data of contact persons designated by clients and other contractual partners:
The contact person’s
- first name and last name,
- user name,
- phone number,
- mobile number,
- email address.
The contact persons of clients consent to the processing of their data by signing the contract between the PCAutomotive and its business partner or by completing the form attached to the contract.
The PCAutomotive processes the data stored on paper or electronically until it is necessary for performing its contractual obligations but no further than five years after the termination of the relationship.
The personal data of the contact persons of clients are processed in the following context:
- Data processing to facilitate keeping contact with clients.
- Data processing for the purpose of invoicing.
- Data processing related to representation.
- Data processing for the purpose of setting user rights in IT systems.
2. Data processing for security purposes
The premises of PCAutomotive are protected by video surveillance and access control systems (hereinafter: system), in line with the opportunity stated in the provisions of Act CXXXIII of 2005 on Security Services and the Activities of Private Investigators (Szvtv.). The PCAutomotive acts with due regard to the principles of necessity and proportionality when the system elements are installed and operated. Based on Section 31 (3) of the Szvtv., PCAutomotive retains video recordings on the system servers for no more than 30 days if the recordings are not used. PCAutomotive stores recordings in a closed IT system located in a locked area subject to separate penetration control and access control. The video recordings made by the system can be viewed by the PCAutomotive security management colleagues and the colleagues of the competent authority in the case of proceedings by the authority. In the case of proceedings, request by authorities, the recordings can be forwarded subject to consent by the CEO and only if any security incident is suspected. Security guards continuously check live recordings, and thus the functionality of the system.
Rules on viewing recordings, possible purposes of using recordings:
- Only the PCAutomotive CEO or the colleagues of PCAutomotive security management are entitled to view recordings, in justified cases and in a documented manner.
- The purpose of using recordings is to ensure the confidentiality, availability and integrity of the data and valuables managed by PCAutomotive.
You can request that the recordings made of you are not deleted, where justified. You are also entitled to contact the PCAutomotive if you believe that that operation of the electronic surveillance system is an affront to your human dignity.
The data processing rules related to the system apply to the access control system also, as in this case data on access and movement are considered personal data that the PCAutomotive retains for 24 hours after you leave.
3. Data processing related to the use of the websites of PCAutomotive
The websites of the PCAutomotive (www.pcautomotive.com) use anonymous user identifiers (cookies) related to the use of certain services in order to improve the quality of use of such services and make use simpler for users. The cookie is a series of signs capable of identifying individual computers and store profile information that service providers store on the computer of the user. The series of signs itself is not capable of identifying personally the user, it can identify the computer only.
If you would not like to have cookies on your computer, please disable cookies in your browser. However, in this case it is possible that you cannot access certain services differently than with cookies enabled.
4. Data processing related to registration on the websites of PCAutomotive
Visitors of the PCAutomotive websites (www.pcautomotive.com) can register for marketing communication. Based on consent by the parties registering for service, the PCAutomotive processes the following personal data provided on its website:
- first and last name,
- user name,
- email address,
provided by the registering party.
The personal data is processed according to Article 6 (1) f) of GDPR.
Please read this information carefully upon registration, and mark the appropriate field to indicate your consent. The PCAutomotive deletes data immediately when the registration is cancelled. You can cancel registration as described in the advice earlier sent, by clicking the registration cancellation function stated in the advice.
5. Processing the personal data of job applicants
Based on the consent of job applicants, the PCAutomotive manages the personal data stated in resumes and attached documents (motivation letter, reference and other documents) received directly or through the contracted selection and recruitment partner. Consent is given by submitting the application.
If you wish to apply for a job posted by the PCAutomotive, please provide only the personal data relevant to the position (e.g. education, experience) and avoid providing information that are not necessarily required to assess whether you are fit for the position (e.g. age, address, religion).
The purpose of data processing is to perform the selection process and to inform applicants on the result of the selection processes.
If the PCAutomotive involves third parties in any phase of the selection process, the applicant is informed accordingly in advance and related consent is requested.
The PCAutomotive processes the above personal data until the posted position is filled, and the data will be deleted immediately when decision is made on filling the position. Should any reason justifying further data processing arise during the selection process (e.g. possibility of later cooperation), the PCAutomotive informs the applicant and requests consent by the applicant for further data processing for a fixed period.
6. Data processing for business development
The PCAutomotive processes the data of potential business partners related to business development, for the purpose of making contact later, based on consent expressed by handing over business cards or in similar manners. In such cases, at the time the first contact is made, the PCAutomotive makes verbal reference to this Information on Data Processing or sends it (as attachment or link) to give written information on data processing details. If no business cooperation is entered into, the PCAutomotive deletes data after three years, but the party concerned can request immediate cancellation of its data at any time at: email@example.com
7. Data processing by the PCAutomotive as employer
As employer, PCAutomotive process the personal data of employees (and third parties working based on other legal relationship) and, as appropriate, the personal data of the relatives of employees. The persons involved are informed separately on data processing by the employer.
Who can know the personal data processed by the PCAutomotive?
All PCAutomotive employees are bound by secrecy. The PCAutomotive places strong emphasis on ensuring with internal regulation and strict IT rights management that the data it controls and processes are known only to the employees to the job of whom the data concerned is related to, in the case of personal data, for example:
- Personal data of job applicants can be known the colleagues and heads of the units posting the position,
- Data related to business development can be known to the colleagues and managers responsible for business development.
There are positions at PCAutomotive that promote compliance with regulations (e.g. legal representative). In order to perform work, the colleagues and managers of these units need to know the data processed or controlled by the PCAutomotive related to certain tasks.
To whom the PCAutomotive forward the personal data?
Data can be forwarded to meet the requirements of regulations, for example, in the following typical cases:
- responding to requests by authorities or reporting to administrative or investigating authorities,
- in order to fulfill a contract, to the party involved.
In certain cases, PCAutomotive can forward personal data to the cooperating law firms, for example in order to finalize a contract or related to a legal dispute. In this case, the law firm is required to manage the transferred data in line with the contract for legal services and the applicable regulations (in particular the secrecy stated in Act LXXVIII of 2017 on the Profession of Lawyer).
In other cases, not regulated by law, when the need to transfer data to third parties arises, data is transferred subject to the written consent of the parties concerned, after prior information is given on the legal basis of data forwarding and the transferee, for example: filling a position at PCAutomotive requires a test related to which PCAutomotive wishes to involve a third-party service provider.
Security of data at the PCAutomotive
The PCAutomotive places great emphasis on the security of personal data it processes or controls, that is to say, to avoid violation of data security resulting adventitious or unlawful destruction, loss, change, unauthorized communication of data or unauthorized access to data (data protection incident).
However, should a data protection incident nevertheless occur, the PCAutomotive has internal regulation the determines the method of incident investigation, informing the parties concerned and the National Data Protection and Information Security Authority (Authority), and the method of documenting and managing incidents without any delay. The PCAutomotive manages physical documents containing personal data subject to strict security requirements. It is not possible to recover the destructed physical documents.
The PCAutomotive provides data protection training to employees to ensure data protection awareness, to facilitate the prevention and proper management of data protection incidents of IT or non-IT nature.
What can you do if you have questions or wish to make a complaint related to the processing of your personal data?
Rights of the persons involved in data processing under the GDPR:
1. Right of information, access;
2. Right of rectification;
3. Right of erasure;
4. Right to restriction of processing;
5. Right to data portability;
6. Right to object.
1. Right of information and access of the data subject
PCAutomotive, informs the data subject on the measures taken by PCAutomotive or on the justification why measures are not taken by sending a response in no more than one month to the address stated in the request submitted.
2. Right to rectification
The data subject has the right to request the rectification of inaccurate personal data concerning him or her. If it is necessary to rectify the personal data controlled by the Controller, the data subject can request (in mail or email) the rectification of data by stating the correct data.
The data subject is required to report to the Controller in writing (in mail or email) any change to its personal data controlled by the Controller immediately but not later than five days after the change. The data subject assumes liability for damages due to failure to report or reporting with delay the change.
Taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.
PCAutomotive informs the data subject without undue delay, no later than one month, in a response letter sent to the address stated in the request submitted on the measures taken or on the justification why measures are not taken.
3. Right to erasure
The data subject has the right to obtain from the Controller the erasure of personal data concerning him or her without undue delay and the Controller is required to erase personal data of the data subject without undue delay in the cases stated in the GDPR (Article 17).
Where the Controller has made the personal data public, that is to say it has personal data forwarded personal data to third parties, in case the right to erasure of the data subject is exercised, the Controller takes reasonable steps to inform controllers that received the personal data forwarded that the data subject has requested the erasure by such controllers if any links to, or copy or replication of those personal data.
The data subject can request PCAutomotive in writing to erase its personal data.
PCAutomotive rejects the request to erase if PCAutomotive is required by law to continue to store the personal data. If there is no such requirement related to the personal data requested to be erased, PCAutomotive informs the data subject without undue delay, no later than one month, in a response letter sent to the address stated in the request submitted on the measures taken or on the justification why measures are not taken.
4. Right to restriction of processing
The data subject has the right to obtain from the Controller restriction of processing if
- the data subject contests the accuracy of personal data;
- the processing is unlawful and the data subject opposes the erasure of the personal data;
- the Controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defense of legal claims;
- the data subject has objected to processing.
The data subject can request PCAutomotive to restrict processing in writing. Where processing has been restricted, PCAutomotive can only store personal data for the periods stated in Article 18 of the GDPR, other controlling activity can be undertaken subject to the consent of the person requesting restriction due to the establishment, exercise or defense of legal claims or for the protection of public interest. The Controller informs in advance the person requesting restriction on terminating the restriction.
5. Right to data portability
The data subject has the right to receive the personal data concerning him or her, which he or she provided to the Controller, in a structured, commonly used and machine-readable format and has the right to transmit those data to another controller without hindrance from the Controller if:
- processing is based on consent or contract stated in Article 20 of the GDPR; and
- processing is carried out by automated means.
6. Right to object
The data subject has the right to object, on grounds related to his or her particular situation, at any time processing personal data concerning him or her, including profiling. In this case personal data can no longer be processed for this purpose unless the Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defense of legal claims.
Where personal data are processed for direct marketing purposes, the data subject has the right to object at any time to the processing of personal data concerning him or her for such marketing which includes profiling to the extent that it is related to such direct marketing.
Where the data subject objects to processing for direct marketing purposes, the Controller can no longer process personal data.
Please be informed that if processing is based on consent (phone number, email address), you can revoke your consent to processing any time, however, it does not affect the lawfulness of processing based on consent before revocation of consent. You can revoke your consent by sending a statement to this effect in mail or email.
The Controller provides information on the measures taken related to the request received on the exercise of the rights stated in Point 1-6. Without undue delay, but no later than one month, in writing, using plain language, in the electronic or mail channel selected by the data subject, which deadline can be extended with two more months if justified, taking into account the complexity of the request and the number of requests.
In line with the details provided in this document, the data subject has the right to request any member of the PCAutomotive to let you know the personal data processed related to you, the correction of such data, and the deletion of data, except for the data that are mandatory to be managed.
If data subject believes that his or her rights related to his or her personal data are violated by the PCAutomotive, the data subject can lodge a complaint as follows:
- In writing, to the mailing address of Pro Concept Automotive Zrt. (1031 Budapest, Záhony utca 7/C.) at any time.
- In email, to email address firstname.lastname@example.org, or to the business email addresses of the colleagues of Pro Concept Automotive Zrt. at any time.
- Related to data protection incidents regarding business applications: email@example.com.
If the data subject’s rights related to the processing of personal data are violated, he or she has the right to contact the Authority (address: H-1155 Budapest, Falk Miksa utca 9-11.; phone: +36 1 391-1400; email: firstname.lastname@example.org; website: https://www.naih.hu), or go to court. Anyone can report to the Authority the violation of rules related to personal data processing or direct threat thereof. Details on further legal remedies are contained in Act V of 2013 on the Civil Code (Ptk.) and the rules of civil proceedings if the case is referred to the court, and in the Info Act if the data protection authority (Authority) is contacted.
You are recommended to lodge a complaint before starting any other proceedings. We make sure that your complaint is investigated with the greatest care, is responded to within one month, and we will do our best to solve the issue to your satisfaction.