Privacy information

PRIVACY NOTICE

The purpose of this Privacy Notice is to ensure that Kopaszi Gát Zrt. and Property Market Kft. (hereinafter jointly referred to as the “Companies”) fulfil their obligation to provide prior information to data subjects regarding the processing of their personal data, and to inform them about the principles of data processing and the available legal remedies.

In preparing this Privacy Notice, the Companies have taken into account the provisions of:

  • Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (“General Data Protection Regulation” or “GDPR”),
  • Act CXII of 2011 on Informational Self-Determination and Freedom of Information,
  • Act CVIII of 2001 on Electronic Commerce and Information Society Services,
  • Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities,
  • Act V of 2013 on the Hungarian Civil Code.

This Notice applies to the data processing activities of the Companies in relation to the sending of newsletters and commercial offers (“CRM Data Processing”), as well as to the data processing carried out during the use of the website www.budapart.hu (“Website Data Processing”).


1. Data Controllers

The personal data are jointly controlled by:

  • Kopaszi Gát Zrt. (company registration number: 01 10 142037, registered office: 1117 Budapest, Dombóvári út 26. 1st floor), and
  • Property Market Kft. (company registration number: 01-09-206694, registered office: 1117 Budapest, Dombóvári út 27.).

2. Fundamental Principles of Data Processing

2.1. Lawfulness, Fairness and Transparency: The Companies process personal data lawfully, fairly and in a transparent manner, ensuring that data subjects are properly informed.

2.2. Purpose Limitation: Personal data are collected solely for the purposes specified in section 4 and shall not be further processed in a manner incompatible with those purposes.

2.3. Data Minimisation: The Companies process only those personal data that are adequate, relevant and limited to what is necessary for the purposes described.

2.4. Accuracy: The Companies take all reasonable steps to ensure that personal data are accurate and up to date, and shall rectify or erase any inaccurate data without delay.

2.5. Storage Limitation: Personal data shall be kept only for as long as necessary to fulfil the purposes set out in section 4.

2.6. Integrity and Confidentiality: The Companies apply appropriate technical and organisational measures to ensure the security of personal data, protecting them against unauthorised or unlawful processing, accidental loss, destruction or damage.


3. Legal Basis for Data Processing

3.1. The legal basis for processing is the data subject’s consent pursuant to Article 6(1)(a) GDPR, as well as the provisions of the Electronic Commerce Act. With regard to CRM Data Processing, the provisions of Section 6(1) of the Advertising Act are also applied, meaning that personal data may only be processed where the data subject has given explicit consent.

3.2. The Companies do not disclose personal data to the public. However, disclosure may be ordered by law in the public interest, specifying the categories of data to be made public. In all other cases, disclosure requires the explicit written consent of the data subject. In case of doubt, it must be presumed that consent has not been given.

3.3. Personal data processed on a mandatory legal basis may be transferred to the Central Statistical Office for statistical purposes, provided the data are processed in a manner that does not allow the identification of individual data subjects, unless otherwise provided by law.


4. Purposes of Data Processing

4.1. CRM Data Processing: The purpose is to provide the services available on the Companies’ website, particularly property listings, offers, business communications, maintaining contact, and ensuring the best possible fulfilment of the data subject’s requests. The specific personal data to be provided are set out in section 5.2.

4.2. Website Data Processing: For the operation of the website www.budapart.hu, the Companies use cookies to measure website traffic, as detailed in section 5.1.

4.3. Personal data provided by the data subject shall not be used for purposes other than those specified in this section. Disclosure to third parties or authorities is only permitted with the prior, explicit consent of the data subject, unless required by law.

4.4. The Companies do not verify the accuracy of the data provided. Responsibility for the correctness of the information lies solely with the person providing it. However, the Companies are obliged to process only accurate personal data. By providing an email address, the data subject assumes responsibility for the fact that the email account is used exclusively by them. Any liability arising from the use of a registered email address rests with the registrant.


5. Categories of Processed Data

5.1. Website Data Processing:
During the visit of the website, the Companies record the following data for the purpose of providing the service, verifying its operation and preventing abuse: date and time of visit, visitor’s IP address, URL of the visited page, URL of the previously visited page, type of browser used.

Technical data automatically recorded during system operation include the data of the user’s logging-in device generated during the use of the service, which are recorded automatically by the system without any separate statement or action of the user. Such data are logged at the time of login and logout. These log files are not linked with other personal data. Only the data controller has access to these data.

5.2. CRM Data Processing:
The following personal data are recorded during the registration process: username, password, password reminder, email address, name, country, address, gender, phone number, newsletter subscription, date of registration, number of logins, last login date, login IP address, and the services used on the website.

The Companies store these data in their Customer Relationship Management system (“CRM system”), which also records customer activity, contacts, content of communications and dates thereof. Where a contract is concluded for the purchase of property, further data are recorded: banking details, identification data (tax number, personal ID number, mother’s maiden name, place and date of birth), details of the selected property, specifications, design and construction details.

Where contracts are concluded for residential units, the Companies may continue to process the customers’ personal data in order to provide further offers and maintain communication with existing clients. By granting consent, customers also consent to their personal data being processed following the conclusion of the property purchase agreement.


6. Scope of Data Processing

6.1. The Companies primarily use email addresses to maintain contact. Where services change, notifications are sent by email. Marketing emails are only sent in compliance with the applicable legal requirements.

6.2. Where links to external service providers are used, cookies may be placed and read on the user’s device to enable customised service. Returning cookies may allow such providers to link current and previous visits, but only in relation to their own content. Users may delete cookies or disable their use in browser settings.


7. Retention Period of Personal Data

7.1. Data processed in the CRM system are retained for 5 years from the date of provision, unless longer retention is required by law (e.g. accounting and tax rules). If a purchase contract is concluded, the data listed in section 5.2 are retained for 5 years from contract date, except for contact details (name, email, phone), which are retained as long as the property is owned or used by the data subject.

7.2. Upon request for deletion or withdrawal of consent, data are erased within 10 working days unless longer retention is required by law.

7.3. Automatically recorded technical data are retained for a maximum of 10 years. Where consent is withdrawn, such technical data shall no longer allow identification of the data subject.

7.4. In cases of unlawful, misleading or abusive use of personal data, or suspected criminal activity, the Companies may erase the data immediately, or retain them for the duration of the legal proceedings.


8. Access to Data, Data Transfers and Data Processing

8.1. Data may be accessed primarily by the Companies’ employees responsible for the operation of the CRM system and the provision of services, but shall not be disclosed publicly.

8.2. For IT operations and service provision, the Companies may engage processors (e.g. system operators). These processors ensure lawful and secure processing, and enable data subjects to exercise their rights. Current processors include:

  • Macette Kft. (2100 Gödöllő, Ibolya u. 56.), virtual infrastructure services.
  • Soulware Zrt. (1031 Budapest, Záhony u. 7.), software development services.
  • ADAMSKY by Positive Kft. (1062 Budapest, Délibáb u. 29.), web development services.

8.3. Processors may not make independent decisions, may only process data as instructed, and may not use the data for their own purposes.

8.4. In specific cases (e.g. court orders, police investigations, legal proceedings concerning intellectual property, property or other rights), personal data may be disclosed to authorities or third parties.

8.5. The Companies shall comply with lawful requests for data disclosure by authorities or courts. The Companies verify the authenticity of such requests and transfer the data securely.

8.6. Where a contract is concluded for services within the Budapart Project, the Companies may transfer the necessary personal data to cooperating project partners. The data subject is separately informed of the recipients and circumstances.

8.7. If data are intended to be used for purposes other than those originally collected, prior consent of the data subject shall be obtained.

8.8. The Companies comply with all statutory restrictions on data collection, recording and processing, and inform data subjects upon request.

8.9. The Companies’ system may collect usage data, which shall not be linked to other external services.


9. Data Security

9.1. Data processing operations are designed and carried out in compliance with the GDPR, ensuring the protection of privacy.

9.2. The Companies take all technical and organisational measures necessary to safeguard personal data.

9.3. Adequate measures are taken to protect personal data against unauthorised access, alteration, disclosure, erasure, destruction, accidental loss or damage, or technological obsolescence.


10. Data Subject Rights

10.1. Data subjects may request information about the processing of their personal data, correction, erasure or restriction of personal data (except where mandatory processing applies), and may withdraw their consent.

10.2. Upon request, the Companies provide information about processed data, sources, purposes, legal bases, duration, processors, and any transfers.

10.3. Requests must be answered in writing, in clear language, within 25 days.

10.4. Requests may only be refused in cases permitted by the GDPR, with written justification and information on remedies.

10.5. Inaccurate data shall be corrected where accurate information is available.

10.6. Data must be erased where processing is unlawful, the data subject requests erasure, the purpose has ceased, or the statutory retention period has expired.

10.7. Instead of erasure, data may be restricted if requested by the data subject or if deletion would harm legitimate interests.

10.8. Rectification, restriction and erasure must be communicated to the data subject and any third parties to whom data were disclosed, unless disproportionate.

10.9. If a request is refused, the Companies inform the data subject within 25 days, giving factual and legal reasons, and informing them of available remedies.

10.10. Data subjects may object to the processing of their personal data where processing is not based on their consent.

10.11. Objections must be examined within 15 days, and the data subject notified of the decision.

10.12. Where the objection is upheld, processing (including data collection and transfer) shall be terminated, and the data restricted.

10.13. Where the data subject disagrees with the decision, or where no decision is taken within the deadline, the data subject may turn to the courts within 30 days.

10.14. Consent may be withdrawn at any time by notice to the Companies (by email to Show E-mail address or by post to 1117 Budapest, Dombóvári út 27.), in which case personal data are erased within 10 working days.


11. Binding Nature and Amendment of this Privacy Notice

11.1. The Companies undertake to process personal data in compliance with this Privacy Notice.

11.2. The Companies reserve the right to unilaterally amend this Privacy Notice at any time.

11.3. Amendments shall be communicated appropriately (e.g. via newsletter, website notice). Continued use of the services constitutes acceptance of the amended Privacy Notice.

11.4. Where amendments materially affect the purpose, duration, scope or categories of personal data processed, renewed consent shall be sought.


12. Remedies and Enforcement

12.1. The Companies strive to process personal data lawfully and fairly. In case of concerns, data subjects may contact the Companies at:

  • Property Market Kft.
    Email: Show E-mail address
    Address: 1117 Budapest, Dombóvári út 27.
  • Kopaszi Gát Zrt.
    Email: Show E-mail address
    Address: 1117 Budapest, Dombóvári út 26. 1st floor.

12.2. Data subjects may lodge complaints with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):
Szilágyi Erzsébet fasor 22/c, 1125 Budapest,
Postal address: 1530 Budapest, PO Box 5,
Tel: +36 (1) 391-1400, Fax: +36 (1) 391-1410,
Email: Show E-mail address,
Website:
http://naih.hu

12.3. Data subjects may also seek judicial remedy under the GDPR and the Hungarian Civil Code.

Where users provide third-party data or cause damage by using the website, the Companies may claim damages and assist the authorities in identifying the infringer.

Budapest, 04 September 2025

CAMERA RULES

 

RULES FOR THE USE OF CAMERAS/ELECTRONIC SURVEILLANCE SYSTEMS
 

Company name:                   Kopaszi Gát Privately Working Limited Liability Company
Registered office:                  1117 Budapest, Dombóvári 26. , 1st floor
Tax number:             32082429-2-43
Company registration number:       01-10-142037

This Policy contains the rules for the use of the Company's Camera/Electronic Surveillance System for the purpose of compliance with REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

The establishment and amendment of the Regulations falls within the competence of the executive director.

1. PURPOSE OF THE RULES

Kopaszi Dam Ltd. (hereinafter: Data Controller) at 1117 Budapest, Dombóvári út 26., 1st floor , uses an electronic surveillance system consisting of a total of 73 cameras for property protection and security purposes , which allows image recording and recording of moving images (hereinafter: recording). The specified purposes also include the protection of the life and physical integrity of employees . The cameras used by the Data Controller record the personal data of all employees and business partners - such as image recording, as well as the behavior of the data subjects - who enter the affected area (hereinafter: data subjects) . In addition to the above, natural persons who enter the area affected by the surveillance are also recorded.

The purpose of this policy is to define the rules governing the processing of personal data captured by cameras, to describe the measures taken to ensure the lawful processing and protection of data, and to ensure the rights of data subjects.

2. SCOPE OF THE RULES

The personal scope of the regulation extends to employees working at the Data Controller's premises, as well as to everyone who enters the area, while its material scope extends to the handling of recordings recorded by the surveillance system and to ensuring the rights of the data subjects.

3. GOVERNING LAW:

- Regulation (EU) 2016/679 of the European Parliament and of the Council on the processing of personal data of natural persons (GDPR),

- Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information ( Infotv ),

- Act CXXXIII of 2005 on the rules of personal and property protection and private investigation activities, and

- Act I of 2012 on the Labor Code (Act I).

4. EXPLANATION OF THE TERMS

This policy is based on the concepts of the applicable laws, in particular the concepts defined in the GDPR and the Infotv :

a) data processing: any operation or set of operations which is performed on personal data or data files, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction (Article 4(2) of the GDPR);

b) data controller: the natural or legal person or organization without legal personality who, independently or jointly with others, determines the purpose of data processing, makes and implements decisions relating to data processing (including the means used), or has them implemented by the Data Processor .

d) data protection incident: a breach of security that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data transmitted, stored or otherwise processed [GDPR Article 4, point 12];

e) balancing test: a documented balancing process carried out in accordance with Article 6(1)(f) of the GDPR, during which the legitimate interest of the Data Controller is identified and weighed against the legitimate interest of the data subjects;

f) data subject: a natural person who can be directly or indirectly identified based on the image recorded by a security camera, in particular employees of the Data Controller, as well as other persons entering the Data Controller's area or falling within the scope of the camera (electronic) surveillance system;

g) camera surveillance system: a closed-circuit camera system that uses fixed security cameras to record moving images indoors and outdoors and store them for a limited period of time;

h) pictogram: a sign used instead of a textual inscription, the purpose of which is to provide the data subject with concise information about the fact of data processing;

i) personal data: any information relating to an identified or directly or indirectly identifiable natural person (“data subject”), primarily an image for the purposes of this policy;

j) operation: the operation of the camera surveillance system and its elements, which enables the recording and storage of moving images.

5. GENERAL RULES OF DATA PROCESSING

4. 1. Purpose of data processing: The Data Controller uses the electronic monitoring system for asset protection purposes . The specified purposes also include the protection of the life and physical integrity of employees, the screening of potential sources of danger, and the control and coordination of work processes. Before starting data processing, the Data Controller conducted a balancing test.

 

4.2. Rules for conducting the balancing test:

During the balancing test, the legitimate interest of the Data Controller will be considered legitimate as a legal basis if it is determined that the Data Controller's interest is more important than the data subject's right to the protection of their personal data or the protection of their right to privacy.

The balancing test consists of the following steps for each camera:

a) is the use of the camera absolutely necessary in the given location, or is there an alternative that can avoid data processing,

b) determination of the legitimate interest that justifies the data processing, as well as the purpose of the data processing and the related data processing period,

c) during the balancing test, the following circumstances must be examined for all cameras:

- protection of machines and other tangible assets located on the property, protection of buildings,

- the interests of the data subject, i.e. the fundamental right to the protection of personal data (primarily the right to image)

- ensuring the rights of the data subject and guarantees for the enforcement of rights;

- data security measures taken and planned to be taken before data processing begins;

- the limited time limitation of data processing;

4.3. Legal basis for data processing:

a) in the case of data subjects who enter the monitored area (building, premises) voluntarily, of their own free will, the legal basis for data processing is the data subject's consent, which is expressed by indicative behavior. The condition for the application of this legal basis is information about data processing before entering the building.

b) in the case of employees, the legal basis for data processing is the legitimate interest of the Data Controller, about which the Data Controller is obliged to inform the employees.

In the course of this, it was established that the Data Controller's interest in the objectives takes precedence over the rights, interests and personal freedom of the data subjects (employees, business partners). Furthermore, it was established that this is the most effective means for the Data Controller to ensure the protection of assets and its objectives. The data subjects' personal rights (including specifically their right to their image) are violated, but the Data Controller implements appropriate guarantee rules to compensate for this. The balancing of interests test is an annex to this regulation .

4.4. Scope of data processed: The surveillance system records the image of the person entering the area monitored by the cameras and the action (moving image) visible in the recording. The camera surveillance system does not record sound. The cameras operate continuously.

4.5. Duration of data processing: The Data Controller stores the recorded recordings for three days, which was determined by the Data Controller taking into account the basic principles of data processing, such as data economy and the principle of limited storage. After the storage period, the recording will be automatically deleted.

4.6. Camera placement: Cameras can be placed throughout the property, especially on the walls of buildings, in areas open to the public or closed off, in parking lots, and in areas used to store equipment or supplies.

The electronic surveillance system may only monitor private areas; camera surveillance may not be directed at public areas.

The Data Controller keeps a list of the installed cameras as follows: the exact location of the camera, the direction of the viewing angle, the purpose and legal basis of the surveillance. The list of the cameras actually in operation is an annex to these regulations .

6. GUARANTEE RULES RELATED TO DATA PROCESSING

6.1. Respect for human dignity: A fundamental principle when using cameras is to respect human dignity, based on which cameras may not operate in changing rooms, dining rooms, washrooms, toilets, or be aimed at monitoring employees. When placing cameras, the Data Controller respects the right to privacy. They may not specifically monitor the work of employees, or only an employee and his or her activities, so the aim is not to influence the behavior of employees at work, even indirectly. The Data Controller may not use hidden cameras.

Based on the above, the purpose of operating the monitoring system is not to control employees or monitor their work intensity, but the recording can be used for the investigation of work accidents, disciplinary and court proceedings.

6.2. Prior information obligation:

During the preliminary information, the Data Controller must provide the data subject with written information about the following in an accessible manner (according to Annex 3!)

  1. the name and contact details of the data controller,

Kopaszi Dam Ltd.
Headquarters: 1117 Budapest, Dombóvári út 26, 1st floor
email:
[EmailProtect|uzemeltetes@budapart.hu{+}uzemeltetes@budapart.hu]
 

b) legal basis and purpose of data processing ( per camera ) /included in a separate annex/

c) if a data processor is used, its name, contact details, description of the activity performed, NONE

d) the location and duration of storage of the recording, the criteria for determining the duration, On a password-protected central data recorder, according to law, for 3 days, automatically deleted

e) data security measures communicated in a form that does not compromise the security of data storage, data storage protected by a high-strength encrypted password

f) the circle of persons authorized to view the data,

g) in which cases and to which bodies and persons may the recordings be forwarded,

h) rules regarding the review of recordings,

i) for what purpose the Data Controller may use the recording,

j) what rights the data subjects are entitled to, how they can exercise them, what legal remedies they can use in the event of a violation of their rights. This is contained in point 8 of the regulations.

In order to inform the data subjects, the Data Controller places a clearly visible notice board at the entrance to the area and at the entrance doors, which contains the following information: “ An electronic surveillance system is installed in the property area and in the buildings for the purpose of property and personal security, which records moving images. The location of the cameras (within 2m) is indicated by a pictogram. The Data Controller stores the recording for 3 days. Detailed information on this is available from the Data Controller and on its website.”

This information warns customers and visitors that by entering, they consent to the camera recording them .

6.3. Other rules: When using the surveillance system, personal data may be processed to the extent strictly necessary to achieve the purpose of data processing. The resolution of the image recorded by the security camera is adapted to the purpose of operating the camera security system. The camera must be set to the lowest resolution necessary to achieve the purpose, taking into account the principle of proportionality.

7. DATA SECURITY MEASURES

7.1. The monitor for viewing and reviewing the images must be placed in such a way that no person other than the authorized person can see them while the images are being broadcast. To this end, it is advisable to protect access to the recordings by locking them, using a key or security code, if possible, which must be locked when leaving. It is not possible to record images broadcast by the cameras with any device other than the central recording unit.

7.2. Persons authorized to access the recordings: the executive, the data controller, as well as additional employees authorized in writing by the executive, security service staff, may access the recordings for the purpose of detecting violations, monitoring the operation of the system, and, upon the request of the data subject, ensuring the data subject's rights, and for the data subject to view his or her own personal data. The recorded or real-time video recording may only be viewed by persons authorized to access .
 

7.3. Use and transmission of recordings:

The following are considered to be uses of recordings:

– in order to investigate security incidents involving personal data,

– to prepare a report in case of suspicion of a crime or violation,

– in order to comply with written requests from authorities,

– in the event of disciplinary proceedings, to establish the facts or to investigate a work accident

– in order to ensure the exercise of the rights of the data subject, whose rights or legitimate interests are affected by the image recording.

The recorded images may be handed over to the investigator or the administrative authority or the police in the event of a suspicion of a crime or violation of the rules, or in other court or administrative proceedings. The recording may only be forwarded with the permission of the manager or a person authorized by him. The recording may be used for the investigation of an occupational accident or for disciplinary proceedings in order to clarify the facts.

Access to stored recordings may only be done in a secure manner and in such a way that the data controller can be identified. The review of stored images and the backup of images must be documented. The data controller shall keep a record of the viewing of the recordings, the reason for viewing the recording, the time and place of viewing, and the person viewing the recording. The data controller may also record this record electronically.

Following the detection of an illegal act, measures must be taken to store the recording of the act and to immediately initiate the necessary official procedure, and the authority must also be informed that a video recording of the act was made.

7.4. Other data security measures: The recorded recordings are located on a separate hard drive in the recording device. No separate backup copy is made of the recordings, the storage period of which is the same as the retention period of the original image recording . Digitally recorded recordings can only be accessed from an external network with a strong password.

8. EXERCISE OF DATA RIGHTS

The exercise of data subject rights is facilitated by the application form in the appendix , which can be obtained from the data controller or downloaded from the website.

8.1. Right of access

The data subject has the right to request information about the processing of his or her personal data, the purpose, legal basis, duration of the processing, the criteria for determining the retention period, the circumstances and effects of the data protection incident affecting his or her personal data, the measures taken, the legal basis and purpose of the data transfer, the recipients of the data transfer, the rights of the data subject, the exercise of rights, and the method of enforcing rights.

8.2. Right to restrict (block) data processing

The data subject may request the blocking of the recording based on the procedural rules detailed in the previous point – i.e. that the Data Controller does not delete the recording – by referring to his/her legitimate interest within 3 days, i.e. before the automatic deletion. If the request is lawful, the later review of the affected part of the recording must be ensured. The Data Controller shall mark the affected part of the recording with a clear indication of the limited nature of the data processing and ensure its separate storage from other data.

The blocking lasts until the reason indicated by the data subject makes it necessary to store the data and there is no need for deletion.

the fact of blocking or its refusal – together with the reason for access, time and name of the person who accessed it. The data subject is obliged to verify his/her identity, however, the release of the recordings cannot be subject to any additional conditions (such as verification of his/her right or legitimate interest). After verifying the data subject’s identity, the Data Controller blocks or releases the recordings in accordance with the request.

The data controller is obliged to release the recordings if requested by a court or authority. However, the data controller may not release copies of recordings that contain personal data of other data subjects besides the applicant.

The Data Controller may not request the purpose of using the recording to be determined.

8.3. Right of access

The data subject may request access to the images taken of him or her within 3 days of the date the images were taken.

The recording cannot be deleted until a decision has been made on the request, so the request must be processed immediately. Access must be provided at a pre-arranged time, within 30 days of receipt of the request.

The data subject may request a copy of the recording provided that the rights of another data subject are not adversely affected.

8.4. Right to object

The data subject has the right to object to data processing by letter or e-mail addressed to the Data Controller's representative, if the legal basis for data processing is the Data Controller's legitimate interest. The data subject may also submit the request by properly completing the form in the appendix.

The manager or the person authorized by him/her shall decide on the request within 25 days of its receipt. The Data Controller shall justify the rejection of the request, and the data shall be blocked by the Data Controller until the decision is made. The objection to the data processing and the decision to do so shall not prevent the automatic deletion of the image recording.

8.5. Right to erasure

The data subject may request that the Data Controller delete the recording containing his/her personal data if the processing of his/her data is unlawful. The request will be decided by the CEO or a person authorized by him/her within 25 days.

8.6. Common rules for exercising data subject rights

The request can also be submitted by properly completing the form in the appendix, which the data subject can submit in person or electronically. The form facilitating the submission of the request is available from the data controller or on the website. The executive director will decide on the request.

If the request is not fulfilled, the reasons for this and the assessment of the request shall be provided in a clear and understandable form within the shortest possible time from the date of submission, but no later than 25 days, upon the request of the data subject in writing, or, if the request is submitted electronically, electronically. The person submitting the request shall be required to prove his/her identity by presenting his/her identity document. The refusal of the request shall be justified.

If it can be reasonably assumed that the person submitting a request for the enforcement of the data subject's rights is not the same person as the data subject, the Data Controller shall fulfill the data subject's request after credible verification of his/her identity. The Data Controller shall retain the data subject's personal data as per the annex for 5 years in order to assess the request and its subsequent provability, based on the legitimate interest of the Data Controller. The Data Controller shall store the submitted requests and the data controller's responses thereto as part of the minutes, attached to them, and the fact of issuing the recording and the personal identification data of the applicant shall be recorded in the minutes.

 

8.7. Further possibilities for legal remedies and enforcement of rights of the data subject

In the event of a violation of the right to the protection of the data subject's personal data and the exercise of the related rights, the data subject may seek legal redress in accordance with the provisions of Section 23 of the Infotv .

The data subject is also entitled to file a complaint with the National Data Protection and Freedom of Information Authority (1125 Budapest, Szilágyi Erzsébet fasor 22/C. 1530 Budapest, Pf. 5., Show E-mail address) in accordance with the provisions of Section 22 of the Infotv .

9. Procedure in case of a data protection incident

In the event of a data protection incident, the person who recognizes it must immediately report it to the executive, who will electronically report the data protection incident to the National Authority for Data Protection and Freedom of Information (NAIH) within 48 hours with the data content according to the electronic interface designed for this purpose. The data protection incident does not need to be reported if it is likely that it does not pose a risk to the enforcement of the rights of the data subjects.

Upon becoming aware of the incident, the executive shall immediately take the technical and organizational measures that are suitable for remedying the data protection incident and mitigating the damage caused. If the data protection incident is likely to have consequences that significantly affect the exercise of a fundamental right of the data subject, the data subject shall be informed of the data protection incident without delay.

10. Other provisions

These regulations enter into force on June 1, 2025.

The provisions of this regulation are to be reviewed annually by the manager or a person authorized by him/her, and in the event of a change in legislation, the regulation must be amended accordingly.

The manager or a person authorized by him/her is entitled to amend these regulations.

11. Attachments

Annex 1: Camera register

Annex 2: Balancing of interests test

Annex 3: Request for exercising the data subject's rights

Annex 1 Camera register

 

Cam ID

Camera location

Viewing angle direction

Purpose of observation

Kam01

Porta

South Korea

Asset protection

Kam02

Main entrance

N

Asset protection

Kam03

ATM 1

NW

Asset protection

Kam04

Barrier

N

Asset protection

Kam05

Ép1

N

Asset protection

Kam06

Ép4

WEDGE

Asset protection

Kam09

Ép9

SW

Asset protection

Kam10

Ép15

N

Asset protection

Kam11

Power plant 1

N

Asset protection

Kam12

Hengermalom Entrance

NY

Asset protection

Kam13

Power Plant 2

D

Asset protection

Kam14

Hengermalom Promenade

N

Asset protection

Kam15

Beach

NW

Asset protection

Kam18

Parking First Dome

K

Asset protection

Kam19

Pier 1.

WEDGE

Asset protection

Kam20

Pier 2.

SW

Asset protection

Kam21

Power Plant Promenade 1

N

Asset protection

Kam22

Power Plant Promenade 2

D

Asset protection

Kam23

Small bridge 1.

N

Asset protection

Kam24

Small bridge 2.

D

Asset protection

Kam25

Beach Promenade 1.

N

Asset protection

Kam26

Beach Promenade 2.

D

Asset protection

Kam27

Gate 1

N

Asset protection

Kam28

Gate 2

D

Asset protection

Kam29

Main Square 1

N

Asset protection

Kam30

Main Square 2

K

Asset protection

Kam31

Main Square 3

D

Asset protection

Kam32

BRD-1

N

Asset protection

Kam33

BRD-2

NY

Asset protection

Kam34

BRD-3

D

Asset protection

Kam35

Beach-South

N

Asset protection

Kam36

Strand-North

D

Asset protection

Kam37

BRB-BRD-1

K

Asset protection

Kam38

BRB-BRD-2

SW

Asset protection

Kam39

BRB-BRD- Bollard

NY

Asset protection

Kam40

BRB 1

N

Asset protection

Kam41

BRB 2

K

Asset protection

Kam42

BRB 3

N

Asset protection

Kam43

BRA 1

K

Asset protection

Kam44

BRA 2

D

Asset protection

Kam45

BRA 3

N

Asset protection

Kam46

BRA 4

D

Asset protection

Kam47

Pillar1

N

Asset protection

Kam48

Pillar2

K

Asset protection

Kam49

Pillar3

South Korea

Asset protection

Kam50

Pillar4

N

Asset protection

Kam51

Pillar5

K

Asset protection

Kam52

Pillar6

D

Asset protection

Kam53

Pillar7

K

Asset protection

Kam54

Pillar8

SW

Asset protection

Kam55

Radisson1

N

Asset protection

Kam56

Radisson2

D

Asset protection

57

New office BRG-BRF 1

N

Asset protection

58

New office BRG-BRF 2

NY

Asset protection

59

New office BRG-BRF 3

D

Asset protection

60

Sásliliom Bay Promenade 1

N

Asset protection

61

Sásliliom Bay Promenade 2

K

Asset protection

62

Sásliliom Bay Promenade 3

D

Asset protection

63

Sásliliom interior 1

N

Asset protection

64

Sásliliom interior 2

K

Asset protection

65

Sásliliom interior 3

NY

Asset protection

66

Sásliliom Biró László József körút 1

N

Asset protection

67

Sásliliom Biró László József körút 2

NY

Asset protection

68

Sásliliom Biró László József körút 3

K

Asset protection

69

E- on - dog walker 1

N

Asset protection

70

E- on - dog runner 2

D

Asset protection

71

E- on - dog walker 3

NY

Asset protection

72

Central Park 1

N

Asset protection

73

Central Park 2

NY

Asset protection

74

Central Park 3

K

Asset protection

75

Garda - Völgycsillag 1

K

Asset protection

76

Garda - Völgycsillag 2

NY

Asset protection

77

Garda - Völgycsillag 3

D

Asset protection

Annex 2: Balancing of interests test

BALANCE OF INTERESTS TEST

Company name: Kopaszi Gát Zrt.

Subject of the balancing test:

Weighing the interests of the entrepreneur and employees or other persons in relation to an electronic monitoring system operated by an entrepreneur

The purpose of the planned data processing is:

- protection of real estate and movables operated by the entrepreneur,

- ensuring the safety of persons and property in the property area,

- protection of assets located on the property (including parked vehicles),

- prevention of violations and crimes,

- assisting the competent authority in the event of a violation or crime

- protection of the life and physical integrity of employees

- filtering out sources of danger

- control and coordination of work processes

- storage of hazardous materials

- protection of raw materials and basic materials

- work-related behavior

Legal basis for the planned data processing:

Pursuant to Article 6(1)(f) of the GDPR, data processing is necessary for the purposes of the legitimate interests of the Contractor, unless these interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

The camera system falls under the scope of Act CXXXIII of 2005 on the rules of personal and property protection and private detective activities.

Persons affected by data processing :

- employees

- contractual (business) partners

  • visitors

Source of personal data:

Personal data is provided by the data subjects (by entering the property or by staying there)

Duration of data management: 3 days

Recipients of the data: persons determined by the manager

Guarantees undertaken by the Company before installing the system:

  • preliminary regulation of rights, entitlements and obligations (who, when and how can view the recordings, how long they are kept, how the data subjects can exercise their rights, etc.)
  • adherence to the principle of gradualism, i.e. always applying the solution with the least harm to interests and rights
  • requiring the data controller to follow procedures in accordance with internal camera regulations
  • a camera installation plan that takes into account the basic requirements for camera placement (cameras cannot be placed in the dining room, locker room, bathroom, the use of hidden cameras is prohibited, etc.) and takes maximum account of the protection of privacy.

- conducting a balance of interests test

FINDINGS

Opinions of stakeholders interviewed during the balancing test

No objections regarding the camera system were received by the test author during the test period. The camera is also considered necessary by employees
to prevent possible theft.

The legitimate interest of the Company

Protecting the property, buildings, assets and safety of the Company's employees, business partners and visitors, as well as its assets.

Reason: the need to install the camera system arose because

- crimes have already occurred that need to be prevented

- has a deterrent effect

Necessity of data processing :

In the opinion of the Company, the camera system is the most effective tool for preventing violations and crimes, and in the event of such an event, for detecting the events and finding the perpetrator, as well as initiating their prosecution. The camera system greatly assists in enforcing the property and personal safety of law-abiding persons.

Violation of the rights and freedoms of the data subjects:

The image rights of the data subjects may be violated during the recording, storage, viewing and other use of the recordings.

Balancing interests:

  • The protection of the Company's property is a fundamental right enshrined in the Fundamental Law.
  • Due to the limited storage period of the recordings and the strict regulation of rights, the rights of the data subjects are not violated
  • the system to be installed also serves the interests of the stakeholders, because it also promotes the personal and property protection of employees, business partners and visitors
  • The Company undertakes to include guarantees in its data protection policy, or in its special policy designed only for the camera system, that guarantee the protection of the rights of the data subjects.
  • The Company undertakes to prepare employee and visitor information regarding the camera system as carefully as possible and to make it available to the data subjects in order to protect the rights and freedoms of the data subjects.

FINDINGS OF THE BALANCE OF INTEREST TEST
 

The basis of data processing:

The Data Controller assesses that in the case of the camera system, the legal basis for data processing complies with the legitimate interest set out in Article 6(1)(f) of the GDPR, and that the interests or fundamental rights of the data subjects are not harmed in a way that would override the legitimate interest of the Company. The data processing is, in the opinion of the Data Controller, necessary (otherwise the personal and property protection purposes cannot be fully ensured) and proportionate (the infringement of the rights related to the person of the data subjects - the right to an image - is proportionate to the purpose). The legitimate interest of the Data Controller is therefore higher than the personal rights of the data subjects, and the Data Controller guarantees the protection of the rights of the data subjects.

The Company has decided to process personal data related to the camera system because it complies with Article 6(1)(f) of the GDPR in terms of legal basis.

 

 

Annex 3

Request to exercise the data subject's rights

Addressee:

Time of receipt/receipt of application:

Dear Address!

The undersigned,

Name of the person concerned:

Place and time of birth:

address:

contact information:

I wish to exercise the following rights in relation to the electronic monitoring system operated by the Data Controller:

request for information; request for blocking (restriction of data processing); request for access; request for deletion; objection

Exact location and time of recording: …………………………………………………...

I would like to inform you of the results of the application assessment in the following manner (email, post, on-site inspection):

…………………………………………………………………………………………..………………………

 

Please provide me with the following information regarding my personal data:

…………

…………

Please block my personal data provided above:

…………​

…………

 

Please provide access to my personal data provided above:

…………

…………

Please delete my personal data provided above:

…………

…………

I object to the processing of my personal data, for the following reasons:

…………

…………

My further comments:

…………

…………

I acknowledge that the Data Controller will process my personal data provided for 5 years based on its legitimate interest in fulfilling the request and in order to prove its fulfillment.

Date:

Name:

Signature: