Privacy notice
You can read Fireeng Kft.’s privacy policy in the document below.
Privacy policy
Effective from 2023 · Hungarian PDF · 15 pages
English translation of the 2023 policy
This is an unofficial English translation of the complete Hungarian policy supplied by Fireeng. The Hungarian PDF remains the original document and has not been changed. This translation preserves its statements, provider details and references as written in 2023; it is not an updated policy for the new website.
The source includes historical references to analytics, registration and newsletters, as well as some inconsistent names and addresses. Short translator’s notes identify these without changing the original statements. For the website’s current use of browser storage and the optional Google map, please read the current cookie policy.
1. Data processing
Fireeng Kft. (hereinafter: the Controller) hereby informs its partners about its practices concerning the processing of personal data, the organisational and technical measures taken to protect data, visitors’ related rights and the means of exercising those rights.
The Controller processes the data of individuals and companies connected with its operations in order to provide them with appropriate services.
The Controller intends to comply fully with the legal requirements governing the processing of personal data, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council.
This privacy notice has been prepared on the basis of Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons’ personal data and the free movement of such data, taking account of Act CXII of 2011 on Informational Self-Determination and Freedom of Information.
Controller
Name: Fireeng Kft.
Address: 2724 Újlengyel, Petőfi Sándor utca 48.
Tax number: 12458541-2-13
Company registration number: 13-09-225081
Telephone: +36 30 657 5262
Representative: György Decsi, Managing Director
Email: info@fireeng.hu
Names of processors
Server colocation services
Name: T-Systems Magyarország Zrt. – Adatpark Budapest
Address: 1087 Budapest, Asztalos Sándor út 13.
Telephone: 1400
Email: TS_ugyfelkapcsolat@t-systems.hu
Website: http://www.t-systems.hu/
Data stored: system logs and data stored in the CRM system.
Operations: rack cabinet services, provision of an Internet connection and power supply.
Web analytics, email and document management, calendar, telephone contacts, spreadsheet synchronisation and targeted advertising
Name: Google LLC
Address: 1 Hacker Way, Menlo Park, California 94025
Telephone: N/A
Email: N/A
Website: https://www.google.com/
Data stored: website visit data, correspondence, individual contracts and quotations, calendar entries, telephone contacts, data shared in spreadsheets according to filters, unique user identifiers and visitor identification cookies.
Operations: analysis of website visit data, A/B testing, email services, document management, calendar services, synchronisation of telephone contacts between devices, online spreadsheets and targeted advertising (retargeting).
Targeted advertising
Name: Facebook Inc.
Address: 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Telephone: +1 650-543-4800
Email: N/A
Website: https://www.facebook.com/
Data stored: website visit data, unique user identifiers and visitor identification cookies.
Operations: targeted advertising (retargeting).
Translator’s note: The Google and Facebook names and addresses above are reproduced exactly as paired in the 2023 source, including the apparent mismatch. They have not been updated or corrected in this translation.
Calendar and telephone contacts
Name: Apple Inc
Address: Apple Park, 1 Apple Park Way, Cupertino, California, U.S.
Telephone: +1 800 220325
Email: N/A
Website: https://www.apple.com/
Data stored: calendar entries and telephone contacts.
Operations: calendar services and synchronisation of telephone contacts between devices.
Encrypted static data and backups
Name: Amazon Web Services Ireland Ltd
Address: One Burlington Plaza, Burlington Road, Dublin, Ireland
Telephone: +1 (206) 266-1000
Email: N/A
Website: https://www.amazon.com/
Data stored: encrypted static files and encrypted backups.
Operations: provision of static storage (S3) and a content delivery network (CloudFront).
Customer service telephone exchange and call recording
Name: Arenim Technologies Kft.
Address: Infopark sétány 1, Building “I”, 1117 Budapest
Telephone: +36 1 8 555 666
Email: kapcsolat@arenimtel.com
Website: https://arenimtel.com/hu/
Data stored: metadata of customer service telephone calls and recorded telephone calls.
Operations: call routing, telephone exchange services and call recording.
Bulk SMS services
Name: Opennetworks Kft.
Address: Budapest, Fehérvári út 50–52., 2nd floor, 1117 Hungary
Telephone: +36-1-999-6000
Email: info@opennet.hu
Website: http://www.opennet.hu/
Data stored: telephone numbers, SMS message content and metadata.
Operations: bulk SMS services for all MiniCRM customers.
International bulk SMS services
Name: ComVision Sp. z o.o.
Address: Gliwice, Ul. Toszecka 10, 44-100, Poland
Telephone: +353 76 888 72 52
Email: support@smsapi.com
Website: https://www.smsapi.com/
Data stored: telephone numbers, SMS message content and metadata.
Operations: international bulk SMS services for all MiniCRM customers.
Accounting
Name: Irisz Office Zrt.
Address: H-1114 Budapest, Bartók Béla út 29., 1st floor, 4.
Telephone: +36 (1) 550 0510
Email: iroda@iriszoffice.hu
Website: www.iriszoffice.hu
Data stored: buyer and seller details shown on invoices, invoice line items and detailed invoice data.
Operations: bookkeeping and preparation of legally required reports and returns.
Online data reporting (invoicing)
Name: National Tax and Customs Administration (NAV)
Address: 1134 Budapest, Dózsa György út 128–132.
Telephone: +36-1-427-3200
Email: N/A
Website: https://www.nav.gov.hu/
Data stored: buyer and seller details shown on invoices, invoice line items and detailed invoice data.
Operations: online data reporting from the invoicing module, data analysis, risk analysis and official inspections.
2. Definitions
- GDPR (General Data Protection Regulation): the European Union’s data protection regulation.
- Processing: any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
- Personal data: any information relating to an identified or identifiable natural person (data subject). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data or online identifier, or to one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity.
- Controller: a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data. Where the purposes and means of processing are determined by Union or Member State law, the controller or the specific criteria for its designation may be provided for by Union or Member State law.
- Consent of the data subject: any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they signify agreement to the processing of personal data relating to them, by a statement or by clear affirmative action.
- Personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
- Recipient: a natural or legal person, public authority, agency or other body to which personal data are disclosed, whether or not it is a third party. Public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law are not regarded as recipients; their processing of those data must comply with the applicable data protection rules according to the purposes of the processing.
- Third party: a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
3. Principles of data processing
The Controller declares that it processes personal data as described in this notice and complies with the applicable legislation, paying particular attention to the following:
Personal data must be processed lawfully, fairly and in a manner transparent to the data subject.
Personal data may only be collected for specified, explicit and legitimate purposes.
The purpose of processing personal data must be appropriate and relevant, and processing must be limited to what is necessary.
Personal data must be accurate and up to date. Inaccurate personal data must be erased without delay.
Personal data must be stored in a form which permits identification of data subjects only for as long as necessary. Personal data may be stored for longer periods only where storage is for archiving in the public interest, scientific or historical research, or statistical purposes.
Personal data must be processed in a manner that ensures appropriate security through suitable technical or organisational measures, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.
The principles of data protection must apply to all information relating to an identified or identifiable natural person.
4. Categories of data processed
Partner data
When contacting Fireeng Kft., contact, billing and project data may be recorded. The Controller stores these in its own CRM system and invoicing software for subsequent contact and service-related purposes.
Registration or partner data
- Surname
- First name
- Job title
- Email address
- Company details (name, address, tax number, contact details, tax number and company registration number)
Newsletters are sent only with prior consent. The related data are:
- Surname
- First name
- Email address
Website-related data
When viewing the Fireeng Kft. website, the start and end times of the user’s visit may be recorded automatically, together with, in some cases and depending on the user’s computer settings, the type of browser and operating system. The system automatically generates statistical data from these records. The operator does not link these data to personal data. When a user logs in, the website sends a session ID which is deleted automatically upon leaving the website.
Data provided for use of the website are processed with the user’s voluntary consent.
Cookie
- Identifier of the page visited
Session cookie
Some cookies are essential to the functioning of the website and certain features, such as navigation. These are called session cookies. They do not collect information about users which could identify them (personal data), be used for marketing, or remember which other websites or subpages the user has visited. They are created when entering the website, stored on the serving server and deleted automatically when the browser window is closed or the browser is exited completely.
5. Important information about data processing
The Service Provider stores and processes data on its own computer, except for the database associated with operating the CRM system.
Newsletter
We send newsletters through the CRM system. Subscription to the newsletter may be made by a declaration.
The Controller does not store or process personal data in other ways, such as on paper.
Purpose of processing: to enable the Controller to provide appropriate additional services to its partners.
Legal basis: the data subject’s consent. Data subjects: users who subscribe to the newsletter.
Duration of processing: this always depends on the specific user purpose, but the data must be erased without delay once the original purpose has been fulfilled. Data subjects may withdraw their consent at any time by writing to the contact email address. Their data will then be erased unless there is a legal obstacle to erasure.
Persons entitled to access the data: the Controller.
Data subjects may ask the Controller for access to their personal data, rectification, erasure or restriction of processing, and may object to the processing of such personal data; they also have the right to data portability.
Data subjects may withdraw their consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Data subjects may exercise their right to lodge a complaint with a supervisory authority.
To use the benefits of registration, that is, the relevant service offered by the website, the data subject must provide the requested personal data. Data subjects are not obliged to provide personal data and will suffer no adverse consequences for not doing so. However, certain website functions cannot be used without registration.
Data subjects are entitled to have the Controller rectify or complete inaccurate personal data concerning them without undue delay upon request.
Data subjects are entitled to have the Controller erase inaccurate personal data concerning them without undue delay upon request. The Controller must erase personal data concerning the data subject without undue delay if there is no other legal basis for processing.
Changes to or erasure of personal data may be requested by email, telephone or post using the contact details given above.
Sending email
If you send us an email, we receive your email address and any other data you include, which we retain to maintain contact. This constitutes processing of personal data.
We store the personal data concerned in the inbox of the email program on our computer for at least one year, or until you request permanent deletion of the emails containing these personal data through any of our published contact channels.
By sending us an email, you accept our principles for processing personal data.
Purpose: providing additional services and establishing contact.
Legal basis: your consent.
Data subjects: persons who send email.
Duration: processing continues until consent is withdrawn. You may withdraw your consent at any time by writing to the contact email address.
Erasure: data are erased when consent to processing is withdrawn. You may withdraw consent at any time by writing to the contact email address.
Persons entitled to access the data: the Controller.
Storage method: electronic.
Changes to or erasure of personal data may be requested by email, telephone or post using the contact details given above.
Providing personal data is essential for identification and contact.
| Category of data | Specific purpose |
|---|---|
| Name | Identification, contact and invoicing. |
| Email address | Identification and contact. |
| Company details | Identification and contact. |
| Telephone number | Identification and contact. |
| Job title | Identification and contact. |
Sending a message using the contact form
Purpose: to allow visitors to send a message (email) conveniently to the website operator through the contact form without using an email program. The operator can only respond to the message or enquiry if it has contact details.
Legal basis: your consent.
Data subjects: visitors sending messages from the website.
Duration: processing continues until consent is withdrawn. You may withdraw your consent at any time by writing to the contact email address.
Erasure: data are erased when consent to processing is withdrawn. You may withdraw consent at any time by writing to the contact email address.
Persons entitled to access the data: the Controller.
Storage method: electronic.
Changes to or erasure of personal data may be requested by email, telephone or post using the contact details given above.
Providing personal data is essential for identification in databases and for contact.
| Category of data | Specific purpose |
|---|---|
| Name | Identification, contact and invoicing. |
| Email address | Identification and contact. |
| Company details | Identification and contact. |
| Telephone number | Identification and contact. |
| Job title | Identification and contact. |
Social networking sites
A social networking site is a media tool through which messages are distributed by social users. Social media use the Internet and online publishing opportunities to turn users from consumers of content into creators of content.
Social media are online applications containing user-generated content, such as Facebook, Google+, Twitter and others.
Social media appearances may include public speeches, lectures, presentations and descriptions of products or services.
Information published on social media may take the form of forums, blog posts, images, video and audio material, message boards, email messages and other forms.
Accordingly, the data processed may include the user’s public profile picture in addition to personal data.
Data subjects: all registered users.
Purpose of collection: promotion of the website or an associated webpage.
Legal basis: the data subject’s voluntary consent.
Duration of processing: according to the rules available on the relevant social networking site.
Erasure deadline: according to the rules available on that site.
Persons entitled to access the data: according to the rules available on that site.
Rights relating to processing: according to the rules available on that site.
Storage method: electronic.
It is important to bear in mind that when a user uploads or submits personal data, they grant the operator of the social networking site a worldwide licence to store and use such content. It is therefore very important to make sure that the user has full authority to disclose the information published.
Google Analytics
Our website uses Google Analytics.
Google Analytics uses first-party cookies to compile reports for its customers about website users’ behaviour.
On behalf of the website operator, Google uses this information to evaluate how users use the website. As an additional service, it prepares reports on website activity for the operator so that further services can be provided.
Google’s servers store the data in encoded form to make misuse more difficult and prevent it.
Google Analytics may be disabled as follows. The source quotes this explanation:
Website users who do not want Google Analytics JavaScript to report their data can install the Google Analytics opt-out browser add-on. The add-on prevents Google Analytics JavaScript (ga.js, analytics.js and dc.js) from sending information to Google Analytics. The add-on can be used in most newer browsers. The Google Analytics opt-out browser add-on does not prevent data being sent to the website itself or to other online analytics services.
Google’s privacy policy: https://policies.google.com/privacy?hl=hu
Detailed information about the use and protection of data is available through the links above.
Translator’s note: This subsection translates the 2023 document’s statements. It does not describe an enabled analytics feature on the new website. The current cookie policy describes the website’s actual browser storage and external services.
6. Data security measures
The Controller exercises the greatest possible care in processing and storing personal data.
The Controller operates its CRM system and website on the servers of the hosting company or companies identified in section 1.
The Hosting Provider is responsible for the storage and security of data on its hosting services under its contract with the Controller, and acts in accordance with its own privacy policy (see the Hosting Provider reference in section 1).
The Controller manages newsletters using the CRM service. The Newsletter Service Provider is responsible for the security of data stored on its servers and acts in accordance with its own privacy policy.
Electronic messages transmitted over the Internet, irrespective of protocol (email, web, FTP and others), are vulnerable to network threats that may lead to dishonest activity or the disclosure or modification of information. The Controller takes all precautions reasonably expected of it against such threats. However, it is generally known, including to users, that the Internet is not one hundred per cent secure. The Controller accepts no responsibility for damage caused by unavoidable attacks occurring despite the greatest care reasonably expected.
7. Purposes of data processing
Processing serves the purpose of maintaining ongoing contact between the Controller and its partners.
For the Controller’s website, recording and storing the time of a visit and the browser and operating system type serves statistical purposes only.
The Controller does not use personal data for purposes other than those specified. Data provided in this manner are processed with the user’s voluntary consent.
The Controller treats all data and facts concerning users confidentially and uses them exclusively to develop its services, sell advertising space, and carry out its own research and statistics. Reports based on these data are published only in a form that does not allow individual users to be identified.
8. Persons with access to the data and processors
The Controller may access personal data provided by users.
The Controller transfers personal data to third parties only with the user’s prior and informed consent. This does not apply to data transfers required by law.
The Controller is entitled and obliged to transmit to the competent authorities any personal data available to it and lawfully stored by it where such transmission is required by law or a final, binding order of an authority. The Controller cannot be held liable for such transmission or its consequences.
9. Responsibility of the controller
The Controller does not verify the personal data supplied to it. The person providing the data is solely responsible for their accuracy. By providing an email address, each user also accepts responsibility for ensuring that only they use the service through that address. Accordingly, all responsibility connected with logins using a given email address rests solely with the user who registered that address. A user providing personal data other than their own must obtain the data subject’s consent.
10. Rights relating to data processing
Right to request information
You may use the contact details provided to ask what data our company processes about you, on what legal basis, for what purpose, from what source and for how long. In response to your request, we will send information to the email address you provide without delay and within no more than 30 days.
Right to rectification
You may use the contact details provided to ask us to change your data. We will act on your request without delay and within no more than 30 days, and send information to the email address you provide.
Right to erasure
You may use the contact details provided to ask us to erase your data. We will do so without delay and within no more than 30 days, and send information to the email address you provide.
Right to blocking
You may use the contact details provided to ask us to block your data. Blocking remains in place for as long as the reason you specify makes storage necessary. We will act without delay and within no more than 30 days, and send information to the email address you provide.
Right to object
You may object to processing using the contact details provided. We will examine the objection as soon as possible after the request is submitted and within no more than 15 days, decide whether it is justified, and inform you of the decision by email.
Remedies concerning data processing
If you experience unlawful processing, please notify our company so that lawful conditions can be restored promptly. We will do everything we can in your interests to resolve the problem described.
If, in your view, lawful conditions cannot be restored, notify the authority using the following contact details:
National Authority for Data Protection and Freedom of Information
Postal address: 1530 Budapest, P.O. Box 5.
Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
Telephone: +36 (1) 391-1400
Fax: +36 (1) 391-1410
Email: ügyfelszolgalat (at) naih.hu
URL: https://naih.hu
Translator’s note: The authority’s contact details are retained from the 2023 source and may be outdated. Its linked official website can be consulted for current contact details.
11. Legislation underlying data processing
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing the 95/46/EC regulation (General Data Protection Regulation).
- Act CXII of 2011 on Informational Self-Determination and Freedom of Information.
- Act LXVI of 1995 on Public Records, Public Archives and the Protection of Private Archival Material.
- Government Decree 335/2005 (XII. 29.) on the General Requirements for Records Management by Bodies Performing Public Duties.
- Act CVm of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services.
Translator’s note: The source uses “regulation” for 95/46/EC and prints “CVm” in the final Act number. These source references are preserved here rather than silently corrected.
12. Legal remedies
A user who believes that the owner of www.tmke.hu has infringed their right to the protection of personal data may bring their claim before a civil court and may also contact the National Authority for Data Protection and Freedom of Information.
Translator’s note: The reference to www.tmke.hu appears in the original Fireeng document. It has been preserved as a source inconsistency and does not identify this website.
13. Information about threats to privacy
Use of the Internet involves various threats to privacy.
To protect your personal data, we recommend using PET (Privacy Enhancing Technologies). Information about these technologies is available on numerous websites.
14. Useful websites
Privacy Enhancing Technologies
- Privacy Enhancing Technologies: http://www.cdt.org
- Free Privacy Enhancing Technologies: http://wizards-of-os.org
Data protection information
- National Authority for Data Protection and Freedom of Information: http://www.naih.hu