Privacy policy
IT Squad Kft. - Privacy Notice
1. Introduction
Below we would like to inform you about the basic data processing carried out by IT Squad Kft. (registered seat: 1087 Budapest, Könyves Kálmán körút 76., company registration number: 01 09 430369, e-mail: hello@itsquad.hu) (hereinafter: the data controller) on the website itsquad.hu, as well as on the social media platforms owned by IT Squad Kft.
Legal basis of this privacy notice:
- Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation, better known as GDPR)
- Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (hereinafter: the Information Act)
Online platforms operated by the data controller:
- Website: https://www.itsquad.hu/
- Facebook: https://www.facebook.com/itsquadhu/
- LinkedIn: https://www.linkedin.com/company/67681253/
2. Definitions
2.1. The terms used in this Policy have the following meanings
2.1.1. "processor": a natural or legal person, public authority, agency, or any other body that processes personal data on behalf of the controller;
2.1.2. "processing": any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction;
2.1.3. "restriction of processing": the marking of stored personal data with the aim of limiting their processing in the future;
2.1.4. "controller": a natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by EU or member state law, the controller or the specific criteria for its designation may be provided for by that law;
2.1.5. "personal data breach": a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed;
2.1.6. "pseudonymisation": the processing of personal data in such a way that it can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures ensuring that the personal data is not attributed to an identified or identifiable natural person;
2.1.7. "recipient": a natural or legal person, public authority, agency, or other body to which personal data is disclosed, whether a third party or not. Public authorities that may receive personal data in the context of a particular inquiry in accordance with EU or member state law are not regarded as recipients; the processing of that data by those public authorities must comply with the applicable data protection rules according to the purposes of the processing;
2.1.8. "cookie": a cookie is a short text file sent by our web server to the data subject's device and read back from it. There are temporary (session) cookies that are automatically deleted from the device when the browser is closed, and longer-lived cookies that remain on the device for a longer period (this also depends on the device's settings);
2.1.9. "health data": personal data related to the physical or mental health of a natural person, including data on health care services provided to that person which reveal information about their health status;
2.1.10. "data subject": a person identified or (directly or indirectly) identifiable based on personal data, who must always be a specific person. Only natural persons qualify as data subjects, not legal persons, so data protection only protects the data of natural persons. However, data such as the phone number, email address, place, or date of birth of a sole trader or a company's representative also qualify as personal data;
2.1.11. "consent of the data subject": any freely given, specific, informed, and unambiguous indication of the data subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them;
2.1.12. "third party": a natural or legal person, public authority, agency, or other body other than the data subject, the controller, the processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data;
2.1.13. "third country": a country that is not a member state of the European Union or the European Economic Area. Member states of the European Union may conclude international agreements involving the transfer of personal data to third countries or international organizations, insofar as such agreements do not affect the GDPR or other provisions of EU law;
2.1.14. "profiling": any form of automated processing of personal data used to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements;
2.1.15. "personal data": any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person. Natural persons may also be associated with online identifiers provided by their devices, applications, tools, and protocols, such as IP addresses and cookie identifiers, as well as other identifiers such as radio frequency identification tags. This may leave traces which, in combination with unique identifiers and other information received by servers, may be used to create profiles of natural persons and identify them;
2.1.16. "international organization": an organization governed by public international law or any body subordinate to such an organization, or any other body set up by, or on the basis of, an agreement between two or more countries;
2.1.17. "filing system": any structured set of personal data which is accessible according to specific criteria, whether centralized, decentralized, or dispersed on a functional or geographical basis;
2.1.18. "enterprise": a natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity.
3. Principles relating to processing
The Controller processes personal data lawfully and fairly, in a transparent manner towards data subjects, for clear and lawful purposes defined in this Policy and its annexes ("purpose limitation"). Processing is limited to what is necessary for the Controller's purposes ("data minimization"). In accordance with the accuracy principle, the Controller ensures that the personal data it processes is up to date; to this end, the Controller takes every reasonable step to ensure that personal data which is inaccurate, having regard to the purposes of processing, is erased or rectified without delay ("accuracy"). The Controller acknowledges that personal data may only be stored for as long as necessary to achieve its purposes ("storage limitation"). The Controller processes data in a manner that ensures appropriate security of personal data through the use of appropriate technical or organizational measures, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage ("integrity and confidentiality"). To demonstrate compliance with these principles, the Controller keeps internal records of its processing activities ("accountability").
The principles set out in this Policy describe our practices regarding personal data. Our data processing principles apply to paper-based processing as well as to all devices, websites, customer service platforms, or other online applications operated by the Controller that link to them by hyperlink or otherwise. However, where this Policy refers to a separate privacy notice or policy for particular processing activities, we make that separate notice or policy available to data subjects. Such policies and notices form annexes to, and an integral part of, this Policy, and unless an annexed policy or notice expressly provides otherwise, the provisions of this Policy apply accordingly.
4. General information on data processing
4.1. Processing related to contact requests
4.1.1. The fact of data collection, the scope of data processed, and the purpose of processing:
- Personal data: first name, last name, email address, phone number.
- Purpose of processing: maintaining contact related to the controller's activities, and delivering news, information, and inquiries related to its professional and cultural activities to data subjects.
4.1.2. Data subjects concerned: all persons who contact the controller personally by phone, email, or on social media.
4.1.3. Duration of processing, deadline for erasure: 1 year following the contact.
4.1.4. Persons entitled to access the data, recipients of personal data: The personal data may be processed by the controller's authorized staff, in compliance with the above principles.
4.1.5. The data subject's rights regarding processing:
- The data subject may request access to, rectification of, erasure of, or restriction of processing of their personal data from the controller, and
- The data subject has the right to data portability and to withdraw consent at any time.
4.1.6. The data subject can initiate access to, erasure, modification, or restriction of processing of their personal data, and data portability, in the following ways:
- By post at 1087 Budapest, Könyves Kálmán körút 76.
- By phone at +36-30-247-22-22
- By email at hello@itsquad.hu
4.1.7. Legal basis of processing:
- Article 6(1)(b) and (c) GDPR;
- the data subject's consent to processing.
4.2. Processing related to marketing and PR activities
4.2.1. The fact of data collection, the scope of data processed, and the purpose of processing:
- Personal data: last name, first name, photograph, other information linked to the person.
- Purpose of processing: increasing the organization's visibility and recognition.
4.2.2. Data subjects concerned: all persons appearing in a post shared by the controller on any of its online platforms.
4.2.3. Duration of processing, deadline for erasure: one year following the sharing of the data.
4.2.4. Persons entitled to access the data, recipients of personal data: The personal data may be processed by the controller's authorized staff, in compliance with the above principles.
4.2.5. The data subject's rights regarding processing:
- The data subject may request access to, rectification of, erasure of, or restriction of processing of their personal data from the controller, and
- The data subject has the right to data portability and to withdraw consent at any time.
4.2.6. The data subject can initiate access to, erasure, modification, or restriction of processing of their personal data, and data portability, in the following ways:
- By post at 1087 Budapest, Könyves Kálmán körút 76.
- By phone at +36-30-247-22-22
- By email at hello@itsquad.hu
4.2.7. Legal basis of processing:
- Article 6(1)(b) and (c) GDPR;
- the data subject's consent to processing.
5. Processors engaged
5.1. Hosting provider
5.1.1. Activity carried out by the processor: hosting services.
5.1.2. Details of the processor:
- Name: BlazeArts Kft.
- Registered seat: 6090 Kunszentmiklós, Damjanich u. 36. 1/8
- Postal address: 6090 Kunszentmiklós, Damjanich u. 36. 1/8
- Phone: +36 1 610 5506
- Email: dpo@forpsi.hu / privacy@forpsi.hu
- Website: https://www.arubacloud.hu/
5.1.3. Fact of processing, scope of data processed: All personal data provided by the data subject.
5.1.4. Data subjects concerned: all users of the website.
5.1.5. Purpose of processing: Making the website available and ensuring its proper operation.
5.1.6. Duration of processing, deadline for erasure: Processing lasts until the agreement between the controller and the hosting provider ends, or until the data subject submits an erasure request to the hosting provider.
5.1.7. Legal basis of processing: Article 6(1)(f) GDPR, and Section 13/A(3) of Act CVIII of 2001 on certain aspects of electronic commerce services and information society services.
5.1.8. Rights of the data subject:
- You may obtain information about the circumstances of processing;
- You have the right to receive confirmation from the controller as to whether your personal data is being processed, and, if so, to access all information related to the processing;
- You have the right to receive your personal data in a structured, commonly used, machine-readable format. You have the right to request that the controller rectify inaccurate personal data without undue delay;
- You may object to the processing of your personal data.
5.2. Use of cookies
Detailed information on the use of cookies is provided in Annex 1.
5.3. Processing on social media platforms owned by the controller
5.3.1. Facebook page
- Page: https://www.facebook.com/itsquadhu/
- Facebook's privacy policy: https://www.facebook.com/policy.php
5.3.2. LinkedIn
- Company page: https://www.linkedin.com/company/67681253/
- LinkedIn's privacy policy: https://www.linkedin.com/legal/privacy-policy
6. Rights of the data subject
6.1. Right of access: the data subject has the right to obtain confirmation from the controller as to whether personal data concerning them is being processed, and, where that is the case, to access the personal data and the information listed in the Regulation.
6.2. Right to rectification: the data subject has the right to obtain from the controller, without undue delay, the rectification of inaccurate personal data concerning them. Having regard to the purposes of processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.
6.3. Right to erasure: the data subject has the right to obtain from the controller the erasure of personal data concerning them without undue delay, and the controller is obliged to erase such personal data without undue delay where certain conditions apply.
6.4. Right to be forgotten: where the controller has made the personal data public and is obliged to erase it, it takes reasonable steps, including technical measures (having regard to available technology and the cost of implementation), to inform controllers processing the data that the data subject has requested the erasure of any links to, or copies or replications of, that personal data.
6.5. Right to restriction of processing: the data subject has the right to obtain restriction of processing from the controller where one of the following applies:
- the data subject contests the accuracy of the personal data, for a period enabling the controller to verify its accuracy;
- the processing is unlawful and the data subject opposes erasure and requests restriction of use instead;
- the controller no longer needs the personal data for processing purposes, but it is required by the data subject for the establishment, exercise, or defense of legal claims;
- the data subject has objected to processing, pending verification of whether the controller's legitimate grounds override those of the data subject.
6.6. Right to data portability: the data subject has the right to receive personal data concerning them that they have provided to a controller in a structured, commonly used, machine-readable format, and has the right to transmit that data to another controller without hindrance from the controller to which the data was provided.
6.7. Right to object: the data subject has the right to object at any time, for reasons relating to their particular situation, to the processing of personal data concerning them, including profiling based on those provisions.
6.8. Objection in the case of direct marketing: where personal data is processed for direct marketing purposes, the data subject has the right to object at any time to the processing of personal data concerning them for such marketing, including profiling to the extent it relates to such direct marketing. Where the data subject objects to processing for direct marketing purposes, the personal data will no longer be processed for such purposes.
6.9. Automated individual decision-making, including profiling: the data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. The preceding paragraph does not apply if the decision:
- is necessary for entering into, or the performance of, a contract between the data subject and the controller;
- is authorized by EU or member state law to which the controller is subject and which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests; or
- is based on the data subject's explicit consent.
7. Time limit for action
The controller informs the data subject of any action taken on the above requests without undue delay, and in any event within 1 month of receipt of the request. This period may be extended by 2 further months where necessary.
The controller informs the data subject of any such extension, together with the reasons for the delay, within 1 month of receipt of the request.
If the controller does not take action on the data subject's request, it informs the data subject without delay, and at the latest within 1 month of receipt of the request, of the reasons for not taking action, and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.
8. Security of processing
Taking into account the state of the art and the cost of implementation, as well as the nature, scope, context, and purposes of processing, together with the varying likelihood and severity of the risk to the rights and freedoms of natural persons, the controller and the processor implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including, among others, where relevant:
- pseudonymisation and encryption of personal data;
- the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of the systems and services used to process personal data;
- the ability to restore the availability of, and access to, personal data in a timely manner in the event of a physical or technical incident;
- a process for regularly testing, assessing, and evaluating the effectiveness of technical and organizational measures taken to ensure the security of processing.
9. Communication of a personal data breach to the data subject
Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller communicates the breach to the data subject without undue delay.
The communication to the data subject describes, in clear and plain language, the nature of the personal data breach and includes the name and contact details of the data protection officer or other contact point from which further information can be obtained; it describes the likely consequences of the breach; and it describes the measures taken or proposed by the controller to address the breach, including, where appropriate, measures to mitigate its possible adverse effects.
Communication to the data subject is not required if any of the following conditions are met:
- the controller has implemented appropriate technical and organizational protection measures, applied to the data affected by the breach, in particular measures (such as encryption) that render the data unintelligible to any person not authorized to access it;
- the controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects is no longer likely to materialize;
- it would involve disproportionate effort, in which case the data subjects are informed instead through a public communication or a similarly effective measure.
Where the controller has not already communicated the breach to the data subject, the supervisory authority, having considered the likelihood of the breach resulting in a high risk, may require it to do so.
10. Notification of a personal data breach to the authority
The controller notifies a personal data breach to the competent supervisory authority under Article 55 without undue delay, and, where feasible, no later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification is not made within 72 hours, it must be accompanied by reasons for the delay.
11. Right to lodge a complaint
Complaints regarding any infringement by the controller may be lodged with the Hungarian National Authority for Data Protection and Freedom of Information:
- National Authority for Data Protection and Freedom of Information (NAIH)
- 1125 Budapest, Szilágyi Erzsébet fasor 22/C., Hungary
- Postal address: 1374 Budapest, Pf. 603., Hungary
- Phone: +36-1-391-1400
- Fax: +36-1-391-1410
- Email: ugyfelszolgalat@naih.hu
12. Annexes
12.1. Annex 1: Information on cookies
Effective from 1 July 2024
1. Identity of the controller
| Name | IT Squad Kft. |
| Registration number | 01 09 430369 |
| Tax number | 32555523-2-42 |
| Registered seat | 1087 Budapest, Könyves Kálmán körút 76. |
| Phone | +36 30 247 22 22 |
| hello@itsquad.hu |
2. Definitions
a. Meaning of "cookie": a "cookie" is a short text file sent by our web server to the data subject's device (whether a computer, mobile phone, or tablet) and read back from it. There are temporary (session) "cookies" that are automatically deleted from the device when the browser is closed, and longer-lived "cookies" that remain on the device for a longer period (this also depends on the device's settings).
3. Detailed provisions on cookies and similar files
In certain cases, itsquad.hu may also collect data that does not on its own allow identification of the data subject, but which may qualify as personal data in certain circumstances. Such data may include, among others, the data subject's IP address, the type of web browser, computer, and operating system used, language settings, internet service provider, or the name of an advertising domain from which the data subject reached, or through which they accessed, the website. This data is stored in a manner that does not allow identification of the data subject.
itsquad.hu uses "cookies" on the website in the following cases:
a. Strictly necessary "cookies": these cookies are necessary for users to browse our pages and use the services offered on the site. If the data subject closes their browser, these cookies are automatically deleted from their computer. Without these cookies, we cannot guarantee that the data subject will be able to use our website.
b. Remarketing "cookies": we use these cookies, among other things, to understand which of our pages data subjects visit, how and how often they use our pages, and how long they spend on a given page.
c. "Cookies" storing statistical data: the purpose of these cookies is to form user groups so that relevant advertisements and content can be displayed. The related process involves manual intervention. For more information on Google Analytics cookies, see Google's Analytics cookie information.
4. "Cookies" used by itsquad.hu
| Name | Description |
|---|---|
| Facebook pixel | If you are also logged into Facebook while visiting our site, we may target you with advertising on the Facebook advertising network based on this group. |
| Google Analytics - Audience measurement | An analytics tool that gives a picture of user behavior on our pages. It lets us see the number of users, time spent on the site, and estimated demographic data. |
| Cookie Law Info - Cookie consent | A tool that offers cookie consent and remembers the response given to it. |
Please note that if cookies are disabled, certain elements, or the full functionality of the website, may not be available.
5. "Cookie" settings
By default, every browser allows the use of cookies. If the data subject wants to delete cookies originating from our pages, or does not want to use them, please refer to the following links depending on which browser you use:
We also draw the data subject's attention to the fact that this "Cookie" notice forms part of the privacy notice covering the data processed by itsquad.hu.