Data Processing Policy

AK4.0 Hungary Kft. – hereinafter referred to as: Company – complies with the prior information obligation of the data subjects regarding the processing of personal data, as required by REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL, by publishing this data protection notice, according to which  each information pursuant to the relevant articles of the Regulation must be made available to the data subjects in a concise, transparent, understandable and easily accessible form, in a clear and comprehensible manner.

NAME OF THE DATA CONTROLLER

The Company informs the data subject that it is considered a data controller for the purposes of processing his/her personal data.

COMPANY NAME: AK4.0 Hungary Kft.

REGISTERED OFFICE: 1037 Budapest, Szépvölgyi út 49-55. E. ép. 2. em. 11. door

COMPANY REGISTRATION NUMBER: 01-09-438787

TAX NUMBER: 32714214-2-41

PHONE: +36 20 313 2153

NAME OF REPRESENTATIVE: Márton Molnár

E-MAIL: molnar.marton@ak40.hu

WEBSITE: www.ak40.hu

Personal data is processed by the Company’s employees with access rights related to the relevant data processing purpose, to the extent necessary for the performance of their activities, for the purposes indicated used appropriately.

DEFINITIONS

        • “personal data”:any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, a number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

        • “data processing”: any operation or set of operations which is performed on personal data or on data sets, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

        • “data restriction”: the marking of stored personal data with a view to limiting their future processing;

        • “profiling”: any form of automated processing of personal data which is performed on personal data or on data sets which is performed by automated means such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

personal data are used to evaluate certain personal characteristics relating to a natural person, in particular to analyse or predict characteristics relating to performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;

    • “pseudonymisation”: the processing of personal data in such a way that the personal data can no longer be identified without the use of additional information, provided that such additional information is stored separately and technical and organisational measures are taken to ensure that the personal data cannot be attributed to an identified or identifiable natural person;

    • “filing system”: a set of personal data, whether centralised, decentralised or organised along functional or geographical lines, which is accessible on the basis of specific criteria;

    • “controller” means the natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of the processing are determined by Union or Member State law, the controller or the specific aspects of the designation of the controller may also be determined by Union or Member State law;

    • “processor” means the natural or legal person, public authority, agency or any other body which processes personal data on behalf of the controller;

    • “recipient” means the natural or legal person, public authority, agency or any other body to which personal data are disclosed, whether or not a third party. Public authorities which have access to personal data in the context of an individual investigation in accordance with Union or Member State law shall not be considered recipients; the processing of such data by those public authorities must comply with the applicable data protection rules in accordance with the purposes of the processing;

    • ‘third party’ means a natural or legal person, public authority, agency or any other body other than the data subject, the controller, the processor or the persons who, under the direct control of the controller or the processor, are authorised to process personal data;

    • ‘consent of the data subject’ means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which the data subject, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;

    • ‘data breach’ means any breach of security leading to the accidental or unlawful destruction of personal data transmitted, stored or otherwise processed, results in the loss, alteration, unauthorized disclosure or unauthorized access to them;

    • “enterprise”: a natural or legal person engaged in economic activity, regardless of its legal form, including partnerships and associations engaged in regular economic activity.

LAWFUL BASIS OF DATA PROCESSING

    1. Consent of the data subject

In the case of data processing based on the data subject’s consent, the data subject may give his/her consent to the processing of his/her personal data – after appropriate prior information – in the following form:

    1. a) in writing, by means of a declaration giving consent to the processing of personal data in the form of,

    1. b) electronically, by explicit conduct on the Company’s website, by ticking a checkbox, or by making relevant technical settings when using information society services, as well as any other statement or act which, in a given context, clearly indicates the data subject’s consent to the planned processing of his or her personal data.

Silence, a pre-ticked box or inaction therefore does not constitute consent.

Consent covers all data processing activities carried out for the same purpose or purposes.

If data processing serves several purposes at the same time, consent must be given for all data processing purposes. If the data subject gives his/her consent following an electronic request, the request must be clear and concise and must not unnecessarily hinder the use of the service for which the consent is requested.

The data subject shall have the right to withdraw his/her consent at any time. The withdrawal of consent shall not affect the lawfulness of the processing based on consent prior to its withdrawal. The data subject shall be informed of this before giving consent. The withdrawal of consent must be made as easy as its granting.

    1. Performance of a contract

    • Data processing is lawful if it is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the data subject’s request prior to entering into a contract.

    • The data subject’s consent to the processing of personal data that is not necessary for the performance of a contract shall not be a condition for entering into a contract.

    1. Compliance with a legal obligation applicable to the data controller, or the protection of the vital interests of the data subject or another natural person

    • The legal basis for data processing is determined by law in the case of compliance with a legal obligation, so the data subject’s consent is not required for the processing of their personal data.

    • The data controller is obliged to inform the data subject about the purpose, legal basis, duration of data processing, the identity of the data controller, as well as their rights and legal remedies.

    • In order to comply with a legal obligation, the data controller is entitled to process the data set that is necessary for the fulfillment of a legal obligation applicable to it after the data subject’s consent has been withdrawn.

    1. Enforcement of the legitimate interests of the data controller or a third party.

    • The legitimate interests of the controller – including the controller to whom the personal data may be disclosed – or of a third party may constitute a legal basis for the processing, provided that the interests, fundamental rights and freedoms of the data subject are not overridden, taking into account the reasonable expectations of the data subject in the light of his or her relationship with the controller. Such a legitimate interest may exist, for example, where there is a relevant and appropriate relationship between the data subject and the controller, for example in cases where the data subject is a client or employee of the controller.

    • To determine the existence of a legitimate interest, it is necessary to carefully examine, in the form of a balancing test, whether the data subject can reasonably expect, at the time of collection of the personal data and in the context thereof, that the data may be processed for the given purpose.

    • The interests and fundamental rights of the data subject may take precedence over the interests of the data controller if the personal data are processed in circumstances in which the data subjects do not expect further processing.

RELATED TO THE PROCESSING OF THE DATA OF THE DATA SUBJECT RIGHTS

    1. The Company provides the following information in brief on the rights of the data subject:

The data subject has the right:

    • to be informed before the start of data processing,

    • to receive feedback from the data controller as to whether his/her personal data is being processed, and if such data processing is in progress, he/she is entitled to access the personal data and the following information,

    • to request correction or deletion of his/her data, to receive notification from the data controller of this,

    • to request restriction of data processing, to receive notification from the data controller of this,

    • to data portability,

    • to object, if your personal data are processed for public interest purposes or with reference to the legitimate interests of the data controller.

    • to be exempt from automated decision-making, including profiling, unless you have given your prior consent,

    • to contact a court with jurisdiction and competence in accordance with the Pp. The court shall proceed with the matter without delay.

    • to lodge a complaint with the supervisory authority. The data subject may exercise his or her right to lodge a complaint at the following contact details: National Data Protection and Freedom of Information Authority, address: 1055 Budapest, Falk Miksa utca 9-11.,  postal address: 1363 Budapest, Pf.: 9. telephone: +36 (1) 391-1400; fax: +36(1)391-1410. https://www.naih.hu  e-mail: ugyfelszolgalat@naih.hu

    • to have an effective judicial remedy against the supervisory authority,

    • to be informed about a data protection incident.

    1. Detailed information on the rights of the data subject

Right to information

The data subject has the right to receive information about the data processing before the start of the activity aimed at processing his/her data.

Information to be provided if personal data are collected from the data subject:

    • to the data controller and – if any – the data controller’s representative identity and contact details;

    • contact details of the data protection officer, if any;

    • the purpose of the intended processing of the personal data and the legal basis for the processing;

    • in the case of processing based on point (f) of Article 6(1) of the Regulation, the legitimate interests of the controller or of a third party;

    • where applicable, the recipients of the personal data or, where applicable, the categories of recipients;

    • where applicable, the fact that the controller intends to transfer the personal data to a third country or to an international organisation, and the existence or absence of an adequacy decision by the Commission or, in the case of transfers referred to in Articles 46, 47 or the second subparagraph of Article 49(1) of the Regulation, an indication of the appropriate and suitable safeguards and a reference to the means of obtaining a copy of them or their accessibility.

In addition to the information referred to in the first paragraph, the controller shall, at the time of obtaining the personal data, provide the data subject with the following additional information in order to ensure fair and transparent processing: informs:

    • the duration of the storage of personal data or, where that is not possible, the criteria for determining that duration;

    • the right of the data subject to request from the controller access to, rectification, erasure or restriction of processing of personal data concerning him or her, and to object to the processing of such personal data, as well as the right of the data subject to data portability;

    • in the case of processing based on Article 6(1)(a) or Article 9(2)(a) of the Regulation, the right to withdraw consent at any time, without affecting the lawfulness of the processing carried out on the basis of consent before its withdrawal;

    • the right to lodge a complaint with a supervisory authority;

    • whether the provision of personal data is based on a legal or contractual obligation or is necessary for the performance of a contract whether it is a prerequisite and whether the data subject is obliged to provide the personal data and the possible consequences of not providing the data;

    • the fact of automated decision-making referred to in Article 22(1) and (4) of the Regulation, including profiling, and at least in such cases, intelligible information about the logic involved and the significance and foreseeable consequences of such processing for the data subject.

If the personal data have not been obtained from the data subject, the data controller shall provide the data subject with the following information:

    • the identity and contact details of the controller and, if any, of the controller’s representative;

    • the contact details of the data protection officer, if any;

    • the purposes of the intended processing of the personal data and the purposes of the processing legal basis;

    • the categories of personal data concerned;

    • the recipients of the personal data or, if applicable, the categories of recipients;

    • where applicable, the fact that the controller intends to transfer the personal data to a recipient in a third country or to an international organisation, and the existence or absence of an adequacy decision by the Commission or, in the case of transfers referred to in Article 46, Article 47 of the Regulation or the second subparagraph of Article 49(1), an indication of the appropriate and suitable safeguards and a reference to the means of obtaining a copy of them or their accessibility.

In addition to the information referred to in the first paragraph, the controller shall provide the data subject with the following additional information necessary to ensure fair and transparent processing for the data subject:

    • the period for which the personal data will be stored, or, if this is not the case, the period for which the personal data will be stored, or, if this is not the case, the period for which the personal data will be stored, possible, the criteria for determining this period;

    • where the processing is based on point (f) of Article 6(1) of the Regulation, the legitimate interests of the controller or a third party;

    • the right of the data subject to request from the controller access to, rectification, erasure or restriction of processing of personal data concerning him or her, and to object to the processing of personal data, as well as the right of the data subject to data portability;

    • in the case of processing based on point (a) of Article 6(1) or point (a) of Article 9(2) of the Regulation, the right to withdraw consent at any time, without affecting the lawfulness of the processing carried out on the basis of consent before its withdrawal;

    • the right to lodge a complaint with a supervisory authority;

    • the source of the personal data and, where applicable, whether the data originate from publicly available sources; and

    • the fact of automated decision-making referred to in Article 22(1) and (4) of the Regulation, including profiling, and at least in those cases, intelligible information on the logic involved and the significance and foreseeable consequences of such processing for the data subject.

Where the controller intends to process personal data for purposes other than those for which they were obtained, the controller shall inform the data subject of that purpose and of any relevant additional information referred to in paragraph (2) prior to the further processing.

Paragraphs (1) to (3) shall not apply if and to the extent that:

    • the data subject already has the information;

    • providing the information in question proves impossible or would involve a disproportionate effort, in particular where archiving in the public interest is required for scientific and historical research purposes or statistical purposes, subject to the conditions and safeguards set out in Article 89(1), or where the obligation referred to in paragraph 1 of this Article is likely to render impossible or seriously jeopardise the achievement of the purposes of such processing. In such cases, the controller shall take suitable measures to safeguard the rights, freedoms and legitimate interests of the data subject, including making the information publicly available;

    • the collection or disclosure of the data is expressly provided for by Union or Member State law to which the controller is subject, which provides for suitable measures to safeguard the legitimate interests of the data subject; or

    • the personal data must remain confidential by virtue of a professional secrecy obligation laid down in Union or Member State law, including a statutory obligation of confidentiality.

Right of access of the data subject

The data subject shall have the right to obtain from the controller information as to whether or not personal data concerning him or her are being processed and, where such processing is taking place, access to the personal data and the following information:

    • the purposes of the processing;

    • the categories of personal data concerned;

    • the recipients or categories of recipients to whom the personal data have been or will be disclosed, including in particular recipients in third countries or international organisations;

    • where applicable, the personal data the planned storage period or, where that is not possible, the criteria for determining that period;

    • the right of the data subject to obtain from the controller rectification, erasure or restriction of processing of personal data concerning him or her and to object to the processing of such personal data;

    • the right to lodge a complaint with a supervisory authority;

    • where the data were not collected from the data subject, all available information on their source;

    • the fact of automated decision-making referred to in Article 22(1) and (4) of the Regulation, including profiling, and at least in those cases, intelligible information on the logic involved and the significance and foreseeable consequences of such processing for the data subject.

Where personal data are transferred to a third country or to an international organisation, the data subject shall have the right to be informed of the transfer. on the appropriate safeguards pursuant to Article 46.

The controller shall provide the data subject with a copy of the personal data which are the subject of the processing. For further copies requested by the data subject, the controller may charge a reasonable fee based on the administrative costs. If the data subject has submitted the request electronically, the information shall be provided in a commonly used electronic format, unless the data subject requests otherwise.

The data subject’s right to rectification and erasure

Right to rectification

The data subject shall have the right to obtain from the controller, at his request, the rectification of inaccurate personal data concerning him or her without undue delay. Taking into account the purposes of the processing, the data subject shall have the right to request the completion of incomplete personal data, including by means of a supplementary statement.

Right to erasure (‘right to be forgotten’)

The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay, and the controller shall be obliged to erase personal data concerning him or her without undue delay where one of the following grounds applies:

    • the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;

    • the data subject withdraws his or her consent to the processing pursuant to point (a) of Article 6(1) of the Regulation (consent to the processing of personal data) or point (a) of Article 9(2) of the Regulation (specific consent) and there is no other legal basis for the processing;

    • the data subject objects to the processing pursuant to point (a) of Article 21(1) of the Regulation (right to object) right) objects to the processing of his or her personal data and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2) of the Regulation (objection to processing for commercial purposes);

    • the personal data have been processed unlawfully;

    • the personal data must be erased for compliance with a legal obligation under Union or Member State law to which the controller is subject;

    • the personal data were collected in connection with the offering of information society services referred to in Article 8(1).

Where the controller has made the personal data public and is required to erase them at the request of the data subject, the controller, taking into account available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform the controllers processing the personal data that the data subject has requested access to the personal data in question. or the erasure of links to or copies or replications of those personal data.

Paragraphs (1) and (2) shall not apply where processing is necessary:

    • for the exercise of the right to freedom of expression and information;

    • for compliance with an obligation to which the controller is subject under Union or Member State law to which the controller is subject under which the personal data are processed or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

    • for reasons of public interest in the field of public health in accordance with points (h) and (i) of Article 9(2) of the Regulation and Article 9(3) of the Regulation;

    • for archiving purposes in the public interest, scientific and historical research purposes or statistical purposes in accordance with Article 89(1) of the Regulation, where the the right referred to in paragraph (1) would likely render impossible or seriously jeopardise such processing; or

    • for the establishment, exercise or defence of legal claims.

Right to restriction of processing

The data subject shall have the right to obtain from the controller restriction of processing where one of the following applies:

    • the data subject contests the accuracy of the personal data, in which case the restriction shall apply for a period enabling the controller to verify the accuracy of the personal data;

    • the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead;

    • the data controller no longer needs the personal data for the purposes of the processing, but the data subject requires them for the establishment, exercise or defence of legal claims; or

    • the data subject has objected to the processing pursuant to Article 21(1) of the Regulation; in such case, the restriction shall apply for a period of time until it is determined whether the legitimate grounds of the controller override those of the data subject.

If processing is subject to restriction pursuant to paragraph (1), such personal data may, with the exception of storage, only be processed with the data subject’s consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for important public interest reasons of the Union or of a Member State.

The controller shall inform the data subject at whose request the processing has been restricted pursuant to paragraph (1) in advance of the lifting of the restriction of the processing.

Notification obligation in relation to the rectification or erasure of personal data or the restriction of processing

The controller shall inform any recipient to whom or with whom the personal data have been disclosed of the rectification, erasure or restriction of processing, unless this proves impossible or involves a disproportionate effort.

Upon request, the controller shall inform the data subject of these recipients.

Right to data portability

The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format and shall have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where

    • the processing is based on point (a) of Article 6(1) of the Regulation (the data subject’s consent to the processing of personal data)

    • or on Article 9 of the Regulation. (2) point (a) of Article 6(1)(b) of the GDPR (the data subject’s express consent to the processing),

    • or is based on a contract pursuant to Article 6(1)(b); and the processing is carried out by automated means.

When exercising the right to data portability pursuant to paragraph (1), the data subject shall have the right to request the direct transmission of personal data between controllers, where technically feasible.

The exercise of the right referred to in paragraph (1) of this Article shall be without prejudice to Article 17 of the Regulation. This right shall not apply where the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

The right referred to in paragraph 1 shall not adversely affect the rights and freedoms of others.

Right to object

    • The data subject shall have the right to object at any time, on grounds relating to his or her particular situation, to processing of personal data concerning him or her carried out in the public interest or in the exercise of official authority vested in him or her, or to processing necessary for the purposes of the legitimate interests pursued by the controller or by a third party (processing based on point (e) or (f) of Article 6(1) of the Regulation), including profiling based on those provisions. In this case, the controller shall not process the personal data any further, unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.

    • Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such purposes, including profiling where such processing is related to direct marketing.

    • If the data subject objects to the processing of personal data for direct marketing purposes, the personal data shall no longer be processed for such purposes.

    • The right referred to in paragraphs (1) and (2) shall be expressly brought to the attention of the data subject at the latest when the data subject is first contacted and the information relating to it shall be displayed clearly and separately from any other information.

    • The information in relation to the use of services related to society and by way of derogation from Directive 2002/58/EC, the data subject may also exercise the right to object by automated means based on technical specifications.

    • Where personal data are processed for scientific and historical research purposes or for statistical purposes in accordance with Article 89(1) of the Regulation, the data subject shall have the right to object, on grounds relating to his or her particular situation, to processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out for reasons of public interest.

Right to be exempted from automated decision-making

The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.

Paragraph 1 shall not apply where the decision:

    • necessary for entering into, or the performance of, a contract between the data subject and the controller;

    • is permitted by Union or Member State law applicable to the controller and which also lays down suitable measures to safeguard the data subject’s rights and freedoms and legitimate interests; or

    • based on the explicit consent of the data subject.

In the cases referred to in points (a) and (c) of paragraph 2, the controller shall implement suitable measures to safeguard the rights, freedoms and legitimate interests of the data subject, including at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to object to the decision.

The decisions referred to in paragraph 2 shall not be based on special categories of personal data referred to in Article 9(1) of the Regulation, unless point (a) or (g) of Article 9(2) applies and suitable measures are taken to safeguard the rights, freedoms and legitimate interests of the data subject.

Right of the data subject to lodge a complaint and obtain a remedy

Right to lodge a complaint with a supervisory authority.

The data subject shall have the right to Pursuant to Article 77 of the Regulation, the data subject has the right to lodge a complaint with the supervisory authority if, in the opinion of the data subject, the processing of personal data concerning him or her infringes this Regulation.

The data subject may exercise his or her right to lodge a complaint at the following contact details:

National Authority for Data Protection and Freedom of Information  address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c  Telephone: +36 (1) 391-1400;  Fax: +36 (1) 391-1410  www: https://www.naih.hu  e-mail: ugyfelszolgalat@naih.hu

The supervisory authority to which the complaint has been submitted shall inform the customer of the procedural developments related to the complaint and its outcome, including the fact that the customer has the right to a judicial remedy pursuant to Article 78 of the Regulation.

Right to an effective judicial remedy against the supervisory authority

    • Without prejudice to other administrative or non-judicial remedies, every natural and legal person shall have the right to an effective judicial remedy against a legally binding decision of the supervisory authority concerning him or her.

    • Without prejudice to other administrative or non-judicial remedies, every data subject shall have the right to an effective judicial remedy if the competent supervisory authority does not deal with the complaint, or fails to inform the data subject within three months of the progress of the procedure or the outcome of a complaint lodged pursuant to Article 77 of the Regulation.

    • The proceedings against the supervisory authority shall be brought before the courts of the Member State in which the supervisory authority is established.

    • If proceedings are brought against a decision of the supervisory authority on which the Board has previously issued an opinion or taken a decision under the consistency mechanism, the supervisory authority shall be obliged to send that opinion or decision to the court.

Right to an effective judicial remedy against the controller or processor

Without prejudice to any administrative or non-judicial remedies available to it, including the right to lodge a complaint with the supervisory authority pursuant to Article 77, each data subject shall have the right to an effective judicial remedy where, in his or her opinion, the the rights under this Regulation have been infringed as a result of the processing of personal data in accordance with this Regulation.

Procedures against the controller or processor shall be brought before the courts of the Member State in which the controller or processor is established. Such proceedings may also be brought before the courts of the Member State in which the data subject has his or her habitual residence, unless the controller or processor is a public authority of a Member State acting in the exercise of its official authority.

Restrictions

Union or Member State law applicable to the controller or processor may, by means of legislative measures, restrict the freedoms provided for in Articles 12 to 22 and 34 and in Articles 12 to 22. the scope of the rights and obligations set out in Article 5, if the limitation respects the essence of the fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society to protect:

    • national security;

    • homeland defence;

    • public security;

    • the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security;

    • other important objectives of general public interest of the Union or of a Member State, in particular important economic or financial interests of the Union or of a Member State, including monetary, budgetary and taxation matters, public health and social security;

    • the protection of the independence of the judiciary and of judicial proceedings;

    • in the case of regulated professions, the prevention, investigation, detection and prosecution of ethical misconduct;

    • in the cases referred to in points (a) to (e) and (g), even occasionally, monitoring, inspection or regulatory activities connected with the exercise of official authority;

    • the protection of the data subject or the rights and freedoms of others;

    • the enforcement of civil law claims.

The legislative measures referred to in paragraph 1 shall contain detailed provisions, where appropriate. at least:

    • the purposes of the processing or the categories of processing,

    • the categories of personal data,

    • the scope of the restrictions imposed,

    • the safeguards against misuse or unauthorised access or transfer,

    • the identification of the controller or categories of controllers,

    • the duration of the data storage and the applicable safeguards, taking into account the nature, scope and purposes of the processing or categories of processing,

    • the risks to the rights and freedoms of the data subjects, and

    • the right of the data subjects to be informed of the restriction, unless this would adversely affect the purpose of the restriction.

About the data breach communication

Where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.

The communication referred to in paragraph 1 to the data subject shall describe in a clear and intelligible manner the nature of the personal data breach and shall include at least the

name and contact details of the data protection officer or other contact person who can provide further information, the likely consequences of the personal data breach, the measures taken or planned by the controller to remedy the personal data breach, including, where appropriate, measures to mitigate any adverse consequences resulting from the personal data breach.

The data subject shall not be required to be informed as referred to in paragraph 1 if any of the following conditions are met:

    • the controller has has implemented technical and organisational protection measures and these measures have been applied to the data affected by the personal data breach, in particular measures such as the use of encryption which render the data unintelligible to persons not authorised to access the personal data;

    • the controller has taken additional measures following the personal data breach to ensure that the high risk to the rights and freedoms of the data subject referred to in paragraph 1 is unlikely to materialise in the future;

    • the provision of information would involve a disproportionate effort. In such cases, the data subjects shall be informed by means of publicly published information or a similar measure shall be taken that ensures similarly effective information of the data subjects.

If the data controller has not yet notified the data subject of the data breach, the supervisory authority may, after considering whether the data breach is likely to involve a high risk, order the data subject to be informed or determine that one of the conditions referred to in paragraph (3) is met.

PROCEDURE TO BE APPLIED IN THE CASE OF A DATA SUBJECT’S REQUEST

The Company shall facilitate the exercise of the data subject’s rights and shall not refuse to comply with the data subject’s request to exercise the rights set out in this data protection notice, unless it proves that it is unable to identify the data subject.

The Company shall inform the data subject of the action taken on the request without undue delay, but in any case within one month of receipt of the request. If necessary, taking into account the complexity of the request and the number of requests, this deadline may be extended by a further two months. The data controller shall inform the data subject of the extension of the deadline, indicating the reasons for the delay, within one month of receipt of the request.

If the data subject submitted the request electronically, the information shall be provided electronically, if possible, unless the data subject requests otherwise.

If the Company does not take action following the data subject’s request, it shall inform the data subject without delay, but no later than one month from receipt of the request, of the reasons for the failure to take action, and of the fact that the data subject may file a complaint with the supervisory authority and exercise his/her right to judicial remedy.

The Company shall provide the data subject with the following information and measures free of charge: feedback on the processing of personal data, access to the processed data, rectification, completion, deletion of data, restriction of data processing, data portability, objection to data processing, notification of a data protection incident information.

If the data subject’s request is manifestly unfounded or, in particular, excessive due to its repetitive nature, the data controller may, taking into account the administrative costs of providing the requested information or taking the requested action: charge a fee of HUF 15,000 or refuse to take action on the request.

The burden of proving that the request is manifestly unfounded or excessive shall lie with the data controller.

Without prejudice to Article 11 of the Regulation, if the data controller has reasonable doubts as to whether the data subject has complied with the requirements of Articles 15 to 21 of the Regulation. in relation to the identity of the natural person submitting the request pursuant to Article 1, may request the provision of additional information necessary to confirm the identity of the data subject.

DATA PROCESSING RELATED TO THE WEBSITE

Information regarding the data of visitors to the Company’s website

During visits to the Company’s website, one or more cookies – small information packages that the server sends to the browser, and then the browser sends back to the server for each request directed to the server – are sent to the computer of the person visiting the website, through which their browser will be uniquely identified, if the person visiting the website has given their express (active) consent to this by their behavior of continuing to browse the website after being clearly and unambiguously informed.

The The exact scope of the use of cookies is contained in a separate information.

Registration, newsletter subscription

In the case of registration or newsletter subscription, the legal basis for data processing is the consent of the data subject, which the data subject provides by checking the box next to the “registration” or “newsletter subscription” text section on the Company’s website after receiving information about the processing of their data.

In the case of registration or newsletter subscription: all natural persons who subscribe to the Company’s newsletter or register on the website and give their consent to the processing of their personal data.

The scope of the processed data in the case of newsletter subscription: full name,  e-mail address.

In the case of registration:  full name, registered office, contact person’s name, address,  e-mail address, telephone number, activity, size of the farm, form of business, tax number or tax identification number

The purpose of data processing in the case of newsletter subscription: informing the data subject about the Company’s services, products, changes in them, news, events.

The purpose of data processing in the case of registration: contacting in order to prepare for concluding a contract, providing services available free of charge on the website to the data subject, access to non-public content of the website.

The recipients of the data (who may see the data) in the case of newsletter subscription and registration: the manager of the Company, his/her employees in charge of customer relations.

Data processor:

ABZ Drone Kft.

2000 Szentendre, Kalászi út 3.

The duration of data processing in the case of newsletter subscription and registration: until the consent is withdrawn. In the case of newsletter subscription, until unsubscription, in the case of registration, until deletion at the request of the data subject.

The data subject may unsubscribe from the newsletter at any time or request the deletion of their registration (personal data). The newsletter can be unsubscribed by clicking on the unsubscribe link in the footer of the e-mails sent to the data subject, or by sending a letter to the registered office of the Company.

Data processing related to direct marketing activities

The legal basis for the Company’s data processing for direct marketing purposes is the data subject’s consent, which is clear and explicit. The data subject provides his clear, explicit prior consent by checking the box next to the text section “Consent to direct marketing inquiries” on the Company’s website after receiving information about the processing of his data.

The data subject can also provide his consent on paper, in accordance with Article 2 of these regulations. by filling out the data form attached to this document.

The affected group: any natural person who gives their clear, express consent to the Company processing their personal data for direct marketing purposes.

The purposes of data processing: maintaining contact with the Company for the purpose of providing services, sending advertisements, offers related to product sales, and notifying about promotions, electronically or by post.

The recipients of personal data: the manager of the Company, employees performing customer service tasks and marketing tasks based on their job.

The scope of personal data processed: name, address, telephone number, e-mail address.

The duration of data processing: the processing of personal data for direct marketing purposes until the data subject withdraws it.

DATA PROCESSING ACTIVITIES RELATED TO THE PERFORMANCE OF A CONTRACT

The Company processes the personal data of natural persons contracting with it – clients, buyers, suppliers, including sole proprietors – in connection with the contractual relationship. The data subject must be informed about the processing of personal data.

The scope of data subjects: all natural persons who establish a contractual relationship with the Company.

The legal basis for data processing is the performance of a contract, the purpose of data processing is to maintain contact, enforce claims arising from the contract, and ensure compliance with contractual obligations.

The recipients of personal data: the manager of the Company, the employees of the Company performing customer service and accounting tasks based on their job, and data processors.

The scope of personal data processed: name, address, registered office, telephone number, e-mail address, tax number, bank account number, entrepreneur ID number, primary producer ID number.

The duration of data processing: 5 years from the termination of the contract.

FOR DATA PROCESSORS AND JOINT DATA PROCESSORS RELATED INFORMATION

The Company informs the data subjects that the following data processors act in connection with some of its data processing:

    • ABZ Drone Kft.; registered office: 2000 Szentendre, Kalászi út 3.; name of the data processing in which the data processor is involved: sending a newsletter

The Company informs the data subjects that the following joint data controllers act in connection with some of its data processing:

    • Szijártó Marcell Law Firm (registered office: 1051 Budapest, József nádor tér 9. II. em. 3.); providing legal advice within the framework of the Young Farmer Mentor Program

    • Gábor Doviscsák, individual lawyer (registered office: 1051 Budapest, József nádor tér 9. II. em. 3.); providing legal advice within the framework of the Young Farmer Mentor Program

PROVISIONS ON DATA SECURITY

The Company ensures the security of data, and in this regard undertakes to take all technical and organizational measures that are essential for the enforcement of data security laws, data and privacy protection rules, and to develop the procedural rules necessary for the enforcement of the above-mentioned laws.

The Company protects data with appropriate measures against unauthorized access, alteration, transmission, disclosure, deletion or destruction, as well as accidental destruction and damage, and against inaccessibility resulting from changes in the technology used.

When defining and applying measures to ensure data security, the Company takes into account the current state of technology and, in the case of several possible data management solutions, chooses the solution that ensures a higher level of protection of personal data, unless this would constitute a disproportionate difficulty.

RULES RELATED TO DATA PROCESSING

General rules related to data processing

    • The rights and obligations of the data processor related to the processing of personal data are determined by the data controller within the framework of the law and separate laws related to data management.

    • The Company declares that the data processor does not have the competence to make substantive decisions regarding data management during its activities, may process the personal data it has come to know only in accordance with the data controller’s instructions, may not process data for its own purposes, and is obliged to store and to preserve.

    • The Company is responsible for the lawfulness of the instructions given to the data processor regarding data processing operations.

    • The Company is obliged to provide information to the data subjects about the identity of the data processor and the place of data processing.

    • The Company does not authorize the data processor to use another data processor.

    • The data processing contract must be in writing. An organization that is interested in the business activity using the personal data to be processed cannot be entrusted with data processing.

Language

The primary language of contracting for the Provider’s Services is Hungarian. The Provider may make its content, including these Terms and Conditions, available in other languages; however, unless expressly agreed otherwise, the Hungarian-language version shall be the sole authoritative version for purposes of legal interpretation, contractual matters, settlement/accounting matters, and the resolution of any dispute.

These Terms and Conditions, the Provider’s Services, the contractual relationship between the Parties, and any dispute arising therefrom or in connection therewith shall be governed by the laws of Hungary.

Any translation or foreign-language description of these Terms and Conditions or of the Provider’s Services shall be provided for information purposes only. In the event of any discrepancy, inconsistency or conflict, the Hungarian-language version published by the Provider shall prevail.

Date, May 5, 2026.