PRIVACY POLICY

I. INTRODUCTION

The purpose of this Privacy Notice is to inform data subjects about Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 (hereinafter: „GDPR”) and Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (hereinafter: “Info tv.”) regarding the processing of data subjects“ personal data by TÁLOSI Law Firm, acting as the data controller (hereinafter: ”Data Controller“) in connection with the website www.talosilegal.com (hereinafter: ”Website”).

The Data Controller pays particular attention to complying with the legal requirements governing the processing of personal data, in particular the provisions of the GDPR.

The term “data subject” refers to the person whose personal data is processed by the Data Controller.

II. IDENTITY AND CONTACT INFORMATION OF THE DATA CONTROLLER

The Data Controller for the data processed in connection with the operation of the Website is the TÁLOSI Law Firm. The Data Controller’s contact information and details are as follows:

Headquarters: 1134 Budapest, Róbert Károly krt. 59.

Email: [email protected]

III. APPLICABLE LAWS

When processing data, the Data Controller must act in accordance with the provisions set forth in the following laws, as specified in this policy:

⦁ Regulation (EU) 2016/679 of the European Parliament and of the Council (April 27, 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: GDPR)

⦁ Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (hereinafter: Infotv.).

⦁ Act V of 2013 on the Civil Code (hereinafter: Civil Code).

⦁ Act I of 2012 on the Labor Code (hereinafter: Mt.).

IV. INTERPRETATIVE PROVISIONS

The terms defined in the GDPR, of which the following should be highlighted in light of the nature of this policy:

⦁ personal data: any information relating to an identified or identifiable natural person („Data Subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

⦁ data processing: any operation or set of operations performed on personal data or data files, whether by automated or non-automated means, including collection, recording, organization, classification, storage, adaptation or alteration, retrieval, consultation, use, disclosure, transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

⦁ data controller: a natural or legal person, public authority, agency, or any other body that, alone or jointly with others, determines the purposes and means of the processing of personal data; if the purposes and means of data processing are determined by Union or Member State law, Union or Member State law may also specify the controller or the specific criteria for designating the controller.

⦁ Data processor: a natural or legal person, public authority, agency, or any other body that processes personal data on behalf of the data controller.

⦁ recipient: any natural or legal person, public authority, agency, or any other body to whom or which personal data is disclosed, regardless of whether it is a third party. Public authorities that have access to personal data in the context of a specific investigation in accordance with Union or Member State law are not considered recipients; the processing of such data by those public authorities must comply with the applicable data protection rules in accordance with the purposes of the processing.

⦁ third party: a natural or legal person, public authority, agency, or any other entity that is not the data subject, the data controller, the data processor, or those persons authorized to process personal data under the direct supervision of the data controller or data processor.

⦁ data filing system: a collection of personal data organized in any manner—whether centralized, decentralized, or structured according to functional or geographic criteria—that is accessible based on specific criteria.

⦁ Data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data that is transmitted, stored, or otherwise processed.

⦁ representative: a natural or legal person established or residing in the European Union who has been designated in writing by the data controller or data processor pursuant to Article 27 and who, represents the data controller or data processor with respect to the obligations incumbent upon the data controller or data processor under this Regulation.

⦁ business: a natural or legal person engaged in economic activity, regardless of its legal form, including partnerships and associations that engage in regular economic activity.

⦁ Data asset inventory: a document used to assess the scope and nature of the personal data processed by the data controller.

⦁ Technical and organizational measures: measures taken by the data controller in light of the nature, scope, circumstances, and purposes of the data processing, as well as the risks of varying likelihood and severity to the rights and freedoms of natural persons, in order to ensure and demonstrate that the processing of personal data is carried out in accordance with the GDPR. The data controller shall review these measures and update them as necessary.

V. GENERAL LEGAL BASES FOR DATA PROCESSING

The processing of personal data is lawful only if and to the extent that at least one of the legal bases set forth below is met:

⦁ The data subject has given consent to the processing of his or her personal data for one or more specific purposes (hereinafter referred to as “data processing based on consent”).

⦁ Data processing is necessary for the performance of a contract to which the data subject is a party, or for taking steps at the data subject’s request prior to entering into a contract (hereinafter referred to as “contract-based data processing”).

⦁ The data processing is necessary to comply with a legal obligation to which the Data Controller is subject (hereinafter: data processing based on a legal obligation).

⦁ Data processing is necessary to protect the vital interests of the data subject or another natural person (hereinafter referred to as “data processing based on vital interests”).

⦁ The data processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller (hereinafter: data processing based on official authority).

⦁ The processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child (hereinafter: data processing based on legitimate interests).

⦁ With respect to the processing of a given set of personal data, the Data Controller always processes such data based on a single legal basis. The legal basis for data processing may change during the course of processing.

VI. DATA SECURITY

The data controller selects and operates the IT tools used to process personal data in the course of providing the service in such a way that the data being processed:

⦁ accessible to authorized users (availability);

⦁ its authenticity and verification are ensured (authenticity of data processing);

⦁ its integrity can be verified (data integrity);

⦁ It must be protected against unauthorized access (data confidentiality).

The data controller protects the data through appropriate measures against unauthorized access, alteration, disclosure, transmission, deletion, or destruction, as well as against accidental destruction.

The data controller shall ensure the security of data processing by implementing technical, administrative, and organizational measures that provide a level of protection appropriate to the risks associated with data processing.

The data controller retains the data during the data processing

⦁ confidentiality: it protects information so that only those who are authorized can access it;

⦁ integrity: safeguards the accuracy and completeness of the information and the processing method;

⦁ Availability: Ensures that when an authorized user needs it, they can actually access the desired information and that the necessary tools are available.

VII. LEGAL BASIS FOR DATA PROCESSING, PURPOSE, SCOPE OF DATA PROCESSED, AND DURATION OF DATA PROCESSING

Data ProcessedPurpose of Data ProcessingLegal Basis for Data ProcessingDuration of Data Processing
1.) By filling out the contact form displayed on the website, the Data Subject:
Name (last name, first name)
Email address
To process an application, fulfill a contract, and establish contact.The Data Controller’s data processing is based on the Data Subject’s consent pursuant to Article 6(1)(a) of the GDPR and on the performance of a contract pursuant to Article 6(1)(b) of the GDPR.Until consent is withdrawn or for as long as necessary to fulfill the contract, but no later than the termination of the contractual relationship.
2.) When subscribing to the newsletter, the Data Subject:
Name (last name, first name)
Email address
Marketing-related communications, sending out information about upcoming conferences, and maintaining the quality of our services.The Data Controller’s processing of data is based on the Data Subject’s consent, in accordance with Article 6(1)(a) of the GDPR.Until the consent is withdrawn, that is, until the Data Subject unsubscribes.

VIII. DATA PROCESSORS, NEWSLETTER

The Data Controller will not disclose the personal data provided by the Data Subject to any other person. If such a transfer were nevertheless necessary, it may only take place after the Data Subject has been informed in advance and has given their consent. An exception to this rule is the transfer of data in response to an official request from a government authority or a court.

By subscribing to the newsletter on the website, the Data Subject consents to receiving communications for marketing purposes.

You may unsubscribe from the newsletter at any time, free of charge and without restriction or having to provide a reason, by clicking the unsubscribe link included in the newsletters or by sending an unsubscribe request to the email address provided.

If you unsubscribe from the newsletter, the personal data we have on file related to sending the newsletter will be deleted, and you will no longer receive newsletters or notifications from us.

IX. STORAGE SERVICE PROVIDER

We use a web hosting provider for the website.

Location of physical data storage: EU territory

X. RULES REGARDING COOKIES

Please be advised that we use small data files (hereinafter referred to as „cookies”) on the Website to identify the Data Subject. These cookies are provided by Google and are used through the Google Analytics system. By visiting the Website and using its various features, the Data Subject consents to the storage of the aforementioned cookies on the Data Subject’s computer and to the Data Controller’s access to them.

Cookies are stored for 30 days; however, the Data Subject may configure their browser to control or block cookie-related activity. Please note, however, that in the latter case—without the use of cookies—you may not be able to use all of the website’s features.

As a technical service provider, the Data Controller may ensure that third parties cooperating with the Data Controller, in particular Google Inc., use cookies to store information if the Data Subject has previously visited the Data Controller’s website, and may display advertisements to the Data Subject based on this information.

The Data Subject may delete the cookie from their own computer or configure their browser to block cookies.

The Data Subject is entitled at any time to request information regarding their data processed in the Data Controller’s system; in this regard, the Data Controller is obligated to provide the Data Subject with the appropriate information regarding the availability of information and policies related to data processing without delay, but no later than within 15 (fifteen) days, so that the Data Subject may obtain the following information: the data being processed, the purpose of the data processing, its legal basis, its duration, and who receives or has received their data and for what purpose.

You will receive a response in writing within 20 (twenty) days of submitting your request, either on paper or electronically, depending on the format of your request. In the case of a paper-based request, we will charge you for any costs that may arise.

Given that the Data Subject may object to the processing of his or her personal data, the Data Controller is required to restrict the processing accordingly within 20 (twenty) days to restrict data processing in accordance with the restriction, implement the provisions set forth in the decision, and provide the Data Controller with the appropriate information electronically.

XI. RIGHTS OF DATA SUBJECTS REGARDING DATA PROCESSING

The Data Subject may exercise the following rights by sending an email:

Right to Correction

The Data Subject has the right at any time to request the correction of any inaccurately recorded personal data processed by the Data Controller. The Data Controller shall rectify any inaccurate personal data concerning the Data Subject without undue delay and is entitled to request that incomplete personal data be supplemented.

Right to Erasure

The Data Subject has the right to request the erasure of his or her personal data processed by the Data Controller if he or she has withdrawn his or her consent, the contractual relationship has ended, and the erasure does not apply to any records or documents that the Data Controller is required by law to retain. In the latter case, the personal data cannot be erased.

Right to Restriction of Data Processing

The Data Controller is required to restrict the processing of personal data upon request by the Data Subject. If, based on the information available to us, it can be assumed that erasure would harm the Data Subject’s legitimate interests, the processing of the personal data must be restricted. The data must be processed as restricted data for as long as the purpose of data processing or the legitimate interest that precluded the erasure of the personal data remains in effect.

Right to Data Portability

The Data Subject may request that the Data Controller allow him or her to review the data processed about him or her on a data storage medium or in paper form.

The Right to Withdraw Consent

The Data Subject has the right to withdraw their consent to data processing at any time; in such cases, we will delete the provided data from our systems.

The Data Controller will investigate user complaints regarding data processing and make a decision on whether the complaint is well-founded, notifying the complainant of this decision in writing within 30 (thirty) days at the latest. If the Data Controller does not grant the Data Subject’s request, it shall provide the Data Subject with the factual and legal grounds for the rejection of the request.

XII. ENFORCEMENT

If we have violated any statutory provision governing data processing or have failed to comply with any request you have made, you may initiate an investigation by the National Authority for Data Protection and Freedom of Information in order to put an end to the alleged unlawful data processing.

Name: National Authority for Data Protection and Freedom of Information

Headquarters: 1055 Budapest, Falk Miksa Street 9-11

Email: [email protected]

Website: http://www.naih.hu

In addition, the Data Subject is also entitled to assert his or her rights before the competent court.

XIII. DATA TRANSFER, DATA PROCESSING, AND THE CIRCLE OF PERSONS WITH ACCESS TO THE DATA

Personal data received by the Data Controller in any form through this website may be accessed by the Data Controller’s employees, who hold the necessary authorizations regarding its use and legal basis.

XIV. OTHER PROVISIONS

We will provide information regarding data processing activities not listed in this notice at the time the data is collected. We hereby inform our clients that we may provide information, disclose data, or transfer documents to courts, prosecutors, investigative authorities, administrative authorities, the National Authority for Data Protection and Freedom of Information, the Hungarian National Bank, or other bodies authorized by law may contact the data controller for the purpose of providing information, disclosing or transferring data, or making documents available.

The data controller shall disclose personal data to public authorities—provided that the authority has specified the exact purpose and scope of the data—only to the extent that is strictly necessary to fulfill the purpose of the request.

The Data Controller reserves the right to unilaterally amend this Privacy Notice in respects other than the legal basis, purpose, and scope of the data processed.

XV. ENTRY INTO FORCE PROVISION

These regulations will take effect on January 1, 2026.