Privacy policy
Privacy policy
Privacy policy of Energrid Smart Technologies Ltd.
Energrid Smart Technologies Ltd. (hereinafter: the “Controller”) processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and the provisions of Hungarian Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information.
The purpose of this policy is to present, in a detailed and transparent manner, the data processing activities carried out by the Controller, with particular regard to the operation of the website, business and contractual relationships, and the processing of employee data.
The Controller processes personal data solely for specified, explicit and legitimate purposes. The purposes of processing include, in particular, establishing and maintaining business relationships, preparing quotations, concluding and performing contracts, maintaining contact, fulfilling legal obligations and ensuring the secure operation of IT systems.
The legal basis for processing is Article 6(1)(b) GDPR (performance of a contract), Article 6(1)(c) GDPR (compliance with a legal obligation) and Article 6(1)(f) GDPR (legitimate interest). In certain cases, processing is based on the data subject’s consent pursuant to Article 6(1)(a) GDPR.
In the course of its activities, the Controller processes in particular the names, contact details and positions of business partners’ contact persons, contractual data, performance and financial data, as well as technical data (e.g. IP address, log data). The data are typically obtained from the data subject or from the organisation employing the data subject.
The Controller processes the data for as long as necessary to achieve the purpose of processing. As a general rule, data arising from a contractual relationship are retained for 5 years following the termination of the relationship, while accounting records are retained for 8 years in accordance with the applicable legislation.
The Controller uses data processors in its operations, in particular for IT and system operation tasks. Data processors carry out their activities on the Controller’s instructions, subject to appropriate data security safeguards.
International data transfers may also take place in the course of the Controller’s operations, in particular when cloud-based systems are used. Such transfers are always carried out with appropriate safeguards in accordance with Chapter V of the GDPR (in particular standard contractual clauses).
The Controller applies appropriate technical and organisational measures to protect personal data, taking into account the nature, circumstances and risks of the processing. In doing so, it ensures the confidentiality, integrity and availability of the data and protects them against unauthorised access.
In the event of a personal data breach, the Controller acts in accordance with Articles 33 and 34 of the GDPR and, where necessary, notifies the supervisory authority.
Data subjects have the right to request information about the processing of their personal data, to request its rectification, erasure or the restriction of its processing, and to object to the processing. These rights are governed by Articles 15–21 of the GDPR.
In the event of an infringement of their rights, data subjects may bring the matter before a court or lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH).
The Controller declares that no automated decision-making or profiling takes place.
The Controller reserves the right to amend this policy unilaterally and will inform data subjects of any changes via its website.
Data controller: Energrid Smart Technologies Ltd. · 1023 Budapest, Frankel Leó utca 45. 3rd floor · info@energridsmart.com
