Privacy Policy
1. Introduction
Absolut Media Production Korlátolt Felelősségű Társaság (hereinafter Absolut Media Production Korlátolt Felelősségű Társaság, service provider, data controller, Company), as data controller, acknowledges the content of this legal notice as binding upon itself.
The Company undertakes that all data processing related to its activities complies with the requirements set out in this policy and in the applicable legislation.
Absolut Media Production Korlátolt Felelősségű Társaság is the operator of the absolutmedia.hu website.
Absolut Media Production Korlátolt Felelősségű Társaság reserves the right to modify this notice at any time. Naturally, it will inform its audience of any changes in due time.
Absolut Media Production Korlátolt Felelősségű Társaság is committed to protecting the personal data of its clients and partners, and considers respect for its clients' right to informational self-determination especially important. The Data Controller treats personal data confidentially and takes every security, technical and organisational measure that guarantees the security of the data.
Below, Absolut Media Production Korlátolt Felelősségű Társaság sets out its data processing principles and presents the expectations it has formulated for itself as data controller and complies with. Its data processing principles are in line with the applicable legislation on data protection, in particular the following:
- Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information;
- Act V of 2013 on the Civil Code (Ptk.);
- Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activity (Grt.);
- Act CVIII of 2001 (Ekertv.) on Certain Issues of Electronic Commerce Services and Information Society Services;
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: „GDPR”)
2. Definitions
- data subject: any specified natural person identified on the basis of personal data or who can be identified, directly or indirectly;
- personal data: data that can be associated with the data subject, in particular the data subject's name, identification mark and information characteristic of one or more of their physical, physiological, mental, economic, cultural or social identity, as well as any conclusion regarding the data subject that can be drawn from such data;
- consent: the voluntary and definite expression of the data subject's wish, based on adequate information, by which they give their unambiguous agreement to the processing of their personal data, either in full or in respect of specific operations;
- data controller: the natural or legal person, or organisation without legal personality, who or which, alone or jointly with others, determines the purpose of the processing of data, makes and implements decisions concerning the processing (including the means used), or has them implemented by a data processor;
- data processing: irrespective of the procedure applied, any operation or set of operations performed on the data, in particular their collection, recording, registration, organisation, storage, alteration, use, retrieval, transfer, disclosure, alignment or combination, blocking, erasure and destruction, as well as the prevention of their further use, the taking of photographs, audio or video recordings, and the recording of physical characteristics suitable for identifying a person (e.g. fingerprint or palm print, DNA sample, iris image);
- data transfer: making the data accessible to a specified third party;
- disclosure: making the data accessible to anyone;
- data erasure: rendering the data unrecognisable in such a way that their restoration is no longer possible;
- data handling (processing operations): the performance of technical tasks related to data processing operations, irrespective of the method and means used and of the place of application, provided that the technical task is performed on the data;
- data processor: the natural or legal person, or organisation without legal personality, who or which processes the data on the basis of a contract, including a contract concluded under a statutory provision.
3. Company details
Our company's details and contact information are as follows:
- Name: Absolut Media Production Korlátolt Felelősségű Társaság
- Postal address: 8000 Székesfehérvár, Honvéd utca 3., Hungary
- Company registration number: 07-09-033904
- Tax number: 32077298-1-07
- Phone: +36 20 957 8009
- Email: info@absolutmedia.hu
- Representative of the data controller: Róbert Németh-Nagy, managing director
4. The scope of personal data, the purpose, legal basis and duration of processing
We draw the attention of those providing data to Absolut Media Production Korlátolt Felelősségű Társaság to the fact that if they do not provide their own personal data, it is the obligation of the person providing the data to obtain the data subject's consent. The data controller is not obliged to verify this. The data controller draws the partner's attention to the fact that if the partner fails to fulfil this obligation and the data subject therefore asserts a claim against the data controller, the data controller may pass the claim, or the amount of the related damage, on to the partner.
We provide the following information in relation to our individual processing activities.
4.1. Requests for quotes and enquiries by direct contact
Those interested may contact our Company directly by email sent to the Company's address or by telephone.
- Purpose of the processing: keeping in touch, in order to facilitate communication between the data subject and our Company and to enable the closest and most effective cooperation possible.
- Legal basis of the processing: legitimate interest, GDPR Article 6(1)(f)
- Scope of personal data processed: name of the person requesting the quote or the contact person; email address, phone number and any other information provided by the data subject,
- Duration of the processing: 3 years after the expiry of the validity period of the quote, or until the data subject objects
- Recipients of the personal data: the data controller does not transfer the data obtained to third parties, with the exception of the data processor(s) indicated in point 7. The recorded data may only be accessed by employees of the Data Controller and the designated colleagues of the data processor(s).
- Indication of the legitimate interest: our Company has a legitimate interest in processing the data subject's data for direct marketing purposes
- Scope of data subjects: partners and data subjects who enquire directly (e.g. by email or phone) about the Company's services.
4.2. Requests for quotes and enquiries through the website (absolutmedia.hu)
Our company enables data subjects to request quotes electronically.
- Purpose of the processing: keeping in touch, in order to facilitate communication between the data subject and our Company and to enable the closest and most effective cooperation possible.
- Legal basis of the processing: the voluntary consent of the data subject, GDPR Article 6(1)(a).
- Scope of personal data processed: name of the person enquiring (first name, surname); email address, phone number, company name and any other information provided by the data subject.
- Duration of the processing: 3 years after the expiry of the validity period of the quote, or until consent is withdrawn.
- Recipients of the personal data: the data controller does not transfer the data obtained to third parties, with the exception of the data processor(s) indicated in point 7. The recorded data may only be accessed by employees of the Data Controller and the designated colleagues of the data processor(s).
- Scope of data subjects: partners and data subjects who enquire through the website about the Company's services and products.
4.3. Processing related to the follow-up of quotes
- Purpose of the processing: the data controller has a legitimate interest in keeping a record of the data subject's data beyond the validity period of the quote for direct marketing purposes
- Legal basis of the processing: legitimate interest of the data controller, GDPR Article 6(1)(f),
- Scope of personal data processed: contact person's surname and first name; phone number; email address
- Recipients of the personal data: the data controller does not transfer the data obtained to third parties, with the exception of the data processor(s) indicated in point 7. The recorded data may only be accessed by employees of the Data Controller and the designated colleagues of the data processor(s).
- Duration of the processing: until the data subject objects
- Indication of the legitimate interest: building business relationships with partners and those requesting quotes, and providing accurate information to data subjects. Our Company has a legitimate interest in processing the data subject's data for direct marketing purposes
- Scope of data subjects: the addressees of quotes previously issued by the Company and the contact person(s) named in them.
4.4. Newsletter subscription
- Purpose of the processing: sending email newsletters that also contain commercial advertising to those interested, and providing information about current matters
- Legal basis of the processing: the prior, voluntary consent of the data subject, GDPR Article 6(1)(a),
- Scope of personal data processed: name, email address
- Duration of the processing: until the voluntary consent is withdrawn or the newsletter is unsubscribed from. Our Company processes the data provided by the data subject until consent is withdrawn. Following the withdrawal of consent, we delete the processed data from our newsletter database within 7 days at the latest, after which we no longer send you newsletters.
- Recipients of the personal data: the data controller does not transfer the data obtained to third parties, with the exception of the data processor(s) indicated in point 7. The recorded data may only be accessed by employees of the Data Controller and the designated colleagues of the data processor(s). You may unsubscribe from the newsletter at any time by sending an email to info@absolutmedia.hu or by clicking the unsubscribe icon in the newsletter.
- Scope of data subjects: partners and data subjects who subscribe to the Company's electronic newsletter.
4.5. Newsletter data (for newsletter subscriptions registered before 25 May 2018)
- Purpose of the processing: sending email newsletters that also contain commercial advertising to those interested, and providing information about current matters
- Legal basis of the processing: legitimate interest of the data controller, GDPR Article 6(1)(f),
- Scope of personal data processed: name, email address
- Duration of the processing: until the data subject objects
- Indication of the legitimate interest: providing information containing commercial advertising and business offers to data subjects who subscribe to the newsletter. Our Company has a legitimate interest in processing the data subject's data for direct marketing purposes.
- Recipients of the personal data: the data controller does not transfer the data obtained to third parties, with the exception of the data processor(s) indicated in point 7. The recorded data may only be accessed by employees of the Data Controller and the designated colleagues of the data processor(s). You may unsubscribe from the newsletter at any time by sending an email to info@absolutmedia.hu or by clicking the unsubscribe icon in the newsletter.
- Scope of data subjects: partners and data subjects who subscribed to the Company's electronic newsletter before 25 May 2018.
4.6. Camera system
Cameras operate on the premises operated by the data controller in the interest of the personal and property security of data subjects and for other purposes. Information signs draw the attention of data subjects to their operation. The activities related to the operation of the camera system are set out in the site's „Property protection camera data processing notice”, which is available on the premises.
4.7. Processing related to ensuring the operation of the information technology service
- Purpose of the processing: the websites of Absolut Media Production Korlátolt Felelősségű Társaság may use so-called "cookies" (temporary markers) that enable faster access to them. By "cookies" we mean an item of information that is only active during an individual client session and that is transferred from the website to the Client's computer for faster identification. The Client may always request that cookies be switched off by changing the browser settings; however, switching them off may slow down or prevent access to some parts of the site and the use of certain functions.
The session cookies used avoid the need to resort to other IT tools that are potentially harmful to the confidentiality of clients' navigation and do not allow the acquisition of identifying personal data.
The user is able to delete cookies from their own computer and to disable the use of cookies in their browser. Cookies can generally be managed in the Tools/Settings menu of browsers, under privacy settings, labelled cookies. - Legal basis of the processing: the voluntary consent of the data subject (User), GDPR Article 6(1)(a).
The User gives their voluntary consent to the processing by accepting the pop-up notice and declaration when starting to browse the website, or by continuing to browse.
Scope of personal data processed: information technology processing concerns the scope of data necessary for the operation of the "cookies" used to run the website and for the use of the log files applied by the web hosting provider. - Duration of the processing: until the session is closed
- Recipients of the personal data: the data controller does not transfer the data obtained to third parties, with the exception of the data processor(s) indicated in point 7. The recorded data may only be accessed by employees of the Data Controller and the designated colleagues of the data processor(s).
- Scope of data subjects: every User visiting the website, irrespective of whether they use the services available on the website.
5. Other processing activities
We provide information about processing activities not listed in this notice at the time the data are collected. We inform our clients that certain authorities, bodies performing public duties and courts may contact our company for the purpose of disclosing personal data. Our company discloses personal data to such bodies, provided that the body concerned has indicated the exact purpose and the scope of the data, only to the extent that is strictly necessary for achieving the purpose of the request, and only where the fulfilment of the request is prescribed by law.
6. Transfer of personal data to a third country or to an international organisation
Our Company does not transfer your personal data referred to above either to a third country or to an international organisation.
7. Information on the use of data processors
During the processing, the data controller transfers the data to the data processor(s) contracted for the performance of the contract.
Categories of recipients: system administration service provider, accounting and payroll service provider, server hosting and web hosting provider
8. Children
Our services are not intended for persons under the age of 16, and we ask that persons under 16 do not provide personal data to the Data Controller.
If it comes to our knowledge that we have collected personal data from a child under 16, we will take the steps necessary to erase the data as soon as possible, with the exception of the processing of data required by law.
9. Automated decision-making
Our Company does not apply automated decision-making in its data processing procedures or data collection.
10. The method of storing personal data and the security of processing
Our company's IT systems and other data retention locations are at its registered office and on the servers provided by the data processor. Our company selects and operates the IT tools used for processing personal data in the course of providing the service in such a way that the processed data are:
- accessible to those authorised (availability);
- authentic and their authentication is ensured (authenticity of processing);
- verifiable as unchanged (data integrity);
- protected against unauthorised access (confidentiality of data).
We pay particular attention to the security of the data, and we also take the technical and organisational measures and establish the procedural rules necessary to give effect to the guarantees under the GDPR. We protect the data with appropriate measures, in particular against unauthorised access, alteration, transfer, disclosure, erasure or destruction, as well as against accidental destruction or damage and against becoming inaccessible due to changes in the technology applied.
The IT systems and networks of our company and our partners are protected against computer-assisted fraud, computer viruses, computer intrusions and denial-of-service attacks. The operator ensures security with both server-level and application-level protection procedures. Daily backup of the data is in place. Our company takes every possible measure to avoid data protection incidents; should such an incident occur, we act without delay, in accordance with our incident management policy, to minimise the risks and remedy the damage.
11. Rights of data subjects and remedies
The data subject may request information about the processing of their personal data, and may request the rectification of their personal data and, with the exception of mandatory processing, their erasure or the withdrawal of consent; they may exercise their right to data portability and their right to object in the manner indicated at the time the data were collected, or via the contact details of the data controller given above.
The rights and remedies of the data subject are defined below and communicated to data subjects on the basis of Act CXII of 2011 and Regulation (EU) 2016/679.
The right to information, otherwise known as the data subject's „right of access”: on the basis of Act CXII of 2011 and Article 15 of Regulation (EU) 2016/679, at the data subject's request the Data Controller provides information about
- the data it processes and the categories of personal data,
- the purpose of the processing,
- the legal basis of the processing,
- the duration of the processing,
- where applicable, the period for which the data are stored or, if this is not possible, the criteria used to determine that period,
- where applicable, if the data were not collected from the data subject, all available information about their source,
- where applicable, automated decision-making, including profiling, and comprehensible information about the logic involved and about the significance of such processing, and
- the expected consequences of such processing for the data subject,
- the details of the data processor, if a data processor has been used, and about the circumstances and effects of any data protection incident and the measures taken to remedy it, furthermore
- in the event of a transfer of the data subject's personal data, the legal basis, purpose and recipient of the transfer.
The information is free of charge if the person requesting it has not yet submitted a request for information concerning the same scope of data to the Data Controller in the current year. In other cases, a cost reimbursement may be charged. Any cost reimbursement already paid must be refunded if the data were processed unlawfully or if the request for information led to rectification.
The Data Controller draws the attention of data subjects to the fact that, on the basis of Act CXII of 2011, the information must be refused
- if, on the basis of a provision of an act, an international treaty or a binding legal act of the European Union, the Data Controller receives personal data in such a way that the transferring data controller indicates, simultaneously with the transfer, the restriction of the rights guaranteed to the data subject under the said act, or another restriction of the processing;
- in the interest of the external and internal security of the state, such as national defence, national security, the prevention or prosecution of criminal offences and the security of the enforcement of punishments, furthermore for state or municipal economic or financial reasons, for a significant economic or financial interest of the European Union, as well as for the prevention and detection of disciplinary and ethical offences related to the practice of professions and of breaches of employment and occupational safety obligations, including in all cases inspection and supervision, and furthermore in the interest of protecting the rights of the data subject or of others.
The Data Controller is obliged to notify the Hungarian National Authority for Data Protection and Freedom of Information about rejected requests for information annually, by 31 January of the year following the reference year.
The right to rectification: the data subject has the right to obtain from the Data Controller, without undue delay, the rectification of inaccurate personal data concerning them. Taking into account the purpose of the processing, the data subject has the right to request the completion of incomplete personal data, including by means of a supplementary statement. At the same time, if the personal data do not correspond to reality and the Data Controller has the personal data that do correspond to reality at its disposal, the Data Controller rectifies the personal data as a matter of obligation, even without the data subject's request.
The right to erasure, otherwise known as the „right to be forgotten”: the data subject has the right to obtain from the Data Controller the erasure of personal data concerning them without undue delay, and the Data Controller is obliged to erase the personal data relating to the data subject without undue delay, provided that mandatory processing does not preclude this.
Apart from the above case, the Data Controller is obliged to erase the data on the basis of Act CXII of 2011 and Regulation (EU) 2016/679 of the European Parliament and of the Council if
- the processing of the data is unlawful;
- the data are incomplete or incorrect, and this state of affairs cannot lawfully be remedied, provided that erasure is not precluded by law;
- the purpose of the processing has ceased, or the statutory time limit for storing the data has expired;
- it has been ordered by a court or by the Authority;
- the personal data are no longer necessary for the purpose for which they were collected or otherwise processed;
- the data subject objects to the processing and there is no overriding lawful ground for the processing;
- the personal data must be erased in order to comply with a legal obligation under the law applicable to the Data Controller;
- the personal data were collected in relation to the offering of information society services directly to children, as referred to in Article 8(1) of Regulation (EU) 2016/679.
Where the Data Controller has, for some reason, made the personal data public and is obliged to erase them under the above, it takes the reasonably expectable steps, including technical measures, taking account of available technology and the cost of implementation, to inform other data controllers processing the data that the data subject has requested the erasure of links to, or copies or replications of, the personal data in question.
The Data Controller draws the attention of data subjects to the limits of the right to erasure or the „right to be forgotten” arising from the EU regulation, which are the following:
- exercising the right to freedom of expression and information;
- compliance with an obligation under Union or Member State law applicable to the data controller which requires the processing of personal data, or the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller;
- public interest in the area of public health;
- archiving purposes in the public interest, scientific and historical research purposes or statistical purposes in accordance with Article 89(1) of Regulation (EU) 2016/679, in so far as the right to erasure is likely to render impossible or seriously impair the achievement of that processing; or
- the establishment, exercise or defence of legal claims.
The right to restriction of processing, otherwise known as the right to blocking: the data subject has the right to obtain from the Data Controller the restriction of processing at their request.
If, on the basis of the information available to it, it may be assumed that erasure would prejudice the legitimate interests of the data subject, the data must be blocked. Personal data blocked in this way may only be processed for as long as the processing purpose that precluded the erasure of the personal data continues to exist.
If the data subject contests the accuracy or correctness of the personal data, but the incorrectness or inaccuracy of the contested personal data cannot be established unambiguously, the data are blocked. In this case, the restriction applies for the period that enables the Data Controller to verify the accuracy of the personal data.
On the basis of the EU regulation, the data must be blocked if
- the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead;
- the Data Controller no longer needs the personal data for the purposes of the processing, but the data subject requires them for the establishment, exercise or defence of legal claims; or
- the data subject has objected to the processing; in this case the restriction applies for the period until it is established whether the legitimate grounds of the Data Controller override the legitimate grounds of the data subject.
Where processing is subject to restriction (blocking), such personal data may, with the exception of storage, only be processed with the data subject's consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State.
The Data Controller hereby expressly draws the attention of data subjects to the fact that the data subject's right to rectification, erasure and blocking may be restricted by law in the interest of the external and internal security of the state, such as national defence, national security, the prevention or prosecution of criminal offences and the security of the enforcement of punishments, furthermore for state or municipal economic or financial reasons, for a significant economic or financial interest of the European Union, as well as for the prevention and detection of disciplinary and ethical offences related to the practice of professions and of breaches of employment and occupational safety obligations, including in all cases inspection and supervision, and furthermore in the interest of protecting the rights of the data subject or of others.
The Data Controller informs the data subject about the matters set out in their request without undue delay, and at the latest within 30 days of receipt of the request, and/or rectifies the data, and/or erases and/or restricts (blocks) the data, or takes other steps in accordance with the request, unless there is a ground precluding this.
The Data Controller notifies the data subject in writing of the rectification, the erasure and the restriction of processing, as well as all those to whom the data were previously transferred or handed over for the purposes of processing. At the data subject's request, the Data Controller informs them about these recipients. The notification may be omitted if, in view of the purpose of the processing, it does not prejudice the legitimate interests of the data subject, or if providing the information proves impossible or would require a disproportionate effort. The Data Controller is also obliged to notify the data subject in writing if the exercise of the data subject's rights cannot be realised for some reason, and is obliged to indicate precisely the factual and legal grounds, as well as the remedies available to the data subject: the possibility of turning to a court and to the Hungarian National Authority for Data Protection and Freedom of Information.
The „right to data portability”: the data subject has the right to
- receive the personal data concerning them which they have provided to the Data Controller in a structured, commonly used, machine-readable format, and furthermore has the right to
- transmit those data to another controller without hindrance from the controller to which the personal data were provided, where:
- the processing is based on consent; and
- the processing is carried out by automated means.
When exercising the right to data portability, the data subject has the right, where technically feasible, to request that the personal data be transmitted directly between controllers.
In view of the processing activities carried out by the Data Controller, the conditions for exercising the right to data portability are not met (there is no automated processing), and therefore the data subject cannot exercise this right.
The right to object: the data subject may object to the processing of their personal data, including profiling, if
- the processing (transfer) of the personal data is necessary solely for the enforcement of a right or legitimate interest of the Data Controller or of the recipient of the data, except in the case of mandatory processing;
- the personal data are used or transferred for the purposes of direct marketing, public opinion polling or scientific research;
- the exercise of the right to object is otherwise permitted by law.
The data subject may also object, on the basis of Article 21(3) of Regulation (EU) 2016/679, to the processing of personal data for direct marketing purposes; in that case the personal data may no longer be processed for such purposes.
Where personal data are processed for scientific and historical research purposes or statistical purposes, the data subject has the right to object, on grounds relating to their particular situation, to the processing of personal data concerning them, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
The Data Controller, while simultaneously suspending the processing, examines the objection within the shortest possible time from the submission of the request, but within 30 days at the latest, and informs the applicant of the outcome in writing. If the applicant's objection is well founded, the Data Controller terminates the processing, including any further collection and transfer of data, and blocks the data, and notifies of the objection and of the measures taken on its basis all those to whom the personal data affected by the objection were previously transferred and who are obliged to take action in order to enforce the right to object.
If the data subject does not agree with the Data Controller's decision, or if the Data Controller fails to observe the time limit referred to above, the data subject is entitled to turn to a court within 30 days of the communication of the decision.
The data subject has the right to object in relation to automated decision-making.
Judicial enforcement: in the event of a breach of their rights, the data subject may turn to a court. The court deals with the case out of turn. It is for the Data Controller to prove that the processing complies with the statutory provisions.
In the event of a breach of your right to informational self-determination, you may submit a report or complaint to:
Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság)
Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c, Hungary
Phone: +36 (1) 391-1400, Fax: +36 (1) 391-1410
www: http://www.naih.hu
email: ugyfelszolgalat@naih.hu
Home / Keywords
Video production
Motion Design
Color Grading
Post-production
Animation