Privacy Policy

This English text is a translation provided for information purposes. In the event of any discrepancy, the Hungarian version of this Privacy Policy shall prevail.

1. Introduction

Bimenzió (hereinafter Bimenzió, service provider, data controller, Company), as data controller, acknowledges the content of this legal notice as binding upon itself. 
The Company undertakes that all data processing related to its activity complies with the requirements set out in this policy and in the applicable legislation. 
Bimenzió is the operator of the bimenzio.neosite.hu website.

Bimenzió reserves the right to change this notice at any time. It will of course inform its audience of any changes in good time.

Bimenzió is committed to protecting the personal data of its clients and partners and considers respect for its clients' right to informational self-determination to be of the utmost importance. The Data Controller treats personal data confidentially and takes every security, technical and organisational measure that guarantees the security of the data.

Below, Bimenzió sets out its data processing principles and presents the expectations it has formulated for itself as data controller and which it observes. Its data processing principles are in line with the applicable data protection legislation, in particular with the following:

  • Act CXII of 2011 on informational self-determination and freedom of information;
  • Act V of 2013 on the Civil Code;
  • Act XLVIII of 2008 on the basic conditions of and certain restrictions on commercial advertising activity;
  • Act CVIII of 2001 on certain aspects of electronic commerce services and information society services;
  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: “GDPR”).

2. Definitions

  • data subject: any specified natural person identified, or identifiable directly or indirectly, on the basis of personal data;
  • personal data: data that can be linked to the data subject – in particular the data subject's name, identification mark and information relating to one or more aspects of their physical, physiological, mental, economic, cultural or social identity – as well as any inference about the data subject that can be drawn from such data;
  • consent: the voluntary and definite expression of the data subject's wish, based on adequate information, by which they give their unambiguous agreement to the processing – in full or in respect of individual operations – of personal data relating to them;
  • data controller: the natural or legal person or unincorporated organisation that, alone or together with others, determines the purpose of the processing of data, makes and implements decisions concerning the processing (including the means used), or has them implemented by a data processor;
  • data processing: regardless of the procedure applied, any operation or set of operations performed on data, in particular their collection, recording, organisation, storage, alteration, use, retrieval, transmission, disclosure, alignment or combination, blocking, erasure and destruction, as well as the prevention of further use of the data, the taking of photographs, audio or video recordings, and the recording of physical characteristics suitable for identifying a person (e.g. finger or palm prints, DNA samples, iris images);
  • data transmission: making data accessible to a specified third party;
  • disclosure: making data accessible to anyone;
  • erasure of data: rendering data unrecognisable in such a way that their restoration is no longer possible;
  • data handling: the performance of technical tasks related to data processing operations, irrespective of the method and means used to carry out the operations and of the place of application, provided that the technical task is performed on the data;
  • data processor: the natural or legal person or unincorporated organisation that processes the data on the basis of a contract – including a contract concluded pursuant to a statutory provision. 

3. Company details

Our company details and contact information are as follows:

  • Name: Bimenzió
  • Postal address: %%levelezes%%
  • Company registration number: %%cegjegyzek%%
  • Tax number: %%adoszam%%
  • Telephone: +36 30 916 7516
  • E-mail:  info@bimenzio.hu
  • Representative of the data controller: %%vezeto%%

4. Scope of personal data, purpose, legal basis and duration of processing

We draw the attention of those providing data to Bimenzió to the fact that if they do not provide their own personal data, it is the obligation of the person providing the data to obtain the consent of the data subject. The data controller is not obliged to verify that such consent exists. The data controller draws the partner's attention to the fact that if the partner fails to comply with this obligation and the data subject therefore asserts a claim against the data controller, the data controller may pass on the asserted claim and the amount of any related damage to the partner.

We provide the following information in relation to our individual data processing activities. 

4.1. Quote requests and enquiries by direct contact

Enquirers have the opportunity to contact our Company directly by electronic mail sent to the Company's address or by telephone.

  • Purpose of processing: keeping in contact in order to promote communication between the data subject and our Company and to ensure the closest and most effective cooperation.
  • Legal basis of processing: legitimate interest – Article 6(1)(f) GDPR
  • Scope of personal data processed: name of the person requesting the quote / contact person; e-mail address, telephone number and any other information provided by the data subject.
  • Duration of processing: for 3 years after the expiry of the validity of the quotation, or until the data subject objects.
  • Recipients of personal data: apart from the data processor(s) indicated in section 7, the data controller does not hand over the data it has obtained to any third party. The recorded data may be accessed only by the employees of the Data Controller and the designated colleagues of the data processor(s).
  • Statement of the legitimate interest: our Company's legitimate interest in processing the data subject's data – direct marketing.
  • Categories of data subjects: partners and data subjects enquiring directly (e.g. by e-mail or telephone) about the Company's services. 

4.2. Quote requests and enquiries through the website (bimenzio.neosite.hu)

Our company gives data subjects the opportunity to request a quotation electronically.

  • Purpose of processing: keeping in contact in order to promote communication between the data subject and our Company and to ensure the closest and most effective cooperation.
  • Legal basis of processing: the data subject's voluntary consent – Article 6(1)(a) GDPR.
  • Scope of personal data processed: the enquirer's name (first name, surname); e-mail address, telephone number, company name and any other information provided by the data subject.
  • Duration of processing: for 3 years after the expiry of the validity of the quotation, or until consent is withdrawn.
  • Recipients of personal data: apart from the data processor(s) indicated in section 7, the data controller does not hand over the data it has obtained to any third party. The recorded data may be accessed only by the employees of the Data Controller and the designated colleagues of the data processor(s).
  • Categories of data subjects: partners and data subjects enquiring through the website about the Company's services and products.

4.3. Data processing related to the follow-up of quotations

  • Purpose of processing: the data controller's legitimate interest in keeping a record of the data subject's data beyond the validity period of the quotation for direct marketing purposes.
  • Legal basis of processing: the data controller's legitimate interest, Article 6(1)(f) GDPR.
  • Scope of personal data processed: contact person's surname and first name; telephone number; e-mail address.
  • Recipients of personal data: apart from the data processor(s) indicated in section 7, the data controller does not hand over the data it has obtained to any third party. The recorded data may be accessed only by the employees of the Data Controller and the designated colleagues of the data processor(s).
  • Duration of processing: until the data subject objects.
  • Statement of the legitimate interest: building business relationships with partners and those requesting quotations, and providing accurate information to data subjects. Our Company's legitimate interest in processing the data subject's data – direct marketing.
  • Categories of data subjects: the addressees of quotations previously issued by the Company and the contact persons named in them.

4.4. Newsletter registration

  • Purpose of processing: sending e-mail newsletters, which may also contain commercial advertising, to interested parties, and providing information about current matters.
  • Legal basis of processing: the data subject's prior, voluntary consent, Article 6(1)(a) GDPR.
  • Scope of personal data processed: name, e-mail address.
  • Duration of processing: until the voluntary consent is withdrawn or the data subject unsubscribes from the newsletter. Our Company processes the data provided by the data subject until consent is withdrawn. Following the withdrawal of consent, we delete the processed data from our newsletter database within 7 days at the latest, after which we no longer send you newsletters.
  • Recipients of personal data: apart from the data processor(s) indicated in section 7, the data controller does not hand over the data it has obtained to any third party. The recorded data may be accessed only by the employees of the Data Controller and the designated colleagues of the data processor(s). You may unsubscribe from the newsletter at any time by sending a letter to our Company at info@bimenzio.hu, or by clicking the unsubscribe icon in the newsletter. 
  • Categories of data subjects: partners and data subjects subscribing to the Company's electronic newsletter.

4.5. Newsletter data (for newsletter registrations made before 25 May 2018)

  • Purpose of processing: sending e-mail newsletters, which may also contain commercial advertising, to interested parties, and providing information about current matters.
  • Legal basis of processing: the data controller's legitimate interest, Article 6(1)(f) GDPR.
  • Scope of personal data processed: name, e-mail address.
  • Duration of processing: until the data subject objects.
  • Statement of the legitimate interest: providing information containing commercial advertising and business offers to data subjects subscribing to the newsletter. Our Company's legitimate interest in processing the data subject's data: direct marketing.
  • Recipients of personal data: apart from the data processor(s) indicated in section 7, the data controller does not hand over the data it has obtained to any third party. The recorded data may be accessed only by the employees of the Data Controller and the designated colleagues of the data processor(s). You may unsubscribe from the newsletter at any time by sending a letter to our Company at info@bimenzio.hu, or by clicking the unsubscribe icon in the newsletter. 
  • Categories of data subjects: partners and data subjects who subscribed to the Company's electronic newsletter before 25 May 2018.

4.6. Camera system

Cameras operate on the premises operated by the data controller in the interest of the personal and property security of data subjects and for other purposes. Information notices draw the attention of data subjects to their operation. The activities related to the operation of the camera system are set out in the premises' “Property protection camera data processing notice”, which is available on site.

4.7. Data processing related to ensuring the operation of the information technology service

  • Purpose of processing: Bimenzió may use so-called “cookies” (temporary markers) on its websites, which allow faster access to them. By “cookies” we mean an item of information that is active only for the duration of an individual client session and that is placed on the Customer's computer from the web page for the purpose of faster identification. The Customer may at any time request that cookies be switched off by modifying their browser settings; switching them off may, however, slow down or prevent access to some parts of the site and the use of certain functions. 
    The session cookies used avoid the need to resort to other information technology tools that are potentially harmful to the confidentiality of clients' navigation and do not make it possible to obtain the identifying personal data of the user.
    The user can delete cookies from their own computer or disable the use of cookies in their browser. Cookies can generally be managed in the Tools/Settings menu of browsers, under the Privacy settings, under the name cookie.
  • Legal basis of processing: the voluntary consent of the data subject (User), Article 6(1)(a) GDPR.
    The User gives their voluntary consent to the processing by accepting the pop-up notice and declaration when they start browsing the website, or by continuing to browse.
    Scope of personal data processed: the information technology processing concerns the range of data required for the operation of the “cookies” used to run the website and for the use of the log files applied by the web hosting provider.
  • Duration of processing: until the session is closed.
  • Recipients of personal data: apart from the data processor(s) indicated in section 7, the data controller does not hand over the data it has obtained to any third party. The recorded data may be accessed only by the employees of the Data Controller and the designated colleagues of the data processor(s).
  • Categories of data subjects: every User visiting the website, irrespective of whether they use the services available on it.

5. Other data processing

We provide information about data processing not listed in this notice at the time the data are collected. We inform our clients that certain authorities, bodies performing public duties and courts may contact our company in order to obtain personal data. Our company discloses personal data to such bodies – provided that the body concerned has indicated the exact purpose and the scope of the data – only to the extent and in the quantity that is strictly necessary to achieve the purpose of the request, and provided that the fulfilment of the request is prescribed by law. 

6. Transfer of personal data to a third country or an international organisation

Our Company does not transfer your personal data referred to above either to a third country or to an international organisation.

7. Information on the use of data processors

In the course of the processing, the data controller transfers the data to the data processor(s) with whom it has contracted for the performance of the contract.
Categories of recipients: system administration service provider, accounting and payroll service provider, server hosting and web hosting service provider.

8. Children

Our services are not intended for persons under the age of 16, and we ask that persons under 16 do not provide Personal data to the Data Controller. 
If we become aware that we have collected personal data from a child under the age of 16 – with the exception of data processed in accordance with statutory requirements – we will take the steps necessary to delete the data as soon as possible.

9. Automated decision-making

Our Company does not apply automated decision-making in its data processing procedures or data collection.

10. The manner of storing personal data and the security of processing

Our company's IT systems and other data storage locations are located at its registered office and on the servers provided by the data processor. Our company selects and operates the IT tools used to process personal data in the course of providing the service in such a way that the processed data are:

  1. accessible to those authorised to access them (availability);
  2. authentic and their authenticity is ensured (authenticity of processing);
  3. verifiably unaltered (data integrity);
  4. protected against unauthorised access (confidentiality of data).

We pay particular attention to the security of the data, and we take the technical and organisational measures and establish the procedural rules that are necessary to give effect to the guarantees under the GDPR. We protect the data with appropriate measures, in particular against unauthorised access, alteration, transmission, disclosure, erasure or destruction, accidental destruction or damage, and against becoming inaccessible as a result of changes in the technology applied.

The IT systems and networks of our company and of our partners are protected against computer-assisted fraud, computer viruses, computer intrusions and denial-of-service attacks. The operator ensures security by means of server-level and application-level protection procedures as well. Daily backup of the data is in place. Our company takes every possible measure to prevent data protection incidents; should such an incident occur, we act without delay – in accordance with our incident management policy – in order to minimise the risks and avert the damage.

11. Rights of data subjects, remedies

The data subject may request information about the processing of their personal data, and may request the rectification and – with the exception of mandatory processing – the erasure or withdrawal of their personal data; they may exercise their right to data portability and their right to object in the manner indicated at the time the data were collected, or at the contact details of the data controller given above.

The rights and remedies of data subjects are set out below and communicated to data subjects on the basis of Act CXII of 2011 and Regulation (EU) 2016/679. 

The right to information, otherwise known as the data subject's “right of access”: on the basis of Act CXII of 2011 and Article 15 of Regulation (EU) 2016/679, at the data subject's request the Data Controller provides information about 

  • the data it processes and the categories of personal data,
  • the purpose of the processing,
  • the legal basis of the processing,
  • the duration of the processing,
  • where applicable, the period for which the data will be stored, or, if that is not possible, the criteria used to determine that period,
  • where applicable, if the data were not collected from the data subject, all available information about their source,
  • where applicable, automated decision-making, including profiling, and meaningful information about the logic involved, as well as the significance of such processing and
  • the envisaged consequences of such processing for the data subject,
  • the details of the data processor, if a data processor has been used, and the circumstances and effects of any data protection incident and the measures taken to address it, and
  • in the event of the transfer of the data subject's personal data, the legal basis, purpose and recipient of the transfer.

The information is free of charge if the person requesting it has not yet submitted a request for information on the same scope of data to the Data Controller in the current year. In other cases, a cost reimbursement may be charged. Any cost reimbursement already paid must be refunded if the data were processed unlawfully or if the request for information led to rectification.

The Data Controller draws the attention of data subjects to the fact that, under Act CXII of 2011, the information must be refused,

  1. if, on the basis of a law, an international treaty or a binding legal act of the European Union, the Data Controller receives personal data in such a way that the transferring data controller indicates, at the same time as the transfer, the restriction of the rights guaranteed to the data subject under the said act, or another restriction on the processing;
  2. in the interest of the external and internal security of the state, such as national defence, national security, the prevention or prosecution of criminal offences and the security of the enforcement of penalties, as well as for state or local government economic or financial reasons, in the significant economic or financial interest of the European Union, and for the purpose of preventing and detecting disciplinary and ethical offences connected with the practice of professions and breaches of labour law and occupational safety obligations – including in every case supervision and inspection – and in the interest of protecting the rights of the data subject or of others.

The Data Controller is obliged to notify the Hungarian National Authority for Data Protection and Freedom of Information of refused requests for information each year by 31 January of the year following the reference year.

The right to rectification: the data subject has the right to obtain from the Data Controller, without undue delay, the rectification of inaccurate personal data concerning them. Taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement. At the same time, if the personal data do not correspond to reality and the Data Controller has the personal data corresponding to reality at its disposal, the Data Controller rectifies the personal data as a matter of obligation, even without a request from the data subject.

The right to erasure, otherwise known as the “right to be forgotten”: the data subject has the right to obtain from the Data Controller the erasure of personal data concerning them without undue delay, and the Data Controller is obliged to erase personal data concerning the data subject without undue delay, provided that mandatory processing does not preclude this.

Apart from the case above, the Data Controller is obliged to erase the data under Act CXII of 2011 and Regulation (EU) 2016/679 of the European Parliament and of the Council if

  • the processing of the data is unlawful;
  • the data are incomplete or incorrect – and this state cannot lawfully be remedied – provided that erasure is not excluded by law;
  • the purpose of the processing has ceased, or the statutory period for storing the data has expired;
  • it has been ordered by a court or by the Authority;
  • the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
  • the data subject objects to the processing and there is no overriding legitimate ground for the processing;
  • the personal data must be erased for compliance with a legal obligation under the law applicable to the Data Controller;
  • the personal data were collected in relation to the offer of information society services referred to in Article 8(1) of Regulation (EU) 2016/679 offered directly to children.

If, for any reason, the Data Controller has made the personal data public and is obliged to erase them as set out above, it takes the reasonably expected steps – including technical measures – taking account of the available technology and the cost of implementation, in order to inform other controllers processing the data that the data subject has requested the erasure of links to, or copies or replications of, those personal data.

The Data Controller draws the attention of data subjects to the limits of the right to erasure or the “right to be forgotten” arising from the EU regulation, which are the following:

  1. exercising the right of freedom of expression and information;
  2. compliance with an obligation under Union or Member State law applicable to the controller which requires the processing of personal data, or the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  3. reasons of public interest in the area of public health;
  4. archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) of Regulation (EU) 2016/679, in so far as the right to erasure is likely to render impossible or seriously impair the achievement of that processing; or
  5. the establishment, exercise or defence of legal claims.

The right to restriction of processing, otherwise known as the right to blocking: the data subject has the right to obtain from the Data Controller restriction of processing at their request.
If, on the basis of the available information, it can be assumed that erasure would harm the legitimate interests of the data subject, the data must be blocked. Personal data blocked in this way may be processed only for as long as the purpose of processing that precluded the erasure of the personal data continues to exist.

If the data subject contests the accuracy or correctness of the personal data, but the incorrectness or inaccuracy of the contested personal data cannot be established unambiguously, the data are blocked. In this case the restriction applies for a period enabling the Data Controller to verify the accuracy of the personal data.

Under the EU regulation, the data must be blocked if

  1. the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead;
  2. the Data Controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims; or
  3. the data subject has objected to the processing; in this case the restriction applies for the period until it is established whether the legitimate grounds of the Data Controller override those of the data subject.

Where processing is subject to restriction (blocking), such personal data may, with the exception of storage, be processed only with the data subject's consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State.

The Data Controller hereby expressly draws the attention of data subjects to the fact that the data subject's right to rectification, erasure and blocking may be restricted by law in the interest of the external and internal security of the state, such as national defence, national security, the prevention or prosecution of criminal offences and the security of the enforcement of penalties, as well as for state or local government economic or financial reasons, in the significant economic or financial interest of the European Union, and for the purpose of preventing and detecting disciplinary and ethical offences connected with the practice of professions and breaches of labour law and occupational safety obligations – including in every case supervision and inspection – and in the interest of protecting the rights of the data subject or of others.
The Data Controller informs the data subject of the matters set out in their request without undue delay, and at most within 30 days of the receipt of the request, and/or rectifies the data, and/or erases and/or restricts (blocks) the data, or takes other steps in accordance with the request, if there is no reason precluding this.

The Data Controller notifies the data subject in writing of the rectification, the erasure and the restriction of processing, as well as all those to whom the data were previously transferred or handed over for the purpose of processing. At the data subject's request, the Data Controller informs them of these recipients. The notification may be omitted if, having regard to the purpose of the processing, it does not harm the legitimate interests of the data subject, or if providing the information proves impossible or would involve a disproportionate effort. The Data Controller is also obliged to notify the data subject in writing if the data subject's exercise of their rights cannot be realised for any reason, and is obliged to state precisely the factual and legal grounds, together with the remedies available to the data subject: the possibility of turning to the courts and to the Hungarian National Authority for Data Protection and Freedom of Information.

The “right to data portability”: the data subject has the right

  1. to receive the personal data concerning them, which they have provided to the Data Controller, in a structured, commonly used, machine-readable format, and furthermore has the right
  2. to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where:
  3. the processing is based on consent; and
  4. the processing is carried out by automated means.

In exercising the right to data portability, the data subject has the right to request that the personal data be transmitted directly from one controller to another, where technically feasible.
In view of the processing carried out by the Data Controller, the conditions for exercising the right to data portability are not met (there is no automated processing), and the data subject is therefore unable to exercise this right.

The right to object: the data subject may object to the processing of their personal data – including profiling – if

  • the processing (transfer) of the personal data is necessary solely for the enforcement of a right or legitimate interest of the Data Controller or of the recipient of the data, except in the case of mandatory processing;
  • the personal data are used or transferred for the purposes of direct marketing, public opinion research or scientific research;
  • the exercise of the right to object is otherwise permitted by law.

The data subject may also object, on the basis of Article 21(3) of Regulation (EU) 2016/679, to the processing of personal data for direct marketing purposes; in this case the personal data may no longer be processed for such purposes.

Where personal data are processed for scientific or historical research purposes or statistical purposes, the data subject has the right to object, on grounds relating to their particular situation, to the processing of personal data concerning them, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
The Data Controller – suspending the processing at the same time – examines the objection within the shortest possible time from the submission of the request, but within 30 days at the latest, and informs the applicant of the result in writing. If the applicant's objection is well founded, the Data Controller terminates the processing – including any further data collection and transfer – and blocks the data, and notifies of the objection and of the measures taken on its basis all those to whom it previously transferred the personal data concerned by the objection and who are obliged to take action in order to give effect to the right to object.

If the data subject does not agree with the Data Controller's decision, or if the Data Controller fails to observe the said deadline, the data subject is entitled to turn to the courts within 30 days of its communication.
The data subject has the right to object in relation to automated decision-making.

Enforcement before the courts: in the event of an infringement of their rights, the data subject may turn to the courts. The court deals with the case out of turn. It is for the Data Controller to prove that the processing complies with the statutory provisions.

In the event of an infringement of your right to informational self-determination, you may lodge a report or complaint with:

Hungarian National Authority for Data Protection and Freedom of Information
Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
Telephone: +36 (1) 391-1400, Fax: +36 (1) 391-1410
web: http://www.naih.hu
e-mail: ugyfelszolgalat@naih.hu