Privacy Policy

  • Last updated: Dec 1, 2020
When processing personal data collected from users and customers through the use of our website, e-mail and newsletter subscriptions, or in connection with our other activities, our company only requests and processes personal data that is strictly necessary and suitable for the purpose of the data processing.

In connection with our activities, we process the following personal data of our customers and website users: Company name, Registered seat, Contact person, Phone number, E-mail address
for the following purposes: Registration purposes

We take responsibility for the security of the data we process and guarantee its protection in the event of a physical or technical incident; access to this data and the restoration and continuous review of the data set is ensured by the technical solution we apply.

We do not disclose the data you provide to any third party for commercial or other purposes, unless you have expressly consented to it — for example, for the purpose of receiving offers from other merchants.

Our company uses cookies on its website, for which we ask for your consent as a user (which you may withdraw at any time later).

You can give your consent when visiting the website by ticking the small checkbox.

It is important to know that cookies allow our website to provide you with personalized information, but the use of our website is not conditional on accepting this application.

By accepting the use of "cookies," our website only obtains data that you would provide anyway, i.e. our website does not receive any information via the cookie banner that the user does not wish to provide, and it cannot access the files stored on your computer.

You have the right to request the modification or deletion of the data we process about you at any time, using the following contact details:
info@numinc.com

You may raise objections or complaints regarding the processing of your data at the following contact details: info@numinc.com

Upon your request, we provide information about the data we process, or the data processed by a data processor engaged by us or at your instruction, including its source, the purpose and legal basis of the processing, its duration, the name and address of the data processor and its activities related to the data processing, the circumstances and effects of any data breach and the measures taken to remedy it, as well as — in the event your personal data is transferred — the legal basis and recipient of the data transfer.

Our company's internal data protection officer is responsible for overseeing measures related to any data breach and keeps a register for the purpose of informing data subjects, which contains
  • the scope of the personal data concerned,
  • the scope and number of those affected by the data breach,
  • the time, circumstances and effects of the data breach and the measures taken to remedy it, as well as
  • other data specified in the legislation governing the processing.

The data controller keeps a data transfer register for the purpose of verifying the lawfulness of data transfers and informing data subjects, which contains the date of transfer of the personal data it processes, the legal basis and recipient of the transfer, a description of the scope of the personal data transferred, as well as other data specified in the legislation governing the processing.

The retention period for the data protection and data transfer registers — and, based on this, the information obligation — may be limited by the legislation governing the processing. Within this limitation, the retention period may not be shorter than five years for personal data and twenty years for special categories of data.

Our company, as Data Controller, is obliged to provide the information requested in a comprehensible form, in writing, at the data subject's request, within the shortest possible time but no later than 25 days from submission of the request. This information is provided free of charge if the person requesting it — in this case, you — has not yet submitted a request for information regarding the same set of data to the data controller in the current year.

In other cases, we charge a cost reimbursement. The amount of the cost reimbursement may be set out in the agreement between our company and the data subject. We are obliged to refund any cost reimbursement already paid if the complainant's data was processed unlawfully, or if the request for information led to a rectification.

Correcting personal data that does not correspond to the facts is our obligation arising from our capacity as Data Controller.

Personal data is deleted if its processing is unlawful, if the data subject requests it, if it is incomplete or incorrect and this cannot be lawfully corrected — provided that deletion is not prohibited by law — if the purpose of the processing has ceased, if the statutory retention period for the data has expired, or if ordered by a court or the data protection commissioner.

We notify the data subject of any rectification or deletion, as well as everyone to whom the data was previously transferred for processing purposes. Notification may be omitted if it does not infringe the data subject's legitimate interest with regard to the purpose of the processing.

The data subject may object to the processing of their personal data if the processing (or transfer) of the personal data is necessary solely for the enforcement of the rights or legitimate interests of the data controller or the data recipient, except where the processing is ordered by law, where the personal data is used or transferred for direct marketing, public opinion research or scientific research purposes, or where the exercise of the right to object is otherwise permitted by law.

Our company, as Data Controller, is obliged — while simultaneously suspending the processing — to examine the objection within the shortest possible time, but no later than 15 days from submission of the request, and to inform the requester in writing of the result. If the objection is justified, we fulfill our obligation to terminate the processing — including any further data collection and transfer — and to block the data, and we notify everyone to whom the personal data affected by the objection was previously transferred, and who are obliged to take action to enforce the right to object, of the objection and any measures taken as a result.

We may only refuse to inform the data subject in exceptional cases — as specified in Section 9(1) and Section 19 of Act CXII of 2011.

In such a case, we inform the data subject in writing of the provision of this Act under which the disclosure was refused. In the event of refusal, we inform the data subject of the possibility and method of judicial remedy and of applying to the Authority.

We notify the Authority of rejected requests annually, by January 31 of the year following the relevant year.

In the event of a violation of their rights — of which we inform the complainant — the data subject may turn to the courts or the data protection authority against our company as Data Controller. Remedies and complaints may be pursued at the following contact details:
Name: National Authority for Data Protection and Freedom of Information (Hungary)
Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c., Hungary
Phone: +36-1-391-1400
Fax: +36-1-391-1410
E-mail: ugyfelszolgalat@naih.hu
Website: www.naih.hu

Dated: December 1, 2020

Print