DATA MANAGEMENT INFORMATION

Regarding Data Management by 22 Media and Design Studio Ltd.

The purpose of this information is to record the data protection and data management principles applied by 22 Media and Design Studio Ltd. (hereinafter: Data Controller), which it recognizes as binding upon itself, and to inform the Data Subjects about their rights related to data management according to Regulation (EU) 2016/679 of the European Parliament and the Council (hereinafter: GDPR) and the Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (hereinafter: Infotv.).

The Data Controller undertakes to ensure that all data management related to its activities complies with the requirements set out in applicable laws, handles the data confidentially, and takes technical and organizational measures to ensure secure data management, preserving the confidentiality and integrity of the data.

Definitions

The terms used in this information shall be interpreted according to the definitions set out in Article 4, Chapter 1 of the GDPR:

Data Controller's Details

Purpose of Data Processing

The purpose of data processing is always detailed in the "Data Management Consent Statement and Information" appendix. Data collection and processing related to the Data Controller's services are based on the voluntary consent of the Data Subject or contractual relationships.

The Data Controller handles the recorded personal data in compliance with applicable data protection laws, particularly the GDPR and the Infotv., and in accordance with this information.

Principles for Processing Personal Data

The Data Controller observes and adheres to the following principles when processing personal data:

Data Transmission

The Data Controller may transfer personal data to processors listed in the data source and process registry while ensuring the confidentiality and integrity of the data. The Data Controller does not transfer personal data to other entities within the country, the Union, or third countries, or to international organizations outside of those listed.

Use of Processors

The Data Controller may use processors for its activities, as listed in the data source and process registry.

Duration of Data Processing

The duration of data storage lasts until the purpose of data processing is achieved and is specified in the "Data Management Consent Statement and Information" document.

Scope of Data Processed

During and following the provision of services, the Data Controller may process the following personal data based on the voluntary consent of the Data Subject or contractual relationships: company name, contact person/Data Subject name, corporate/business phone numbers, corporate/business email addresses, corporate/business postal addresses, Data Subject's IT device data, Microsoft personal data, usernames, and passwords.

The listed data categories are indicative, with exact specifications made in the "Data Management Consent Statement and Information" document.

Data Subject's Right of Access

The Data Subject has the right to receive confirmation from the Data Controller on whether their personal data is being processed, and if so, access to the personal data and the following information:

The Data Controller shall provide a copy of the personal data undergoing processing. For any further copies requested by the Data Subject, the Data Controller may charge a reasonable fee based on administrative costs. If the Data Subject submits the request electronically, the information shall be provided in a commonly used electronic format unless otherwise requested.

Right to Rectification

The Data Subject has the right to obtain from the Data Controller without undue delay the rectification of inaccurate personal data concerning them. Taking into account the purposes of the processing, the Data Subject has the right to have incomplete personal data completed.

Right to Erasure ('Right to be Forgotten')

The Data Subject has the right to obtain from the Data Controller the erasure of personal data concerning them without undue delay, and the Data Controller has the obligation to erase personal data without undue delay where one of the following grounds applies:

If the Data Controller has made the personal data public and is obliged to erase it, the Data Controller, taking into account available technology and implementation costs, shall take reasonable steps, including technical measures, to inform other controllers processing the personal data that the Data Subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data.

The right to erasure does not apply to the extent that processing is necessary:

Right to Restriction of Processing

The Data Subject has the right to obtain from the Data Controller restriction of processing where one of the following applies:

Where processing has been restricted under the above conditions, such personal data shall, with the exception of storage, only be processed with the Data Subject's consent or for the establishment, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.

The Data Controller shall inform the Data Subject before the restriction of processing is lifted.

Right to Object

The Data Subject has the right to object, on grounds relating to their particular situation, at any time to processing of personal data concerning them which is based on the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller, or processing necessary for the purposes of the legitimate interests pursued by the Data Controller or a third party, including profiling based on those provisions. The Data Controller shall no longer process the personal data unless the Data Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the Data Subject or for the establishment, exercise, or defense of legal claims.

Where personal data is processed for direct marketing purposes, the Data Subject has the right to object at any time to processing of personal data concerning them for such marketing, including profiling to the extent that it is related to such direct marketing. If the Data Subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.

Where personal data is processed for scientific or historical research purposes or statistical purposes in accordance with the GDPR, the Data Subject, on grounds relating to their particular situation, shall have the right to object to processing of personal data concerning them unless the processing is necessary for the performance of a task carried out for reasons of public interest.

The right to object can be exercised electronically by the Data Subject.

Right to Data Portability

The Data Subject has the right to receive the personal data concerning them, which they have provided to a Data Controller, in a structured, commonly used, and machine-readable format and has the right to transmit those data to another Data Controller without hindrance from the Data Controller to which the personal data have been provided, where:

The Data Controller shall provide the requested data in XML format to the Data Subject on a data carrier provided by the Data Subject.

In exercising the right to data portability, the Data Subject shall have the right to have the personal data transmitted directly from one Data Controller to another, where technically feasible. Such a request must be made in writing by the Data Subject, accompanied by proof of identity.

The right to data portability shall not adversely affect the rights and freedoms of others.

Right to Withdraw Consent

The Data Subject has the right to withdraw their consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Before giving consent, the Data Subject shall be informed thereof. The consent withdrawal can be done using the "Data Management Consent Withdrawal Statement" document.

Right to Lodge a Complaint with a Supervisory Authority

Without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement, if the Data Subject considers that the processing of personal data relating to them infringes the GDPR.

The supervisory authority to which the complaint has been submitted shall inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy.

The Data Controller is obliged to comply with the decision of the supervisory authority.

In Hungary, the competent supervisory authority is the National Authority for Data Protection and Freedom of Information, whose contact details are:

Automated Decision-Making and Profiling

The Data Controller ensures that no decision is made regarding the Data Subject solely on automated processing, including profiling, which produces legal effects concerning them or significantly affects them. Exceptions include:

Data Management Consent Statement and Information for Newsletter Subscription

Data processing is based on the Data Subject's voluntary, informed declaration, which includes the Data Subject's explicit consent for the use of personal data provided during newsletter subscription.

The Data Subject can unsubscribe from the newsletter at any time using the contacts in the newsletter or the "Unsubscribe" feature, which constitutes withdrawal of consent. In such cases, all data of the Data Subject will be immediately deleted.

The Data Controller does not verify the accuracy of the personal data provided. The Data Subject is solely responsible for the accuracy of the data provided. By providing their email address, the Data Subject assumes responsibility for the use of the service from the provided email address.