Loxon’s Privacy Policy
Loxon Solutions Zrt
Company registration number: 01-10-047809
Registration authority: Company Registry Court of the Metropolitan Court of Budapest
Tax number: 14356933-2-41
Registered office: 1134 Budapest, Lőportár utca 20/b.
Mailing address (place of data processing): 1134 Budapest, Lőportár utca 20/b.
Telephone: (+36)-1-789-0626
Email: office@loxon.eu
Registration numbers for the purpose of data processing issued by the National Authority for Data Protection and Freedom of Information: NAIH-107805/2016 and NAIH-108914/2016
Privacy Notice
- REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Regulation (EC) No 95/46 Privacy Policy) (before and after: GDPR)
- Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (before and after: Info tv.)
- Act C of 2000 on Accounting (hereinafter: Accounting Act)
- Act CVIII of 2001 on Certain Issues of Electronic Commercial Services and Information Society Services.
- Act I of 2012 on the Labor Code
3. Rights of the data subject
Processed data | Purpose of the processing | Legal basis for processing | Duration of processing | The scope of the persons eligible for processing |
name | The data will be processed solely for the purpose of examining the employability of the candidate on the basis of application, voluntary disclosure and, if the candidate is fit for purpose, our company will establish an employment relationship with the applicant. | Article 6(1b) of GDPR: the fulfilment of contract | The data of candidates who are not contracted for employment will be retained and maintained in our database for a period of 3 years from the date of their last contact, in order to re-establish contact with them to fill any new positions that may be opened. The personal data of the data subject will then be deleted. The data of candidates data with which the employment contract is concluded will be processed in accordance with our company’s internal data management policies. | Colleagues dealing with HR and selection |
place and date of birth | ||||
place of residence | ||||
e-mail address | Article 6 (1a) of GDPR: the consent of the data subject | |||
phone number | ||||
education | ||||
job information | ||||
knowledge of foreign languages | ||||
photo | ||||
data on the results of online and personal tests completed by job applicants | Article 6 (1a) of GDPR: the consent of the data subject | |||
other information typically included in the CV, such as publications, professional recognitions, references, leisure activities |
- www.loxon.eu Career site;
- via jobs@loxon.eu;
- personally at our own and external events, conferences, job fairs, university presentations, competitions, and other events where our company appears as an exhibitor, sponsor or participant;
- by post or in person at our company premises and offices;
- In electronic or paper mail sent to our employees;
- through job portals (especially Profession, LinkedIn).
Processed data | Purpose of the processing | Legal basis for processing | Duration of processing | The scope of the persons eligible for processing |
name | notification of vacant positions and professional events, keeping contact to establish employment relationship; | Article 6 (1a) of GDPR: the consent of the data subject | Until the withdrawal of the data subject’s consent, but also in the absence thereof, for a maximum period of 3 years from the last contact. | HR staff |
date of birth | ||||
e-mail address | ||||
phone number | ||||
degree (university, major, year of graduation) |
The Marketing and Sales Area organizes and sponsors events, as well as creates and makes contents available in order to raise awareness of potential clients and partners in our company and to build a client / partner pool database from the data of their representatives and contact persons that they share with us. Our company notifies those included in the client / partner pool database of sales of our products and services and professional events and contents. The recording of the data in the client / partner pool database are made possible through the following channels:
- Self-organized events
- Third-party events
- Our company’s website
Processed data | Purpose of the processing | Legal basis for processing | Duration of processing | The scope of the persons eligible for processing |
name | Notification of the sale of our company’s products and services and of professional events | Article 6(1f) of GDPR: the legitimate interest of our company | Within 30 days of becoming aware of loss of contact quality. | Marketing and sales staff |
company name | ||||
position occupied | ||||
e-mail address | ||||
phone number |
Processed data | Purpose of the processing | Legal basis for processing | Duration of processing | The scope of the persons eligible for processing |
name | Facilitating communication with a client, business partner, concluding and executing contracts, and enforcing claims and rights under the contract | Article 6(1f) of GDPR: the legitimate interest of our company | If the information is in the contract, 5 years from the date of termination of the contract. In other cases, 30 days from the date of termination of the contact quality | management, sales and marketing manager, staff involved in the project |
e-mail address | ||||
phone number | ||||
position | ||||
Skype name | ||||
LinkedIn Profile |
Processed data | Purpose of the processing | Legal basis for processing | Duration of processing | The scope of the persons eligible for processing |
image | primarily the protection of human life, physical integrity, personal liberty and property | Article 6(1f) of GDPR: the legitimate interest of our company | 3 business days after recording | COO |
The angle of view of the cameras can only be focused on the target area. Thus, we only observe our own property or the area in use, which focuses on the following areas:
Location of cameras | Observed area |
HQ entrance door | HQ entrance door |
HQ emergency exit | HQ emergency exit |
HQ server room 1 | HQ server room entrance door |
HQ server room 2 | HQ server room emergency exit |
DC entrance door 7 | DC entrance door 7 |
DC emergency exit 7 | DC emergency exit 7 |
DC server room 7 | DC server room 7 entrance door |
DC 1 lobby 1 | DC 1 west entrance + security grille |
DC 1 lobby 2 | DC 1 east entrance + security grille |
DC emergency exit 1 | DC emergency exit 1 |
DEB entrance | DEB entrance |
DEB server room | DEB server room |
HQ = 1134 Budapest, Lőportár utca 20/b 4th floor
DC 7. = 1134 Budapest, Dévai utca 26-28. 7th floor
DC 1. = 1134 Budapest, Dévai utca 26-28. 1st floor
DEB = 4025 Debrecen, Simonffy utca 2/A.
Processed data | Purpose of the processing | Legal basis for processing | Duration of processing | The scope of the persons eligible for processing |
It varies according to the service provided to the partner, and the scope of the actual data is specified in the data processing contract concluded with the partner. | Processing of data to fulfill a service contract with our partner. | Article 6(1b) of GDPR: the fulfilment of contract | Until the service is completed. | management, sales and marketing manager, project staff, COO |
4.6. Image and video recordings
Processed data | Purpose of the processing | Legal basis for processing | Duration of processing | The scope of the persons eligible for processing |
image | marketing and advertising activity | Article 6 (1a) of GDPR: the consent of the data subject | Until the consent of the data subject is withdrawn. Processing may continue only for as long as the data can be reasonably used for the purpose of processing, even without the withdrawal of consent. | HR staff |
The data subject explicitly consents to the processing by participating in the event. If they do not wish to be included in this recording, please indicate clearly. If they for the deletion of recordings, we will do so immediately from our own database, however, the deletion of recordings that may have been printed or placed on social media platforms must be requested from directly the given organization by the data subject.
4.7. Contact details in case of emergency
In the event of an emergency, we ask our employees to provide us with contact details through which they may inform the affected person about the circumstances affecting the employee in the event of an emergency. In this scope, our company processes data as follows:
Processed data | Purpose of the processing | Legal basis for processing | Duration of processing | The scope of the persons eligible for processing |
name | contact and information | Article 6(1f) of GDPR: the legitimate interest of our company | Until the termination of employment of our employee | HR staff |
contact |
In the case of an emergency contact, it is the job and responsibility of the employee to obtain the consent of the person concerned to share their information with our company. According to Article 6(1f) of GDPR, our company receives and processes the data for the legitimate interest of our employee to the extent necessary and for a period appropriate.
4.8. Alumni Program
Our company is aiming to maintain the contact with our employees – depending on their interest in this regard – even after the termination of their employment. To this end our company has established the Alumni Program for our former employees, in the framework of which we regularly inform the members about the events and occasions organised by our company, and also offer the opportunity to participate in them. Our former employees are free to decide to participate in the Alumni Program, and we make inquiries only to those of our former employees who have given their express consent thereto.
We provide the opportunity to enter the Alumni Program through the registration surfaces available on our company’s website. In order to participate in the Alumni Program, during the registration our company requests the consent of the data subject to the processing of their personal data as follows:
Processed data | Purpose of the processing | Legal basis for processing | Duration of processing | The scope of the persons eligible for processing |
name | keeping contact and provide information | Article 6 (1) a) of GDPR: the consent of the data subject | Until the withdrawal of the data subject’s consent | HR staff |
e-mail address | ||||
phone number | ||||
period of employment at our company | statistical purposes |
The consent given to participate in the Alumni Program and to receive newsletters may be withdrawn at any time by sending an e-mail to marketing@loxon.eu or a mail to the registered office of our company, or by clicking on the “I am deleting myself from the Alumni Program” or “I unsubscribe from the newsletter” links at the bottom of the information e-mails sent under the Alumni Program.
4.9. Cookies
- Google AdWords remarketing, e-DM retargeting and display/banner retargeting and search remarketing
- Google Analytics service
- Facebook service
- LinkedIn service
- Google Tag Manager
- Instagram service
- Twitter service
5. Data transfer
5.1. By accepting these terms and conditions, you consent to data transfer to the following partners and authorities.
5.2. In the case of transfer of data abroad, the level of data protection in the third country to which the personal data are transferred may be lower than in the European Union. You acknowledge and expressly consent, when making contact, that your personal information may be accessed or transmitted by employers in such third countries. You must contact the employer, sponsor or, where applicable, the third party to prohibit their data processing.
5.3. We will not transfer sensitive data to any third party in writing or verbally, nor do we create the possibility for any third party to access sensitive data in any way.
5.4. Data transfer for each type of data processing:
5.4.1. Personal details of job applicants:
- The IT background of the online test to be filled in during the job application is provided by our business partner, the Business Case Society Korlátolt Felelősségű Társaság (company registration number: 01-09-175725, registered seat: 1076 Budapest, Thököly út 42. V. em. 33.). During the registration process in the system and in connection with the completion of the test, our partner as data processor processes the following personal data of the data subject: name, e-mail address.
5.4.2. Pool databases
- Our company is a graphic and printing contractor for subcontracting prizes, awards, gifts.
- To send invitations for the events of our companies by event organizers and subcontractors.
- To handle VIP client invitations for the given conference sponsored by our company organized by event organizers and subcontractors.
- The graphical and printing subcontractors of our company to address client gifts.
5.4.3. Partner contact information:
- To send invitations for the events of our companies by event organizers and subcontractors.
- To handle VIP client invitations for the conferences organized by event organizers and subcontractors.
- The graphical and printing subcontractors of our company to address client gifts.
- Subcontractors employed in the implementation and maintenance of our products.
- Subcontractors working closely with our company in day-to-day customer management.
- Potential partners during the bidding process for reference – only with prior consent.
- Case studies, research companies, content production companies for reference publication – only with prior consent.
- Research institutes for conducting customer satisfaction surveys.
5.4.4. Electronic surveillance system
- Our company transfers the recorded footage to third parties only in cases defined by law (e.g. to the police, labor safety authority).
5.4.5. Access to partner databases while providing the service
- Subcontractors employed in implementing our own products.
- Subcontractors working closely with our company in day-to-day customer management.
5.4.6. Image and video recordings
- Specialized in the production of content in the case of the marketing use of recordings
- subcontractors (marketing agency, graphic artist, printing house, etc.).
6. Data security
6.1. To protect the privacy of our personal information, our Company has in place technical and procedural rules that prevent unauthorized access, alteration or transmission, deliberate and accidental deletion or destruction of such information.
6.2. Incoming CVs are stored on our own network drives in an encrypted folder, which is accessible only to our company selection staff. In addition, our company records the applications in a data summary file, which is also stored on the aforementioned drive.
6.3. The data of our Partners, Clients and interested parties are recorded and managed in the HubSpot. You can find more information about HubSpot’s privacy
policy at: https://legal.hubspot.com/privacy-policy http://content.trust.salesforce.com/trust/en/learn/compliance
6.4. Please be advised that our company concludes an agreement with any partner to whom it transfers personal data or that provides our company with data processing activities. In order to increase the security available when processing your data, our company obliges this partner to carry out its activities in accordance with the Privacy Policy.
6.5. In addition to the above, our company conducts quarterly audits to verify if the requirements of these and the related internal policies have been met, any data protection incident has occurred, the requests for data processing (including deletion) has been performed, or whether there have been any circumstances that may affect the data processing. Through this periodic review, our company aims to promote the security of personal data and the most appropriate management of data.
7. Control
7.1. We expressly state that the monitoring and control regulated herein will be carried out solely for the specific purpose to be achieved, when the economic interests of our company, any employee of our company (especially property protection) or one of our partners are justifiable. Recorded material should only be reviewed in the event of a suspected violation of law or crime, or in the case of an occupational accident.
7.2. The monitor for viewing and reviewing the images is placed so that they cannot be seen by anyone outside the scope of authority during the transfer of the images. Surveillance and monitoring of stored images shall be conducted solely for the purpose of detecting offenses and taking any action needed to put an end to them. It is not allowed record images from cameras other than the central recording unit.
7.3. It is to be noted that there is currently no other method or procedure by which the above stated objectives can be achieved, which would involve either no data processing or more limited processing.
8. Enforcement
8.1. You can assert your right to the protection of your personal data before a civil court, or you can contact the Office of the Commissioner for Fundamental Rights or the National Data Protection and Information Authority.
8.2. National Data Protection and Freedom of Information Authority (address: 1125 Budapest, Szilágyi Erzsébet fasor 22 / C, postal address: 1530 Budapest, Pf.: 5.) anyone may initiate an investigation by filing a complaint alleging that there has been or there is an imminent threat of infringement of law relating to the processing of personal data or the exercise of their rights to becoming aware of information of public interest or which are public due to public interest.
8.3. You can refer to the court concerned:
– the denial of information
– the rejection of the request for rectification, deletion or blocking
– the violation of your rights; and
– if you disagree with the decision on the request for objection, or if our company fails to comply with the deadline for examining the request for objection, within 30 days of the date of notification of the decision or the last day of the deadline.
8.4. The court in the place where the company as the defendant is seated (Budapest Metropolitan Court) has jurisdiction to hear the case. At the choice of the data subject, the lawsuit may be initiated before the court in the place where they are domiciled.
9. Incident management
9.1. Pursuant to the Regulation, “privacy incident” means a breach of security that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of or unauthorized access to the personal data transferred, stored or otherwise processed.
9.2. As soon as our company becomes aware of a privacy incident, it shall report it to the competent supervisory authority without undue delay and, if possible, no later than 72 hours after becoming aware of the privacy incident.
9.3. If you have any complaints, objection about our company’s processing, please contact our company for consultation before initiating any of the above procedures.
LOXON SOLUTIONS Zrt.