privacy notice
This page is an English translation, provided for convenience, of our Hungarian-language data processing notice ("Adatkezelési tájékoztató ügyfelek részére"). The Hungarian original is the legally authoritative version. Download the original PDF (Hungarian).
Mobil Kapcsolat Plc., operator of the PRISMA - Controlled Connection platform, is committed to protecting your personal data and to respecting your right to informational self-determination. We handle your personal data in confidence and take every technical and organisational security measure needed to keep it safe.
By providing us with personal data or other information, you confirm that you have read and understood the version of this notice in force at that time, and that you knowingly accept and consent to Mobil Kapcsolat Plc. processing your personal data for the purposes listed below.
We reserve the right to amend this notice unilaterally, with effect from the date of the change. We recommend checking this page periodically so you can keep track of any changes. On request, we will notify you of changes or send you the version of this notice currently in force.
Please note that, on the basis of statutory authorisation, other bodies - the National Authority for Data Protection and Freedom of Information (NAIH), investigating authorities, the prosecution service, courts, and similar - may approach us as data controller, requesting information, the disclosure of data, or the handing over of documents. Mobil Kapcsolat Plc. discloses personal data only to the extent, and in the manner, that is sufficient for the purpose of such a request and for which statutory authorisation exists, once the exact purpose and the scope of data requested has been specified.
Who we are
Mobil Kapcsolat Plc. - operator of the PRISMA platform
- Address
- 1117 Budapest, Alíz utca 1., Building B, 6th floor, Hungary
- Company registration number
- 01-10-141662
- Registered by
- Fővárosi Törvényszék Cégbírósága (Company Registry Court of the Budapest-Capital Regional Court)
- Tax number
- 27539365-2-43
- EU VAT ID
- HU27539365
- Represented by
- Péter Megyeri
- Internal data protection officer
- Krisztina Kovácsné Cserni
- info@prismaservices.eu
- Website
- www.prismaservices.eu
Processing activities we carry out
This notice covers the personal data we process, and why, across the following activities:
- GDPR compliance and data-subject request handling
- Complaints and quality objections
- Contracted private-individual partners
- Contact persons and representatives of business partners
- Cookies
- Help desk service
- Partner relations, enquiries and business communication
- Electronic monitoring and recording (CCTV)
GDPR compliance and data-subject request handling
- Purpose
- Complying with the data-protection obligations that apply to us as controller in relation to customers and partners, and demonstrating that compliance.
- What this involves
- We record and fully manage data-protection incidents and data-subject requests, for transparent communication with you and so you can exercise your rights. Where we act on a request, we process only the identifying data that is strictly necessary to do so.
- Legal basis
- Necessary for compliance with our legal obligations.
- Applicable law
- Regulation (EU) 2016/679 (GDPR); Act CXII of 2011 on informational self-determination and freedom of information.
- If you don't provide this data
- We would be unable to fulfil our legal obligation, risking unlawful storage or handling of personal data and regulatory sanctions.
- Responsible / recipients
- Managing director, administrator, internal data protection officer.
- Data subjects
- Anyone whose data we process in this context.
- Source of data
- The data subject; our customers.
- Data retained & retention period
- The request, information or incident report received, the sender's personal data (name, contact details) and its content (subject, type, documentation, outcome, etc.) - kept until the individual matter is resolved.
- In force since
- 25 May 2018.
- Storage
- Electronically, in our e-mail system and on our network; on paper, under lock.
- International transfer
- None.
Complaints and quality objections
- Purpose
- Consumer-protection administration; handling complaints and quality objections about our products and services.
- What this involves
- We process customers' and clients' personal data to handle complaints and quality objections concerning our products and services, as required by consumer-protection and e-commerce law. Beyond the mandatory name and address, you may voluntarily provide further data (contact details, e-mail, phone number); any documents or evidence you submit may also contain personal data.
- Legal basis
- Necessary for compliance with our legal obligations.
- Applicable law
- Act V of 2013 on the Civil Code (§6:22); Act CLV of 1997 on consumer protection; Act CVIII of 2001 on certain e-commerce services and information-society services.
- If you don't provide this data
- You would be unable to exercise your consumer rights.
- Responsible / recipients
- Managing director, administrator, operator.
- Data subjects
- Customers, clients, authorised representatives.
- Source of data
- Customers, clients, tenants.
- Data retained & retention period
- Name, address, comments, objections, contact details, other evidence - kept for 5 years.
- In force since
- 25 May 2018.
- Storage
- Electronically, in our e-mail system and on our network; on paper, under lock.
- International transfer
- None.
Contracted private-individual partners
- Purpose
- Concluding, performing and terminating engagement agreements with private-individual contractors; establishing and maintaining that relationship.
- What this involves
- We keep records of contractors engaged under service agreements in order to coordinate, carry out and oversee those agreements, and to take steps at your request before entering into one. Applying data minimisation, only the data genuinely needed case by case is processed.
- Legal basis
- Necessary for performance of a contract, or to take steps at your request before entering into one.
- Applicable law
- Act C of 2000 on accounting.
- If you don't provide this data
- The engagement relationship cannot be established and contact cannot be maintained.
- Responsible / recipients
- Managing director, administrator, finance assistant.
- Data subjects
- Private-individual contractors.
- Source of data
- The contractors themselves, and our staff and associates involved in concluding, performing or terminating the agreement.
- Data retained & retention period
- Name, address, e-mail address, phone number, bank account number, mother's name, tax identification number, tax number, home address, the represented company's data and the individual's position within it - kept for 8 years.
- In force since
- 25 May 2018.
- Storage
- On paper, in a binder at our office; electronically, in our e-mail system and on our network.
- International transfer
- None.
Contact persons and representatives of business partners
- Purpose
- Performing contracts with customers that are not private individuals; general business contact.
- What this involves
- We keep records of the natural-person representatives and contact persons of our business partners, principals, suppliers, subcontractors and banks, in order to maintain business contact and to conclude and perform contracts, applying data minimisation so that only the most necessary data of representing employees or contact persons is processed.
- Legal basis
- Necessary for performance of a contract, or to take steps at your request before entering into one.
- Applicable law
- Act C of 2000 on accounting; Act CXXXIII of 2003 on condominiums.
- If you don't provide this data
- The customer relationship cannot be established, contact cannot be maintained, and the contract cannot be concluded or performed.
- Responsible / recipients
- Managing director, administrator, finance assistant.
- Data subjects
- Natural-person representatives and contact persons of business partners.
- Source of data
- The business partners' own representatives and contact persons.
- Data retained & retention period
- Name, phone number, e-mail address, the represented company's data and the individual's position within it - kept for 8 years.
- In force since
- 25 May 2018.
- Storage
- Electronically, in our e-mail system and on staff mobile devices, on our network, and in contracts.
- International transfer
- None.
Cookies
- Purpose
- Making sure our website works correctly and our service can be provided - through technically essential session and security cookies - and, where you consent, gathering statistics.
- What this involves
- Session and security cookies are necessary so visitors can browse our website and use its features without interruption. Beyond that, we also collect data for statistical and convenience purposes, but only if you accept it.
- Legal basis
- For essential cookies: necessary for performance of a contract, or to take steps at your request before entering into one. For optional cookies: your consent.
- Applicable law
- Act CVIII of 2001 on certain e-commerce services and information-society services (§13/A); Act C of 2003 on electronic communications (§155(4)).
- If you don't provide this data
- Our website may not work correctly and our service may be disrupted.
- Responsible / recipients
- The Company. Website operator: Mobil Kapcsolat Plc.
- Data subjects
- Website visitors.
- Source of data
- Visitors to our website.
- Retention
- Until the purpose of processing has been achieved; a session cookie is deleted once the session or browser closes.
- In force since
- 25 May 2018.
- International transfer
- Any transfer to a third country or international organisation is only ever carried out in full compliance with the Regulation.
| Name | Purpose | Data stored | Duration |
|---|---|---|---|
| laravel_session | System cookie that keeps the website working correctly. | No personal data; issues an anonymous identifier. | For the session. |
| Name | Purpose | Data stored | Duration |
|---|---|---|---|
| XSRF-TOKEN | Session cookie supporting the security of the platform and its forms. | Only the visitor identifier generated by the laravel_session cookie. | For the visit only; deleted once browsing ends. |
| reCAPTCHA (third-party, Google) | Protects the contact form against automated submissions. See Google reCAPTCHA Terms. | Set by Google. | Set by Google. |
| Name | Purpose | Data stored | Duration |
|---|---|---|---|
| cookie_skip_popup | Remembers your cookie choice so it's applied automatically on your next visit. | Stored only in your own browser; we store nothing. | Until you delete it yourself. |
| Name | Purpose | Data stored | Duration |
|---|---|---|---|
| Google Analytics (third-party) | Collects anonymised statistics about website visitors. Set by www.google-analytics.com/analytics.js. See Google Analytics Terms and Google Privacy Policy. | Set by Google. | Set by Google. |
Our web server and website also keep text log files for development and debugging purposes (access log and error log), recording the visitor's IP address, operating system, page visited, date and time. These are kept for 7 days and then deleted automatically.
You can review or change your cookie choices at any time - see our Cookie Policy.
Help desk service
- Purpose
- Handling service requests under contract and warranty claims; investigating complaints submitted directly to us.
- What this involves
- We examine whether a consumer's warranty claim is justified and fulfil it where it is. For warranty claims, we are required to record the consumer's name, address, and their consent to us processing that data as set out in the record. For complaints received directly, beyond the mandatory data you may voluntarily provide further data (contact details, e-mail, phone number); documents and other evidence you submit may also contain personal data.
- Legal basis
- Necessary for performance of a contract, or to take steps at your request before entering into one; for warranty claims, necessary for compliance with our legal obligations.
- Applicable law
- Government Decree 249/2004 (VIII. 27.) on mandatory warranty for certain repair and maintenance services (§4(6)); Act V of 2013 on the Civil Code.
- If you don't provide this data
- The service cannot be carried out, or the warranty claim cannot be enforced.
- Responsible / recipients
- Help-desk staff; contracted partners involved in the investigation.
- Data subjects
- Anyone contacting our help desk, or their representative; complainants.
- Source of data
- The person submitting the request, or their representative.
- Data retained & retention period
- Identifier, name, address, phone number, comments, objections, fault description, contact details, other evidence - kept for 5 years.
- In force since
- 25 May 2018.
- Storage
- Electronically, in our help-desk system; on paper; by e-mail.
- International transfer
- None.
Partner relations, enquiries and business communication
- Purpose
- Maintaining contact with partners and prospects; establishing and running customer relationships; carrying out our business activity and providing our services (quotes, contracts, contract performance, and similar).
- What this involves
- We keep records of prospects and people who initiate contact in order to maintain contact and provide information, applying data minimisation. Messages received through our contact channels - e-mail or the website's contact form - may also contain other personal data. We also process the personal data of people we meet at business events (conferences, trade fairs, training sessions, etc.), and of contact persons, representatives or associates designated by other legal persons we deal with in the course of our business activity. Where useful, we also keep records of contacts at various authorities and institutions, to facilitate communication with them.
- Legal basis
- Necessary for the legitimate interests pursued by us or by a third party (the related legitimate-interest assessment, "Partner", can be inspected at our office).
- Applicable law
- Act C of 2000 on accounting.
- If you don't provide this data
- The partner relationship cannot be established and contact cannot be made.
- Responsible / recipients
- The Company.
- Data subjects
- Prospects; contact persons, representatives and associates designated by other legal persons we have a business relationship with; participants at business events.
- Source of data
- Prospects, and the persons designated by the legal persons described above.
- Data retained & retention period
- Name, phone number, e-mail address, the represented company's data and the individual's position within it - kept for 8 years.
- In force since
- 25 May 2018.
- Storage
- Electronically, in our e-mail system and on staff mobile devices, on our network; on paper.
- International transfer
- None.
Electronic monitoring and recording (CCTV)
We operate an electronic monitoring and recording (CCTV) system at our premises. The detailed notice and policy governing that system can be inspected on request from our internal data protection officer, or at reception.
Data processing (our processors)
Where processing is carried out on our behalf by someone else, we only ever use processors that provide sufficient guarantees to implement appropriate technical and organisational measures, so that processing meets the Regulation's requirements and protects your rights. Every processor we use is bound, by contract or another legal instrument, to:
- process personal data only on our documented instructions;
- ensure that everyone authorised to process the data has committed to confidentiality;
- take the security measures required by GDPR Article 32;
- help us respond to data-subject requests and meet our own obligations under GDPR Articles 32-36;
- delete or return all personal data once the service ends, unless the law requires it to be kept;
- make available to us all information needed to demonstrate compliance, and allow audits, including on-site inspections.
Mobil Kapcsolat Plc. itself also acts as a data processor for some of its own customers. In that role, we guarantee — in particular as regards expertise, reliability and resources — that we carry out the technical and organisational measures the Regulation requires, including the security of processing, and that everyone with access to personal data in that role is bound by confidentiality.
The processors currently engaged to run this website are:
Hosting provider
- Company
- DV Info Informatikai Ltd.
- Address
- 4025 Debrecen, Piac utca 77., Hungary
- info@dvinfo.hu
- Website
- www.dvinfo.hu
Website developer
- Company
- Monogramma Ltd.
- Address
- 8175 Balatonfűzfő, Fűzliget sétány 3. D., Hungary
- hello@monogramma.hu
- Website
- www.monogramma.hu
International data transfers
We comply with the Regulation's provisions on international data transfers, in particular Chapter V, having regard to recitals 101-116. Whenever personal data is transferred to a third country or an international organisation, you are entitled - as set out in GDPR Article 46 — to be informed of the appropriate safeguards applied to that transfer. We do not currently transfer personal data to a third country in connection with any of the processing activities listed in this notice.
Your rights
In line with applicable law, you can exercise the following rights over the personal data we hold about you, using the contact details above:
Right to information and access
For as long as we process your data, you can request information about, and access to, the personal data we hold on you and how we process it - including our identity and contact details, the purpose, legal basis and duration of processing, the identity of any processor we use, the legal basis and recipient of any data transfer, and (where a data breach is likely to result in a high risk to your rights and freedoms) information about that breach.
Right to rectification
You can ask us to correct your personal data at any time during processing - if your data has changed or is inaccurate, we will update it on request.
Right to erasure
Where you have consented to processing, you can withdraw that consent at any time and ask us to erase your data, provided there is no other legal basis for processing it - this does not affect the lawfulness of processing carried out before the withdrawal. Beyond that, you can ask us to erase your data without undue delay where: it is no longer needed for the purpose it was collected for; you object to the processing and there is no overriding legitimate ground for it; it has been processed unlawfully; erasure is required by a legal obligation that applies to us; or the data was collected in connection with offering information-society services. We cannot erase data where processing is necessary for freedom of expression and information; to comply with a legal obligation or a task carried out in the public interest; for reasons of public health; for archiving, scientific, historical or statistical purposes; or for the establishment, exercise or defence of legal claims.
Right to restriction of processing
We will restrict processing of your data on request where: you contest its accuracy, for the period needed to verify it; the processing is unlawful but you oppose erasure and request restriction instead; we no longer need the data but you need it for a legal claim; or you have objected to processing, pending verification of whether our grounds override yours. While restricted, your data may only be stored, or otherwise processed with your consent, for legal claims, to protect another person's rights, or for an important EU or member-state public interest. We will tell you before lifting a restriction.
Right to object
You can object to processing of your data where it is based on our or a third party's legitimate interest, or on a public-interest or official-authority task assigned to us. In that case, we will stop that processing unless we can demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or that the processing is needed to establish, exercise or defend legal claims. You can also object at any time to your data being processed for direct-marketing purposes, including any related profiling - once you do, we will stop that processing for that purpose.
Automated decision-making and profiling
You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you. This does not apply where the decision is necessary for a contract between you and us, is authorised by law with safeguards for your rights and legitimate interests, or is based on your explicit consent.
Right to data portability
Where processing is based on your consent or on a contract, and is carried out by automated means, you can ask to receive the personal data you provided to us in a structured, commonly used, machine-readable format, and to have it transmitted to another controller without hindrance from us.
Exercising these rights after your death
Under Hungarian law, within five years of a data subject's death, a person the data subject authorised - by an official registration, a public document, or a private document with full evidentiary force lodged with us (if more than one, the latest such document) — may exercise the rights the data subject would have had. If no such authorisation was made, a close relative under the Civil Code may exercise those rights instead, within the same five years; whichever close relative exercises this right first is the one entitled to do so.
How we handle your requests
We will inform you of any action taken on a request under GDPR Articles 15-22 without undue delay, and in any event within one month of receiving it. Where necessary, taking into account the complexity and number of requests, that period can be extended by a further two months; if so, we will tell you about the extension, and our reasons for it, within one month of receiving your request. If you submitted your request electronically, we will reply electronically unless you ask otherwise.
If we do not act on your request, we will tell you why, without delay and at the latest within one month of receiving it, and inform you that you can lodge a complaint with a supervisory authority and seek judicial remedy.
We provide the information and actions you request free of charge. If your request is manifestly unfounded or excessive - in particular because it is repetitive — we may charge a reasonable fee that reflects our administrative costs, or refuse to act on the request.
We will inform every recipient to whom your personal data was disclosed of any rectification, erasure or restriction we carry out, unless that proves impossible or involves disproportionate effort; on request, we will tell you who those recipients are.
We will provide you with a copy of the personal data undergoing processing. We may charge a reasonable, cost-based fee for any further copies you request. If you submitted your request electronically, the information will be provided in a commonly used electronic format, unless you ask otherwise.
Complaints and judicial remedy
If you believe your rights have been infringed, we recommend first raising it with our representative at the contact details above. If that does not resolve the matter, or you would rather not pursue it that way, you are entitled to lodge a complaint with the National Authority for Data Protection and Freedom of Information (NAIH), or to bring the matter before a court - court proceedings of this kind are handled as a priority, and you may choose to bring the action before the regional court with jurisdiction over your place of residence or stay.
National Authority for Data Protection and Freedom of Information (NAIH)
- Address
- 1055 Budapest, Falk Miksa utca 9-11., Hungary
- Postal address
- 1363 Budapest, Pf. 9., Hungary
- Phone
- +36 1 391 1400 or +36 30 683 5969
- Fax
- +36 1 391 1410
- ugyfelszolgalat@naih.hu
- Website
- naih.hu
This "Data processing notice for customers" was last updated on 4 April 2025.