Privacy Policy
Contents
- Details of the Data Controller
- Purpose and Scope of this Privacy Policy
- Applicable Legislation and Data Protection Principles
- Individual Data Processing Activities
- Cookies and Similar Technologies
- Data Processors, Recipients and External Service Providers
- Transfers of Personal Data to Third Countries
- Data Security and Personal Data Breaches
- Automated Decision-Making and Profiling
- Special Categories of Personal Data and Children’s Data
- Rights of Data Subjects
- Legal Remedies
- Amendments to this Privacy Policy
1. Details of the Data Controller
|
Full company name |
REVERTO-GLOBAL Kereskedelmi és Szolgáltató Korlátolt Felelősségű Társaság |
|
Short company name |
REVERTO-GLOBAL Kft. |
|
Registered office |
9090 Pannonhalma, Imre herceg útja 2., Hungary |
|
Company registration number |
08-09-021846 |
|
Tax number |
23354393-2-08 |
|
|
info@reverto-global.hu |
|
Telephone |
+36 20 331 0099 |
|
Websites |
https://www.reverto-global.hu; https://reveto-global-kft.odoo.com |
|
Data protection contact |
Requests from data subjects and enquiries relating to data protection may be submitted using the email address above or by post. |
Hereinafter, REVERTO-GLOBAL Kft. is referred to as the “Data Controller”.
2. Purpose and Scope of this Privacy Policy
The purpose of this Privacy Policy is to explain in a clear and transparent manner how the Data Controller processes the personal data of natural persons when a data subject:
- visits the Data Controller’s websites;
- contacts the Data Controller, requests a quotation, sends an email or makes a telephone enquiry;
- acts as a customer, prospective customer, supplier, subcontractor or business partner;
- participates in the Data Controller’s 3D surveying, virtual tour, Matterport, Google Street View, drone surveying, point cloud, BIM, digital twin or related projects;
- subscribes to a newsletter or requests marketing communications;
- submits a job application or professional introduction;
- interacts with the Data Controller through its social media channels;
- submits a data subject request, complaint or other legal enquiry.
This Privacy Policy applies to the websites www.reverto-global.hu and reverto-global-kft.odoo.com, the forms available on those websites and the Data Controller’s related business processes. Where a third-party website or service processes personal data independently, the privacy policy of the relevant third-party service provider shall apply.
The Data Controller may also act as a Data Processor where, on the instructions of a customer, it creates or processes 3D models, virtual tours, images or other project materials. In such cases, the customer determines the purposes and essential means of the processing, while the Data Controller acts in accordance with its agreement with the customer and the applicable data processing terms.
3. Applicable Legislation and Data Protection Principles
The Data Controller’s processing of personal data is governed in particular by the following legislation:
- Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation – GDPR);
- Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Hungary);
- Act V of 2013 on the Civil Code of Hungary;
- Act C of 2000 on Accounting;
- Act CXXVII of 2007 on Value Added Tax;
- Act CVIII of 2001 on Electronic Commerce and Information Society Services;
- Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities;
- Act C of 2003 on Electronic Communications.
The Data Controller processes personal data lawfully, fairly and transparently, for specified purposes, limited to what is necessary, accurately, for no longer than required, and subject to appropriate technical and organisational security measures.
In accordance with the principle of accountability, the Data Controller documents the legal basis and purpose of the processing, the applicable retention periods and the necessary security measures.
4. Individual Data Processing Activities
The following sections describe the Data Controller’s principal processing activities. In a specific matter, more than one processing purpose and legal basis may apply at the same time.
4.1. Website Operation, Technical Logging and IT Security
|
Data Subjects |
Visitors to the websites and users of the online services. |
|
Data Processed |
IP address, date and time of visit, page or URL viewed, referring page, browser and operating system type, device characteristics, session identifier, language setting, error codes, security data and server log data. |
|
Purpose of Processing |
Operating the website, displaying content, maintaining sessions, troubleshooting, preventing abuse, ensuring network and IT security, and maintaining service performance. |
|
Legal Basis |
Article 6(1)(f) GDPR: the Data Controller’s legitimate interest in operating a secure, stable website protected against abuse. |
|
Retention Period |
Technical and security logs are generally retained for no longer than 12 months, unless a specific security incident, legal claim or legal requirement justifies a longer period. Inactive session data may be deleted sooner. |
|
Source of Data |
The Data Subject’s browser and device, and the Odoo web infrastructure. |
|
Recipients |
Odoo S.A.; and, where necessary, the Data Controller’s IT service providers and authorised employees. |
|
Consequences of Providing or Not Providing Data |
Without processing the necessary technical data, certain website functions would not operate, or would not operate securely. |
4.2. Contact and Requests for Quotations
|
Data Subjects |
Persons who make enquiries or request quotations via the website, email, telephone, social media or other channels. |
|
Data Processed |
Name, company name, job title, email address, telephone number, subject, message, content of the enquiry, details of the requested service, attachments, time of contact and technical data. |
|
Purpose of Processing |
Responding to the enquiry, assessing requirements, technical or commercial consultation, preparing a quotation, preparing an on-site survey and taking steps prior to entering into a contract. |
|
Legal Basis |
For an individual making an enquiry, Article 6(1)(b) GDPR. For a representative or contact person of a legal entity, Article 6(1)(f) GDPR: the legitimate interests of the Data Controller and the Data Subject’s employer in conducting business communications and handling requests for quotations. |
|
Retention Period |
If no contract is concluded, 1 year after the matter is closed. If a contract is concluded, the data may be processed as part of the contractual documentation in accordance with Section 4.4. In the event of a legal claim, until the end of the limitation period or the final conclusion of the proceedings. |
|
Source of Data |
The Data Subject, the organisation represented by them, or publicly available business contact details provided in the enquiry. |
|
Recipients |
Employees involved in handling the matter; Odoo S.A.; the email service provider; and, where necessary, subcontractors involved in preparing the quotation. |
|
Mandatory Data |
Without the data marked as mandatory on the form, the Data Controller may be unable to respond or prepare a quotation. Data Subjects should not provide unnecessary special-category data or sensitive information relating to third parties. |
4.3. Email, Telephone and Other Business Communications
|
Data Subjects |
Customers, prospective customers, business partners, suppliers, authorities and other contact persons. |
|
Data Processed |
Name, contact details, organisation, job title, content and time of communications, attachments and basic call-related data. As a general rule, the Data Controller does not record the audio of telephone calls. |
|
Purpose of Processing |
Contact management, coordination of tasks and orders, customer service, documentation, confirmation of performance and resolution of disputes. |
|
Legal Basis |
Article 6(1)(b) GDPR where the Data Subject is a contracting party; Article 6(1)(f) GDPR where the Data Subject is an organisational contact person; and Article 6(1)(c) GDPR where processing is necessary to comply with a legal obligation. |
|
Retention Period |
Depending on the nature of the matter, 1 year after the matter is closed; for contractual or legally significant communications, 5 years after termination of the contract or performance, or until the end of legal proceedings. |
|
Recipients |
Microsoft 365 or another email and communications service provider; employees handling the matter and, where necessary, contractual contributors. |
4.4. Customer Relations, CRM, Contracting and Contract Performance
|
Data Subjects |
Individual customers; representatives and contact persons of customers, clients and partners; and persons participating in projects. |
|
Data Processed |
Identification and contact data, company role, quotation and contract data, orders, project parameters, site data, tasks, deadlines, performance confirmations, complaints, communications and related documents. |
|
Purpose of Processing |
Customer and project management, conclusion and performance of contracts, provision of services, documenting consultations, quality assurance, handling receivables and legal claims. |
|
Legal Basis |
Article 6(1)(b) GDPR; for organisational contact persons, Article 6(1)(f) GDPR; and, for documentation required by law, Article 6(1)(c) GDPR. |
|
Retention Period |
Until the contract has been performed and thereafter, as a general rule, until the expiry of the general limitation period for civil claims, i.e. 5 years. Where an accounting document is involved, the longer period specified in Section 4.5 applies. |
|
Recipients |
Odoo S.A.; Microsoft; accountant; invoicing service provider; bank; legal representative; and professional subcontractors and technology providers necessary for performance. |
4.5. Invoicing, Accounting and Payments
|
Data Subjects |
Customers, partners, suppliers, sole traders and natural-person contact persons. |
|
Data Processed |
Name or business name, address or registered office, tax number, bank account details, invoicing and payment data, subject, amount and date of performance, and contact details. |
|
Purpose of Processing |
Issuing invoices, complying with accounting and tax obligations, handling payments, debt collection and ensuring auditability. |
|
Legal Basis |
Article 6(1)(c) GDPR: compliance with legal obligations relating to accounting, taxation and retention of records; where necessary, Article 6(1)(b) GDPR. |
|
Retention Period |
Accounting records and the data supporting them must be retained for at least 8 years under the Hungarian Accounting Act. |
|
Recipients |
Accountant, tax adviser, invoicing service provider, Hungarian tax authority (NAV), account-holding financial institution, auditor or other body authorised by law. |
4.6. Supplier and Subcontractor Relationships
|
Data Subjects |
Suppliers, subcontractors, experts and their representatives or contact persons. |
|
Data Processed |
Name, company name, job title, contact details, professional competence, quotation, contract, performance, authorisation and financial data, and project access rights. |
|
Purpose of Processing |
Partner selection, contracting, coordination of performance, access management, settlement, quality control and legal claims. |
|
Legal Basis |
Article 6(1)(b), (c) and (f) GDPR. The legitimate interest is the organisation, documentation and verifiability of the business cooperation. |
|
Retention Period |
For the duration of the cooperation and, as a general rule, for 5 years thereafter; accounting records are retained for at least 8 years. |
|
Recipients |
The customer, project partner, accountant, legal representative, Odoo, Microsoft and other service providers necessary for carrying out the relevant task. |
4.7. 3D Surveying, Virtual Tours, Matterport, Google Street View, Drone, Point Cloud, BIM and Digital Twin Projects
|
Data Subjects |
Owners, users, employees and visitors of the surveyed site, passers-by, vehicle users, persons participating in the project and any natural person who may become identifiable in an image or other project material. |
|
Data Processed |
360-degree images, photographs, video, drone footage, point clouds, spatial models, site and geolocation data, date and time, technical metadata, floor-plan and object data. Images may incidentally contain faces, vehicle registration plates, voices, personal belongings, nameplates, displays or other identifiers. |
|
Purpose of Processing |
On-site data capture, condition documentation, creation of a 3D model or virtual tour, technical analysis, creation of a BIM/digital twin, project monitoring, delivery, archiving and publication in accordance with the customer’s instructions. |
|
Role of the Data Controller |
For its own reference or marketing use, the Data Controller acts as a Data Controller. When processing project materials on a customer’s instructions, it generally acts as a Data Processor and the customer acts as the Data Controller. The specific roles are determined by the contract and the actual decision-making powers. |
|
Legal Basis |
Article 6(1)(b) GDPR where the Data Subject is an individual contracting party. For customer contact persons and persons necessary for project performance, Article 6(1)(f) GDPR. For persons captured accidentally or incidentally, the legitimate interest of the Data Controller or its customer in producing documentation and technical services, subject to an appropriate balancing test and risk mitigation. As a general rule, consent is required for marketing use of an identifiable person who is deliberately featured. |
|
Risk Mitigation Measures |
Advance coordination of the survey date; on-site information; where possible, removal of persons from the capture area; concealment of unnecessary personal belongings and displays; blurring or removal of faces and vehicle registration plates where justified and technically feasible; access-controlled sharing; and public publication only with appropriate authorisation. |
|
Retention Period |
For the duration of the project and thereafter for the period specified in the contract; unless otherwise agreed, for up to 5 years after project closure for quality assurance and legal claims. A publicly published tour or model remains available until instructed otherwise by the customer, until the end of the service period or until the legal basis ceases to apply. Deleted data may remain in service providers’ backups for a limited period. |
|
Recipients |
The customer and persons designated by the customer; Matterport/CoStar Group; Google services where publication to Google Street View or Maps is involved; cloud and hosting providers; professional subcontractors; and an authority or legal representative where required by law or a legal claim. |
|
Information Provided to Data Subjects |
The customer who has authority over the site is responsible for appropriately informing persons present at the location and for ensuring the lawful conditions of the survey. Upon request, the Data Controller may provide a template notice or on-site signage. |
4.8. References, Case Studies and Publication for Marketing Purposes
|
Data Subjects |
Representatives of customers and partners, project participants, persons identifiable in images or videos, and persons providing testimonials. |
|
Data Processed |
Name, job title, organisation, portrait, voice, statement, project photograph, video, virtual tour, logo, project description and result. |
|
Purpose of Processing |
Presentation of the Data Controller’s services, professional references, case studies, website and social media communications. |
|
Legal Basis |
Where an identifiable natural person is deliberately featured, consent under Article 6(1)(a) GDPR, or an appropriately documented contractual or legitimate-interest legal basis, applies. For a legal entity’s name and logo, contractual permission applies. |
|
Retention Period |
Until consent is withdrawn, the reference permission ends, the marketing purpose ceases to exist or a valid objection is made. Withdrawal does not affect the lawfulness of earlier use; it may not always be possible to recall printed materials or campaign materials that have already been finalised. |
|
Recipients |
Website visitors, users of social platforms, Odoo, Meta, LinkedIn, Google, Matterport and marketing or creative service providers. |
4.9. Newsletters and Direct Marketing
|
Data Subjects |
Persons who voluntarily subscribe to the newsletter or other marketing communications. |
|
Data Processed |
Name, email address, company name, interests or subscription preferences, date and evidence of consent, technical data necessary to demonstrate consent, and the fact of unsubscription. |
|
Purpose of Processing |
Sending newsletters, professional content, service information, invitations and marketing offers, and managing subscriptions and unsubscriptions. |
|
Legal Basis |
Voluntary consent under Article 6(1)(a) GDPR and the rules applicable to commercial advertising activities. |
|
Retention Period |
Until consent is withdrawn or the person unsubscribes. After unsubscription, the Data Controller may retain the minimum data necessary to demonstrate the giving and withdrawal of consent and to prevent further unauthorised contact for up to 5 years. |
|
Data Subject Right |
Consent may be withdrawn at any time, without giving reasons and free of charge, using the unsubscribe option in the message or by contacting info@reverto-global.hu. |
|
Consequence |
Subscription is voluntary; failure to subscribe does not prevent the use of any other service. |
4.10. Job Applications and Professional Applications
|
Data Subjects |
Job applicants and persons interested in internship or subcontracting opportunities. |
|
Data Processed |
Name, contact details, CV, cover letter, qualifications, professional experience, portfolio, language skills, salary expectations, interview notes, test work or assessment, and any other data voluntarily provided by the Data Subject. |
|
Purpose of Processing |
Assessing the applicant’s suitability, contacting the applicant, conducting interviews and the recruitment process, making an offer and preparing a contract. |
|
Legal Basis |
Article 6(1)(b) GDPR: steps taken at the Data Subject’s request prior to entering into a contract. For short-term retention after the recruitment process, Article 6(1)(f) GDPR: defence against legal claims. Longer retention for future job opportunities is based exclusively on separate, voluntary consent. |
|
Retention Period |
Until the relevant recruitment process is completed and, as a general rule, for a further 6 months. With separate consent, an application may be retained for up to 1 year for future opportunities. If the applicant is hired, the necessary data are transferred to records relating to the employment relationship. |
|
Special Categories of Personal Data |
The Data Controller does not request data concerning health, political opinions, religious beliefs, trade union membership, sex life or other special categories of personal data. Providing a photograph in a CV is not mandatory. |
|
Recipients |
Managers and employees involved in the selection process; Microsoft 365, Odoo, a job portal or recruitment service provider where used. |
4.11. Social Media and Messaging Platforms
|
Data Subjects |
Followers, visitors, commenters and users who send messages through Facebook, Instagram, LinkedIn or other social media pages. |
|
Data Processed |
The user’s publicly available profile data on the platform, reactions, follows, comments, shares and messages, as well as aggregated statistics provided by the platform. |
|
Purpose of Processing |
Contact management, customer information, professional and marketing communications, responding to enquiries, community management and performance measurement. |
|
Legal Basis |
Article 6(1)(f) GDPR: the Data Controller’s legitimate interest in public business communications and customer relations. Consent is used where required for direct marketing or optional measurement technologies. |
|
Retention Period |
Public posts and comments remain on the platform until removed by the Data Subject or the platform, or until moderation justifies deletion. Private messages are generally retained for 1 year after the matter is closed; where they relate to a contract, the relevant contractual retention period applies. |
|
Joint or Independent Controllership |
Platforms may act as independent data controllers for their own purposes and, for certain statistical services, as joint controllers with the operator of the page. Details are available in the privacy policy of the relevant platform. |
4.12. Data Subject Requests, Complaints and Legal Claims
|
Data Subjects |
Persons submitting requests, complaints, formal notices or legal enquiries, and persons affected by the matter. |
|
Data Processed |
Name, contact details, content of the request, information necessary to identify the Data Subject, related evidence, responses and measures taken. |
|
Purpose of Processing |
Ensuring rights under the GDPR, handling complaints, complying with legal obligations, and establishing, exercising or defending legal claims. |
|
Legal Basis |
Article 6(1)(c) and (f) GDPR. |
|
Retention Period |
As a general rule, 5 years from the final closure of the request, or until the end of the relevant procedure and applicable limitation period. |
|
Identification |
The Data Controller may request additional information only to the extent necessary to reasonably verify the identity and entitlement of the Data Subject for the purpose of handling the request. |
5. Cookies and Similar Technologies
A cookie is a small data file stored in the browser. The website may use cookies necessary for its operation without consent, while optional analytics, marketing, social media and embedded-service technologies may only be activated after the visitor has given prior consent.
5.1. Default Odoo Cookies and Possible Third-Party Cookies
|
Cookie / Identifier |
Service Provider |
Category |
Purpose and Duration |
|
session_id |
Odoo |
Necessary |
Session authentication, security, forms and website functionality. The actual expiry period depends on the Odoo configuration. |
|
frontend_lang |
Odoo |
Necessary / Preference |
Remembering the selected language. The actual expiry period depends on the Odoo configuration. |
|
im_livechat_previous_operator |
Odoo |
Optional |
Remembering the previous live-chat operator and interaction history where live chat is enabled. |
|
utm_campaign, utm_source, utm_medium |
Odoo |
Optional |
Measurement of campaign source and visit attribution. |
|
_ga, _gid, _gat, _gac_* |
|
Optional Analytics |
Measuring website usage and campaign performance, only where consent has been given. |
|
__gads, __gac, _fbp and other marketing identifiers |
Google / Meta |
Optional Marketing |
Advertising and campaign measurement, only where the relevant service is actually active and the visitor has consented. |
The above list is based on the default and typical cookies supported by Odoo. It does not mean that every cookie listed is active during every visit or is currently in use. The actual and up-to-date list is available on the website at /cookie-policy; specific expiry periods should be checked using the browser developer tools and the relevant service provider settings.
5.2. Managing and Withdrawing Consent
- Cookies that are necessary for the basic operation of the website may be used without consent.
- Optional cookies and external tracking services may be activated only after the visitor has made a choice.
- Refusing consent does not prevent the basic use of the website, but certain embedded content or convenience functions may not be available.
- Consent may be withdrawn at any time via the “Cookie Policy” link or by deleting cookies in the browser.
- Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
5.3. Embedded Content
The website may embed Matterport tours, Google Maps or Street View content, YouTube or other videos, social media posts or external forms. Such service providers may receive technical data and online identifiers from the Data Subject’s device. Non-essential embedded content must be blocked until the visitor gives consent, or displayed behind a placeholder that loads the external content only after a separate click.
6. Data Processors, Recipients and External Service Providers
The Data Controller grants access to personal data only to the extent necessary for the relevant purpose. Certain service providers act as Data Processors on the Data Controller’s instructions, while others—particularly social and public platforms—may act as independent Data Controllers for their own purposes.
|
Service Provider / Recipient |
Role and Purpose |
Categories of Personal Data |
|
Odoo S.A. Belgium |
Website, hosting, forms, CRM and related business applications. Odoo processes data stored in the customer database on the Data Controller’s instructions. |
Website visit, contact, CRM and customer data. European region and subprocessors published by Odoo. |
|
Microsoft Ireland Operations Limited |
Email, Microsoft 365, OneDrive, Teams and office collaboration, where these are used by the Data Controller. |
Contact, correspondence, document and meeting data. |
|
Matterport / CoStar Group |
3D virtual tours, digital spatial models, hosting, sharing and embedding. |
Images, spatial models, site data, metadata and personal data that may incidentally appear in the captured material. |
|
Google Ireland Limited and affiliated service providers |
Google Analytics, Tag Manager, Maps, Street View, YouTube, reCAPTCHA or other Google services, only where the relevant function is actually used. |
Online identifiers, browser and device data, visit and campaign data, and on-site or published images. |
|
Meta Platforms Ireland Limited |
Facebook and Instagram pages, messages, embeds and possible campaign measurement. |
Public profile data, interactions, messages and optional online identifiers. |
|
LinkedIn Ireland Unlimited Company |
LinkedIn company page, professional communications, messages and possible campaign measurement. |
Profile data, interactions, messages and optional online identifiers. |
|
Accountant, tax adviser, invoicing provider and bank |
Invoicing, accounting, taxation, payments and statutory reporting. |
Invoicing, contractual, payment and contact data. |
|
Professional subcontractors and IT service providers |
Surveying, drone operations, modelling, BIM, software processing, hosting, maintenance or support. |
Only project and contact data necessary for the performance of the specific task, subject to contractual confidentiality and, where appropriate, data processing terms. |
The Data Controller regularly reviews its current service providers. Upon request, it provides information about the recipients actually involved in a particular processing activity. Personal data may be disclosed to an authority, court or other authorised body only on the basis of a legal authorisation or a binding request.
7. Transfers of Personal Data to Third Countries
The Data Controller primarily gives preference to service providers and hosting regions operating within the European Economic Area. However, the operation of certain global service providers—such as Microsoft, Google, Matterport/CoStar or social media platforms—may involve access, support, subprocessors or data storage outside the European Economic Area.
A transfer to a third country may take place only where:
- the European Commission has determined that the country in question ensures an adequate level of protection;
- the provider participates in a valid compliance mechanism, where applicable;
- the protection is ensured by Standard Contractual Clauses adopted by the European Commission together with any necessary supplementary measures;
- or another exceptional transfer condition under the GDPR is met.
At the Data Subject’s request, the Data Controller provides information about the safeguards applicable to a transfer and the availability of a copy of those safeguards, subject to the rights of third parties and the protection of trade secrets.
8. Data Security and Personal Data Breaches
The Data Controller protects personal data by applying technical and organisational measures appropriate to the risks. Such measures may include, in particular:
- role-based access limited to what is necessary;
- strong passwords, multi-factor authentication and regular review of access rights;
- encrypted data transmission, backups and system updates;
- confidentiality and data-processing obligations for contributors;
- data minimisation, access logging and, where necessary, anonymisation or blurring;
- incident response, deletion and recovery procedures.
In the event of a personal data breach, the Data Controller assesses the risk to the rights and freedoms of Data Subjects. Where the conditions of the GDPR are met, the breach is reported to the supervisory authority without undue delay and, where feasible, within 72 hours; where the breach is likely to result in a high risk, the affected Data Subjects are also informed.
9. Automated Decision-Making and Profiling
The Data Controller does not use solely automated decision-making that produces legal effects concerning a Data Subject or similarly significantly affects them. Web analytics, campaign attribution or technical security scoring does not in itself result in such a decision. If such processing is introduced in the future, the Data Controller will update this Privacy Policy in advance and provide the required safeguards.
10. Special Categories of Personal Data and Children’s Data
The Data Controller’s services are not directed at children and the website does not request special categories of personal data. Data Subjects should not provide health, biometric, political, religious, trade union, sex-life or other special-category data unless a separate, lawfully justified process and appropriate information are in place.
If a 3D survey or project material incidentally captures such data—for example on a screen, document or in the on-site environment—the Data Controller and the customer must consider removal, blurring, access restriction or other risk-mitigation measures. Once aware of unnecessary processing, the Data Controller deletes or restricts the data unless retention is justified by a legal obligation or legal claim.
11. Rights of Data Subjects
The Data Subject may exercise their rights by emailing info@reverto-global.hu or by sending a letter to the Data Controller’s registered office. The Data Controller responds without undue delay and, in any event, within one month. Taking into account the complexity and number of requests, this period may be extended by a further two months; the Data Controller informs the Data Subject of any extension within the first month.
Right to Information and Access
The Data Subject may request confirmation as to whether their personal data are being processed and may access the essential information concerning the processing and obtain a copy of their personal data.
Right to Rectification
The Data Subject may request the correction of inaccurate data and the completion of incomplete data.
Right to Erasure
The Data Subject may request erasure where the purpose of processing has ceased, consent has been withdrawn and there is no other legal basis, a valid objection has been made, the processing is unlawful, or erasure is required by law. Erasure does not apply, among other cases, where retention is necessary to comply with a legal obligation or for legal claims.
Right to Restriction of Processing
The Data Subject may request restriction of processing, for example where the accuracy of the data is contested, the processing is unlawful, the data are required for a legal claim, or an objection is being assessed.
Right to Data Portability
Where automated processing is based on consent or a contract, the Data Subject may request that data provided by them be supplied in a structured, commonly used and machine-readable format and, where technically feasible, transmitted to another Data Controller.
Right to Object
The Data Subject may object, on grounds relating to their particular situation, to processing based on legitimate interests. In that case, the Data Controller will no longer process the personal data unless it demonstrates compelling legitimate grounds, or the data are required for the establishment, exercise or defence of legal claims. The Data Subject may object to direct marketing at any time and without giving reasons.
Withdrawal of Consent
Consent may be withdrawn at any time as easily as it was given. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Complaint and Judicial Remedy
The Data Subject may lodge a complaint with the supervisory authority and bring court proceedings if they consider that the processing of their personal data infringes applicable law.
As a general rule, the Data Controller handles requests free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, the Data Controller may charge a reasonable fee or refuse to act. If the Data Controller does not take action, it informs the Data Subject within one month of the reasons and of the available remedies.
12. Legal Remedies
The Data Subject may first contact the Data Controller directly at info@reverto-global.hu. In addition, a complaint may be lodged with the supervisory authority:
|
Authority |
Hungarian National Authority for Data Protection and Freedom of Information (NAIH) |
|
Registered Office |
1055 Budapest, Falk Miksa utca 9-11. |
|
Postal Address |
1363 Budapest, Pf. 9. |
|
Telephone |
+36 1 391 1400 |
|
|
ugyfelszolgalat@naih.hu |
|
Website |
https://www.naih.hu |
The Data Subject may also bring proceedings before a court. At their choice, proceedings may be initiated before the competent regional court according to the Data Controller’s registered office or the Data Subject’s own place of residence or habitual residence, in accordance with the procedural rules in force at the time.
13. Amendments to this Privacy Policy
The Data Controller may amend this Privacy Policy, in particular where legislation, regulatory practice, the website, technologies used, service providers or business processes change. The version currently in force is available on the website. In the event of a material change, the Data Controller may also provide a separate notice in a manner appropriate to the circumstances.
Effective from: 22 July 2026
Version: 2.0 2.0