PRIVACY AND DATA PROCESSING POLICY
WSH Ltd pays particular attention to the protection of personal data while pursuing its business activities, and therefore, in accordance with the applicable legislation, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation – GDPR – hereinafter: Regulation), it states and publishes in this policy the main rules it applies to the processing and protection of personal data, the rights of data subjects and means of enforcement of such rights available to data subjects, as well as related practical information.
First of all, we would like to provide you with a summary of the most important information concerning data processing:
The name of the data controller:
WSH Számítástechnikai, Oktató és Szolgáltató Limited Liability Company (WSH Ltd)
The data controller's contact details are as follows:
Address: 1117 Budapest, Budafoki út 97.;
Summary of the most important data processing activities:
Scope of personal data processed
Purpose of the data processing
Legal basis for the data processing
Duration of the data processing
Recipients to whom the data is disclosed
Use of website cookies
Ensuring the proper functioning of the website, traffic analysis
Legitimate interest of WSH Ltd with regard to marketing activities
Until deletion by the user, or for a maximum of 7 days
Google Ireland Limited
Information provided by the applicant in their CV
Contacting the applicant, making a decision on the establishment of an employment relationship
Until the decision on employment is communicated
No transmission of data
Company contact details (e.g. name, telephone number, e-mail address, fax number, postal address)
Maintenance of contact between WSH Ltd and the partner to ensure business continuity
Legitimate interest of WSH Ltd and the partner represented by the contact person
For as long as the contact is maintained or, in the case of data included in a contract, at the latest until the end of the mandatory retention period of the accounting document
The accounting documents are forwarded by us to the accounting service provider
Data provided by the participant in the adult education contract, data generated during the training, educational identifier
Conducting of the training
Fulfilment of the legal obligation provided for in Sections 16 and 21 of Act LXXVII of 2013, or in the case of the educational identifier, legitimate interest (Government decree, 11/2020., Article 25/A)
The last day of the 8th year from the date of conclusion of the adult education contract or from the date on which it was established
Data Reporting System of Adult Training; Educational Authority (educational identifier); instructor; body authorised to monitor adult education activities in the case of individual assessment
Please note that WSH Ltd does not act as a data controller but as a data processor of the examination centres when conducting the vendor examinations. Therefore, please contact the examination centres for information on data processing related to the examinations
If we process your data with your consent, you may withdraw your consent at any time, however, this does not affect the lawfulness of the previously performed data processing. If the data processing is necessary for the performance of a contract or is based on a legal obligation, the provision of the data is not compulsory, but in this case you will not be able to use the requested service.
In the case of processing based on legitimate interest, you have the right to object to the data processing at any time.
WSH Ltd does not currently utilise automated decision-making (or profiling).
Our Company may typically process personal data on the following legal bases: (1) the Data Subject's consent – Article 6, Section (1), Clause (a) of GDPR; (2) performance of a contract concluded with the Data Subject – Article 6, Section (1), Clause (b) of GDPR; (3) compliance with a legal obligation – Article 6, Section (1), Clause (c) of GDPR; and (4) enforcement of the legitimate interest of our Company as Data Controller or of a third party – under Article 6, Section (1), Clause (f) of GDPR
Rights of the Data Subject:
You have the right of access to your personal data processed by us, the right to request its rectification or erasure, the right to object to the data processing, the right to data portability in certain cases, the right to request the restriction of processing (pending a decision on the fate of the data) as well as the right to lodge a complaint with the competent authority (Hungarian National Authority for Data Protection and Freedom of Information – (address: 1055 Budapest, Falk Miksa u. 9-11., telephone number: +36-1-391-1400, e-mail: email@example.com, website: www.naih.hu). We will provide a response to your requests and enquiries in relation to data processing within one month. In the event of an infringement, you may also bring a claim before the competent court (tribunal).
Below is a detailed description of the data protection and data processing rules:
Website cookie management:
Purpose of the data processing: With regard to the cookies utilised by the www.wsh.hu website, the purpose of the data processing is to ensure the proper functioning of the website and to perform anonymous analysis of traffic. Our website does not run any advertisements, as the function and purpose of these cookies is solely to ensure the proper functioning and readability of the website and to provide us with anonymous (non-personally identifiable) statistical information about how users use the website.
Legal basis for the data processing: WSH Ltd's legitimate interest in marketing activities. Cookies are small text files that the website places on your computer or mobile device when you visit the website.
The scope of Personal Data processed: Website cookies record your browser type, your IP address, the website you are visiting, the region where you are located and your language settings, as well as the date and time.
Duration of the data processing: Website cookies are stored on your device for up to 7 days. You have the right to object to the data processing at any time by deleting cookies in your browser settings, by using an incognito mode to continue browsing or by using the full cookie blocking option available at https://tools.google.com/dlpage/gaoptout .
Processing of the data of job applicants:
Purpose of the data processing: If you apply for one of our job advertisements or otherwise voluntarily send us a CV or other document containing Personal Data, the purpose of the data processing is to make a decision on the establishment of a contractual relationship, and with regard to the processing of contact details (e.g. telephone number, e-mail address), to contact you, in order to request further information, arrange an interview or communicate the decision.
Legal basis for the data processing: As long as no contractual relationship is established between you and WSH Ltd, the legal basis for data processing is your consent, which you may withdraw at any time!
The scope of Personal Data processed: We will only process the personal data provided by you (including the e-mail or postal address from which the mail is sent), and we do not check your social media profiles.
Duration of the data processing: AWe will only keep your data until we make a decision on whether to enter into a contractual relationship with you and to inform you of this decision. If an employment relationship is established, you will separately receive the relevant privacy and data processing policy and information sheet.
Data transmission: Your Personal Data provided during the application process will not be forwarded.
Processing of data of company contacts:
Purpose of the data processing: If you are acting as a contact person for one of our current or prospective partners (or on behalf of your own sole proprietorship), the purpose of the data processing is to allow WSH Ltd and its partner to ensure business continuity through your involvement as a contact person.
Legal basis for the data processing: If you are acting as a contact person of one of our partners, the legal basis for the data processing is the legitimate interest of WSH Ltd and your employer/partner represented by you with regard to the ability to contact each other as legal persons through their natural person representatives (contact persons).
The scope of Personal Data processed: We do not process any of your Personal Data other than the contact details you have provided (e.g. name, title, telephone number, fax number, e-mail address, postal address).
Duration of the data processing: We will process the contact details you provide only as long as the contact is to be maintained, unless the data is also recorded in a contract concluded with the partner or in another document subject to retention obligation – in the latter case, we process such data as part of the document until the end of the legally defined mandatory retention period of the document as an accounting document (currently 8 years under Article 169 of Act C of 2000 on Accounting).
Data transmission: If any Personal Data of the contact person is included in an accounting document, such data is forwarded to the accounting service provider processing the documents (Matolcsi és Társa Ltd – 8000 Székesfehérvár, Honvéd u. 3/A. 3. em. 51.) as data processor.
Processing of course participants' data:
Purpose of the data processing: With regard to the personal data of participants of our training and education courses, the purpose of the data processing is the provision of the training.
Legal basis for the data processing: If you participate in a training course organised by WSH Ltd, which falls under the scope of the Adult Education Act, the legal basis for the data processing is the fulfilment of the legal obligation provided for in Articles 16 and 21 of Act LXXVII of 2013, and with regard to the processing of your educational identifier, the legal interest in connection with the observance of the provisions of Government Decree, 11/2020 (II.7.), Article 25/A. You have the right to object at any time to data processing based on legitimate interests.
The scope of Personal Data processed: As a participant in our training course, your data included in your adult learning contract, your educational identifier (which, if you are not aware of it or do not already have one, is obtained by us from the Educational Authority by electronic means, by way of transmitting your natural personal identification data) as well as data generated during the course, including the data of the Certificate prepared in the Data Reporting System of Adult Training.
Duration of the data processing: As a course participant, your personal data will be recorded, kept and processed until the last day of the eighth year from the conclusion of the adult education contract or from the date on which the data is generated, pursuant to Article 16 and Article 21, Section (6) of Act LXXVII of 2013.
Data transmission: We record the data of our training courses and participants, as defined in Article 15 of Act LXXVII of 2013, in the Data Reporting System of Adult Training; if we need to request your educational identifier, we forward your natural personal identification data to the Educational Authority; furthermore, the bodies authorised to monitor adult education activities are entitled to gain knowledge of your personal data during their individual investigations. You have the right to opt-out of the transfer of certain data of yours, for which you will be given the opportunity at the start of the training. If the training is provided with the contribution of a third party instructor, the training documentation will be created with his/her assistance.
Terms used in this Policy shall be understood in accordance with the applicable legislation, in particular the provisions of the Regulation. In particular:
Data Subject: an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Personal Data: any information relating to the Data Subject.
Data processing: any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Data Controller: who determines, alone or jointly with others, the purposes of the processing of Personal Data. For the purposes of this Policy, the Data Controller is WSH Számítástechnikai, Oktató és Szolgáltató Limited Liability Company (headquarters: 1117 Budapest, Budafoki út 97., company registration number: 01-09-461038)
Data Processor: a natural or legal person, public authority, agency or other body that processes Personal Data on behalf of the Data Controller.
Consent of the Data Subject: a freely given, specific, informed and unambiguous indication of the Data Subject's wishes by which the Data Subject, by a statement or by a clear affirmative action, signifies agreement to the processing of Personal Data relating to him or her.
Recipient: a natural or legal person, public authority, agency or other body, to which the Personal Data is disclosed. Public authorities that receive Personal Data in the framework of a particular inquiry, in accordance with legislation, are not regarded as Recipients.
Profiling: Any form of automated processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
General principles of data processing
Our Company processes personal data at all times in compliance with the principles of lawfulness, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality as well as accountability as defined in the Regulation and applies these principles during each step of the processing.
Rights of the Data Subject
- Right of access
You have the right to receive feedback from WSH Ltd on whether your personal data is being processed and, if so, you also have the right to receive the following information defined in legislation, related to your personal data:
- Purpose of the data processing
- the type of personal data we process
- the recipients to whom we have disclosed or will disclose the personal data
- the intended period of storage of the personal data
- your rights of rectification, erasure, restriction, objection, complaint
- if we did not collect the data from you, information about the source of the data.
- Right to rectification
You have the right to have inaccurate personal data about you corrected by our Company at your request (e.g. in the case of a change in the data or clerical error) or to request that incomplete personal data be completed.
- Right to erasure
In the event that
- the personal data is no longer needed for the purposes for which it was collected or processed, or if
- the processing was based solely on your consent and you wish to withdraw your constent, or
- you legitimately object to the data processing; or
- the personal data has been unlawfully processed; or
- the personal data must be erased due to a legal provision; or
- the data was collected for commercial purposes,
then you have the right to request the erasure of personal data relating to you.
Please note that the right of erasure cannot be exercised where data processing is necessary for the exercise of the right to freedom of expression and information, for compliance with a legal obligation, in the public interest relating to public health, in the context of processing for archiving purposes in the public interest, scientific or historical research purposes, statistical purposes or for the enforcement of legal claims. The deletion is not automatic; in the event that you submit a request for deletion, our Company will examine whether the conditions for deletion are met and will inform you accordingly. Please also note that in certain cases you have the right to object to processing instead of the right of erasure (see below: Section 6. Right to object).
- Right to restriction of processing
You have the right to submit a request that our Company is to restrict processing in the following cases:
- for the time period while our Company is verifying the accuracy of the personal data due to your contesting it;
- in the case of unlawful processing, if you request the restriction of use instead of erasure;
- Our Company no longer needs to process the given personal data, but you require the data in order to pursue your legal claims;
- If you have objected to the processing, as the processing will be restricted while our Company investigates the objection.
The restriction is a temporary measure, and while your data is subject to the restriction, we will not carry out any data processing operations on the personal data other than to ensure storage. You will be informed in advance of the lifting of the restriction.
- Right to data portability
If the data processing is based on your consent or it is performed in the context of the fulfilment of a contract and is carried out by automated means, then you have the right to request the personal data in a structured, commonly used, machine-readable format and to have it transmitted to another controller or, where technically feasible, have it transmitted directly by our Company to another controller.
- Right to object
If the processing is carried out for direct marketing purposes, you have the right to object to the processing. In this case, we will no longer process your personal data for this purpose.
If the processing is based on other legitimate interests of WSH Ltd or a third party, you have the right to object to the processing. In this case, we will no longer process the personal data unless we can supply proof that the data processing is justified on legitimate grounds which override your interests or rights or that it is necessary for the enforcement of the legal claims of WSH Ltd.
- Right to lodge a complaint
You may lodge a complaint about the processing of your data by our Company with the Hungarian National Authority for Data Protection and Freedom of Information (address: 1055 Budapest, Falk Miksa u. 9-11., telephone number: +36-1-391-1400, e-mail: firstname.lastname@example.org, weboldal: www.naih.hu). Furthermore, if you deem the processing of your personal data to be unlawful, you have the right to bring a civil action before the competent court.
Enforcement of the Data Subject's rights
You may request information about the processing of your personal data either in writing (e-mail or letter) or orally, or exercise your rights using the above contact details. Proof of identity will only be requested from you in case of doubt.
Information will primarily be provided to you in writing (by e-mail where possible), but at your request, we will also respond orally as soon as possible, but no later than 1 month after the receipt of the request.
Depending on the complexity of the request or the number of requests, this deadline may be extended by up to 2 months, and we will inform you of this fact within 1 month of receipt of the request, indicating the reasons as well.
If no action is taken in response to the request, you will also be informed of this fact as well as the reasons for it, at the latest within 1 month of receipt of the request.
The privacy and data processing policy and the actions taken in response to requests concerning the exercise of the rights listed above, as well as the reply to such requests will be provided free of charge by our Company. However, if the request is clearly unfounded or involves an excessive demand, in particular because of its repetitive nature, we are entitled to charge a reasonable fee or refuse to take action based on the request.
In the event of a personal data breach, if it is likely to result in a high risk to the rights of Data Subjects, we will promptly provide information concerning the incident in person or by means of a public notice.
Security of data processing
Our company is ISO 27001 certified, which refers to an information security standard that WSH Ltd implemented in order to ensure active management of its data security matters in line with international best practices. By implementing the ISO 27001 standard, our Company established an information security management system that is able to ensure the confidentiality, integrity and availability of its information, including the Personal Data it processes, in line with changes in the external and internal environment of the organisation, while guaranteeing that only authorised persons can have access to the data.
Entry into force
This Policy shall enter into force on 1 October 2020.
This Policy may be amended by the Data Controller at any time by its unilateral decision and the change shall become effective upon its publication.