Cookies and Privacy
PRIVACY NOTICE
www.supremex.hu website
Supremex Kft. (hereinafter: Data Controller) hereby provides this notice to inform its clients about the data processing activities related to the www.supremex.hu website, in accordance with the applicable legislation — with particular regard to Regulation (EU) 2016/679 (the General Data Protection Regulation, hereinafter: Regulation) — and its own data protection policies.
The Data Controller is committed to protecting your personal data and acknowledges that it must be handled responsibly. The following is a summary of how the Data Controller collects, uses and protects your personal data, and what rights you have in this regard.
This notice contains information solely in relation to the specific data processing activities described herein and does not cover all activities of the Data Controller. For further information, please contact the Data Controller.
Contents
1. The Data Controller
Name of Data Controller: Supremex Korlátolt Felelősségű Társaság
Registered office: 2096 Üröm, Kormorán utca 15., Hungary
Mailing address: 1139 Budapest, Kartács utca 27., 3rd floor. Apt. 14, Hungary
E-mail address: info@supremex.hu
Phone number: +36 30 563 4803
No Data Protection Officer has been designated at the Data Controller.
2. Overview of Data Processing Activities
2.1 Information Requests, Contact and Quotation Requests
Data subjects may request information or quotations from the Data Controller regarding its services.
Categories of personal data
|
Name, contact details (phone number, e-mail address) of the data subject |
Purpose of processing
|
Maintaining contact with prospective clients, responding to enquiries, providing quotations |
Legal basis
|
Article 6(1)(a) of the Regulation – consent of the data subject. The data subject acknowledges that the personal data provided during contact with the Data Controller will be processed for the purpose of providing a response, and the data subject consents to such processing. Following the completion of communication, the Data Controller deletes the data after 6 months (disposal period). |
Recipients
|
Employees of the Data Controller in the performance of their duties. Where contact is made online, the Data Controller engages an IT service provider as data processor. |
Retention period
|
Until withdrawal of consent, or up to 6 months from the completion of the communication (disposal period), whichever occurs first — unless a claim can be lawfully asserted in connection with the ad hoc contact, in which case the data may be retained for up to 5 years for the purpose of demonstrating such claim. |
2.2 Processing of Partner Contact Data
In the course of its relationship with contractual partners and clients, the Data Controller processes contact and representative data of the partners. Given the nature of the data, processing of personal data (e.g. name, e-mail address, phone number) may be necessary.
Categories of personal data
|
Name and contact details (phone number, e-mail address) of the contact person or representative |
Purpose of processing
|
Ensuring effective cooperation with contractual partners and clients |
Legal basis
|
Article 6(1)(f) of the Regulation – the legitimate interest of the Data Controller in ensuring the continuity and uninterrupted nature of its business relationships |
Recipients
|
Employees of the Data Controller in the performance of their duties. |
Retention period
|
Until the end of the contractual relationship, or in the case of ongoing cooperation, until 30 June of the calendar year following the termination of the cooperation (document destruction date). |
2.3 Event-Related Data Processing
Categories of personal data
|
Applicant's name, position, stamp number, registration number, company name, contact details (e-mail, phone, address), place of work, professional qualifications, scientific publications, and where applicable, dietary preferences (food allergies). |
Purpose of processing
|
Evaluation of applications for participation in professional events; provision of support (registration, accommodation, catering); confirmation of participation; and regulatory reporting. |
Legal basis
|
GDPR Art. 6(1)(b): Performance of contract (an agreement is concluded between the Data Controller and the Applicant upon submission and acceptance of the application). GDPR Art. 9(2)(a): Explicit consent for the processing of health data (dietary requirements). GDPR Art. 6(1)(c): Legal obligation (Accounting Act and pharmaceutical regulatory reporting). |
Recipients
|
Employees of the Data Controller in the performance of their duties. Where contact is made online, the Data Controller engages an IT service provider as data processor.
|
Retention period
|
In the event of a rejected application: up to 1 year following the evaluation decision. In the event of a successful application: up to 8 years following payment/grant (due to the retention obligation for accounting documents). |
3. Transfer of Data to Third Parties
The operation of certain of our services and functions requires us to share information with other users or at your request. In addition, we may share your data with trusted external service providers for purposes of certain technical data analysis, processing and/or storage services, as well as newsletter management. These providers are carefully selected and must comply with strict data protection and security standards.
Personal data will under no circumstances be transferred to third parties without your explicit consent, except where required by law, during regulatory proceedings, or where subcontractors (e.g. accounting, courier or postal service providers) are engaged to fulfil our contractual obligations. In such cases, subcontractors undertake a contractual obligation to use your data solely for the purpose of fulfilling the contract. Subcontractors are not authorised to retain such data or to transfer it to third parties for any purpose.
Data processors within the EU
TBL Support Services Informatikai, Szolgáltató és Kereskedelmi Kft. (registered office: 1196 Budapest, Batthyány utca 57.; Company registration number: 01-09-321156; Tax number: 26269416-2-43) – contracted data processor providing IT services
Data processors outside the EU
Personal data are transferred to third countries only where appropriate safeguards are in place. Our third-country data processor partners are authorised to receive personal data from the European Union on the basis of the EU–U.S. Data Privacy Framework (DPF) adopted by the European Commission — an adequacy decision pursuant to Article 45 of the Regulation.
All of our third-country data processor partners comply with the requirements set out in the EU–U.S. Data Privacy Framework (DPF) concluded between the United States and the European Union, and between the United States and Switzerland, regarding the processing, use and retention of personal data.
- Google – EU–U.S. Data Privacy Framework (DPF)
- Facebook – EU–U.S. Data Privacy Framework (DPF)
4. Data Security Measures
We use IT tools selected by the Data Controller and the Data Processors for the processing, handling and protection of data. These systems ensure that only persons with appropriate authorisation can access the data, and that only such persons may record, read, transmit, modify or delete the data. The technologies employed guarantee the integrity and security of the data throughout the data processing process.
5. Your Rights
Your rights are determined by the Regulation, the most important of which are:
You may request from the Data Controller access to your personal data, rectification, erasure or restriction of processing, object to the processing of such personal data, and you have the right to data portability.
With regard to data processed on the basis of consent, you may withdraw your consent at any time, without providing reasons; however, this does not affect the lawfulness of processing carried out prior to the withdrawal of consent.
You may exercise your rights by contacting the Data Controller at the contact details set out above. Upon submission of a request, the Data Controller will respond in writing without undue delay and at the latest within one month. For further information, please contact the Data Controller at the contact details provided.
In the event of an alleged infringement of your rights, you may lodge a complaint with the National Authority for Data Protection and Freedom of Information (address: 1055 Budapest, Falk Miksa utca 9–11., Hungary; +36-1-391-1400; ugyfelszolgalat@naih.hu) or may bring a court action. Court proceedings fall within the jurisdiction of the Regional Court (törvényszék). The proceedings may also — at the choice of the data subject — be brought before the Regional Court of the data subject's place of residence (a list of Regional Courts and their contact details is available at:
http://birosag.hu/torvenyszekek
For any further information, please contact the Data Controller at the contact details set out above.
Budapest, 1 September 2026
Categories of personal data
Purpose of processing
Legal basis
Retention period
Legal basis