Privacy Policy

BEST BOND Limited Liability Company

This Privacy Policy was adopted and put into effect by Best Bond Kft. hereinafter referred to as the “Controller”, effective from 20 May 2026, in order to comply with Regulation (EU) 2016/679 of the European Parliament and of the Council hereinafter referred to as the “Regulation”, and in particular with the provisions of Article 12 thereof, which require the implementation of measures relating to transparent information.

The purpose of this Policy is to ensure that the Controller provides data subjects with all information required from controllers under the Regulation concerning the processing of personal data in a concise, transparent, intelligible and easily accessible form, using clear and plain language, and to provide comprehensive information on the Controller’s activities related to the processing of personal data.

I. General Information

I.1. The Controller

Best Bond Kft.

Registered office: 1173 Budapest, Pesti út 17.

Company registration number: 01 09 291924

Tax number: 23080656242

Representative: Kiss Gergő, Managing Director

Phone number: +36 30 201 0011

Email address: kiss.gergo@bestbond.hu

I.2. Data Protection Officer

The Controller does not employ or appoint a Data Protection Officer.

II. Data Processing Activities Carried Out by the Controller

II.1. Intended purposes of personal data processing, types of different processing activities and legal bases

Personal data included in contracts concluded by the Controller

Type of data processing:
Personal data included in contracts concluded by the Controller.

Categories of data processed:
Personal data of the parties contracting with the Controller, and of persons identified by name in the contract, in particular: name, birth name, place of birth, date of birth, mother’s name and residential address.

Purpose of data processing:
Performance of contracts concluded by the Controller with its partners, identification of the contracting parties, ensuring payment of the remuneration due to the Controller, proving the conclusion and validity of the contract, and fulfilling reporting obligations imposed on the Controller.

Legal basis for data processing:
Article 6(1)(b) of the Regulation: processing is necessary for the performance of a contract.
Article 6(1)(f) of the Regulation: processing is necessary for the enforcement of the Controller’s legitimate interests.
Article 6(1)(a) of the Regulation: the data subject has given consent to the processing.

Duration of data storage:
For the duration of the validity and effect of the contract, and until the expiry of the limitation period for enforcing rights and claims arising from the contract.

Persons or organisational units entitled to access the data:
The current Managing Director of the Controller.

Person entitled to dispose of the processed data and responsible for their processing:
The current Managing Director of the Controller.

Sending newsletters electronically

Type of data processing:
Sending newsletters electronically.

Categories of data processed:
Email addresses of newsletter recipients.

Purpose of data processing:
Continuous information of persons interested in the newsletter about news, promotions and developments related to the Controller’s activities.

Legal basis for data processing:
Article 6(1)(a) of the Regulation: the data subject has given consent to the processing.

Duration of data storage:
Until the data subject withdraws their declaration of consent.

Persons or organisational units entitled to access the data:
The current Managing Director of the Controller.

Person entitled to dispose of the processed data and responsible for their processing:
The Managing Directors of the Controller.

II.2. Further information pursuant to Article 13(1) of the Regulation

The Controller does not intend to transfer the personal data processed by it to a third country or to an international organisation.

The Controller does not use automated decision-making or profiling.

II.3. Processors in a contractual relationship with the Controller

The following agents of the Controller may access personal data to the extent strictly necessary for the performance of their duties:

  • legal representative;
  • auditor, financial consultant;
  • IT service provider.

The Controller has concluded data processing agreements with the above-mentioned processors in order to ensure the lawfulness of its data processing and data protection activities.

In order to fulfil its contractual and statutory obligations, the Controller also provides data to its account-holding financial institution and to other authorities.

III. Information on the Rights of Data Subjects in Relation to Data Processing

III.1. Consent of data subjects to data processing and withdrawal of consent

Where processing is based on consent, the Controller must be able to demonstrate that the data subject has consented to the processing of their personal data.

If the data subject gives consent in the context of a written declaration that also concerns other matters, the request for consent must be presented in a manner clearly distinguishable from those other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such a declaration containing the data subject’s consent that infringes the Regulation shall not be binding.

In connection with entering into a contract with the Controller, the Controller may make the conclusion of the contract subject to the data subject providing the scope and extent of data requested by the Controller, that is, the provision of the personal data specified by the Controller. If this is not provided, the Controller is entitled to refuse to conclude the contract.

Where the processing of personal data is based on the data subject’s consent, the data subject may refuse to provide the data. In such a case, however, the Controller is entitled to refuse to conclude the contract.

The exercise of the data subject’s right to withdraw consent shall not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

III.2. Right of access of data subjects

Data subjects may request information on what data the Controller processes, for what purpose, for how long, to whom the data are transferred, and from where the data processed by the Controller originate.

The data subject has the right to obtain confirmation from the Controller as to whether personal data concerning them are being processed, and where such processing is taking place, the right to access the personal data and the following information:

a) the purposes of the processing;

b) the categories of personal data concerned;

c) the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations;

d) where possible, the intended period for which the personal data will be stored, or, if this is not possible, the criteria used to determine that period;

e) the data subject’s right to request from the Controller rectification or erasure of personal data concerning them, or restriction of processing, and to object to the processing of such personal data;

f) the right to lodge a complaint with a supervisory authority;

g) where the data were not collected from the data subject, any available information as to their source.

The Controller shall provide the data subject with a copy of the personal data undergoing processing.

The Controller shall not request any fee or reimbursement of costs in connection with fulfilling the first request for copies submitted by the data subject. However, if the data subject requests the release of data that the Controller has already provided to them, the Controller may make the fulfilment of the request subject to the payment of a cost reimbursement of HUF 5,000 + VAT, regardless of the extent of the documentation.

Where the data subject submits the request electronically, the information shall be provided in a commonly used electronic format, unless the data subject requests otherwise.

III.3. Right to rectification and restriction of processing

Data subjects may request the rectification of their personal data or the restriction of their processing.

The data subject has the right to obtain from the Controller, without undue delay, the rectification of inaccurate personal data concerning them.

Taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.

The data subject has the right to obtain from the Controller restriction of processing where one of the following applies:

a) the data subject contests the accuracy of the personal data, in which case the restriction applies for a period enabling the Controller to verify the accuracy of the personal data;

b) the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead;

c) the Controller no longer needs the personal data for the purposes of processing, but the data subject requires them for the establishment, exercise or defence of legal claims; or

d) the data subject has objected to processing, in which case the restriction applies for the period until it is determined whether the legitimate grounds of the Controller override those of the data subject.

Where processing has been restricted on the above grounds, such personal data shall, with the exception of storage, only be processed with the data subject’s consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State.

The Controller shall inform the data subject, at whose request processing has been restricted on the above grounds, before the restriction of processing is lifted.

III.4. Right to data portability

The data subject has the right to receive the personal data concerning them, which they have provided to the Controller, in a structured, commonly used and machine-readable format.

The data subject also has the right to transmit those data to another controller without hindrance from the Controller, provided that the processing is based on the data subject’s consent or is necessary for the performance of a contract.

III.5. Right to erasure, also known as the right to be forgotten

The data subject has the right to obtain from the Controller the erasure of personal data concerning them without undue delay, and the Controller is obliged to erase personal data concerning the data subject without undue delay where one of the following grounds applies:

a) the personal data are no longer necessary for the purpose for which they were collected or otherwise processed;

b) the data subject withdraws the consent on which the processing is based, and there is no other legal basis for the processing;

c) the data subject objects to the processing and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing;

d) the personal data have been unlawfully processed;

e) the personal data must be erased in order to comply with a legal obligation under Union or Member State law applicable to the Controller.

III.6. Right to object

The data subject has the right to object, on grounds relating to their particular situation, at any time to the processing of their personal data, where such processing is necessary for the enforcement of the Controller’s legitimate interests or for the performance of a task carried out in the exercise of official authority, including profiling based on those provisions.

In such a case, the Controller may no longer process the personal data unless the Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or which are related to the establishment, exercise or defence of legal claims.

III.7. Exercising the rights of data subjects, complaints and legal remedies

Requests by the data subject in connection with exercising their rights of access, as well as requests concerning the release, modification or erasure of their data, may be submitted by postal letter addressed to the Managing Directors of the Controller at the registered office of the Controller.

On the basis of such a request, the Managing Directors of the Controller, or an employee authorised by them, shall inform the data subject within one month of receipt of the request about the measures taken by the Controller on the basis of the request.

If the data subject suffers a violation of rights in connection with the Controller’s data processing, they have the right to lodge a complaint with the competent supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)

Registered office: 1055 Budapest, Falk Miksa utca 9-11.

Website: www.naih.hu

Email: ugyfelszolgalat@naih.hu

Phone number: 1/391-1440

The data subject may also enforce their rights before the courts in civil proceedings under the Hungarian Information Act and the Civil Code, Act V of 2013.

IV. Measures Taken by the Controller in the Field of Data Protection and Data Security

IV.1. General information on data security

The Controller ensures the security of the data and takes the technical measures necessary to ensure that the data collected, stored and processed are protected. The Controller also makes every effort to prevent the destruction, unauthorised use and unauthorised alteration of such data.

The Controller also undertakes to call upon every person to whom the data may be transmitted or transferred to fulfil their obligations in this regard.

IV.2. Data security in the IT infrastructure

The Controller takes the following specific measures to ensure data security at the level of the IT infrastructure:

The Controller stores the personal data available to it on servers operated by specialist IT companies, including Rackhost Zrt. registered office: 6722 Szeged, Tisza Lajos körút 41., company registration number: 06-10-000489.

Access to these servers is granted exclusively to the Controller’s Managing Director and to the IT specialists of the referenced specialist companies with the appropriate level of authorisation, subject to strict confidentiality obligations.

Access to data stored in the document management system is only possible with a password and appropriate authorisation. Connection to the Controller’s database is only possible with appropriate authorisation and licences.

The Controller uses real-time protection against malicious software across all of its systems, including individual subsystems.

IV.3. Data security in communication

Data are transmitted in encrypted form between the Controller’s IT networks and central firewalls.

The Controller ensures protection against unauthorised external intrusion through the hardware solution of its perimeter device.

The network protocols used by the Controller guarantee the integrity of the data and secure communication.

IV.4. Physical data security

The security of the personal data processed by the Controller is ensured by the above-mentioned specialist IT companies, which, on the basis of their contracts concluded with the Controller, are obliged to guarantee the physical and software security of personal data.

IV.5. Data security at the organisational level

The Controller makes this Policy available on its website and informs the parties contracting with it of its content before establishing a legal relationship with the Controller and during the conclusion of the contract.

The parties contracting with the Controller acknowledge that they have become familiar with this Policy during the contracting process, meaning that the Controller documents the presentation of the Policy.

V. Handling Personal Data Breaches

A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data transmitted, stored or otherwise processed.

The Controller shall notify the competent supervisory authority of a personal data breach without undue delay and, where possible, no later than 72 hours after becoming aware of the breach, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.

Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Controller shall inform the data subject of the personal data breach without undue delay.

The notification shall describe, in clear and plain language, the nature of the personal data breach and shall include at least the name and contact details of the contact person providing further information on the matter, the likely consequences of the personal data breach, and the measures taken or planned by the Controller to remedy the breach.

Effective from: 20 May 2026

Best Bond Kft.

Kiss Gergő

Managing Director