PREAMBLE
NOVU Tervezőiroda Korlátolt Felelősségű Társaság (hereinafter: the “Company”) carries out BIM (Building Information Modelling)-based architectural and general design activities for buildings and structures, and also performs the physical and functional modelling of facilities. Using BIM models, a comprehensive information source is created for facilities, tracking the entire life cycle of the facility from concept through demolition. The BIM model may contain the information of all disciplines that can be shown on conventional engineering plans; however, thanks to the 3D database, model-based material quantities can be determined accurately, and it also assists with coordination of construction work on site. Beyond construction, these models also assist in the operation and maintenance of buildings and in coordinating their demolition.
In the course of the above activities, the Company processes personal data of natural persons. The purpose of this Policy is therefore to declare and demonstrate that the Company’s controller activities comply with the applicable national and European Union legislation.
I. SUBJECT OF THE POLICY
1. The subject of this Policy is the regulation of the Company’s practice as a controller, as defined in Article 4(7) of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation; hereinafter: “GDPR”), in relation to the processing of personal data.
II. SCOPE OF THE POLICY
1. This Policy applies to the Company’s executive officers, members, employees and agents, and to all data recorded by the Company for the purpose of carrying out the Company’s activities.
III. DEFINITIONS
1. With regard to the GDPR, the following definitions apply for the purposes of this Policy:
1.1. Personal data: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, number, location data, online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (GDPR Article 4(1)).
1.2. Processing: any operation or set of operations performed on personal data or on sets of personal data, whether by automated or non-automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction (GDPR Article 4(2)).
1.3. Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law (GDPR Article 4(7)).
1.4. Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller (GDPR Article 4(8)).
1.5. Consent of the data subject: any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which the data subject, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her (GDPR Article 4(11)).
1.6. Personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed (GDPR Article 4(12)).
1.7. Information society service: a service as defined by Section 2(f) of Act CVIII of 2001, provided electronically, at a distance, usually for remuneration, and accessed individually by the recipient of the service.
2. The definitions applicable to the GDPR provisions on the protection of personal data and the free movement of personal data are comprehensively contained in points 1–26 of Article 4 of the GDPR.
IV. CONTROLLER AND CONTACT DETAILS
1. Controller details and contact information:
Name: NOVU Tervezőiroda Korlátolt Felelősségű Társaság
Registered office: 1056 Budapest, Belgrád rakpart 17, 3rd floor, door 5
Company registration number: 01-09-904812
Registration authority: Company Court of the Metropolitan Court of Budapest
Tax number: 14460809-2-41
Telephone: +36 1 617 9636
E-mail: hello@novu.eu
V. PRINCIPLES OF DATA PROCESSING
1. The principles governing the processing of personal data are as follows:
Lawfulness, fairness and transparency: personal data must be processed lawfully and fairly and in a transparent manner in relation to the data subject.
Purpose limitation: personal data must be collected only for specified, explicit and legitimate purposes and must not be processed in a manner incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes is not considered incompatible with the original purposes.
Data minimisation: personal data must be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
Accuracy: personal data must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that inaccurate personal data, having regard to the purposes of processing, are erased or rectified without delay.
Storage limitation: personal data must be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; longer storage is permitted only where the data will be processed for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, subject to appropriate technical and organisational measures required for the protection of the rights and freedoms of data subjects.
Integrity and confidentiality: personal data must be processed in a manner ensuring appropriate security through appropriate technical or organisational measures, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.
Accountability: the Company is responsible for compliance with the above principles and must be able to demonstrate such compliance.
VI. SCOPE, PURPOSE, LEGAL BASIS AND RETENTION PERIOD OF PROCESSED DATA
1. The Company’s processing activities are based on voluntary consent and/or statutory authorisation. In the case of processing based on voluntary consent, data subjects may withdraw their consent at any stage of the processing. In certain cases, laws require the processing, storage or transfer of all or part of the data provided. In such cases, the Company shall act in accordance with the applicable legislation.
A. DATA RELATING TO THE COMPANY’S MEMBERS
1. Under Act V of 2013 on the Civil Code (hereinafter: “Civil Code”), the Company is a legal person established as a business association with registered capital consisting of predetermined capital contributions. The Company processes the data of its members specified in the relevant provisions of the Civil Code and Act V of 2006 on the Publicity of Company Information, Court Company Registration Proceedings and Final Settlement (hereinafter: “Companies Act”).
2. Establishment of membership is voluntary; upon conclusion of the relevant agreement, the legal basis for processing is the data subject’s consent (GDPR Article 6(1)(b)).
3. Following establishment of membership, the legal basis for processing members’ data is Sections 3:5 and 3:197 of the Civil Code and Section 25(1)(k) and Section 27(3) of the Companies Act.
4. Categories of processed data: name; place and date of birth; mother’s birth name; residential address; where the member’s voting rights exceed 50% or the member has a qualified majority influence, the fact thereof; date of commencement and termination of membership; amount of the capital contribution.
5. Deletion: the Company deletes the member’s data five years after termination of membership.
B. DATA RELATING TO THE COMPANY’S EXECUTIVE OFFICERS
1. The Company’s management duties are performed by a managing director as executive officer.
2. The Company processes executive officers’ data under Section 3:22 and Section 3:26(2) of the Civil Code and Section 24(1)(h) of the Companies Act.
3. Categories of processed data: name; place and date of birth; mother’s birth name; residential address; tax identification number; date of commencement and, where necessary, termination of the legal relationship.
4. Deletion: pursuant to Sections 3:24 and 3:86(2) of the Civil Code, the Company deletes the data of a former executive officer five years after termination of the mandate.
C. DATA RELATING TO THE COMPANY’S EMPLOYEES
i. Legal basis and categories of processed data
1. For the purposes of its activities, the Company processes employees’ personal data in the context of employment under Section 10 of Act I of 2012 on the Labour Code (hereinafter: “Labour Code”). Only data may be requested and recorded, and only occupational fitness examinations may be conducted, which are necessary for establishing, maintaining and terminating employment, ensuring healthy working conditions and carrying out related work-organisation tasks, or which are required by rules applicable to the employment relationship.
2. Legal bases: employee consent (GDPR Article 6(1)(a) and (b)); the employer’s legitimate interest (GDPR Article 6(1)(f)); and compliance with a legal obligation to which the employer is subject (GDPR Article 6(1)(c)).
3. Categories of processed data: name; birth name; date of birth; mother’s name; residential address; nationality; tax identification number; social security identification number (TAJ); pensioner registration number (for pensioner employees); telephone number; private e-mail address; identity card number; number of official document certifying residential address; bank account number and name of bank; start and end dates of employment; position; copies of documents certifying education and professional qualifications; photograph; CV; salary and data concerning salary payments and other benefits; debts deductible from salary on the basis of a final decision, legislation or written consent, and the entitlement to such deduction; employee performance evaluation; manner and reasons for termination of employment; summary of occupational fitness examinations; in the case of membership in a private pension fund or voluntary mutual insurance fund, the name and identification number of the fund and the employee’s membership number; for foreign employees, passport number and the name and number of the document certifying the right to work; data recorded in accident reports concerning accidents suffered by employees; data recorded by the camera system used by the Company for property protection; data proving the employee’s involvement with COVID-19 infection and recovery (vaccination certificate, data of the application provided by EESZT or immunity certificate); data proving vaccination against COVID-19 (EESZT application data, vaccination certificate or immunity certificate); planned vaccination date and type of vaccine.
4. Data concerning illness and trade-union membership may be processed by the employer only for the purpose of fulfilling a right or obligation specified in the Labour Code.
5. Purpose: establishment and maintenance of employment, filling a position, including ensuring a healthy working environment, organising participation at foreign trade exhibitions, compliance with work-organisation rules, and termination of employment or enforcement of claims arising from the Labour Code.
6. Recipients: the employer’s manager, person exercising employer’s rights, employees and processors performing labour-related tasks.
7. Only personal data of senior employees may be transferred to the Company’s owners.
ii. Retention period
1. As a general rule, the Company deletes employee data relating to establishment, existence and termination of employment three years after termination of employment (Labour Code Section 286(1)).
2. Documents concerning compensation for damage caused by a criminal offence or payment of compensation for infringement of personality rights are deleted after five years, or, if the limitation period for criminal liability is longer, after expiry of that limitation period (Labour Code Section 286(2)).
3. Data necessary for determining social-security pension entitlements are deleted five years after the employee reaches the applicable retirement age (Act LXXXI of 1997, Sections 43(2) and 99/A(1)).
4. A document containing employee data which does not fall into the above categories and is not data related to the Company’s payer obligations is retained without a time limit as a document of lasting value pursuant to the relevant provisions of Act LXVI of 1995.
iii. Special rules for processing data relating to fitness examinations
1. Only a fitness examination required by employment rules or necessary for exercising a right or fulfilling an obligation specified in such rules may be applied to an employee. Before the examination, the employee must be informed in detail, among other things, of the skill or ability to be assessed and of the instrument and method used. If legislation requires the examination, employees must also be informed of the title and exact provision of the legislation.
2. Processable personal data: the fact of occupational fitness and the conditions necessary for it.
3. Legal basis: the employer’s legitimate interest (GDPR Article 6(1)(f)).
4. Purpose: establishment and maintenance of employment and filling a position.
5. Recipients/categories: the employees examined and the professional conducting the examination may know the result.
6. Deletion: the Company deletes employees’ data three years after termination of employment.
iv. Special rules for processing job applicants’ data
1. Purpose: application, assessment of applications and conclusion of an employment contract with the selected candidate. The data subject must be informed if the Company did not select him or her for the position.
2. Categories: name, date and place of birth, mother’s name, residential address, qualification data, photograph, telephone number, e-mail address and notes made about the applicant, if any.
3. Legal basis: consent of the data subject (GDPR Article 6(1)(a) and (b)).
4. Recipients/categories: the manager authorised to exercise employer’s rights and persons performing labour-related tasks at the Company.
5. Retention: until the application/recruitment process is assessed. Data of unsuccessful applicants must be deleted. Data of a person who withdraws an application must also be deleted.
6. The Company may retain applications only on the basis of the applicant’s express, clear and voluntary consent, provided retention is necessary to achieve a data-processing purpose consistent with the legislation. Such consent must be requested after completion of the recruitment process.
v. Processing related to the Company’s payer obligations
1. On the legal basis of compliance with a legal obligation, the Company processes the personal data required by tax laws of data subjects—employees, their family members, persons employed and other recipients of benefits—with whom it has a payer relationship under Section 7(31) of Act CL of 2017 on the Rules of Taxation (hereinafter: “Taxation Act”), for fulfilling tax and contribution obligations (determination of tax, tax advances and contributions, payroll and social-security administration).
2. Categories: data specified in Section 50 of the Taxation Act, in particular identification data, sex, nationality, tax identification number and social security identification number (TAJ). Where tax legislation attaches legal consequences to such data, the Company may process employees’ health data (Personal Income Tax Act Section 40) and trade-union membership data (Personal Income Tax Act Section 47(2)(b)) for tax and contribution compliance, payroll and social-security administration.
3. Purpose: fulfilment by the Company of tax and contribution payment obligations in respect of employees, persons employed and other benefit recipients.
4. Legal basis: compliance with a statutory obligation (GDPR Article 6(1)(c)).
5. Retention: eight years after termination of the legal relationship constituting the legal basis.
6. Recipients: Company employees and processors performing tax, payroll and social-security/payer functions, and the competent public authorities to which data must be transferred to fulfil statutory obligations.
vi. Special rules concerning employees’ COVID-related data
1. Purpose: ensuring safe working conditions at the workplace, organising home office work and ensuring employer representation at foreign trade exhibitions.
2. Categories: vaccination certificate proving protection against COVID-19, data of the application provided by EESZT, immunity certificate, and the employee’s declaration concerning the planned vaccination date and type of vaccine.
3. Legal basis: compliance with the controller’s statutory obligation (GDPR Article 6(1)(c) and Article 9(2)(b), Labour Code Section 54(4)) and the employer’s legitimate interest (GDPR Article 6(1)(f)).
4. Retention: the Company deletes employees’ data three years after termination of employment.
5. Recipients: the person exercising employer’s rights.
D. PROCESSING OF CONTRACTUAL PARTNERS’ DATA
i. Natural-person contractual partners
1. On the legal basis of performance of a contract, the Company processes data of natural persons contracting with it for conclusion, performance and termination of the contract and provision of contractual discounts.
2. Categories depend on the nature and content of the contract and may include, in particular: name, birth name, date of birth, mother’s name, residential address, tax identification number, identity card number, telephone number, e-mail address, website address, bank account number and customer number.
3. Processing is lawful where it covers data actually necessary for conclusion and performance of the contract. It is also lawful where necessary to take steps at the request of the data subject before entering into a contract.
4. Legal basis: performance of a contract or taking steps at the request of the data subject prior to entering into a contract (GDPR Article 6(1)(b)).
5. Recipients: employees handling contracting tasks and employees/processors performing accounting and tax tasks.
6. Retention: five years after termination of the contract.
7. Before processing begins, the natural-person data subject must be informed that processing is based on conclusion and performance of the contract; this information may also be included in the contract concluded by the parties.
ii. Natural-person contact persons of legal-entity contractual partners
1. On the legal basis of performance of a contract, the Company processes data of legal-entity partners with which it contracts and, in connection with this, data of their natural-person contact persons for conclusion, performance and termination of contracts and provision of contractual discounts.
2. Categories vary according to the nature and content of the contract and include in particular the natural person’s name, address, telephone number and e-mail address.
3. Legal basis: consent of the data subject (GDPR Article 6(1)(a)).
4. Purpose: performance of the contract with the Company’s legal-entity partner and business contact.
5. Recipients/categories: employees, officers and processors performing contracting tasks.
6. Retention: five years after termination of the business relationship or the person’s status as contact person.
E. VISITOR DATA PROCESSING ON THE COMPANY’S WEBSITE
i. Information on the use of cookies
1. The Company operates a website ([www.novu.eu](https://www.novu.eu/)) to present its activities and facilitate contact.
2. For personalised service, the Company places and reads a small data package, a cookie, on the Visitor’s computer or other device. If the browser returns a previously stored cookie, the controller handling the cookie may link the Visitor’s current visit with previous visits; because cookies are domain-bound, this is possible only in relation to its own content.
3. Cookies enable the Website to recognise whether the Visitor has visited it before. Cookies help the Company improve website content by showing which parts are most popular, which pages Visitors enter and how long they stay. By studying this, the Website can be better adapted to Visitors’ needs so that, through improvements based on the information obtained, it operates as closely as possible to Visitors’ expectations.
4. Some cookies used by the Website are strictly necessary for navigation. Others are functional cookies that support personalised operation by remembering previous settings, such as the selected language.
5. The Website uses two types of cookies: session cookies and persistent cookies.
A. Session cookies
1. Session cookies are stored only while browsing the Website in the cookies file; their validity is limited to the relevant session and they are automatically deleted when the browser is closed. These cookies are essential for proper operation of certain Website functions and applications.
2. Purpose: identification of Visitors’ current session, maintaining the current session between page requests and preventing data loss.
3. Legal basis: consent of the data subject (GDPR Article 6(1)(a)), which may be withdrawn at any time. The Visitor can delete cookies from his or her computer or disable cookies in the browser. Cookies can generally be managed under the Privacy settings of the browser’s Tools/Settings menu, under “cookie” or “cookies”.
4. Retention: until the session ends.
B. Persistent cookies
1. Persistent cookies remain on the Visitor’s device after the Visitor leaves the Website. Currently, the Website uses only analytical cookies originating from Google as an external service provider (Google Analytics) for statistical data collection.
2. Purpose: analysis of Visitor habits to improve service quality and web analytics.
3. Categories: geographic location, browser, operating system, language settings, numerical visitor statistics, time spent on the page, new and returning Visitor, subpages visited, age, sex and interests.
4. Legal basis: consent of the data subject (GDPR Article 6(1)(a)), which may be withdrawn at any time. The Visitor can delete cookies or disable them in the browser.
5. Retention:
_ga: 2 years
_gid: 24 hours
_gat: 1 minute
6. Since the Company may store data on, or access data stored on, a Visitor’s electronic communications terminal equipment only after the Visitor has been clearly and fully informed—including of the purpose of processing—and has given consent (Section 155(4) of Act C of 2003), the Company’s website must provide a short summary of cookie use and a link to the full information. This information ensures that, before and during use of the Website’s information-society services, the Visitor can learn which categories of data are processed for which purposes, including data that cannot be directly linked to the Visitor; it also ensures that the Visitor can consent to the use of cookies and change that setting at any time.
ii. Social-media sites
1. The Website contains links to social-media sites (e.g. LinkedIn, Facebook, Instagram). Because external links connect directly to the providers’ servers, those providers communicate directly with the Visitor’s computer or other device and may thereby collect Visitor data.
2. The Company does not process personal data through links to social-media sites.
iii. Messaging system
1. The Website has a messaging system through which Visitors can send a message to the Company without registration. When a message is sent, the sender’s public IP address and timestamp, as well as data provided by the Visitor (name, e-mail address, telephone number and message text), are stored.
2. An IP address is a sequence of numbers that uniquely identifies the Visitor’s computer and may also allow geographic localisation. The IP address and date/time data alone are not sufficient to identify the Visitor, but when combined with other data (e.g. data supplied in a message), they may permit conclusions to be drawn about the Visitor.
3. Purpose: enabling the Visitor to contact the Company without separate registration.
4. Categories: Visitor name, e-mail address, telephone number and message content; date and time of the message; Visitor IP address; operating system and browser used.
5. Recipients/categories: persons commissioned by the Company to handle electronic communications.
6. Legal basis: consent of the data subject (GDPR Article 6(1)(a)).
7. Retention: five years from sending the message or from taking the measures necessary on the basis of the message.
iv. Newsletter processing
1. After subscribing on the Website, the Visitor receives the Company’s Newsletter at the e-mail address provided at specified intervals.
2. Purpose: sending e-mails/newsletters containing commercial advertising, direct business acquisition and marketing communications.
3. Category: e-mail address.
4. Legal basis: consent of the data subject (GDPR Article 6(1)(a)), which may be withdrawn at any time.
5. Retention: until the Visitor unsubscribes from the Newsletter. Unsubscription may be completed at any time by clicking the “Unsubscribe” button at the bottom of the Newsletter.
6. Data transfer: data are not transferred to third parties. Transfer to a third party takes place only if the Controller has previously informed the Visitor clearly and understandably and the Visitor has consented to the transfer with that knowledge.
F. ELECTRONIC SURVEILLANCE SYSTEM OPERATED BY THE COMPANY
1. For property-protection purposes, the Company operates a 24-hour electronic surveillance system at its registered office.
2. Legal basis: GDPR Article 6(1)(f), because the Company has a legitimate interest in protecting assets at its registered office that are of major importance to its economic operations.
3. Categories: images and conduct of the persons concerned.
4. Recordings are stored on servers at the registered office with enhanced data-security measures, ensuring that unauthorised persons cannot view or copy them. The Company records each access to recordings in a separate report, including the name of the person accessing them, the reason and the time of access.
5. A data subject whose rights or legitimate interests are affected by recording may, in writing and by demonstrating the right or legitimate interest, request that the Company not destroy or delete the recording until a court or authority requests it, but for no more than 30 days. Upon a court or authority request, the recording must be sent without delay. If no court or authority request is made within 30 days from the request to refrain from destruction, the Company deletes the recording.
6. Recipients/categories: the Company’s executive officers; in the event of a request from an authority or court, persons designated by the relevant authority or court to receive the data.
7. Retention: 5 days; if used, transfer to the court or authority.
VII. TECHNICAL ASPECTS OF DATA PROCESSING
1. The Company selects and operates IT equipment used for processing personal data so that processed data are accessible to authorised persons, authenticity and authentication are ensured, integrity can be verified, and the data are protected against unauthorised access.
2. The Company protects data through appropriate measures, in particular against unauthorised access, alteration, transfer, disclosure, erasure or destruction, as well as against accidental destruction or damage and loss of accessibility resulting from changes in the technology used.
3. To protect electronically processed datasets in its various registers, the Company uses appropriate technical solutions to ensure that stored data cannot be directly linked and assigned to a data subject, except where permitted by law.
4. Taking into account the state of technology at all times, the Company uses technical, organisational and organisational-security measures providing a level of protection appropriate to the risks associated with processing.
5. The Company performs electronic data processing and record-keeping using computer programs that meet data-security requirements. The program ensures that access to data is provided only for specified purposes, under controlled conditions, and only to persons who need access in order to perform their duties. The Company protects its IT systems with a firewall and antivirus protection.
6. During processing, the Company maintains confidentiality, meaning that information is protected so that only authorised persons may access it. It ensures integrity by protecting the accuracy and completeness of information and processing methods, and ensures availability so that, when an authorised user needs information, the user can actually access the requested information and the related resources are available.
7. The Company classifies and handles personal data as confidential data. It imposes confidentiality obligations on employees concerning processing of personal data. Access to personal data is restricted by assigning authorisation levels.
8. During automated processing of personal data, the controller and processor additionally ensure:
8.1. prevention of unauthorised data entry;
8.2. prevention of unauthorised persons using automated data-processing systems through data-transmission equipment;
8.3. the ability to verify and establish to which bodies personal data have been or may be transmitted using data-transmission equipment;
8.4. the ability to verify and establish which personal data were entered into automated data-processing systems, when and by whom;
8.5. recoverability of installed systems in the event of malfunction; and
8.6. preparation of reports on errors occurring during automated processing.
9. For the protection of personal data, the Company ensures monitoring of incoming and outgoing electronic communications.
10. Sharing personal data processed by the Company on the Internet is prohibited.
11. Use of unauthorised programs received from or downloaded from external sources is prohibited.
12. Only competent persons may access work in progress and documents under processing. Personnel, payroll, labour-related and other documents containing personal data must be kept securely locked away.
13. Appropriate physical protection must be ensured for data and the devices and documents carrying them.
VIII. RIGHTS OF DATA SUBJECTS
a. Procedural rules for exercising data-subject rights
1. The Company takes appropriate measures to provide the data subject with all information and communications concerning processing of personal data required by the GDPR in a concise, transparent, intelligible and easily accessible form, using clear and plain language, particularly for information addressed specifically to children. Information must be provided in writing or by other means, including, where appropriate, electronically. At the data subject’s request, oral information may also be provided, provided the data subject’s identity has been verified by other means.
2. The Company facilitates the exercise of the data subject’s rights under the GDPR. The data subject may request information about processing of personal data, request rectification or, except where processing is mandatory, erasure or withdrawal, and may exercise the rights to data portability and objection in the manner indicated when the data were collected or through the Company’s contact details above.
3. The Company informs the data subject of measures taken following a request without undue delay and in any event within one month of receipt. Where necessary, taking into account the complexity and number of requests, the period may be extended by a further two months. The Company informs the data subject of any extension within one month of receipt of the request, stating the reasons for the delay. Where the request was submitted electronically, the information should, where possible, also be provided electronically unless the data subject requests otherwise.
4. If the Company takes no action on the data subject’s request, it informs the data subject without undue delay and at the latest within one month of receipt of the request of the reasons for not taking action and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.
5. The Company provides requested information and communications free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, the Company may, taking into account the administrative costs of providing the information or taking the requested action, charge a reasonable fee or refuse to act on the request.
6. The Company bears the burden of demonstrating that a request is manifestly unfounded or excessive.
7. Where the Company has reasonable doubts concerning the identity of the natural person making a request, it may request additional information necessary to confirm the data subject’s identity.
b. Special rules for the protection of children
1. Where processing is based on consent, in relation to information-society services offered directly to children, processing is lawful where the child is at least 16 years old. For a child under 16, processing is lawful only to the extent and where consent is given or authorised by the holder of parental responsibility over the child.
2. Taking into consideration available technology, the Company makes reasonable efforts to verify in such cases that consent was given or authorised by the holder of parental responsibility.
3. The above rules do not affect Sections 2:10–2:18 of the Civil Code in force, which establish rules on the validity of legal declarations by minors, including the validity, form or effect of contracts concluded by them.
c. Special rules concerning special categories of personal data
1. Processing personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade-union membership, as well as genetic and biometric data for the purpose of uniquely identifying a natural person, health data and data concerning a natural person’s sex life or sexual orientation is prohibited, except for the exceptions provided in Article 9(2) and (3) of the GDPR.
2. Accordingly, special categories of personal data may be processed in particular where:
2.1. the data subject has given explicit consent, unless Union or national law provides that the prohibition may not be lifted by the data subject’s consent;
2.2. processing is necessary for the Company or the data subject to fulfil obligations and exercise specific rights in the field of employment and social-security and social-protection law;
2.3. processing relates to personal data which the data subject has manifestly made public; or
2.4. processing is necessary for preventive or occupational medicine purposes.
d. Certain rights of data subjects and how they are exercised
i. Right to information and access to personal data
A. Data collected directly from the data subject
1. Where personal data relating to the data subject are collected from the data subject, the Company provides the following information at the time the personal data are obtained:
1.1. the identity and contact details of the controller and, where applicable, the controller’s representative;
1.2. the contact details of the data protection officer, where one has been appointed;
1.3. the purposes of the intended processing and the legal basis for the processing;
1.4. where processing is based on GDPR Article 6(1)(f), the legitimate interests pursued by the controller or a third party;
1.5. where applicable, the recipients or categories of recipients of the personal data;
1.6. where applicable, the fact that the Company intends to transfer personal data to a third country or international organisation, and the existence or absence of a Commission adequacy decision or, in transfers under GDPR Articles 46, 47 or the second subparagraph of Article 49(1), reference to the appropriate and suitable safeguards and the means of obtaining a copy or information on where they are available.
2. In addition, to ensure fair and transparent processing, the Company provides:
2.1. the period for which the personal data will be stored or, if that is not possible, the criteria used to determine that period;
2.2. information about the data subject’s right to request access to and rectification or erasure of personal data, restriction of processing, and to object to processing, as well as the right to data portability;
2.3. where processing is based on GDPR Article 6(1)(a) or Article 9(2)(a), information about the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal;
2.4. the right to lodge a complaint with a supervisory authority;
2.5. whether provision of personal data is a statutory or contractual requirement or a requirement necessary to enter into a contract, whether the data subject is obliged to provide the personal data, and the possible consequences of failure to provide them; and
2.6. the existence of automated decision-making, including profiling, referred to in GDPR Article 22(1) and (4), and, at least in those cases, meaningful information about the logic involved and the significance and envisaged consequences of such processing for the data subject.
3. If the Company intends to further process personal data for a purpose other than that for which they were collected, before that further processing it informs the data subject of the other purpose and all relevant additional information described above.
4. The above provisions do not apply where and to the extent that the data subject already has the information.
B. Data not collected directly from the data subject
1. Where personal data have not been obtained from the data subject, the Company provides the data subject with:
1.1. the identity and contact details of the controller and, where applicable, the controller’s representative;
1.2. the contact details of the data protection officer, where one has been appointed;
1.3. the purposes of the intended processing and the legal basis;
1.4. the categories of personal data concerned;
1.5. the recipients or categories of recipients of the personal data;
1.6. where applicable, the fact that the Company intends to transfer personal data to a recipient in a third country or international organisation, together with the existence or absence of an adequacy decision and the applicable safeguards under GDPR Articles 46, 47 or the second subparagraph of Article 49(1), including how to obtain a copy or where they are available.
2. In addition, the Company provides the following information necessary to ensure fair and transparent processing:
2.1. the period for which the personal data will be stored or the criteria for determining that period;
2.2. where processing is based on GDPR Article 6(1)(f), the legitimate interests pursued by the controller or third party;
2.3. the data subject’s rights to access, rectification, erasure, restriction of processing, objection and data portability;
2.4. where processing is based on consent under GDPR Article 6(1)(a) or Article 9(2)(a), the right to withdraw consent at any time without affecting prior lawful processing;
2.5. the right to lodge a complaint with a supervisory authority;
2.6. the source from which the personal data originate and, where applicable, whether they came from publicly accessible sources; and
2.7. the existence of automated decision-making, including profiling, referred to in GDPR Article 22(1) and (4), together with meaningful information about the logic involved and the significance and envisaged consequences for the data subject.
3. The Company provides the above information:
3.1. within a reasonable period after obtaining the personal data, having regard to the specific circumstances, but at the latest within one month;
3.2. if the personal data are used for communication with the data subject, at the latest at the time of the first communication; or
3.3. if disclosure to another recipient is envisaged, at the latest when the personal data are first disclosed.
4. If the Company intends to further process the personal data for a purpose other than that for which they were obtained, it informs the data subject of the other purpose and all relevant additional information before the further processing.
5. The above provisions do not apply where and to the extent that:
5.1. the data subject already has the information;
5.2. providing the information proves impossible or would involve disproportionate effort, particularly in processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes under the conditions and safeguards of GDPR Article 89(1), or where the obligation would likely render impossible or seriously impair achievement of the processing objectives. In such cases, the Company takes appropriate measures to protect the data subject’s rights, freedoms and legitimate interests, including making the information publicly available;
5.3. obtaining or disclosure of the data is expressly provided for by Union or Member State law applicable to the controller, which provides appropriate measures to protect the data subject’s legitimate interests; or
5.4. the personal data must remain confidential under a professional secrecy obligation imposed by Union or Member State law, including a statutory obligation of secrecy.
6. The right to information may be exercised in writing through the Company’s stated contact details. At the data subject’s request, after identity verification, information may also be provided orally.
ii. Right of access
1. The data subject has the right to obtain confirmation from the Company as to whether personal data concerning him or her are being processed and, where processing is taking place, access to the personal data and to the following information: the purposes of processing; categories of personal data; recipients or categories of recipients to whom the data have been or will be disclosed, especially recipients in third countries and international organisations; the planned storage period; the rights to rectification, erasure and restriction and the right to object; the right to lodge a complaint with a supervisory authority; information about data sources; and the existence of automated decision-making, including profiling, together with meaningful information about the logic involved, significance and envisaged consequences.
2. Where personal data are transferred to a third country or international organisation, the data subject has the right to be informed of the appropriate safeguards relating to the transfer.
3. The Company provides a copy of the personal data undergoing processing. For additional copies requested by the data subject, the Company may charge a reasonable fee based on administrative costs. At the data subject’s request, the information is provided electronically.
iii. Right to rectification
1. The data subject has the right to obtain from the Company, without undue delay, rectification of inaccurate personal data concerning him or her. Taking into account the purposes of processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.
iv. Right to erasure (“right to be forgotten”)
1. The data subject has the right to obtain from the Company the erasure of personal data concerning him or her without undue delay, and the Company is obliged to erase personal data without undue delay where:
1.1. the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
1.2. the data subject withdraws consent on which the processing is based and there is no other legal ground for processing;
1.3. the data subject objects to the processing and there are no overriding legitimate grounds for the processing, or the data subject objects to processing for direct marketing;
1.4. the personal data have been unlawfully processed;
1.5. the personal data must be erased to comply with a legal obligation in Union or Member State law applicable to the Company; or
1.6. the personal data were collected in relation to the offer of information-society services.
2. If the Company has made the personal data public before receiving the erasure request and is obliged to erase them, it takes reasonable steps, taking account of available technology and implementation cost, including technical measures, to inform controllers processing the data that the data subject has requested erasure of links to, or copies or replications of, those personal data.
3. Erasure may not be requested where processing is necessary:
3.1. for exercising freedom of expression and information; for compliance with a legal obligation requiring processing under Union or national law or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; for reasons of public interest in the area of public health; for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes where erasure would likely render the processing impossible or seriously impair it; or for the establishment, exercise or defence of legal claims.
v. Right to restriction of processing
1. The data subject has the right to obtain restriction of processing where:
1.1. the accuracy of the personal data is contested, for the period enabling the Company to verify accuracy;
1.2. processing is unlawful and the data subject opposes erasure and requests restriction of use instead;
1.3. the Company no longer needs the personal data for processing purposes, but the data subject requires them for establishment, exercise or defence of legal claims; or
1.4. the data subject has objected to processing, pending verification of whether the Company’s legitimate grounds override those of the data subject.
2. Where processing is restricted, the personal data, except for storage, may be processed only with the data subject’s consent, or for establishment, exercise or defence of legal claims, protection of the rights of another natural or legal person, or for important public-interest reasons of the Union or a Member State.
3. The Company informs the data subject who has obtained restriction before the restriction is lifted.
4. The Company informs every recipient to whom personal data have been disclosed about rectification, erasure or restriction, unless this proves impossible or requires disproportionate effort. At the data subject’s request, the Company informs the data subject about those recipients.
vi. Right to data portability
1. The data subject has the right to receive personal data concerning him or her, which he or she has provided to the Company, in a structured, commonly used and machine-readable format and has the right to transmit those data to another controller without hindrance from the Company, provided processing is based on consent or a contract and is carried out by automated means.
2. In exercising the right to data portability, the data subject may request direct transmission of personal data between controllers where technically feasible.
3. Exercising the right to data portability must not adversely affect the rights and freedoms of others.
vii. Right to object and automated decision-making in individual cases
1. The data subject has the right, on grounds relating to his or her particular situation, to object at any time to processing of personal data based on a task carried out in the public interest or in the exercise of official authority vested in the Company, or processing necessary for the legitimate interests pursued by the Company or a third party, including profiling based on those provisions.
2. In such a case, the Company may no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or the processing is necessary for establishment, exercise or defence of legal claims.
3. The right to object must be explicitly brought to the data subject’s attention at the latest at the time of first communication and must be presented clearly and separately from other information.
4. Where personal data are processed for direct marketing, the data subject has the right to object at any time to processing for that purpose, including profiling insofar as it is related to direct marketing. Where the data subject objects to processing for direct marketing, the personal data may no longer be processed for those purposes.
viii. Automated decision-making in individual cases, including profiling
1. The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
2. The above right does not apply where the decision:
2.1. is necessary for entering into or performing a contract between the data subject and the Company;
2.2. is authorised by Union or national law applicable to the Company and that law lays down suitable measures to safeguard the data subject’s rights, freedoms and legitimate interests; or
2.3. is based on the data subject’s explicit consent.
ix. Right to withdraw consent
1. Where processing is based on consent (GDPR Article 6(1)(a)), the data subject has the right to withdraw consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal. The data subject must be informed of this before giving consent. Withdrawal must be as easy as giving consent.
2. The data subject must be appropriately informed of the legal consequences of withdrawing consent.
IX. PROCESSOR
1. Where processing is carried out on behalf of the Company by another party, the Company may use only processors that provide sufficient guarantees to implement appropriate technical and organisational measures so that processing meets GDPR requirements and the rights of data subjects are protected.
2. A processor may not engage another processor without the Company’s prior specific or general written authorisation. Where general written authorisation is given, the processor must inform the Company of any intended changes concerning the addition or replacement of other processors, thereby giving the Company the opportunity to object to such changes.
3. Processing by the processor must be governed by a contract that binds the processor to the controller and specifies the subject matter, duration, nature and purpose of processing, the types of personal data, the categories of data subjects, and the obligations and rights of the controller.
4. Where a processor engages another processor for specific processing activities carried out on behalf of the Company, the same data-protection obligations must be imposed on that other processor by contract as those set out between the Company and the processor, in particular requiring appropriate guarantees for appropriate technical and organisational measures and compliance with the GDPR. If the other processor fails to fulfil its data-protection obligations, the processor that engaged it remains fully liable to the Company for performance of the other processor’s obligations.
5. The Company and any person acting under the authority of the Company or the processor who has access to personal data may process those data only on the Company’s instructions, unless required to do so by Union or Member State law.
6. For the above processing activities, the Company performs electronic data processing and record-keeping using computer software meeting data-security requirements. Access is limited to persons who need it for their duties and is provided for specified purposes under controlled conditions. The Company does not use a processor for electronic data processing.
X. RECORDS OF PROCESSING ACTIVITIES
1. The Company’s executive officers, employees and any other person entrusted by the Company with processing shall maintain records of the processing activities carried out within their responsibility.
2. Where the Company uses a processor, the processor and, where applicable, the processor’s representative shall maintain records of all categories of processing activities carried out on behalf of the Company in accordance with the GDPR.
3. Records must be maintained in writing, including electronically.
4. The Company and, where applicable, the processor cooperate with the supervisory authority in carrying out their tasks, upon request by the authority.
XI. PERSONAL DATA BREACH
a. Notification of a personal data breach to the supervisory authority
1. A personal data breach is a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
2. In accordance with Chapter VII of this Policy, taking into account the state of science and technology and implementation costs and the nature, scope, context and purposes of processing, the Company implements appropriate technical and organisational measures to guarantee data security during processing.
3. If, despite the above, a personal data breach occurs during the Company’s processing activities—for example, computer equipment used to store data disappears or is lost, documents containing personal data are copied by unauthorised persons, personal data are unlawfully disclosed because documents are improperly destroyed, or a similar event occurs—the Company takes all measures required by this chapter to mitigate the adverse consequences arising from the breach.
4. Temporary unavailability of access to personal data due to system maintenance does not constitute a personal data breach.
5. Company employees, persons employed under other work-related legal relationships and processors used by the Company must immediately notify the Company’s managing director if, while performing their duties, they detect a personal data breach or an event indicating one.
6. Through the contact details stated above, the Company continuously ensures that contractual partners or other data subjects can report a personal data breach to the Company when they detect one.
7. Upon notification of a breach, the Company’s manager immediately examines the notification, identifies the incident and determines whether an actual personal data breach occurred or whether the notification is erroneous.
8. If an actual personal data breach occurred, the Company investigates and determines it and records the following in the breach report:
8.1. date and place of the breach;
8.2. description, circumstances and effects of the breach;
8.3. scope and scale of data affected;
8.4. categories of persons affected;
8.5. description of measures taken to remedy the breach; and
8.6. description of measures taken to prevent, remedy and mitigate damage arising from the breach.
9. When a breach occurs, the affected systems, persons and data must be identified and isolated, and evidence supporting the occurrence and circumstances of the breach must be preserved. Only thereafter may lawful operation be restored.
10. The Company notifies the competent supervisory authority of a personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If notification is not made within 72 hours, reasons for the delay must accompany it. Where there is no data protection officer, the Company’s managing director is responsible for notification.
11. The notification must contain at least the following facts and circumstances:
11.1. the nature of the personal data breach, including, where possible, the categories and approximate number of data subjects concerned and the categories and approximate number of personal-data records concerned;
11.2. the name and contact details of the data protection officer or other contact point from which further information can be obtained;
11.3. the likely consequences of the personal data breach; and
11.4. the measures taken or proposed by the Company to address the breach, including, where appropriate, measures to mitigate possible adverse effects.
12. Where the information cannot be provided simultaneously, it may be provided subsequently in stages without further undue delay.
13. The Company records personal data breaches, including the facts relating to the breach, its effects and the remedial measures taken. The record includes the report prepared by the Company’s managing director. This register enables the supervisory authority to verify compliance with GDPR requirements.
b. Information to the data subject about a personal data breach
1. Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Company informs the data subject of the breach without undue delay.
2. The communication to the data subject must describe the nature of the breach in clear and plain language and contain at least the information and measures specified in points XI/a/11.2 and 11.3 of this Policy.
3. The data subject need not be informed where any of the following applies:
3.1. the Company has implemented appropriate technical and organisational protection measures and those measures were applied to the personal data affected by the breach, in particular measures such as encryption that render the data unintelligible to unauthorised persons;
3.2. the Company has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects is no longer likely to materialise; or
3.3. informing the data subject would involve disproportionate effort. In such cases, the data subjects must be informed by publicly available information or by a similar measure ensuring equally effective information.
4. If the Company has not yet informed the data subject, the supervisory authority, after considering whether the breach is likely to result in a high risk, may require the Company to do so or may determine that one of the above conditions is met.
XII. DATA PROTECTION IMPACT ASSESSMENT AND PRIOR CONSULTATION
1. Where a type of processing, particularly using new technologies, is likely to result in a high risk to the rights and freedoms of natural persons, taking into account its nature, scope, context and purposes, the Company carries out an assessment before processing begins of how the planned processing operations affect the protection of personal data.
2. When carrying out a data protection impact assessment, the Company must seek the professional advice of the data protection officer, where one has been appointed.
3. The assessment covers at least:
3.1. a systematic description of the envisaged processing operations and the purposes of processing, including, where applicable, the legitimate interest pursued by the Company;
3.2. an assessment of the necessity and proportionality of the processing operations in relation to the purposes;
3.3. an assessment of the risks to the rights and freedoms of data subjects; and
3.4. the measures envisaged to address the risks, including safeguards, security measures and mechanisms to ensure protection of personal data and demonstrate compliance with the GDPR, taking into account the rights and legitimate interests of data subjects and other persons.
4. Where the impact assessment indicates that processing would result in a high risk in the absence of measures taken by the Company to mitigate the risk, the Company consults the supervisory authority before processing the personal data.
XIII. APPOINTMENT, STATUS AND TASKS OF THE DATA PROTECTION OFFICER
a. Appointment of the data protection officer
1. The Company must appoint a data protection officer where:
1.1. its core activities consist of processing operations which, by virtue of their nature, scope and/or purposes, require regular and systematic monitoring of data subjects on a large scale; or
1.2. its core activities consist of processing special categories of personal data.
2. The data protection officer must be appointed on the basis of professional qualities and, in particular, expert knowledge of data-protection law and practices and the ability to perform the tasks of a data protection officer.
3. The Company publishes the name and contact details of the data protection officer and communicates them to the supervisory authority.
b. Status of the data protection officer
1. The data protection officer may perform duties under an employment relationship or on the basis of a mandate.
2. The Company must ensure that the data protection officer is involved properly and in a timely manner in all matters relating to protection of personal data. The Company provides all resources necessary for performance of the officer’s duties. The Company must ensure that the data protection officer receives no instructions from anyone concerning the performance of those duties and cannot be instructed by the Company’s management.
3. The data protection officer may not be penalised or dismissed in connection with performing his or her tasks and reports directly to the Company’s highest governing body.
4. Data subjects may contact the data protection officer on all issues relating to processing of their personal data and exercise of their rights. The data protection officer is subject to a duty of confidentiality concerning facts and data that come to his or her knowledge in connection with the performance of the tasks.
c. Tasks of the data protection officer
1. The data protection officer performs at least the following tasks:
1.1. informs and advises the Company and employees/agents carrying out processing about their obligations under the GDPR and other Union or national data-protection provisions;
1.2. monitors compliance with the GDPR, other Union or national data-protection provisions and the Company’s internal rules concerning protection of personal data, including assignment of responsibilities, awareness-raising and training of personnel involved in processing operations, and related audits;
1.3. provides advice, upon request, regarding the data protection impact assessment and monitors its performance as necessary;
1.4. cooperates with the supervisory authority; and
1.5. acts as the contact point for the supervisory authority on processing-related matters and consults with it, where appropriate, on any other issue.
2. The data protection officer performs duties with due regard to the risk associated with processing operations and taking into account the nature, scope, context and purposes of processing.
XIV. REMEDIES AVAILABLE TO DATA SUBJECTS
a. Right to lodge a complaint with a supervisory authority
1. The data subject has the right to lodge a complaint with a supervisory authority if, in the data subject’s opinion, processing of personal data concerning him or her infringes the GDPR.
2. The supervisory authority with which the complaint has been lodged must inform the data subject of the progress and outcome of the complaint, including the possibility of seeking a judicial remedy.
3. Name and contact details of the supervisory authority:
Name: Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság)
Registered office: 1125 Budapest, Szilágyi Erzsébet fasor 22/C, Hungary
Postal address: 1530 Budapest, Pf.: 5., Hungary
Telephone: 06/1-391-1400
E-mail: ugyfelszolgalat@naih.hu
Website: http://www.naih.hu/
4. If the supervisory authority rejects the complaint or finds it unfounded, the data subject is entitled to bring an administrative action in accordance with the rules of administrative litigation.
b. Right to a judicial remedy against the supervisory authority
1. Both the data subject and the Company have the right to a judicial remedy against a legally binding decision of the supervisory authority concerning them.
2. The data subject has the right to a judicial remedy where the supervisory authority does not deal with the complaint or does not inform the data subject within three months of the progress or outcome of the complaint.
c. Right to a judicial remedy against the Company
1. In the event of infringement of rights, the data subject may bring proceedings against the Company before a court under the applicable legislation, in particular the GDPR and Act CXII of 2011 on Informational Self-Determination and Freedom of Information. In its decision, the court may order the Company to cease unlawful processing, restore lawful processing or engage in specified conduct and, where necessary, decide claims for damages or compensation for non-material harm.
2. The court with jurisdiction and competence for the proceedings is the Metropolitan Court of Budapest at the Company’s registered office or, at the data subject’s choice, the court having jurisdiction at the data subject’s place of residence.
d. Right to compensation and liability
1. A data subject who has suffered material or non-material damage as a result of an infringement of the GDPR is entitled to compensation from the Company for the damage suffered.
2. Each controller involved in processing is liable for damage caused by processing that infringes the GDPR. A processor is liable for damage caused by processing only where it has failed to comply with obligations specifically imposed on processors by the GDPR or has acted outside or contrary to lawful instructions of the Company.
3. The Company is exempt from liability if it proves that it is not in any way responsible for the event giving rise to the damage.
4. Where more than one controller or processor, or both a controller and a processor, are involved in the same processing and are responsible for damage caused by processing, each controller or processor is jointly and severally liable for the entire damage in order to ensure effective compensation of the data subject.
XV. SPECIAL RULES FOR TRANSFERS OF PERSONAL DATA TO THIRD COUNTRIES OR INTERNATIONAL ORGANISATIONS
1. Personal data may be transferred to a third country or international organisation, including onward transfers from a third country or international organisation to another third country or international organisation, where the data are or are intended to be processed after the transfer, only if, in addition to compliance with the other GDPR provisions, the controller and processor comply with the conditions laid down in Chapter V of the GDPR. All provisions of Chapter V must be applied to ensure that the level of protection guaranteed to natural persons by the GDPR is not undermined.
XVI. FINAL PROVISIONS
1. In matters not regulated by this Policy, the GDPR and the provisions of the national legislation on informational self-determination and freedom of information in force from time to time shall apply.
2. The Company’s managing director is authorised to adopt and amend this Policy.
3. The provisions of this Policy must be made known to all employees of the Company, persons engaged by the Company under other work-related legal relationships and the Company’s officers. Contracts for work or services must provide that compliance with and enforcement of this Policy are material obligations of every employee, other person employed and officer.