The ECO-CRANES HUNGARY Cranes and Lifting Equipment Limited Liability Company (company registration number: 13-09-083304, tax number: 11912606-2-13, registered office: 2151 Fót, Ybl Miklós utca 42.) (hereinafter: Service Provider, Data Controller) is subject to the following policy:
On the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL (27 April 2016), we provide the following information.
This privacy policy governs the data management practices of the following websites: https://ecocranes.hu
The privacy policy is available on the following page:
https://ecocranes.hu/adatkezelesi-tajekoztato/
Amendments to the regulations shall enter into force upon publication at the above address.
Name: ECO-CRANES HUNGARY Cranes and Lifting Equipment Limited Liability Company
Registered office: 2151 Fót, Ybl Miklós utca 42.
Email: info@ecocranes.hu
Telephone: 27 360823
- „personal data”: any information relating to an identified or identifiable natural person („data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
- „data processing”: any operation or set of operations performed on personal data or data files, whether automated or not, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
- „data controller”: the natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by Union or Member State law, Union or Member State law may also lay down specific criteria for the controller or for the designation of the controller;
- „data processor”: a natural or legal person, public authority, agency or any other body which processes personal data on behalf of the data controller;
- „addressee”: a natural or legal person, public authority, agency or any other body to whom or which personal data are disclosed, whether a third party or not. Public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.;
- „the consent of the person concerned”: a voluntary, specific and unambiguous expression of the data subject's will, based on adequate information, by which the data subject indicates his or her consent to the processing of personal data concerning him or her by means of a statement or by means of a clearly affirmative action;
- „data protection incident”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
Principles governing the processing of personal data
Personal data:
- processing must be carried out lawfully, fairly and in a transparent manner in relation to the data subject („legality, fair procedure and transparency”);
- collection shall be carried out for specified, explicit and legitimate purposes and shall not be processed in a manner that is incompatible with those purposes; in accordance with Article 89(1), further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered incompatible with the initial purposes („purpose limitation”);
- be adequate and relevant for the purposes of data processing and limited to what is necessary („data economy”);
- they must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they were processed, are erased or rectified without delay („accuracy”);
- shall be stored in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) for scientific or historical research purposes or statistical purposes, subject to the implementation of appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject („limited shelf life”);
- processing must be carried out in such a manner that appropriate technical or organisational measures are applied to ensure adequate security of personal data, including protection against unauthorised or unlawful processing, accidental loss, destruction or damage („integrity and confidentiality”).
The data controller is responsible for compliance with the above and must be able to demonstrate such compliance („accountability”).
The data controller declares that data processing is carried out in accordance with the principles set out in this section.
Advertising and measurement terminology
- „pixel / tracking code”: a piece of code embedded in a website which uses cookies or similar technologies to collect information about a visitor’s activity on the website for the purposes of ad measurement and targeting (e.g. Meta Pixel).
- „remarketing (retargeting)”: an advertising solution that enables targeted reach to visitors who have previously visited the website via advertising platforms.
- „Conversions API (CAPI)”: a server-side event-tracking solution that transmits events occurring on the website to the advertising provider in an anonymised (hashed) form.
- „Custom Audience”: an audience uploaded by the data controller or derived from website traffic, used for advertising targeting.
- „joint data controller”: where two or more data controllers jointly determine the purposes and means of data processing [Article 26 of the GDPR].
- „pseudonymisation”: the processing of personal data in such a way that, without the use of further information, it is no longer possible to determine to which specific data subject the data relates (e.g. hashing).
REQUEST FOR QUOTATION
- The fact of data collection, the scope of data processed and the purposes of data processing:
Personal data Purpose of data processing Name Identification Telephone number Maintaining contact, coordination Email address Contact details are required to send the offer (response). Message It is necessary for developing and customising the offer. Date of request for quotation Performing a technical operation. IP address at the time of the request for quotation Performing a technical operation. The email address does not need to contain any personal information.
- The scope of those affected: all interested parties requesting a quote on the website.
- Duration of data processing, deadline for data deletion: Until the data subject requests deletion. The data controller shall inform the data subject electronically of the deletion of any personal data provided by the data subject in accordance with Article 19 of the GDPR. If the data subject's request for deletion also covers the e-mail address provided by him or her, the data controller shall also delete the e-mail address after providing the information.
- Identity of potential data controllers entitled to access the data, recipients of personal data: Personal data may be processed by the data controller's authorised employees in accordance with the provisions of this notice.
- Aexplanation of the rights of data subjects in relation to data processing:
- The data subject may request from the data controller access to and rectification or erasure of personal data concerning him or her or restriction of processing, and
- object to the processing of such personal data, and
- the data subject has the right to data portability and to withdraw consent at any time.
- Personal data access, You may request the deletion, modification or restriction of the processing of your data, as well as data portability, in the following ways:
- by post to 2151 Fót, Ybl Miklós utca 42,
- by email to info@ecocranes.hu by email,
- by telephone on 27 360823.
- Legal basis for data processing: Article 6(1)(b) of the GDPR.
- Please be advised that
- data processing is necessary for the purpose of making an offer.
- obliged provide personal data so that we can send you an offer.
- failure to provide data with the entails, that we are unable to provide you with a personalised quote.
Enquiries may be submitted directly via the enquiry form on the website, or via the instant form (Lead Form) displayed on the Meta (Facebook/Instagram) advertising platform. In the latter case, the data provided by the data subject is transferred by Meta Platforms Ireland Ltd. to the data controller. The legal basis for data processing in this case is also Article 6(1)(b) and (f) of the GDPR.
DATA PROCESSORS USED
Hosting provider
- Activity performed by the data processor: Hosting service
- Name and contact details of the data processor:
bEcommerce.hu Ltd.
Registered office: 1204 Budapest, Alsó határút 109.
Location: 8411 Veszprém, Öregrét utca 4.
Postal address: 8411 Veszprém, Öregrét utca 4.
Email: hello@becommerce.hu - The fact of data processing, the scope of data processed: All personal data provided by the data subject.
- Data subjects: All data subjects using the website.
- Purpose of data processing: To make the website available and ensure its proper operation.
- Duration of data processing, deadline for data deletion: Data processing shall continue until the termination of the agreement between the data controller and the hosting provider, or until the data subject submits a request for deletion to the hosting provider.
- Legal basis for data processing: Article 6(1)(f) of the GDPR and Section 13/A(3) of Act CVIII of 2001 on certain issues related to electronic commerce services and information society services.
Advertising and analytics provider (Meta)
- Activities carried out by the data processor/recipient: ad management, Meta Pixel, Conversions API, Custom Audience, Lead Ads.
- Name and contact details: Meta Platforms Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland.
- The fact that data is processed; the scope of the data processed: pseudonymised online identifiers, event data, hashed email addresses and/or telephone numbers, and the data provided via the Lead Form.
- Data subjects: data subjects who have consented to the processing of their data for advertising purposes.
- Purpose of data processing: displaying and measuring adverts, and remarketing.
- Legal basis for data processing: the data subject’s consent [Article 6(1)(a) of the GDPR].
Analytics and advertising provider (Google)
- Activities carried out by the data processor/recipient: web analytics (Google Analytics 4), Google Ads conversion tracking and remarketing.
- Name and contact details: Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland.
- The fact that data is processed; the scope of the data processed: pseudonymised user/advertising identifiers, truncated IP addresses, events, conversion data.
- Data subjects: data subjects who have consented to the use of cookies and the processing of advertising data.
- Purpose of data processing: traffic analysis, ad measurement, remarketing.
- Legal basis for data processing: the data subject’s consent [Article 6(1)(a) of the GDPR].
HANDLING OF COOKIES
- The fact of data processing, the scope of data processed: Unique identification number, dates, times
- Data subjects: All data subjects visiting the website.
- Purpose of data processing: Identification of users.
- Duration of data processing, deadline for data deletion:
Cookie type Legal basis for data processing Duration of data processing Processed data set Session cookies Act CVIII of 2001 on certain issues of electronic commerce services and information society services (Elkertv.) Section 13/A(3) The relevant
period until the visitor session is closedconnect.sid Persistent or saved cookies Act CVIII of 2001 on certain issues of electronic commerce services and information society services (Elkertv.) Section 13/A(3) until the data subject is deleted Advertising and analytics cookies (subject to consent) The data subject’s consent [Article 6(1)(a) of the GDPR] up to approximately 13 months _fbp, fr (Meta); _ga, _ga_*, _gcl_au (Google) - Persons authorised to access the data: The data controller does not process personal data through the use of cookies.
- Explanation of data subjects' rights regarding data processing: Data subjects have the option to delete cookies in the Tools/Settings menu of their browsers, usually under the Privacy settings.
- Legal basis for data processing: Consent from the data subject is not required if the sole purpose of using cookies is to transmit information via an electronic communications network or if the service provider absolutely needs them to provide an information society service specifically requested by the subscriber or user.
- The use of advertising and analytics cookies on the website (e.g. Meta Pixel, Google Analytics 4, Google Ads) require the data subject’s prior consent [Article 6(1)(a) of the GDPR], which may be given via the website’s cookie consent manager (cookie banner) and may be withdrawn at any time.
Community Pages
- The fact that data is collected, and the scope of the data processed: the name used to register on social media sites such as Facebook, Instagram, X (formerly Twitter), Pinterest, YouTube and LinkedIn, etc., and the user’s public profile picture.
- Data subjects: All data subjects who have registered on social media platforms such as Facebook, Instagram, X (formerly Twitter), Pinterest, YouTube, LinkedIn, etc., and have „liked” the website.
- Purpose of data collection: Sharing and „liking” certain content elements, products, promotions or the website itself on social media sites.
- Duration of data processing, deadline for data deletion, persons authorised to access the data and description of the data subjects' rights in relation to data processing: Data subjects can find information about the source of the data, its processing, the method of transfer and the legal basis on the relevant social media site. Data processing takes place on social media sites, so the duration and method of data processing, as well as the options for deleting and modifying data, are governed by the regulations of the given social media site.
- Legal basis for data processing: the data subject's voluntary consent to the processing of their personal data on social media sites.
META (FACEBOOK/INSTAGRAM) LEAD ADS – INSTANT FORMS
- The fact that data is collected and the scope of the data processed: data provided via the instant form (Lead Form) associated with Meta (Facebook, Instagram) advertising: name, email address, telephone number, any other data provided on the form (e.g. company name, message), and the lead ID generated by Meta.
- Scope of data subjects: all data subjects who complete and submit Meta’s instant form.
- Purpose of data processing: to receive and respond to the data subject’s enquiry, and to establish contact.
- Duration of data processing and deadline for erasure: until the data subject submits a request for erasure or until the business relationship is terminated. The data controller shall download the lead data from the Meta platform without undue delay; the copy stored on the Meta site shall be deleted in accordance with Meta’s deletion rules (within a maximum of 90 days).
- The identity of potential data controllers entitled to access the data, and the recipients of the personal data: the data controller’s authorised staff, and Meta Platforms Ireland Ltd. as a recipient/data processor.
- Legal basis for data processing: Article 6(1)(b) of the GDPR (measures taken at the data subject’s request prior to entering into a contract) and Article 6(1)(f) of the GDPR (the data controller’s legitimate interest in responding to enquiries).
META PIXEL AND REMARKETING (RETARGETING)
- The fact that data is collected, and the scope of the data processed: data processed via the Meta Pixel embedded on the website and the associated cookies (e.g. _fbp, fr): device and browser data, IP address (in truncated/pseudonymised form), actions performed on the website (pages viewed, quote request events), pseudonymised online identifiers.
- Data subjects: all visitors to the website who have given their consent to the use of cookies.
- The purpose of data processing: to measure the effectiveness of adverts, track conversions, and carry out remarketing – targeting visitors who have previously visited the website via Meta’s (Facebook, Instagram) advertising platforms.
- Duration of data processing and deadline for data erasure: for the lifetime of the relevant cookies, or until consent is withdrawn.
- The identity of any potential data controllers entitled to access the data, and the recipients of the personal data: Meta Platforms Ireland Ltd.
- Legal basis for data processing: the data subject’s consent [Article 6(1)(a) of the GDPR], which is given via the website’s cookie consent manager (cookie banner). Pixel and remarketing are only activated once consent has been given; consent may be withdrawn at any time by changing the cookie settings.
META CONVERSIONS API (SERVER-SIDE EVENT TRANSMISSION)
- The fact that data is collected and the scope of the data processed: the data controller uses the Meta Conversions API (CAPI) solution, under which events occurring on the website (e.g. requests for quotes) are transmitted to Meta on the server side. The data transmitted is transferred in a pseudonymised, encrypted (hashed) form: hashed email addresses and/or telephone numbers, event data, and technical identifiers.
- Data subjects: individuals who carry out an action on the website (e.g. submit an enquiry) and who have given their consent to the processing of their data for advertising purposes.
- Purpose of data processing: to measure advertising conversions more accurately and independently of the browser used, and to optimise advertisements.
- The identity of any potential data controllers entitled to access the data, and the recipients of the personal data: Meta Platforms Ireland Ltd.
- Legal basis for data processing: the data subject’s consent [Article 6(1)(a) of the GDPR], in accordance with Meta Pixel, given and withdrawn via the cookie banner.
META CUSTOM AUDIENCE (CUSTOM AUDIENCE)
- The fact of data collection and the scope of the data processed: the data controller uses the Meta Custom Audience service, in the course of which it uploads pseudonymised, hashed identifiers (email addresses, telephone numbers) from its own lists of customers and prospective customers, and uses audiences created from website visitors for the purpose of targeted advertising.
- Scope of data subjects: those data subjects whose data are lawfully held by the data controller and who have consented to the processing of their data for advertising purposes.
- The purpose of data processing: to display relevant adverts to current and former prospects, and to create lookalike audiences.
- Duration of data processing and deadline for data erasure: until consent is withdrawn or until the audience list is deleted from the Meta system.
- Joint data processing: the data controller and Meta Platforms Ireland Ltd. are considered joint data controllers in relation to Custom Audience, in accordance with Meta’s „Controller Addendum”. The relevant terms and conditions of Meta set out the essential details of joint data processing and the exercise of data subjects’ rights.
- Legal basis for data processing: the data subject’s consent [Article 6(1)(a) of the GDPR]. The data subject may withdraw their consent at any time and may object to the processing of their data for direct marketing purposes [Article 21(2) of the GDPR].
GOOGLE ANALYTICS 4 (WEB ANALYTICS)
- The fact that data is collected and the scope of the data processed: the website uses the Google Analytics 4 service; data processed via the associated cookies (e.g. _ga, _ga_*): pseudonymised user/device identifiers, truncated IP addresses, technical data relating to the visit and interactions carried out on the website.
- Data subjects: all data subjects who visit the website and consent to the use of cookies.
- The purpose of data processing: to analyse website traffic and usage, to compile statistics, and to improve the service.
- The identity of any potential data controllers entitled to access the data, and the recipients of the personal data: Google Ireland Ltd.
- Legal basis for data processing: the data subject’s consent [Article 6(1)(a) of the GDPR], via the cookie banner.
GOOGLE ADS – CONVERSION TRACKING AND REMARKETING
- The fact that data is collected, and the scope of the data processed: data processed via Google Ads conversion tracking and remarketing cookies (e.g. _gcl_au, as well as Google/DoubleClick advertising cookies): pseudonymised advertising identifiers, actions performed on the website, conversion events.
- Data subjects: visitors to the website who have given their consent.
- The purpose of data processing: to measure the effectiveness of Google adverts and to target previous visitors (remarketing) within the Google advertising network.
- The identity of any potential data controllers entitled to access the data, and the recipients of the personal data: Google Ireland Ltd.
- Legal basis for data processing: the data subject’s consent [Article 6(1)(a) of the GDPR]. The data controller uses the Google Consent Mode v2 solution, which aligns the processing of data for Google services with the data subject’s consent status.
INTERNATIONAL DATA TRANSFER
When using Meta and Google services, personal data may be transferred outside the European Economic Area to the United States. This transfer is subject to appropriate safeguards: the service providers are certified participants in the EU–US Data Privacy Framework, and the transfer of data is governed by the Standard Contractual Clauses (SCCs) adopted by the European Commission.
CUSTOMER RELATIONS AND OTHER DATA PROCESSING
- If you have any questions or problems while using our data processing services, you can contact the data controller using the methods provided on the website (telephone, e-mail, social media, etc.).
- The data controller shall delete the data provided in emails, messages, telephone calls, Facebook, etc., together with the name and email address of the interested party and other personal data provided voluntarily, after a maximum of two years from the date of disclosure.
- We will provide information about data processing not listed in this notice at the time of data collection.
- In the event of an exceptional request from an authority or a request from other bodies based on legal authorisation, the Service Provider shall be obliged to provide information, communicate and transfer data, and make documents available.
- In such cases, the Service Provider shall disclose to the requesting party – provided that the exact purpose and scope of the data have been specified – only such personal data and to such an extent as is strictly necessary to achieve the purpose of the request.
Rights of data subjects
- Right of access
You have the right to obtain confirmation from the data controller as to whether your personal data is being processed and, if so, you have the right to access your personal data and the information listed in the Regulation. - Right to rectification
You have the right to request that the data controller correct any inaccurate personal data concerning you without undue delay. Taking into account the purpose of the data processing, you have the right to request that incomplete personal data be completed, including by means of providing a supplementary statement. - Right to erasure
You have the right to request that the data controller erase your personal data without undue delay, and the data controller is obliged to erase your personal data without undue delay under certain conditions. - The right to be forgotten
Where the controller has made the personal data public and is obliged to erase it, taking into account the available technology and the cost of implementation, it shall take reasonable steps, including technical measures, to inform controllers who process the data that you have requested the deletion of any links to, or copies or replications of, that personal data. - Right to restriction of processing
You have the right to request that the data controller restrict data processing if any of the following conditions are met:- You contest the accuracy of the personal data, in which case the restriction applies for a period enabling the controller to verify the accuracy of the personal data;
- the processing is unlawful and you oppose the erasure of the data and request the restriction of their use instead;
- the data controller no longer needs the personal data for the purposes of the processing, but they are required by you for the establishment, exercise or defence of legal claims;
- You have objected to the processing of your data; in this case, the restriction applies for as long as it takes to determine whether the legitimate grounds of the controller override your legitimate grounds.
- Right to data portability
You have the right to receive the personal data concerning you, which you have provided to a data controller, in a structured, commonly used and machine-readable format, and you have the right to transmit those data to another data controller without hindrance from the data controller to which the personal data have been provided (...) - The right to protest
In the case of data processing based on legitimate interest or public authority powers as legal grounds, you have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data, including profiling based on those provisions. - Objection in the case of direct solicitation
If personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such purposes, including profiling, insofar as it is related to direct marketing. If you object to the processing of personal data for direct marketing purposes, the personal data may no longer be processed for this purpose. - Automated decision-making in individual cases, including profiling
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
The preceding paragraph shall not apply if the decision:
- It is necessary for the conclusion or performance of a contract between you and the data controller;
- the decision is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard your rights and freedoms and legitimate interests; or
- It is based on your explicit consent.
Deadline for action
The data controller shall, without undue delay, but in any event within one month of receiving the request, respond to the request. within 1 month inform you of the measures taken in response to the above requests.
If necessary, this Extendable by 2 months. The data controller shall decide on the extension of the deadline within 15 working days of receiving the request, stating the reasons for the delay. within 1 month informs you.
If the data controller does not take action upon your request, without delay, but no later than one month after receiving your request, inform you of the reasons for not taking action, and that you may lodge a complaint with a supervisory authority and exercise your right to judicial remedy.
Security of data processing
The data controller and data processor shall take into account the state of the art and the costs of implementation, and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including, where appropriate:
- the pseudonymisation and encryption of personal data;
- ensuring the ongoing confidentiality, integrity, availability and resilience of systems and services used to process personal data;
- in the event of a physical or technical incident, the ability to restore access to personal data and the availability of data in a timely manner;
- a procedure for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of data processing.
Informing the data subject about the data protection incident
If the data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.
In the information provided to the data subject clearly and comprehensibly the nature of the data breach must be described, and the name and contact details of the data protection officer or other contact person providing further information must be provided; the likely consequences of the data breach must be described; describe the measures taken or planned by the data controller to remedy the data breach, including, where appropriate, measures to mitigate any adverse consequences resulting from the data breach.
The data subject shall not be informed if any of the following conditions are met:
- the data controller implemented appropriate technical and organisational protection measures, and these measures have been applied to the data affected by the data breach, in particular those measures – such as encryption – that prevent unauthorised persons from accessing personal data render the data incomprehensible;
- the data controller has taken further measures following the data protection incident which ensure that the high risk to the rights and freedoms of the data subject is unlikely to materialise in the future;
- the information would require a disproportionate effort. In such cases, the persons concerned shall be informed by means of publicly available information or by similar measures that ensure that the persons concerned are informed in a similarly effective manner.
If the controller has not yet notified the data subject of the personal data breach, the supervisory authority may, after considering whether the personal data breach is likely to result in a high risk, order the controller to inform the data subject.
Reporting a data protection incident to the authority
The data controller shall notify the supervisory authority competent pursuant to Article 55 of the personal data breach without undue delay and, where feasible, not later than 72 hours after becoming aware of it to the supervisory authority competent under Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. If the notification is not made within 72 hours, the reasons for the delay must be included.
Complaints procedure
Complaints against any infringement by the data controller may be lodged with the National Authority for Data Protection and Freedom of Information:
National Authority for Data Protection and Freedom of Information
1125 Budapest, Szilágyi Erzsébet fasor 22/C.
Postal address: 1530 Budapest, PO Box: 5.
Telephone: +36 -1-391-1400
Fax: +36-1-391-1410
Email: ugyfelszolgalat@naih.hu