Website, Contact and Request for Quotation
Data Controller / Service Provider: ARJO-Consulting Kft.
Issued on: 22 July 2026 – effective from the date of publication on the website
Scope of this Privacy Notice
This Privacy Notice describes the processing of personal data related to the use of the https://arjokft.hu and https://en.arjokft.hu websites, contact and request-for-quotation forms, direct e-mail enquiries, and the management of cookie settings. The Data Controller will provide separate information, where necessary, regarding further data processing related to the performance of concluded client contracts.
1. Details of the Data Controller
Full company name: ARJO-Consulting Korlátolt Felelősségű Társaság
Abbreviated company name: ARJO-Consulting Kft.
Registered office and mailing address: 1037 Budapest, Vízimenta utca 15., Door 1, Hungary
Company registration number: 01-09-440978
Tax number: 32756566-2-41
Registering court: Company Court of the Metropolitan Court of Budapest
Authorised representatives: Bőhm Ármin, Managing Director, and Dr. Hohmann Johanna, Managing Director, with joint signing authority
Contact e-mail: info@arjokft.hu
Websites: https://arjokft.hu; https://en.arjokft.hu
Based on the present data processing activities, the Data Controller is not required to appoint a Data Protection Officer and has not appointed one. Data protection questions or data subject requests may be submitted via the above e-mail address.
2. Principles of Data Processing
The Data Controller processes personal data only for specified and lawful purposes, to the extent and for the period necessary. The data is not sold, made public, or made accessible to anyone other than those who require access for the performance of their duties.
The Data Controller strives to ensure the accuracy, confidentiality, integrity and availability of the data.
The website primarily provides information for businesses, institutions and professional partners. Users should preferably not provide special categories of personal data — such as health data, political opinions or other sensitive information — in free-text fields.
3. Individual Data Processing Activities
3.1. Technical Operation of the Website, Logging and IT Security
Purpose of data processing:
To make the website available, detect errors, prevent misuse and IT attacks, and maintain the security of the system.
Categories of data processed:
IP address; date and time of access; address of the requested page or file; technical response code; technical data relating to the browser, operating system and device; referring page, if transmitted by the browser.
Source of data:
The user’s browser and the technical logs of the web server.
Legal basis:
Legitimate interest pursuant to Article 6(1)(f) of the GDPR. The legitimate interest is to maintain a secure and reliable website and to ensure that errors and misuse can be investigated.
Retention period:
As a general rule, no longer than 30 days. In the event of a security incident, misuse or legal dispute, the relevant log data may be stored separately for as long as necessary for the investigation of the incident and the enforcement of claims.
Persons with access / recipients:
The authorised managing directors and contributors of the Data Controller; Rackhost Zrt. as hosting and technical service provider; authorities or courts acting on the basis of law.
Consequence of providing data:
The processing of technical data is necessary for the secure use of the website. Without logging, certain parts of the website would not function, or would not function securely.
3.2. Contact, Request for Quotation and Direct E-mail Enquiries
Purpose of data processing:
To receive enquiries, identify the interested party, provide a response, conduct communication, prepare quotations, and — at the request of the data subject — take steps prior to entering into a contract.
Categories of data processed:
Name; e-mail address; selected service; content of the message; further data voluntarily provided by the user, such as company name, position or telephone number; content of correspondence and communication.
Source of data:
The data subject or the organisation represented by the data subject.
Legal basis:
If the data subject requests a quotation or initiates the conclusion of a contract in their own name: Article 6(1)(b) of the GDPR.
If the data subject acts as a contact person of a company or institution, or sends a general professional enquiry: legitimate interest pursuant to Article 6(1)(f) of the GDPR. The legitimate interest is to respond to enquiries and maintain business and professional communication.
Retention period:
If no contract is concluded, the enquiry and related correspondence will be retained for 6 months from closure and then deleted, unless a legal dispute or enforcement of claims justifies longer retention. If a contract is concluded, contractual data will generally be retained for 5 years after termination of the contract, while data forming part of accounting records will be retained for 8 years in accordance with accounting legislation.
Persons with access / recipients:
The managing directors of the Data Controller and persons involved in handling the given enquiry; Rackhost Zrt. as e-mail and hosting service provider; where necessary, the Data Controller’s legal, accounting or professional contributors to the extent required for the performance of their tasks.
Consequence of providing data:
Without the data marked as mandatory, the enquiry cannot be submitted or answered. Providing additional data is voluntary.
Role of the checkbox below the form:
The statement “I have read and acknowledged the Privacy Notice” only confirms that the information has been provided. It does not constitute consent to data processing and does not replace the legal bases specified above.
3.3. Management of Cookie Settings and Consents
Purpose of data processing:
To remember the user’s cookie settings, implement the acceptance or rejection of non-essential cookies, and verify the giving and withdrawal of consent.
Categories of data processed:
Selected cookie categories; date and time of selection and modification; consent identifier; technical setting stored in the browser; technical data required for verification, if recorded by the consent management tool.
Source of data:
The user’s choice and browser.
Legal basis:
For non-essential cookies — such as preference, statistical or marketing cookies — consent pursuant to Article 6(1)(a) of the GDPR, in accordance with Section 155(4) of the Electronic Communications Act.
For records necessary to verify consent: Article 6(1)(c) of the GDPR, in accordance with the requirements of accountability and verifiability of consent.
For personal data processing related to cookies strictly necessary for the operation of the website: legitimate interest pursuant to Article 6(1)(f) of the GDPR.
Retention period:
As a general rule, the system stores the user’s choice for 12 months, after which a new choice may be requested. The user may withdraw or modify their consent at any time on the “Cookie Settings” interface.
Persons with access / recipients:
The Data Controller and the technical operator of the website; external service providers authorised by the data subject, only to the extent specified in the Cookie Notice.
Consequence of providing data:
Acceptance of non-essential cookies is voluntary. Refusing them must not prevent the use of basic content and the contact option, although certain convenience functions may be limited.
3.4. Links to External Websites and Social Media Platforms
The website may contain links to external services, such as Google Maps, Facebook, Instagram and LinkedIn. From the moment the external website is opened, the respective service provider acts as an independent data controller in accordance with its own privacy terms. The Data Controller does not control the data processing of external service providers.
If the website later uses embedded maps, videos, social media modules, analytics or advertising services, these may only be activated with the necessary prior consent and after the relevant notices have been properly updated.
4. Data Processor and Data Transfer
4.1. Hosting, E-mail and Technical Service Provider
Data processor: Rackhost Zrt.
Registered office: 6722 Szeged, Tisza Lajos körút 41., Hungary
E-mail: info@rackhost.hu
Website: https://www.rackhost.hu
Task:
Hosting, domain, e-mail and contractual technical operation services; processing of server logs and technical website data in accordance with the instructions of the Data Controller.
Beyond the above, the Data Controller may transfer personal data only on the basis of a legal obligation or a lawful request from an authority or court. Personal data is not sold for commercial purposes.
4.2. Transfers to Third Countries
The Data Controller does not plan to transfer personal data to third countries within the scope of its own website-related and contact-related data processing activities.
External services opened separately by the user, or service providers listed in the Cookie Notice and enabled with consent, may transfer data outside the European Economic Area in accordance with their own terms. Detailed information on the legal basis and safeguards of such transfers is provided by the respective service provider’s privacy notice.
5. Data Security
The Data Controller applies technical and organisational measures proportionate to the risks. These include, in particular, access restrictions, management of user permissions, encrypted data transmission (SSL/TLS), regular updates and backups, logging, and appropriate contractual obligations for data processors.
In the case of data transmission via the internet, complete risk-free operation cannot be guaranteed. Therefore, the Data Controller investigates security incidents and, where necessary, takes the measures required by law.
6. Rights of the Data Subject
The data subject may exercise their rights by contacting info@arjokft.hu. The Data Controller will respond to the request without undue delay and, as a general rule, within one month. Where necessary, taking into account the complexity or number of requests, this deadline may be extended by a further two months, of which the Data Controller will inform the data subject within one month.
Access:
The data subject may request information on whether data processing is taking place and may request a copy of the personal data processed.
Rectification:
The data subject may request the correction of inaccurate data and the completion of incomplete data.
Erasure:
The data subject may request the deletion of personal data under the conditions specified by law.
Restriction:
The data subject may request that the Data Controller only store the data or process it for specified purposes.
Data portability:
In the case of automated data processing based on consent or contract, the data subject may request that their data be provided or transferred in a structured, commonly used and machine-readable format.
Right to object (Article 21 of the GDPR):
The data subject may object at any time, on grounds relating to their particular situation, to processing based on legitimate interest [Article 6(1)(f) of the GDPR]. In the event of objection, the Data Controller will no longer process the personal data, unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or which are related to the establishment, exercise or defence of legal claims.
Pursuant to Article 21(4) of the GDPR, the Data Controller expressly draws the data subject’s attention to the right to object no later than at the time of the first communication, and provides this information clearly and separately from any other information.
Withdrawal of consent:
Consent may be withdrawn at any time with effect for the future. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
The fulfilment of requests is generally free of charge. In the case of manifestly unfounded, repetitive or excessive requests, the Data Controller may charge a reasonable fee or refuse to act, in accordance with the conditions laid down by law.
7. Complaints, Supervisory Authority and Judicial Remedies
The data subject may first contact the Data Controller so that the matter can be resolved as quickly as possible. Independently of this, the data subject may lodge a complaint with the supervisory authority or seek judicial remedy.
Supervisory authority:
Hungarian National Authority for Data Protection and Freedom of Information – NAIH
Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
Mailing address: 1363 Budapest, Pf. 9., Hungary
E-mail: ugyfelszolgalat@naih.hu
Website: https://www.naih.hu
Judicial proceedings may be initiated in accordance with the applicable procedural rules. The data subject may also bring proceedings before the court competent for their place of residence or habitual residence.
8. Automated Decision-Making and Profiling
The Data Controller does not carry out solely automated decision-making based on contact or request-for-quotation data, and does not create profiles concerning the data subject that would have legal or similarly significant effects.
9. Minors
The website and the services are not intended for minors. If the Data Controller becomes aware that data relating to a minor has been provided unnecessarily, it will delete such data without undue delay.
10. Amendments to this Privacy Notice
The Data Controller may amend this Privacy Notice in the event of changes to the functions of the website or the legal environment. The version in force at any given time is available on the website.
11. Legal Background
• Regulation (EU) 2016/679 of the European Parliament and of the Council – General Data Protection Regulation (GDPR).
• Act CXII of 2011 on Informational Self-Determination and Freedom of Information.
• Act CVIII of 2001 on Certain Issues of Electronic Commerce Services.
• Act C of 2003 on Electronic Communications, in particular Section 155(4).
• Act V of 2013 on the Civil Code.
• Act C of 2000 on Accounting.