PRIVACY NOTICE

Based on the GDPR (EU 2016/679) and the applicable Hungarian data protection legislation

Version: 1.0
Effective date: 1 August 2026
Review: as necessary

1. Details of the Data Controller

1.1 Identification Details of the Data Controller

1.2 Data Protection Contact

1.3 Personal and Material Scope of the Notice

1.4 Purpose of the Document

2. Legal Background

2.1 Primary Legal Sources Governing Data Processing

2.2 Principles for the Application of Legislation

3. Definitions

3.1 Application of the Definitions

4. Principles of Data Processing

4.1 Lawfulness, Fairness and Transparency

4.2 Purpose Limitation

4.3 Data Minimisation

4.4 Accuracy

4.5 Storage Limitation

4.6 Integrity and Confidentiality

4.7 Accountability

5.1 Contact and Requests for Quotations

5.1.1 Electronic Contact

5.1.2 Telephone and In-Person Contact

5.1.3 Requests for Quotations

5.1.4 Rights of Data Subjects

5.2 Grant Consultancy and Grant Application Preparation

5.2.1 Preliminary Consultation and Assessment of Grant Opportunities

5.2.2 Preliminary Grant Eligibility Assessment

5.2.3 Processing of Data Required for Preparing Grant Applications

5.2.4 Management of Grant Application Documentation

6.1 General Information

6.2 Registration for Training and Management of the Training Relationship

6.3 Data Processing Related to the Delivery of Training

6.4 Subsidised Training Programmes

7. Data Processors

7.1 General Information

7.2 Data Processors Engaged

7.2.1 Hosting and Email Service Provider

7.2.2 Website Operator / Maintenance Provider

7.2.3 Microsoft 365 Cloud Services (Outlook, OneDrive)

7.3 Principles Governing the Engagement of Data Processors

8. Rights of Data Subjects

9. Legal Remedies

10. Data Security

10.1 Principles of Data Security

10.2 Management of Personal Data Breaches

10.3 Application of This Section

1. DETAILS OF THE DATA CONTROLLER

Sillabusz 2000 Kft. is committed to processing the personal data of its clients, partners, training participants and all other data subjects in a lawful, fair and transparent manner. This Privacy Notice is intended to fulfil the information obligation set out in Articles 12–14 of the GDPR and provides detailed information on the purposes, legal bases and duration of the processing activities carried out by the Data Controller, the rights of data subjects, and the data security principles applied.

1.1 Identification Details of the Data Controller

Company name:
Sillabusz 2000 Kft.

Registered office:
2045 Törökbálint, Deák Ferenc utca 37., Hungary

Company registration number:
Cg. 13-09-237018

Tax number:
12446258-2-13

Email:
sillabusz2000kft@gmail.com

Telephone:
+36 70 623 9614

1.2 Data Protection Contact

The contact person designated by the Data Controller for data protection matters is:

The contact person is responsible for receiving requests from data subjects concerning data processing, providing information and coordinating data protection enquiries.

1.3 Personal and Material Scope of the Notice

This Privacy Notice applies to all processing activities carried out by Sillabusz 2000 Kft. in connection with grant consultancy, grant application preparation, project management, adult education, training organisation, business development, and the administrative, communication and customer service activities associated with its operations.

Its personal scope covers, in particular, prospective clients, clients, natural-person contacts of contractual partners, applicants for and participants in training programmes, lecturers, subcontractors, newsletter subscribers, website visitors and every natural person whose personal data is processed by the Data Controller.

1.4 Purpose of the Document

The purpose of this document is to explain the rules governing the processing of personal data in a transparent and comprehensible manner, provide appropriate information to data subjects, facilitate the exercise of data subject rights under the GDPR, and demonstrate the Data Controller’s compliance with its accountability obligations.

2. LEGAL BACKGROUND

When processing personal data, Sillabusz 2000 Kft. acts exclusively in accordance with the applicable legislation of the European Union and Hungary. Its processing operations are designed on the basis of the principles of lawfulness, fairness, transparency, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability.

For each processing activity, the Data Controller determines the purpose and legal basis of processing, the categories of data processed, the retention period and any recipients in accordance with the GDPR.

2.1 Primary Legal Sources Governing Data Processing

GDPR – Regulation (EU) 2016/679

The European Union’s General Data Protection Regulation.

It establishes the general legal framework for processing, the rights of data subjects and the obligations of the Data Controller.

Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Infotv.)

The foundation of Hungarian data protection legislation.

It supplements the domestic application of the GDPR, supervisory procedures and the enforcement of the right to informational self-determination.

Act LXXVII of 2013 on Adult Education

Special rules governing adult education activities.

It sets out obligations relating to training administration, data reporting and records.

Act V of 2013 on the Civil Code (Ptk.)

Regulation of contractual relationships.

It provides one of the legal foundations for processing connected with clients, partners and service relationships.

Act C of 2000 on Accounting and Applicable Tax Legislation

Document retention obligation.

It determines the retention periods applicable to invoices and financial documents.

Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (Elkertv.)

Regulation of electronic services.

It contains requirements relating to the operation of the website and certain technical processing activities.

2.2 Principles for the Application of Legislation

The Data Controller seeks not only formal compliance with legislation but also the fulfilment of its purpose.

Accordingly, when designing each processing operation, it assesses in advance the necessity and proportionality of the processing and selects the appropriate legal basis pursuant to Article 6(1) of the GDPR.

3. DEFINITIONS

The purpose of this section is to provide a brief and easily understandable explanation of the key terms necessary for interpreting this Privacy Notice.

The definitions are based on the terminology of the GDPR but do not constitute a verbatim reproduction of it.

Data Controller

The organisation that determines the purposes and means of processing personal data. In this Notice, the Data Controller is Sillabusz 2000 Kft.

Data Subject

The natural person whose personal data is processed by the Data Controller, such as a prospective client, client, training applicant or participant.

Personal Data

Any information relating to an identified or identifiable natural person, such as their name, email address or telephone number.

Processing

Any operation performed on personal data, including in particular its collection, recording, storage, use, alteration, transmission or deletion.

Data Processor

An external service provider or partner that processes personal data on behalf of and in accordance with the instructions of the Data Controller, such as a hosting provider or accountant.

Recipient

A person or organisation to whom the Data Controller lawfully discloses personal data.

Consent

A voluntary and unambiguous indication by the data subject through which they agree to the processing of their personal data for a specified purpose.

Special Category Personal Data

Personal data requiring a higher level of protection than usual, such as health data. Sillabusz 2000 Kft. processes such data only where the applicable statutory conditions are met.

Personal Data Breach

An event that results or may result in unauthorised access to, loss, destruction or alteration of personal data.

Retention Period

The period for which the Data Controller stores personal data in accordance with the purpose of processing or a statutory obligation.

3.1 Application of the Definitions

The above terms have the same meaning throughout all sections of this Notice.

Where legislation provides a different definition for a particular processing activity, this is specifically indicated in the relevant section.

4. PRINCIPLES OF DATA PROCESSING

Sillabusz 2000 Kft. conducts all of its processing activities in accordance with the principles laid down in the GDPR.

These principles ensure that personal data is processed lawfully, transparently and securely. The following principles apply to all processing activities described in this Notice.

4.1 Lawfulness, Fairness and Transparency

Personal data is processed in every case on a specified legal basis and with clear and comprehensible information provided to data subjects.

During processing, we seek to ensure that data subjects are always aware of what data we process, for what purpose and for how long.

4.2 Purpose Limitation

Personal data is collected only for predetermined and lawful purposes.

Data provided for grant consultancy, grant application preparation, project management, adult education or communication is not used for any other purpose incompatible with the original purpose.

4.3 Data Minimisation

We request and process only personal data that is genuinely necessary for providing the relevant service or complying with a statutory obligation.

4.4 Accuracy

We take reasonable measures to ensure that processed data is accurate and up to date.

Inaccurate data is rectified or supplemented upon request.

4.5 Storage Limitation

Personal data is retained only for as long as justified by the purpose of processing or a statutory obligation.

After the retention period has expired, the data is erased or anonymised unless otherwise required by law.

4.6 Integrity and Confidentiality

We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, destruction or alteration.

4.7 Accountability

The Data Controller is responsible for ensuring that its processing practices comply with the law and for being able to demonstrate such compliance through appropriate documentation where necessary.

5.1 CONTACT AND REQUESTS FOR QUOTATIONS

A significant proportion of the activities of Sillabusz 2000 Kft. begins with personal contact.

Prospective clients may contact the company in connection with grant consultancy, grant application preparation, project management or training.

In every case, the purpose of processing is to respond to the enquiry, prepare a quotation and, where cooperation is established, prepare for the conclusion of a contract.

The Data Controller processes only the personal data that is necessary.

5.1.1 Electronic Contact

Prospective clients may contact the Data Controller by email or through the contact form available on the website.

Purpose of processing:
Responding to enquiries, establishing contact and arranging consultations.

Legal basis:
Article 6(1)(b) of the GDPR or, in the case of general enquiries, Article 6(1)(a).

Data processed:
Name, email address, telephone number where provided, the content of the enquiry and any additional information provided voluntarily.

Retention period:
No longer than one year after the matter has been closed.

Recipients:
The Data Controller’s staff and the data processors providing email and hosting services.

The Data Controller uses the data exclusively for handling the relevant matter and discloses it to third parties only where required by law or in the context of contractual data processing.

5.1.2 Telephone and In-Person Contact

Where an enquiry is made by telephone or in person, only the necessary data is recorded.

Purpose of processing:
Providing information, arranging appointments and presenting services.

Legal basis:
Article 6(1)(b) of the GDPR.

Data processed:
Name, telephone number, email address where necessary, and the subject of the enquiry.

Retention period:
No longer than one year or, where a contract is concluded, in accordance with the rules applicable to the contract.

Recipients:
The relevant staff members of the Data Controller.

5.1.3 Requests for Quotations

Where a quotation is requested, the Data Controller processes the data required to prepare the quotation.

Purpose of processing:
Preparing an individual quotation and making preparations for cooperation.

Legal basis:
Article 6(1)(b) of the GDPR.

Data processed:
Contact details and information relating to the requested service and project.

Retention period:
No longer than one year after the quotation expires if no contract is concluded.

Recipients:
The Data Controller’s staff and, where necessary, data processors.

5.1.4 Rights of Data Subjects

A detailed description of the rights of data subjects is provided in Section 8 of this Notice.

5.2 GRANT CONSULTANCY AND GRANT APPLICATION PREPARATION

In the course of providing grant consultancy and grant application preparation services, Sillabusz 2000 Kft. processes the personal data required for cooperation with the client.

Processing is always limited to what is necessary for preparing and providing the service and maintaining contact.

5.2.1 Preliminary Consultation and Assessment of Grant Opportunities

The purpose of the preliminary consultation is to determine whether the client or project may meet the requirements of a specific call for proposals.

The consultation may take place in person, by telephone or online.

Purpose of processing:
Assessing grant opportunities, providing professional advice and maintaining contact.

Legal basis:
Article 6(1)(b) of the GDPR – taking steps at the request of the data subject prior to entering into a contract.

Data processed:
Name, email address and telephone number of the contact person, basic company details, a brief description of the project and any additional information voluntarily provided by the data subject.

Retention period:
No longer than one year after the consultation has been concluded, unless a contract is entered into.

Recipients:
The Data Controller’s staff and the necessary IT data processors.

The Data Controller processes only the data required to provide the relevant service.

Such data may be accessed only by staff involved in performing the task and, where necessary, by data processors.

5.2.2 Preliminary Grant Eligibility Assessment

During the preliminary assessment, the Data Controller examines whether the client meets the basic eligibility conditions of the selected grant.

Only the data necessary for this purpose is requested.

Purpose of processing:
Preliminary examination of grant eligibility and preparation of the service.

Legal basis:
Article 6(1)(b) of the GDPR.

Data processed:
Contact details, company identification data, key project information and information required to assess the grant conditions.

Retention period:
No longer than one year after completion of the preliminary assessment or, where a contract is concluded, in accordance with the retention rules applicable to the contract.

Recipients:
The relevant staff members of the Data Controller and, where necessary, data processors.

5.2.3 Processing of Data Required for Preparing Grant Applications

When preparing a grant application, Sillabusz 2000 Kft. processes only the personal data necessary for compiling and submitting the application and representing the client.

Processing is always limited to what is necessary for performing the relevant grant-related task.

Purpose of processing:
Compiling the grant documentation, preparing the application, preparing it for submission, maintaining contact and drafting the required declarations.

Legal basis:
Article 6(1)(b) of the GDPR – performance of a contract and taking steps at the request of the data subject prior to entering into a contract.

Data processed:
Names, positions and contact details of contact persons; identification data of managing directors and persons authorised to represent the organisation; project data; financial data; and, where necessary, personal data contained in powers of attorney, declarations and other documents to be submitted.

Retention period:
Until the expiry of the limitation period for civil law claims following termination of the contract or, where legislation or the relevant funding scheme requires a longer retention period, for that longer period.

Recipients:
The relevant staff members of the Data Controller, participating data processors and organisations involved in the submission or evaluation of the grant application where necessary for performing the service.

5.2.4 Management of Grant Application Documentation

After the grant application has been prepared, the Data Controller manages the application documentation for the purposes of performing the contract, carrying out related administration, and complying with any subsequent inspections and legal obligations.

Purpose of processing:
Registering and retaining the grant application documentation, ensuring its retrievability and complying with contractual and statutory obligations.

Legal basis:
Article 6(1)(b) of the GDPR and, where applicable, Article 6(1)(c) – compliance with a legal obligation.

Data processed:
Personal data contained in the grant application documentation, including in particular contact details, representation data, declarations, powers of attorney and personal data contained in the submitted annexes.

Retention period:
Until the end of the retention period prescribed by the applicable legislation or the rules of the relevant funding programme following termination of the contract.

Recipients:
The relevant staff members of the Data Controller, IT and document-management data processors, and authorities or funding bodies acting pursuant to law.

Access to grant application documentation is restricted to persons who require it to perform their duties or comply with statutory obligations.

The Data Controller treats the documents as confidential and protects them through appropriate data security measures.

6.1 GENERAL INFORMATION

In the course of its adult education activities, Sillabusz 2000 Kft. processes participants’ personal data in accordance with the applicable legislation governing adult education, in particular Act LXXVII of 2013, Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), and other related legislation.

The purpose of processing is to establish the training relationship, deliver the training, comply with statutory record-keeping and data-reporting obligations, and maintain continuous contact with participants.

In every case, the Data Controller processes only the personal data necessary to achieve the relevant purpose, treats such data confidentially, and protects it through appropriate technical and organisational measures.

A significant proportion of adult education processing activities is prescribed by law.

The Data Controller is therefore required to process more data than would be necessary in the case of a general service.

6.2 Registration for Training and Management of the Training Relationship

Registration for training, preliminary reconciliation of data, conclusion of the training contract and communication during the training period are closely related processing activities.

During these processes, Sillabusz 2000 Kft. processes only the personal data necessary for organising and delivering the training and complying with statutory obligations.

Purpose of processing:
Receiving applications for training, verifying admission requirements, establishing the training relationship, concluding the training contract, organising the training and communicating with participants.

Legal basis:
Article 6(1)(b) of the GDPR – taking steps prior to entering into a contract and performance of the contract; and Article 6(1)(c) of the GDPR in the case of processing prescribed by law.

Data processed:
The participant’s name, birth name, place and date of birth, mother’s name, residential address, email address, telephone number, other data necessary for organising the training and complying with statutory obligations, and information provided during communication.

Retention period:
For the period prescribed by the applicable legislation, in particular the rules governing adult education, and for as long as the statutory retention obligation continues after termination of the training relationship.

Recipients:
The relevant staff members of the Data Controller, data processors participating pursuant to law and, where data must be reported under legislation, the relevant authorities or organisations maintaining the applicable registers.

When managing applications and training relationships, the Data Controller requests and processes only personal data indispensable for organising and delivering the training, maintaining the records prescribed by law and communicating with the data subject.

Personal data may be accessed only by authorised persons.

6.3 Data Processing Related to the Delivery of Training

During the delivery of training, Sillabusz 2000 Kft. processes the personal data required for implementing the training in accordance with statutory requirements.

This includes, in particular, reporting data to the Adult Education Data Reporting System (FAR), maintaining attendance sheets and progress logs, using online education platforms, organising examinations and issuing certificates and confirmations.

Purpose of processing:
Lawful delivery of training, documenting training progress, complying with statutory record-keeping and reporting obligations, organising examinations and issuing certificates.

Legal basis:
Article 6(1)(b) of the GDPR – performance of a contract, and Article 6(1)(c) – compliance with a legal obligation.

Data processed:
The participant’s identification and contact details, data relating to participation, attendance, performance, examinations and the issuance of certificates, and the FAR data prescribed by law.

Retention period:
For the retention period prescribed by the legislation governing adult education.

Recipients:
The relevant staff members of the Data Controller, the operator of FAR, authorities acting pursuant to law and the necessary IT data processors.

6.4 Subsidised Training Programmes

Where training is implemented under a European Union or Hungarian funding programme – in particular GINOP Plusz, DIMOP Plusz or another funding scheme – Sillabusz 2000 Kft. also fulfils the data-reporting and record-keeping obligations prescribed by the funding agreement and applicable legislation.

Purpose of processing:
Delivering the subsidised training, demonstrating compliance with the funding conditions, fulfilling mandatory data-reporting obligations and enabling inspections.

Legal basis:
Article 6(1)(c) of the GDPR – compliance with a legal obligation, and Article 6(1)(b) – performance of the training relationship.

Data processed:
Participants’ identification and contact details, declarations required by the funding programme, eligibility and participation data, and personal data contained in documents confirming completion of the training.

Retention period:
Until the end of the retention period specified in the legislation, funding agreement or call for proposals applicable to the funding programme.

Recipients:
Managing authorities, intermediary bodies, supervisory authorities, audit organisations and other bodies acting pursuant to law.

7. DATA PROCESSORS

7.1 General Information

Sillabusz 2000 Kft. engages data processors to provide certain services.

Data processors process personal data exclusively on the instructions of the Data Controller and in accordance with the applicable data protection legislation.

They may not make independent decisions concerning the processing of personal data and may process such data only for the purposes and duration specified in the relevant contract.

7.2 Data Processors Engaged

The following sections are intended to record the data processors engaged by Sillabusz 2000 Kft.

The actual details of the data processors must be included in the final document.

7.2.1 Hosting and Email Service Provider

Name of data processor:
Rackhost Informatikai Zrt.

Registered office:
6722 Szeged, Tisza Lajos krt. 41., Hungary

Data processed:
Personal data contained in electronic correspondence, contact details such as name, email address and telephone number, personal data contained in email attachments, and personal data contained in documents stored on the hosting service.

Purpose of processing:
Providing electronic mail services, securely storing documents and electronic files, and providing the IT infrastructure necessary for the operation of the Data Controller.

Legal basis of processing by the processor:
The data processor acts on behalf of and on the instructions of the Data Controller as a processor pursuant to Article 28 of the GDPR.

The legal basis of the processing it performs is the same as the legal basis applicable to the relevant processing activity, in particular Article 6(1)(b), (c) or (f) of the GDPR and, where necessary, Article 6(1)(a).

Is data transferred?
No personal data is transferred to a third country.

7.2.2 Website Operator / Maintenance Provider

Name of data processor:
Rackhost Informatikai Zrt.

Registered office:
6722 Szeged, Tisza Lajos krt. 41., Hungary

Data processed:
Personal data submitted through the website, such as contact form data; personal data stored in the website database; and technical log data generated during the operation of the website, where the data processor has access to such data.

Purpose of processing:
Ensuring the continuous operation, maintenance, updating, troubleshooting, security and availability of the website.

Legal basis:
The data processor carries out processing pursuant to Article 28 of the GDPR, on the basis of the data processing agreement concluded with the Data Controller and in accordance with the Data Controller’s instructions.

Is data transferred?
No personal data is transferred to a third country.

7.2.3 Microsoft 365 Cloud Services (Outlook, OneDrive)

Name of data processor:
Microsoft Ireland Operations Limited, Microsoft 365 services

Registered office:
One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland

Data processed:
Personal data contained in documents stored in the following cloud services:

This includes, in particular, contact details, contracts, grant application documentation, adult education documentation and personal data contained in other electronic files uploaded by the Data Controller.

Purpose of processing:
Secure electronic storage, backup, synchronisation and sharing of documents, and support for the Data Controller’s business and administrative activities.

Legal basis:
The data processor carries out processing pursuant to Article 28 of the GDPR, on the basis of its contract with the Data Controller and in accordance with the Data Controller’s instructions.

Is data transferred?
Yes.

Transfers are carried out on the basis of safeguards compliant with Chapter V of the GDPR, such as the Standard Contractual Clauses adopted by the European Commission.

7.3 Principles Governing the Engagement of Data Processors

Sillabusz 2000 Kft. engages only data processors that provide sufficient guarantees regarding the secure processing of personal data and compliance with the requirements of the GDPR.

Data processors may access only the data necessary to perform their tasks and may process such data solely in accordance with the instructions of the Data Controller.

The Data Controller reviews the list of data processors as necessary and updates this Notice whenever changes occur.

8. RIGHTS OF DATA SUBJECTS

Sillabusz 2000 Kft. ensures that natural persons affected by the processing of personal data can exercise the rights granted to them under the GDPR.

Data subjects may submit requests in writing or electronically using the contact details of the Data Controller provided in this Notice.

The Data Controller assesses requests without undue delay and no later than within one month.

Right to information

The data subject may request information concerning the processing of their personal data.

Right of access

The data subject may obtain information about which personal data is processed by the Data Controller, for what purpose and for how long.

Right to rectification

The data subject may request the correction or completion of inaccurate or incomplete personal data.

Right to erasure

Where the statutory conditions are met, the data subject may request the erasure of their personal data.

Right to restriction of processing

In certain circumstances, the data subject may request that processing be restricted.

Right to data portability

Where the conditions laid down in the GDPR are met, the data subject may request the transfer of data they have provided.

Right to object

Where processing is based on legitimate interests, the data subject may object to the processing of their personal data.

Withdrawal of consent

Where processing is based on consent, the data subject may withdraw that consent at any time.

Withdrawal does not affect the lawfulness of processing carried out prior to the withdrawal.

Where necessary, the Data Controller is entitled to verify the identity of the person submitting the request in order to prevent personal data from being disclosed to an unauthorised person.

9. LEGAL REMEDIES

Where a data subject considers that the processing of their personal data by Sillabusz 2000 Kft. does not comply with the applicable data protection legislation, they are advised first to contact the Data Controller directly so that the issue or complaint can be resolved as soon as possible.

Where the data subject disagrees with the response or considers that their rights continue to be infringed, they are entitled to lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information, NAIH, or seek judicial remedy in accordance with the GDPR and the Infotv.

Contacting the Data Controller

The data subject may submit a request or complaint directly to the Data Controller.

NAIH

A complaint may be lodged with the Hungarian National Authority for Data Protection and Freedom of Information.

Judicial remedy

The data subject may bring proceedings before the court having jurisdiction according to their place of residence or habitual residence.

Sillabusz 2000 Kft. seeks to handle all data protection enquiries cooperatively and transparently and within the statutory deadlines.

10. DATA SECURITY

When processing personal data, Sillabusz 2000 Kft. pays particular attention to data security and to preventing unauthorised access, alteration, disclosure, erasure, loss or destruction.

The Data Controller applies technical and organisational measures appropriate to the nature and volume of the data processed and the risks associated with processing.

10.1 Principles of Data Security

Employees and other persons participating in the processing of personal data are required to treat personal data obtained in the course of their work as confidential, comply with data protection and information security rules, and take all measures reasonably expected of them to protect personal data.

10.2 Management of Personal Data Breaches

Where the Data Controller becomes aware of an event that endangers or may have endangered the security of personal data, it immediately investigates the circumstances of the incident, takes the measures necessary to prevent or mitigate harm and, where required by law, fulfils its notification and information obligations under the GDPR.

10.3 Application of This Section

The data security requirements set out in this section apply to all processing activities of Sillabusz 2000 Kft. described in this Privacy Notice.