Privacy Policy
Reference: GDPR DOC 1.0
Issue No: 0.0.1
Issue Date: 25 March 2025
Introduction
Background to the General Data Protection Regulation (GDPR)
The General Data Protection Regulation 2016 replaces the EU Data Protection Directive of 1995 and supersedes the laws of individual Member States developed in compliance with Data Protection Directive 95/46/EC. Its purpose is to protect the rights and freedoms of natural persons (living individuals) and to ensure that personal data is not processed without their knowledge and, wherever possible, with their consent.
Definitions used by the organisation
The following definitions are drawn from the GDPR.
Material scope — Article 2
The GDPR applies to the processing of personal data wholly or partly by automated means (for example, by computer) and to non-automated processing of personal data, such as paper records, where those records form part of, or are intended to form part of, a filing system.
Territorial scope — Article 3
The GDPR applies to controllers established in the European Union (EU) that process personal data of data subjects in the context of that establishment. It also applies to controllers outside the EU that process personal data to offer goods or services to, or monitor the behaviour of, data subjects resident in the EU.
Article 4 definitions
Establishment
The main establishment of a controller in the EU is the place where it makes the principal decisions about the purposes and means of its data-processing activities. The main establishment of a processor in the EU is its administrative centre. A controller based outside the EU may need to appoint a representative in the jurisdiction in which it operates to act on its behalf and deal with supervisory authorities.
Personal data
Any information relating to an identified or identifiable natural person (a data subject). An identifiable person is someone who can be identified directly or indirectly, including by reference to a name, identification number, location data, online identifier, or factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity.
Special categories of personal data
Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership; and genetic, biometric, health, sex-life or sexual-orientation data.
Data controller
The natural or legal person, public authority, agency or other body that alone or jointly with others determines the purposes and means of personal-data processing. Where Union or Member State law determines those purposes and means, it may provide for the controller or criteria for its nomination.
Data subject
Any living individual who is the subject of personal data held by an organisation.
Processing
Any operation or set of operations performed on personal data, whether or not by automated means. This includes collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, making available, alignment, combination, restriction, erasure and destruction.
Profiling
Any form of automated processing intended to evaluate personal aspects relating to a natural person, or to analyse or predict their work performance, economic situation, location, health, personal preferences, reliability or behaviour. This is linked to the data subject's right to object to profiling and to be informed about profiling, measures based on it and their envisaged effects.
Personal data breach
A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. Controllers may have to report breaches to the supervisory authority and, where a breach is likely to adversely affect personal data or privacy, to affected data subjects.
Data subject consent
Any freely given, specific, informed and unambiguous indication of a data subject's wishes by which they signify, through a statement or clear affirmative action, agreement to the processing of personal data relating to them.
Child
The GDPR defines a child as a person under 16 years old, although Member State law may lower this age to no lower than 13. Processing a child's personal data is lawful only where parental or custodian consent has been obtained. Controllers must make reasonable efforts to verify that consent is given or authorised by the holder of parental responsibility.
Third party
A natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
Filing system
Any structured set of personal data accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis.
Policy statement
The Board of Directors and management of Ways Tech International Kft., located at 1071 Dembinszky Utca 20, Budapest, Hungary, are committed to compliance with relevant EU and Member State laws governing personal data and to protecting the rights and freedoms of individuals whose information Ways Tech International Kft. collects and processes in accordance with the GDPR.
Compliance with the GDPR is described by this policy and other relevant policies, including the Information Security Policy and related processes and procedures.
The GDPR and this policy apply to all of Ways Tech International Kft.'s personal-data processing functions, including processing of customers', clients', employees', suppliers', partners' and other individuals' personal data from any source.
Ways Tech International Kft. has established data-protection and privacy objectives in its PIMS and GDPR Objectives Record.
The Data Protection Officer (DPO) is responsible for reviewing the register of processing annually in light of changes to Ways Tech International Kft.'s activities, including changes identified in the data inventory register and management review, and additional requirements identified through data-protection impact assessments (DPIAs). The register must be available on request by the supervisory authority.
This policy applies to all Ways Tech International Kft. employees, staff and outsourced suppliers. Any breach of the GDPR or this PIMS will be addressed under the organisation's disciplinary policy and may also constitute a criminal offence, in which case it will be reported to the appropriate authorities as soon as possible.
Partners and third parties working with or for Ways Tech International Kft. that have, or may have, access to personal data are expected to read, understand and comply with this policy. No third party may access personal data held by Ways Tech International Kft. without first entering into a data-confidentiality agreement that imposes obligations no less onerous than those to which Ways Tech International Kft. is committed and gives Ways Tech International Kft. the right to audit compliance.
Responsibilities and roles under the GDPR
Ways Tech International Kft. is a data processor under the GDPR.
Top management and everyone in managerial or supervisory roles throughout Ways Tech International Kft. are responsible for developing and encouraging good information-handling practices. Individual responsibilities are set out in job descriptions.
István Szabó (DPO) is accountable to the Board of Directors for management of personal data within Ways Tech International Kft. and for ensuring that compliance with data-protection legislation and good practice can be demonstrated. This accountability includes:
- Development and implementation of GDPR requirements under this policy
- Security and risk management related to compliance with this policy
The DPO is responsible for day-to-day compliance with this policy and the GDPR. Managers and executives are likewise responsible for processing within their respective areas.
The DPO has specific responsibilities for procedures such as the Subject Access Request Procedure and is the first point of contact for employees seeking clarification on data-protection compliance.
Compliance with data-protection legislation is the responsibility of all employees of Ways Tech International Kft. who process personal data. The organisation's Training Policy sets out role-specific training and awareness requirements.
Employees are responsible for ensuring that personal data about them, and supplied by them to Ways Tech International Kft., is accurate and current.
Data protection principles
All personal-data processing must comply with the principles in Article 5 of the GDPR. Ways Tech International Kft.'s policies and procedures are designed to support that compliance.
Lawfulness, fairness and transparency
Personal data must be processed lawfully, fairly and transparently.
- Lawfully: A lawful basis must be identified before processing personal data. Consent is one possible basis.
- Fairly: The controller must make specified information available to data subjects where practicable, whether the data was obtained directly from them or from another source.
- Transparently: GDPR Articles 12, 13 and 14 require privacy information to be understandable, accessible and communicated in clear, plain language.
At a minimum, privacy information must include:
- The identity and contact details of the controller and, where applicable, its representative
- The DPO's contact details
- Processing purposes and legal basis
- The retention period
- The rights to access, rectification, erasure and objection, and applicable conditions
- Categories of personal data concerned
- Recipients or categories of recipients, where applicable
- Where applicable, intended transfers to third countries and the level of protection afforded
- Any further information needed to ensure fair processing
Purpose limitation
Personal data may be collected only for specified, explicit and legitimate purposes. Data collected for specified purposes must not be used for purposes that differ from those formally notified in Ways Tech International Kft.'s GDPR register of processing.
Data minimisation
Personal data must be adequate, relevant and limited to what is necessary for the purpose of processing.
The DPO is responsible for ensuring that Ways Tech International Kft. does not collect information that is not strictly necessary. Data-collection forms, including requirements for new information systems, must include a fair-processing statement or a link to the privacy statement and be approved by the DPO.
The DPO will ensure that data-collection methods are reviewed at least annually through internal audit to verify that collected data remains adequate, relevant and not excessive.
Accuracy
Personal data must be accurate and kept up to date. Every reasonable step must be taken to erase or rectify inaccurate data without delay.
Data stored by a controller must be reviewed and updated where necessary. Data should not be retained unless it is reasonable to consider it accurate.
The DPO is responsible for ensuring that staff understand the importance of collecting and maintaining accurate data. Data subjects are also responsible for ensuring that the information they provide is accurate and current.
Employees, customers and other relevant parties should notify Ways Tech International Kft. of changes in circumstances so personal records can be updated. The DPO is responsible for appropriate procedures and policies to keep data accurate, taking account of the volume of data, how quickly it may change and other relevant factors.
At least annually, the DPO will review retention dates for all processed personal data by reference to the data inventory and identify data no longer required for its registered purpose. Such data will be securely deleted or destroyed in line with the Secure Disposal of Storage Media Procedure.
The DPO is responsible for responding to rectification requests within one month. This may be extended by a further two months for complex requests. If Ways Tech International Kft. does not comply, the DPO will explain the reasoning and inform the data subject of their right to complain to a supervisory authority and seek a judicial remedy.
Where inaccurate or out-of-date personal data has been passed to third parties, the DPO will make appropriate arrangements to notify them that the data must not be used to inform decisions about the individual and will pass corrections where required.
Storage limitation
Personal data must be kept in a form that permits identification of data subjects only for as long as necessary for processing.
Where personal data is retained beyond the processing period, it will be encrypted to protect the data subject's identity in the event of a breach. Personal data will be retained in line with the Retention of Records Procedure and securely destroyed after the applicable retention date.
The DPO must specifically approve, in writing, retention that exceeds periods defined in the Retention of Records Procedure and ensure that the justification is identified and consistent with data-protection legislation.
Integrity and confidentiality
Personal data must be processed in a way that ensures appropriate security.
The DPO will conduct risk assessments that take account of all circumstances surrounding Ways Tech International Kft.'s processing operations. In assessing suitable technical measures, the DPO will consider:
- Password protection
- Automatic locking of idle terminals
- Removal of USB and other memory-media access rights
- Antivirus software and firewalls
- Role-based access rights, including rights for temporary staff
- Encryption of devices that leave the organisation's premises, including laptops
- Security of local and wide-area networks
- Privacy-enhancing technologies, including pseudonymisation and anonymisation
- Relevant international security standards
In assessing organisational measures, the DPO will consider:
- Appropriate training levels throughout the organisation
- Measures addressing employee reliability, such as references
- Data-protection provisions in employment contracts
- Disciplinary measures for data breaches
- Monitoring staff compliance with relevant security standards
- Physical access controls for electronic and paper records
- A clear-desk policy
- Secure storage of paper records in lockable, fire-proof cabinets
- Restrictions on portable-device use outside the workplace
- Restrictions on use of employees' personal devices in the workplace
- Clear password rules
- Regular backups of personal data and off-site storage of backup media
- Contractual requirements for appropriate security measures when data is transferred outside the EEA
These controls are selected based on identified risks to personal data and the potential for damage or distress to affected individuals. Ways Tech International Kft.'s compliance with this principle is addressed in its Information Security Management System (ISMS), developed in line with ISO/IEC 27001:2022.
Accountability
The controller must be able to demonstrate compliance with the GDPR's other principles. The accountability principle in Article 5(2) requires controllers to demonstrate compliance and makes this their explicit responsibility.
Ways Tech International Kft. demonstrates compliance by implementing data-protection policies, adhering to codes of conduct, applying technical and organisational measures, and using practices including data protection by design, DPIAs, breach-notification procedures and incident-response plans.
Data subjects' rights
Data subjects have the following rights regarding data processing and recorded personal data:
- To make subject access requests about information held and to whom it has been disclosed
- To prevent processing likely to cause damage or distress
- To prevent processing for direct-marketing purposes
- To be informed about the mechanics of automated decision-making that will significantly affect them
- Not to have significant decisions affecting them made solely by automated processing
- To seek compensation for damage caused by a GDPR contravention
- To rectify, block, erase, including through the right to be forgotten, or destroy inaccurate data
- To ask a supervisory authority to assess whether the GDPR has been contravened
- To receive personal data in a structured, commonly used and machine-readable format and have it transmitted to another controller
- To object to automated profiling occurring without consent
Ways Tech International Kft. enables data subjects to exercise these rights. Data subjects may make access requests under the Subject Access Request Procedure, which describes how the organisation will respond in accordance with GDPR requirements.
Data subjects may complain to Ways Tech International Kft. about processing of their personal data, handling of a request or the outcome of a complaint, in line with the Complaints Procedure.
Consent
Ways Tech International Kft. understands consent to mean an explicit, freely given, specific, informed and unambiguous indication of a data subject's wishes, signified through a statement or clear affirmative action. A data subject may withdraw consent at any time.
Consent requires that the data subject has been fully informed about the intended processing, is in a fit state of mind, and has agreed without pressure. Consent obtained under duress or from misleading information is not valid.
There must be active communication demonstrating active consent. Consent cannot be inferred from a lack of response. The controller must be able to demonstrate that consent was obtained for the processing operation.
For sensitive data, explicit written consent is required unless another legitimate basis for processing applies.
Where Ways Tech International Kft. provides online services to children, parental or custodial authorisation must be obtained. This applies to children under 16 unless the relevant Member State has set a lower age, which cannot be below 13.
Security of data
All employees are responsible for ensuring that personal data held by Ways Tech International Kft. and under their responsibility is kept securely and is not disclosed to third parties unless the third party is specifically authorised to receive it and has entered into a confidentiality agreement.
Personal data must be accessible only to people who need to use it, and access may be granted only in line with the Access Control Policy. Personal data must be protected, as appropriate:
- In a lockable room with controlled access
- In a locked drawer or filing cabinet
- When computerised, through password protection under the Access Control Policy
- On removable computer media only where encrypted in line with Secure Disposal of Storage Media requirements
Care must be taken to ensure that PC screens and terminals are visible only to authorised employees. Employees must enter an Acceptable Use Agreement before receiving access to organisational information; this includes rules regarding screen time-outs.
Manual records must not be left where unauthorised people can access them and may not be removed from business premises without explicit written authorisation. Once manual records are no longer needed for daily client support, they must be securely archived in line with the Information Security Policy.
Personal data may be deleted or disposed of only in line with the Retention of Records Procedure. Manual records that have reached their retention date must be shredded and disposed of as confidential waste. Hard drives of redundant PCs must be removed and destroyed before disposal.
Processing personal data off-site carries a greater risk of loss, theft or damage. Staff must be specifically authorised to process data off-site.
Disclosure of data
Ways Tech International Kft. must ensure that personal data is not disclosed to unauthorised third parties, including family members, friends, government bodies and, in some circumstances, the police. Employees must exercise caution when asked to disclose data about another person and will receive training to address this risk.
Any disclosure must be relevant and necessary to conduct Ways Tech International Kft.'s business. Requests for disclosure must be supported by appropriate documentation and specifically authorised by the DPO.
Retention and disposal of data
Ways Tech International Kft. will not keep personal data in a form that permits identification of data subjects for longer than necessary in relation to the purpose or purposes for which it was collected.
Personal data may be stored for longer periods where it will be processed solely for archiving in the public interest, scientific or historical research, or statistical purposes, subject to appropriate technical and organisational safeguards for data subjects' rights and freedoms.
Retention periods for each category of personal data, and the criteria used to determine them, including statutory retention obligations, are set out in the Retention of Records Procedure.
Ways Tech International Kft.'s retention and disposal procedures apply in all cases. Personal data must be securely disposed of in accordance with the GDPR principle requiring processing in a manner that ensures appropriate security and protects data subjects' rights and freedoms.
Data transfers
Exports of data from the European Economic Area (EEA) to countries outside the EEA (third countries) are unlawful unless an appropriate level of protection for data subjects' fundamental rights is in place.
Personal data may not be transferred outside the EEA unless one or more applicable safeguards or exceptions applies.
Adequacy decisions
The European Commission may determine that a third country, territory or specified sector provides an adequate level of protection. Where an adequacy decision applies, no additional authorisation is required.
Countries that are members of the EEA but not the EU are accepted as meeting adequacy conditions. The European Commission publishes countries that satisfy adequacy requirements in the Official Journal of the European Union.
Privacy Shield
Where Ways Tech International Kft. transfers personal data from the EU to an organisation in the United States, it should verify that the organisation is signed up to the Privacy Shield framework with the U.S. Department of Commerce. Organisations participating in that framework must follow the Privacy Principles and renew membership annually.
Assessment of adequacy by the data controller
When assessing adequacy, the exporting controller should take account of:
- The nature of the information transferred
- The country or territory of origin and final destination
- How the information will be used and for how long
- The laws and practices of the recipient country, including relevant codes of practice and international obligations
- The security measures to be applied at the overseas location
Binding corporate rules
Ways Tech International Kft. may adopt approved binding corporate rules for transfers outside the EU, subject to submission to and approval by the relevant supervisory authority.
Model contract clauses
Ways Tech International Kft. may adopt approved model contract clauses, including Standard Contractual Clauses (SCCs), for transfers outside the EEA.
Exceptions
In the absence of an adequacy decision, Privacy Shield membership, binding corporate rules or model contract clauses, a transfer to a third country or international organisation may take place only where one of the following conditions applies:
- The data subject explicitly consented after being informed of possible transfer risks
- The transfer is necessary to perform a contract with the data subject or implement pre-contractual measures at their request
- The transfer is necessary to conclude or perform a contract in the data subject's interest between the controller and another person
- The transfer is necessary for important reasons of public interest
- The transfer is necessary to establish, exercise or defend legal claims
- The transfer is necessary to protect the vital interests of the data subject or another person where the data subject is physically or legally incapable of consent
Information asset register and data inventory
Ways Tech International Kft. has established a data inventory and data-flow process as part of its GDPR-compliance approach. The inventory and data flow identify:
- Business processes that use personal data
- Sources of personal data
- Volumes of data subjects
- Descriptions of each personal-data item
- Processing activities
- Categories of personal data processed
- Purpose or purposes for each category of personal data
- Recipients and potential recipients of personal data
- The organisation's role throughout the data flow
- Key systems and repositories
- Data transfers
- Retention and disposal requirements
Ways Tech International Kft. identifies risks associated with processing particular types of personal data and assesses the level of risk to individuals. DPIAs are carried out for processing performed by Ways Tech International Kft. and for processing undertaken on its behalf by other organisations.
The organisation will manage risks identified through assessments to reduce the likelihood of non-conformance with this policy.
Where processing, especially involving new technologies and considering its nature, scope, context and purpose, is likely to result in a high risk to individuals' rights and freedoms, Ways Tech International Kft. will carry out a DPIA before processing begins. A single DPIA may cover similar processing operations that present similar high risks.
If a DPIA indicates that Ways Tech International Kft. is about to begin processing that could cause damage or distress to data subjects, the decision to proceed must be escalated to the DPO. Where there are significant concerns about possible damage, distress or the quantity of data, the DPO will escalate the matter to the supervisory authority.
Appropriate ISO/IEC 27001:2022 controls will be selected and applied to reduce processing risks to an acceptable level and support GDPR compliance.
Document owner and approval
The Data Protection Officer (DPO) owns this document and is responsible for ensuring that it is reviewed in line with the review requirements stated above.
A current version is available to all staff and published on the company website.
This policy was approved by the Board of Directors on 25 March 2025 and is issued on a version-controlled basis under the signature of the Chief Executive Officer (CEO).
Signature:
Date: 25 March 2025