Date of last revision: 13 July 2023.
The purpose of the Privacy Notice
Grant Thornton Consulting Kft. as the controller of personal data (hereinafter: Controller), hereby accepts the provisions hereof as binding upon itself, and undertakes an obligation to ensure that the processing of data by it as a controller, as related to its activities, comply with the requirements of the present policy and the relevant provisions of national law and EU legislation in effect.
A privacy policy relating to the data processing activities of the Controller is continuously available at https://grantthornton.hu/en/privacy-notice
The Controller reserves the right amend this privacy notice at any time, with notification given to data subjects in due time.
Grant Thornton Consulting Kft. is committed to the protection of the personal data of its clients and partners, and considers respecting its clients’ right to informational self-determination of particular importance. Grant Thornton Consulting Kft. processes personal data confidentially, and uses every security, technical and organisational measure to ensure data security.
The practice of Grant Thornton Consulting Kft. as a controller of personal data is described below.
The purpose of the present document is to inform you about how we process the personal data of visitors to the www.grantthornton.wpengine.com website.
The member companies of Grant Thornton Hungary (Grant Thornton Consulting Kft., Grant Thornton Audit Kft., Grant Thornton Advisory Kft., Grant Thornton Valuation Kft., Grant Thornton Digital Kft.) are by agreement considered a joint controller, represented by Grant Thornton Consulting Kft., which is entitled to act on behalf of all member companies. Grant Thornton Consulting Kft. is also responsible for providing appropriate information to data subjects and for processing and responding to requests from public authorities to the member companies.
Where a link on this website takes users to external websites that are not directly linked to our company, we are not responsible for the data protection practices of those websites.
Information on the Controller
The Controller does not appoint a data protection officer.
Grant Thornton Consulting Kft.
Registered seat: 1134 Budapest, Dévai utca 26-28 (Dévai Center)
Mailing address: 1134 Budapest, Dévai utca 26-28 (Dévai Center)
Company registration number: 01-09-074993
E-mail: dataprivacy@hu.gt.com
Phone: +36 1 455 2000
Website: grantthorntonhungary.hu
The scope of personal data processed
Our website is does not transmit any personal data to us during your visit, unless you send us a request using one of our web forms. Such data is not transmitted to any third parties either for consideration or otherwise.
We reserve the right to transfer your data to our partners in the Grant Thornton International network if this is necessary to answer your query. Your personal data will only be stored for the period, necessary for the purpose for which it is transferred and for as long as is necessary to comply with this privacy statement and in accordance with the law.
Online offer
The Controller has created web forms in order to allow visitors to submit requests for proposals. The Controller processes the following data for the purpose of contacting and liaising with the visitors:
- personal name
- company name
- e-mail address
- phone number
Pursuant to Article 6 (1) b) of the GDPR, processing is lawful if necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
If no contract is concluded after the request was submitted, the data will be deleted within 1 year. If the contact data are also recorded in a contract concluded between the parties, the data will be kept for 8 years after the termination of the legal relationship, in accordance with the accounting rules on the retention of contracts.
Cookies
Our website uses Google Analytics, a web analytics service provided by Google Inc. (“Google”).
We recommend that you accept “cookies” to make full use of certain features of the website. A “cookie” is a small piece of text containing personalised information that is stored on the data subject’s computer by the data subject’s browser. The purpose of cookies is to help us recognise returning visitors, to implement customised visitor functions and to process user logins (identification, authentication).
The data processing is carried out for statistical purposes only, in order to enhance the user experience by using the website traffic data; the Controller stores the data as statistical data, they do not know any personal data. In transferring the data collected, Google applies the General Terms and Conditions for the transfer of personal data relating to online advertising and measurement outside Europe. To find out more about Google Analytics, please visit the following website: https://support.google.com/analytics#topic=3544906)
Newsletters
We only send newsletters with the express consent of the data subject. Subscribers are entitled to withdraw their consent without any adverse consequences by clicking on the “Unsubscribe from this list” link at the bottom of the newsletter or by sending an e-mail to hirlevel@hu.gt.com.
Access to the data
The personal data provided by the data subject may only be disclosed to the Controller’s executive officers and designated staff and, where necessary, to a data processor. The Controller stores the personal data provided by the data subject on servers located at the Controller’s headquarters, guarded by 24/7 security.
Rights related to data processing
The data subject may, at any time, request information in writing from the Controller in order to be informed by the Controller about the following:
- what personal data is processed,
- what is the purpose of data processing,
- what is the source of the data,
- for how long are the data kept,
- to whom, when, under what legal provisions, and to which personal data the Controller granted access or transferred the personal data.
The Controller shall comply with the data subject’s request within a maximum of 30 days by electronic letter sent to the contact details provided.
The data subject may, at any time, request in writing that the Controller modify any of their personal data. Controller shall grant the request within a maximum of 30 days and shall notify the data subject accordingly.
The data subject may request the erasure of their personal data in writing from the Controller. The Controller shall reject the erasure request if the law or an internal regulation obliges the Controller to continue to store the personal data. However, in the absence of such an obligation, the Controller shall comply with the data subject’s request within a maximum of 30 days and shall notify the data subject accordingly.
The data subject may request the blocking of their personal data in writing from the Controller, stating the reason. The blocking lasts for as long as the reason indicated by the data subject makes it necessary to store the data. In this case, the Controller will continue to store the personal data until the authority or court requests it, after which the data will be deleted.
The data subject shall have the right to receive personal data concerning them which they have provided to a Controller and the right to transmit such data to another Controller. Controller shall grant the request within a maximum of 30 days and shall notify the data subject accordingly.
The data subject may object in writing to the processing of personal data if the Controller would transfer or use the personal data for direct marketing, public opinion polls or scientific research. The data subject may not object to the Controller’s disclosure of their personal data to the authority in the course of an ongoing authority procedure.)
Right to legal action in courts
Data subjects may take legal action against the data controller in case their rights are violated. The court shall act in such cases in expedited proceedings.
Data protection authority procedure
Complaints may be submitted to National Authority for Data Protection and Freedom of Information-
Name: National Authority for Data Protection and Freedom of Information
Registered seat: 1125 Budapest, Szilágyi Erzsébet fasor 22/C.
Mailing address: 1530 Budapest, P.O. Box 5.
Phone: +36 1 391 1400
Fax: +36 1 391 1410
E-mail: ugyfelszolgalat@naih.hu
Website: www.naih.hu
Miscellaneous provisions
We provide information on other data controlling activities not listed here at the time when such data is recorded.
We hereby inform our clients that, on the basis of the authority of the courts, the prosecutor’s office, the investigating authority, other authorities proceeding in misdemeanour or criminal cases, administrative authorities, the National Authority for Data Protection and Freedom of Information (NAIH), the Central Bank of Hungary, as well as other bodies based on the authorisation of a relevant provision of law may contact the Controller with requests for information, transmission of data, as well as making available documents.
In such cases, Grant Thornton Consulting Kft. shall only provide or disclose such personal data and to the extent that is indispensable for achieving the purpose of the requests, provided that the authority identified the exact purpose and the scope of data requested.