Legal Notices

Privacy Notice

ALLODIAL CIVIL RIGHTS SOCIETY

1. Introduction

The Allodial Civil Rights Society(hereinafter: Controller or Association) is an organization performing human rights advocacy and protection. The Association is committed to protecting the personal data of its clients, website visitors, supporters, and partners, and considers the respect for the data subjects' right to information self-determination as highly important.

The purpose of this notice is to ensure that data subjects receive clear, comprehensible, and detailed information prior to the commencement of data processing regarding what personal data the Association processes, for what purposes, on what legal bases, and for how long, as well as what rights they have in connection with the data processing.

The Controller processes personal data in accordance with the following regulations:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR – General Data Protection Regulation);
  • Act CXII of 2011 on the Right to Information Self-Determination and on Freedom of Information (Infotv.);
  • Act V of 2013 on the Civil Code of Hungary (Ptk.);
  • Act CVIII of 2001 on certain issues of electronic commerce services and information society services (Ekertv.).

2. Data of the Controller

DescriptionData
Name of ControllerAllodial Civil Rights Society
RepresentativeBálint Fodor – administrator
Email addressallodialhumanrights@protonmail.com

3. Definitions

Personal data

Any information relating to an identified or identifiable natural person ('data subject') (e.g., name, email address, telephone number, IP address).

Special categories of data

Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic and biometric data, health data or data concerning a natural person's sex life or sexual orientation.

Processing

Any operation or set of operations performed on personal data (collection, recording, storage, use, transmission, erasure, etc.).

Controller

Who determines the purposes and means of the processing of personal data.

Processor

Who processes personal data on behalf of the controller (e.g., hosting provider).

Consent of the data subject

Any freely given, specific, informed and unambiguous indication of the data subject's wishes.

4. Specific Data Processing Operations

4.1Handling Advocacy and Legal Aid Inquiries

As part of its human rights defense activities, the Association accepts inquiries from persons who have suffered rights violations or seek legal assistance.

Processed Data

Name, contact details (email, phone, address), description of the case and documents attached thereto, as well as other data voluntarily provided by the data subject due to the nature of the case.

Purpose of Processing

Receiving, investigating the inquiry, providing legal information and advocacy assistance, and maintaining contact.

Legal Basis

Consent of the data subject (GDPR Article 6(1)(a)); in the case of a contract-like mandate, GDPR Article 6(1)(b); in the case of the establishment or defense of legal claims, legitimate interest pursuant to GDPR Article 6(1)(f).

Duration of Processing

5 years from the closure of the case (general limitation period under Hungarian law), or until consent is withdrawn.

Processing of Special Categories of Data: Due to the nature of advocacy activities, the case presented by the data subject may contain special categories of data (e.g., data on ethnic origin, health status, religious or philosophical beliefs). The Association processes these solely based on the data subject's explicit consent (GDPR Article 9(2)(a)), or for the establishment, exercise or defense of legal claims (GDPR Article 9(2)(f)), under strict confidentiality.

4.2Contact (Email, Webform, Phone)

Processed Data

Name, email address, telephone number (if provided), content of message.

Purpose of Processing

Answering inquiries, maintaining communication.

Legal Basis

Consent of the data subject (GDPR Article 6(1)(a)).

Duration of Processing

1 year following the resolution of the inquiry, or until consent is withdrawn.

4.3Newsletters and Informational Updates

Processed Data

Name, email address, timestamp of subscription.

Purpose of Processing

Sending updates about the Association's activities, events, and calls.

Legal Basis

Consent of the data subject (GDPR Article 6(1)(a)).

Duration of Processing

Until consent is withdrawn (unsubscribing); unsubscription is possible via link at the bottom of any newsletter or by contacting the Controller.

4.4Donations and Financial Support

Processed Data

Name, email address, bank account / transaction details, amount of donation.

Purpose of Processing

Receiving and recording donations, fulfilling accounting obligations, sending acknowledgments.

Legal Basis

Fulfillment of contract (GDPR Article 6(1)(b)) and compliance with legal obligation (GDPR Article 6(1)(c) - Section 169 of the Hungarian Accounting Act).

Duration of Processing

8 years for accounting documents.

4.5Membership and Volunteer Applications

Processed Data

Name, birth details, address, contact details, other details required for application.

Purpose of Processing

Establishing and maintaining membership/volunteer relationship, contact.

Legal Basis

Fulfillment of contract (GDPR Article 6(1)(b)), or compliance with legal obligation (membership record keeping pursuant to Act CLXXV of 2011 on Association Rights).

Duration of Processing

5 years following termination of the relationship.

4.6Website Technical Logging and Cookies

Technical Log Data:

During website visitation, the hosting provider's server may automatically record the visitor's IP address, time of visit, browser, and operating system type. The purpose of this processing is to operate the website securely and prevent abuses (legal basis: GDPR Article 6(1)(f) - legitimate interest). Retention time: 30 days.

Cookies:

The website uses cookies strictly necessary for core functionality. If statistical or marketing cookies (e.g. Google Analytics) are implemented, they are only deployed based on the visitor's prior explicit consent, which the visitor can adjust or withdraw at any time via cookie settings. Cookies can also be disabled or deleted in browser settings.

5. Data Processors, Data Transfers

The Controller may use data processors (particularly hosting providers, and accounting services) to perform processing operations. Data processors process personal data strictly under the Controller's instructions and cannot use them for their own purposes. Information about active data processors will be provided by the Controller upon request at the contact details shown in Section 2.

Data Transfers to Third Parties: The Controller transfers personal data to third parties strictly with the data subject's explicit consent, except for mandatory transfers prescribed by law (e.g. authority requests). In advocacy matters, transfers on behalf of the data subject towards authorities, courts, or other organs are performed exclusively with the subject's knowledge and authorization.

The Controller does not transfer personal data to third countries (outside the European Economic Area). If the Controller uses US services (e.g. Google, Meta) in the future, this section will be amended accordingly.

6. Data Security

The Controller ensures the security of processed data through appropriate technical and organizational measures, including in particular:

  • data can only be accessed by authorized persons bound by confidentiality;
  • electronically stored data are protected by password, paper-based documents are stored in closed locations;
  • highly sensitive data relating to advocacy cases are processed with enhanced confidentiality and separate storage;
  • the Controller protects data against unauthorized access, alteration, transfer, disclosure, erasure, or destruction.

Personal Data Breach: In the event of a personal data breach, the Controller acts in accordance with GDPR Articles 33–34: reports the breach to the supervisory authority without undue delay and at the latest within 72 hours, and – if it entails high risks – informs the affected data subjects.

7. Rights of the Data Subjects

The data subject is entitled to the following rights in connection with data processing, which they can exercise at the contact details shown in Section 2:

a

Right to information and access

(GDPR 15. cikk)

The data subject has the right to obtain confirmation as to whether or not personal data concerning them are being processed, and access to a copy of the processed data.

b

Right to rectification

(GDPR 16. cikk)

The data subject has the right to obtain the rectification of inaccurate personal data, and to have incomplete personal data completed.

c

Right to erasure ('right to be forgotten')

(GDPR 17. cikk)

The data subject has the right to obtain the erasure of personal data concerning them if the purpose of processing has ceased, consent is withdrawn, or processing is unlawful. (Not applicable if processing is necessary for compliance with a legal obligation or for the establishment of legal claims).

d

Right to restriction of processing

(GDPR 18. cikk)

The data subject has the right to obtain restriction of processing, for example, if they contest the accuracy of the personal data, or if processing is unlawful but they oppose erasure.

e

Right to data portability

(GDPR 20. cikk)

The data subject has the right to receive the personal data concerning them, which they have provided, in a structured, commonly used and machine-readable format.

f

Right to object

(GDPR 21. cikk)

The data subject has the right to object, on grounds relating to their particular situation, at any time to processing of personal data concerning them based on legitimate interests.

g

Right to withdraw consent

(GDPR 7. cikk (3))

The data subject has the right to withdraw their consent at any time; the withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

The Controller fulfills the request without undue delay and at the latest within one month of receipt, or provides grounds for rejection. If necessary, taking into account the complexity of the request, this period may be extended by two further months, of which the data subject will be notified.

8. Remedies and Enforcement

a

Complaint to the Controller

Please submit any complaint regarding data processing to the Controller first using the contacts in Section 2 – we will do our best to investigate and resolve it promptly.

b

Complaint to the Supervisory Authority

The data subject may file a complaint with the National Authority for Data Protection and Freedom of Information.

National Authority for Data Protection and Freedom of Information (NAIH)

HQ: 1055 Budapest, Falk Miksa utca 9–11.

Postal: 1363 Budapest, Pf. 9.

Phone: +36 (1) 391-1400

E-mail: ugyfelszolgalat@naih.hu

Website: www.naih.hu

c

Judicial Enforcement

In case of rights infringement, the data subject may file a claim in court. Per local laws, the claim is heard before regional courts (Törvényszék); the data subject can choose to bring the claim before the regional court of their domicile or residence.

9. Amendments to the Privacy Notice

The Controller reserves the right to amend this notice unilaterally (due to changes in regulations or processing practices). The current notice is always available on the website. In case of significant amendments, the Controller will notify subjects via a prominent callout on the website.

Allodial Civil Rights Society

Represented by: Bálint Fodor, administrator