Privacy Policy & Data Protection Statement
DOPAMA Informatikai Kft. (hereinafter: Service Provider or Data Controller) considers the protection of the personal data of its clients, partners, and website visitors to be of utmost importance. We are committed to processing personal data in full compliance with the European and Hungarian regulations in force, specifically Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation or GDPR) and Act CXII of 2011 on the Right to Informational Self-Determination and on Freedom of Information (Infotv.).
IMPORTANT DISTINCTION:
DOPAMA Kft., as a professional IT service provider, acts as a **Data Controller** for the data processing activities carried out through its website (dopama.hu). However, during the system administration and IT infrastructure services provided to its business clients, it acts as a **Data Processor** with respect to the personal data hosted on the clients' networks. This statement governs only the data processing activities where DOPAMA Kft. acts as a Data Controller.
1. Details of the Data Controller
The operator of this website and controller of your personal data is:
| Official Company Name: | DOPAMA Informatikai Korlátolt Felelősségű Társaság (Dopama Kft.) |
| Head Office: | 45 Döbrőce utca, Budapest 1163, Hungary |
| Company Registration No: | 01-09-197639 (registered by the Court of Registration of the Budapest Metropolitan Court) |
| Tax Number: | HU25064115 |
| Managing Director: | Zsolt Dósa |
| Data Protection Reg. No: | NAIH-81892/2014 |
| Email address: | info@dopama.hu |
| Phone numbers: | +36 30 960 0292 (Mobile) / +36 1 700 4463 (Landline) |
2. Principles of Data Processing
We adhere to the following principles during data processing:
- Lawfulness, fairness, and transparency: Data is processed lawfully, fairly, and in a transparent manner in relation to the data subject.
- Purpose limitation: Personal data is collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
- Data minimisation: Personal data is adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.
- Accuracy: Reasonable steps are taken to ensure that personal data that are inaccurate are erased or rectified without delay.
- Storage limitation: Personal data is kept in a form which permits identification of data subjects for no longer than is necessary for the purposes.
- Integrity and confidentiality: Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.
3. Specific Data Processing Activities
3.1. General Inquiries and Quote Requests via the Website
Visitors can submit request forms or email the Service Provider to ask for consultations, services, or quotes.
- Scope of processed data: Name, company name (optional), email address, telephone number (if provided), custom message content, and captcha validation response.
- Purpose of processing: Replying to user requests, preparing customized IT service quotes, and corporate communication.
- Legal basis: Consent of the data subject (GDPR Article 6(1)(a)), or taking steps at the request of the data subject prior to entering into a contract (GDPR Article 6(1)(b)).
- Retention period: If a contract is signed, data is kept for 5 years after the termination of the contract (statute of limitations under civil law). If no contract is concluded, we delete all related information within 1 year from the last correspondence or quote expiration.
3.2. Newsletter and Professional Updates
We occasionally send security bulletins, IT advisory papers, and company updates to subscribed users.
- Scope of processed data: Name, email address.
- Purpose of processing: Sharing IT news, security alerts, and promotional material (educational and marketing purposes).
- Legal basis: Explicit consent of the subscriber (GDPR Article 6(1)(a)).
- Retention period: Until consent is withdrawn (by clicking the unsubscribe link). Once unsubscribed, data is permanently erased from the newsletter list.
3.3. Server Logs and Technical Logs
Our server automatically logs visits to ensure website security and resolve technical errors.
- Scope of processed data: IP address of the visitor, timestamp of access, pages accessed, referral link, browser type, and operating system.
- Purpose of processing: Safeguarding the website against cyberattacks (like DDoS or brute force attempts), troubleshooting, and infrastructure stability.
- Legal basis: Legitimate interest of the Data Controller to operate a secure and reliable website (GDPR Article 6(1)(f)).
- Retention period: Server logs are deleted automatically after a maximum of 30 days.
4. Use of Cookies
To improve user experience, measure traffic analytics, and support website functionality, we use cookies (small text files saved on your computer or device). We categorize cookies as follows:
- Necessary (Technical) Cookies: Required for the essential operation of the website, page navigation, and basic security. The site cannot function properly without these. Legal basis: Legitimate interest (GDPR Article 6(1)(f)).
- Statistical / Analytical Cookies: Help us analyze how visitors interact with our pages (e.g. Google Analytics). The collected data is aggregated and anonymized. Legal basis: Consent (GDPR Article 6(1)(a)).
You can adjust your browser settings at any time to block or delete cookies. Consult your browser's Help menu for instructions.
5. Data Processors and Transfers
We only work with trusted partners who guarantee GDPR compliance and employ state-of-the-art information security protocols.
| Processor Name | Registered Address | Activity Performed |
|---|---|---|
| DOPAMA Informatikai Kft. (Internal systems) | 45 Döbrőce utca, Budapest 1163, Hungary | Web hosting, email servers, and primary storage of business records. |
| Google Ireland Limited (Google Analytics) | Gordon House, Barrow Street, Dublin 4, Ireland | Web analytics and user behavior statistics. |
We do not transmit personal data to third countries outside the European Economic Area (EEA). In the case of Google Analytics, data is anonymized, and operations are safeguarded by Standard Contractual Clauses (SCC) provided by Google.
6. Data Security Measures
As a professional IT firm, DOPAMA Kft. implements high-level physical and logical security measures:
- All communication between your browser and our website, including form inputs, is protected by **SSL/TLS (HTTPS) encryption**.
- Our servers are protected by active firewalls, intrusion detection systems, malware prevention, and regular security patches.
- We execute secure, encrypted **data backups** stored on redundant media in secure physical facilities.
- Access to personal data is restricted to authorized personnel of DOPAMA Kft. who are bound by strict professional confidentiality agreements.
7. Rights of the Data Subjects
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access (GDPR Article 15): Find out if we are processing your personal data, and if so, request a copy of the data.
- Right to Rectification (GDPR Article 16): Request correction of inaccurate or incomplete personal data.
- Right to Erasure / "Right to be Forgotten" (GDPR Article 17): Request deletion of your data when consent is withdrawn, purpose has ended, or processing is unlawful.
- Right to Restriction (GDPR Article 18): Ask to lock processing of data under certain disputes (e.g. while verifying accuracy).
- Right to Data Portability (GDPR Article 20): Receive your data in a structured, machine-readable format or request direct transfer to another controller.
- Right to Object (GDPR Article 21): Object to data processing based on legitimate interest.
- Right to Withdraw Consent: Withdraw your consent at any time without affecting the lawfulness of processing before the withdrawal.
To exercise any of these rights, contact us at info@dopama.hu. We will reply to your request within 30 days.
8. Legal Remedies
If you believe that your data protection rights have been violated by DOPAMA Kft., you have the following recourses:
- Contact us: We request that you first send your complaint to info@dopama.hu so we can resolve any issues directly and amicably.
- Regulatory Authority: File a formal complaint with the authority in Hungary:
National Authority for Data Protection and Freedom of Information (NAIH)
Address: 9-11 Falk Miksa utca, Budapest 1055, Hungary
Mailing Address: H-1363 Budapest, Pf. 9.
Email: ugyfelszolgalat@naih.hu
Website: www.naih.hu - Court Action: Bring a claim in court. You can initiate proceedings in the court of your place of residence or habitual residence. In Hungary, regional courts (törvényszék) have jurisdiction.