Services

ENG

Privacy Policy

RGM Solution Consulting Limited Liability Company

1. Introduction, legal background, details and contact information of the Data Controller

RGM Solution Tanácsadó Kft. (1138 Budapest, Madarász Viktor utca 47-49. 1. lház. 7. em. 701. ajtó., tax number: 32254473-2-41, Company Registration Number: 01-09-415605, https://rgmsolution.hu/, hereinafter referred to as RGM Solution Kft., Service Provider, Data Controller), as Data Controller, recognizes the content of this legal notice as binding upon itself.
The purpose of this notice is to record the data protection and data processing principles applied by RGM Solution Kft. and the Company's data protection and data processing policy.
RGM Solution Kft. undertakes that all data processing related to its activities meets the expectations set forth in this notice and in the applicable legislation.
RGM Solution Kft. is committed to protecting the personal data of its clients and partners, and considers it of paramount importance to respect its clients' right to informational self-determination. RGM Solution Kft. treats personal data confidentially and takes all security, technical, and organizational measures that guarantee the security of the data.
The content of the RGM Solution Kft. website is protected by copyright, so any of its visual or textual elements may only be used with the prior written permission of the owner. This also applies to the Privacy Policies published on the site. RGM Solution Kft. accepts no liability for any potential damage resulting from visiting the website.

Legal background:

In this notice and during data processing, we act in accordance with the relevant applicable legislation, with particular regard to the following:
-      Regulation (EU) 2016/679 of the European Parliament and of the Council (April 27, 2016) – on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Regulation (EC) No 95/46 (General Data Protection Regulation, GDPR);
-         Act CXII of 2011 on the Right to Informational Self-Determination and on Freedom of Information (Infotv.),
-        Act CVIII of 2001 on certain issues of electronic commerce services and information society services (Eker tv.).

Data Controller's details, contact information:

Name: RGM Solution Tanácsadó Korlátolt Felelősségű Társaság
Representative: István Béla Nagy, Managing Director
Address: 1138 Budapest, Madarász Viktor utca 47-49. Bldg. 1, Fl. 7, Door 701
Company Registration Number: 01-09-415605
Tax Number: 32254473-2-41
Contact Person: Martin Nagy, Managing Director
Contact Person's Mobile Number, E-mail Address: +36 70 933 3713, nagymartin@rgmsolution.hu

2. Definitions

Data subject: any natural person who is identified or - directly or indirectly - identifiable on the basis of specific personal data;

Personal data: any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

Processing: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;

Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;

Data processing operations: the performance of technical tasks related to data processing operations, regardless of the method and instrument used to perform the operations and the place of application, provided that the technical task is performed on the data;

Consent of the data subject: any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;

Personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed;

Disclosure: making data accessible to anyone;

Erasure of data: making data unrecognizable in such a way that its recovery is no longer possible;

3. Principles of data processing

RGM Solution Kft. outlines its data processing principles below, presenting the requirements it has established for itself as a data controller and strictly adheres to.

Principles of Data Processing

The fundamental principles of processing personal data are defined by the GDPR and the Hungarian Info Act (Infotv.), according to which the following principles apply during data processing:

According to the principle of lawfulness, fairness, and transparency, personal data must be processed lawfully, fairly, and in a transparent manner for the data subject;

According to the principle of purpose limitation, personal data must be collected only for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes; in accordance with Article 89(1) of the GDPR, further processing for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes shall not be considered incompatible with the initial purposes;

According to the principle of data minimisation, the processed personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed;

According to the principle of accuracy, personal data must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay;

According to the principle of storage limitation, personal data must be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject;

According to the principle of integrity and confidentiality, personal data must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organisational measures.

According to the principle of accountability, the Data Controller is responsible for, and must be able to demonstrate compliance with, the principles outlined above.

The Data Controller takes all reasonable measures to ensure that the personal data it processes complies with the above principles and the applicable legislation, and remains inaccessible to unauthorized persons. The data processing notices are publicly available on the Data Controller's website.

4. Scope of data subjects

The data subjects involved in the data processing are the persons visiting the Website operated by the Data Controller, those sending messages on the Website via the Contact menu, those applying for job advertisements published on the Website, those interested in the Data Controller's services through the Website, and those liking the Facebook profile through the Website.

5. Type of processed data, purpose, legal basis, and duration of data processing

We would like to draw the attention of data providers to the fact that if they do not provide their own personal data, it is the duty of the data provider to obtain the consent of the data subject.

 

Scope of processed data

Name of data

Purpose of data processing

Legal basis of data processing

Duration

Data of website visitors

date, time, IP address of the user's computer, address of the visited page, address of the previously visited page, data related to the user's operating system and browser

ensuring the proper and high-quality functioning of the website, monitoring and improving the quality of our services, identifying malicious visitors attacking our website, measuring traffic, statistical purposes

the data controller has a legitimate interest in identifying users and preventing abuse [GDPR Article 6(1)(f)], and Section 13/A (3) of the Eker. tv..

30 days from viewing the website

Sending a message in the Contact menu

last name, first name, company name, phone number, email address, date and time, text of the message

initiating contact, keeping in touch

consent of the data subject [GDPR Article 6(1)(a)]

until the consent of the data subject is withdrawn, but for a maximum of 2 years from the date of contacting

6. Data processors engaged

The data processor's rights and obligations regarding the processing of personal data are determined by the Data Controller within the framework of the law. The Data Controller is responsible for the legality of the instructions given by them. The data processor may not make any substantive decisions regarding the data processing, may process the personal data of which they become aware solely in accordance with the provisions of the Data Controller, may not perform data processing for their own purposes, and is obliged to store and preserve the personal data in accordance with the provisions of the Data Controller.

Hosting provider
Name and contact details of the data processor:
Company name:
Postal address:
Registered office address:
Tax number:
Website:
Privacy policy:

Receiving and sending emails:
Activity performed by the data processor: email communication and file sharing
Name of the data processor: Google Ireland Limited
Address: Gordon House Barrow Street Dublin 4 Ireland
Contact details: https://cloud.google.com

7. Method of storing personal data, security of data processing

RGM Solution Kft. and its data processors, taking into account the state of the art and the costs of implementation, as well as the nature, scope, context and purposes of processing and the risk of varying likelihood and severity for the rights and freedoms of natural persons, shall implement appropriate technical and organisational measures to ensure a level of data security appropriate to the risk.

RGM Solution Kft. selects and operates the IT tools used to provide the service for the processing of personal data in such a way that the processed data:

- is accessible to those authorized to access it (availability);
- its authenticity and verification are ensured (authenticity of data processing);
- its integrity can be verified (data integrity);
- is protected against unauthorized access (data confidentiality).

RGM Solution Kft. protects the data by means of appropriate measures, in particular against unauthorized access, alteration, transmission, disclosure, deletion or destruction, as well as against accidental destruction, damage and becoming inaccessible due to changes in the technology used.

In order to protect the data files processed electronically in its various registers, RGM Solution Kft. ensures by means of an appropriate technical solution that the stored data cannot be directly linked and assigned to the data subject, unless permitted by law.

Taking into account the current state of technology, RGM Solution Kft. ensures the protection of the security of data processing through technical, organizational and structural measures that provide a level of protection appropriate to the risks associated with data processing.

During data processing, RGM Solution Kft. preserves

a) confidentiality: protects the information so that only those authorized can access it;
b) integrity: protects the accuracy and completeness of the information and the processing method;
c) availability: ensures that when the authorized user needs it, they can actually access the requested information, and that the related tools are available.

The IT systems and networks of RGM Solution Kft. and its partners are protected against computer-aided fraud, espionage, sabotage, vandalism, fire and flood, as well as computer viruses, hacking and denial-of-service attacks. The operator ensures security through server-level and application-level protection procedures.

8. Rights of data subjects regarding data processing, remedies

The data subject's fundamental right is the right to information, which the Data Controller ensures for its clients through the privacy policy placed on the homepage of the website it operates. The data subject is entitled to request information from the Data Controller, which the Data Controller shall answer in writing within 30 days.

The data subject has the right of access, under which they are entitled to obtain feedback from the Data Controller as to whether their personal data is being processed, and if so, what the purpose of the data processing is, which of their data is processed, and to which recipient(s) it has been disclosed, and for how long it is planned to be processed. Furthermore, they may initiate the rectification, erasure, or restriction of processing of their personal data, and may object to the processing of their personal data. The data subject also has the right to lodge a complaint with a supervisory authority.

By virtue of the right to rectification, the data subject has the right to obtain from the Data Controller without undue delay the rectification of inaccurate personal data concerning him or her, and may request that incomplete personal data be completed.

The data subject has the right to erasure ('right to be forgotten'), which means that personal data must be erased if:
-        the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
-        the data subject withdraws consent on which the processing is based, and where there is no other legal ground for the processing;
-        the data subject objects to the processing and there are no overriding legitimate grounds for the processing, or the data subject objects to the processing pursuant to Article 21(2) of the Regulation;
-        the personal data have been unlawfully processed;
-        the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;
-        the personal data have been collected in relation to the offer of information society services referred to directly to children.

Based on the right to be forgotten, the data subject is entitled to obtain from the Data Controller the erasure of personal data concerning him or her upon request. The Data Controller is obliged to erase personal data concerning the data subject without undue delay if:
-        the personal data are no longer necessary;
-        the data subject objects to the processing;
-        the data subject withdraws consent;
-        the personal data have been unlawfully processed; 

Under the right to restriction of processing, data may only be stored, and other processing is only possible with the data subject's consent or for the establishment, exercise, or defense of legal claims. The data subject has the right to obtain from the Data Controller restriction of processing if:
-        the accuracy of the personal data is contested by the data subject;
-        the Data Controller no longer needs the personal data, but they are required by the data subject for the establishment, exercise, or defense of legal claims;
-        the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;

Data subjects may exercise their rights by sending a written request to the Data Controller
-        postal address: 1138 Budapest, Madarász Viktor utca 47-49. 1. lház. 7. em. 701. ajtó. or to the
-        Data Controller's e-mail address: info@rgmsolution.hu.
 

Informing the data subject about a personal data breach

When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.

The communication to the data subject shall describe in clear and plain language the nature of the personal data breach and contain the name and contact details of the data protection officer or other contact point where more information can be obtained; describe the likely consequences of the personal data breach; describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.

The communication to the data subject shall not be required if any of the following conditions are met:
-        the controller has implemented appropriate technical and organizational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorized to access it, such as encryption;
-        the controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects is no longer likely to materialize;
-        it would involve disproportionate effort. In such a case, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.

If the controller has not already communicated the personal data breach to the data subject, the supervisory authority, having considered the likelihood of the personal data breach resulting in a high risk, may require it to do so.

 

Legal remedies:

The data subject is entitled to initiate proceedings with the National Authority for Data Protection and Freedom of Information (NAIH) if an infringement has occurred or there is an imminent danger of an infringement in connection with the processing of personal data.

Contact details of the Authority:
Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c.
Postal address: 1530 Budapest, Pf.: 5.,
Phone: +36 (1) 391-1400,
E-mail: ugyfelszolgalat@naih.hu,
Website: http://naih.hu

In the event of an infringement of their rights, the data subject may file a lawsuit against the Data Controller in court. The adjudication of the lawsuit falls within the jurisdiction of the regional court (törvényszék). The lawsuit may also be brought, at the data subject's choice, before the regional court of their place of residence or stay. A person who otherwise lacks legal capacity to sue may also be a party to the lawsuit. The Authority may intervene in the lawsuit on behalf of the data subject to assist them in winning the case.

Phone number:

Opening hours:

Mon-Fri: 08:00-17:00

Copyright © 2026 RGM Solution Kft. – All rights reserved

Privacy policy

Phone number:

Opening hours:

Mon-Fri: 08:00-17:00

Copyright © 2026 RGM Solution Kft. – All rights reserved

Privacy policy

Phone number:

Opening hours:

Mon-Fri: 08:00-17:00

Copyright © 2026 RGM Solution Kft. – All rights reserved

Privacy policy