About us Let's talk
About us Let's talk

Legal

Privacy Policy

Advantek Laboratories Kft. (Advantek Laboratories Korlátolt Felelősségű Társaság) · 1119 Budapest, Fehérvári út 97-99., Hungary · Effective from 7 July 2026

Olvassa el magyarul (Hungarian original) →

This page is an English-language translation of Advantek's Hungarian-language data protection notice ("Adatkezelési tájékoztató"), provided as a courtesy for our English-speaking visitors, clients, and partners. In the event of any discrepancy or conflict between this translation and the Hungarian original, the Hungarian original governs. You can read it in full here: Adatkezelési tájékoztató.

Introduction

Advantek Laboratories Korlátolt Felelősségű Társaság (registered seat: 1119 Budapest, Fehérvári út 97-99., Hungary; company registration number: 01 09 453038; tax number: 32786075-2-43; represented by Dávid Nagy, Managing Director) — referred to below as the "Controller" — is committed to protecting personal data. The Controller regards the content of this notice as binding on itself and undertakes that all data processing connected with its activities complies with this notice, with applicable Hungarian law, and with the legal acts of the European Union — in particular Regulation (EU) 2016/679 of the European Parliament and of the Council (the "GDPR").

The Controller's data processing principles are aligned with the applicable Hungarian data protection legislation, in particular:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation);
  • Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information;
  • Act V of 2013 on the Civil Code;
  • Act C of 2000 on Accounting;
  • Act CLV of 1997 on Consumer Protection;
  • Act LIII of 2017 on the Prevention and Combating of Money Laundering and Terrorist Financing.

This document informs, in accordance with European Union and Hungarian law, persons who are in an engagement (mandate) relationship with the Controller about the processing of their personal data and their related rights, as well as visitors to and users of the Controller's website and contact channels.

Data Controller

The Controller carries out the processing of its clients' data itself.

Name
Advantek Laboratories Korlátolt Felelősségű Társaság
Registered seat
1119 Budapest, Fehérvári út 97-99., Hungary
Postal address
1119 Budapest, Fehérvári út 97-99., Hungary
Company registration no.
01 09 453038
Tax number
32786075-2-43
Electronic official contact
Company Gateway (Cégkapu) — 32786075
Email
david@advanteklabs.com
Phone
+36 70 779 0131
Data Protection Officer
None appointed
Legal representative
Dávid Nagy, Managing Director

Scope of Data Processed, Purpose, Legal Basis, and Duration

The data processing carried out in connection with the Controller's activities is based on voluntary consent, on a contract, or on statutory authorization. The Controller requests data only for the purposes listed below and only to the extent necessary to achieve them, and such requests only exceptionally concern data that qualifies as personal data. Where processing is based on voluntary consent, data subjects may withdraw their consent at any stage of the processing. In certain cases, the retention, storage, or transfer of a given set of data is mandated by law, of which data subjects are informed separately.

We draw the attention of anyone providing data to the fact that if they provide personal data other than their own, it is their responsibility to obtain the consent of the data subject concerned. In relation to the processing described in this notice, persons under 16 years of age may not provide personal data about themselves, except where their legal guardian has consented to this.

1. Processing of personal data provided before the conclusion of an engagement agreement

Scope of data
Personal data made available by the client to the Controller which comes to the Controller's knowledge before the engagement (mandate) agreement is concluded
Legal basis
GDPR Article 6(1)(b) — performance of a contract
Purpose
Concluding and performing the engagement agreement
Duration
If the engagement does not materialize, the data is deleted 3 months after the inquiry. If the engagement is concluded, the retention period is as set out under "2." below.
Data transfer
None
Processor
Google Ireland Limited; HubSpot Ireland Limited
Method of provision
Voluntary, for the purpose of establishing and maintaining the engagement relationship

2. Processing related to the performance of engagements

Scope of data
Personal data of natural persons, or of representatives of legal persons, processed in connection with the performance of a specific engagement, together with any personal data handed over in relation to the matter, or which otherwise comes into the Controller's possession, as necessary for performance
Legal basis
GDPR Article 6(1)(b) — performance of a contract
Purpose
Performing the engagement received
Duration
5 years from termination of the engagement, or from settlement of the invoice issued for it (until expiry of the limitation period)
Data transfer
None
Processor
Google Ireland Limited; Billingo Technologies Zrt.
Method of provision
Voluntary, for the purpose of establishing and maintaining the engagement relationship

3. Processing of data submitted through contact on www.advanteklabs.com

Scope of data
Surname, first name, email address (optionally: phone number)
Legal basis
Voluntary consent of the data subject (GDPR Article 6(1)(a))
Purpose
Responding to inquiries submitted through the contact form on the "Contact" section of www.advanteklabs.com
Duration
Retained for up to 1 year from the change of the contact person
Data transfer
No transfer to third parties
Processor
Google Ireland Limited; HubSpot Ireland Limited
Method of provision
Voluntary

4. Processing related to contracts concluded with business partners

Scope of data
Surname, first name, phone number, and email address
Legal basis
GDPR Article 6(1)(f) — legitimate interest of the Controller and of the data subject's employer
Purpose
Performance of the contract
Duration
Retained for up to 1 year from the change of the contact person
Data transfer
No transfer to third parties
Processor
Google Ireland Limited; Billingo Technologies Zrt.
Method of provision
Data provided at the time the contract is concluded

Other processing

For any processing not listed in this notice, information is provided at the time the data is collected. Courts, prosecutors, investigative authorities, misdemeanor authorities, administrative authorities, the National Authority for Data Protection and Freedom of Information (NAIH), or other bodies authorized by law may approach the Controller to request information, disclosure of data, or the provision of documents. The Controller discloses personal data to such authorities — provided the authority has specified the exact purpose and scope of the request — only to the extent and only insofar as strictly necessary to achieve the stated purpose of the request.

Data Processors

Name
Google Ireland Limited
Registered seat
Gordon House, Barrow Street, Dublin 4, Ireland
Tax number
IE 6388047V
Processing task
Hosting and email services
Name
Billingo Technologies Zrt.
Registered seat
1133 Budapest, Árbóc utca 6., 1st floor, Hungary
Tax number
27926309-2-41
Processing task
Invoicing services
Name
HubSpot Ireland Limited
Registered seat
HubSpot House, 1 Sir John Rogerson's Quay, Dublin 2, Ireland
Tax number
IE 9849471F
Processing task
Customer relationship management

The Controller reserves the right to engage additional processors, and will give individual notice of their identity no later than the commencement of the relevant processing.

Storage of Personal Data and Security of Processing

  • The Controller's IT systems and other data storage locations are located at the registered seat of its processor(s).
  • The Controller selects and operates the IT tools used to provide its services so that the processed data is accessible to those authorized to access it, its authenticity and certification are ensured, its unchanged state can be verified, and it is protected against unauthorized access.
  • The Controller protects the data it processes, with appropriate measures, in particular against unauthorized access, alteration, transmission, disclosure, deletion, or destruction, as well as against accidental destruction or damage, and against inaccessibility resulting from changes in the technology applied.
  • With respect to the data it processes, the Controller uses appropriate technical means to ensure that stored data cannot be directly linked to, or associated with, the data subject, except where the law permits this.
  • Having regard to the current state of the art, the Controller implements technical, organizational, and administrative measures that provide a level of protection commensurate with the risks associated with the processing.

In the course of processing, the Controller preserves:

  • Confidentiality: it protects the data against unauthorized access.
  • Integrity: it ensures the accuracy and completeness of the information and of the processing method.
  • Availability: it ensures that, when an authorized user needs it, the desired information is accessible and the tools necessary for this are available.

Rights of Data Subjects and Remedies

Data subjects may request information about the processing of their personal data, may request the rectification of their personal data, or — except for mandatory processing — its erasure or the withdrawal of consent, may exercise their right to data portability and their right to object in the manner indicated when the data was collected, or through the Controller's contact details set out above.

Right to information

The Controller takes appropriate measures to provide data subjects with all information referred to in Articles 13 and 14 of the GDPR concerning the processing of personal data, and with any communication under Articles 15–22 and Article 34, in a concise, transparent, intelligible, and easily accessible form, using clear and plain language.

The right to information may be exercised in writing, through the contact details set out in the "Data Controller" section of this notice. At the data subject's request, information may also be provided orally, once their identity has been verified.

Right of access

Data subjects have the right to obtain confirmation from the Controller as to whether their personal data is being processed, and, if so, to be granted access to the personal data and to the following information:

  • the purposes and legal basis of the processing;
  • the categories of personal data concerned;
  • the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organizations;
  • the envisaged period for which the personal data will be stored;
  • the right to request rectification, erasure, or restriction of processing, and the right to object, as well as the right to data portability;
  • the right to lodge a complaint with a supervisory authority;
  • information about the source of the data;
  • the existence of automated decision-making, including profiling, and meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the data subject.

Where personal data is transferred to a third country or to an international organization, the data subject has the right to be informed of the appropriate safeguards relating to the transfer.

The Controller provides the data subject with a copy of the personal data undergoing processing. For any further copies requested, the Controller may charge a reasonable fee based on administrative costs. At the data subject's request, information is provided electronically. The Controller provides this information within one month at the latest, from the submission of the request.

Right to rectification

Data subjects may request the rectification of inaccurate personal data concerning them held by the Controller, and the completion of incomplete data.

Right to erasure

Data subjects have the right to obtain, without undue delay, the erasure of personal data concerning them by the Controller, upon request, where one of the following grounds applies:

  • the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
  • the data subject withdraws the consent on which the processing is based, and there is no other legal basis for the processing;
  • the data subject objects to the processing and there are no overriding legitimate grounds for it;
  • the personal data have been unlawfully processed;
  • the personal data must be erased for compliance with a legal obligation under Union or Hungarian law to which the Controller is subject;
  • the personal data were collected in connection with the offer of information society services.

Erasure may not be requested where the processing is necessary:

  • for exercising the right of freedom of expression and information;
  • for compliance with a legal obligation under Union or Hungarian law to which the Controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;
  • for reasons of public interest in the area of public health, or for archiving, scientific or historical research, or statistical purposes based on public interest; or
  • for the establishment, exercise, or defense of legal claims.

The Controller deletes the data subject's data from its records within 5 (five) business days of receiving the erasure request. Written erasure requests are accepted by the Controller at data.protection@advanteklabs.com.

Right to restriction of processing

At the data subject's request, the Controller restricts processing where one of the following applies:

  • the data subject contests the accuracy of the personal data, for a period enabling the Controller to verify its accuracy;
  • the processing is unlawful and the data subject opposes erasure and requests the restriction of use instead;
  • the Controller no longer needs the personal data for the purposes of processing, but the data subject requires them for the establishment, exercise, or defense of legal claims; or
  • the data subject has objected to the processing, pending verification of whether the Controller's legitimate grounds override those of the data subject.

Where processing has been restricted, such personal data may, with the exception of storage, only be processed with the data subject's consent, or for the establishment, exercise, or defense of legal claims, for the protection of the rights of another natural or legal person, or for important public interest reasons of the Union or a Member State.

The Controller informs the data subject in advance before lifting the restriction on processing.

Right to data portability

Data subjects have the right to receive the personal data concerning them that they have provided to the Controller in a structured, commonly used, machine-readable format, and to transmit those data to another controller.

Right to object

Data subjects have the right to object, on grounds relating to their particular situation, at any time to the processing of their personal data carried out for the performance of a task in the public interest or in the exercise of official authority vested in the Controller, or which is necessary for the purposes of the legitimate interests pursued by the Controller or a third party, including profiling based on those provisions, as well as to processing carried out for direct marketing purposes. Following an objection, the Controller may no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or which relate to the establishment, exercise, or defense of legal claims.

Automated individual decision-making, including profiling

Data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. This right does not apply where the processing is:

  • necessary for entering into, or the performance of, a contract between the data subject and the Controller;
  • authorized by Union or Hungarian law to which the Controller is subject, and which also lays down suitable measures to safeguard the data subject's rights, freedoms, and legitimate interests; or
  • based on the data subject's explicit consent.

Right to withdraw consent

Data subjects have the right to withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Procedural rules

The Controller informs the data subject, without undue delay and in any event within one month of receipt of the request, of the actions taken on a request under Articles 15–22 of the GDPR. That period may be extended by a further two months where necessary, taking into account the complexity and number of requests.

The Controller informs the data subject of any such extension, together with the reasons for the delay, within one month of receipt of the request. Where the data subject made the request electronically, information is provided electronically, unless otherwise requested.

If the Controller does not take action on the data subject's request, it informs the data subject without delay, and at the latest within one month of receipt of the request, of the reasons for not taking action, and of the possibility to lodge a complaint with a supervisory authority and to seek a judicial remedy.

The Controller provides the requested information and communication free of charge. If the data subject's request is manifestly unfounded or excessive, in particular because of its repetitive character, the Controller may charge a reasonable fee, taking into account the administrative costs of providing the requested information or communication or taking the requested action, or may refuse to act on the request.

The Controller informs each recipient to whom personal data have been disclosed of any rectification, erasure, or restriction of processing, unless this proves impossible or involves disproportionate effort. The Controller informs the data subject about those recipients if the data subject requests this.

Compensation and damages

Any person who has suffered material or non-material damage as a result of an infringement of data protection law is entitled to compensation from the Controller or the processor for the damage suffered. A processor is liable for damage caused by processing only where it has not complied with the obligations specifically directed to processors under the law, or where it has acted outside, or contrary to, the lawful instructions of the Controller.

Where more than one controller or processor, or both a controller and a processor, are involved in the same processing and are responsible for damage caused by it, each controller or processor is held liable for the entire damage, on a joint and several basis.

The Controller or the processor is exempt from liability if it proves that it is not in any way responsible for the event giving rise to the damage.

Right to a judicial remedy

In the event of an infringement of their rights, data subjects may bring proceedings against the Controller before a court. The court deals with the case as a priority.

Supervisory Authority Procedure

Complaints and requests for a remedy may be submitted to the National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság — NAIH):

Name
National Authority for Data Protection and Freedom of Information (NAIH)
Registered seat
1125 Budapest, Szilágyi Erzsébet fasor 22/C., Hungary
Postal address
1530 Budapest, Pf.: 5., Hungary
Phone
+36 1 391 1400
Fax
+36 1 391 1410
Email
ugyfelszolgalat@naih.hu
Website
naih.hu

Amendment of this Privacy Policy

The Controller reserves the right to unilaterally amend this Privacy Policy, subject to appropriate publication of the amended text.

Budapest, 7 July 2026.

© 2026 Advantek. All rights reserved.