This page is an English-language translation of Advantek's Hungarian-language data protection notice ("Adatkezelési tájékoztató"), provided as a courtesy for our English-speaking visitors, clients, and partners. In the event of any discrepancy or conflict between this translation and the Hungarian original, the Hungarian original governs. You can read it in full here: Adatkezelési tájékoztató.
Advantek Laboratories Korlátolt Felelősségű Társaság (registered seat: 1119 Budapest, Fehérvári út 97-99., Hungary; company registration number: 01 09 453038; tax number: 32786075-2-43; represented by Dávid Nagy, Managing Director) — referred to below as the "Controller" — is committed to protecting personal data. The Controller regards the content of this notice as binding on itself and undertakes that all data processing connected with its activities complies with this notice, with applicable Hungarian law, and with the legal acts of the European Union — in particular Regulation (EU) 2016/679 of the European Parliament and of the Council (the "GDPR").
The Controller's data processing principles are aligned with the applicable Hungarian data protection legislation, in particular:
This document informs, in accordance with European Union and Hungarian law, persons who are in an engagement (mandate) relationship with the Controller about the processing of their personal data and their related rights, as well as visitors to and users of the Controller's website and contact channels.
The Controller carries out the processing of its clients' data itself.
The data processing carried out in connection with the Controller's activities is based on voluntary consent, on a contract, or on statutory authorization. The Controller requests data only for the purposes listed below and only to the extent necessary to achieve them, and such requests only exceptionally concern data that qualifies as personal data. Where processing is based on voluntary consent, data subjects may withdraw their consent at any stage of the processing. In certain cases, the retention, storage, or transfer of a given set of data is mandated by law, of which data subjects are informed separately.
We draw the attention of anyone providing data to the fact that if they provide personal data other than their own, it is their responsibility to obtain the consent of the data subject concerned. In relation to the processing described in this notice, persons under 16 years of age may not provide personal data about themselves, except where their legal guardian has consented to this.
For any processing not listed in this notice, information is provided at the time the data is collected. Courts, prosecutors, investigative authorities, misdemeanor authorities, administrative authorities, the National Authority for Data Protection and Freedom of Information (NAIH), or other bodies authorized by law may approach the Controller to request information, disclosure of data, or the provision of documents. The Controller discloses personal data to such authorities — provided the authority has specified the exact purpose and scope of the request — only to the extent and only insofar as strictly necessary to achieve the stated purpose of the request.
The Controller reserves the right to engage additional processors, and will give individual notice of their identity no later than the commencement of the relevant processing.
In the course of processing, the Controller preserves:
Data subjects may request information about the processing of their personal data, may request the rectification of their personal data, or — except for mandatory processing — its erasure or the withdrawal of consent, may exercise their right to data portability and their right to object in the manner indicated when the data was collected, or through the Controller's contact details set out above.
The Controller takes appropriate measures to provide data subjects with all information referred to in Articles 13 and 14 of the GDPR concerning the processing of personal data, and with any communication under Articles 15–22 and Article 34, in a concise, transparent, intelligible, and easily accessible form, using clear and plain language.
The right to information may be exercised in writing, through the contact details set out in the "Data Controller" section of this notice. At the data subject's request, information may also be provided orally, once their identity has been verified.
Data subjects have the right to obtain confirmation from the Controller as to whether their personal data is being processed, and, if so, to be granted access to the personal data and to the following information:
Where personal data is transferred to a third country or to an international organization, the data subject has the right to be informed of the appropriate safeguards relating to the transfer.
The Controller provides the data subject with a copy of the personal data undergoing processing. For any further copies requested, the Controller may charge a reasonable fee based on administrative costs. At the data subject's request, information is provided electronically. The Controller provides this information within one month at the latest, from the submission of the request.
Data subjects may request the rectification of inaccurate personal data concerning them held by the Controller, and the completion of incomplete data.
Data subjects have the right to obtain, without undue delay, the erasure of personal data concerning them by the Controller, upon request, where one of the following grounds applies:
Erasure may not be requested where the processing is necessary:
The Controller deletes the data subject's data from its records within 5 (five) business days of receiving the erasure request. Written erasure requests are accepted by the Controller at data.protection@advanteklabs.com.
At the data subject's request, the Controller restricts processing where one of the following applies:
Where processing has been restricted, such personal data may, with the exception of storage, only be processed with the data subject's consent, or for the establishment, exercise, or defense of legal claims, for the protection of the rights of another natural or legal person, or for important public interest reasons of the Union or a Member State.
The Controller informs the data subject in advance before lifting the restriction on processing.
Data subjects have the right to receive the personal data concerning them that they have provided to the Controller in a structured, commonly used, machine-readable format, and to transmit those data to another controller.
Data subjects have the right to object, on grounds relating to their particular situation, at any time to the processing of their personal data carried out for the performance of a task in the public interest or in the exercise of official authority vested in the Controller, or which is necessary for the purposes of the legitimate interests pursued by the Controller or a third party, including profiling based on those provisions, as well as to processing carried out for direct marketing purposes. Following an objection, the Controller may no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject, or which relate to the establishment, exercise, or defense of legal claims.
Data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them. This right does not apply where the processing is:
Data subjects have the right to withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
The Controller informs the data subject, without undue delay and in any event within one month of receipt of the request, of the actions taken on a request under Articles 15–22 of the GDPR. That period may be extended by a further two months where necessary, taking into account the complexity and number of requests.
The Controller informs the data subject of any such extension, together with the reasons for the delay, within one month of receipt of the request. Where the data subject made the request electronically, information is provided electronically, unless otherwise requested.
If the Controller does not take action on the data subject's request, it informs the data subject without delay, and at the latest within one month of receipt of the request, of the reasons for not taking action, and of the possibility to lodge a complaint with a supervisory authority and to seek a judicial remedy.
The Controller provides the requested information and communication free of charge. If the data subject's request is manifestly unfounded or excessive, in particular because of its repetitive character, the Controller may charge a reasonable fee, taking into account the administrative costs of providing the requested information or communication or taking the requested action, or may refuse to act on the request.
The Controller informs each recipient to whom personal data have been disclosed of any rectification, erasure, or restriction of processing, unless this proves impossible or involves disproportionate effort. The Controller informs the data subject about those recipients if the data subject requests this.
Any person who has suffered material or non-material damage as a result of an infringement of data protection law is entitled to compensation from the Controller or the processor for the damage suffered. A processor is liable for damage caused by processing only where it has not complied with the obligations specifically directed to processors under the law, or where it has acted outside, or contrary to, the lawful instructions of the Controller.
Where more than one controller or processor, or both a controller and a processor, are involved in the same processing and are responsible for damage caused by it, each controller or processor is held liable for the entire damage, on a joint and several basis.
The Controller or the processor is exempt from liability if it proves that it is not in any way responsible for the event giving rise to the damage.
In the event of an infringement of their rights, data subjects may bring proceedings against the Controller before a court. The court deals with the case as a priority.
Complaints and requests for a remedy may be submitted to the National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság — NAIH):
The Controller reserves the right to unilaterally amend this Privacy Policy, subject to appropriate publication of the amended text.
Budapest, 7 July 2026.