Data protection and processing principles and policy applied by ARLITECH Kft. Last updated: 1 January 2026.
1.1 The purpose of this Privacy Notice is to set out the data protection and data processing principles applied by ARLITECH KORLÁTOLT FELELŐSSÉGŰ TÁRSASÁG (registered seat: 2100 Gödöllő, Dózsa György út 13., 3rd floor 309, Hungary; company registration number: 13 09 114879; represented by: Ákos Jenei, managing director; hereinafter: "COMPANY" or "DATA CONTROLLER") and the Company's data protection and processing policy, which the Company, as data controller, accepts as binding on itself.
1.2 This Privacy Notice contains the principles for processing personal data provided by Customers in connection with the use of the services provided by the Company.
1.3 In drafting the provisions of this Privacy Notice, the Company has had particular regard to Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (hereinafter: "GENERAL DATA PROTECTION REGULATION" or "GDPR"); Hungarian Act CXII of 2011 on the right of informational self-determination and freedom of information (hereinafter: "INFOTV."); Hungarian Act V of 2013 on the Civil Code (hereinafter: "PTK."); and Hungarian Act XLVIII of 2008 on the Basic Conditions and Certain Limitations of Commercial Advertising Activity (hereinafter: "GRTV.").
1.4 Unless otherwise stated, the scope of this Privacy Notice does not extend to services and data processing operations linked to promotions, prize draws, services, other campaigns or content of third parties (other than the Data Controller) that advertise or otherwise appear on the Website referenced in this Notice.
1.5 Unless otherwise stated, the scope of this Privacy Notice does not extend to the services and data processing of websites or service providers reached via links from a website covered by this Notice. Such services are governed by the privacy notice of the third-party operator, and the Data Controller assumes no liability for such data processing.
"Processing": any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
"Data Controller": the person who, alone or jointly with others, determines the purposes and means of the processing of personal data.
"Personal data": any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
"Personal data breach": a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
"Processor": a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
"Website": the www.arlitech.hu website and press product operated by the Data Controller.
"Service(s)": services operated and provided by the Data Controller.
"User": the natural person who registers for the Services and, in connection therewith, provides the data listed below.
"Privacy Notice": this Privacy Notice of the Data Controller.
3.1 When the User visits the Website, the Data Controller's system automatically records the User's IP address.
3.2 At the User's discretion, the Data Controller may process the following data in connection with the Services available on the Website, for the relevant Service:
The User may also register via their Facebook account. If the User chooses this option, the link redirects the User to the Facebook Admin page, where the provider will inform them about how the data transmitted is processed. Facebook's privacy policy is available at: https://www.facebook.com/about/privacy.
data processing principles are defined in a separate set of rules in each case.
If the User sends an email or postal letter (e.g. a message) to the Data Controller, the Data Controller records the User's email address, address (if provided) and any other data voluntarily submitted by the User, and processes them to the extent and for the period necessary to deliver the service.
In the course of its editorial activity, the Data Controller processes the data of all natural persons who contribute to the production of the content, either as a source or by being referred to in the edited content. In such cases the personal data most frequently processed by the Data Controller may include: the data subject's name, position, place of work, age, residence-related data, and any other data indicating how the data subject relates to the topic of the edited content.
3.3 Notwithstanding the above, it may occur that a service provider technically connected to the operation of the Services carries out data processing activity on the Website without the Data Controller's knowledge. Such activity does not qualify as Processing carried out by the Data Controller. The Data Controller does everything reasonably possible to prevent and filter such data processing.
4.1 To provide a tailored service, the Data Controller may place small data packets ("cookies") on the User's computer. The purpose of cookies is to enable the high-quality operation of the page, to provide personalised services and to enhance the user experience. The User may delete cookies from their own computer or configure their browser to disallow cookies. By disallowing cookies, the User acknowledges that the operation of the page may not be fully functional.
4.2 In the course of providing personalised services using cookies, the Data Controller processes the following Personal data: demographic data (based on the data referenced above) and information on areas of interest, habits and preferences (based on browsing history).
4.3 Data recorded for technical reasons during system operation: data of the User's logging-in computer that is generated during use of the Service and that the Data Controller's system records as an automatic by-product of technical processes. The system automatically logs such automatically recorded data on login and logout, without any separate declaration or action by the User.
5.1 The purposes of processing carried out by the Data Controller are:
5.2 The Data Controller does not use the Personal data provided for any purpose other than those set out in this section.
5.2.1 Processing takes place on the basis of a voluntary, informed declaration by the User, which contains the User's express consent to the use of Personal data communicated by them or generated about them during use of the Website. Where processing is based on consent, the User is entitled to withdraw their consent at any time, although this does not affect the lawfulness of processing carried out before the withdrawal.
5.2.2 The Data Controller records the User's IP address upon entry to the Website in connection with the provision of the Service, on the basis of the Data Controller's legitimate interest and for the lawful provision of the Service (e.g. to filter out unlawful use or unlawful content), without separate consent from the User.
5.2.3 The legal basis of Processing within the framework of content provision is, in addition to the User's voluntary consent, in certain cases the safeguarding of the fundamental rights to information and freedom of expression, within the limits set by law.
5.2.4 The User warrants that, before providing or making accessible the personal data of other natural persons in the course of using the Services (e.g. gifting), they have lawfully obtained the consent of the natural person concerned, in accordance with applicable law.
5.2.5 All liability for user-provided content rests with the User. By providing an email address or registration data, each User undertakes responsibility that only they will use the Services from the email address, address or with the data they have provided. Accordingly, all liability arising from logins or service use connected with a given email address and/or data rests solely with the User who registered or provided the data.
6.1 The Data Controller processes Personal data in accordance with the principles of good faith, fair dealing and transparency, and in compliance with applicable law and the provisions of this Privacy Notice.
6.2 The Personal data essential for using the Services is processed by the Data Controller on the basis of the User's consent and exclusively for the specified purpose.
6.3 The Data Controller processes Personal data only for the purposes set out in this Privacy Notice and in applicable law. The scope of Personal data processed is proportionate to the purpose of processing and shall not be exceeded. In any case where the Data Controller intends to use the Personal data for a purpose different from the original purpose of collection, the User is informed and the Data Controller obtains prior, express consent or provides the User with an opportunity to object to such use.
6.4 The Data Controller does not verify the Personal data provided. Sole responsibility for the accuracy of the Personal data provided rests with the person providing it; the Data Controller, however, takes every reasonable measure to ensure that personal data which is inaccurate for the purposes of the processing is rectified or erased without delay.
6.5 The Personal data of a data subject under the age of 16 may be processed only with the consent of an adult exercising parental responsibility over them. The Data Controller is not in a position to verify the eligibility of the consenting person or the content of their declaration; the User or the person exercising parental responsibility warrants that the consent complies with the law. If the User wishes to provide the personal data of a person under the age of 16 as third-party personal data (e.g. gifting), the User warrants that they have obtained legally compliant consent. In the absence of consent, the Data Controller does not collect Personal data relating to data subjects under the age of 16, except for the IP address used during use of the Service, which is automatically recorded by the nature of internet services.
6.6 The Data Controller does not transfer the Personal data it processes to any third party other than the Processors named in this Privacy Notice.
6.7 The provision in this section is without prejudice to the use of data in statistically aggregated form, which may not contain in any form any data that would enable the relevant User to be identified, and therefore does not qualify as Processing or as data transfer.
6.8 The Data Controller notifies the relevant User and all those to whom the Personal data was previously transferred for processing purposes about any rectification, restriction or erasure of the Personal data processed by it. Notification may be omitted if, taking into account the purpose of the processing, this does not prejudice the legitimate interests of the data subject.
6.9 The Data Controller ensures the security of Personal data, taking technical and organisational measures and establishing procedural rules to safeguard recorded, stored and processed data and to prevent its accidental loss, unlawful destruction, unauthorised access, unauthorised use, unauthorised alteration or unauthorised dissemination. The Data Controller calls on every third party to whom it transfers Personal data to fulfil this obligation.
6.10 In view of the relevant provisions of the GDPR, the Data Controller is not required to designate a data protection officer.
7.1 The Data Controller stores automatically recorded IP addresses for a maximum of 30 days from recording.
7.2 In the case of emails and postal letters sent by the User exclusively for the purpose of contact or complaint handling, the Data Controller addressed deletes the email address or any address indicated in the letter on the 90th day after the conclusion of the matter referenced in the request, except where, in an individual case, the Data Controller's legitimate interest justifies further processing of the Personal data, until that legitimate interest exists.
7.3 The processing of Personal data provided by the User continues until the User deletes their account created during registration, unsubscribes from the Service, otherwise requests erasure of the Personal data, withdraws their consent, or the Data Controller ceases to provide the Service. In such cases, the Personal data is irretrievably deleted from the Data Controller's systems.
7.4 A request by the User to terminate Processing without deleting the registered account or unsubscribing from the Service does not affect the User's right to use the Service; however, certain Services may not be available without the relevant Personal data.
7.5 In cases of unlawful or deceptive use of Personal data or where the User commits a crime or attacks the system, the Data Controller is entitled to delete the User's Personal data without delay, while, where there is suspicion of a crime or civil liability, the Data Controller is entitled to retain the Personal data for the duration of the relevant proceedings.
7.6 If a court or authority orders the deletion of Personal data by final decision, the Data Controller shall execute the deletion.
8.1 The User may request that the Data Controller inform them whether their personal data is being processed and, if so, that they be granted access to the Personal data processed, in particular with regard to:
8.2 The User may request information about the processing of their Personal data at any time in writing, by registered or registered-with-receipt mail to the Data Controller's address, or by email to info@arlitech.hu.
8.3 The Data Controller treats a written information request as authentic if the User can be unambiguously identified from the submitted request. The Data Controller treats an emailed information request as authentic only if the User sends it from the email address they have provided.
8.4 The User may request rectification or modification of the Personal data processed by the Data Controller.
8.5 Taking into account the purposes of Processing, the User may request the completion of incomplete Personal data.
8.6 The Personal data provided by the User in connection with a given Service can be modified by email sent to the above email address, by clicking the link at the end of each newsletter, or in the User's registered account by editing the account settings. Once a request to modify Personal data has been fulfilled, the prior (deleted) data cannot be restored.
8.7 The User may request erasure of the Personal data processed by the Data Controller. Erasure may be refused:
8.8 The Data Controller informs the User of any refusal of an erasure request, indicating the reason for the refusal. Once a request to erase Personal data has been fulfilled, the prior (deleted) data cannot be restored.
8.9 Newsletters sent by the Data Controller can be unsubscribed via the unsubscribe link contained in them. Upon unsubscription, the Data Controller deletes the User's Personal data from the newsletter database.
8.10 The User may request that the Data Controller restrict processing of Personal data where:
8.11 The User may request, where applicable, that the Data Controller transfer the Personal data which the User has provided and which is processed by automated means by the Data Controller, in a structured, commonly used and machine-readable format, to the User and/or transmit it to another controller.
8.12 The User may object to the processing of their Personal data:
The Data Controller examines the lawfulness of the User's objection and, if it finds the objection well-founded, terminates Processing and blocks the Personal data processed, and notifies all those to whom the Personal data subject to the objection had previously been transferred about the objection and any measures taken on its basis.
8.13 If the Personal data breach is likely to result in a high risk to the rights and freedoms of Users, the Data Controller informs the User of the Personal data breach without undue delay. The User does not need to be informed if any of the following conditions are met:
9.1 To carry out its activities, the Data Controller uses the Processors named above in this Privacy Notice.
9.2 Processors do not make independent decisions; they may act only in accordance with the contract concluded with the Data Controller and the instructions received.
9.3 The Data Controller monitors the work of the Processors.
9.4 Processors may engage further processors only with the Data Controller's consent.
9.5 By accepting this Privacy Notice, the User expressly accepts and consents to the Data Controller transferring their Personal data to the Processors.
9.6 The Data Controller carries out its Online book sales activity through the processor Mediarey Hungary Services Zártkörűen Működő Részvénytársaság (registered seat: 1065 Budapest, Hajós utca 23. 1st floor 10.; company registration number: 01-10-140295; hereinafter: Forbes). By accepting this Privacy Notice, the User expressly consents to the Data Controller engaging Forbes as a processor. The Data Controller informs Data Subjects that there is a data processing agreement in force between the Data Controller and Forbes that complies with applicable law.
10.1 Data transfer to the Processors specified in this Privacy Notice may be carried out without the User's separate, case-by-case consent, since the User gives express and unambiguous consent to such transfer by accepting this Privacy Notice. The disclosure of Personal data to third parties or authorities, unless legislation provides otherwise, is possible only on the basis of an authority's decision or with the User's prior, express consent.
10.2 The Data Controller is entitled and obliged to forward to the competent authorities any Personal data available and lawfully stored by it, where the Data Controller is required to do so by law or by a final order of an authority. The Data Controller cannot be held liable for such transfer or for any consequences thereof.
10.3 The Data Controller maintains a data transfer register to verify the lawfulness of data transfers and to ensure the User's information.
11.1 The Data Controller reserves the right to modify this Privacy Notice at any time by unilateral decision.
11.2 Applicable laws and procedural practices change from time to time. If the Data Controller decides to update this Privacy Notice, it publishes the changes on the Website. In the event of a material change to the way the Data Controller processes Personal data, the Data Controller sends prior notice to the User and, where required by law, requests the User's consent prior to implementing such changes. The Data Controller strongly recommends that the User read this Privacy Notice and stay continuously informed of the practices followed by the Data Controller. This Privacy Notice was last modified on 1 January 2026.
12.1 The Data Controller's staff can be reached with any question or comment relating to data processing at info@arlitech.hu.
12.2 The User may submit a data-processing complaint directly to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) (address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c., Hungary; telephone: +36-1-391-1400; email: ugyfelszolgalat@naih.hu; website: www.naih.hu).
12.3 If their rights are violated, the User may bring the matter before a court. The case falls within the jurisdiction of the regional court (törvényszék). At the data subject's choice, the action may also be brought before the regional court of the data subject's place of residence or place of stay. Upon request, the Data Controller will inform the User of the available remedies and how to use them.