Privacy Policy
1. Introduction
L-IT Group Ltd., as the owner of the fidsys.com website and operator of the online FID logging system (hereinafter: FID, fidsys.com service provider, or data controller), as data controller, acknowledges the content of this legal notice as binding upon itself. It undertakes that its data processing in connection with its service complies with the requirements set out in this notice and in the applicable legislation.
The data protection principles relating to the FID Android and iOS application and the fidsys.com website are continuously available within the applications and on the fidsys.com website.
The service provider reserves the right to amend this notice at any time, in which case it will publish a notice with appropriate content on the fidsys.com website.
If a user has a question that is not, or not clearly, answered by this notice, they may submit it to the service provider in writing. Although the fidsys.com team makes every effort to ensure that the quality of the service it provides is impeccable, it accepts no liability for any damage arising from improper use of the system.
The data controller is committed to protecting the personal data of its partners and users and considers respect for its customers' right to informational self-determination to be of paramount importance. The operator of the FID system treats the personal data placed at its disposal as confidential and takes all security, technical, and organizational measures that guarantee the security of the data ("data security").
Below, FID sets out its data processing principles and presents the requirements it has established for itself, as data controller, and adheres to. The data controller declares that its data processing principles are in line with the applicable data protection legislation.
2. Definitions
-
personal data: any data relating to an identified or identifiable natural person ("data subject"), and any inference drawn from such data concerning the data subject. Personal data retains this quality during processing for as long as its connection with the data subject can be restored. A person is considered identifiable in particular if they can be identified, directly or indirectly, by reference to a name, an identification number, or one or more factors specific to their physical, physiological, mental, economic, cultural, or social identity;
-
consent: any freely given and specific indication of the data subject's wishes, based on appropriate information, by which they unambiguously signify their agreement to the processing of personal data relating to them, whether covering all processing operations or only certain ones;
-
objection: a statement by the data subject objecting to the processing of their personal data and requesting the cessation of the processing or the deletion of the data processed;
-
data controller: the natural or legal person, or organization without legal personality, that determines the purpose of the processing of data, makes and implements decisions regarding the processing (including the means used), or has such decisions implemented by a data processor engaged by it;
-
data processing: any operation or set of operations performed on data, irrespective of the procedure applied, such as collection, recording, organization, storage, alteration, use, transmission, disclosure, alignment or combination, blocking, deletion, and destruction, as well as preventing further use of the data. Data processing also includes taking photographs, audio, or video recordings, and recording physical characteristics suitable for identifying a person (e.g., fingerprints or palm prints, DNA samples, iris images);
-
data transfer: making data accessible to a specified third party;
-
disclosure: making data accessible to anyone;
-
data deletion: rendering data unrecognizable in such a way that it can no longer be restored;
-
data blocking: marking data with an identifying flag for the purpose of restricting its further processing permanently or for a specified period;
-
data destruction: the complete physical destruction of the data carrier containing the data;
-
data processing (technical operations): performing technical tasks connected with data processing operations, regardless of the method and means used to carry out the operations and the place of application;
-
data processor: the natural or legal person, or organization without legal personality, that processes data on behalf of the data controller;
-
third party: a natural or legal person, or organization without legal personality, that is not the same as the data subject, the data controller, or the data processor;
-
third country: any country that is not a member of the European Economic Area.
-
data subject: any natural person identified or identifiable, directly or indirectly, based on personal data.
All other terms used in this document but not separately defined herein shall be interpreted in accordance with FID's General Terms and Conditions.
3. Principles governing FID's data processing
Personal data may be processed if
a. the data subject consents to it, or
b. it is ordered by law or, based on statutory authorization within the scope specified therein, by a local government decree for a purpose based on public interest ("mandatory data processing").
The consent of a person without legal capacity or with limited legal capacity who is a minor does not require the consent of their legal representative, since the statement is aimed at registration occurring routinely in everyday life and does not require deliberation (Section 2:14(2) of the Civil Code).
Personal data may only be processed for a specified purpose, to exercise a right or fulfill an obligation. Data processing must comply with the purpose of the processing at every stage.
Only personal data that is essential for achieving the purpose of the processing, suitable for achieving that purpose, and only to the extent and for the duration necessary to achieve the purpose, may be processed.
Personal data may only be processed with informed consent.
The data subject must be informed - clearly, comprehensibly, and in detail - of all facts related to the processing of their data, in particular the purpose and legal basis of the processing, the person authorized to carry out the processing and the processing operations, the duration of the processing, and who may access the data. This information must also cover the data subject's rights and remedies relating to the processing.
The personal data processed must meet the following requirements:
a. their collection and processing must be fair and lawful;
b. they must be accurate, complete and, where necessary having regard to the purpose of the processing, kept up to date;
c. the data subject must only be identifiable for as long as is necessary for the purpose of the processing.
The use of a general and uniform personal identification number without restriction is prohibited.
Personal data may only be transferred, and different data processing operations may only be linked, if the data subject has consented to it, or the law permits it, and if the conditions and requirements of data processing are met for each item of personal data.
Personal data (including special categories of data) may be transferred from the country to a data controller or data processor located in a third country - regardless of the data carrier or method of data transmission - if the data subject has expressly consented to it, or the law permits it, and an adequate level of protection of personal data is ensured in the third country during the processing of the transferred data. Data transfers to Member States of the European Economic Area shall be treated as if they were transfers within the territory of Hungary.
4. Scope of personal data, purpose, legal basis, and duration of processing
Within the services, the processing of all data relating to the data subject is based on voluntary consent.
4.1 Data of website visitors
The fidsys.com website, www.fidsys.com, may be freely visited without providing any personal information. The website provides information about FID's services. For the purpose of personalized service, the service provider may place a small data packet, a so-called cookie, on the user's computer to retain the settings saved by the user. The user may delete the cookie from their own computer or may configure their browser to prohibit the use of cookies. The code of the FID website may contain links from and to an external server independent of FID, which external server supports independent auditing of the website's traffic and other web analytics data (Google Analytics). The external service provider operating/supervising this external server does not have access to personal data; FID only provides access to aggregated data. Detailed information on the processing of this data is provided by the external service provider. Contact: http://www.google.com.
While visiting the fidsys.com website, FID may record the user's IP address, the time of the visit, and the address of the page viewed - for technical reasons and for the purpose of compiling statistics on user habits. The data is stored on the server for one year.
4.2 Data processing related to payment transactions
During the provision of fidsys.com's services, users' personal data is generally not stored. However, during the provision of FID's services, the following data - entered on the Merchant's payment interface or stored by the Merchant - may be transferred for transaction security (fraud prevention) purposes and to track user transactions: (i) subscriber name and/or organization name, (ii) username, (iii) billing address, (iv) telephone number, (v) e-mail address.
FID retains this data for 5 years from the completion of the transaction.
Fidsys.com may send notifications relating to transactions to the e-mail address provided in this way.
4.3 Data processing for the purpose of contact and customer service
Contact with the service provider can be made by submitting a name, e-mail address, and message via the form found on the fidsys.com website and in the applications, or by e-mail.
FID uses the messages processed in this way only for their intended purpose, archives them after the matter has been finally settled, and retains them for 5 years.
FID also maintains a telephone customer service line. The contact details for the telephone customer service are available on the www.fidsys.com website. FID's telephone customer service records and archives calls. Where the user has given verbal consent by telephone, FID's telephone customer service requests the user's name and e-mail address. Fidsys.com processes data collected in this way by telephone customer service for 1 year.
4.4 Other data processing
For any data processing not listed in this notice, FID provides information at the time the data is collected.
FID hereby informs users that courts, prosecutors' offices, and investigating authorities may contact the service provider to request information, disclosure of data, or the provision of documents (pursuant to Section 71 of the Code of Criminal Procedure).
FID discloses to authorities - provided the authority has specified the exact purpose and scope of the data in its lawful request - only the personal data, and only to the extent, that is strictly necessary to fulfill the purpose of the request.
5. Method of storing personal data; security of processing
The servers hosting the FID website are located in an environment supervised by Rackforest Zrt., which handles operations. FID's systems are operated by the service provider. These organizations may access data processed by FID solely as data processors.
FID selects and operates the IT tools used in providing the service for the processing of personal data in such a way that the data processed:
a. is accessible to those authorized to access it (availability);
b. has assured authenticity and authentication (authenticity of processing);
c. has verifiable integrity (data integrity);
d. is protected against unauthorized access (confidentiality of data).
FID ensures the security of data processing through technical, organizational, and operational measures that provide a level of protection appropriate to the risks associated with the processing.
During data processing, fidsys.com preserves:
a. confidentiality: it protects information so that only those authorized may access it;
b. integrity: it protects the accuracy and completeness of information and the method of its processing;
c. availability: it ensures that when an authorized user needs it, they can indeed access the desired information, and that the associated tools are available.
FID's IT system and network are both protected against computer-assisted fraud, espionage, sabotage, vandalism, fire and flood, as well as against computer viruses, computer intrusions, and denial-of-service attacks. The operator ensures security through server-level and application-level protective procedures.
FID hereby informs users that electronic messages transmitted over the internet, regardless of protocol (e-mail, web, ftp, etc.), are vulnerable to network threats that may lead to unfair activity, disputing of contracts, or the disclosure or alteration of information. To guard against such threats, the service provider takes every precaution that can reasonably be expected of it. It monitors its systems in order to record any security deviations and to be able to provide evidence in the event of any security incident. System monitoring also enables verification of the effectiveness of the precautions applied.
6. Data controller's details and contact information
Name: L-IT Group Ltd.
Address: 2112 Veresegyház, Kökény utca 12-14. HUNGARY
E-mail: kapcsolat@l-it.hu
Company registration number: 13-09-203477
Tax number: 11712152-2-13
Data protection registration ID: pending issuance
7. Remedies
The data subject may request information about the processing of their personal data, and may request the correction, or - except for data processing ordered by law - the deletion of their personal data, in the manner indicated at registration or through customer service.
At the data subject's request, FID, as data controller, shall provide information about the data it processes, or that is processed by a processor engaged by it, on the purpose and legal basis of the processing, its duration, the name and address (registered office) of the data processor, and its activities related to the processing, as well as who receives or has received the data and for what purpose.
The data controller shall provide the information in writing, in a comprehensible form, within the shortest possible time from submission of the request, but no later than 30 days. This information is provided free of charge if the person requesting it has not already submitted a request for information regarding the same set of data to the data controller in the current year. In other cases, fidsys.com may charge a fee to cover costs.
FID deletes personal data if its processing is unlawful, if the data subject requests it, if the purpose of the processing has ceased, if the statutory retention period for the data has expired, or if ordered by a court or the data protection authority (National Authority for Data Protection and Freedom of Information).
FID notifies the data subject, as well as all those to whom the data was previously transferred for processing purposes, of any correction or deletion. Notification may be omitted if it does not prejudice the data subject's legitimate interest regarding the purpose of the processing.
The data subject may object to the processing of their personal data if:
a. the processing or transfer of personal data is necessary solely for the data controller or data recipient to fulfill a legal obligation or to enforce a legitimate interest, except where the processing is ordered by law (the case of "mandatory data processing");
b. the personal data is used or transferred for the purposes of direct marketing, public opinion polling, or scientific research;
c. the exercise of the right to object is otherwise permitted by law.
FID - simultaneously suspending the processing - shall examine the objection within the shortest possible time from submission of the request, but no later than 15 days, and shall inform the person making the request in writing of the outcome (its assessment of the merits of the objection). If the objection is well-founded, the data controller shall terminate the processing - including any further collection and transfer of data - and shall block the data and shall notify all those to whom it previously transferred the personal data subject to the objection of the objection and of any measures taken as a result, who are then obliged to take action to enforce the right to object.
If the data subject disagrees with FID's decision, they may bring the matter before a court within 30 days of being notified of the decision.
In the event of an infringement of their rights, the data subject may bring proceedings against the data controller before a court. FID shall compensate any damage caused to another person through unlawful processing of the data subject's data or through breach of data security requirements. The data controller is liable to the data subject for damage caused by the data processor as well. The data controller is exempt from liability if the damage was caused by an unavoidable cause outside the scope of the data processing.
Damages need not be compensated to the extent that they resulted from the intentional or grossly negligent conduct of the injured party.
Complaints regarding FID's data processing may be submitted to the National Authority for Data Protection and Freedom of Information, at the following contact details:
Registered office: 1125 Budapest, Szilágyi Erzsébet fasor 22/c. HUNGARY
Postal address: 1530 Budapest, P.O. Box 5. HUNGARY
Phone: +36 (1) 391-1400
Fax: +36 (1) 391-1410
E-mail: ugyfelszolgalat@naih.hu
Cookie Policy
This policy applies to the fidsys.com website operated by L-IT Group Ltd., its subpages, and the cookies used thereon.
What is a cookie?
Cookies are files or pieces of information stored on your computer (or other internet-capable devices, such as smartphones or tablets) when you visit a website operated by L-IT Group Ltd. A cookie generally contains the name of the website the cookie came from, the "lifetime" of the cookie (i.e., how long it remains on your device), and its value, which is usually a randomly generated unique number.
What do we use cookies for?
We use cookies to make L-IT Group Ltd.'s pages easier to use and to allow them, as well as our products, to be better tailored to your interests and needs. Cookies may also be used to help speed up your future activities and improve your experience while using our pages. We also use cookies to compile anonymous, aggregated statistics that help us better understand how people use our pages and help us improve their structure and content. This information does not allow us to identify you personally.
What types of cookies do we use?
We may use two types of cookies on L-IT Group Ltd.'s pages - "session cookies" or "persistent cookies." Session cookies are temporary: they remain on your device only until you leave L-IT Group Ltd.'s page. Persistent cookies remain on your device for much longer, or until you manually delete them (how long they remain on your device depends on the cookie's lifetime and your browser settings).
Do cookies store personal information?
Personal data collected through cookies may only be used to make certain content or elements available to the visitor. This data is encrypted in such a way that it is impossible for third parties to access it.
Data collected and stored by cookies is processed by L-IT Group Ltd. in accordance with its Privacy Notice.
Deleting cookies
Most internet browsers are initially set to accept cookies. You can change your settings to block cookies, or you can request a warning when cookies are set on your device. There are numerous ways to manage cookies. Please refer to your browser's information or help page if you would like to learn more about browser settings and how to change them.
If you disable the cookies we use, this may affect your experience while on L-IT Group Ltd.'s website - for example, you may not be able to visit certain parts of the website, or you may not receive personalized information.

