PRIVACY
NOTICE
Brand Food Zártkörűen Működő Részvénytársaság
Effective from: 31 July 2026
1. Introduction and scope of this Notice
Brand Food Zártkörűen Működő Részvénytársaság (hereinafter referred to as the “Controller”, the “Service Provider” or the “Company”) respects the privacy of natural persons and processes their personal data in accordance with the applicable data protection legislation.
The purpose of this Notice is to provide transparent information about the processing of personal data in connection with the use of the https://brandfood.hu/ website, contact with the Controller, business communications and the Controller’s presence on LinkedIn.
The processing of personal data is governed in particular by Regulation (EU) 2016/679 of the European Parliament and of the Council (the “GDPR”), Act CXII of 2011 on Informational Self-Determination and Freedom of Information (the “Hungarian Privacy Act”), Act CVIII of 2001 on Electronic Commerce and Information Society Services (the “E-commerce Act”), and Act C of 2003 on Electronic Communications.
This Notice applies to the processing of personal data on the following website:
The intended publication address of this Notice is:
https://brandfood.hu/adatkezelesi-tajekoztato/
Amendments to this Notice shall take effect upon publication at the above address. Where reasonably possible, the Controller will provide a separate notice on the website about material changes.
2. Details and contact information of the Controller
|
Full registered name |
Brand Food Zártkörűen Működő Részvénytársaság |
|
Short name |
Brand Food Zrt. |
|
Registered office |
10 Munkácsy Mihály Street, 2151 Fót, Hungary |
|
Company registration number |
13-10-042139 |
|
Tax number |
28956093-2-13 |
|
|
office@brandfood.hu |
|
Telephone |
+36 70 622 62 99 |
|
Website |
Főoldal |
Data protection enquiries, data subject requests and complaints may be submitted using the postal address, email address or telephone number stated above.
3. Definitions
“personal data”: any information relating to an identified or identifiable natural person (the “data subject”).
“processing”: any operation performed on personal data or sets of personal data, whether or not by automated means, including in particular collection, recording, organisation, storage, alteration, retrieval, use, transmission, restriction, erasure or destruction.
“controller”: the person or organisation that determines the purposes and means of processing personal data.
“processor”: the person or organisation that processes personal data on behalf of the Controller.
“recipient”: the person or organisation to whom personal data is disclosed.
“consent”: any freely given, specific, informed and unambiguous indication of the data subject’s wishes.
“personal data breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
“profiling”: a form of automated processing of personal data used to evaluate personal aspects relating to a natural person.
4. Principles relating to the processing of personal data
The Controller processes personal data in accordance with the following principles:
- lawfulness, fairness and transparency;
- purpose limitation;
- data minimisation;
- accuracy and keeping data up to date;
- storage limitation;
- integrity and confidentiality;
The Controller processes only personal data that is necessary for the relevant purpose and retains it only for as long as necessary. The Controller applies appropriate technical and organisational measures to protect the security of the personal data processed.
5. Contact enquiries and their handling
A data subject may contact the Controller by email, by telephone, using the contact details displayed on the website or, where available, through a contact form.
|
Personal data processed |
Purpose of processing |
Legal basis |
Retention period |
|
name and company name |
identification and addressing the data subject |
Article 6(1)(a) GDPR – consent; for requests for quotations, pre-contractual steps under Article 6(1)(b) GDPR |
no more than 2 years after the enquiry is closed |
|
email address and telephone number |
communication and responding to the enquiry |
Article 6(1)(a) or (b) GDPR |
no more than 2 years after the enquiry is closed |
|
content of the message, question or request for a quotation |
responding to the enquiry and preparing a quotation |
Article 6(1)(a) or (b) GDPR |
no more than 2 years after the enquiry is closed; in the event of a legal dispute, until the claim becomes time-barred |
|
additional data provided voluntarily |
fulfilling the data subject’s request |
Article 6(1)(a) GDPR |
until the purpose has been achieved, but no longer than 2 years |
Providing personal data is voluntary; however, without the information necessary for communication, the Controller may be unable to respond to the enquiry. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal.
6. Requests for quotations, business negotiations and contractual relationships
Where an enquiry leads to a request for a quotation or to the establishment of a supplier, customer or other business relationship, the Controller processes the data of the data subject and the partner’s contact persons for the preparation and performance of that business relationship.
|
Personal data processed |
Purpose |
Legal basis |
Retention period |
|
name, job title and representative capacity |
identifying the business partner and the contact person |
Article 6(1)(b) GDPR; for a contact person of a legal entity, Article 6(1)(f) GDPR – legitimate business interests |
for unsuccessful negotiations, no more than 2 years; where a contract is concluded, 5 years after the end of the relationship |
|
business email address and telephone number |
business communications |
Article 6(1)(b) or (f) GDPR |
5 years after the end of the relationship |
|
quotation, order, contract and related communications |
conclusion and performance of a contract and enforcement of claims |
Article 6(1)(b) and (f) GDPR |
5 years from termination of the contract |
|
invoicing and accounting data |
compliance with legal and accounting obligations |
Article 6(1)(c) GDPR |
accounting documents are retained for at least 8 years |
The legitimate interests pursued are maintaining the Controller’s business relationships, performing contracts, communicating with business partners and establishing, exercising or defending legal claims. A data subject has the right to object, on grounds relating to their particular situation, to processing based on legitimate interests.
7. Technical operation of the website and log data
When the website is visited, the hosting provider’s systems may record technical data in order to ensure operation of the service, identify faults, maintain IT security and prevent misuse.
|
Personal data processed |
Purpose |
Legal basis |
Retention period |
|
IP address, time of the request, page visited, technical browser and device data, error logs and security logs |
operation of the website, troubleshooting and detection of attacks and misuse |
Article 6(1)(f) GDPR – legitimate interest in secure and continuous operation |
in accordance with the technical settings of the service, generally no more than 90 days; in the event of an incident, until the related procedure is closed |
A data subject does not have to provide personal data separately merely to view the website. Server logs may be accessed by the Controller, the hosting provider and authorised IT service providers.
8. Cookies and similar technologies
A cookie is a small data file that a website may place on a visitor’s device. Cookies may be session cookies, which are deleted when the browser is closed, or persistent cookies, which remain on the device for a specified period.
|
Cookie category |
Purpose |
Legal basis |
Typical duration |
|
strictly necessary cookies |
essential operation of the website, security, load balancing and storage of consent choices |
Article 6(1)(f) GDPR and Section 13/A(3) of the E-commerce Act; consent is not required |
for the session or for the period necessary for the technical purpose |
|
functional cookies |
remembering the visitor’s choices and settings |
Article 6(1)(a) GDPR – consent |
as specified in the cookie settings |
|
statistical/analytics cookies |
measuring traffic and use of the website and improving the service |
Article 6(1)(a) GDPR – consent |
generally from a few minutes up to 2 years |
|
marketing cookies |
measuring advertising performance, conversion tracking, personalisation or remarketing |
Article 6(1)(a) GDPR – consent |
as specified in the cookie settings, typically from a few days up to 2 years |
Non-essential cookies may be activated only after the data subject has given prior consent. Consent may be withdrawn or changed at any time through the cookie settings interface. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
The names, providers, purposes and expiry periods of the cookies actually used on the website can be viewed in the cookie management interface. Cookies may also be deleted or disabled in the browser, although doing so may limit the operation of certain functions.
9. Google Analytics
Where Google Analytics is active on the website, the Controller uses it to compile aggregated statistics about website traffic and usage. The service may place or read non-essential cookies only after the data subject has consented to analytics.
|
Provider |
Personal data processed |
Purpose and legal basis |
Retention |
|
Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland |
online identifiers (e.g. client ID), technical information derived from the IP address, device and browser data, pages viewed, events, referring page and timestamps |
website traffic statistics and service improvement; Article 6(1)(a) GDPR |
depending on the configuration; user-level data is generally retained for no more than 14 months and some cookies for up to 2 years |
The Controller configures Google Analytics in accordance with the principle of data minimisation. Google may also process data under its own terms and may use processors located outside the European Economic Area. Safeguards for transfers may include, in particular, an adequacy decision, the EU-U.S. Data Privacy Framework or the standard contractual clauses adopted by the European Commission.
Google Privacy Policy: https://policies.google.com/privacy
Google Analytics Opt-out Browser Add-on: https://tools.google.com/dlpage/gaoptout?hl=en
10. Google Ads conversion tracking and Consent Mode
Where the Controller uses Google Ads and conversion tracking, the purpose of the service is to measure whether a visitor who clicked on an advertisement completed a specified action on the website. Cookies used for marketing and advertising purposes may be activated only with the data subject’s consent.
|
Personal data processed |
Purpose |
Legal basis |
Retention |
|
online and cookie identifiers, advertisement click data, technical data relating to the visit and conversion event, and technical information associated with the IP address |
conversion measurement, assessing campaign performance and, where consent is given, remarketing and personalised advertising |
Article 6(1)(a) GDPR – consent |
in accordance with Google’s and the cookie manager’s settings, for no longer than the specified lifetime of the relevant cookie |
Google Consent Mode v2 may control, in accordance with the visitor’s choices, consent signals including analytics_storage, ad_storage, ad_user_data and ad_personalization. The ad_user_data signal governs the transfer of user data to Google for advertising purposes, while ad_personalization governs the use of data for personalised advertising.
The data subject may withdraw or change consent at any time through the cookie management interface. Google’s privacy terms also apply to Google services and any transfers of data to third countries.
11. Presence on LinkedIn
The Controller may operate a LinkedIn page or profile to present its services, products and professional activities and to communicate with prospective customers and business partners.
|
Personal data processed |
Data subjects and purpose |
Legal basis |
Retention |
|
public profile data, name, profile picture, job title, reactions, comments, shares, messages and any further data voluntarily provided by the data subject |
persons who follow, interact with or message the Controller’s page; communications, contact and presentation of services |
Article 6(1)(a) GDPR; for direct enquiries or business relationships, Article 6(1)(b) or (f) GDPR |
until the interaction is deleted or consent is withdrawn; for message exchanges, no more than 2 years, and for contractual matters, for the applicable retention period |
LinkedIn is operated by LinkedIn Ireland Unlimited Company (Wilton Place, Dublin 2, Ireland), which acts as an independent controller in respect of its own processing activities. LinkedIn may also generate statistical and analytical data about visitors and may transfer data outside the European Economic Area in accordance with its own privacy terms.
LinkedIn Privacy Policy: https://www.linkedin.com/legal/privacy-policy
A data subject may delete their own comments, reactions or messages on LinkedIn and may also contact the Controller using the contact details provided in this Notice. In relation to processing carried out independently by LinkedIn, data subject rights may also be exercised directly with LinkedIn.
12. Processors used by the Controller
12.1. Hosting and related IT services
|
Full registered name |
Rackforest Informatikai Kereskedelmi Szolgáltató és Tanácsadó Zártkörűen Működő Részvénytársaság |
|
Short name |
Rackforest Zrt. |
|
Registered office |
11 Victor Hugo Street, 5th floor, B05001, 1132 Budapest, Hungary |
|
Company registration number |
01-10-142004 |
|
Tax number |
32056842-2-41 |
|
|
info@rackforest.hu |
|
Telephone |
+36 1 211 0044 |
|
Website |
IT szenvedéllyel – RackForest |
|
Processing activity |
provision of web hosting, servers and related IT infrastructure; storage, backup and technical hosting of data processed through the website |
|
Duration of processing |
for the duration of the service relationship between the Controller and the processor and in accordance with the applicable backup and deletion rules |
Rackforest Zrt. acts on the Controller’s documented instructions and within the framework of the data processing agreement. The legal basis for the underlying processing between the Controller and the data subject also determines the legal basis for processing by the processor; Article 28 GDPR applies to the processor’s involvement.
12.2. External platform providers
Depending on the nature of the services they provide, Google and LinkedIn may act as independent controllers, joint controllers or processors. When using individual services, the Controller applies the necessary contractual and technical safeguards and makes non-essential processing conditional on consent.
If the Controller appoints a new processor in the future or the functions of the website change materially, this Notice will be updated.
13. Data transfers, recipients and third countries
The Controller transfers personal data only where an appropriate legal basis exists and the transfer is necessary for the relevant processing purpose. Recipients of personal data may include:
- employees and contractors of the Controller who participate in the performance of its tasks and are bound by confidentiality;
- the processors and platform providers named in this Notice;
- accounting, legal or IT professionals where their involvement is necessary;
- courts, authorities, investigative bodies or other public authorities acting under applicable law.
When responding to a request from a public authority, the Controller discloses only data that has been lawfully requested and is necessary for the purpose of the request.
The use of Google and LinkedIn services may involve transfers of data outside the European Economic Area. In such cases, the relevant provider and the Controller apply appropriate safeguards under Chapter V GDPR, including an adequacy decision, the EU-U.S. Data Privacy Framework or the standard contractual clauses adopted by the European Commission.
14. Rights of data subjects
Under the GDPR, a data subject may exercise the following rights:
Right of access: The data subject may request confirmation as to whether the Controller processes their personal data and may request access to the data processed and to information about the purposes, legal bases, recipients and duration of processing.
Right to rectification: The data subject may request the correction of inaccurate personal data and the completion of incomplete data.
Right to erasure: The data subject may request the erasure of their personal data where the purpose of processing has ceased, consent has been withdrawn, processing is unlawful or another condition under the GDPR is met. Erasure cannot be required where processing is necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims.
Right to restriction of processing: The data subject may request restriction of processing, in particular where they contest the accuracy of the data, the processing is unlawful or the data is required for the establishment, exercise or defence of legal claims.
Right to data portability: For automated processing based on consent or a contract, the data subject may request to receive personal data concerning them that they have provided in a structured, commonly used and machine-readable format, or to have such data transmitted to another controller where technically feasible.
Right to object: The data subject may object, on grounds relating to their particular situation, to processing based on legitimate interests or the performance of a task carried out in the public interest. The Controller will then cease processing unless it demonstrates compelling legitimate grounds or the processing is necessary for legal claims.
Withdrawal of consent: Consent may be withdrawn at any time without giving reasons. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
Rights relating to automated decision-making: For the processing activities described in this Notice, the Controller does not make decisions based solely on automated processing that produce legal effects concerning the data subject or similarly significantly affect them.
15. Submission and handling of data subject requests
A data subject may submit a request by any of the following methods:
- by post: 10 Munkácsy Mihály Street, 2151 Fót, Hungary;
- by email: office@brandfood.hu;
- by telephone: +36 70 622 62 99.
Before acting on a request, particularly where reasonable doubts exist, the Controller may request additional information necessary to verify the identity of the data subject and the legitimacy of the request. Only information necessary for verification will be requested.
The Controller will inform the data subject of the action taken without undue delay and in any event within one month of receiving the request. That period may be extended by a further two months where necessary, taking into account the complexity and number of requests; the Controller will provide notice of the extension and the reasons for it within one month.
Requests are generally handled free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, the Controller may charge a reasonable fee or refuse to act on the request.
16. Data security and personal data breaches
The Controller protects personal data by implementing technical and organisational measures appropriate to the risks of processing. These measures are intended in particular to:
- prevent unauthorised access, alteration, disclosure or erasure;
- maintain the confidentiality, integrity and availability of data;
- restrict and regularly review access rights;
- provide reasonable protection for systems and communication channels and use backups and logging;
- detect, investigate, document and manage personal data breaches.
In the event of a personal data breach, the Controller assesses the risk in accordance with the GDPR. Where the breach is likely to result in a risk to the rights and freedoms of natural persons, the Controller will notify the supervisory authority without undue delay and, where feasible, within 72 hours. Where the risk is high, the affected data subjects will also be informed unless an exception under the GDPR applies.
17. Personal data of minors
The website and the Controller’s services are not specifically intended for children. The Controller does not knowingly collect consent-based personal data from persons under the age of 16 without the involvement of their legal representative. If the Controller becomes aware of such processing, it will take the necessary steps to erase the data or establish an appropriate legal basis.
18. Complaints and legal remedies
The Controller asks data subjects to submit any data protection question or complaint first to office@brandfood.hu so that the Company can investigate and resolve the matter.
A data subject has the right to lodge a complaint with the supervisory authority:
|
Name of authority |
Hungarian National Authority for Data Protection and Freedom of Information (NAIH) |
|
Registered office |
9–11 Falk Miksa Street, 1055 Budapest, Hungary |
|
Postal address |
P.O. Box 9, 1363 Budapest, Hungary |
|
|
ugyfelszolgalat@naih.hu |
|
Telephone |
+36 1 391 1400 |
|
Website |
https://www.naih.hu/ |
A data subject may also bring court proceedings if their rights have been infringed. At the data subject’s choice, proceedings may be commenced before the competent regional court for the Controller’s registered office or for the data subject’s place of residence or, failing that, place of stay. The court will hear the case as a matter of priority.
19. Amendments to this Notice
The Controller may amend this Notice, in particular following changes in legislation or regulatory practice, the introduction of a new service or processor, or changes to the technical operation of the website. The version currently in force is available on the website.
If the website’s actual cookie or service settings change, the Controller will also update the cookie management interface and the relevant sections of this Notice.
20. Final provisions
This Privacy Notice is effective from 31 July 2026.
The Controller reserves the right to provide a separate privacy notice for specific processing activities, for example in connection with a particular campaign, event, application procedure, job advertisement or the introduction of a new online function. In such cases, the separate notice will take precedence in relation to the relevant processing activity.
Brand Food Zrt.
10 Munkácsy Mihály Street, 2151 Fót, Hungary
office@brandfood.hu | +36 70 622 62 99