PRIVACY
NOTICE

Brand Food Zártkörűen Működő Részvénytársaság

https://brandfood.hu/

Effective from: 31 July 2026

 

 

1. Introduction and scope of this Notice

Brand Food Zártkörűen Működő Részvénytársaság (hereinafter referred to as the “Controller”, the “Service Provider” or the “Company”) respects the privacy of natural persons and processes their personal data in accordance with the applicable data protection legislation.

The purpose of this Notice is to provide transparent information about the processing of personal data in connection with the use of the https://brandfood.hu/ website, contact with the Controller, business communications and the Controller’s presence on LinkedIn.

The processing of personal data is governed in particular by Regulation (EU) 2016/679 of the European Parliament and of the Council (the “GDPR”), Act CXII of 2011 on Informational Self-Determination and Freedom of Information (the “Hungarian Privacy Act”), Act CVIII of 2001 on Electronic Commerce and Information Society Services (the “E-commerce Act”), and Act C of 2003 on Electronic Communications.

This Notice applies to the processing of personal data on the following website:

https://brandfood.hu/

The intended publication address of this Notice is:

https://brandfood.hu/adatkezelesi-tajekoztato/

Amendments to this Notice shall take effect upon publication at the above address. Where reasonably possible, the Controller will provide a separate notice on the website about material changes.

2. Details and contact information of the Controller

Full registered name

Brand Food Zártkörűen Működő Részvénytársaság

Short name

Brand Food Zrt.

Registered office

10 Munkácsy Mihály Street, 2151 Fót, Hungary

Company registration number

13-10-042139

Tax number

28956093-2-13

Email

office@brandfood.hu

Telephone

+36 70 622 62 99

Website

Főoldal

 

Data protection enquiries, data subject requests and complaints may be submitted using the postal address, email address or telephone number stated above.

3. Definitions

“personal data”: any information relating to an identified or identifiable natural person (the “data subject”).

“processing”: any operation performed on personal data or sets of personal data, whether or not by automated means, including in particular collection, recording, organisation, storage, alteration, retrieval, use, transmission, restriction, erasure or destruction.

“controller”: the person or organisation that determines the purposes and means of processing personal data.

“processor”: the person or organisation that processes personal data on behalf of the Controller.

“recipient”: the person or organisation to whom personal data is disclosed.

“consent”: any freely given, specific, informed and unambiguous indication of the data subject’s wishes.

“personal data breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

“profiling”: a form of automated processing of personal data used to evaluate personal aspects relating to a natural person.

4. Principles relating to the processing of personal data

The Controller processes personal data in accordance with the following principles:

The Controller processes only personal data that is necessary for the relevant purpose and retains it only for as long as necessary. The Controller applies appropriate technical and organisational measures to protect the security of the personal data processed.

5. Contact enquiries and their handling

A data subject may contact the Controller by email, by telephone, using the contact details displayed on the website or, where available, through a contact form.

Personal data processed

Purpose of processing

Legal basis

Retention period

name and company name

identification and addressing the data subject

Article 6(1)(a) GDPR – consent; for requests for quotations, pre-contractual steps under Article 6(1)(b) GDPR

no more than 2 years after the enquiry is closed

email address and telephone number

communication and responding to the enquiry

Article 6(1)(a) or (b) GDPR

no more than 2 years after the enquiry is closed

content of the message, question or request for a quotation

responding to the enquiry and preparing a quotation

Article 6(1)(a) or (b) GDPR

no more than 2 years after the enquiry is closed; in the event of a legal dispute, until the claim becomes time-barred

additional data provided voluntarily

fulfilling the data subject’s request

Article 6(1)(a) GDPR

until the purpose has been achieved, but no longer than 2 years

 

Providing personal data is voluntary; however, without the information necessary for communication, the Controller may be unable to respond to the enquiry. Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before its withdrawal.

6. Requests for quotations, business negotiations and contractual relationships

Where an enquiry leads to a request for a quotation or to the establishment of a supplier, customer or other business relationship, the Controller processes the data of the data subject and the partner’s contact persons for the preparation and performance of that business relationship.

Personal data processed

Purpose

Legal basis

Retention period

name, job title and representative capacity

identifying the business partner and the contact person

Article 6(1)(b) GDPR; for a contact person of a legal entity, Article 6(1)(f) GDPR – legitimate business interests

for unsuccessful negotiations, no more than 2 years; where a contract is concluded, 5 years after the end of the relationship

business email address and telephone number

business communications

Article 6(1)(b) or (f) GDPR

5 years after the end of the relationship

quotation, order, contract and related communications

conclusion and performance of a contract and enforcement of claims

Article 6(1)(b) and (f) GDPR

5 years from termination of the contract

invoicing and accounting data

compliance with legal and accounting obligations

Article 6(1)(c) GDPR

accounting documents are retained for at least 8 years

 

The legitimate interests pursued are maintaining the Controller’s business relationships, performing contracts, communicating with business partners and establishing, exercising or defending legal claims. A data subject has the right to object, on grounds relating to their particular situation, to processing based on legitimate interests.

7. Technical operation of the website and log data

When the website is visited, the hosting provider’s systems may record technical data in order to ensure operation of the service, identify faults, maintain IT security and prevent misuse.

Personal data processed

Purpose

Legal basis

Retention period

IP address, time of the request, page visited, technical browser and device data, error logs and security logs

operation of the website, troubleshooting and detection of attacks and misuse

Article 6(1)(f) GDPR – legitimate interest in secure and continuous operation

in accordance with the technical settings of the service, generally no more than 90 days; in the event of an incident, until the related procedure is closed

 

A data subject does not have to provide personal data separately merely to view the website. Server logs may be accessed by the Controller, the hosting provider and authorised IT service providers.

8. Cookies and similar technologies

A cookie is a small data file that a website may place on a visitor’s device. Cookies may be session cookies, which are deleted when the browser is closed, or persistent cookies, which remain on the device for a specified period.

Cookie category

Purpose

Legal basis

Typical duration

strictly necessary cookies

essential operation of the website, security, load balancing and storage of consent choices

Article 6(1)(f) GDPR and Section 13/A(3) of the E-commerce Act; consent is not required

for the session or for the period necessary for the technical purpose

functional cookies

remembering the visitor’s choices and settings

Article 6(1)(a) GDPR – consent

as specified in the cookie settings

statistical/analytics cookies

measuring traffic and use of the website and improving the service

Article 6(1)(a) GDPR – consent

generally from a few minutes up to 2 years

marketing cookies

measuring advertising performance, conversion tracking, personalisation or remarketing

Article 6(1)(a) GDPR – consent

as specified in the cookie settings, typically from a few days up to 2 years

 

Non-essential cookies may be activated only after the data subject has given prior consent. Consent may be withdrawn or changed at any time through the cookie settings interface. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

The names, providers, purposes and expiry periods of the cookies actually used on the website can be viewed in the cookie management interface. Cookies may also be deleted or disabled in the browser, although doing so may limit the operation of certain functions.

9. Google Analytics

Where Google Analytics is active on the website, the Controller uses it to compile aggregated statistics about website traffic and usage. The service may place or read non-essential cookies only after the data subject has consented to analytics.

Provider

Personal data processed

Purpose and legal basis

Retention

Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland

online identifiers (e.g. client ID), technical information derived from the IP address, device and browser data, pages viewed, events, referring page and timestamps

website traffic statistics and service improvement; Article 6(1)(a) GDPR

depending on the configuration; user-level data is generally retained for no more than 14 months and some cookies for up to 2 years

 

The Controller configures Google Analytics in accordance with the principle of data minimisation. Google may also process data under its own terms and may use processors located outside the European Economic Area. Safeguards for transfers may include, in particular, an adequacy decision, the EU-U.S. Data Privacy Framework or the standard contractual clauses adopted by the European Commission.

Google Privacy Policy: https://policies.google.com/privacy

Google Analytics Opt-out Browser Add-on: https://tools.google.com/dlpage/gaoptout?hl=en

10. Google Ads conversion tracking and Consent Mode

Where the Controller uses Google Ads and conversion tracking, the purpose of the service is to measure whether a visitor who clicked on an advertisement completed a specified action on the website. Cookies used for marketing and advertising purposes may be activated only with the data subject’s consent.

Personal data processed

Purpose

Legal basis

Retention

online and cookie identifiers, advertisement click data, technical data relating to the visit and conversion event, and technical information associated with the IP address

conversion measurement, assessing campaign performance and, where consent is given, remarketing and personalised advertising

Article 6(1)(a) GDPR – consent

in accordance with Google’s and the cookie manager’s settings, for no longer than the specified lifetime of the relevant cookie

 

Google Consent Mode v2 may control, in accordance with the visitor’s choices, consent signals including analytics_storage, ad_storage, ad_user_data and ad_personalization. The ad_user_data signal governs the transfer of user data to Google for advertising purposes, while ad_personalization governs the use of data for personalised advertising.

The data subject may withdraw or change consent at any time through the cookie management interface. Google’s privacy terms also apply to Google services and any transfers of data to third countries.

11. Presence on LinkedIn

The Controller may operate a LinkedIn page or profile to present its services, products and professional activities and to communicate with prospective customers and business partners.

Personal data processed

Data subjects and purpose

Legal basis

Retention

public profile data, name, profile picture, job title, reactions, comments, shares, messages and any further data voluntarily provided by the data subject

persons who follow, interact with or message the Controller’s page; communications, contact and presentation of services

Article 6(1)(a) GDPR; for direct enquiries or business relationships, Article 6(1)(b) or (f) GDPR

until the interaction is deleted or consent is withdrawn; for message exchanges, no more than 2 years, and for contractual matters, for the applicable retention period

 

LinkedIn is operated by LinkedIn Ireland Unlimited Company (Wilton Place, Dublin 2, Ireland), which acts as an independent controller in respect of its own processing activities. LinkedIn may also generate statistical and analytical data about visitors and may transfer data outside the European Economic Area in accordance with its own privacy terms.

LinkedIn Privacy Policy: https://www.linkedin.com/legal/privacy-policy

A data subject may delete their own comments, reactions or messages on LinkedIn and may also contact the Controller using the contact details provided in this Notice. In relation to processing carried out independently by LinkedIn, data subject rights may also be exercised directly with LinkedIn.

12. Processors used by the Controller

12.1. Hosting and related IT services

Full registered name

Rackforest Informatikai Kereskedelmi Szolgáltató és Tanácsadó Zártkörűen Működő Részvénytársaság

Short name

Rackforest Zrt.

Registered office

11 Victor Hugo Street, 5th floor, B05001, 1132 Budapest, Hungary

Company registration number

01-10-142004

Tax number

32056842-2-41

Email

info@rackforest.hu

Telephone

+36 1 211 0044

Website

IT szenvedéllyel – RackForest

Processing activity

provision of web hosting, servers and related IT infrastructure; storage, backup and technical hosting of data processed through the website

Duration of processing

for the duration of the service relationship between the Controller and the processor and in accordance with the applicable backup and deletion rules

 

Rackforest Zrt. acts on the Controller’s documented instructions and within the framework of the data processing agreement. The legal basis for the underlying processing between the Controller and the data subject also determines the legal basis for processing by the processor; Article 28 GDPR applies to the processor’s involvement.

12.2. External platform providers

Depending on the nature of the services they provide, Google and LinkedIn may act as independent controllers, joint controllers or processors. When using individual services, the Controller applies the necessary contractual and technical safeguards and makes non-essential processing conditional on consent.

If the Controller appoints a new processor in the future or the functions of the website change materially, this Notice will be updated.

13. Data transfers, recipients and third countries

The Controller transfers personal data only where an appropriate legal basis exists and the transfer is necessary for the relevant processing purpose. Recipients of personal data may include:

When responding to a request from a public authority, the Controller discloses only data that has been lawfully requested and is necessary for the purpose of the request.

The use of Google and LinkedIn services may involve transfers of data outside the European Economic Area. In such cases, the relevant provider and the Controller apply appropriate safeguards under Chapter V GDPR, including an adequacy decision, the EU-U.S. Data Privacy Framework or the standard contractual clauses adopted by the European Commission.

14. Rights of data subjects

Under the GDPR, a data subject may exercise the following rights:

Right of access: The data subject may request confirmation as to whether the Controller processes their personal data and may request access to the data processed and to information about the purposes, legal bases, recipients and duration of processing.

Right to rectification: The data subject may request the correction of inaccurate personal data and the completion of incomplete data.

Right to erasure: The data subject may request the erasure of their personal data where the purpose of processing has ceased, consent has been withdrawn, processing is unlawful or another condition under the GDPR is met. Erasure cannot be required where processing is necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims.

Right to restriction of processing: The data subject may request restriction of processing, in particular where they contest the accuracy of the data, the processing is unlawful or the data is required for the establishment, exercise or defence of legal claims.

Right to data portability: For automated processing based on consent or a contract, the data subject may request to receive personal data concerning them that they have provided in a structured, commonly used and machine-readable format, or to have such data transmitted to another controller where technically feasible.

Right to object: The data subject may object, on grounds relating to their particular situation, to processing based on legitimate interests or the performance of a task carried out in the public interest. The Controller will then cease processing unless it demonstrates compelling legitimate grounds or the processing is necessary for legal claims.

Withdrawal of consent: Consent may be withdrawn at any time without giving reasons. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

Rights relating to automated decision-making: For the processing activities described in this Notice, the Controller does not make decisions based solely on automated processing that produce legal effects concerning the data subject or similarly significantly affect them.

15. Submission and handling of data subject requests

A data subject may submit a request by any of the following methods:

Before acting on a request, particularly where reasonable doubts exist, the Controller may request additional information necessary to verify the identity of the data subject and the legitimacy of the request. Only information necessary for verification will be requested.

The Controller will inform the data subject of the action taken without undue delay and in any event within one month of receiving the request. That period may be extended by a further two months where necessary, taking into account the complexity and number of requests; the Controller will provide notice of the extension and the reasons for it within one month.

Requests are generally handled free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, the Controller may charge a reasonable fee or refuse to act on the request.

16. Data security and personal data breaches

The Controller protects personal data by implementing technical and organisational measures appropriate to the risks of processing. These measures are intended in particular to:

In the event of a personal data breach, the Controller assesses the risk in accordance with the GDPR. Where the breach is likely to result in a risk to the rights and freedoms of natural persons, the Controller will notify the supervisory authority without undue delay and, where feasible, within 72 hours. Where the risk is high, the affected data subjects will also be informed unless an exception under the GDPR applies.

17. Personal data of minors

The website and the Controller’s services are not specifically intended for children. The Controller does not knowingly collect consent-based personal data from persons under the age of 16 without the involvement of their legal representative. If the Controller becomes aware of such processing, it will take the necessary steps to erase the data or establish an appropriate legal basis.

18. Complaints and legal remedies

The Controller asks data subjects to submit any data protection question or complaint first to office@brandfood.hu so that the Company can investigate and resolve the matter.

 

 

A data subject has the right to lodge a complaint with the supervisory authority:

Name of authority

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)

Registered office

9–11 Falk Miksa Street, 1055 Budapest, Hungary

Postal address

P.O. Box 9, 1363 Budapest, Hungary

Email

ugyfelszolgalat@naih.hu

Telephone

+36 1 391 1400

Website

https://www.naih.hu/

 

A data subject may also bring court proceedings if their rights have been infringed. At the data subject’s choice, proceedings may be commenced before the competent regional court for the Controller’s registered office or for the data subject’s place of residence or, failing that, place of stay. The court will hear the case as a matter of priority.

19. Amendments to this Notice

The Controller may amend this Notice, in particular following changes in legislation or regulatory practice, the introduction of a new service or processor, or changes to the technical operation of the website. The version currently in force is available on the website.

If the website’s actual cookie or service settings change, the Controller will also update the cookie management interface and the relevant sections of this Notice.

20. Final provisions

This Privacy Notice is effective from 31 July 2026.

The Controller reserves the right to provide a separate privacy notice for specific processing activities, for example in connection with a particular campaign, event, application procedure, job advertisement or the introduction of a new online function. In such cases, the separate notice will take precedence in relation to the relevant processing activity.

Brand Food Zrt.
10 Munkácsy Mihály Street, 2151 Fót, Hungary
office@brandfood.hu  |  +36 70 622 62 99