Privacy Policy

1.      Legal Provisions Governing Data Processing

The following laws apply to the processing of customer data:

2.      Definitions

Data Controller (plural: Data Controllers): the natural or legal person who, in the course of owning, managing, storing, ensuring the operational conditions, maintaining, or programming the Website or third-party elements integrated into the Website, gains access to personal data provided by Users. The Data Controller may be the primary controller or a third party.

  1. Primary data controller: Website owner;
  2. Third-party data controller: a natural or legal person performing data processing tasks on behalf of the Website Owner.

Data medium: a device capable of recording digital files in the form of electrical signals that can be read by a computer.

Third-Party Data Controller: the group of data controllers that, under a contractual agreement with the Website Owner, provides services related to ensuring operational conditions, maintenance, programming, upkeep, data collection, and data storage.

Web browser: the program run by the User on the Device, which the User uses to visit the Website and navigate the site.

User (plural: Users; for clarity: Website User): the natural or legal person(s) who visits the Website using a Web Browser running on their Device(s). A User shall be deemed to include any an information technology specialist or other type of assistant, acting with or without compensation, who is presumed to be knowledgeable about the configuration of the Device and/or Web Browser, and whom the User has entrusted with configuring the Device or Web Browser owned or used by the User. The User remains responsible for the correct configuration of the Device and Browser even if this was done through an authorized representative.

Written Request: For the purposes of this Notice, a “written request” includes: a letter sent by mail or courier service, or delivered in person or by an authorized representative; an open postcard; a telegram; or an email. The following do not qualify as written requests: text messages (short text messages sent from a mobile, nomadic, or landline telephone), or messages sent via a chat program or interface.

Device (plural: Devices): the electrically powered device and its accessories that the User uses to visit the Website. For the purposes of visiting the Website, Devices can be classified by type into mobile and desktop devices; this classification is used—for statistical purposes—in connection with anonymous data related to browsing while visiting the Website.

Identifiable data: data that can be linked to a specific User and that contains any one of the following pieces of information individually, or a combination of several of the following:

  1. the User’s real name,
  2. the real name of the User’s minor or juvenile child, as well as any data of the minor or juvenile child that, based on this definition, applies to the adult User and is specified in points 1 and 3–12 of this definition and is unambiguously linked to that person,
  3. the User’s address of residence, place of stay, registered office, or business location,
  4. the User’s mailing address,
  5. the User’s email address,
  6. any identifier assigned to the User by any Hungarian or foreign government authority, consisting of a combination of numbers and letters (e.g., personal identification number, identification document number, etc.),
  7. the User’s landline, mobile, or pager number,
  8. the name of the User’s employer and the employer’s contact information,
  9. the User’s alias used for online login (known in English as a “nickname” and commonly referred to as a “username”),
  10. the User’s password used for online login, in plaintext or encrypted form,
  11. a digital image of the User’s handwritten signature or a copy of it in image format,
  12. the User’s authentic electronic signature.

Anonymous data: data that is explicitly anonymous. Any set of data linked to a User’s identity that does not contain the data specified in the definition of identified data.

Record: the totality of data pertaining to a single User that contains multiple data points.

Verbal request: as defined in this Notice, any request made in person or via telecommunications that does not fall under the category of written requests.

Web Hosting: For the purposes of this Notice, a unit consisting of the combination of electrical and information technology, hardware, and software capable of remotely accessing a website, on which the Web Hosting Provider provides an environment suitable for operating the Website. The geographic location of the Web Hosting is Budapest, Hungary.

Web Hosting Provider: For the purposes of this Notice, the business entity or company that provides web hosting as a product to the Website Owner.

Website Owner: For the purposes of this Notice, the natural or legal person designated as the Website Owner in the detailed description of this Notice.

Website: For the purposes of this Notice, the digital platform accessible at the URL https://rebaco.hu/, which provides information about the activities of Rebaco Kft. and is available on the public international network (the Internet). The following are considered elements of the Website: the source code of the Website’s script files and the MySQL database storing variable elements.

Website visit (session), as an abstract concept: Website visit: the User’s activity during which they arrive at the Website, browse among its pages, and then leave the Website.

Webmaster: the business entity detailed below that assumes responsibility, on behalf of the Website Owner, for the integrity and functionality of the Website’s code.

3.      Data Controller

Primary Data Controller and Website Owner:

Name: Rebaco Construction Limited Liability Company

Registered office: 1203 Budapest, Közműhelytelep Street 28, Building A, Ground Floor, Unit 5

Representative: Balázs Kovács

Phone number: +36 20 347 5029

3.1.            Third-party data processors

3.1.1.                   Web hosting provider

Grafcom Media Kft. will provide this information after the hosting order is placed.

Company name: Tenweb, Inc.

Address: 40 E Main Street, Suite 721, Newark, DE 19711, United States

Tax ID:

Email: info@10web.io

Data processed: anonymous data related to browsing.
The service provider’s privacy policy in English: https://10web.io/privacy-policy/

3.1.2.                   Anonymous measurement of user behavior (Google web analytics service)

This includes all anonymous visitor tracking providers whose tracking codes have been placed on the website. In Central Europe, the service provided by Google Ireland Ltd. is generally used.

Name: Google Ireland Limited

Headquarters: Gordon House, Barrow Street, Dublin 4 (Ireland)

Company registration number: 368047

Scope of data processed: anonymous data related to browsing, which is listed in detail in Google Ireland Limited’s privacy policy.

Google Ireland Limited’s Privacy Policy in Hungarian

4.      The scope of data collected while using the website and the purposes of data processing are detailed

4.1.            Anonymous data collected for statistical purposes related to browsing

4.1.1.                   Data Controller

The data controllers are Google Ireland Limited (Ireland) and the Website Owner jointly.

4.1.2.                   Source of the data

The source of the data is the data recorded as a result of the User’s visit to the Website.

4.1.3.                   Scope of data

  1. the public IP address of the Device used for browsing,
  2. the user agent identifier of the web browser used for browsing: this identifier provides information about the type of device (desktop or mobile), the device’s operating system, the web browser type, and the web browser version number,
  3. the User’s browsing activity on the site from the moment they arrive until they close or leave the site,
  4. the classification of the User’s Device by type,
  5. GPS location,
  6. data from the Device’s sensor(s).

4.1.4.                   The purpose of using this data is

  1. an anonymous, quantitative analysis of the number of Users,
  2. an anonymous, statistical analysis of the quality classification of the Devices used by Users,
  3. an anonymous, statistical analysis of the geographic location of Users,
  4. an anonymous, quantitative analysis of visits to individual subpages of the Website,
  5. an anonymous, numerical analysis of Website traffic,
  6. an anonymous, factual record of user activity on the Website hosted on the Web Hosting Service (system log).

4.1.5.                   Data Retention Policy

Google Ireland Limited retains data regarding visits to the Website in accordance with the terms of service provided to the Website owner. Detailed information regarding data retention policies is provided in Google Ireland Limited’s Privacy Policy.

4.2.            Cookies

Cookies (singular: cookie; plural: cookies) are small information files placed in the directory or folder where the User’s browser stores temporary files while using the Website; they contain the settings specified by the User for the website.

The purpose of using cookies is:

  1. to facilitate the User’s future browsing. If the User blocks or disables cookies, the User will not be able to take advantage of the services provided by cookies that facilitate browsing during subsequent visits to the Website.
  2. to collect anonymous data for the Website Owner regarding Users’ browsing habits on the Website and the number of Users visiting the Website. If a User disables the use of these cookies, they may continue browsing the Website without interruption; however, the Website Owner will not be informed of the User’s browsing activity on the Website. The Website Owner is not entitled to place Users who disable cookies used to track browsing habits at any disadvantage.

The Website’s own code does not directly place cookies on the User’s computer.

The independent system embedded in the Website’s code (the service provider(s) listed in Section 3.1.3 should be specified here) retains the User’s settings; in this regard, the cookie policy of MotiBro Kft. applies. (Here, reference should again be made to the external service provider’s privacy policy or other equivalent legal statement.)

With regard to the Google web analytics code installed on the Website, the data retention policies of Google Ireland Limited (Ireland) apply.

5.      Access to Data and Data Security Measures

5.1.            Access to Data and Data Transfer

The Data Controller’s employees may access the personal data you provide in order to perform their duties.

The Data Controller may disclose the processed personal data to the third parties listed in Section 3.1 of this Notice, in accordance with individual contracts or publicly available general terms and conditions, for the purposes of performing its own duties and maintaining the Website, ensuring its operational security, operating the web server, and preserving the integrity of the data.

The Data Controller may disclose personal data to organizations not listed in Section 3.1 of this Notice in exceptional cases specified by law. Such cases include, for example,

  1. if legal proceedings are initiated against the User and the presiding court requires the transfer of the User’s personal data,
  2. if the competent investigative authority requests the disclosure of the User’s personal data for investigative purposes.

5.2.            Data Security Measures

The Website Owner may store the User’s personal data related to the Website in the following locations:

  1. on the web hosting server,
  2. on a data storage medium owned by the Website Owner and inaccessible to others,
  3. on a data storage medium connected to a computer owned by the Website Owner’s business entity or its members and inaccessible to others,
  4. on a remote server individually owned by the third-party data controllers mentioned in Section 3.1, to which both the third-party data controller company and the Website Owner have access,
  5. on a data storage medium owned by the third-party data controller, to which the third-party data controller has exclusive access.

The Website Owner, as the Data Controller, and third-party Data Controllers acting on behalf of the Website Owner shall take appropriate measures to ensure that:

  1. unauthorized persons do not gain access to personal data or data related to an individual, whether identified or unidentified,
  2. personal or personally identifiable data, whether identified or unidentified, is not altered by unauthorized persons,
  3. personal or personally identifiable data, whether identified or unidentified, can be restored to their original state or a state as close as possible to the original in the event of a technical failure, malfunction, or damage to the data at their original location.

6.      The User’s Rights Regarding Data Processing

6.1.            The User’s Right of Access and Information

As the data subject, the User has the right to access their personal data.

If the User requests confirmation from the Data Controller as to whether the Data Controller is processing the User’s personal data, the Data Controller is obligated to provide information regarding the following:

  1. What personal data the Data Controller processes,
  2. the legal basis on which the Data Controller processes the personal data,
  3. For what purposes the Data Controller processes the personal data,
  4. The sources from which the Data Controller obtains the personal data,
  5. How long the Data Controller processes the personal data.

The User has the right to be informed by the Data Controller as to whether or not the Data Controller processes the User’s personal data (hereinafter: the right to information). The User’s right to information

  1. extends to identified personal data,
  2. does not extend to non-identified data that can be linked to a specific individual,
  3. does not extend to identified or unidentified personal data pertaining to other Users,
  4. and includes pseudonymized data that can be unambiguously linked to the User in question.

Upon the User’s request, Data Controllers shall provide access to and a copy of the User’s personal data via their online platform. If the User does not wish to use the online platform, Data Controllers may charge a reasonable processing fee for the disclosure of the data.

The User must notify the Data Controllers in writing of any request falling within the scope of exercising their rights of access and information regarding their data if the User does not wish to or is unable to use the online platforms provided by the Data Controllers, or if the online platforms are not suitable for the User to exercise their rights.

6.2.            The User’s Right to Rectification

The User has the right to have their personal, identified data rectified.

The User’s right to rectification

  1. does not extend to non-identifiable data linked to the User’s person,
  2. applies exclusively to identified data linked to the User’s own person,
  3. does not extend to identified data linked to other Users,
  4. and includes pseudonymized data that can be unambiguously linked to the User.

Data controllers will correct or supplement the User’s personal data solely upon the User’s written request.

6.3.            The User’s Right to Erasure

Under certain conditions, the User is entitled to request the erasure of their personal data. The basis for exercising this right is a written request from the User.

Data controllers, individually and jointly, are obligated to erase the User’s data without undue delay if:

  1. the Data Controller processes such personal data,
  2. the User requests the erasure of their personal data, and
  3. the personal data is no longer necessary for the purposes for which the Data Controller processes the personal data.

Data controllers are individually and jointly obligated to erase the User’s data without undue delay if:

  1. the Data Controller processes the User’s personal data,
  2. the User requests the erasure of their personal data,
  3. the User withdraws their consent, which serves as the legal basis for the processing of their data, and
  4. there is no other legal basis for processing the User’s data.

Data controllers are individually and jointly obligated to erase the User’s data without undue delay if:

  1. the processing is necessary to protect the legitimate interests of the Data Controllers or a third party, and
  2. the User objects to the Data Controller’s processing of their personal data and
  3. the legitimate grounds for processing such personal data do not override the User’s objection.

Data Controllers are individually and jointly obligated to erase the User’s data without undue delay if:

  1. the User requests the erasure of their data and
  2. the processing of the data by the Data Controller is not unlawful, or
  3. the erasure is required by applicable law, or
  4. the User’s data is collected in connection with information society services.

The basis for exercising the right to erasure is the User’s written request.

6.4.            The User’s Right to Restriction of Data Processing

The User has the right to request the restriction of the processing of their data.

The User’s right to request the restriction of the processing of their personal data

  1. does not extend to anonymous data,
  2. applies exclusively to personal data relating to the User,
  3. does not extend to personal data relating to other Users,
  4. and includes pseudonymized data that can be unambiguously linked to the User.

The Data Controller shall restrict the processing of the User’s personal data during the period in which it verifies the accuracy of such data, if the User requests the restriction of the processing of their personal data and the User disputes the accuracy of their data.

The Data Controller shall restrict the processing of the User’s personal data if the User requests the restriction of the processing of data that is being processed unlawfully and the User objects to the erasure of such data.

The Data Controller shall restrict the processing of the User’s personal data if:

  1. the User requests the restriction of the processing of their personal data and
  2. the Data Controller no longer needs the User’s personal data for the purposes of data processing, and
  3. the User requests the restriction of the data for the purpose of asserting, exercising, or defending legal claims.

The Data Controller shall restrict the processing of the User’s personal data if:

  1. the User objects to the processing of their personal data that is necessary for the legitimate interests of any of the Data Controllers or all of them together, and
  2. the User is awaiting confirmation as to whether there is a lawful basis for the Data Controller’s processing of the User’s personal data that takes precedence over the User’s objection.

If the Data Controllers, individually or jointly, restrict the processing of the User’s data, the Data Controllers, individually or jointly, are entitled to:

  1. store the User’s personal data,
  2. process the User’s personal data based on the User’s consent,
  3. process the User’s personal data to assert, exercise, or defend a legal claim, or to protect the rights of another person.

The basis for exercising the right to restrict data processing is a written request from the User.

6.5.            The User’s Right to Data Portability

The User has the right to receive the personal data concerning him or her, which the User has provided to a Data Controller, in a structured, commonly used, and machine-readable format.

The User is also entitled to have their personal data—with their consent—transferred to a data controller designated by the User, provided that the data processing is carried out by automated means.

The User’s right to data portability:

  1. does not extend to anonymous data,
  2. applies exclusively to the User’s specified personal data,
  3. does not extend to the personal data of other Users,
  4. does not extend to data that has been clearly pseudonymized.

6.6.            Forms of Exercising the User’s Rights

The User is entitled to exercise their rights regarding the processing of their data in both explicit and implicit forms.

An implicit form of exercising these rights is when the User configures the settings of the Browser and/or the Device in such a way as to prevent or prohibit the transmission or collection of data. In this case, the User is not required to notify the Website Owner or the Data Controllers.

Exercising these rights is considered an explicit form of doing so if the User:

  1. submits a written request to the Website Owner or the Data Controllers to exercise their rights, in accordance with the formal requirements set forth in this Privacy Notice,
  2. where possible, authorizes the Website Owner and the Data Controllers jointly to process the data via the online interface. On the online platform, the data collection interface (form) must clearly indicate in text which element is required for the User to express consent, as well as how the User may express consent or refuse consent by interacting with that element. The element used to express the User’s consent must be programmed such that, if the User consents, the data is transmitted; if the User refuses to consent, the data is not transmitted in any form.

With regard to the explicit exercise of rights via the online interface, if the User refuses to give consent to data processing, the User will forfeit access to online services that require personal data, for which data is collected and transmitted on the Website.

With regard to anonymous data linked to the User as an individual, the Website Owner is not entitled to cause any legal disadvantage to the User if the User does not expressly exercise their right to data collection and data transmission.

Due to technical limitations, the following adverse consequences may occur for the User if the User engages in activities with the Device or Browser that do not explicitly prohibit or restrict such actions:

  1. the User’s settings regarding the display and use of the Website will not be retained, and the User will be forced to re-enter them each time they visit the Website;
  2. unwanted changes may occur in the Website’s text or visual elements.

The Website Owner and the Data Controllers assume no liability, either individually or jointly, for any settings on the Device or in the Browser that express no explicit prohibition or restriction by the User.

6.7.            Form of the User’s Requests and Processing Deadlines

The Data Controllers shall respond to written requests from the User regarding the rights specified in Sections 6.1–6.5 of this Notice without undue delay, but no later than within 1 month.

The written request must include:

  1. the User’s real name,
  2. at least two additional pieces of information about the User that allow the Data Controller to identify the data record associated with the User,
  3. the User’s unambiguous request regarding their own personal data,
  4. a justification for the request to exercise rights is not a required element of the written request.

If it cannot be clearly determined based on the written request which data unit (record) containing personal data includes the User’s data, the Data Controller is entitled to request additional data from the User in writing, drawn from the scope of the processed data.

If the User’s intent regarding the processing of their data cannot be clearly determined based on the written request, the Data Controller is required to request clarification or specification of the request in writing from the User.

For security reasons, Data Controllers are unable to accept verbal requests.

6.8.            The User’s Right to File a Complaint

If the User believes that their rights have been violated, the Data Controllers, individually and jointly, recommend that the User initiate a consultation by contacting the Data Controllers directly. If such a discussion does not yield a resolution, or if the User does not wish to participate in such a process, the User may turn to the court or the National Authority for Data Protection and Freedom of Information (NAIH). If initiating court proceedings, the User may choose to file the case with the court having jurisdiction over their address or place of residence.

The NAIH’s contact information is as follows: 1125 Budapest, Szilágyi Erzsébet fasor 22/c.; phone: +36 1 391 1400; fax: +36 1 391 1410; email: ugyfelszolgalat@naih.hu; website: naih.hu

7.      Amendments to this Notice

The data controllers reserve the right to jointly amend this notice at any time. The data controllers will notify Users of such amendments by email, if applicable, and in all cases in accordance with applicable laws.