Privacy and data processing policy
Purpose of the Policy
The purpose of this Policy is to define the principles and rules of data protection and data processing applied by 2.8 Rental Filmtechnikai Szolgáltató Kft. (hereinafter: Service Provider), as well as to set out the Service Provider's data protection and data processing policy.
The Service Provider processes the data of customers who order rentable equipment through the website www.2point8rental.com (hereinafter: Website). Only individuals acting within their professional capacity, independent occupation, or business activity, representatives of legal entities, and sole proprietors may register on the Website (hereinafter collectively: Businesses). The data of Businesses are public due to public interest; however, during the ordering process, the registering Business may also provide personal data. Therefore, the Service Provider ensures compliance with all legal requirements related to the processing of personal data.
This Policy has been designed and is applied in compliance with Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (hereinafter: Infotv.), Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (hereinafter: Ekertv.), and Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR).
In the event of changes to the services provided by the Service Provider or to the General Terms and Conditions (hereinafter: GTC), the Service Provider may notify users of these changes electronically via email. These notifications will not be used for advertising purposes.
Data Controller Information
Name: 2.8 Rental Filmtechnikai Szolgáltató Kft.
Registered Office: 1112 Budapest, Dayka Gábor utca 60. II. em. 8.
Company Registration Number: 01-09-272417
Tax Number: 25390793-2-43
Electronic Contact: hello@2point8rental.com
Bank Account Number: Raiffeisen Bank 12010240-01530482-00100008
Registering Authority: Metropolitan Court of Registration
Data Processing Activities on the Website
1. Placing an Order
Purpose of Data Processing: To establish contact with the User via confirmation email.
Processed Data: Name of individual or business, business email address, other data provided by the User in the message box.
Legal Basis: User consent, performance of contract.
Data Retention Period: 1 year from the date of the quotation request.
Storage Method: Electronic.
2. Order Fulfillment
Purpose of Data Processing: Identification before contract conclusion, contract conclusion, making contractual declarations.
Processed Data: Name of individual or business, business email address, other data provided by the User in the message box.
Legal Basis: Responding to the quotation request.
Data Retention Period: Until the order is completed or up to 1 year.
Storage Method: Electronic.
3. Invoice Issuance
Purpose of Data Processing: Issuing a receipt (electronic invoice).
Processed Data: Name of individual or business, business email address, tax number/tax identification number.
Legal Basis: Statutory data processing obligation (Act C of 2000 on Accounting, Section 166 (1)).
Data Retention Period: 1 year from the date of the quotation request.
Storage Method: Electronic.
4. Invoice Retention
Purpose of Data Processing: Retention of receipt (electronic invoice).
Processed Data: Name of individual or business, business email address, tax number/tax identification number.
Legal Basis: Statutory data processing obligation (Act C of 2000 on Accounting, Section 169 (1)).
Data Retention Period: 8 years from the issuance of the electronic invoice.
Storage Method: Electronic.
How the Service Provider Handles Data
The Service Provider generally does not verify the personal data provided. The person providing the data is solely responsible for its accuracy. By providing an email address, the User assumes responsibility for ensuring that only they use that email address. The Service Provider, in case of doubt, may verify the User’s connection to the represented business entity through publicly available official business registry data.
Who is Authorized to Access the Data?
Data is primarily accessible to the Service Provider and its internal employees. They are not disclosed or transferred to third parties, except where required by court or authority orders.
In certain cases, as specified in the GTC, the Service Provider may share specific User data with its cooperating legal partner, dr. Eördögh Lívia Klára, attorney-at-law, under GDPR Article 29 guarantees.
User Rights
Users have the following rights regarding their personal data:
Right of Access: Users can request information about the processing of their personal data.
Right to Rectification: Users can request correction of inaccurate or incomplete data.
Right to Erasure (Right to be Forgotten): Users may request the deletion of personal data under specific conditions.
Right to Restriction of Processing: Users may request that data processing be restricted under certain conditions.
Right to Data Portability: Users may receive their personal data in a structured, commonly used, machine-readable format and transfer it to another service provider.
The Service Provider will respond to user requests as soon as possible, but no later than 30 days (or 15 days in case of an objection). If a request is denied, the User will be informed of the reasons.
Users may enforce their rights in court under the Civil Code (Act V of 2013) or file a complaint with the National Authority for Data Protection and Freedom of Information (NAIH) (1125 Budapest, Szilágyi Erzsébet fasor 22/c.; https://www.naih.hu/panaszuegyintezes-rendje.html).
Cookies (Cookies Policy)
During visits to the Website, small text files (cookies) may be placed on the User’s computer for identification purposes. The Website uses Google Analytics cookies to analyze website traffic. These cookies store only the date, time, and location of specific page visits.
Other Provisions
The Service Provider may collect non-personally identifiable data on User activities, which are not linked to other provided data or services.
If the Service Provider intends to use data for purposes other than the original purpose, Users will be informed in advance, and their explicit consent will be obtained.
The Service Provider ensures the security of personal data and takes technical measures to prevent unauthorized access, destruction, or alteration.
The Service Provider maintains records of its data processing activities in compliance with GDPR Article 30.
In case of a data breach, the Service Provider follows GDPR Articles 33 and 34 and documents all incidents, their impact, and remedial actions taken.
The Service Provider reserves the right to unilaterally modify this Policy at any time. Users will be notified of changes via the Website. Continued use of the Website implies acceptance of the revised Policy.
Effective: Budapest, February 3, 2025
2.8 Rental Filmtechnikai Szolgáltató Kft.