Privacy Policy

LAYER Kereskedelmi Szolgáltató és Ipari Kft.

layer.hu

 

I. PURPOSE AND SCOPE OF THIS PRIVACY POLICY

The website layer.hu (hereinafter: the Website) is operated by LAYER Kereskedelmi Szolgáltató és Ipari Kft. (hereinafter: the Data Controller).

This Privacy Policy provides information to visitors and users of the Website (hereinafter: Data Subjects) about the processing of personal data in connection with the Website and the services provided by the Data Controller.

Personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation, hereinafter: GDPR) and the applicable Hungarian legislation.

The Data Controller considers the protection of personal data and the right of Data Subjects to informational self-determination to be of particular importance.

The Website provides information about Sárréti Industrial Park, the activities of LAYER Kft., industrial properties, development and investment opportunities and related services.

Where a processing activity is not covered by this Privacy Policy, the Data Subject will be provided with appropriate information when the relevant personal data is collected.

 

II. DEFINITIONS

Data Subject: an identified or identifiable natural person.

Personal Data: any information relating to an identified or identifiable natural person.

Data Controller: the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data.

Processing: any operation or set of operations performed on personal data, including collection, recording, organisation, storage, retrieval, use, disclosure, restriction, erasure or destruction.

Data Processor: a natural or legal person that processes personal data on behalf of the Data Controller.

Consent: any freely given, specific, informed and unambiguous indication of the Data Subject’s wishes by which the Data Subject signifies agreement to the processing of personal data relating to them.

Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data.

The terms used in this Privacy Policy shall be interpreted in accordance with, in particular:

  • Regulation (EU) 2016/679 (GDPR);
  • Act CXII of 2011 on Informational Self-Determination and Freedom of Information;
  • Act V of 2013 on the Hungarian Civil Code.

 

III. DETAILS OF THE DATA CONTROLLER

Data Controller: LAYER Kereskedelmi Szolgáltató és Ipari Kft.

Short company name: LAYER Kft.

Registered office: 5520 Szeghalom, Kandó Kálmán utca 1, Hungary

Company registration number: 04-09-001080

Tax number: 10241837-2-04

Website: layer.hu

E-mail: kozpont@layer.hu

Telephone: +36 30 637 4852

Represented by: István Layer, Managing Director

Place of processing: Hungary.

 

IV. PURPOSES AND LEGAL BASES OF PROCESSING

4.1 Contact and requests for quotations

When a Data Subject contacts the Data Controller through the Website, by e-mail or by telephone, the Data Controller processes the personal data necessary to respond to and manage the enquiry.

Data Subjects: persons submitting an enquiry, request for quotation or other communication.

Categories of personal data:

  • name;
  • e-mail address;
  • telephone number, if provided;
  • company name, if provided;
  • other personal data voluntarily included in the enquiry.

Purpose of processing: handling enquiries and requests for quotations, business communication and maintaining appropriate records of communications.

Legal basis: the Data Subject’s consent pursuant to Article 6(1)(a) GDPR or, where the enquiry relates to steps taken at the request of the Data Subject prior to entering into a contract, Article 6(1)(b) GDPR.

Retention period: no longer than one year after the enquiry has been concluded, unless further retention is required due to a contractual relationship or applicable legal obligation.

The Data Subject may withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.

 

4.2 Website usage data and cookies

Technical data may be generated when the Website is used, and the Website may use cookies.

The categories of data may include:

  • date and time of the visit;
  • IP address;
  • address of the page visited;
  • technical information relating to the browser and operating system.

The purpose of processing is to ensure the proper and secure operation of the Website, identify technical problems, prevent misuse and, where appropriate consent has been provided, enable statistical or other purposes specified in the Website’s cookie settings.

Cookies that are strictly necessary for the operation of the Website do not require separate consent. Cookies requiring consent may only be used after the Data Subject has provided the relevant consent.

Retention periods depend on the type of cookie. Session cookies are retained until the end of the browsing session, while other cookies may be stored for the period specified in the applicable cookie settings.

 

V. DATA PROCESSORS

The Data Controller may use data processors to provide hosting and technical services required for the operation of the Website.

RackForest Informatikai Kereskedelmi Szolgáltató és Tanácsadó Kft.

Office: 1132 Budapest, Victor Hugo utca 11, 5th floor, Hungary

Tax number: 14671858-2-41

Processing activity: web hosting and server services.

Purpose: ensuring the technical operation of the Website.

Categories of data: personal and technical data processed in connection with the operation of the Website.

Retention: for the duration of the operation of the Website and/or in accordance with the contractual relationship between the Data Controller and the Data Processor.

 

VI. DISCLOSURE AND TRANSFER OF PERSONAL DATA

The Data Controller only discloses or transfers personal data where there is an appropriate legal basis and a specified purpose for doing so.

Personal data may be made available to data processors to the extent necessary for them to provide their services.

Where personal data is transferred to a third country, the Data Controller will ensure that the transfer is carried out in accordance with the requirements and safeguards set out in the GDPR.

 

VII. RIGHTS OF DATA SUBJECTS

Subject to the conditions set out in applicable data protection law, Data Subjects may request:

  • information about the processing of their personal data;
  • access to their personal data;
  • rectification of inaccurate personal data;
  • erasure of personal data in applicable circumstances;
  • restriction of processing;
  • data portability where the statutory requirements are met;
  • the right to object to processing where applicable.

Requests may be submitted using the contact details of the Data Controller specified in Section III.

The Data Controller will provide information on the action taken on a request without undue delay and in any event within one month of receipt of the request.

Where necessary, taking into account the complexity and number of requests, this period may be extended by a further two months. The Data Subject will be informed of any such extension.

 

VIII. COMPLAINTS AND LEGAL REMEDIES

Data Subjects may submit requests concerning the processing of their personal data using the contact details specified in Section III.

If a Data Subject considers that the processing of their personal data infringes applicable data protection legislation, they have the right to lodge a complaint with the Hungarian supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)

Address: 1055 Budapest, Falk Miksa utca 9–11, Hungary

Postal address: 1363 Budapest, Pf. 9, Hungary

E-mail: ugyfelszolgalat@naih.hu

Data Subjects also have the right to seek judicial remedy in accordance with the GDPR and applicable Hungarian legislation.

 

IX. PERSONAL DATA BREACHES

The Data Controller manages and documents personal data breaches in accordance with the GDPR.

Where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, the Data Controller will notify the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach.

Where a personal data breach is likely to result in a high risk to the rights and freedoms of Data Subjects, the Data Controller will also inform the affected Data Subjects in accordance with the GDPR.

 

X. DATA SECURITY

The Data Controller implements appropriate technical and organisational measures designed to ensure the security, confidentiality, integrity and availability of personal data.

The Data Controller takes appropriate measures to protect personal data against unauthorised access, alteration, disclosure, erasure or destruction, as well as against accidental loss, destruction or damage.

 

XI. OTHER PROVISIONS

The Data Controller reserves the right to amend this Privacy Policy, particularly where amendments are required due to changes in legislation, regulatory practice, the operation of the Website or the Data Controller’s processing activities.

The current version of the Privacy Policy will be made available on the Website.

Effective date: 18 September 2026.