HőKép3D · hokep3d.hu
Privacy Notice
On personal data processing in connection with the HőKép3D engineering thermal-imaging survey service and the hokep3d.hu website, under Articles 13–14 of Regulation (EU) 2016/679 (GDPR) and Act CXII of 2011 on informational self-determination (Infotv.).
Our service is for businesses only. We therefore process personal data mainly of representatives, contacts and employees of businesses, and incidentally in images taken during surveys.
1. The controller
| Name | [Company name] ([legal form]); trading as HőKép3D (the Controller) |
| Seat | [seat] |
| Company registry no. / tax no. | [company registry / registration number]; [tax number] |
| Representative | [managing director / sole trader] |
| Data-protection contact | [name], info@hokep3d.hu, [+36 …] |
| Data Protection Officer | The Controller is not required to appoint a DPO under GDPR Article 37 (1) (its activity is not regular and large-scale monitoring of individuals or large-scale processing of special-category data, and it is not a public body). [confirm] |
The Controller keeps a record of processing activities (GDPR Art. 30) and a personal data breach register.
2. Basic concepts
2.1. Personal data: any information relating to an identified or identifiable natural person (e.g. name, e-mail address, phone number, recognisable face, vehicle number plate). Company data of a legal person are not personal data; data of a legal person’s representative, contact person or employee, and of a sole trader, are.
2.2. Controller: who determines the purposes and means of processing; processor: who processes personal data on behalf of and on the instructions of the controller (GDPR Art. 4 (7)–(8)).
2.3. Images: radiometric thermal images, visible-light (RGB) photos or video, drone images and photogrammetry data taken of a facility during a survey.
3. Principles
3.1. The Controller processes personal data lawfully, fairly and transparently, for specified, explicit and legitimate purposes, to the extent and for the time necessary (GDPR Art. 5).
3.2. The service examines buildings, structures and equipment – not people. We process data of persons and number plates appearing in images only incidentally and keep it to a minimum (data minimisation; data protection by design and by default – GDPR Art. 25).
3.3. The Controller does not use automated decision-making, including profiling (GDPR Art. 22). AI-assisted tools are used only for technical processing of building images, not to identify or evaluate persons; an engineer approves findings that enter the documentation. With consent-based ad measurement (Section 4.10) Google may also process data for ad personalisation in its own advertising systems; you can exclude this by refusing or withdrawing consent.
4. Individual processing activities
4.1. Enquiries and contact (website form, e-mail, phone)
| Data subjects | the person requesting a quote or making contact (business representative, employee, sole trader) |
| Data | name, position, company name, e-mail, phone, content of the message |
| Purpose | answering the enquiry, preparing a quote |
| Legal basis | for a sole trader, GDPR Art. 6 (1) (b) – steps at the data subject’s request prior to entering into a contract; for an employee or representative of a business, Art. 6 (1) (f) – legitimate interest (answering a business enquiry) |
| Source | the data subject |
| Retention | if no contract is concluded, 12 months from last contact; if a contract is concluded, see 4.2 |
| Note | Providing the data is a condition of making a quote; without it we cannot quote. |
4.2. Quote, contract formation and performance, communication, delivery of documentation
| Data subjects | Client’s contacts, representatives, on-site escorts, staff with portal access |
| Data | name, position, e-mail, phone, signature, time of on-site presence, identifier and access log for the 3D heat map (time, IP address, action) |
| Purpose | conclusion and performance of the contract, communication, secure delivery of documentation |
| Legal basis | for a sole-trader Client, Art. 6 (1) (b) – contract performance; for a business’s staff, Art. 6 (1) (f) – legitimate interest (communication needed to perform the contract); access log: Art. 6 (1) (f) – security of documentation, detecting misuse |
| Source | the data subject or the data subject’s employer (the Client) |
| Retention | 5 years from the end of the contract (Civil Code 6:22 § – general limitation period); access log: 12 months |
4.3. Invoicing, bookkeeping
| Data subjects | sole-trader Clients; the contact named on the invoice |
| Data | name, address, tax number, billing e-mail |
| Legal basis | Art. 6 (1) (c) – legal obligation: Act CXXVII of 2007 on VAT; Act C of 2000 on accounting (Accounting Act) |
| Retention | 8 years (Accounting Act s. 169 (2)) |
| Recipients | accountant, invoicing software provider, the Hungarian tax authority (NAV Online Invoice reporting) |
4.4. Business outreach (outgoing offers) – prospective clients
The Controller conducts outgoing business outreach under its internal outreach policy.
| Whom we contact | only the general organisational e-mail address of a legal person (e.g. info@, iroda@, ugyfelszolgalat@) published by the business on its own website or in the company register; we may address the message to the attention of a function (e.g. facility operations manager) |
| Whom we do NOT contact without prior consent | a named individual (employee, manager), a sole trader, a private or freemail address, or persons on a purchased or automatically harvested list. We send direct-marketing e-mail to these addresses only with the data subject’s prior, clear and express consent (Act XLVIII of 2008 on advertising, Advertising Act, s. 6; GDPR Art. 6 (1) (a)). |
| Data | organisation name, general e-mail address, website, source and date of collection, the fact of outreach and replies |
| Legal basis | processing of general organisational addresses – where that is personal data at all – rests on legitimate interest under GDPR Art. 6 (1) (f) (business contact); the balancing test is available on request. For a named contact who has consented: Art. 6 (1) (a) |
| Source | the business’s website, company register; for consenting contacts, the data subject |
| Objection / unsubscribe | the recipient may object at any time without giving reasons (GDPR Art. 21 (2)–(3)) or withdraw consent: by e-mail (“UNSUBSCRIBE”), via the link in the message, or by post. We act within 1 working day. |
| Retention | 24 months from last contact; after objection or unsubscribe, the minimal identifier (e-mail address) stays on a suppression list for [5] years, reviewed annually [confirm]; proof of consent for 3 years after withdrawal |
| Information (Art. 14) | in the footer of the first message: identity of the controller, source of the data, legal basis, e-mail and postal opt-out, link to this notice. |
4.5. Operating the website, server logs, statistics
| Data subjects | website visitors |
| Data | IP address, time of request, requested page, browser and device type, referrer (server log) |
| Purpose | secure operation of the website, troubleshooting, protection against abuse |
| Legal basis | Art. 6 (1) (f) – legitimate interest (website operation and security) |
| Retention | 30 days |
| Cookies, tracking | Without consent the website uses on your device only the local storage strictly necessary to remember your cookie choice (hk3d-consent). Measurement and advertising cookies are set only with your consent; see Section 4.10 and the Cookie Notice. |
| Statistics | None without consent: visitor statistics, behaviour analytics and ad measurement rest on your consent (Section 4.10). |
4.6. On-site images (thermal, RGB, drone, photogrammetry)
See Sections 5 and 6.
4.7. Occupational safety and access records
| Data subjects | the Controller’s staff working on site, the Client’s escort |
| Data | name, signature, time of induction |
| Legal basis | Art. 6 (1) (c) – obligations under Act XCIII of 1993 on occupational safety; or Art. 6 (1) (f) – legitimate interest |
| Retention | 5 years from the end of the contract |
4.8. Establishing, exercising and defending legal claims
| Data | data from the categories above relevant to the claim |
| Legal basis | Art. 6 (1) (f) – legitimate interest |
| Retention | until the claim is time-barred or the proceedings are finally closed |
4.9. Case-study consent, feedback (pilot programme)
| Data subjects | the Client’s representative giving consent; the person in the feedback interview |
| Data | name, position, the fact, time and content of consent, feedback content |
| Legal basis | Art. 6 (1) (b) (pilot programme contract terms) and (f); for a quote or material published under a person’s name, separate consent, Art. 6 (1) (a) |
| Retention | duration of consent + 3 years from withdrawal (provability) [confirm] |
| Note | An anonymised case study contains no personal data, no data identifying the business, and no recognisable persons or plates. |
4.10. Consent-based measurement: visitor statistics, behaviour analytics, ad measurement
| Data subjects | website visitors who have consented to the respective category in the cookie bar |
| Services, categories | Statistics: Google Analytics 4 (Google Ireland Ltd.); Behaviour analytics: Microsoft Clarity (Microsoft Ireland Operations Ltd.); Ad measurement: Google Ads conversion measurement (Google Ireland Ltd.). A separate decision per category; none is pre-selected. |
| Data | online identifiers (cookies _ga, _ga_*, _clck, _clsk, _gcl_au, _gcl_aw), IP address (received by the provider as a technical necessity of the request), pages viewed and their time, referrer (with personal-looking query parameters removed), device, browser and operating-system data, approximate location, events (quote form sent, e-mail and phone clicks, PDF downloads with file name, calculator use with facility type and level, 3D view started, segment of the offer page), for Clarity click, scroll and pointer-movement data and a masked, replayable recording of page use; after an ad click, the ad-click identifier. Not included in the measurement: name, e-mail address, phone number, any form content (Clarity masks form fields; they are not part of events). |
| Purpose | analysing and improving the website’s reach and usability; measuring whether ads lead to quote requests |
| Legal basis | GDPR Art. 6 (1) (a) – consent; for accessing and placing data on your device, consent under s. 155 (4) of the Electronic Communications Act. Consent is voluntary, refusing carries no disadvantage, and use of the website and the quote request do not depend on it. |
| Consent handling | A bar asks for consent on the first visit (“Accept” and “Reject” of equal weight; “Settings” per category). The scripts are not loaded before consent. Your choice (per category), its time and the notice version are recorded in your browser’s local storage (hk3d-consent) and are valid for 12 months. |
| Withdrawal | At any time, as easily as giving it: with the “Cookie settings” link in the footer or by e-mail (info@hokep3d.hu). After withdrawal the website no longer loads the service’s script and deletes the related cookies on its own domain. Withdrawal does not affect the lawfulness of earlier processing. |
| Recipients, processors | Google Ireland Limited (Google Analytics 4, Google Ads), Microsoft Ireland Operations Limited (Microsoft Clarity). For Google Analytics and Clarity the respective provider acts as processor; for parts of Google Ads measurement Google may also be an independent controller under its own terms [confirm]. Google Signals and ad personalisation are switched off in Google Analytics; we do not allow ad storage for Clarity. |
| Third-country transfer | The providers may also process data in the United States; the safeguards are in Section 10 (EU–US Data Privacy Framework, otherwise standard contractual clauses). |
| Retention | Cookies: as in Section 4 of the Cookie Notice (_ga, _ga_* 2 years; _gcl_au, _gcl_aw 90 days; _clck 1 year; _clsk 1 day). Data held by the providers: Google Analytics event-level data 14 months (retention set in GA4); Clarity recordings and metrics per the Clarity setting, at most [30 days / 13 months]; Google Ads conversion data per the Google Ads setting [confirm]. Proof of consent: see Section 11. |
5. On-site images – detailed rules
5.1. Purpose and necessity. The purpose of images is the technical survey of the envelope and equipment of the facility. Images are not aimed at identifying persons. The resolution of radiometric thermal images generally does not allow identification; RGB and drone images may, however, show a recognisable person or plate. According to the position of the Hungarian data protection authority, a recognisable image or video of a person is personal data and recording it is processing.
5.2. Roles. Because images are taken at the Client’s facility on the Client’s instruction, for the data of persons and number plates appearing incidentally the Client is the controller and the Controller is a processor, under the terms in Annex 2 to the Terms (GDPR Art. 28). In that capacity the Controller acts on the Client’s instructions; blurring persons and plates is a default instruction. The Controller acts as an independent controller for minimal data held for its own legitimate interests: the integrity hash manifest that ensures verifiability of the measurement (this contains no personal data), the defence of legal claims, and quality assurance (in aggregated, anonymous form). [confirm: final legal characterisation of the roles]
5.3. Legal basis. The Client’s basis is typically legitimate interest under GDPR Art. 6 (1) (f) (surveying the technical condition of its facility); the Controller’s own processing is also based on legitimate interest. We provide the balancing test on request.
5.4. Minimisation at capture. Where possible we survey outside working hours, at night; before imaging we ask people to leave the field of view, agreeing with the Client’s escort; we take no images of excluded areas; we plan drone flights to capture neighbouring properties and public areas as little as possible.
5.5. Minimisation in processing. We blur or mask recognisable persons and plates at the start of processing; only blurred material appears in the documentation and in any publication. Where technically possible we blur before uploading to an external (e.g. AI-assisted) provider. We remove EXIF/GPS metadata before sharing outside the project.
5.6. Retention. Original images without blurring – if needed for integrity checking – are kept for no more than 12 months from handover under strictly limited access, then deleted. Blurred raw data and the documentation are kept for 3 years from handover. [confirm]
5.7. Information on site. The Client undertakes to inform its employees and persons on site of the survey in advance; for this we provide a short notice (attached to the Site Consent) that refers to this notice. During drone flights we place an information sign near the take-off point.
5.8. Objection. A data subject may object to the processing of images under Section 12 (with the Client or with us, at the Controller’s contact details); on a well-founded objection we blur or delete the image portion concerning the data subject and document the change.
6. Drone imaging
6.1. We perform drone imaging only where airspace and permits allow (Act XCVII of 1995 on aviation, Government Decree 4/1998 (I. 16.), Regulations (EU) 2019/947 and 2019/945), with the Client’s consent. We check the flight area in the official airspace app.
6.2. Drone imaging may affect privacy more than ground imaging, so we carried out and documented a data protection impact assessment screening (threshold analysis). According to the screening the risk is not high, with these safeguards: flights limited to the Client’s site; avoiding flights over neighbouring properties, public areas and employees; an information sign at the take-off point; short retention; blurring persons and plates at the start of processing; prior information to data subjects through the Client. We update the screening when circumstances change (e.g. a new type of site).
6.3. Section 5 applies correspondingly to drone images. Where necessary, the Controller gives the authority the privacy declaration required for an ad hoc airspace request.
7. The website, hosting, statistics
7.1. The website is hosted by [hosting provider name, seat, e-mail] (processor). The hosting provider processes the server logs.
7.2. We serve fonts and scripts from our own server; we embed no third-party content (maps, videos, social-media modules) that would transmit visitors’ IP addresses to third parties. Exception: the website loads the scripts of Google Analytics 4, Microsoft Clarity and Google Ads only if the visitor has consented to the respective category (Section 4.10); without consent your browser does not connect to these providers. If we introduce further external services we will amend this notice and ask for consent.
7.3. The quote request form works [by e-mail (mailto) / through the service of [form provider] – processor]. [state the solution actually used]
7.4. Links to external social-media profiles are mere links; following them subjects you to the third party’s own privacy rules.
8. Data security
8.1. The Controller applies technical and organisational measures proportionate to the risk under GDPR Art. 32, in particular:
(a) encryption: data in transit over encrypted channels (TLS), stored raw images and backups encrypted, field storage media device-encrypted;
(b) access control: role-based access limited to the necessary minimum; two-factor authentication for administrative and cloud accounts; regular review of permissions;
(c) integrity: a hash is made of each raw file after recording, to detect later modification; processing is traceable through a version log;
(d) availability: regular backups stored separately, restoration tested periodically;
(e) organisational measures: staff confidentiality undertakings, data-protection training, secure deletion or destruction of storage media.
8.2. Personal data breach. The Controller keeps a breach register; it reports a breach posing a risk to the Hungarian data protection authority (NAIH) within 72 hours of becoming aware (GDPR Art. 33) and informs data subjects without undue delay where the risk is high (Art. 34). As a processor it notifies the Client within 48 hours.
9. Processors and recipients
9.1. The Controller uses the following processors under written contracts under GDPR Art. 28 (list to be completed with the actual providers):
| Activity | Processor | Data | Location |
|---|---|---|---|
| Website hosting | [hosting provider name, seat] | server logs, form data | [EU/EEA] |
| E-mail and office software | [provider] | correspondence, contact data | [EU/EEA / USA – Section 10] |
| Visitor statistics, ad measurement (only with consent, Section 4.10) | Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Google Analytics 4, Google Ads) | online identifiers, IP address, page-use and event data, ad-click identifier | EU/EEA; transfer to a third country (USA) possible – Section 10 |
| Behaviour analytics (only with consent, Section 4.10) | Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, Ireland (Microsoft Clarity) | online identifiers, IP address, masked page-use recording, click and scroll data | EU/EEA; transfer to a third country (USA) possible – Section 10 |
| Cloud storage, backup | [provider] | raw images, documentation | [EU/EEA] |
| AI-assisted processing (image processing, text editing) | [provider] | blurred images, measurement data | [EU/EEA / USA – Section 10] |
| Accounting | [accountant name, seat] | billing data | Hungary |
| Invoicing software | [provider] | billing data (NAV Online Invoice) | Hungary |
| Subcontractor (e.g. drone pilot, field staff) | [if any] | images, contact data | [ ] |
| Form service | [if any] | enquiry data | [ ] |
9.2. In our contract with the AI provider we exclude use of the data for training its own models or for any other own purpose, and require deletion after processing.
9.3. Other recipients. We do not sell or pass personal data to third parties except: (a) the Client (as part of the documentation, in blurred form); (b) authorities where legally obliged (NAV, courts, investigating authorities); (c) our legal counsel in case of a legal claim; (d) where necessary, the aviation authority in connection with drone flights; (e) the insurer and insurance intermediary in case of a claim.
10. Transfers to third countries
10.1. We prefer providers that process data within the European Economic Area (EEA). If a processor handles data outside the EEA, the transfer relies on one of: (a) an adequacy decision of the European Commission (GDPR Art. 45), including Implementing Decision (EU) 2023/1795 on the EU–US Data Privacy Framework if the US recipient is certified under it (Google LLC and Microsoft Corporation are listed as certified on the public DPF list; the current status can be checked at https://www.dataprivacyframework.gov [confirm]); (b) the standard contractual clauses of the Commission (Implementing Decision (EU) 2021/914; GDPR Art. 46 (2) (c)), with a transfer impact assessment and, where needed, supplementary measures (e.g. encryption). [confirm: current status of the framework when put into use]
10.2. On request we give information about the safeguard used and how to obtain it.
11. Summary of retention periods
| Data | Retention |
|---|---|
| Enquiries, contact without a contract | 12 months from last contact |
| Contract documents, contact data | 5 years from end of contract |
| Accounting records | 8 years |
| Outgoing business outreach (organisational addresses) | 24 months from last contact |
| Suppression list (objection / unsubscribe) | [5] years, reviewed annually |
| Proof of consent | validity + 3 years from withdrawal |
| Cookie choice (hk3d-consent, in the visitor’s browser) | 12 months, or until the notice version changes |
| Measurement: cookies and provider data (Google Analytics 4, Microsoft Clarity, Google Ads) | per Section 4.10 (cookies 1 day – 2 years; provider data [2–14] months) |
| Blurred raw data and documentation | 3 years from handover |
| Original images without blurring (if needed) | up to 12 months from handover |
| Server log | 30 days |
| 3D heat map access log | 12 months |
| Breach register | 5 years |
| Drone DPIA-screening documentation | duration of activity + 3 years |
12. Data subjects’ rights
12.1. Access (Art. 15): you may ask whether your personal data are being processed and, if so, obtain access and a copy.
12.2. Rectification (Art. 16): you may ask for inaccurate data to be corrected and incomplete data to be completed.
12.3. Erasure (Art. 17): you may ask for erasure if the purpose has ended, you withdrew consent, you successfully objected, or processing is unlawful – unless processing is necessary for a legal obligation (e.g. accounting retention) or for legal claims.
12.4. Restriction (Art. 18): you may ask for restriction while accuracy is contested, if processing is unlawful, or while a claim or objection is being assessed.
12.5. Portability (Art. 20): where processing is based on contract or consent and automated, you may receive the data you provided in a structured, commonly used, machine-readable format.
12.6. Objection (Art. 21): you may object at any time, on grounds relating to your situation, to processing based on legitimate interest; we then stop processing unless compelling legitimate grounds or legal claims justify it. If you object to direct marketing, we may no longer process the data for that purpose, without any reason needed.
12.7. Withdrawal of consent: where processing is based on consent you may withdraw it at any time; this does not affect the lawfulness of processing before withdrawal. You can withdraw your consent to website measurement (Section 4.10) with the “Cookie settings” link in the footer, as easily as you gave it.
12.8. Handling requests. Send requests to the contact details in Section 1. We reply without undue delay and at the latest within one month; this may be extended by a further two months where necessary, with notice to you (GDPR Art. 12 (3)). Information is free; for manifestly unfounded or excessive requests we may charge a reasonable fee or refuse. If in doubt we may ask for further identifying information. If the controller is the Client, not us (Section 5.2), we forward the request.
13. Remedies
13.1. You may complain to us at the contact details in Section 1; we recommend contacting us before starting an official or court procedure.
13.2. Complaint to the authority (GDPR Art. 77, Infotv. s. 52): Hungarian National Authority for Data Protection and Freedom of Information (NAIH); address: 1055 Budapest, Falk Miksa utca 9–11.; postal address: 1363 Budapest, Pf. 9.; e-mail: ugyfelszolgalat@naih.hu; website: https://www.naih.hu.
13.3. Court (GDPR Art. 79, Infotv. s. 23): you may go to court if your rights are infringed. The regional court has competence; at your choice you may bring the action before the regional court for your place of residence or stay. Courts can be found at https://birosag.hu.
13.4. You may claim compensation or non-pecuniary damages for unlawful processing (GDPR Art. 82; Civil Code 2:52 §).
14. Changes to this notice
14.1. We may amend this notice, e.g. on a change in law, a new processor or a new purpose. We publish the amended notice at https://hokep3d.hu/adatkezelesi-tajekoztato/ before it takes effect and notify the contacts of current Clients by e-mail.
14.2. For a new purpose we give separate information before processing starts and, if necessary, ask for consent.
14.3. We archive earlier versions and provide them on request.
Related documents: Terms (Sections 25–26, Annex 2) · Cookie Notice · Site Consent · Case-Study Consent.