Privacy Policy

Introduction

Our aim is to ensure that you feel safe when using our website; therefore, the protection of your privacy and personal rights is important to us. Please read the following summary carefully regarding the operation of our website. You may rely on us to process your data transparently and fairly, and we make every effort to handle your data carefully and responsibly.

The purpose of this Privacy Policy is to inform you about how we use your personal data. In doing so, we comply with the strict requirements of Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (hereinafter: the “Information Act”) and the General Data Protection Regulation (GDPR).

The data processing principles of Nivis Assistance Zrt. are in line with the applicable data protection legislation, in particular the following:

Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (Information Act);
Act V of 2013 on the Civil Code;
Act CLV of 1997 on Consumer Protection;
Act XIX of 1998 on Criminal Procedure;
Act C of 2000 on Accounting;
Act CVIII of 2001 on certain issues of electronic commerce services and information society services;
Act C of 2003 on Electronic Communications;
Act CXXXIII of 2005 on the rules governing private security and private investigation activities;
Act XLVIII of 2008 on the basic requirements and certain restrictions of commercial advertising activities;
Act CLIX of 2012 on Postal Services.

Details of the Data Controller and contact details of the Data Protection Officer

For the purposes of the GDPR, other data protection laws applicable in EU Member States and other provisions relating to data protection, the data controller is:

Nivis Assistance Zrt.
Company registration number: 01-10-045876
Registered office: Hungary, 1071 Budapest, Dembinszky utca 44.
Tax number: 14186060-2-42
Central telephone number: +36 1 999 0880
E-mail address: info@nivis.hu
Data Protection Officer of the Data Controller: Mácsai Edmond
The Data Protection Officer can be contacted at the following e-mail address or postal address:
E-mail: info@nivis.hu
Postal address: Nivis Assistance Zrt., 1071 Budapest, Dembinszky utca 44.

Personal data

Personal data means any data that can be associated with the data subject, in particular the data subject’s name, identification mark, and one or more factors specific to the data subject’s physical, physiological, mental, economic, cultural or social identity, as well as any conclusion that can be drawn from the data concerning the data subject.

In addition to the registered user’s name, address, telephone number, e-mail address and tax identification number, further data are automatically collected for technical reasons during each visit to our website. Such data include, for example, the IP address assigned to your computer by your internet service provider for the purpose of connecting to the internet, or information about the internet location from which you accessed our offer, as well as the settings of the browser you use (“technical information”). In certain cases, this technical material may constitute personal data. As a general rule, however, we use such technical data only to the extent necessary from a technical point of view for the operation and protection of our website against attacks and misuse, and otherwise in pseudonymised or anonymised form for statistical purposes.

Scope of processing of personal data

We collect and use your personal data only to the extent necessary for the operation of the website and for providing our content and services, for example when you register on our website, log in to your existing customer account or order products. We collect and use your personal data only with your consent. An exception applies where prior consent cannot be obtained due to certain circumstances and the processing is permitted by law.

The security of your personal data is of paramount importance to us. We therefore take technical and organisational measures to protect the data we process, thereby preventing loss or misuse by third parties. Our employees who perform data processing tasks are subject to mandatory confidentiality obligations. The security of your personal data is also ensured by encrypted transmission; for example, we use SSL (Secure Sockets Layer) for communication with your browser. A lock symbol appears in your browser so that you can see when an SSL connection has been established. To ensure that your data are always protected, we regularly review our technical security measures and, where necessary, adapt them to new technological requirements. These principles also apply to companies that process and use data on our behalf and according to our instructions.

Purposes of data processing and legal principles applicable to the processing of personal data

We collect, process and use your personal data for the following purposes:

Contracts relating to the use of funeral services
Sending quotations
Customer service and identification in the telephone system
Providing data to institutions performing public funeral-service tasks for funerals

We may process your personal data on the following legal bases:

Article 6(1)(a) GDPR serves as the legal basis for processing where we obtain your consent for specific processing purposes.
Article 6(1)(b) GDPR regulates the processing of personal data for the performance of a contract, for example in connection with the purchase of a product. The same applies to processing operations necessary for pre-contractual measures, such as handling enquiries relating to products or services.
Article 6(1)(c) GDPR applies where we are subject to a legal obligation requiring the processing of personal data, for example in relation to tax obligations.
Article 6(1)(d) GDPR provides that personal data may be processed in order to protect your vital interests or those of another natural person.
Article 6(1)(f) GDPR relates to our legitimate interests, for example where we use service providers to fulfil orders, carry out statistical surveys and analyses, or log login attempts. Our interest is to provide and optimise a user-friendly, attractive and secure website in a manner that serves both our business interests and your expectations.

Retention period for personal data and deletion practice

We process and store personal data only for as long as necessary to achieve the purpose of processing, or for as long as required by law or another applicable provision. Once the purpose ceases to exist or has been fulfilled, your personal data will be deleted or access to them will be restricted. Restricted access means that the data will be deleted as soon as the expiry of retention periods prescribed by laws, articles of association or contracts permits this, provided that there is no reason to assume that deletion would prejudice your legitimate interests and provided that deletion would not require disproportionate resources due to the specific circumstances of storage.

Collection of general data and information (log files)

In accordance with Article 6(1)(f) GDPR, our website collects a range of general data and information upon each access and temporarily stores these in server log files. Log files are generated automatically by the computer system. The following data may be collected:

Access to the website (date, time and frequency)
How you arrived at the website (referring page, hyperlink, etc.)
The browser and browser version used by you
The operating system used by you
Your internet service provider
The IP address assigned to your computer by your internet service provider when connecting to the internet

The collection and storage of these data are necessary for operating the website, ensuring its functionality and properly presenting the contents of our website. We also use these data to optimise our website and to ensure the security of our IT systems. For these reasons, the data are stored for technical precautionary purposes for a maximum of seven days.

We also use these data for marketing, market research and service-structuring purposes. In order to meet expectations, we create and analyse pseudonymised user profiles, but only if you have not exercised your right to object or withdrawn your consent to such use of your data.

Cookies, web analytics services and social media

Nivis Assistance Zrt. is committed to providing you with services of the highest possible standard. Our aim is to maintain your trust. Accordingly, we wish to provide clear information on how we use and store cookies on our website www.nivis.hu.

Cookies are small text, image or software files that are placed and stored on your computer, smartphone or other device used to access the internet while browsing websites. Cookies are extremely useful tools that enable a website to recognise the user and store information about the user’s visit.

Separate Cookie Policy rules apply to cookies.

Communicating information about special offers and other messages relating to our products and services, such as requests for quotations

We use your data to send the information you request about our products, services and other special offers to the e-mail address you provide. We do this only with your prior consent or where permitted by law. Consent to such communication is governed by Article 6(1)(a) and Article 7 GDPR.

a. Requesting a quotation
Via the website: You have the option to request a free quotation on our website. When you do so, the data provided are transmitted to us, including at least your name, e-mail address and telephone number. Your consent to the processing is obtained during the online procedure, and this Privacy Policy is also made available at that time.

b. Registration at our offices
If you register on the website of one of our offices in order to receive information by e-mail, we store your e-mail address together with the name of the relevant office unit so that we can provide you with region-specific information about our products and services.

c. Postal mail
We do not send marketing materials to you by post.

We want you to read our e-mails with interest, and therefore we try to compile only information that you are likely to find relevant. For this reason, we measure and store openings and clicks associated with your user profile. This information includes whether you open our e-mails and, if so, when, which content you click in the e-mail, and whether you receive our e-mail and, if not, why not. We also use these data for statistical purposes.

You may, of course, unsubscribe from receiving such e-mails, i.e. withdraw your consent with effect for the future. An unsubscribe link is available in every e-mail and newsletter. You will then be asked to confirm your unsubscribe request on our website. You may also contact us at any time using the following contact details to withdraw your consent:

E-mail: info@nivis.hu
Postal address: Nivis Assistance Zrt., 1071 Budapest, Dembinszky utca 44.

It is not possible to unsubscribe from certain informational messages that are necessary for the performance of contracts and the operation of our website, including service-related e-mails.

Processing of personal data when contacting us, registering and placing orders as visitors

a. Contacting us
When you contact us by telephone, e-mail or via the contact form, the data you provide are stored on the basis of Article 6(1)(a) GDPR so that we can answer your questions. The contact is logged in order to demonstrate compliance with legal requirements. Your consent to the processing is obtained when you complete the form, and this Privacy Policy is also made available at that time. The related data are deleted when the communication in question has ended and the relevant matter has been finally resolved.

b. Miscellaneous
Pursuant to Article 6(1)(c) and (f) GDPR, we store and use your personal data and technical information where this is necessary to prevent or investigate misuse or other unlawful conduct on our website, for example to maintain data security in the event of an attack against our IT systems. This may also be done pursuant to orders from administrative authorities or courts, insofar as required by law, and in order to protect our rights and interests and to the extent necessary to defend against claims.

Transfer of personal data to third parties

When transferring your personal data, we always provide the highest possible level of security. Therefore, we transfer your data only to service providers and partners who have undertaken contractual obligations and who have been carefully selected in advance. We transfer data only to organisations established in Hungary or in the European Economic Area and therefore subject to strict EU data protection legislation, or to organisations subject to equivalent security rules. We do not currently transfer data to third countries and do not plan to do so.

a. Transfer to affiliated companies of the Group pursuant to Article 6(1)(b) GDPR
In order to conclude contracts relating to services and deliveries available on our website, we transfer your personal data to companies affiliated with the Group in Hungary, where they are stored in a central database for internal group-level invoicing and accounting purposes. This is particularly necessary so that you can use all our services. If you wish to use the service at one of our offices operated by another legal entity belonging to the group, the office selected by you will be notified of your order and will process it. If you contact the office or our telephone customer service with a question or complaint, they will also have access to the service data in order to handle your matter.

b. Transfer of data to service partners pursuant to Article 6(1)(b) and (f) GDPR
For the operation and optimisation of our website and for the performance of contracts, we engage various service providers to perform certain tasks on our behalf, such as providing central IT services, hosting our website, processing payments and delivering products. We transfer to these service providers the information collected for the relevant purposes, such as name, address and e-mail address.

Some of these companies act on our behalf in order to process and fulfil orders and may therefore use the data provided only in accordance with our instructions. In this case, we are legally responsible for ensuring that the companies we engage take appropriate data security precautions. We therefore agree specific data security measures with these companies and regularly monitor those measures.

Contrary to external data processing requirements, we transfer data to third parties in the following cases of contract performance, where such parties themselves are responsible for the use of the data:

Performance of cremation services
Payment of cemetery fees
Identification due to death occurring abroad

c. Transfer of data to other third parties pursuant to Article 6(1)(c) and (f) GDPR
Finally, we may transfer your personal data to third parties or administrative bodies in accordance with applicable data protection laws if we are legally obliged to do so, for example on the basis of an order from an administrative authority or court, or if we are entitled to do so, for example because it is necessary to investigate a criminal offence or to establish and enforce our rights and interests.

Contacting Nivis Assistance Zrt.

If you wish to contact Nivis Assistance Zrt., you may do so using the contact details provided in this notice or displayed on the website. Nivis Assistance Zrt. deletes all e-mails received by it, together with the sender’s name, e-mail address, date and time data and any other personal data provided in the message, no later than five years after the disclosure of the data.

Purpose of processing: enforcement of the rights of customers and the data controller, ensuring evidence for the resolution of possible legal disputes, subsequent verifiability, subsequent proof of agreements, and quality assurance.
Legal basis of processing: voluntary consent of the data subject.
Scope of processed data: letters and personal data provided during correspondence.
Deadline for deletion: 5 years, corresponding to the general limitation period under the Civil Code.

Data processors:

Name: Adytum Kft.
Registered office: 3530 Miskolc, Arany János u. 11-13.
Tax number: 11877495-2-05
Company registration number: 05-09-007768
Data processing task: provision of cremation services

Name: Budapesti Temetkezési Intézet Zrt.
Registered office: 1136 Budapest, Hegedűs Gyula utca 49-51.
Tax number: 10987553-2-41
Company registration number: 01-10-042694
Data processing task: performance of public funeral-service tasks in the course of funeral services

Name: De-Facto Kft.
Registered office: 1111 Budapest, Irinyi J. utca 31. ground floor 8.
Tax number: 12172126-2-43
Company registration number: 01-09-561423
Data processing task: accounting and bookkeeping tasks

Name: National Heritage Institute
Registered office: 1086 Budapest, Fiumei út 16-18.
Data processing task: cemetery administration in connection with the use of funeral services

Applications for job advertisements

Nivis Assistance Zrt. stores applications received.

Purpose of processing: application for a position to be filled at Nivis Assistance Zrt. and participation in the selection process.
Legal basis of processing: voluntary consent of the data subject.
Type of processed personal data: cover letters, CVs, applications and other personal data provided therein.
Duration of processing: six months from the submission of the application.

Rights of the natural person concerned

You naturally have rights in relation to the collection of your data, and we are pleased to inform you of them below. If you wish to exercise any of the following rights free of charge, simply send us a message. You may use the following contact details without costs, except for any costs charged by your service provider for sending the message:

E-mail: info@nivis.hu
Postal address: Nivis Assistance Zrt., 1071 Budapest, Dembinszky utca 44.

For your own security, we reserve the right to request further information to verify your identity when responding to your request. If identification is not possible, we also reserve the right to refuse to respond to the request.

a. Right of access
You have the right to request information from us about the personal data stored about you.

b. Right to rectification
You have the right to request the immediate rectification and/or completion of personal data stored about you.

c. Right to restriction of processing
You have the right to request that the processing of your personal data be restricted if you dispute the accuracy of the data stored about you, if the processing is unlawful and we no longer need the data but you do not wish the data to be deleted and need them for the establishment, exercise or defence of legal claims, or if you have objected to the processing.

d. Right to erasure
You have the right to request the deletion of your personal data stored by us, unless retention of the data is necessary for freedom of expression and information, compliance with a legal obligation, reasons of public interest, the establishment or defence of legal claims, or the exercise of rights.

e. Right to notification
If you have exercised your right to rectification, erasure or restriction of processing, we will notify all recipients of your personal data about how the data have been rectified or erased, or that processing is now subject to restriction, unless this proves impossible or involves disproportionate effort.

f. Right to data portability
You have the right to request a copy of the data you have provided to us and to request that we send it to you or to a third party in a structured, commonly used and machine-readable format. If you request that the data be sent directly to another controller, we will do so only where technically feasible.

g. Right to object
If we process your personal data on the basis of legitimate interests pursuant to Article 6(1)(f) GDPR, you have the right to object to the processing at any time pursuant to Article 21 GDPR.

h. Right to withdraw consent
You have the right to withdraw your consent to the collection of data at any time with effect for the future. Data collected until the withdrawal are not affected. We hope you understand that processing the withdrawal of consent may take some time for technical reasons, and during this period you may still receive messages from us.

i. Right to lodge a complaint with a supervisory authority
If the processing of your personal data infringes data protection legislation or your data protection rights have otherwise been violated, you may lodge a complaint with the supervisory authority.

Hungarian National Authority for Data Protection and Freedom of Information
Postal address: 1530 Budapest, Pf. 5.
Registered office: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
Telephone: 06/1/391-1400
Fax: 06/1/391-1410
E-mail: ugyfelszolgalat@naih.hu
URL: http://naih.hu

Please note that when your data are deleted, you will no longer have access to your services through our website. This may include re-downloading services. Therefore, please make a backup copy of your data before exercising your right to erasure. Access to data will only be restricted, but the data will not be deleted, if we are obliged to store the data on the basis of statutory, constitutional or contractual obligations, in order to prevent the use of the data for other purposes.

Data security

The security of your personal data is extremely important to us. We therefore protect the data stored by us using technical and organisational measures in order to effectively prevent their loss or manipulation by third parties. Our employees who process personal data are bound by data confidentiality obligations and are required to comply with them. In order to protect your personal data, such data are transmitted in encrypted form. To ensure the long-term protection of your data, we regularly review our technical security measures and, where necessary, adapt them to the technological standards applicable at the relevant time. These principles also apply to companies that process and use data on the basis of our orders and instructions.

Nivis Assistance Zrt. and its processors implement appropriate technical and organisational measures, taking into account the state of the art, the cost of implementation, the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity to the rights and freedoms of natural persons, in order to ensure a level of data security appropriate to the risk.

Nivis Assistance Zrt. selects and operates the IT tools used for the processing of personal data during the provision of the service in such a way that the processed data are:

a) accessible to those authorised to access them (availability);
b) authentic and authentication is ensured (authenticity of processing);
c) verifiably unchanged (data integrity);
d) protected against unauthorised access (confidentiality of data).

Nivis Assistance Zrt. protects the data by appropriate measures, in particular against unauthorised access, alteration, transmission, disclosure, deletion or destruction, as well as accidental destruction, damage and inaccessibility resulting from changes in the technology used.

In order to protect data files processed electronically in its various records, Nivis Assistance Zrt. ensures by appropriate technical means that stored data cannot be directly linked and assigned to the data subject, except where permitted by law. Taking into account the current state of technology, Nivis Assistance Zrt. ensures the security of data processing through technical, organisational and organisational measures that provide a level of protection appropriate to the risks arising in connection with the processing.

During data processing, Nivis Assistance Zrt. preserves:

a) confidentiality: it protects information so that only those authorised may access it;
b) integrity: it protects the accuracy and completeness of the information and the method of processing;
c) availability: it ensures that authorised users can access the required information when needed and that the related tools are available.

The IT systems and networks of Nivis Assistance Zrt. and its partners involved in data processing are protected against computer-assisted fraud, espionage, sabotage, vandalism, fire and flood, as well as computer viruses, computer intrusions and denial-of-service attacks. The operator ensures security through server-level and application-level protection procedures.

We inform users that electronic messages transmitted over the internet, regardless of protocol (e-mail, web, FTP, etc.), are vulnerable to network threats that may lead to dishonest activity, contractual disputes, or the disclosure or modification of information. To protect against such threats, the data controller takes all precautions reasonably expected of it. It monitors systems in order to record any security anomaly and to provide evidence in the event of any security incident. System monitoring also enables verification of the effectiveness of the precautions applied.

Nivis Assistance Zrt., as data controller, keeps records of any personal data breaches, indicating the facts relating to the breach, its effects and the measures taken to remedy it.

Links to websites of other companies

Our website contains links to websites of other companies. We are not responsible for the data security practices of other websites accessible through these links. Please enquire with such external websites regarding their applicable privacy policies.

Amendments to the Privacy Policy

In order to ensure that our Privacy Policy complies with the legal requirements in force from time to time, we reserve the right to amend it at any time. This also applies where the Privacy Policy must be amended in order to describe new or modified products or services.

Effective from: 1 July 2020

www.nivis.hu website
Operated by Nivis Assistance Zrt.
Customer service:
Telephone number: +36 (1) 999 0880
E-mail: info@nivis.hu