Privacy Policy for Clients
The protection of personal data is extremely important to us, therefore in this Privacy Policy we explain what personal data we process about you, for what purpose, and on what legal basis. The Privacy Policy also contains the rights you are entitled to.
Data Controller Details
Data Controller: E.Power Storage Builder Kft (hereinafter: Data Controller). Registered Office: 2160 Csomád, Kossuth Lajos út 47. Company Registration Number: Cg 13-09-224034. Tax Number: 13633868-2-13. Website: www.eepower.eu. Email contact: info@eepower.eu.
General Legislation and Guidelines Underlying Data Processing
Regulation (EU) 2016/679 of the European Parliament and of the Council (27 April 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (GDPR). Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (Infotv.). Act V of 2013 on the Civil Code (Ptk.). Act CXXVII of 2007 on Value Added Tax (VAT Act). Act C of 2000 on Accounting (Accounting Act). Act CXIX of 1995 on the Use of Name and Address Information Serving the Purposes of Research and Direct Marketing (DM Act). Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (Eker tv.). Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities (Grt.).
Definitions
Personal data: any information relating to an identified or identifiable natural person (‘Data Subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Typical personal data includes in particular: name, address, place and date of birth, mother’s name.
Data processing: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Data Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
Data Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Recipient: a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not.
Principles
During the processing of personal data, the Data Controller considers the following principles, meaning personal data must be processed lawfully, fairly and in a transparent manner in relation to the Data Subject (lawfulness, fairness and transparency). Personal data must be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1) of the GDPR, not be considered to be incompatible with the initial purposes (purpose limitation). They must be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (data minimisation). They must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (accuracy). They must be kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) of the GDPR subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the Data Subject (storage limitation). They must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (integrity and confidentiality). The Data Controller shall be responsible for, and be able to demonstrate compliance with, the above (accountability).
Data Processing Activities
Data Processing Activities Performed in a Data Controller Capacity
Contact by email. Purpose of processing: Making contact via email. Legal basis: GDPR Article 6(1)(b): processing is necessary for the performance of a contract or in order to take steps at the request of the Data Subject prior to entering into a contract. Categories of Data Subjects: Inquirer. Scope of personal data: Name, phone number, email address. Data retention period: Until the end of the 1st year following contact. Data transfer: No data transfer takes place under Articles 44-49 of the GDPR. Recipients: The Data Controller does not use Data Processor(s). Source of data: The source of personal data is the inquirer. Method and consequence of data provision: The provision of data is necessary. If you do not provide your personal data, the Data Controller cannot contact you.
Sending a newsletter. Purpose of processing: Sending a newsletter. Legal basis: GDPR Article 6(1)(a): consent. Categories of Data Subjects: Person subscribing to the newsletter. Scope of personal data: Name, email address. Data retention period: Until the withdrawal of consent. Data transfer: No data transfer takes place under Articles 44-49 of the GDPR. Recipients: The Data Controller does not use Data Processor(s). Source of data: The source of personal data is the person subscribing to the newsletter. Method and consequence of data provision: The provision of data is voluntary. If you do not provide your personal data, the Data Controller cannot send you a newsletter.
Writing comments on knowledge base professional articles. Purpose of processing: Writing comments on knowledge base professional articles. The Data Subject may also write the comment using their social media profile. Legal basis: GDPR Article 6(1)(a): consent. Categories of Data Subjects: Person writing the comment. Scope of personal data: Name, public social media profile data. Data retention period: Until the withdrawal of consent. Data transfer: No data transfer takes place under Articles 44-49 of the GDPR. Recipients: The Data Controller does not use Data Processor(s). Source of data: The source of personal data is the person writing the comment. Method and consequence of data provision: The provision of data is voluntary. If you do not provide your personal data, you cannot write a comment.
Claiming a coupon. Purpose of processing: Claiming a coupon with registration. Legal basis: GDPR Article 6(1)(b): processing is necessary for the performance of a contract or in order to take steps at the request of the Data Subject prior to entering into a contract. Categories of Data Subjects: Registering person. Scope of personal data: Phone number, email address. Data retention period: Until the end of the 1st year following the use of the coupon. Data transfer: No data transfer takes place under Articles 44-49 of the GDPR. Recipients: The Data Controller does not use Data Processor(s). Source of data: The source of personal data is the registering person. Method and consequence of data provision: The provision of data is necessary. If you do not provide your personal data, the Data Controller cannot provide you with a coupon.
Client review. Purpose of processing: Displaying reviews from clients. Legal basis: GDPR Article 6(1)(a): consent. Categories of Data Subjects: Client. Scope of personal data: Name, company name, domain name, content of the review. Data retention period: Until the withdrawal of consent. Data transfer: No data transfer takes place under Articles 44-49 of the GDPR. Recipients: The Data Controller uses Data Processor(s): Google Form provider: Google Ireland Ltd. (registered office: Google Building Gordon House, Barrow St, Dublin 4, Ireland). Source of data: The source of personal data is the client. Method and consequence of data provision: The provision of data is voluntary. If you do not provide your personal data, the Data Controller cannot display your review.
Sending system messages to clients. Purpose of processing: Registration serves the purchase of the service package. Legal basis: GDPR Article 6(1)(b): processing is necessary for the performance of a contract or in order to take steps at the request of the Data Subject prior to entering into a contract. Categories of Data Subjects: Registering person. Scope of personal data: Email address. Data retention period: Until the end of the 1st year following the deletion of the registration. Data transfer: No data transfer takes place under Articles 44-49 of the GDPR. Recipients: The Data Controller does not use Data Processor(s). Source of data: The source of personal data is the registering person. Method and consequence of data provision: The provision of data is necessary. If you do not provide your personal data, you cannot register.
Webmail login. Purpose of processing: Webmail login for registered clients with business email. Legal basis: GDPR Article 6(1)(b): processing is necessary for the performance of a contract or in order to take steps at the request of the Data Subject prior to entering into a contract. Categories of Data Subjects: Client. Scope of personal data: Email address. Data retention period: Until the end of the 1st year following the performance or termination of the contract. Data transfer: No data transfer takes place under Articles 44-49 of the GDPR. Recipients: The Data Controller does not use Data Processor(s). Source of data: The source of personal data is the client. Method and consequence of data provision: The provision of data is necessary. If you do not provide your personal data, you cannot log in to the webmail interface. Recipients: The Data Controller does not use Data Processor(s). No data transfer takes place on the part of the Data Controller. Source of data: The source of personal data is the claimant (old, new), witness. Method and consequence of data provision: The provision of data is necessary. If you do not provide your personal data, you cannot initiate a change of ownership.
Contractual contact. In the case of its contracted Partners (supplier, client), the Data Controller communicates and maintains a business relationship through the contact person specified in the contract. Purpose of processing: To maintain communication and implement cooperation for the purpose of realizing the contract between the Data Controller and the Partner. Legal basis: GDPR Article 6(1)(f): legitimate interest. Categories of Data Subjects: Employee of the Partner (sole trader, Kft., Bt., Zrt.), as a designated contact person. Scope of personal data: Name, position, phone number, email address. Data retention period: Until the end of the 5th year following the performance or termination of the contract. Data transfer: No data transfer takes place under Articles 44-49 of the GDPR. Recipients: The Data Controller does not use Data Processor(s). Source of data: The source of personal data is the Partner’s contact person. Method and consequence of data provision: The provision of data is necessary. If you do not provide your personal data, the Data Controller cannot coordinate with the Partner.
Complaint handling. Purpose of processing: Handling complaints related to any service. Legal basis: GDPR Article 6(1)(c): compliance with a legal obligation: Act CLV of 1997 on Consumer Protection. Categories of Data Subjects: Consumer. Scope of personal data: Name, address, phone number, email address, place, time and method of submitting the complaint, detailed description of the complaint, list of records, documents and other evidence presented by the consumer. Data retention period: 3 years based on Section 17/A. paragraph (7) of the Consumer Protection Act. Data transfer: No data transfer takes place under Articles 44-49 of the GDPR. Recipients: The Data Controller does not use Data Processor(s). Source of data: The source of personal data is the consumer, as the complainant. Method and consequence of data provision: The provision of data is voluntary. If you do not provide the necessary data, the Data Controller may not be able to investigate your complaint.
Communication on social media platforms. Purpose of processing: Communication on social media platforms. Legal basis: GDPR Article 6(1)(a): consent. Categories of Data Subjects: Person registered on the social media platform. Scope of personal data: Name, public profile data. Data retention period: Processing takes place on social media platforms, therefore the privacy policy of the given social media platform applies. Data transfer: No data transfer takes place under Articles 44-49 of the GDPR. Recipients: The Data Controller does not use Data Processor(s). Source of data: The source of personal data is the registered person. Method and consequence of data provision: The provision of data is voluntary. If you do not provide your personal data, the Data Controller cannot inform you about its current activities and services on social media platforms.
Data Processing Activities Performed in a Data Processor Capacity
The Website uses cookies. A cookie is a file that is placed on your computer when you visit a website. A cookie is an information package sent by the server to the browser, which the browser then sends back to the server with the data content determined by the server upon each request. The purpose of this is to save the internet settings of the website you visit, so if you visit the same website again from the same device, the page will already remember the set parameters.
A cookie has countless functions. Cookies are most commonly used to personalize advertisements and services, and to analyze website traffic. According to current legislation, a cookie can only be stored on your device if it is strictly necessary, i.e., essential for the operation of the website; these are called “necessary cookies”. The use of any other type of cookie requires your consent. You can view and adjust the cookies currently used on the website in the pop-up window that appears when entering the website.
Modern browsers allow you to change cookie settings. Some browsers automatically accept cookies by default, but this setting can also be changed to prevent automatic acceptance in the future. In the event of an adjustment, the browser will subsequently offer the option of choosing cookie settings every time.
Given that the purpose of cookies is to support and facilitate the usability and processes of the website, it cannot be guaranteed that you will be able to fully use all functions of the website if cookies are disabled. In this case, the website may operate differently than intended in the browser. Further detailed information on the cookie settings of the following browsers: Google Chrome, Firefox, Microsoft Internet Explorer 11, Microsoft Internet Explorer 10, Microsoft Internet Explorer 9, Microsoft Internet Explorer 8, Microsoft Edge, Safari.
Fingerprint.
Social Media. The Data Controller is available on the following social media platform(s). The operator of the social media platform acts as an independent Data Controller; information on data processing is available at the following links: Facebook, Meta Platforms Ireland Ltd. (registered office: 4 Grand Canal Square, Grand Canal Harbour Dublin 2, Ireland), https://www.facebook.com/privacy/explanation. Instagram, Meta Platforms Ireland Ltd. (registered office: 4 Grand Canal Square, Grand Canal Harbour Dublin 2, Ireland), https://www.facebook.com/help/instagram/155833707900388/. LinkedIn, LinkedIn Ireland Unlimited Company (registered office: Wilton Plaza Wilton Place, Dublin 2 Ireland), https://www.linkedin.com/legal/privacy-policy. X, Twitter International Unlimited Company (registered office: One Cumberland Place, Fenian Street Dublin 2, D02 AX07, Ireland), http://twitter.com/hu/privacy. Reddit, Reddit Ireland Limited (registered office: Georges Quay Plaza, Floor 2-101, Dublin D02 F856 Ireland), https://www.reddit.com/policies/privacy-policy. Pinterest, Pinterest Europe Ltd. (registered office: Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland), https://policy.pinterest.com/hu/privacy-policy. TikTok, TikTok Technology Ltd., (registered office: 10 Earlsfort Terrace, Dublin, D02 T380, Ireland), https://www.tiktok.com/legal/privacy-policy-eea?lang=hu. Youtube, Google Ireland Ltd. (registered office: Gordon House, Barrow Street, Dublin 4, Ireland), https://policies.google.com/technologies/product-privacy?hl=hu. Google Business Profile, Google Ireland Ltd. (registered office: Gordon House, Barrow Street, Dublin 4, Ireland), https://policies.google.com/privacy?hl=hu&fg=1. The Data Controller does not record or process personal data about the user of the given social media platform in its internal database and system.
Access to Data
The competent employees of the Data Controller may access personal data to the necessary extent in order to perform their tasks.
Data Security Measures
The Data Controller ensures through appropriate IT, technical, and personnel measures that it protects the personal data it processes against, among other things, unauthorized access or unauthorized alteration.
Data Subject Rights and Their Content Related to Data Processing
Right to information /GDPR Articles 13-14/: You have the right to be informed of the fact and purposes of data processing at the time your personal data is obtained. The Data Controller will also provide you with additional information necessary to ensure fair and transparent processing, taking into account the specific circumstances and context of the processing of personal data. You must also be informed of the fact of profiling and its consequences.
Right of access /GDPR Article 15/: You have the right to request information as to whether personal data concerning you are being processed, and, where that is the case, to access them to know what personal data of yours, on what legal basis, for what processing purpose, for how long they process, to whom, when, under what legal provision, access was granted to which of your personal data, or to whom your personal data was transferred, from what source your personal data originate (if you did not provide them to the Data Controller), and whether automated decision-making, including profiling, is used, as well as the logic involved.
Right to rectification /GDPR Article 16/: You have the right to request that the Data Controller rectify inaccurate personal data concerning you or complete incomplete personal data. Thus, you may ask the Data Controller to modify any of your personal data (for example, you can change your email address or other contact information at any time).
Right to erasure (‘right to be forgotten’) /GDPR Article 17/: You have the right to request the Data Controller to erase your personal data if one of the following grounds applies: your personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; you withdraw your consent on which the processing is based according to Article 6(1)(a) or Article 9(2)(a), and where there is no other legal ground for the processing; you object to the processing pursuant to Article 21(1) and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Article 21(2); your personal data have been unlawfully processed; your personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the Data Controller is subject; your personal data have been collected in relation to the offer of information society services referred to in Article 8(1).
Right to restriction /GDPR Article 18/: You have the right to request the Data Controller to restrict processing if one of the following grounds applies: you contest the accuracy of your personal data (in this case, the restriction applies for a period enabling the Data Controller to verify the accuracy of the personal data); the processing is unlawful and you oppose the erasure of the data and request the restriction of their use instead; the Data Controller no longer needs the personal data for the purposes of processing, but they are required by you for the establishment, exercise or defence of legal claims; you have objected to processing pursuant to Article 21(1) (in this case, the restriction applies pending the verification whether the legitimate grounds of the Data Controller override your legitimate grounds).
Right to data portability /GDPR Article 20/: You have the right to receive the personal data concerning you, which you have provided to a Data Controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another Data Controller without hindrance from the Data Controller to which the personal data have been provided, where the processing is based on consent pursuant to Article 6(1)(a) or Article 9(2)(a) or on a contract pursuant to Article 6(1)(b), and the processing is carried out by automated means. You have the right, where technically feasible, to request the direct transmission of your personal data between Data Controllers.
Right to object /GDPR Article 21/: You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on Article 6(1)(e) or (f), including profiling based on those provisions. In this case, the Data Controller shall no longer process your personal data unless the Data Controller demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims. Where your personal data are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing.
Right to withdraw consent /GDPR Article 7(3)/: You have the right to withdraw your consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. Prior to giving consent, you must be informed thereof. It shall be as easy to withdraw as to give consent.
Data Subject Remedies and Their Content Related to Data Processing
Right to lodge a complaint with a Supervisory Authority /GDPR Article 77/: If your right to the protection of your personal data is violated, you may submit a complaint to the following Authority: National Authority for Data Protection and Freedom of Information, Registered office: 1055 Budapest, Falk Miksa utca 9-11., Mailing address: 1363 Budapest, Pf. 9., Phone: +36 (1) 391-1400, Email: ugyfelszolgalat@naih.hu, Website: www.naih.hu.
Right to an effective judicial remedy against a Data Controller or Data Processor (initiating judicial proceedings) /GDPR Article 79/: You have the right to turn to a court against the Data Controller or Data Processor if you experience unlawful processing of your personal data. The court will handle the case out of turn. In this case, you can freely decide whether to submit your claim to the regional court (törvényszék) competent for your place of residence or place of stay. Availability of regional courts: www.birosag.hu/torvenyszekek.
Updating the Privacy Policy
The Data Controller reserves the right to unilaterally modify this Privacy Policy. The modification of this policy may take place, in particular, if required by legislative changes, data protection authority practices, business needs, or other circumstances. At the request of the Data Subject, the Data Controller will send them a copy of the policy currently in force in a mutually agreed format.
Budapest, July 23, 2026.