1. Purpose of the Data Management Notice

Scheffer Norbert ev. (hereinafter, service provider, data controller) and Scheffer Viktorina as data controller acknowledge the content of this legal notice as binding upon themselves. They undertake to ensure that all data processing activities related to their operations comply with the provisions of this policy, applicable national laws, and the requirements set forth in the legal acts of the European Union.
The data protection guidelines regarding the data processing by Scheffer Norbert ev. and Scheffer Viktorina are continuously available on the website www.neoship.com.

Scheffer Norbert ev. reserves the right to change this notice at any time. Any changes will be duly communicated to the public in a timely manner.

Scheffer Norbert ev. is committed to protecting the personal data of its customers and partners and considers it particularly important to respect its customers' right to informational self-determination. Scheffer Norbert ev. and Scheffer Viktorina treat personal data confidentially and take all security, technical and organizational measures to guarantee the security of the data. Scheffer Norbert ev. describes its data management practices below.

2. Data Controller's Details
Scheffer Norbert ev. and Scheffer Viktorina will delete any email requests, along with any personal data, within 5 business days upon request.
Az Scheffer Norbert ev. illetve Scheffer Viktorina minden hozzá beérkezett e-mailt a személyes adatokkal együtt kérésre 5 munkanapon belül törli.

Name: Scheffer Norbert ev. and Scheffer Viktorina
Address:2 Határ út, 9172 Győrzámoly, Hungary
Phone number: +3670/452-8657
Email: info@neoship.com

3. Scope of Processed Personal Data

3.1 Personal Data to be Provided During Inquiry
Name, phone number, email address

3.2 Technical Data
Scheffer Norbert ev. and Scheffer Viktorina select and operate the IT tools used for processing personal data in a manner that ensures the data:
Is accessible only to authorized individuals (availability);
Its authenticity and verification are ensured (data processing authenticity);
Its integrity can be verified (data integrity);
It is protected from unauthorized access (data confidentiality).
Scheffer Norbert ev. and Scheffer Viktorina protect data with appropriate measures against unauthorized access, modification, transmission, disclosure, deletion, destruction, and accidental destruction.
Scheffer Norbert ev. and Scheffer Viktorina ensure data processing security through technical, organizational, and procedural measures that provide an appropriate level of protection against risks related to data processing.
Scheffer Norbert ev. and Scheffer Viktorina aim to preserve:
Confidentiality: Protects the information so that only authorized individuals can access it;
Integrity: Protects the accuracy and completeness of information and processing methods;
and
Availability: Ensures that when authorized users need the information,
they can access it,
and that the related tools are available.

3.3 Cookies
3.3.1 Purpose of Cookies
Collect information about visitors and their devices;
Remember visitors' individual settings that may be used, for example,
so they don’t have to re-enter them;
Facilitate website usage;
Ensure a quality user experience.
To provide customized service, a small data package, known as a cookie, is placed on the user’s
computer, and is read back during subsequent visits. If the browser sends a previously saved cookie, the
service provider can link the user's current visit with previous ones,
but only concerning its own content.

3.3.2 Strictly Necessary Session Cookies
These cookies are used to ensure that visitors can fully and smoothly browse the website and use its functions. The validity of these cookies lasts until the session (browsing) ends. When the browser is closed, these cookies are automatically deleted from the computer or other browsing devices.

3.3.3 Third-Party Cookies (Analytics)
www.neoship.com also uses cookies from third parties, such as Google Analytics. Google Analytics collects information about how visitors use the website for statistical purposes. The data is used to improve website development and user experience. These cookies remain on the visitor's computer or browsing device until they expire or are deleted by the visitor.

3.4 Data Related to Online Administration
Provide a detailed list of personal data requested during online transactions. Indicate which fields are mandatory to complete
and verify the necessity of the requested data.

5. Purpose, Method, and Legal Basis for Data Processing

5.1 General Data Processing Principles
The data processing activities of Scheffer Norbert ev. are based on voluntary consent or legal authorization.
We draw the attention of individuals providing data to Scheffer Norbert ev. that if they provide personal data of another person, it is their responsibility to obtain the consent of the affected individual. The data processing principles comply with the applicable data protection regulations, including:
Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (Infotv.);
Regulation (EU) 2016/679 of the European Parliament and of the Council (April 27, 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation, GDPR);
Act V of 2013 on the Civil Code (Ptk.);
-
Act LIII of 2017 on the Prevention and Combating of Money Laundering and Terrorist Financing (Pmt.);
(Pmt.);
Act CCXXXVII of 2013 on Credit Institutions and Financial Enterprises (Hpt.).

6. Locations of Physical Data Storage
Personal data (i.e., data that can be associated with your person) may be processed in the following ways: Firstly, technical data related to your computer, browser, internet address, and visited pages are automatically generated in our computer system in connection with maintaining an internet connection.
Secondly, you may provide your name, contact information, or other data if you wish to establish personal contact with us while using the website.

7. Rights of Data Subjects and Enforcement Options
The data subject has the right to request information about the processing of their personal data and may request the correction, deletion (except for mandatory data processing), or withdrawal of their data. They may also exercise their right to data portability and objection in the manner indicated at the time of data collection or through the contact details provided above.

7.1 Right to Information
Scheffer Norbert ev. takes appropriate measures to ensure that all information regarding personal data processing, as mentioned in Articles 13 and 14 of the GDPR, and all notifications under Articles 15–22 and 34, are provided to the data subject in a concise, transparent, intelligible, and easily accessible form, using clear and plain language.

7.2 Right of Access
The data subject has the right to obtain confirmation from the data controller as to whether personal data concerning them is being processed. If such processing is taking place, they have the right to access the personal data and the following information:

7.3 Right to Rectification
The data subject may request the correction of inaccurate personal data concerning him or her processed by Scheffer Norbert ev. or Scheffer Viktorina and the completion of incomplete data.

7.4 Right to Erasure
The data subject has the right to request the deletion of their personal data without undue delay if:
The data is no longer necessary for the purposes for which it was collected or processed;
The data subject withdraws their consent, and there is no other legal basis for the processing;
The data subject objects to the processing, and there is no overriding legitimate reason for processing;
The data was unlawfully processed;
The data must be deleted to comply with a legal obligation;
The data was collected in connection with offering information society services.
The right to erasure does not apply where processing is necessary for the exercise of freedom of expression and information, compliance with a legal obligation, tasks carried out in the public interest, or for the establishment, exercise, or defense of legal claims.

7.5 Right to Restriction of Processing
At the request of the data subject, Scheffer Norbert ev. shall restrict the processing of the data if one of the following conditions is met:
the data subject disputes the accuracy of the personal data, in which case the restriction shall apply for a period enabling the accuracy of the personal data to be verified;
the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead;
the controller no longer needs the personal data for the purposes of the processing, but the data subject requires them for the establishment, exercise or defence of legal claims; or
the data subject has objected to the processing; in which case the restriction shall apply for a period of time until it is determined whether the legitimate grounds of the controller override those of the data subject.
Where processing is subject to restriction, personal data may be processed, with the exception of storage, only with the consent of the data subject, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for important public interests of the Union or of a Member State.

7.6 Right to data portability
The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to the controller, in a structured, commonly used and machine-readable format and to transmit those data to another controller.

7.7 Right to object
The data subject shall have the right, on grounds relating to his or her particular situation, to object at any time to processing of personal data concerning him or her which is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, or for the purposes of the legitimate interests pursued by the controller or by a third party, including profiling based on those provisions. In the event of an objection, the controller shall no longer process the personal data unless there are compelling legitimate grounds for doing so which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.

7.8 Automated decision-making in individual cases, including profiling. The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.

7.9 Right to withdraw
The data subject shall have the right to withdraw his or her consent at any time.

7.10 Right to a court
The data subject may take legal action against the data controller in the event of a violation of his or her rights. The court shall hear the case without delay.

7.11 Data protection authority procedure
A complaint can be filed with the National Data Protection and Freedom of Information Authority:
Name: National Data Protection and Freedom of Information Authority
Headquarters: 1125 Budapest, Szilágyi Erzsébet fasor 22/C.
Mailing address: 1530 Budapest, P.O. Box: 5.
Telephone: 0613911400
Fax: 0613911410