Skip to content
SZINORG What We Do Portfolio Sustainability For Investors News Contact HU

Privacy Notice

How SZINORG Universal Zrt. processes personal data in connection with operating the szinorg.hu website.

In force from: 28 August 2026

This is an English translation provided for convenience. In the event of any discrepancy, the Hungarian version of this notice prevails.

I. General information

1. The controller

Company nameSZINORG Universal Vagyonkezelő Zártkörűen Működő Részvénytársaság
Registered office4025 Debrecen, Simonffy utca 34–36.
Represented bySzabó Sándor, Chief Executive Officer, member of the Board of Directors
Phone+36 52 507 300
Emailinfo@szinorg.hu
Websiteszinorg.hu

2. Data protection officer

AppointedDr. Czére-Réti Ügyvédi Iroda
Address4025 Debrecen, Hatvan utca 55.
Contacttel: 06/20-210-9939, email: info@drreti.hu

3. Principles

In processing personal data, the Company observes the following principles [GDPR Article 5]:

  • Lawfulness, fairness and transparency: personal data is processed lawfully, fairly and in a manner transparent to the data subject.
  • Purpose limitation: personal data is collected only for specified, explicit and legitimate purposes, and is not processed in a manner incompatible with those purposes.
  • Data minimisation: only data necessary to achieve the purpose is processed.
  • Accuracy: the data processed is accurate and, where necessary, kept up to date; inaccurate data is rectified or erased without delay.
  • Storage limitation: personal data is stored only for as long as is necessary to achieve the purpose of processing.
  • Integrity and confidentiality: appropriate technical and organisational measures ensure the security of the data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.
  • Accountability: the Company is responsible for compliance with these principles and is able to demonstrate that compliance.

4. Security of processing

Taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of processing, as well as the risk to the rights and freedoms of natural persons, the Company implements appropriate technical and organisational measures. The website is served in its entirety over an encrypted (HTTPS) connection. The Company has not adhered to an approved code of conduct or to a certification mechanism under the GDPR.

5. Hosting and data storage

The Company uses a hosting provider to operate the website. The content of the website and the associated data files are stored by the Firebase Hosting, Cloud Firestore and Cloud Storage services of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). According to the provider's information, the website is served from a data centre located within the European Economic Area. Domain name and DNS services are provided by Websupport Magyarország Kft. (address: 1119 Budapest, Fehérvári út 97-99.). Data processed in the Company's own IT systems is stored on the IT infrastructure used by the Company.

II. Processing connected with the website

The website has no registration, login or customer account, and no data collection form. The processing described below relates solely to the operation of the website; processing connected with the Company's other activities is covered by separate notices.

1. Operational log data

In order to maintain IT security and to resolve faults, the system serving the website logs dynamic requests — in particular requests for news and article pages. The data processed comprises: the time of the request (timestamp), the address of the requested page (URL), the browser identifier (user agent), and the response status. The request log accessible to the Company does not contain the IP address of the website visitor; the log shows the IP address of the Google CDN server. No log accessible to the Company is generated for the serving of static pages.

The legal basis for processing is legitimate interest under GDPR Article 6(1)(f): the Controller has a legitimate interest in ensuring the security, availability and proper functioning of the website and the IT system serving it, in detecting and preventing IT attacks and unauthorised access, and in identifying any operational faults.

Log data is not used for marketing purposes and no profiling is carried out. Retention period: 30 days, after which log data is deleted automatically.

2. Traffic measurement

To measure website traffic — solely with the visitor's prior consent [GDPR Article 6(1)(a)] — we use Google Analytics 4. The purpose of measurement is to understand and improve use of the website. The service may technically use the visitor's IP address, among other things to determine approximate geographic location; however, according to Google's own information, the IP addresses of users from the European Economic Area are not logged or stored by Google but discarded after use.

A list of the cookies placed, their retention periods, and how consent may be given and withdrawn are set out in the Cookie Notice. We do not use advertising or social media cookies.

3. Contact

Where contact is initiated using the email addresses and telephone numbers published on the website, the data that comes to the Company's knowledge — name, email address, telephone number and the content of the enquiry — is processed solely in connection with the subject of the enquiry, for the purposes of handling the contact, answering the data subject's enquiry and conducting the related communication.

The legal basis for processing is GDPR Article 6(1)(b) (taking steps at the data subject's request prior to entering into a contract) and Article 6(1)(f) legitimate interest (business communication).

Where contact is not followed by the conclusion of a contract, and no other purpose or legal basis justifies further processing, the Company erases the personal data 6 months after the enquiry is closed. Where a contractual relationship arises from the contact, or where another purpose and legal basis justifies further processing, the retention period applicable to that processing applies.

4. Publication of our colleagues' data

4.1. Publication of name, position and business contact details

The website displays the name, position and photograph of the Company's senior officers and designated contacts, and — in the context of investor relations — their company telephone number and email address.

The purpose of processing is to present the Company credibly and to facilitate business contact.

Legal basis: legitimate interest under GDPR Article 6(1)(f). The Company has a legitimate interest in making the contact details of persons and contacts relevant to its operation available to website visitors, business partners and other data subjects, thereby enabling direct and effective contact.

As a general rule, the Company publishes personal data on the website for as long as the data subject holds the relevant position or contact role. Where the data subject objects to the processing under GDPR Article 21, the Company examines whether there are compelling legitimate grounds justifying continued processing.

4.2. Publication of photographs

The Company publishes photographs of certain senior officers and staff on the website only with the data subject's prior, voluntary and informed consent.

Purpose of processing: to present the Company in a more personal and credible way, to make the persons named on the website easier to identify, and to facilitate contact.

Legal basis for processing: the data subject's consent under GDPR Article 6(1)(a).

The photograph remains available on the website until consent is withdrawn, but at most for as long as the data subject holds the relationship in respect of which the photograph was published.

The data subject may withdraw consent at any time, without giving reasons. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal. Where consent is withdrawn, the Company arranges for the photograph to be removed without delay, provided there is no other appropriate legal basis for its further processing.

5. Mandatory disclosures

The publication of investor, accounting and sustainability documents on the website is based on statutory obligations and on disclosure obligations connected with the bond programme [GDPR Article 6(1)(c)]. In some cases these documents also contain the names of natural persons acting as signatories or auditors. The documents remain available for the period prescribed by law.

The publication and retention of accounting and sustainability documents is governed in particular by Sections 95/I, 153–154/B and 169 of Act C of 2000 on Accounting; as a general rule, accounting vouchers and the documents underlying them are retained for at least 8 years. Documents relating to the bond programme remain available for the period prescribed by the applicable capital market rules, the bond programme and the issue documentation, or — where the disclosure obligation is linked to the existence of the bond — for the term of the bond.

6. Summary table

PurposeData subjectsData processedLegal basisDuration
Secure operation visitors log data (timestamp, requested URL, browser identifier (user agent), response status) 6(1)(f) legitimate interest 30 days
Traffic measurement visitors cookie identifier, usage data 6(1)(a) consent 2 months
Contact enquirers, partners name, contact details, content of the enquiry 6(1)(b) and 6(1)(f) 6 months from the closure of the enquiry
Presenting our colleagues senior officers, contacts name, position, photograph, company contact details for name, position and company contact details: 6(1)(f); for photographs: 6(1)(a) for name, position and company contact details: for as long as the position or contact role is held; for photographs: until consent is withdrawn, but at most for as long as the data subject's related relationship exists
Mandatory disclosures signatories, auditors the names appearing in the documents 6(1)(c) legal obligation for accounting vouchers and the documents underlying them, as a general rule at least 8 years; for documents relating to the bond programme, the period prescribed by the applicable rules, the bond programme and the issue documentation, or — where the disclosure obligation is linked to the existence of the bond — the term of the bond.

III. Processors and data transfers

In connection with operating the website, the Company does not transfer or sell personal data to any independent controller. The following processors are used for the operation of the website:

ProcessorServiceData concerned
Google Ireland Limited Firebase Hosting, Cloud Firestore, Cloud Storage — hosting and serving; Google Analytics 4 — traffic measurement operational log data, the content published on the website, and — where consent is given — measurement data
Websupport Magyarország Kft. domain name registration and DNS services the registration data associated with the domain

Processors act on the Company's instructions and take no independent processing decisions. Where a processor transfers data outside the European Economic Area, it does so on the basis of the standard contractual clauses (SCC) adopted by the European Commission.

When the embedded map on the Contact page and the website's fonts are loaded, the visitor's browser connects directly to Google's service; in that respect Google acts as an independent controller. Details are set out in the Cookie Notice.

IV. Rights of the data subject

The data subject may exercise the following rights at any time using the Company's contact details — by post to the registered office, or at info@szinorg.hu. The Company responds to requests without undue delay and at the latest within one month; this period may be extended by a further two months in view of the complexity of the request, of which the data subject will be informed.

  • Access: to obtain confirmation as to whether personal data concerning them is being processed, access to that data, and information on the purpose of processing, the categories of data concerned, the recipients, the storage period and the source of the data.
  • Rectification: to request the rectification of inaccurate data and the completion of incomplete data.
  • Erasure: to request erasure where the data is no longer needed, where consent has been withdrawn and no other legal basis applies, where the data subject has objected to the processing, where the data has been processed unlawfully, or where erasure is required by law. The Company does not erase data it is required by law to retain.
  • Restriction of processing: to request restriction where the accuracy of the data is contested, where processing is unlawful but the data subject opposes erasure, where the Company no longer needs the data but the data subject requires it for the establishment of legal claims, or where the data subject has objected to the processing.
  • Objection: to object at any time, on grounds relating to their particular situation, to processing based on legitimate interest. In that case the Company will no longer process the data unless it demonstrates compelling legitimate grounds which override the interests, rights and freedoms of the data subject, or which relate to the establishment, exercise or defence of legal claims.
  • Data portability: to receive data processed by automated means on the basis of consent or a contract in a structured, commonly used, machine-readable format, and to request its transmission to another controller.
  • Withdrawal of consent: where processing is based on consent, to withdraw that consent at any time; this does not affect the lawfulness of processing before the withdrawal.

No profiling or automated decision-making is carried out in connection with the data processed.

V. Personal data breach

A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

The Company notifies the competent supervisory authority of a breach without undue delay and at the latest within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to the rights of natural persons. Where the breach is likely to result in a high risk to the rights and freedoms of the data subject, the Company also informs the data subject without delay of the nature of the breach and of measures proposed to mitigate its adverse effects. The Company keeps a record of breaches.

VI. Remedies

1. Complaint to the Company

Complaints relating to data processing may be submitted using the following contact details: SZINORG Universal Vagyonkezelő Zrt., 4025 Debrecen, Simonffy utca 34–36., info@szinorg.hu. Where a complaint also qualifies as a data subject request under the GDPR, the Company responds within the time limit set out in GDPR Article 12.

2. Supervisory authority

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Postal address: 1363 Budapest, Pf. 9.
Address: 1055 Budapest, Falk Miksa utca 9-11.
Phone: +36 1 391 1400
Email: ugyfelszolgalat@naih.hu
Web: www.naih.hu

3. Judicial remedy

Where the data subject considers that their rights have been infringed in connection with the processing of their personal data, they may bring proceedings before the regional court (törvényszék) competent for their place of residence or stay.

VII. Amendment of this notice

The Company reserves the right to amend this notice unilaterally, in particular in the event of a change in legislation or in the operation of the website. The text in force at any given time is available on this page.

SZINORG

Over 70 years of building and development — wholly Hungarian-owned.

Sitemap

  • What We Do
  • Portfolio
  • For Investors
  • News
  • Contact

For Investors

  • Latest reports
  • Investor relations
  • Sustainability

Contact

  • 4025 Debrecen, Simonffy u. 34–36.
  • +36 52 507 300
  • info@szinorg.hu
  • LinkedIn
  • Privacy notice
  • Cookie notice
  • Imprint

© 2026 SZINORG Universal Zrt. All rights reserved.