Privacy Notice
Below we inform you about the processing of personal data in connection with the https://solaregio.hu/ website operated by Régió Terv Kft.
This Privacy Notice contains essential information concerning the processing of your personal data. Reading or acknowledging this Notice does not constitute consent to all processing activities. Where consent is required for a particular processing activity, the Data Controller requests it separately by means of the Data Subject’s prior, voluntary and unambiguous declaration. The Data Controller publishes material amendments to this Notice on the Website and, where justified, also informs the Data Subject separately. An amendment in itself may not result in personal data previously provided being processed for a new purpose or on a new legal basis.
This Privacy Notice applies exclusively to the personal data of natural-person Data Subjects, since data relating to legal persons and other organisations without legal personality do not constitute personal data.
I. Data Controller
Name: Régió Terv Kft.
Address: 4032 Debrecen, Böszörményi út 161, Hungary
Telephone: +36-20/ 519-9554
E-mail: info@solaregio.hu
II. Basic information
II.1. Where the legal basis for processing by Régió Terv Kft. is the voluntary consent of the Data Subject, the Data Subject may withdraw their consent at any time. Such withdrawal does not affect the lawfulness of processing carried out before the withdrawal. The Data Controller retains data proving the fact of consent for as long as this is required to demonstrate consent or by another legitimate interest of the Data Controller.
II.2. The Data Subject is responsible for the truthfulness and accuracy of the personal data provided. The Data Controller does not verify the authenticity of the personal data supplied. The Data Controller is not liable for the processing of incorrect or false data provided by the Data Subject, or for any damage suffered by the Data Subject or a third party as a result of incorrect or false information provided by the Data Subject. The Data Controller also accepts no liability if it is misled regarding the legal capacity of the Data Subject.
II.3. Merely visiting or using the Website, or providing personal data, does not in itself constitute consent to data processing. Where processing is based on consent, consent may be given only by the Data Subject’s voluntary, specific and unambiguous declaration based on appropriate information.
II.4. In the case of a legally incapable Data Subject under the age of 14, only the Data Subject's legal representative may provide personal data on their behalf. A declaration by the legal representative is required for the provision of personal data relating to a legally incapable User. The signed declaration must be delivered to the Data Controller in person, by post or by email, or may be made in another verifiable manner (e.g. by image and/or audio recording).
II.5. The processing of the personal data of a minor with limited legal capacity who has not yet reached the age of 16 requires the consent of the minor's legal representative.
II.6. A declaration of consent to data processing made by a minor who has reached the age of 16 is valid without the consent or subsequent approval of their legal representative (including registration or the provision of personal data by other means). Depending on the method of data collection, such a Data Subject may provide consent to processing.
II.7. Unless otherwise required by law, the Data Controller processes the personal data made available to it only for the purposes described in this notice and only to the extent and for the period necessary to achieve those purposes.
II.8. Depending on the consent provided by the visitor, the Data Controller's Website places cookies (small text data files) on the visitor's computer or mobile device for the purposes and on the legal bases set out in the cookie notice. More detailed information on cookie processing is provided in the cookie notice displayed on the Data Controller's Website, including information on the scope of the data collected and the logic applied, as well as the significance and expected consequences of the processing for the Data Subject.
III. Individual processing activities
1. Operation and use of the Website
| Data Subjects | Natural persons visiting the SolaRegio website |
|---|---|
| Purpose of processing | Making the Website available, ensuring its proper and secure operation, and detecting technical errors and misuse |
| Categories of data processed | During operation of the Website: IP address, time of the visit and requests, address of the page visited or resource requested, browser and device data, and technical and security log data. |
| Legal basis for processing | For the technical operation and IT security of the Website: the legitimate interest of the Data Controller [Article 6(1)(f) GDPR]. |
| Recipients | Contabo GmbH. |
| Processor | Hosting provider: Contabo GmbH. (Aschauer Straße 32a, 81549 Munich, Germany) The processor has access to those personal data of Data Subjects that are necessary for the performance of its duties. Processing by the processor continues for the term of the service agreement concluded with the processor. |
| Duration of processing | IP addresses and log data are processed only for the duration of use of the website and webshop. |
| Other | For data collected while browsing the Website, see the Cookie Notice |
2. Sending newsletters (professional advice and latest offers)
| Data Subjects | Persons subscribing to the newsletter on the SolaRegio Website. Any natural person who wishes to receive regular information about the Data Controller’s news and offers and therefore subscribes to the newsletter service by providing personal data. |
|---|---|
| Purpose of processing | Sending informational e-mails summarising energy-sector developments appearing on the Website, the latest offers and links to them. The purpose of sending informational e-mails (newsletters) containing energy news and information about the Data Controller’s latest products and services is to provide the recipient with comprehensive general information. |
| Categories of data processed | Name (optional), e-mail address |
| Legal basis for processing | Subscription to the newsletter is based on voluntary, prior consent [Article 6(1)(a) GDPR]. |
| Recipients | Contabo GmbH. |
| Processor | Hosting provider: Contabo GmbH. (Aschauer Straße 32a, 81549 Munich, Germany) The processor has access to those personal data of Data Subjects that are necessary for the performance of its duties. Processing by the processor continues for the term of the service agreement concluded with the processor. |
| Duration of processing | The Data Controller processes the data until consent is withdrawn (unsubscribe). |
| Other |
3. Requesting a consultation on the Website
| Data Subjects | Persons requesting a free consultation on the SolaRegio Website. |
|---|---|
| Purpose of processing | Providing information and consultation to the interested person, preparing an offer and preparing the conclusion of a contract. |
| Categories of data processed | Name, email address and telephone number (optional) |
| Legal basis for processing | Article 6(1)(b) GDPR – taking steps at the request of the Data Subject prior to entering into a contract. |
| Recipients | Contabo GmbH. |
| Processor | Hosting provider: Contabo GmbH. (Aschauer Straße 32a, 81549 Munich, Germany) The processor has access to the personal data of Data Subjects that are necessary for the performance of its duties. Processing by the processor continues for the term of the service agreement concluded with the processor. |
| Duration of processing | For no longer than one year after the request for quotation is closed or, where no contract is concluded, until the Data Subject's request for erasure is fulfilled, provided that no other legal basis exists for continued processing. |
| Other |
4. Persons purchasing products sold in the webshop
| Data Subjects | Persons purchasing products sold in the SolaRegio webshop |
|---|---|
| Purpose of processing | Conclusion of contracts relating to products sold by the Data Controller, performance of tasks connected with performance of the contract (delivery of the ordered product, invoicing), and communication to facilitate performance. Compliance with statutory invoicing and document-retention obligations. |
| Categories of data processed | 1. Order and contact data: customer name, e-mail address, telephone number, name, quantity and purchase price of the ordered product, order identifier, dates of the order, confirmation and performance, selected payment, delivery or collection method, and communications relating to the order. 2. Delivery data: recipient name, delivery address, telephone number, e-mail address, order and parcel identifiers, and data and instructions necessary for delivery. In the case of personal collection: name and contact details of the person collecting the order, order identifier, place and time of collection and, where necessary, data required to verify collection. 3. Invoicing data: billing name, billing address and, where necessary, tax number. Where the customer is a legal person, the name and contact details of the natural-person contact or representative may also be processed. 4. Payment-related data: selected payment method, amount payable and paid, payment status and time, and transaction or payment identifier. In the case of bank transfer: name and bank-account number of the payer, time and amount of the transfer and the payment reference. In the case of Barion bank-card payment, the Data Controller does not receive or store the complete bank-card data. |
| Legal basis for processing | Performance of a contract [Article 6(1)(b) GDPR]. Compliance with a legal obligation [Article 6(1)(c) GDPR] with regard to issuing and retaining accounting documents. |
| Recipients | Online bank-card payment: Barion Payment Zrt. (1117 Budapest, Irinyi József utca 4-20, 2nd floor; company registration number: 01-10-048552; tax number: 25353192-2-43), which acts as an independent data controller in relation to provision of the payment service, execution of the transaction, fraud prevention and its own statutory obligations. Bank transfer: banks and payment-service providers involved in the transfer act as independent data controllers in relation to their own services and statutory obligations. Delivery: GLS General Logistics Systems Hungary Csomag-Logisztikai Kft., which acts as an independent data controller in relation to performance of the carriage service and its own statutory obligations. The recipient’s name, delivery address, telephone number, e-mail address, parcel and order identifiers, and delivery instructions may be transmitted to GLS. National Tax and Customs Administration of Hungary (NAV): recipient of the statutory online reporting of invoice data. |
| Processor | Accounting office: Csősz Mónika Fruzina Sole Proprietor (4029 Debrecen, Virág utca 34, 3rd floor, door 14). Within the accounting activity performed on the Data Controller’s instructions, it may access invoices and accounting documents as a processor. When fulfilling statutory obligations directly applicable to it, it may act as an independent data controller. |
| Duration of processing | Data relating to performance of the contract that do not qualify as accounting documents are processed by the Data Controller until the end of the applicable civil-law limitation period (5 years). Invoices and accounting documents supporting bookkeeping records are retained for 8 years. Where a legal dispute is pending, the related data may be processed until the proceedings are finally concluded or for as long as necessary for enforcement of the claim. |
| Other | The Data Controller uses the Számlázz.hu invoicing service to issue invoices. Invoicing data are stored in the Data Controller’s own IT system. |
Third-party data controllers process the personal data communicated by us in their own name and in accordance with their own privacy policies.
“Third party” means a natural or legal person, public authority, agency or other body other than the Data Subject, the Data Controller, the processor and persons who, under the direct authority of the Data Controller or processor, are authorised to process personal data.
5. Information relating to the Data Controller's services
| Data Subjects | Persons using the Data Controller's services |
|---|---|
| Purpose of processing | Communication relating to the services provided by the Data Controller and performance of the contract |
| Categories of data processed | Name, address, telephone number and email address, as necessary |
| Legal basis for processing | Performance of a contract (Article 6(b) GDPR) |
| Processor | - |
| Duration of processing | For the duration of use of the service |
| Other | This processing includes email, telephone or written information from the Data Controller containing essential information connected with the provision of services (so-called system messages and notices). It is therefore not possible to unsubscribe from or refuse such information. |
6. Other communication and complaint handling
| Data Subjects | Persons contacting the Data Controller or submitting a complaint |
|---|---|
| Purpose of processing | Where the Data Subject contacts the Data Controller, the purpose of processing depends on the purpose of the contact (e.g. responding to incoming e-mails, substantive handling of a complaint and providing information on the measures taken, etc.). |
| Categories of data processed | Name, e-mail address, telephone number and home address, depending on which data the Data Subject provides or which communication channel is used. |
| Legal basis for processing | For a consumer complaint: compliance with a legal obligation [Article 6(1)(c) GDPR]. For other contacts: depending on the subject matter of the enquiry, performance of a contract or the Data Controller’s legitimate interest in responding to enquiries and being able to demonstrate the response subsequently [Article 6(1)(b) or (f) GDPR]. |
| Processor | - |
| Duration of processing | The Data Controller retains a written consumer complaint, a copy of the response and the record drawn up concerning the complaint for 3 years. Data relating to other enquiries are processed for the time necessary to provide a response and, where justified, to enforce claims. |
| Other | This processing includes e-mail, telephone or written notices from the Data Controller containing information essential to the provision of services (so-called system messages and notices); it is therefore not possible to unsubscribe from or refuse such information. |
7. Enforcement of claims, disputes and official proceedings
| Data Subjects | Persons against whom the Data Controller asserts a claim (for example, where the Data Controller sends a demand letter or commences legal proceedings for payment of a service fee/purchase price), or persons asserting a claim against the Data Controller. Data Subjects whose personal data are processed in connection with a matter affected by official proceedings. |
|---|---|
| Purpose of processing | Enforcement and collection of the Data Controller’s claims, proving the Data Controller’s position where a claim is asserted against it, and complying with requests and orders from authorities. |
| Categories of data processed | Name, home address, telephone number and other information relating to the claim. |
| Legal basis for processing | Legitimate interest [Article 6(1)(f) GDPR]. Legitimate interest: debt collection, enforcement of claims and legal protection. Compliance with a legal obligation [Article 6(1)(c) GDPR]. |
| Recipient | Legal representative, where necessary |
| Purpose of transfer | Enforcement of claims |
| Legal basis for transfer | The Data Controller’s legitimate interest. Legitimate interest: debt collection, enforcement of claims and legal protection. |
| Duration of processing | 5 years after the claim-enforcement procedure or proceedings have been finally concluded. |
| Other |
8. “Robinson list”
| Data Subjects | Persons who have objected to direct-marketing communications |
|---|---|
| Purpose of processing | Prevention of unlawful processing operations |
| Categories of data processed | Name, home address, email address and telephone number |
| Legal basis for processing | Legitimate interest (Article 6(f) GDPR). The legitimate interest is the Data Controller's interest in complying with applicable data-protection and other legislation and fulfilling the Data Subject's request concerning informational self-determination. |
| Duration of processing | The Data Controller processes the data until direct-marketing processing ceases or for as long as the legitimate interest continues to exist. |
| Other |
9. Contact persons of business partners
| Data Subjects | Contact persons of business partners |
|---|---|
| Purpose of processing | Ensuring smooth and uninterrupted communication during contractual relationships through contact persons, for which the Data Controller needs to know the contact persons' details |
| Categories of data processed | Name, email address, telephone number, related company name and, where applicable, position |
| Legal basis for processing | Legitimate interest (Article 6(f) GDPR). The legitimate interest is ensuring the communication required for performance of contracts concluded with third parties. |
| Processor | - |
| Duration of processing | For the term of the underlying contract. Where the personal data appear in the contract or on an invoice issued in connection with it, the Data Controller retains those documents for eight years in accordance with the rules applicable to accounting documents. |
| Other |
IV. Data security
The Data Controller ensures the security of data in accordance with the applicable requirements.
As part of its data-security measures, the Data Controller implements in particular the technical and organisational measures and establishes the procedural rules required to ensure that the processed data are protected against unauthorised access, alteration, transfer, disclosure, erasure, destruction, accidental loss or damage, and against becoming inaccessible as a result of changes in the technology used.
All employees and other staff of the Data Controller are required, by virtue of their employment or other legal relationship, to comply with the above principles concerning processing and data security.
To protect the confidentiality and integrity of Data Subjects' personal data, the Data Controller stores personal data in password-protected databases. Personal data are protected by network and infrastructure security measures, including firewalls, content filtering and antivirus software. Passwords are stored using a one-way, non-reversible hashing procedure.
V. Your rights as a Data Subject
As a Data Subject, you have the following rights under the GDPR:
Right of access: Under Article 15 GDPR, you may at any time request confirmation as to whether we process your personal data. Where such processing is taking place, Article 15 GDPR entitles you to access the personal data and certain additional information, including the purposes of processing, the categories of personal data, the categories of recipients, the envisaged retention period, the source of the data, the use of automated decision-making and, where data are transferred to a third country, information concerning the appropriate safeguards, and to receive a copy of your personal data.
Right to rectification: Under Article 16 GDPR, you have the right to request the rectification of inaccurate or incorrect personal data concerning you.
Right to erasure: Where the conditions of Article 17 GDPR are met, you may request the immediate erasure of personal data stored about you. The right to erasure does not apply, among other cases, where processing is necessary for exercising the right to freedom of expression and information, complying with a legal obligation of our company (such as statutory retention periods), or establishing, exercising or defending legal claims.
Right to restriction of processing: Where the conditions of Article 18 GDPR are met, you may request restriction of the processing of your personal data.
Right to data portability: Where the conditions of Article 20 GDPR are met, you may request that personal data concerning you be provided in a structured, commonly used and machine-readable format.
Right to withdraw consent: You may withdraw at any time, with effect for the future, any consent previously given to the processing of your personal data. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
Right to object: Where the conditions of Article 21 GDPR are met, you may object to the processing of your personal data, as a result of which we must cease processing them. The right to object applies only within the limits laid down in Article 21 GDPR. Furthermore, ceasing processing may conflict with our company's interests, in which case we may remain entitled to process your personal data despite your objection.
If you submit an objection, we will no longer process your personal data unless the processing is justified by compelling legitimate grounds that override your interests, rights and freedoms, or the processing is connected with the establishment, exercise or defence of legal claims.
Right to lodge a complaint with a supervisory authority: Where the conditions of Article 77 GDPR are met, you may lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement, if you consider that the processing of your personal data infringes the GDPR. The right to lodge a complaint is without prejudice to other administrative or judicial remedies. Right to rectification: Under Article 16 GDPR, you have the right to request the rectification of inaccurate or incorrect personal data concerning you.
The competent supervisory authority:
Hungarian National Authority for Data Protection and Freedom of Information
Address: 1055 Budapest, Falk Miksa utca 9-11, Hungary
Postal address: 1363 Budapest, PO Box 9, Hungary
Telephone: +36-1-391-1400
Fax: +36-1-391-1410
Email: ugyfelszolgalat@naih.hu
Nevertheless, we recommend that you always submit your complaint to the Data Controller first.
If you wish to exercise your rights, please do so preferably in writing using the contact details of the Data Controller set out above.
VI. Obligation to provide data
You are generally not obliged to provide us with your personal data. If you do not provide the personal data required for contacting us, we will be unable to respond to your enquiry. Personal data that are strictly necessary and must be provided for the above processing purposes are indicated accordingly.
VII. Automated decision-making / Profiling
We do not use automated decision-making or profiling (automated analysis of personal characteristics).
VIII. Amendments
The Data Controller is entitled to amend this Notice. The amended Notice becomes effective upon publication on the Website at the time specified in it. An amendment in itself may not result in personal data previously provided being processed for a new purpose or on a new legal basis. If consent is required for new processing, the Data Controller will request new consent from the Data Subject before the processing begins.
24 August 2026.