About the data processing carried out in the Convoy Zero application.
The legally binding version is the Hungarian one. In the event of any discrepancy, the Hungarian text prevails.
Open the Hungarian versionST22connect Kft. (hereinafter referred to as the “Data Controller”) places particular emphasis on ensuring that, in the course of its data processing activities, it acts in compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the “General Data Protection Regulation” or “GDPR”), Act CXII of 2011 on Informational Self-Determination and Freedom of Information (hereinafter referred to as the “Info Act”), other applicable legislation, and the data protection practices developed by the Hungarian National Authority for Data Protection and Freedom of Information (hereinafter referred to as the “NAIH”).
Name: ST22connect Kft.
Registered office and mailing address: 15 Szentlőrinci út, 7634 Pécs, Hungary
Company registration number: 02-09-088009
Tax number: 32431115-2-02
Represented by: Turcsi Péter Zsolt, Managing Director
E-mail address: partners@convoyzero.com
The scope of the personal data processed includes the data provided or collected in connection with the use of the application and the services provided by the Data Controller.
The primary source of the data is the information provided by you and your activities within the application. Where, during registration or login, you use a profile created with an external service provider, in particular a Facebook, Google or Apple account, the Data Controller receives certain personal data necessary for registration or login from the external service provider selected by you. The Data Controller processes only those data that are transferred by the external service provider as part of the relevant login method and that are necessary for creating or identifying the user account.
If any of the personal data processed undergoes any modification or change during the period of data processing, please notify us without delay using the contact details provided in Section 1.
The Data Controller processes the personal data provided by the data subject in the course of contacting the Data Controller — by e-mail, contact form or telephone — for the purpose of communication, on the basis of the data subject’s explicit and voluntary consent expressed by initiating contact (Article 6(1)(a) of the General Data Protection Regulation). The provision of personal data is voluntary; however, in the absence of the required data or consent, we may be unable to respond to or fulfil your request for contact. The data will be processed until the communication is concluded or until the consent is withdrawn.
The Data Controller processes the data subject’s name, e-mail address, telephone number and identification data associated with the user account for the purposes of creating and maintaining the user account of a natural person, identifying the user, enabling login to the application, and providing access to functions of the application that require registration.
The legal basis for the processing is Article 6(1)(b) of the General Data Protection Regulation, as the processing is necessary for entering into and/or performing a contract between the data subject and the Data Controller.
Where the data subject registers or logs in using a Facebook, Google, Apple or other external service provider account available within the application, the Data Controller receives from the selected service provider the data necessary to identify the user and create the user account. Such data may include, in particular, the unique user identifier generated by the external service provider, the user’s name and e-mail address. The Data Controller does not obtain or store the password associated with the external service provider account.
Where registration or login is carried out using an external service provider account, the source of the data subject’s personal data is the external service provider selected by the data subject.
The provision of the personal data necessary to create a user account is a condition for using the service. The personal data will be processed for as long as the user account remains active or until it is deleted. Where certain data must also be processed for another purpose, the retention period specified for that particular processing purpose shall apply.
Where registration is made on behalf of a company, the Data Controller processes the name, e-mail address and telephone number of the contact person for the purpose of maintaining contact, on the basis of Article 6(1)(f) of the General Data Protection Regulation. The processing shall continue until the person ceases to act as the contact person, a new contact person is designated, or the registration is deleted.
On the basis of the data subject’s prior, voluntary, specific and explicit consent, the Data Controller processes certain personal data of the data subject and data relating to the use of the application for the purpose of providing personalised marketing content, offers and advertisements.
The categories of personal data processed include the data subject’s name, e-mail address, type of driving licence and vehicles the data subject is authorised to drive, work experience, languages spoken, preferred working schedule and type of transport assignment, typical routes, preferred base country, as well as data relating to the use of the application, including in particular the content and job advertisements viewed by the data subject and the use of certain functions of the application.
Using the above data, the Data Controller may create a profile relating to the data subject’s professional preferences and interests in order to display job advertisements, services, offers and marketing content that are expected to be relevant to the data subject and, where the data subject has also consented to the use of the relevant communication channel, to send such content to the data subject.
The legal basis for the processing is the data subject’s consent pursuant to Article 6(1)(a) of the General Data Protection Regulation. Giving consent is voluntary, and refusal to give consent or withdrawal of consent does not affect the use of the basic functions of the application.
The data subject may withdraw consent at any time, without giving reasons and free of charge. Following the withdrawal of consent, the Data Controller will no longer process the data subject’s personal data for the purposes of personalised marketing and related profiling. The profiling does not result in a decision based solely on automated processing that produces legal effects concerning the data subject or similarly significantly affects the data subject. The processing shall continue until the consent is withdrawn or the user account is deleted.
The Data Controller processes certain personal data of the data subject and data relating to the use of the application for the purpose of providing personalised marketing content, offers and advertisements, on the basis of the data subject’s prior, voluntary, specific and explicit consent.
The categories of personal data processed include the data subject’s name, e-mail address, type of driving licence and vehicles the data subject is authorised to drive, work experience, languages spoken, preferred working schedule and type of transport assignment, typical routes, preferred base country, as well as data relating to the use of the application, including in particular the content and job advertisements viewed by the data subject and the use of certain functions of the application.
Using the above data, the Data Controller may create a profile relating to the data subject’s professional preferences and interests in order to display job advertisements, services, offers and marketing content that are expected to be relevant to the data subject and, where the data subject has also consented to the use of the relevant communication channel, to send such content to the data subject.
The legal basis for the processing is the data subject’s consent pursuant to Article 6(1)(a) of the General Data Protection Regulation. Giving consent is voluntary, and refusal to give consent or withdrawal of consent does not affect the use of the basic functions of the application.
The data subject may withdraw consent at any time, without giving reasons and free of charge. Following the withdrawal of consent, the Data Controller will no longer process the data subject’s personal data for the purposes of personalised marketing and related profiling. The profiling does not result in a decision based solely on automated processing that produces legal effects concerning the data subject or similarly significantly affects the data subject. The processing shall continue until the consent is withdrawn or the user account is deleted.
.
The Data Controller, on the basis of the data subject’s explicit and voluntary consent pursuant to Article 6(1)(a) of the General Data Protection Regulation, transfers the data subject’s name, e-mail address, telephone number, CV and video interview for the purpose of enabling the data subject to apply for a job advertisement, depending on the advertiser’s subscription plan. The processing shall continue until the data are transferred or until the consent is withdrawn.
The Data Controller processes the personal data necessary for recruitment and placement services on the basis that such processing is necessary for entering into and performing a contract with you as the data subject, pursuant to Article 6(1)(b) of the General Data Protection Regulation.
The provision of these data is a prerequisite for entering into the contract and is also based on contractual obligations. Without providing the required data, the contract cannot be concluded or performed.
The personal data processed include your name, telephone number, e-mail address, type of driving licence and vehicles you are authorised to drive, work experience, languages spoken, preferred working schedule and type of transport assignment, typical routes, base country, and the video interview conducted with you.
The data will be processed for five years in accordance with the applicable civil law limitation period.
The Data Controller processes the data subject’s name and address for the purpose of issuing invoices in compliance with applicable legislation and fulfilling its statutory accounting document retention obligations, on the basis of compliance with a legal obligation pursuant to Article 6(1)(c) of the General Data Protection Regulation. The legal obligation arises from Section 159(1) of Act CXXVII of 2007 on Value Added Tax and Section 169(2) of Act C of 2000 on Accounting, under which invoices must be issued and retained for eight years. Furthermore, pursuant to Section 169(1)–(2) of the Accounting Act, business entities are required to retain accounting documents that directly or indirectly support their bookkeeping records. Accordingly, the personal data are processed for a period of eight years from the date of issuance of the invoice.
The Data Controller processes the data subject user’s name, telephone number, e-mail address and the content of the complaint for the purpose of handling consumer protection complaints, on the basis of compliance with a legal obligation pursuant to Article 6(1)(c) of the General Data Protection Regulation. Although the submission of a claim is voluntary, if the data subject chooses to submit such a claim to the Data Controller, the Data Controller becomes subject to certain legal obligations in connection with the handling of that claim, in accordance with Act CLV of 1997 on Consumer Protection. The provision of these data is required by law; without them, the Data Controller is unable to process the claim. Consumer protection complaints are retained for three years in accordance with the applicable provisions of the Consumer Protection Act.
The Data Controller processes the date and fact of the data subject’s consent, as well as the data subject’s IP address, for the purpose of demonstrating that consent was given, on the basis of compliance with a legal obligation pursuant to Article 6(1)(c) of the General Data Protection Regulation. When placing an order or subscribing to a newsletter, the IT system stores the technical data relating to the consent in order to enable the Data Controller to demonstrate at a later date that valid consent was obtained. This processing is necessary to comply with Article 7(1) of the General Data Protection Regulation, under which the Data Controller must be able to demonstrate that the data subject has consented to the processing of his or her personal data. Accordingly, the relevant data are retained until the end of the applicable limitation period following the termination of the underlying processing activity.
The Data Controller processes data relating to the use of the application, including the frequency and duration of use and the pages visited, for the purpose of improving its services, on the basis of its legitimate interests pursuant to Article 6(1)(f) of the General Data Protection Regulation. The data will be processed for a period of five years.
| Purpose of the Data Processing | Legal Basis for Data Processing | Categories of Personal Data Processed |
|---|---|---|
| Contact | Article 6(1)(a) of the General Data Protection Regulation | Data provided in the course of contacting the Data Controller |
| Registration, creation and management of a user account, and enabling login | Article 6(1)(b) of the General Data Protection Regulation | Name, e-mail address, telephone number, user identifier; where registration is carried out using an external service provider account, the unique identifier and other data necessary for registration provided by the external service provider |
| Communication and correspondence | Article 6(1)(a) of the General Data Protection Regulation; in the case of contact persons of companies, Article 6(1)(f) | Name, e-mail address, telephone number |
| Personalised marketing | Article 6(1)(a) of the General Data Protection Regulation | Name, e-mail address, type of driving licence and vehicles the data subject is authorised to drive, typical routes, preferred base country, manner of use of the application, work experience, languages spoken, preferred working schedule and type of transport assignment, as well as viewed content/job advertisements |
| Transfer of data for the purpose of enabling applications for job advertisements | Article 6(1)(a) of the General Data Protection Regulation | Name, e-mail address, telephone number, CV, video interview |
| Recruitment and placement services | Article 6(1)(b) of the General Data Protection Regulation | Name, telephone number, e-mail address, type of driving licence and vehicles the data subject is authorised to drive, work experience, languages spoken, preferred working schedule and type of transport assignment, typical routes, base country, and video interview |
| Issuing invoices | Article 6(1)(c) of the General Data Protection Regulation | Name, address |
| Handling other consumer protection complaints | Article 6(1)(c) of the General Data Protection Regulation | Name, e-mail address, telephone number, content of the complaint |
| Improvement of services | Article 6(1)(f) of the General Data Protection Regulation | Data relating to the use of the application (frequency of use, duration of use, pages visited) |
Access to the personal data is restricted to those employees of the Data Controller who require such access for the performance of their duties. Employees are subject to confidentiality obligations with regard to the personal data they access.
For accounting purposes, the Data Controller engages SHS Kft. as a data processor. The details of the data processor are as follows:
Name: SHS Könyvelő és Adótanácsadó Korlátolt Felelősségű Társaság
Registered office: 31 Szabadság utca, 7342 Mágocs, Hungary
Contact details: +36-30-377-6755, shs@shskft.hu
For the development of the application and the provision of IT support, the Data Controller engages Zengo Kereskedelmi és Szolgáltató Korlátolt Felelősségű Társaság as a data processor. The details of the data processor are as follows:
Name: Zengo Kereskedelmi és Szolgáltató Korlátolt Felelősségű Társaság
Registered office: 10 Szent István tér, 6721 Szeged, Hungary
Contact details: +36 (62) 202 039, info@zengo.eu
For analytics and crash detection purposes, the Data Controller engages Google LLC as a data processor. The details of the data processor are as follows:
Name: Google LLC
Registered office: 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
Contact details: privacy@google.com, +1 650-253-0000 (US headquarters)
Please note that, in connection with the use of data processor services, your personal data may be transferred to third countries outside the European Economic Area. Please be aware that in such countries public authorities may have broad rights of access to personal data, which may entail certain risks. In order to ensure an adequate level of protection for personal data, Google LLC applies the Standard Contractual Clauses (SCCs) to transfers of personal data to third countries and also implements additional technical and organisational measures to ensure an appropriate level of data protection.
For the purpose of data storage and the provision of web services, including backend server infrastructure, the Data Controller engages Amazon Web Services, Inc. as a data processor. The details of the data processor are as follows:
Name: Amazon Web Services, Inc.
Registered office: 410 Terry Avenue North, Seattle, WA 98109-5210, USA
Contact details: privacy@amazon.com, +1 206-266-4064 (US headquarters)
Please note that, in connection with the use of data processor services, your personal data may be transferred to data processors located in third countries outside the European Economic Area. Please be aware that in such countries public authorities may have broad rights of access to personal data, which may entail certain risks. In order to ensure an adequate level of protection for personal data, Amazon Web Services, Inc. applies the Standard Contractual Clauses (SCCs) to transfers of personal data to third countries and also implements additional technical and organisational measures to ensure an appropriate level of data protection.
In the case of online payment, personal data are transferred, on the basis of the data subject’s consent expressed by selecting the relevant payment method, to the Worldline Saferpay payment service provider, which acts as an independent data controller. Its details are as follows:
Name: Worldline SA/NV
Registered office: River Ouest, 80 Quai Voltaire, 95870 Bezons, France
Contact details: dataprotection@worldline.com, +41 58 399 5757 (Swiss headquarters)
For the purpose of issuing and retaining electronic invoices, the Data Controller engages Számlázz.hu as a data processor. The details of the data processor are as follows:
Name: KBOSS.hu Kft.
Registered office: 7 Záhony utca, 1031 Budapest, Hungary
Contact details: info@szamlazz.hu, +36 1 499 99 99
For the purpose of sending newsletters, the Data Controller engages MailerLite as a data processor. The details of the data processor are as follows:
Name: MailerLite Limited
Registered office: 88 Harcourt Street, Dublin 2, D02 DK18, Ireland
Contact details: https://www.mailerlite.com/contact-us
For the purpose of storing video interviews and providing access to them in connection with job applications, the Data Controller engages Vimeo as a data processor. The details of the data processor are as follows:
Name: Vimeo.com, Inc.
Registered office: 555 West 18th Street, New York, NY 10011, USA
Contact details: legal@vimeo.com or privacy@vimeo.com, +1 212-314-7457 (US headquarters)
Please note that, in connection with the use of data processor services, your personal data may be transferred to data processors located in third countries outside the European Economic Area. Please be aware that in such countries public authorities may have broad rights of access to personal data, which may entail certain risks.
In order to ensure an adequate level of protection for personal data, Vimeo complies with the requirements of the EU-U.S. Data Privacy Framework (DPF) and also implements additional technical and organisational measures to ensure an appropriate level of data protection.
The Data Controller may provide the option for the data subject to register for or log in to the application using an account created with an external service provider, in particular Facebook, Google or Apple.
The external service provider acts as an independent data controller when providing its own services and managing the data subject’s user account. The processing carried out by the external service provider is governed by that service provider’s own privacy notice.
The Data Controller receives from the external service provider only the data necessary for registration, identification of the user and enabling login.
Certain functions of the application operate automatically. In particular, depending on the subscription plan selected by the advertiser, the system may automatically determine how many applicants’ personal data the advertiser is entitled to access.
In the case of a subscription plan that allows access only to the data of the first applicant, the system automatically makes the personal data of the first applicant available based on the chronological order in which applications are received. The data of subsequent applicants are not accessible under that subscription plan; the advertiser may access such data by subscribing to a plan that provides this entitlement. The advertiser can always see the total number of applicants. If the first applicant withdraws their application, the next applicant in the order becomes visible.
When determining the order of applicants, the Data Controller does not assess the applicants’ professional suitability, personal characteristics or any other attributes, and the determination of the order is not based on profiling.
The Data Controller may also carry out profiling for the purpose of personalised marketing as described in Section 3.3. Such profiling does not result in an automated decision that produces legal effects concerning the data subject or similarly significantly affects the data subject.
The Data Controller ensures an appropriate level of security for the data subject’s personal data by implementing appropriate technical and organisational measures, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.
To the extent permitted by its organisational and technical capabilities, the Data Controller takes all reasonable measures to ensure that its data processors also implement appropriate data security measures when processing your personal data.
7.1. The data subject has the right to access the information specified in Article 15 of the General Data Protection Regulation in relation to the processing of his or her personal data (right of access), including in particular the right to be informed by the Data Controller about:
which personal data are processed;
the purposes and legal basis of the processing;
the source from which the personal data were collected;
the envisaged period for which the personal data will be stored, or the criteria used to determine that period;
to whom, when and which of the data subject’s personal data the Data Controller has disclosed or provided access, or to whom the personal data have been transferred; and
the rights, complaint procedures and legal remedies available to the data subject in relation to the processing.
7.2. Pursuant to Article 16 of the General Data Protection Regulation, the data subject has the right to request the correction or rectification of inaccurate, incorrect or incomplete personal data concerning him or her (right to rectification).
7.3. Pursuant to Article 17 of the General Data Protection Regulation, the data subject has the right to request the erasure of his or her personal data (right to erasure) where:
the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
where the processing is based on consent, the data subject withdraws his or her consent and there is no other legal ground for the processing;
the data subject has successfully objected to the processing pursuant to Section 7.7;
the personal data have been unlawfully processed; or
the personal data must be erased in order to comply with a legal obligation.
The personal data will not be erased where the processing is necessary:
for compliance with a legal obligation or for the performance of a task carried out in the public interest or in the exercise of official authority;
for the establishment, exercise or defence of legal claims;
for exercising the right of freedom of expression and information; or
for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, where the right to erasure is likely to render impossible or seriously impair the achievement of the objectives of such processing.
7.4. Pursuant to Article 18 of the General Data Protection Regulation, the data subject has the right to request restriction of the processing of his or her personal data (right to restriction of processing) where:
the data subject contests the accuracy of the personal data, in which case the processing shall be restricted for a period enabling the Data Controller to verify the accuracy of the personal data;
the data subject has objected to the processing pursuant to Section 7.7, in which case the processing shall be restricted for the period necessary to determine whether the legitimate grounds of the Data Controller override those of the data subject;
the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead; or
the Data Controller no longer needs the personal data for the purposes of the processing, but the data subject requires them for the establishment, exercise or defence of legal claims.
Where processing has been restricted, such personal data shall, with the exception of storage, be processed only with the data subject’s consent, for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the European Union or of a Member State.
7.5. Where processing is based on consent, the data subject has the right to withdraw his or her consent at any time, without giving reasons, pursuant to Article 7(3) of the General Data Protection Regulation (right to withdraw consent). Consent may be withdrawn in writing or in the same manner in which it was given. Withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
7.6. Where processing is based on consent or is necessary for the performance of a contract and is carried out by automated means, the data subject has the right, pursuant to Article 20 of the General Data Protection Regulation, to receive the personal data concerning him or her that he or she has provided in a commonly used electronic format, or to request that the Data Controller transmit those data to another data controller (right to data portability).
7.7. Where processing is based on a balancing of legitimate interests, the data subject has the right to object, on grounds relating to his or her particular situation, to the processing of his or her personal data (right to object). Pursuant to Article 21 of the General Data Protection Regulation, the Data Controller shall no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or where the processing is necessary for the establishment, exercise or defence of legal claims.
Where personal data are processed for direct marketing purposes, the data subject has the right to object at any time to the processing of his or her personal data for such purposes, including profiling to the extent that it is related to such direct marketing. Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.
7.8. The data subject may exercise his or her rights free of charge using the contact details specified in Section 1. In most cases, the exercise of data subject rights requires the identification of the data subject, while in certain cases, such as exercising the right to rectification, additional information or evidence may be required.
The Data Controller shall respond to a request concerning the exercise of data subject rights no later than one month after receipt of the request. Where necessary, taking into account the complexity and number of requests, this period may be extended by a further two months. The data subject shall be informed of any such extension within one month of receipt of the request.
The Data Controller reserves the right to amend this Privacy Notice in order to ensure compliance with the legislation in force from time to time, the data processing activities carried out by the Data Controller, and the operation of the application.
The Data Controller will make the amended Privacy Notice available in the application and on its website. Where an amendment materially affects the rights of data subjects or the circumstances of the processing, the Data Controller will also inform the data subjects separately of the amendment in an appropriate manner.
Where a new processing activity requires the data subject’s consent, the Data Controller will request such consent separately.
Any complaint relating to the processing of personal data may be submitted using the contact details specified in Section 1. If you wish to submit a complaint by post, you may send it to the address specified in Section 1.
If you believe that your rights have been infringed in connection with the processing of your personal data, or that there is an imminent risk of such infringement, you may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) (mailing address: 1363 Budapest, Pf. 9; telephone: +36 (1) 391-1400; e-mail: ugyfelszolgalat@naih.hu; website: https://naih.hu).
In the event of an infringement of your data protection rights, you may also bring court proceedings. At your choice, proceedings may also be initiated before the competent regional court of your place of residence or place of stay.
.