In order to comply with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), Act CXII of 2011 on Informational Self-Determination and Freedom of Information (the "Info Act"), and related legal provisions, the Service Providers hereby inform all Data Subjects with whom they come into contact about the processing of their personal data during visits to the website, as follows.
1. Provider information
Data Protection Officer
This Privacy Notice covers data protection information related to services provided on the website https://szinhome.hu (hereafter "Website") by the Provider.
2. Activities on the website
As a member entity of the SZINORG corporate group, the Service Provider is engaged in the sale of real estate assets owned by the group. Prospective clients may obtain information about the properties offered for sale via the Website, as the Service Provider publishes all relevant data regarding the properties on the Website. In addition to accessing information, users may also contact the Service Provider through the Website. For the purpose of facilitating efficient communication, interested parties may also provide their contact details by completing the contact form available on the Website.
Accordingly, the purpose of the operation of the Website is to facilitate the efficient and effective sale of properties, as well as the conclusion of sale and purchase agreements and other related contracts.
2.1. Use of the website
Access to the Website is not subject to registration; the properties offered for sale may be freely viewed by any user. Detailed information about each property — including, in particular, 3D furnished floor plans, visual designs, size, room list with dimensions, orientation, technical specifications, gross price, payment schedule, and availability status (available/sold) — is accessible by selecting the given property.
If a property available for sale attracts the interest of a visitor, the visitor may contact the Service Provider by selecting the relevant tab and providing their name and contact details.
2.2. Data processing activities
Szin-Real, as Provider, collects the information listed below via the contact form in order to facilitate communication with prospective clients. This Privacy Notice explains the legal basis, purpose, duration, and transfer of the collected data.
2.2.1. Submission of the contact form
During the visit to the Website, the User may contact the Service Provider directly by completing the form available under the "Contact" menu. In the course of filling out this form, the following data are collected and processed:
| Personal data | Purpose | Legal basis | Duration | Transfers |
|---|---|---|---|---|
| Name Email address Phone number | Identification, communication, taking steps prior to entering into a contract | Article 6(1)(b) GDPR — processing is necessary for taking steps at the request of the data subject prior to entering into a contract (in particular, in connection with an enquiry regarding a property) | For contact enquiries: a maximum of 6 months from the closure of the enquiry. In the event of entering into a contract: for the period necessary for the performance of the contract and for compliance with applicable legal retention obligations. | For the hosting service provider |
The completion of the contact form is voluntary and does not entail any obligation to enter into a contract. By submitting the form, the data subject acknowledges and accepts that the Service Provider will process the personal data provided in accordance with this Privacy Notice, and may contact the data subject for the purpose of facilitating a potential contractual relationship in connection with the properties listed on the Website.
2.3. Website traffic data management
Certain details — such as user IP addresses and system information — are logged for generating site traffic statistics and ensuring proper Website functioning. IP addresses are not linked to other identifying data. For more information, see Section 11 (Cookies).
3. Visiting the website
3.1. Liability
The Data Subject, as a user of the Website, uses the Website entirely at their own risk and acknowledges that the Service Provider shall not be held liable for any material or non-material damages arising from such use, except in cases of intentional misconduct or breaches of contract resulting in harm to life, physical integrity, or health. Except for liability for any third parties engaged by the Service Provider, the Service Provider excludes all liability for the conduct of Website users, and the Data Subject shall bear full and exclusive responsibility for their own conduct. The Data Subject is obliged to ensure that their use of the Website does not, either directly or indirectly, infringe the rights of third parties or violate any applicable laws.
3.2. Copyrights
The Website is a copyrighted compilation ("collective work") under Hungarian law (Act LXXVI/1999 § 7). Protection extends to the compilation even if some elements are not individually protected. Copyrights to the Website's design, graphics, text, and technical solutions are held by the Provider. Unauthorized reproduction — online, in print, in public, or in other forms — may trigger a contractual penalty of HUF 200,000 plus VAT per page or image. Automated data extraction, archiving, reverse-engineering source code, or similar actions are strictly prohibited.
4. Data transfers
Collected data are forwarded only to third parties providing hosting services. The data are stored with:
5. Rights of data subjects
5.1. Right to erasure (deletion)
Data subjects may request immediate deletion of their personal data if:
- the data are no longer needed for the original purpose;
- consent has been withdrawn and no other legal basis applies;
- they object to processing with no overriding lawful grounds;
- data were processed unlawfully;
- the data must be erased to comply with EU or national law;
- the data were collected in connection with information society services.
Data required by law for storage may not be deleted.
5.2. Right to information and access
Data subjects may request information about processing — what data is processed, how, if locked or deleted, and any measures taken. They may request access to their data at any time. The Provider will respond in writing in a clear manner within a maximum of 25 days of receiving the request, indicating purposes, legal basis, duration, and recipients of the data (if any transfers occurred).
5.3. Right to feedback
Data subjects are entitled to feedback on whether their personal data is being processed and, if so, to access:
- processing purposes;
- categories of personal data;
- categories of recipients (including international transfers);
- planned storage duration or criteria for determining it;
- right to request correction, deletion, restriction, or objection;
- right to lodge a complaint with a supervisory authority;
- data source if not collected directly from the data subject.
5.4. Right to rectification
Data subjects may request corrections of their data via ertekesites@szinhome.hu or by mail to the Provider's registered office, specifying which data category and new data apply. Changes are implemented promptly upon receipt.
5.5. Right to restrict data processing
Data subjects may request restriction of processing if:
- they dispute data accuracy — restriction applies until accuracy is verified;
- processing is unlawful but they oppose deletion, requesting restriction instead;
- data is no longer needed by Provider but required by the subject for legal claims;
- they object to processing and Provider's lawful reasons have not yet prevailed.
5.6. Right to object
The Data Subject shall have the right to object, at any time, on grounds relating to their particular situation, to the processing of their personal data where the processing is necessary for the purposes of the legitimate interests pursued by the Service Provider or by a third party, unless such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject. The Service Provider informs visitors to the Website that no profiling or automated decision-making is carried out in relation to the personal data processed.
5.7. Right to withdraw consent
Users may withdraw consent to data storage at any time. Upon withdrawal, the Provider deletes the data immediately. Withdrawal is possible by email or postal mail.
5.8. Right to data portability
Data subjects may request their personal data in a machine-readable format and have it transferred directly to another controller — if data processing is based on consent or contract and processing is automated. This right does not apply if processing is in the public interest or conducted in the exercise of official authority, nor if it adversely affects others' rights and freedoms.
5.9. Right to lodge a complaint
Data subjects may file complaints with the Provider or directly with the supervisory authority. If submitted to the Provider, it will be reviewed and responded to within 15 days. Consumer complaints can be submitted by mail to: 4025 Debrecen, Simonffy utca 17–19, Hungary, or by email to ertekesites@szinhome.hu.
If the Provider deems a complaint unfounded, the subject may contact the National Authority for Data Protection and Freedom of Information (NAIH; 1125 Budapest, Szilágyi Erzsébet fasor 22/c., +36 1 391 1400, ugyfelszolgalat@naih.hu) or seek judicial remedy.
6. Handling of data security incidents
In the event of a data breach concerning any data it processes, the Service Provider shall report the incident to the competent supervisory authority without undue delay and, where feasible, no later than 72 hours after having become aware of it, unless it can demonstrate, in accordance with the accountability principle, that the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.
If the data breach is likely to result in a high risk to the rights and freedoms of the Data Subject, the Service Provider shall inform the Data Subject without undue delay so they can take the necessary precautions.
7. Principles considered in data processing
- Lawfulness, fairness and transparency: Personal data shall be processed lawfully, fairly, and in a manner that is transparent to the Data Subject.
- Purpose limitation: Personal data shall be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
- Accuracy: Personal data shall be accurate and, where necessary, kept up to date.
- Storage limitation: Personal data shall be kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the personal data are processed.
- Integrity and confidentiality: Personal data shall be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
- Accountability: The Service Provider shall be responsible for compliance with the above principles and must be able to demonstrate such compliance.
8. Security of personal data processing
The Service Provider shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the cost of implementation, the nature, scope, context, and purposes of processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons.
The Service Provider has not joined any approved code of conduct or certification mechanism under the GDPR.
9. Data storage
The physical location of data storage is: 4025 Debrecen, Simonffy utca 17–19, Hungary. The Service Provider stores the personal data obtained during contact via its electronic communication channel (ertekesites@szinhome.hu) as well as on its own server and in the database of its Website. The Service Provider maintains records of the data provided through the contact form on its own server for the purpose of fulfilling its data transfer and data storage obligations.
10. Restrictions
In the case of a Data Subject who is under the age of 16, or who is otherwise incapable or has limited legal capacity, and where the legal basis for the data processing is the consent referred to in Article 6(a) of the GDPR, such processing shall be lawful only if and to the extent that consent is given or authorized by the holder of parental responsibility over the child.
11. Cookies on the website
The Service Provider uses cookies on the Website.
What are cookies?
A cookie is a small data file that is stored on the user's terminal device (e.g. computer, mobile phone), which enables the proper functioning of the Website, the storage of user preferences, and the analysis of Website usage. Cookies typically contain a unique identifier and, in certain cases — particularly when combined with other data — may qualify as personal data within the meaning of Article 4(1) of the GDPR.
Purpose of data processing
- ensuring the proper functioning of the Website,
- improving user experience,
- collecting statistical information on Website usage,
- displaying personalised content and advertisements.
Legal basis for processing
- Necessary cookies: Article 6(1)(f) GDPR — legitimate interest (ensuring the secure and proper operation of the Website).
- Statistical and marketing cookies: Article 6(1)(a) GDPR — the data subject's consent.
Consent may be given via the cookie management interface displayed on the Website and may be withdrawn at any time.
Categories of personal data processed
- IP address (including truncated/anonymised form),
- browser type,
- operating system data,
- date and duration of the visit,
- pages viewed and clicks,
- unique cookie identifier.
Types of cookies and their characteristics
Strictly necessary cookies
Essential for the proper functioning of the Website and cannot be disabled in our systems. Legal basis: legitimate interest. Retention period: session duration.
Statistical cookies (Google Analytics)
The Website uses Google Analytics to analyse user behaviour.
- Provider: Google Ireland Limited
- Purpose: statistical analysis
- Legal basis: consent
During data processing, personal data may be transferred to a third country (United States).
Marketing cookies (Google Ads)
Google Ads cookies enable the creation of remarketing lists, personalised advertising, and measurement of conversions. Legal basis: consent.
Marketing cookies (Meta / Facebook Pixel)
The Website may also use the Facebook Pixel service provided by Meta Platforms Ireland Ltd. The purpose of these cookies is tracking user behaviour, remarketing activities (Facebook, Instagram), and measuring advertising effectiveness. Typical cookies include: _fbp, _fbc. During data processing, personal data may be transferred to a third country (United States). Legal basis: consent.
Cookie consent cookie
This cookie records the user's cookie preferences. Retention period: 365 days.
Data transfers and data processors
The following data processors may be involved in the processing of personal data through cookies: Google Ireland Limited, Meta Platforms Ireland Ltd. In the course of data processing, personal data may be transferred to third countries. Such transfers are carried out subject to appropriate safeguards, in particular the use of standard contractual clauses (SCCs).
Managing and deleting cookies
Users may manage cookies via the cookie management interface available on the Website, and through their browser settings. Most browsers allow users to automatically refuse or delete cookies.
12. Record of data processing activities
The Service Provider maintains a record of processing activities in accordance with applicable data protection legislation. This record includes:
- the name and contact details of the Data Controller;
- the purposes of the processing;
- a description of the categories of Data Subjects and the categories of personal data;
- the categories of recipients to whom the personal data have been or will be disclosed;
- where possible, the envisaged time limits for the erasure of the different categories of data.
This Privacy Notice takes effect on 1 April 2026.