Data Protection Notice

    Version v2.0 · In force from 26 August 2026

    1. Purpose, scope and structure of this notice

    ABIC Enterprise Korlátolt Felelősségű Társaság (registered seat: 2724 Újlengyel, Nyári Pál utca 15., Hungary; company registration number: 13-09-240332; tax number: 32807727-2-13; represented independently by Csaba Binó and Balázs Jakobicz, managing directors; electronic contact: info@abicenterprise.com; hereinafter: Company or Controller) treats all personal data confidentially and takes the technical and organisational measures necessary to protect personal data.

    This notice describes for what purpose, on what legal basis, what data, for how long and with whose involvement the Company processes personal data, and what rights data subjects may exercise.

    This notice covers the following activities of the Company:

    #
    5.1
    Processing activity
    Website contact and requests for quotation
    Data subjects
    prospects, client representatives
    #
    5.2
    Processing activity
    Contact data of clients, suppliers and partners
    Data subjects
    employees of contractual partners
    #
    5.3
    Processing activity
    Business development (B2B) outreach and CRM records
    Data subjects
    contacts at target companies
    #
    5.4
    Processing activity
    Newsletters and professional updates
    Data subjects
    subscribers
    #
    5.5
    Processing activity
    Operation of the website, cookies and log data
    Data subjects
    website visitors
    #
    5.6
    Processing activity
    Expert database and staffing process
    Data subjects
    applicants as experts
    #
    5.7
    Processing activity
    Data of employees and subcontractors after contracting
    Data subjects
    employees, subcontractors
    #
    5.8
    Processing activity
    Enforcement of legal claims, complaint and incident handling
    Data subjects
    all data subjects

    This notice does not cover the processing that the Company carries out as a processor, on the instructions of its client, within a client project. In such cases the client is the controller and the client's own notice applies.

    For the details of employment relationships and of contractor and mandate relationships, the Company uses a separate notice handed directly to the data subject at the time of contracting. That notice is to be read together with this one; in the event of a discrepancy, the activity-specific notice prevails.

    2. The controller and its contact details

    Name
    ABIC Enterprise Korlátolt Felelősségű Társaság
    Registered seat
    2724 Újlengyel, Nyári Pál utca 15., Hungary
    Company registration number
    13-09-240332
    Tax number
    32807727-2-13
    Representation
    Csaba Binó and Balázs Jakobicz, managing directors, independently
    General e-mail
    info@abicenterprise.com
    Data protection matters
    info@abicenterprise.com
    Telephone
    +36 70 883 3122
    Website
    https://www.abicenterprise.com
    Data protection contact person
    Dr. Dániel Jávor, data protection contact person

    Data protection officer. Under Article 37 GDPR the Company is not required to designate a data protection officer: it is not a public authority, its core activities do not consist of regular and systematic monitoring of data subjects on a large scale, and it does not process special categories of data on a large scale. In data protection matters the Company's data protection contact person acts, who can be reached at info@abicenterprise.com.

    3. Definitions

    Term
    GDPR
    Meaning
    Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
    Term
    Personal data
    Meaning
    any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier – such as a name, a number, location data or an online identifier – or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
    Term
    Special category data
    Meaning
    data referred to in Article 9 GDPR: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic and biometric data, health data, and data concerning a person's sex life or sexual orientation.
    Term
    Processing
    Meaning
    any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, storage, use, disclosure, transmission, restriction, erasure or destruction.
    Term
    Controller
    Meaning
    the body or person which determines the purposes and means of the processing of personal data.
    Term
    Processor
    Meaning
    the body or person which processes personal data on behalf of and on the instructions of the Controller.
    Term
    Recipient
    Meaning
    the body or person to which personal data are disclosed, whether or not a third party.
    Term
    Third country
    Meaning
    a country outside the European Economic Area (EEA).
    Term
    Profiling
    Meaning
    any form of automated processing of personal data consisting of the use of personal data to evaluate or predict certain personal aspects relating to a natural person – such as performance at work, economic situation, personal preferences or reliability.
    Term
    Pseudonymisation
    Meaning
    the processing of personal data in such a manner that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately.
    Term
    Consent of the data subject
    Meaning
    any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
    Term
    Personal data breach
    Meaning
    a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data processed.

    4. Data protection principles

    The Company processes personal data lawfully, fairly and in a transparent manner in relation to the data subject. It collects data only for specified, explicit and legitimate purposes, and only to the extent necessary to achieve the purpose. It keeps the data up to date, retains them only for as long as necessary for the purpose, and protects them with appropriate security measures.

    The Company maintains a record of all its processing activities in accordance with Article 30 GDPR and is able to demonstrate compliance with these principles (accountability).

    5. The individual processing activities

    5.1 Website contact and requests for quotation

    Item
    Data processed
    Content
    name, e-mail address, telephone number, the name of the organisation represented and the data subject's position, and the text of the message and any attachment.
    Item
    Purpose of the processing
    Content
    receiving and answering the enquiry, preparing a quotation for the service, and documenting the contact.
    Item
    Legal basis
    Content
    Article 6(1)(b) GDPR – where the enquiry concerns a service of the Company, the processing is necessary in order to take steps at the data subject's request prior to entering into a contract;
    Article 6(1)(f) GDPR – for other enquiries, the Company's legitimate interest in answering and documenting business communications addressed to it.
    Item
    Retention period
    Content
    a period of 12 months from the closure of the enquiry. If a contractual relationship is established, the data continue to be processed under section 5.2. Where legislation prescribes a longer period, that period applies.
    Item
    Consequences of not providing the data
    Content
    the e-mail address is required in order to answer the enquiry; without it the Company cannot reply.

    5.2 Contact data of clients, suppliers and partners

    Item
    Data processed
    Content
    the contact person's name, position, business e-mail address and telephone number, the details of the organisation represented, the correspondence arising during the contractual cooperation, and the documents relating to performance.
    Item
    Purpose of the processing
    Content
    preparation, conclusion and performance of the contract, keeping in contact, invoicing, and retention of accounting documents under accounting and tax legislation.
    Item
    Legal basis
    Content
    Article 6(1)(b) GDPR – where the contracting party is a natural person (for example a sole trader);
    Article 6(1)(f) GDPR – for the contact person of a contracting party that is a legal person, the legitimate interest of the Company and of the partner in the contact necessary to perform the contract;
    Article 6(1)(c) GDPR – for the data appearing on accounting documents, under Section 169 of Act C of 2000 on Accounting.
    Item
    Retention period
    Content
    5 years from the termination of the contractual relationship (the general limitation period under the Hungarian Civil Code); for accounting documents, 8 years from the creation of the document.

    5.3 Business development (B2B) outreach and CRM records

    The Company contacts the professional contact persons of organisations likely to be interested in its services for business purposes, and keeps a record of whom it contacted, when and through which channel. The name of a contact person is personal data even where we process it solely in a professional capacity.

    Item
    Data processed
    Content
    name, position, name of the employing organisation, business contact details, the address of the public professional profile, the date and channel of the outreach, whether a reply was given, and the data subject's country.
    Item
    Source of the data (Article 14 GDPR)
    Content
    publicly available professional and corporate sources – the organisation's website, the commercial register, professional social networks, conferences and industry publications – and data provided by the contact person in person.
    Item
    Purpose of the processing
    Content
    presenting the Company's services to potentially interested organisations, and recording who has opted out, so that no repeat contact takes place.
    Item
    Legal basis
    Content
    Article 6(1)(f) GDPR – the Company's legitimate interest in business contact and in acquiring business. The Company has carried out a legitimate interest assessment, which is available on request. The electronic communications ("ePrivacy") rules of the data subject's country also apply to the channel of contact; the Company takes these into account for each outreach.
    Item
    Retention period
    Content
    24 months from the outreach if the data subject does not respond. In the event of an opt-out ("I do not wish to receive further contact"), the Company keeps the data subject on a suppression list solely in order to prevent further contact, with the minimum data necessary for that purpose: name, e-mail address and the date of the opt-out.
    Item
    Right to object
    Content
    the data subject may object at any time, without giving reasons, to outreach based on legitimate interest, at info@abicenterprise.com or via the unsubscribe link included in the message. Upon objection the Company ceases the outreach without delay.

    5.4 Newsletters and professional updates

    Item
    Data processed
    Content
    name, e-mail address, the date of subscription, the identifier of the text version accepted at subscription, and delivery and opening data.
    Item
    Purpose of the processing
    Content
    sending the Company's professional content, newsletters and event invitations.
    Item
    Legal basis
    Content
    Article 6(1)(a) GDPR – the data subject's consent. Giving consent is voluntary, is not a condition of any service, and may be withdrawn at any time free of charge. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
    Item
    Retention period
    Content
    until consent is withdrawn. Thereafter the Company keeps a record of the unsubscription on a suppression list in order to prevent further sending.

    5.5 Operation of the website, cookies and log data

    The Company's public website is available at www.abicenterprise.com, including the careers page (/careers). This section relates to that public website.

    Technical log data. During the operation of the website the system records log data: IP address, browser and device type, the time of the visit, the page viewed and the address of the referring page. Legal basis: the Company's legitimate interest in the secure and proper operation of the website (Article 6(1)(f) GDPR). Retention period: no longer than 12 months.

    What a cookie is. A cookie is a small data file placed on the visitor's device which the website reads back during the visit. The Company treats technologies similar to cookies — such as the browser's local storage — in the same way as cookies.

    Category
    Strictly necessary
    What it does
    the basic operation of the website, maintaining the session, security, and remembering the cookie setting
    Legal basis and retention period
    legitimate interest – Article 6(1)(f); may be used without consent; no longer than 12 months
    Category
    Statistical (analytics)
    What it does
    aggregated measurement of the number and source of visits and of movement within the site, for the purpose of developing the website
    Legal basis and retention period
    consent – Article 6(1)(a); not loaded until consent is given; no longer than 12 months, or until consent is withdrawn
    Category
    Marketing and advertising tracking
    What it does
    the Company does not use such cookies and does not pass data collected on the website to third parties for advertising purposes
    Legal basis and retention period

    Consent to statistical cookies may be given via the cookie settings interface displayed on the website, may be refused there just as easily, and may be withdrawn at any time free of charge. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. The Company uses statistical data in aggregated form; it does not take decisions relating to individual visitors on that basis.

    The cookies and browser-side storage actually used are the following. A genuine HTTP cookie arises solely from statistical measurement; the remaining items stay in the local storage of the visitor's browser and are not uploaded to the Company's servers.

    Name
    _ga, _ga_Y65MER0QJN
    Type
    HTTP cookie (Google Analytics 4)
    Purpose
    audience measurement
    Lifetime
    2 years
    Name
    abic_consent
    Type
    localStorage
    Purpose
    storing the cookie decision
    Lifetime
    persistent, until deleted
    Name
    i18nextLng
    Type
    localStorage
    Purpose
    the selected language (HU/EN/DE)
    Lifetime
    persistent, until deleted
    Name
    theme
    Type
    localStorage
    Purpose
    light/dark display mode
    Lifetime
    persistent, until deleted
    Name
    abic_expert_application_draft
    Type
    localStorage
    Purpose
    draft of the application form
    Lifetime
    deleted upon submission
    Name
    scroll-pos:*
    Type
    sessionStorage
    Purpose
    remembering the scroll position
    Lifetime
    until the end of the browser session

    Statistical measurement runs within Google Consent Mode: the default state of analytics_storage is "denied", meaning that the measurement cookie is not placed until consent is given. The Company records the cookie decision in the abic_consent storage. The Company does not use marketing or advertising tracking cookies.

    Draft of the application form. The application form on the careers page saves a draft while it is being completed, so that a started application can be continued later. The draft remains solely on the visitor's own device, in the browser's local storage (abic_expert_application_draft), is not uploaded to the Company's servers and is deleted upon submission; it also disappears when the browser data are cleared. If no submission is made, the Company does not become aware of the content of the draft. Only the finally submitted application reaches the Company's server, and it enters the system managing the expert database only after the e-mail address has been confirmed (double opt-in).

    Browser settings. Visitors may at any time delete previously placed cookies in their browser settings and block the placing of new ones. If strictly necessary cookies are blocked, certain functions of the website will not work properly.

    5.6 Expert database and staffing process

    The Company delivers its SAP consulting and digital transformation services using its own staff and contracted subcontractors. For this purpose it maintains an expert database of professionals who apply to it with the intention of cooperating.

    An important distinction. The Company is not a recruitment agency and not a temporary work agency. It does not process an applicant's data in order to sell the applicant to another company, but in order to plan the expert capacity needed to perform its own service contracts. The Company does not sell or rent out its database, and transfers data to third parties only with the data subject's separate consent given for the specific project.

    The path of an application. An application submitted on the careers page does not enter the expert database automatically. The steps of the process are as follows:

    Step
    1. Submission and e-mail confirmation
    What happens
    After submission the Company sends a confirmation e-mail. The data become processable only after the e-mail address has been confirmed (double opt-in).
    Step
    2. Separate record
    What happens
    The confirmed application waits in a separate record; at this point it is not yet part of the expert database.
    Step
    3. Admission decision
    What happens
    A member of our staff opens each application individually and decides whether to admit or reject it.
    Step
    4. Pre-screened pool
    What happens
    If admitted, the applicant enters the pre-screened pool of the expert database.
    Step
    5. Qualified pool
    What happens
    Entry here only where valid consent, a signed Cooperation Declaration and a processed CV are all available. It is from this pool that the Company approaches professionals with a specific project opportunity.

    There is no automatic progression at any stage; every admission is decided by a member of our staff.

    If the Company rejects an application, it erases the applicant's data within 30 days of the rejection. Thereafter only the minimised evidentiary log under section 5.6.6 remains.

    5.6.1 Data processed

    Data group
    What the data subject provides
    What it contains
    name, e-mail address, telephone number, place of residence (country, city), CV and its content (qualifications, work experience, SAP module knowledge, project references, language skills, certifications), the professional data given in structured form on the application form (area of expertise, SAP modules, language skills with the level under the Common European Framework of Reference [CEFR], region), availability data (from when, at what capacity, willingness to work on site), the preferred form of engagement (employment, subcontractor relationship or both), fee expectation, and, in the case of a subcontractor application, the details of the business (company name, registered seat, tax number).
    Data group
    What the system records automatically
    What it contains
    the application identifier, the time of the application and of the consent, the identifier and language of the consent text version, the source of the application (form URL) and IP address, the time of the e-mail confirmation (double opt-in), the confirmation identifier and the IP address of the confirmation, and the version numbers of the documents accepted. These are needed so that the Company can demonstrate the lawfulness of the processing.
    Data group
    What the Company itself records during the process
    What it contains
    the status of the application (received, admitted, rejected, qualified), the time of the decision and the identifier of the member of staff taking it, internal professional notes and assessments made about the applicant, the fact and time of presenting the professional profile to a client or delivery partner, and events relating to the renewal of consent. These data fall within the scope of the right of access under Article 15 GDPR: at the data subject's request the Company provides information about them as well, to the extent that this does not adversely affect the rights of others.
    Data group
    Source of the data
    What it contains
    as regards the data provided by the applicant, exclusively the data subject. The Company does not collect data for the expert database from CV databases or by purchasing data. Where the Company itself approaches professionals from public professional sources, section 5.6.7 applies; the data of a professional approached in that way enter the expert database only through his or her own application.
    Data group
    What the Company expressly does not request and does not process
    What it contains
    health data, religious or political beliefs, trade union membership, ethnic origin, sexual orientation, criminal data, photograph, date of birth and marital status. The Company asks data subjects to leave these out of their CV as well. If such data nevertheless reach the Company, it erases them and does not take them into account during selection.
    Data group
    Consequences of not providing the data
    What it contains
    submitting an application requires the name, e-mail address, CV and availability data — without these the Company cannot assess which project requirement the profile might match, and the application therefore cannot be submitted. Providing the telephone number, place of residence and fee expectation is voluntary; their absence is not an obstacle to applying, but makes it harder to find a suitable project.

    5.6.2 Purposes, legal bases and retention periods

    Purpose
    Receiving the application, confirming the e-mail address, and deciding on admission or rejection
    Legal basis
    consent – Article 6(1)(a)
    Retention period
    until the decision is made; in the event of rejection, 30 days from the decision
    Purpose
    Internal status, note and assessment data arising during the application process
    Legal basis
    consent – Article 6(1)(a), and the Company's legitimate interest in documenting its decisions – Article 6(1)(f)
    Retention period
    for the same period as the related applicant data
    Purpose
    Storage in the expert database, approach with a project opportunity
    Legal basis
    consent – Article 6(1)(a)
    Retention period
    12 months, renewable
    Purpose
    Assessment of an application received for a specific advertised position
    Legal basis
    steps prior to entering into a contract – Article 6(1)(b)
    Retention period
    until the selection is closed
    Purpose
    Sending the professional profile to a client or delivery partner
    Legal basis
    separate consent – Article 6(1)(a)
    Retention period
    until the given selection process is closed
    Purpose
    Handling the Cooperation Declaration and demonstrating its performance
    Legal basis
    contract – Article 6(1)(b), enforcement of legal claims – Article 6(1)(f)
    Retention period
    the term of the declaration, then 5 years
    Purpose
    Sending a reminder to renew consent
    Legal basis
    consent – Article 6(1)(a); the reminder is an inseparable part of managing the consent
    Retention period
    until expiry
    Purpose
    Demonstrating the giving and withdrawal of consent
    Legal basis
    accountability – Article 5(2), and the legitimate interest in the establishment, exercise and defence of legal claims – Article 6(1)(f). Article 7(1) is a requirement of demonstrability, not a separate legal basis.
    Retention period
    5 years after erasure, in minimised form
    Purpose
    Newsletter, professional updates
    Legal basis
    separate consent – Article 6(1)(a)
    Retention period
    until withdrawal

    5.6.3 The four separate consents

    The application form contains four independent checkboxes. None is pre-ticked, and a separate log entry is created for each:

    Checkbox
    storage of the data in the expert database
    What it means
    this is a condition of registration, because without consent there is nothing to store;
    Checkbox
    acceptance of the Cooperation Declaration
    What it means
    this is a contractual declaration, not a data processing consent; the two have different legal fates;
    Checkbox
    sending the professional profile to a client
    What it means
    optional, and may also be given later, project by project;
    Checkbox
    newsletter and professional updates
    What it means
    optional.

    Items 3 and 4 are not a condition of registration: an application is complete even without ticking them, and the data subject is entered in the database in the same way. Any consent may be withdrawn at any time, free of charge and as easily as it was given.

    5.6.4 The 12-month time limit and renewal

    The Company retains the data for 12 months from the date consent is given. The reason for this period is the principle of accuracy: the most important elements of an SAP consultant profile – the current project, availability, the most recent module knowledge and the fee expectation – typically change within one project cycle, so with longer storage the accuracy of the data could not be ensured.

    The renewal procedure is as follows:

    When
    30 days before expiry
    What happens
    The Company contacts the data subject by e-mail and shows what data it stores about him or her.
    When
    7 days before expiry
    What happens
    The Company repeats the reminder.
    When
    If confirmed
    What happens
    Processing continues for a further 12 months, repeatable an unlimited number of times.
    When
    If no response
    What happens
    The Company erases the data automatically and permanently.

    If no response is received, the Company erases the data automatically and permanently. Silence is not consent. The Company regards only an express renewal statement as a renewal — not the opening of an e-mail, a click on a link, or a reply to a project offer.

    Self-service interface. In every outgoing e-mail the Company includes a personal link that requires no login, through which the data subject can view and update the data stored, renew or withdraw consent, and request erasure of the data. Erasure takes no more steps than registration did.

    5.6.5 Transfer of data to a client or delivery partner

    The Company sends the professional profile to its client or delivery partner only where the data subject has given prior and explicit consent for the given project. Before requesting confirmation, the Company specifies:

    to whom it sends the profile (a named client, not a general description),

    for which position,

    exactly what it sends (a full CV or an anonymised professional profile),

    how long the confirmation remains valid.

    In the first instance — where the client's selection process allows this — the Company sends an anonymised professional profile that does not contain the data subject's name or current employer.

    From the moment the profile is sent, the client becomes an independent controller and acts in accordance with its own data protection notice. In its contracts the Company stipulates that the client may use the profile solely for the given selection purpose and must erase the data of candidates not selected once the process is closed. If the data subject later requests erasure from the Company, the Company erases its own systems but can no longer erase the copy previously transferred lawfully to the client. The data subject needs to be aware of this before giving the confirmation.

    5.6.6 What the Company retains after erasure

    Under Article 7(1) GDPR the Company must be able to demonstrate that valid consent existed. It therefore retains, after erasure, only a minimised evidentiary log:

    Item retained
    A salted hash of the e-mail address
    Why
    not the e-mail address itself, but an irreversible hash of it
    Item retained
    The time of the consent
    Why
    to demonstrate that valid consent existed
    Item retained
    The time of the withdrawal or expiry
    Why
    to demonstrate when the processing ceased
    Item retained
    The identifier of the text version
    Why
    to demonstrate which version of the text the data subject accepted
    Item retained
    What the Company does not retain
    Why
    name, CV, telephone number and any other data suitable for identification
    Item retained
    Retention period of the log
    Why
    5 years

    5.6.7 Sourcing professionals from public professional sources

    Because of the limited number of professionals available in SAP niche areas, the Company also sources professionals itself from public professional sources and approaches them with an invitation to apply to the expert database. This is a separate processing activity, distinct from the processing described in sections 5.6.1–5.6.6, because at this stage the data do not originate from the data subject.

    Item
    Data processed
    Content
    name, the address of the public professional profile, current or former role and employer, area of expertise and module knowledge, region, and the date and channel of the outreach and whether a reply was given. At this stage the Company does not process CVs, fee expectations or private contact details.
    Item
    Source of the data (Article 14 GDPR)
    Content
    publicly available professional sources — professional social networks, conference and speaker lists, professional publications and corporate websites. The Company does not purchase data and does not collect from CV databases.
    Item
    Legal basis
    Content
    Article 6(1)(f) GDPR — the Company's legitimate interest in sourcing the expert capacity needed to perform its service contracts. The Company has carried out a legitimate interest assessment, which is available on request. The Company provides the information required under Article 14 GDPR at the latest upon first contact, within the outreach message itself.
    Item
    Retention period
    Content
    12 months from the outreach if the data subject does not reply. In the event of a negative reply the Company erases the data without delay and keeps the data subject — in order to prevent further contact — on a suppression list, with the name, contact detail and the date of the opt-out only.

    The Company does not transfer data processed in this way to a client or delivery partner. If the data subject applies, his or her data enter the consent-based processing under sections 5.6.1–5.6.6 and the record created during sourcing ceases to exist; the Company does not maintain the two records in parallel.

    5.7 Data of employees and subcontractors after contracting

    Where an employment contract, or a contractor or mandate agreement, is concluded, the processing relating to the expert database ceases and new processing begins: processing connected with the performance of the relationship, payroll, social security and tax returns, working time records, and participation in client projects.

    Item
    Legal basis
    Content
    performance of the contract (Article 6(1)(b)), compliance with the Company's legal obligations (Article 6(1)(c) — in particular Act I of 2012 on the Labour Code, social security and tax legislation, and the Accounting Act), and the establishment, exercise and defence of legal claims (Article 6(1)(f)).
    Item
    Retention period
    Content
    for the period prescribed by law, or in the absence of such a period, for 5 years from the termination of the relationship. For data prescribed by pension insurance legislation, the longer statutory period applies.

    The Company hands the detailed notice directly to the data subject at the time of contracting.

    5.8 Enforcement of legal claims, complaint and incident handling

    The Company records, investigates and answers the complaints, personal data breaches and data subject requests it receives.

    Item
    Legal basis
    Content
    compliance with a legal obligation (Article 6(1)(c) — Articles 12, 30, 33 and 34 GDPR), and the Company's legitimate interest in the establishment, exercise and defence of legal claims (Article 6(1)(f)).
    Item
    Retention period
    Content
    5 years for data subject requests, the answers given and the breach register; in the event of a legal dispute, until the end of the limitation period following the final decision.

    6. Processors and recipients

    6.1 Access within the Company

    Personal data are accessible to the Company's managing directors and to those members of staff who need access in order to perform their duties. Access is restricted by authorisation levels, tied to individual user accounts and, in the case of the expert database, logged: it can be traced who viewed a profile and when. Members of staff are bound by an obligation of confidentiality.

    6.2 Processors

    The Company uses IT and support services for its activities. These providers process personal data on behalf of the Company, solely on the Company's written instructions, on the basis of a contract under Article 28 GDPR, and may not use the data for their own purposes.

    Categories of processors used:

    Category
    Hosting and cloud provider
    Activity
    storage of data, operation of applications
    Place of storage
    EEA
    Category
    E-mail and office services provider
    Activity
    e-mail communication, document management
    Place of storage
    EEA
    Category
    Application management and CRM system
    Activity
    records of applications and outreach
    Place of storage
    EEA
    Category
    Newsletter and notification system
    Activity
    sending system messages, renewal reminders and newsletters
    Place of storage
    outside the EEA (USA) — on the basis of the DPF or SCCs (see section 7)
    Category
    Process automation platform
    Activity
    running the application and notification workflows
    Place of storage
    EEA
    Category
    Accounting service provider
    Activity
    bookkeeping, payroll
    Place of storage
    Hungary
    Category
    Document and CV processing service
    Activity
    machine reading of the submitted CV and conversion into structured data
    Place of storage
    outside the EEA (USA) — on the basis of the DPF or SCCs (see section 7)
    Category
    Artificial intelligence provider
    Activity
    supporting the matching of professional profiles with project requirements; the provider may not use the data for its own purposes or for model training
    Place of storage
    outside the EEA (USA) — on the basis of the DPF or SCCs (see section 7)
    Category
    Web analytics provider
    Activity
    producing website traffic statistics, solely on the basis of the visitor's consent
    Place of storage
    EEA

    The Company maintains a list of its current processors by name and makes it available free of charge to data subjects on request at info@abicenterprise.com.

    6.3 Other recipients

    Recipient
    Clients and delivery partners
    On what condition
    solely on the basis of the separate, project-specific consent under section 5.6.5, as independent controllers.
    Recipient
    Legal, accounting and tax advisers
    On what condition
    subject to an obligation of confidentiality, to the extent necessary.
    Recipient
    Authorities and courts
    On what condition
    on the basis of a statutory obligation, within the scope of their request.

    The Company does not sell or rent out personal data and does not pass them to third parties for marketing purposes.

    7. Transfers to third countries

    The Company stores and processes personal data primarily within the European Economic Area.

    Certain providers used — typically in the context of technical support — may also access data from outside the EEA. Any such transfer is always based on one of the safeguards under Chapter V GDPR:

    Safeguard
    Adequacy decision
    What it means
    an adequacy decision of the European Commission — for the United States, in the case of providers certified under the EU–US Data Privacy Framework
    Safeguard
    Standard contractual clauses (SCCs)
    What it means
    the standard contractual clauses adopted by the European Commission, where necessary with supplementary technical and organisational measures

    The Company stores the data held in the expert database and the CVs submitted within the European Economic Area, in data centres in Ireland and Germany. A defined set of data is, however, processed by providers established in the United States of America: the artificial intelligence provider performing the machine reading of CVs and supporting the matching of professional profiles, and the provider sending system messages and reminders. These transfers take place on the basis of one of the safeguards above — certification under the EU–US Data Privacy Framework, or standard contractual clauses. The artificial intelligence provider processes the data solely on the Company's instructions; it may not use them for its own purposes or for model training.

    At the data subject's request the Company provides information on which provider involves a transfer outside the EEA and on what safeguard it is based, and makes available a copy of the safeguard applied.

    8. Automated decision-making, profiling and artificial intelligence

    In the processing activities described in sections 5.1–5.5 and 5.7–5.8 of this notice the Company does not use automated decision-making or profiling.

    In the case of the expert database (section 5.6) the Company also supports the matching of professional profiles with open project opportunities using IT tools, including a solution based on artificial intelligence. This qualifies as profiling within the meaning of Article 4(4) GDPR, and the Company therefore provides the following information:

    What the system does. Applicants provide part of their professional data in structured form already on the application form. In addition, the system also reads the submitted CV by machine and records the professional data contained in it in structured form — that is, it does not merely store the uploaded file but also processes it. It then ranks, on the basis of the professional data in the profile — SAP module knowledge, years of experience, project references, language skills, availability, region — which profiles may match a given project requirement.

    What the system does not do. It does not take decisions. Who is approached, whose profile is presented to the client, and who drops out of the process is in every case decided by a member of our staff, exercising genuine judgement, and that decision is documented. The system does not by itself exclude anyone from the process.

    It follows from the above that the Company does not take decisions based solely on automated processing within the meaning of Article 22 GDPR. Nevertheless, the data subject may at any time ask for the criteria of the assessment to be explained and may object to an assessment concerning him or her at info@abicenterprise.com.

    Generative artificial intelligence in communication. Where the Company uses artificial intelligence (for example a chatbot) in its communication with prospects or applicants, it states this clearly at the start of the communication.

    EU regulation on artificial intelligence. The Company monitors the application of the European Union's Regulation on artificial intelligence (AI Act) and documents the classification of the system supporting candidate ranking as well as its own role in relation to that system. Should the obligations under that Regulation become applicable to the Company, the Company will separately inform data subjects that they fall within the scope of such a system.

    9. Data security measures

    Taking into account the state of the art, the costs of implementation and the nature, scope and risks of the processing, the Company applies appropriate technical and organisational measures. These include in particular:

    Measure
    Access management
    Content
    authorisation levels, individual user accounts, the need-to-know principle, multi-factor authentication in critical systems.
    Measure
    Encryption
    Content
    transmission of data over an encrypted channel (TLS), and encryption of stored data where the provider makes this available.
    Measure
    Logging
    Content
    logging of access to personal data and of processing operations, with profile-level access logging for the expert database.
    Measure
    Backup and recovery
    Content
    regular backups, verification of recoverability, and a rotational deletion rule for backups that extends erasure requests to the backups as well.
    Measure
    Automated erasure
    Content
    machine calculation of retention periods and scheduled execution of erasure, without human discretion.
    Measure
    Organisational measures
    Content
    confidentiality obligations for staff, data protection information and training for them, internal procedures.
    Measure
    Processor control
    Content
    conclusion of the contract under Article 28 and verification of the providers' security level.

    The Company designs and operates its systems so as to ensure authorised access, the integrity and authenticity of the data, and protection against unauthorised access, alteration, disclosure or destruction.

    10. Handling personal data breaches

    Case
    Every breach
    Action and deadline
    The Company enters it in a register, recording the fact of the breach, its effects and the measures taken to remedy it.
    Case
    Where the breach is likely to result in a risk to the rights and freedoms of data subjects
    Action and deadline
    Notification to the Hungarian National Authority for Data Protection and Freedom of Information within 72 hours of becoming aware of it.
    Case
    Where the breach is likely to result in a high risk
    Action and deadline
    The Company also informs the data subjects without delay, in clear and plain language.

    11. Summary of retention periods

    Processing
    Website enquiry
    Retention period
    12 months from closure
    Processing
    Data of contractual partners
    Retention period
    5 years from termination of the relationship
    Processing
    Accounting documents
    Retention period
    8 years
    Processing
    B2B business development outreach
    Retention period
    24 months; suppression list in the event of an opt-out
    Processing
    Newsletter
    Retention period
    until consent is withdrawn
    Processing
    Website log data and cookies
    Retention period
    no longer than 12 months, or in line with the cookie setting
    Processing
    Expert database
    Retention period
    12 months, renewable
    Processing
    Cooperation Declaration
    Retention period
    its term, then 5 years
    Processing
    Demonstrating consent (minimised log)
    Retention period
    5 years after erasure
    Processing
    Employment, subcontractor relationship
    Retention period
    as prescribed by law, in the absence of such a period 5 years
    Processing
    Data subject requests, breach register
    Retention period
    5 years
    Processing
    Application received but not yet assessed
    Retention period
    until the decision on admission or rejection
    Processing
    Rejected application
    Retention period
    30 days from the rejection
    Processing
    Draft of the application form
    Retention period
    until submission, in the visitor's browser; disappears when browser data are cleared
    Processing
    Recording the cookie consent
    Retention period
    no longer than 12 months, or until consent is withdrawn
    Processing
    Sourcing professionals from public sources (5.6.7)
    Retention period
    12 months from the outreach; immediate erasure in the event of a negative reply

    12. Rights of data subjects

    Data subjects may exercise the following rights using the contact details given in section 2.

    Right
    Right to information and access (Articles 13–15)
    What it means
    information on whether the Company processes data about the data subject and, if so, what data, for what purpose, for how long and to whom they are transferred; a copy of the data processed may be requested
    Right
    Right to rectification (Article 16)
    What it means
    correction of inaccurate data, completion of incomplete data
    Right
    Right to erasure (Article 17)
    What it means
    erasure of the data where the purpose has ceased, consent has been withdrawn, or the processing is unlawful
    Right
    Right to restriction of processing (Article 18)
    What it means
    "freezing" of the data until disputed accuracy or lawfulness is clarified
    Right
    Right to data portability (Article 20)
    What it means
    where processing is based on consent or contract and is carried out by automated means, the data are provided in a machine-readable format
    Right
    Right to object (Article 21)
    What it means
    objection to processing based on legitimate interest; in the case of direct marketing, without any condition
    Right
    Right to withdraw consent (Article 7(3))
    What it means
    at any time, free of charge and as easily as it was given; withdrawal does not affect the lawfulness of earlier processing
    Right
    Rights relating to automated decision-making (Article 22)
    What it means
    requesting human intervention, expressing a point of view, contesting the decision

    Procedure. The Company fulfils the request without undue delay and at the latest within one month. That period may be extended by a further two months, taking into account the complexity and the number of requests; the Company informs the data subject of any extension within the original period. Information and action are free of charge, unless the request is manifestly unfounded or — in particular because of its repetitive character — excessive.

    Identification. Where the Company has reasonable doubts concerning the identity of the person making the request, it may request further information for identification purposes. The Company uses data requested for identification solely for that purpose and erases them once the matter is closed.

    13. Remedies

    Complaint to the Company. Data subjects may at any time contact the Company directly using the contact details in section 2. The Company investigates and answers the complaint.

    Complaint to the supervisory authority.

    Name
    Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
    Address
    Falk Miksa utca 9-11., 1055 Budapest, Hungary
    Postal address
    Pf. 9., 1363 Budapest, Hungary
    Telephone
    +36 (1) 391-1400
    E-mail
    Website

    Judicial remedy. Data subjects may turn to the courts if their rights are infringed. The case falls within the competence of the regional court (törvényszék) and may, at the data subject's choice, also be brought before the regional court of his or her domicile or place of residence. The court deals with the case as a matter of priority.

    14. Amendment of this notice and version control

    The Company reserves the right to amend this notice. The version in force is available at all times at https://www.abicenterprise.com/adatkezelesi-tajekoztato.

    The Company informs data subjects of consent-based processing — that is, those in the expert database and newsletter subscribers — of any material amendment in advance by e-mail.

    Every version has its own version number and date of entry into force. The Company archives earlier versions so that it can be traced which version of the text the data subject knew when giving consent.

    Version
    v1.0
    In force
    [date]
    Change
    website contact (the former /privacy-policy document, which the present version replaces in its entirety)
    Version
    v2.0
    In force
    26 August 2026
    Change
    comprehensive notice: processors and place of storage, transfers to third countries, expert database and staffing process (the path of an application, double opt-in, admission decision), sourcing professionals from public sources, B2B outreach, cookies and cookie consent, artificial intelligence, remedies

    ABIC Enterprise — Complexity made simple.