B
Burján Ingatlan

Privacy Notice

I. General information, the Controller

Controller:

Name: Extraverz Szolgáltató Kft.
Registered seat: 5000 Szolnok, Czakó E. u. 3. VII/56., Hungary
Tax number: 11277455-1-16
Phone: +36 20 397 1163
E-mail: info@burjaningatlan.hu
Data protection contact: Szilárd Burján, Managing Director.

The Controller is a company registered in Hungary. Under the GDPR, it is not required to appoint a data protection officer.

The website www.burjaningatlan.hu (hereinafter: the "Website") is operated by Extraverz Szolgáltató Kft.; accordingly, the Controller for the data processing carried out on the Website is Extraverz Szolgáltató Kft.

Data Subject

A data subject is a natural person whose personal data the Controller processes. This includes, in particular, anyone who contacts the Controller, wishes to sell or let a property, is looking for a property, or otherwise makes use of the Controller's services.

A data subject may also be a natural person whose personal data reaches the Controller from another person or from a publicly available source.

Applicable legislation

The Controller carries out its data processing in particular on the basis of the following legislation:

Under the GDPR, the Controller processes personal data lawfully, fairly and in a transparent manner, for specified purposes, and to the extent and for the period necessary for those purposes.

Scope of this Notice

This Notice covers the processing of personal data carried out by the Controller.

Personal data means any information relating to an identified or identifiable natural person.

This Notice therefore does not cover data that does not qualify as personal data, or the processing of data not carried out by the Controller.

II. Principles, purposes and legal bases of the processing

2.1. Principles of the processing

The Controller processes personal data:

2.2. Purposes of the processing

The Controller may process personal data in particular for the following purposes:

2.3. Legal bases of the processing

The Controller applies the appropriate legal basis for each processing activity depending on its purpose and circumstances.

Performance of a contract and pre-contractual steps
Under Article 6(1)(b) GDPR, the Controller may process personal data that is necessary for the performance of a contract with the data subject, or to take steps at the data subject's request prior to entering into a contract.

Compliance with a legal obligation
Under Article 6(1)(c) GDPR, the Controller processes data whose processing is required by law. This includes, in particular, processing under the AML Act and accounting legislation.

Legitimate interest
Under Article 6(1)(f) GDPR, the Controller may also process personal data to pursue its legitimate interests, provided the processing is necessary and the Controller's interests are not overridden by the interests, fundamental rights and freedoms of the data subject.

The Controller's legitimate interests include, in particular:

Where the processing is based on a legitimate interest, the Controller applies the requirements of a balancing-of-interests test.

Consent
Under Article 6(1)(a) GDPR, the Controller processes personal data on the basis of consent in cases where consent is the appropriate legal basis.

Consent is freely given, specific, informed and unambiguous. The data subject may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.

Reading or acknowledging this Notice does not, in itself, constitute consent to any processing for which separate consent is required under the GDPR.

2.4. Voluntary nature of providing data

Providing data is generally voluntary. Providing the data necessary to conclude and perform the agency agreement, and — where the AML Act applies — for customer due diligence, is a condition for using the service. If the data subject does not provide this data, the Controller cannot accept the mandate, or cannot carry out a transaction falling under the AML Act.

For a simple inquiry made via the Website, by phone or by e-mail, a name and a contact detail are generally sufficient. Without these, the Controller cannot respond to the inquiry.

III. The processing procedure and the categories of data processed

3.1. Description of the processing procedure

The Controller's services can be used via the Website, by phone, by e-mail, and through personal contact.

Where a data subject instructs the Controller to sell or let a property, the data subject enters into a contract with Extraverz Szolgáltató Kft.

For the performance of the service, the property agent may record the necessary data of the property and the client, and prepare the property listing.

The finished listing may be published on the Website, on real estate portals, and on other public platforms through which the Controller facilitates the sale or letting of the property.

As a general rule, the personal data of the property owner is not published in listings. Listings may show the contact details of the property agent. In photographs of properties, the Controller strives to ensure that no identifiable natural person, licence plate or document appears.

For a client looking for a property, the Controller may record the data necessary to fulfil the search request.

When the agency relationship ends, the listing is removed from the sale/letting platforms, and the Controller either deletes the data or retains it for the purpose, in the manner and for the period set out in this Notice.

The Controller does not record phone calls.

3.2. Source of the data

The Controller obtains personal data primarily directly from the data subject, for example:

In certain cases, the Controller may also obtain personal data from another person or from a publicly available source, provided there is an appropriate legal basis for processing it. Such a source may be, for example, a publicly available land registry or other database, or data provided by another client for the purposes of the agency service.

Providing data voluntarily does not automatically amount to consent to the processing. The legal basis of the processing must in every case be determined based on the specific purpose of the processing and the provisions of the GDPR.

Where the data does not originate from the data subject, the Controller provides information under Article 14 GDPR, unless such information is not required under the Regulation.

3.3. Categories of personal data processed

Depending on the purpose of the processing, the Controller may process the following data.

Contact and identification data for inquiries and general contact:

Further identification data required to conclude a contract and perform the mandate:

Property-related data:

Property-search-related data:

AML Act data – only where the AML Act applies to the given transaction:

Billing data:

In the event of a legal dispute:

3.4. Place of the processing

Paper-based documents are kept at a place designated and appropriately secured by the Controller.

Personal data may also be stored in the Controller's IT systems. For electronic processing, the Controller applies appropriate technical and organisational measures to protect the data.

IV. Individual processing activities

4.1. Contact via the Website, by phone or by e-mail

Purpose: responding to inquiries, providing information, calling back, and selecting the appropriate service.
Legal basis: pre-contractual steps taken at the data subject's request [Article 6(1)(b) GDPR]; where no intention to contract can yet be established, the Controller's legitimate interest in maintaining contact [Article 6(1)(f) GDPR].
Data processed: name, phone number, e-mail address, content of the inquiry, data on the relevant property or search request.
Retention: if the inquiry does not result in a mandate, the Controller retains the data for 1 year from the last contact and then deletes it, unless a longer retention period is justified by law or by the need to assert a legal claim.

4.2. Processing related to the sale or letting of a property

Purpose: sale or letting of the property and the related contact, advertising and agency activity.
Legal basis: pre-contractual steps and performance of the contract [Article 6(1)(b) GDPR]; depending on the specific processing, a legal obligation [Article 6(1)(c) GDPR] or a legitimate interest [Article 6(1)(f) GDPR], in particular to match supply and demand and to publish the listing.
Retention: 5 years from the termination of the agency relationship. Where a longer retention period is prescribed for the same data by the AML Act or accounting rules, the Controller applies the longer period.

4.3. Processing related to a property search

Purpose: recording the data subject's property requirements, recommending properties, contacting the data subject and facilitating the property transaction.
Legal basis: pre-contractual steps or performance of the contract [Article 6(1)(b) GDPR]; in the absence of these, the legitimate interest in carrying out the agency activity [Article 6(1)(f) GDPR]. Separate consent only where it is the appropriate legal basis for the processing [Article 6(1)(a) GDPR].
Retention:

4.4. Assertion of legal claims

Purpose: asserting, exercising and defending contractual or other legal claims and the Controller's rights.
Legal basis: the Controller's legitimate interest [Article 6(1)(f) GDPR]; where the processing is necessary to comply with a legal obligation, Article 6(1)(c) GDPR.
Retention: until the claim can no longer be enforced, typically until the end of the limitation period under the Hungarian Civil Code, and until the final conclusion of any related legal remedy proceedings.

4.5. Processing related to the prevention of money laundering and terrorist financing

Purpose: fulfilling customer due diligence, record-keeping and other obligations under the AML Act.
Legal basis: compliance with a legal obligation [Article 6(1)(c) GDPR], under the AML Act.
This processing does not apply to every inquiry, only where the AML Act applies to the given transaction or business relationship.
Retention: 8 years from the termination of the business relationship or the performance of the transaction. Where the data is affected by an official, prosecutorial or judicial request, the longer retention period of up to 10 years under the AML Act applies.

4.6. Processing related to billing and bookkeeping

Purpose: fulfilling billing, bookkeeping and tax obligations.
Legal basis: compliance with a legal obligation [Article 6(1)(c) GDPR].
Retention: accounting records must be kept for at least 8 years under the Accounting Act.

4.7. Direct marketing

Purpose: sending offers, newsletters or advertising relating to the Controller's services.
Legal basis: the data subject's prior consent [Article 6(1)(a) GDPR], or, where the conditions of the advertising legislation are met, the relevant statutory authorisation.
Retention: until consent is withdrawn or the sending of advertising ceases. Consent may be withdrawn at any time via the contact e-mail address. Withdrawal does not affect the lawfulness of earlier processing.

V. Other information relating to the processing

5.1. Data transfers, categories of recipients

The Controller transfers personal data to a third party only on an appropriate legal basis.

Recipients, or categories of recipients, of personal data include in particular:

5.2. Processors

The Controller may engage processors, in particular for hosting, IT and bookkeeping tasks.

A processor acts on the Controller's instructions and may not independently determine the purposes and means of the processing, unless expressly authorised to do so by law.

The Controller enters into contractual arrangements with its processors that comply with the requirements of the GDPR.

5.3. Transfers to third countries

The Controller does not transfer personal data to a third country outside the European Union or the European Economic Area, and does not transfer it to any international organisation.

Should this practice change in future, the Controller will provide the information required under the GDPR before any such transfer and will ensure appropriate safeguards.

5.4. Automated decision-making

The Controller does not apply automated decision-making within the meaning of Article 22 GDPR, and does not carry out any profiling resulting in such a decision.

5.5. Data security

The Controller applies appropriate technical and organisational measures to protect personal data, in particular against:

Such measures may include, in particular, access control, IT security, backups, anti-virus protection and physical security.

5.6. Technical data and cookies

The Website does not use cookies and does not apply similar tracking technology.

There are no cookies on our website – partly because we dislike them, partly because they add clutter, and partly because no one reads them anyway.

While the Website is operating, the hosting provider's system may briefly record the technical log data necessary to provide the service (e.g. the time of connection, the address of the page requested). The Controller does not use this data for profiling, statistical analysis or marketing. The hosting provider may store the log data for as long as necessary to ensure operation and security.

5.7. End of the processing – deletion of data

The Controller deletes or anonymises personal data once the purpose of the processing has ceased and there is no legal or legitimate interest, or statutory obligation, that requires the further retention of the data.

Where the processing is based on consent, the data subject may withdraw that consent. Withdrawal does not affect the lawfulness of the earlier processing.

The data subject's right to erasure does not necessarily result in the immediate deletion of the data if, for example, the Controller is required by law to retain the data, or the data is needed to assert, exercise or defend legal claims.

5.8. Personal data breach

In the event of a personal data breach, the Controller acts in accordance with the GDPR and applicable law.

Where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, the Controller notifies the competent supervisory authority without undue delay, and where feasible within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk.

Where a personal data breach is likely to result in a high risk to the rights and freedoms of the data subject, the Controller informs the data subject without undue delay, in accordance with the conditions set out in the GDPR.

The Controller documents personal data breaches.

VI. Rights of the data subject

Under the conditions set out in the GDPR, the data subject has, in particular, the following rights.

Right to information and access
The data subject has the right to request information as to whether their personal data is being processed and, if so, to request access to the personal data processed and to information relating to the processing.

Right to rectification
The data subject has the right to request the rectification of inaccurate personal data, or the completion of incomplete data.

Right to erasure
The data subject has the right to request the erasure of their personal data where the conditions set out in the GDPR are met. The right to erasure does not apply where the processing must continue to comply with a legal obligation, to assert a legal claim, or for another reason set out in the GDPR.

Right to restriction of processing
The data subject has the right to request the restriction of processing in the cases set out in the GDPR.

Right to object
Where the processing is based on the Controller's legitimate interest, the data subject has the right to object to the processing under the conditions set out in Article 21 GDPR. The data subject may object at any time to processing carried out for direct marketing purposes.

Right to data portability
Where the GDPR conditions are met, the data subject has the right to receive the personal data concerning them that they have provided to the Controller in a structured, commonly used and machine-readable format, and to request that this data be transmitted to another controller.

Right to withdraw consent
Where the processing is based on consent, the data subject may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

VII. Exercising the data subject's rights

The data subject may submit a request to exercise the above rights to the Controller at the following contact details:

E-mail: info@burjaningatlan.hu
Phone: +36 20 397 1163
Postal address: 5000 Szolnok, Czakó E. u. 3. VII/56., Hungary

The Controller responds to the data subject's request within the time limit set out in the GDPR.

As a general rule, the Controller informs the data subject of the action taken on the request within one month of receiving it.

For a particularly complex request or a large number of requests, this time limit may be extended by a further two months under the conditions set out in the GDPR. The Controller informs the data subject of any such extension and the reasons for the delay.

The Controller may request further information where necessary to confirm the data subject's identity. As a general rule, fulfilling the request is free of charge. In the case of a manifestly unfounded or excessive repeated request, a fee may be charged under the GDPR, or the Controller may refuse to act on the request.

VIII. Legal remedies

The data subject has the right to lodge a complaint with the competent supervisory authority if they consider that the processing of their personal data infringes the GDPR.

The competent supervisory authority in Hungary is:

National Authority for Data Protection and Freedom of Information (NAIH)
Seat: 1055 Budapest, Falk Miksa utca 9–11., Hungary
Postal address: 1363 Budapest, Pf. 9., Hungary
Phone: +36 (1) 391-1400
E-mail: ugyfelszolgalat@naih.hu
Website: www.naih.hu

Regardless of the right to lodge a complaint, the data subject may also bring proceedings before a court. Such proceedings may be brought before the competent regional court (törvényszék) of the data subject's place of residence or habitual stay.

IX. Amendment of this Notice

The Controller reserves the right to amend this Privacy Notice, in particular in the event of a change in the applicable law, in the processing activities, or in the operation of the Website.

The version of the Privacy Notice in force at any given time is available on the Website.

Effective date: 20 August 2026.

← Back to home