Privacy Notice
I. General information, the Controller
Controller:
Name: Extraverz Szolgáltató Kft.
Registered seat: 5000 Szolnok, Czakó E. u. 3. VII/56., Hungary
Tax number: 11277455-1-16
Phone: +36 20 397 1163
E-mail: info@burjaningatlan.hu
Data protection contact: Szilárd Burján, Managing Director.
The Controller is a company registered in Hungary. Under the GDPR, it is not required to appoint a data protection officer.
The website www.burjaningatlan.hu (hereinafter: the "Website") is operated by Extraverz Szolgáltató Kft.; accordingly, the Controller for the data processing carried out on the Website is Extraverz Szolgáltató Kft.
Data Subject
A data subject is a natural person whose personal data the Controller processes. This includes, in particular, anyone who contacts the Controller, wishes to sell or let a property, is looking for a property, or otherwise makes use of the Controller's services.
A data subject may also be a natural person whose personal data reaches the Controller from another person or from a publicly available source.
Applicable legislation
The Controller carries out its data processing in particular on the basis of the following legislation:
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR);
- Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (Hungary);
- Act LIII of 2017 on the Prevention and Combating of Money Laundering and Terrorist Financing ("AML Act"), to the extent its provisions apply to the given processing;
- Act C of 2000 on Accounting;
- Act XLVIII of 2008 on the Basic Conditions of and Certain Limitations to Commercial Advertising Activity.
Under the GDPR, the Controller processes personal data lawfully, fairly and in a transparent manner, for specified purposes, and to the extent and for the period necessary for those purposes.
Scope of this Notice
This Notice covers the processing of personal data carried out by the Controller.
Personal data means any information relating to an identified or identifiable natural person.
This Notice therefore does not cover data that does not qualify as personal data, or the processing of data not carried out by the Controller.
II. Principles, purposes and legal bases of the processing
2.1. Principles of the processing
The Controller processes personal data:
- lawfully, fairly and in a manner transparent to the data subject;
- only for specified, explicit and legitimate purposes;
- limited to what is necessary for the purposes of the processing;
- while striving to keep the data accurate and up to date;
- for no longer than necessary;
- protected by appropriate technical and organisational measures.
2.2. Purposes of the processing
The Controller may process personal data in particular for the following purposes:
- identifying the client;
- making and maintaining contact;
- responding to inquiries received via the Website or otherwise;
- facilitating the sale or letting of a property;
- recording the details of a property offered for sale or letting;
- preparing and publishing property listings;
- finding prospective buyers or tenants;
- recording and handling the requirements of clients looking for a property;
- bringing together clients looking for and offering a property;
- coordination in connection with the property transaction;
- creating and performing the agency (mandate) agreement between the data subject and the Controller;
- facilitating related services, such as an energy performance certificate or a valuation;
- fulfilling obligations under applicable law;
- customer due diligence and compliance with the obligations under the AML Act, where applicable to the given transaction;
- invoicing and bookkeeping;
- handling complaints;
- asserting, exercising and defending legal claims;
- pursuing the Controller's legitimate interests;
- direct marketing and sending advertising, only where the legal conditions for doing so are met or, where required, the data subject has given prior consent.
2.3. Legal bases of the processing
The Controller applies the appropriate legal basis for each processing activity depending on its purpose and circumstances.
Performance of a contract and pre-contractual steps
Under Article 6(1)(b) GDPR, the Controller may process personal data that is necessary for the performance of a contract with the data subject, or to take steps at the data subject's request prior to entering into a contract.
Compliance with a legal obligation
Under Article 6(1)(c) GDPR, the Controller processes data whose processing is required by law. This includes, in particular, processing under the AML Act and accounting legislation.
Legitimate interest
Under Article 6(1)(f) GDPR, the Controller may also process personal data to pursue its legitimate interests, provided the processing is necessary and the Controller's interests are not overridden by the interests, fundamental rights and freedoms of the data subject.
The Controller's legitimate interests include, in particular:
- matching supply and demand while performing the mandate;
- ensuring continuity of contact;
- asserting, exercising and defending the Controller's contractual and other legal claims;
- preventing abuse, false inquiries and unauthorised use of data;
- protecting IT systems and business secrets.
Where the processing is based on a legitimate interest, the Controller applies the requirements of a balancing-of-interests test.
Consent
Under Article 6(1)(a) GDPR, the Controller processes personal data on the basis of consent in cases where consent is the appropriate legal basis.
Consent is freely given, specific, informed and unambiguous. The data subject may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
Reading or acknowledging this Notice does not, in itself, constitute consent to any processing for which separate consent is required under the GDPR.
2.4. Voluntary nature of providing data
Providing data is generally voluntary. Providing the data necessary to conclude and perform the agency agreement, and — where the AML Act applies — for customer due diligence, is a condition for using the service. If the data subject does not provide this data, the Controller cannot accept the mandate, or cannot carry out a transaction falling under the AML Act.
For a simple inquiry made via the Website, by phone or by e-mail, a name and a contact detail are generally sufficient. Without these, the Controller cannot respond to the inquiry.
III. The processing procedure and the categories of data processed
3.1. Description of the processing procedure
The Controller's services can be used via the Website, by phone, by e-mail, and through personal contact.
Where a data subject instructs the Controller to sell or let a property, the data subject enters into a contract with Extraverz Szolgáltató Kft.
For the performance of the service, the property agent may record the necessary data of the property and the client, and prepare the property listing.
The finished listing may be published on the Website, on real estate portals, and on other public platforms through which the Controller facilitates the sale or letting of the property.
As a general rule, the personal data of the property owner is not published in listings. Listings may show the contact details of the property agent. In photographs of properties, the Controller strives to ensure that no identifiable natural person, licence plate or document appears.
For a client looking for a property, the Controller may record the data necessary to fulfil the search request.
When the agency relationship ends, the listing is removed from the sale/letting platforms, and the Controller either deletes the data or retains it for the purpose, in the manner and for the period set out in this Notice.
The Controller does not record phone calls.
3.2. Source of the data
The Controller obtains personal data primarily directly from the data subject, for example:
- by e-mail;
- by phone;
- at a personal meeting;
- when filling in a contract or other document;
- via the Website.
In certain cases, the Controller may also obtain personal data from another person or from a publicly available source, provided there is an appropriate legal basis for processing it. Such a source may be, for example, a publicly available land registry or other database, or data provided by another client for the purposes of the agency service.
Providing data voluntarily does not automatically amount to consent to the processing. The legal basis of the processing must in every case be determined based on the specific purpose of the processing and the provisions of the GDPR.
Where the data does not originate from the data subject, the Controller provides information under Article 14 GDPR, unless such information is not required under the Regulation.
3.3. Categories of personal data processed
Depending on the purpose of the processing, the Controller may process the following data.
Contact and identification data for inquiries and general contact:
- name;
- phone number;
- e-mail address;
- address, if provided by the data subject;
- content of the inquiry.
Further identification data required to conclude a contract and perform the mandate:
- family and given name;
- residential address;
- other data recorded in the contract necessary for its performance.
Property-related data:
- address of the property;
- land registry (topographic lot) number;
- floor area;
- other material characteristics of the property;
- sale price or rental fee;
- photographs of the property.
Property-search-related data:
- characteristics of the property sought;
- geographic and other search criteria;
- other information provided by the client necessary to fulfil the search.
AML Act data – only where the AML Act applies to the given transaction:
- birth name;
- place and date of birth;
- mother's birth name;
- nationality;
- residential address;
- type and number of identity document;
- data on the beneficial owner;
- data on politically exposed person status;
- for a legal person or an unincorporated organisation, the data of the authorised representative.
Billing data:
- billing name;
- billing address;
- other data on taxation and billing required by law.
In the event of a legal dispute:
- data relating to the claim or dispute;
- documents and communications necessary to assert the legal claim.
3.4. Place of the processing
Paper-based documents are kept at a place designated and appropriately secured by the Controller.
Personal data may also be stored in the Controller's IT systems. For electronic processing, the Controller applies appropriate technical and organisational measures to protect the data.
IV. Individual processing activities
4.1. Contact via the Website, by phone or by e-mail
Purpose: responding to inquiries, providing information, calling back, and selecting the appropriate service.
Legal basis: pre-contractual steps taken at the data subject's request [Article 6(1)(b) GDPR]; where no intention to contract can yet be established, the Controller's legitimate interest in maintaining contact [Article 6(1)(f) GDPR].
Data processed: name, phone number, e-mail address, content of the inquiry, data on the relevant property or search request.
Retention: if the inquiry does not result in a mandate, the Controller retains the data for 1 year from the last contact and then deletes it, unless a longer retention period is justified by law or by the need to assert a legal claim.
4.2. Processing related to the sale or letting of a property
Purpose: sale or letting of the property and the related contact, advertising and agency activity.
Legal basis: pre-contractual steps and performance of the contract [Article 6(1)(b) GDPR]; depending on the specific processing, a legal obligation [Article 6(1)(c) GDPR] or a legitimate interest [Article 6(1)(f) GDPR], in particular to match supply and demand and to publish the listing.
Retention: 5 years from the termination of the agency relationship. Where a longer retention period is prescribed for the same data by the AML Act or accounting rules, the Controller applies the longer period.
4.3. Processing related to a property search
Purpose: recording the data subject's property requirements, recommending properties, contacting the data subject and facilitating the property transaction.
Legal basis: pre-contractual steps or performance of the contract [Article 6(1)(b) GDPR]; in the absence of these, the legitimate interest in carrying out the agency activity [Article 6(1)(f) GDPR]. Separate consent only where it is the appropriate legal basis for the processing [Article 6(1)(a) GDPR].
Retention:
- for a search without a contract, 1 year from the closing of the search or from the last contact;
- for a contractual relationship, 5 years from its termination, or the longer statutory retention period.
4.4. Assertion of legal claims
Purpose: asserting, exercising and defending contractual or other legal claims and the Controller's rights.
Legal basis: the Controller's legitimate interest [Article 6(1)(f) GDPR]; where the processing is necessary to comply with a legal obligation, Article 6(1)(c) GDPR.
Retention: until the claim can no longer be enforced, typically until the end of the limitation period under the Hungarian Civil Code, and until the final conclusion of any related legal remedy proceedings.
4.5. Processing related to the prevention of money laundering and terrorist financing
Purpose: fulfilling customer due diligence, record-keeping and other obligations under the AML Act.
Legal basis: compliance with a legal obligation [Article 6(1)(c) GDPR], under the AML Act.
This processing does not apply to every inquiry, only where the AML Act applies to the given transaction or business relationship.
Retention: 8 years from the termination of the business relationship or the performance of the transaction. Where the data is affected by an official, prosecutorial or judicial request, the longer retention period of up to 10 years under the AML Act applies.
4.6. Processing related to billing and bookkeeping
Purpose: fulfilling billing, bookkeeping and tax obligations.
Legal basis: compliance with a legal obligation [Article 6(1)(c) GDPR].
Retention: accounting records must be kept for at least 8 years under the Accounting Act.
4.7. Direct marketing
Purpose: sending offers, newsletters or advertising relating to the Controller's services.
Legal basis: the data subject's prior consent [Article 6(1)(a) GDPR], or, where the conditions of the advertising legislation are met, the relevant statutory authorisation.
Retention: until consent is withdrawn or the sending of advertising ceases. Consent may be withdrawn at any time via the contact e-mail address. Withdrawal does not affect the lawfulness of earlier processing.
V. Other information relating to the processing
5.1. Data transfers, categories of recipients
The Controller transfers personal data to a third party only on an appropriate legal basis.
Recipients, or categories of recipients, of personal data include in particular:
- the Website's hosting provider and providers supporting the Controller's IT operations, as processors;
- the accountant, as a processor;
- real estate listing portals and other public advertising platforms – these typically also carry out processing for their own purposes and are therefore generally not processors but independent controllers;
- the provider of an energy performance certificate, a valuer, a lawyer, a notary, or any other person providing a related service requested by the data subject, to the extent necessary for performance;
- the other client involved in the transaction (e.g. a prospective buyer, prospective tenant, seller), with only the data necessary for the transaction; as a general rule, the owner's identification data is not shown in the listing;
- authorities and courts, where required by law or justified by an official request, in particular the National Tax and Customs Administration (NAV), the financial intelligence unit, the National Authority for Data Protection and Freedom of Information (NAIH), investigating authorities, the prosecution service and the courts.
5.2. Processors
The Controller may engage processors, in particular for hosting, IT and bookkeeping tasks.
A processor acts on the Controller's instructions and may not independently determine the purposes and means of the processing, unless expressly authorised to do so by law.
The Controller enters into contractual arrangements with its processors that comply with the requirements of the GDPR.
5.3. Transfers to third countries
The Controller does not transfer personal data to a third country outside the European Union or the European Economic Area, and does not transfer it to any international organisation.
Should this practice change in future, the Controller will provide the information required under the GDPR before any such transfer and will ensure appropriate safeguards.
5.4. Automated decision-making
The Controller does not apply automated decision-making within the meaning of Article 22 GDPR, and does not carry out any profiling resulting in such a decision.
5.5. Data security
The Controller applies appropriate technical and organisational measures to protect personal data, in particular against:
- unauthorised access;
- unauthorised alteration;
- unauthorised transfer;
- unauthorised deletion;
- accidental destruction;
- loss;
- and other unlawful forms of processing.
Such measures may include, in particular, access control, IT security, backups, anti-virus protection and physical security.
5.6. Technical data and cookies
The Website does not use cookies and does not apply similar tracking technology.
There are no cookies on our website – partly because we dislike them, partly because they add clutter, and partly because no one reads them anyway.
While the Website is operating, the hosting provider's system may briefly record the technical log data necessary to provide the service (e.g. the time of connection, the address of the page requested). The Controller does not use this data for profiling, statistical analysis or marketing. The hosting provider may store the log data for as long as necessary to ensure operation and security.
5.7. End of the processing – deletion of data
The Controller deletes or anonymises personal data once the purpose of the processing has ceased and there is no legal or legitimate interest, or statutory obligation, that requires the further retention of the data.
Where the processing is based on consent, the data subject may withdraw that consent. Withdrawal does not affect the lawfulness of the earlier processing.
The data subject's right to erasure does not necessarily result in the immediate deletion of the data if, for example, the Controller is required by law to retain the data, or the data is needed to assert, exercise or defend legal claims.
5.8. Personal data breach
In the event of a personal data breach, the Controller acts in accordance with the GDPR and applicable law.
Where a personal data breach is likely to result in a risk to the rights and freedoms of natural persons, the Controller notifies the competent supervisory authority without undue delay, and where feasible within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk.
Where a personal data breach is likely to result in a high risk to the rights and freedoms of the data subject, the Controller informs the data subject without undue delay, in accordance with the conditions set out in the GDPR.
The Controller documents personal data breaches.
VI. Rights of the data subject
Under the conditions set out in the GDPR, the data subject has, in particular, the following rights.
Right to information and access
The data subject has the right to request information as to whether their personal data is being processed and, if so, to request access to the personal data processed and to information relating to the processing.
Right to rectification
The data subject has the right to request the rectification of inaccurate personal data, or the completion of incomplete data.
Right to erasure
The data subject has the right to request the erasure of their personal data where the conditions set out in the GDPR are met. The right to erasure does not apply where the processing must continue to comply with a legal obligation, to assert a legal claim, or for another reason set out in the GDPR.
Right to restriction of processing
The data subject has the right to request the restriction of processing in the cases set out in the GDPR.
Right to object
Where the processing is based on the Controller's legitimate interest, the data subject has the right to object to the processing under the conditions set out in Article 21 GDPR. The data subject may object at any time to processing carried out for direct marketing purposes.
Right to data portability
Where the GDPR conditions are met, the data subject has the right to receive the personal data concerning them that they have provided to the Controller in a structured, commonly used and machine-readable format, and to request that this data be transmitted to another controller.
Right to withdraw consent
Where the processing is based on consent, the data subject may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
VII. Exercising the data subject's rights
The data subject may submit a request to exercise the above rights to the Controller at the following contact details:
E-mail: info@burjaningatlan.hu
Phone: +36 20 397 1163
Postal address: 5000 Szolnok, Czakó E. u. 3. VII/56., Hungary
The Controller responds to the data subject's request within the time limit set out in the GDPR.
As a general rule, the Controller informs the data subject of the action taken on the request within one month of receiving it.
For a particularly complex request or a large number of requests, this time limit may be extended by a further two months under the conditions set out in the GDPR. The Controller informs the data subject of any such extension and the reasons for the delay.
The Controller may request further information where necessary to confirm the data subject's identity. As a general rule, fulfilling the request is free of charge. In the case of a manifestly unfounded or excessive repeated request, a fee may be charged under the GDPR, or the Controller may refuse to act on the request.
VIII. Legal remedies
The data subject has the right to lodge a complaint with the competent supervisory authority if they consider that the processing of their personal data infringes the GDPR.
The competent supervisory authority in Hungary is:
National Authority for Data Protection and Freedom of Information (NAIH)
Seat: 1055 Budapest, Falk Miksa utca 9–11., Hungary
Postal address: 1363 Budapest, Pf. 9., Hungary
Phone: +36 (1) 391-1400
E-mail: ugyfelszolgalat@naih.hu
Website: www.naih.hu
Regardless of the right to lodge a complaint, the data subject may also bring proceedings before a court. Such proceedings may be brought before the competent regional court (törvényszék) of the data subject's place of residence or habitual stay.
IX. Amendment of this Notice
The Controller reserves the right to amend this Privacy Notice, in particular in the event of a change in the applicable law, in the processing activities, or in the operation of the Website.
The version of the Privacy Notice in force at any given time is available on the Website.
Effective date: 20 August 2026.