Our CertificationsView
Certifications
Contact

info@chessenergy.hu
+36 20 555 8537

Office

6723 Szeged,
Római körút 21.

Privacy Notice

Effective from: 15 July 2026

Chess Energy Kft. is committed to protecting personal data. The purpose of this Privacy Notice is to provide clear and transparent information about the processing of the personal data of website visitors, prospective clients, business contacts and job applicants.

In particular, this Notice explains the purposes and legal bases of processing, the categories of personal data processed, data retention periods, the persons who may access the data, the service providers used, and the rights and legal remedies available to data subjects.

1. Details of the Controller

Name of the Controller: Chess Energy Kft.

Registered office: 6723 Szeged, Római körút 21, Hungary

Company registration number: 06-09-023323

Tax number: 25863440-2-06

Represented by: Dániel Tóth, Managing Director

Postal address: 6723 Szeged, Római körút 21, Hungary

Email address: info@chessenergy.hu

Telephone: +36 20 555 8537

Website: www.chessenergy.hu

Hereinafter referred to as the Controller.

Data Protection Officer

The Controller is not required to appoint a data protection officer and has therefore not appointed one.

2. Scope of this Notice

This Notice applies to the processing of personal data carried out through the chessenergy.hu website operated by the Controller and in the course of related electronic communications.

In particular, this Notice covers the following processing activities:

  • contact enquiries and requests for quotations;
  • applications for specific job vacancies;
  • speculative job applications;
  • retention of job applications for future opportunities;
  • electronic correspondence;
  • website operation and IT security;
  • the use of cookies and similar technologies;
  • the use of Google Analytics;
  • the use of Google Search Console;
  • recording cookie preferences and consent choices.

3. Principles of Data Processing

The Controller processes personal data lawfully, fairly and transparently in relation to data subjects.

The Controller requests and processes only personal data that are necessary for the relevant processing purpose. Personal data are processed solely for specified and lawful purposes and only for as long as necessary to achieve those purposes.

The Controller implements appropriate technical and organisational measures to ensure the security of personal data and protects such data, in particular, against unauthorised access, alteration, transmission, disclosure, erasure, destruction, loss or damage.

4. Contact Enquiries and Requests for Quotations

4.1. Purpose of Processing

The purpose of processing is to enable the Controller to receive and respond to enquiries submitted through the contact form available on the website, by email, by telephone or through other communication channels.

The purposes of processing may include, in particular:

  • responding to general questions;
  • establishing contact;
  • handling enquiries relating to a project or service;
  • processing requests for quotations;
  • preparing business discussions;
  • returning a call or providing a response.

4.2. Categories of Personal Data Processed

  • name;
  • company or organisation name, where provided;
  • job title, where provided;
  • email address;
  • telephone number, where provided;
  • subject of the enquiry or message;
  • content of the message;
  • date and time of the enquiry;
  • additional information generated during the communication;
  • technical data associated with form submission, such as IP address and security log data, where recorded by the system.

4.3. Legal Basis for Processing

Where the purpose of the enquiry is to prepare a contract or business cooperation, the legal basis for processing is taking steps at the request of the data subject prior to entering into a contract, pursuant to Article 6(1)(b) of the GDPR.

Where the personal data of a contact person acting on behalf of a legal entity or other organisation are processed, the legal basis is the legitimate interest of the Controller and the organisation concerned in maintaining contact, conducting business communications and preparing cooperation, pursuant to Article 6(1)(f) of the GDPR.

In the case of a general enquiry that is not related to the preparation of a contract or business cooperation, the legal basis for processing may be the data subject’s consent, pursuant to Article 6(1)(a) of the GDPR.

4.4. Source of the Data

The personal data are provided by the data subject. In the case of a business contact, the data may also be provided to the Controller by the data subject’s employer, principal or another representative of that organisation.

4.5. Data Retention Period

Where an enquiry is not followed by the conclusion of a contract or further cooperation, the Controller retains the personal data relating to the enquiry for 1 year from the closure of the matter.

Where an enquiry is followed by the conclusion of a contract or a further business relationship, the data may continue to be processed as part of the relevant contractual, accounting or other related processing activity for the applicable retention period.

In the event of a legal claim or dispute, the Controller may retain the data until the claim has been finally resolved or the applicable limitation period has expired.

4.6. Consequences of Failure to Provide Data

Without the data marked as mandatory, the Controller will be unable to receive, properly process or respond to the enquiry.

5. Application for a Specific Job Vacancy

5.1. Purpose of Processing

The purpose of processing is to receive, register and assess applications submitted for a specific vacancy advertised on the website or elsewhere, evaluate the applicant’s professional suitability, maintain contact with the applicant and conduct the recruitment and selection process.

5.2. Categories of Personal Data Processed

In connection with an application, the Controller may process, in particular, the following personal data:

  • name;
  • email address;
  • telephone number;
  • title of the position applied for;
  • curriculum vitae and its full contents;
  • cover letter and its full contents;
  • information relating to education, qualifications and professional licences or authorisations;
  • information relating to previous employment and professional experience;
  • information relating to language skills and other professional knowledge;
  • salary expectations provided by the applicant, where requested by the form;
  • information relating to the place or method of work or the applicant’s potential start date;
  • other documents uploaded by the applicant;
  • date and time of the application and related communications;
  • information provided during interviews and professional discussions;
  • professional assessments and notes made by persons participating in the selection process;
  • technical and security data associated with form submission, where recorded by the system.

5.3. Legal Basis for Processing

The legal basis for processing is taking steps at the request of the data subject prior to entering into an employment contract or establishing another employment relationship, pursuant to Article 6(1)(b) of the GDPR.

The legal basis for retaining the data for a limited period following completion of the selection process may be the Controller’s legitimate interest, pursuant to Article 6(1)(f) of the GDPR. The legitimate interest is to document the selection process, handle questions relating to the decision and establish, exercise or defend potential legal claims.

The data subject has the right to object to processing based on legitimate interests.

5.4. Source of the Data

The personal data are primarily provided by the applicant. Where the applicant applies through a recruitment agency or another intermediary organisation, the data may also originate from that intermediary.

5.5. Persons Authorised to Access the Data

Application data may be accessed only by persons whose participation in the selection process makes such access necessary.

These may include, in particular:

  • the Controller’s management;
  • persons performing HR or employment-related duties;
  • the manager responsible for the relevant professional area;
  • professional staff involved in the selection process;
  • the Controller’s IT service providers, subject to appropriate confidentiality and data protection obligations.

5.6. Data Retention Period

The Controller retains the data submitted in response to a specific job vacancy until the selection process has been completed and for 1 year thereafter.

[# TO BE REVIEWED: whether Chess Energy accepts a retention period of 6 months following completion of the selection process]

Where the applicant is employed, the data required for the employment relationship may continue to be processed for the new purpose in accordance with the separate data protection rules applicable to employees.

Where the applicant gives separate consent to the retention of their application materials for future job opportunities, the data may be processed for the additional period specified in that consent.

In the event of a legal claim or dispute, the Controller may retain the relevant data until the proceedings or dispute have been finally resolved.

5.7. Consequences of Failure to Provide Data

Without the data marked as mandatory in the application form and the documents required to assess the application, the Controller will be unable to evaluate the application.

6. Speculative Job Applications

6.1. Purpose of Processing

The purpose of processing is to enable the Controller to receive and register speculative applications that are not linked to a currently advertised vacancy and to contact the applicant if a future opportunity matching their professional profile becomes available.

6.2. Categories of Personal Data Processed

  • name;
  • email address;
  • telephone number;
  • area of interest or professional field;
  • curriculum vitae and its full contents;
  • cover letter or introductory message;
  • information relating to education, qualifications and professional licences or authorisations;
  • professional experience;
  • language skills and other professional knowledge;
  • preferences relating to the place or method of work;
  • potential start date;
  • other documents uploaded by the data subject;
  • date and time of the application and related communications;
  • technical and security data associated with form submission, where recorded by the system.

6.3. Legal Basis for Processing

The legal basis for processing is the applicant’s freely given consent, pursuant to Article 6(1)(a) of the GDPR.

Consent may be withdrawn at any time, without giving reasons, using the Controller’s contact details set out in this Notice.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

6.4. Data Retention Period

The Controller processes data relating to speculative job applications for 1 year from receipt of the application.

At the end of the 1-year period, the Controller deletes the application data unless the data subject provides renewed, properly documented consent before the expiry of the retention period.

Where the applicant enters the selection process for a specific vacancy, the data may continue to be processed in accordance with the rules applicable to that selection process.

6.5. Consequences of Failure to Provide Data

Without the data and documents marked as mandatory, the Controller will be unable to register the speculative application or consider it in connection with future job opportunities.

7. Retention of Data Relating to Applicants for Specific Vacancies for Future Job Opportunities

The Controller retains the data of applicants who applied for a specific vacancy but were not selected for that position for future job opportunities only where the applicant has provided separate and freely given consent.

This consent is separate from the application for the specific vacancy, and refusal to provide it does not affect the assessment of the current application.

Purpose of processing: to contact the applicant if a new job opportunity matching their professional profile becomes available during the validity period of the consent.

Legal basis for processing: the data subject’s consent, pursuant to Article 6(1)(a) of the GDPR.

Duration of processing: 1 year from the date consent is given, or until consent is withdrawn earlier.

8. Special Categories of Personal Data in Job Applications

The Controller does not request special categories of personal data relating to racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, genetic or biometric data, sex life or sexual orientation for the purpose of assessing job applications.

Applicants are requested not to include special categories of personal data that are not necessary for assessing the application in their curriculum vitae, cover letter or other documents.

The Controller may erase or redact without undue delay any special-category personal data provided voluntarily but not required for the selection process.

The Controller requests a certificate of good conduct, a medical fitness document or another document containing special-category personal data only where justified by the nature of the position or required by law. The data subject will receive separate information about such processing.

9. Electronic Correspondence

The Controller may also receive and process data submitted through contact and job application forms by electronic mail.

The data processed in the course of electronic correspondence may include, in particular:

  • the names of the sender and recipient;
  • email addresses;
  • the subject and content of the message;
  • documents attached to the message;
  • the date and time of sending and delivery;
  • technical data recorded by the email system.

The legal basis and retention period for electronic correspondence depend on the purpose of the relevant message. Contact enquiries are governed by Section 4 of this Notice, while job applications are governed by Sections 5–7.

10. Website Operation and Processing of Technical Log Data

10.1. Purpose of Processing

The Controller and its hosting provider may process technical log data to ensure the secure and proper operation of the website.

The purposes of processing include, in particular:

  • ensuring the operation of the website;
  • identifying and resolving errors;
  • maintaining IT and network security;
  • detecting unauthorised access attempts;
  • preventing misuse and automated attacks;
  • ensuring website availability.

10.2. Categories of Personal Data Processed

  • IP address;
  • date and time of the visit;
  • address of the page or file accessed;
  • HTTP response code;
  • technical information relating to the visitor’s browser and device;
  • address of the previous or referring page;
  • events relating to system operation and security;
  • error and security log entries.

10.3. Legal Basis for Processing

The legal basis for processing is the Controller’s legitimate interest in operating the website securely, ensuring service availability and preventing cyberattacks, pursuant to Article 6(1)(f) of the GDPR.

10.4. Data Retention Period

As a general rule, the Controller and its hosting provider retain technical and security log data for no longer than 90 days.

In the event of a security incident, misuse or legal claim, the relevant log data may be retained for longer, until the incident has been investigated or the relevant proceedings have been concluded.

11. Cookies and Similar Technologies

11.1. What Is a Cookie?

A cookie is a small data file that a website may place on a visitor’s device or access through the visitor’s browser. Cookies may enable, among other things, the proper operation of the website, the storage of visitor preferences and the measurement of website use.

11.2. Categories of Cookies Used on the Website

Strictly Necessary Cookies

These cookies are required for the website’s essential operation and security, the proper functioning of forms, load balancing or remembering the visitor’s cookie preferences.

Without these cookies, certain website functions would not operate or would not operate properly. Separate consent is not required for strictly necessary cookies.

The legal basis for any related processing of personal data is the Controller’s legitimate interest in operating the website securely and properly, pursuant to Article 6(1)(f) of the GDPR.

Statistics Cookies

Statistics cookies enable the Controller to obtain information about how visitors use the website, including which pages they view, how long they remain on the website, what device they use and the source from which they arrived.

Statistics cookies may be placed or activated only after the visitor has given prior consent.

The legal basis for processing is the data subject’s consent, pursuant to Article 6(1)(a) of the GDPR.

Marketing Cookies

The website does not currently use cookies for marketing or advertising purposes.

11.3. Detailed List of Cookies Used

The name, provider, purpose, category and validity period of each cookie can be viewed through the cookie settings interface available on the website or in a separate Cookie Policy.

Cookie settings or Cookie Policy: [# TO BE COMPLETED: URL or the name of the button that opens the cookie settings]

Consent management system used: [# TO BE COMPLETED: for example, Cookiebot, Complianz, CookieYes or another solution]

11.4. Modifying and Withdrawing Consent

When first opening the website, the visitor may allow or reject the use of cookies requiring consent through the cookie settings interface displayed.

The visitor may modify or withdraw previously given consent at any time using the cookie settings interface available on the website.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

12. Recording Cookie Preferences and Consent Choices

For the purpose of demonstrating whether consent to cookies was given or refused and remembering visitor preferences, the Controller may record:

  • the date and time of consent or refusal;
  • the cookie categories selected;
  • the consent identifier;
  • the version of the notice or cookie settings interface in effect when consent was given;
  • limited technical data, such as a partially anonymised IP address, where recorded by the system used.

The purpose of processing is to implement the visitor’s choice and demonstrate that the Controller has acted in accordance with the requirements applicable to consent.

The legal basis for processing is compliance with the Controller’s legal obligations and its legitimate interest in demonstrating such compliance, pursuant to Article 6(1)(c) and (f) of the GDPR.

Retention period: [# TO BE COMPLETED: the actual retention period used by the consent management system; it is recommended that this cover the validity period of the consent and the limitation period for any potential claims]

13. Google Analytics

13.1. Purpose of the Service

The Controller uses Google Analytics 4 to measure website traffic, usage and technical performance.

The service enables the Controller to obtain aggregated statistical information including:

  • the number of website visitors;
  • the number of sessions and page views;
  • the pages visited;
  • actions and events performed on the website;
  • the approximate geographical location of the visit;
  • the type of browser and device used;
  • the source from which the visitor arrived at the website;
  • the time spent on the website;
  • the technical performance of the website.

13.2. Details of the Service Provider

Service provider: Google Ireland Limited

Registered office: Gordon House, Barrow Street, Dublin 4, Ireland

Privacy Policy: https://policies.google.com/privacy

13.3. Legal Basis for Processing

Google Analytics may be activated only after the visitor has given prior consent.

The legal basis for processing is the data subject’s consent, pursuant to Article 6(1)(a) of the GDPR.

The visitor may modify or withdraw consent at any time through the cookie settings interface.

13.4. Categories of Personal Data Processed

Depending on the Google Analytics settings, the following data may be processed in particular:

  • online identifiers and cookie identifiers;
  • device and browser data;
  • approximate geographical location;
  • page-view and session data;
  • actions and events performed on the website;
  • information relating to the source of the visit;
  • technical and performance data.

The Controller does not intentionally transmit visitors’ names, email addresses, telephone numbers or other data that directly identify them to Google Analytics.

13.5. Data Retention

The retention period for user-level and event-level data in Google Analytics is:

[# TO BE COMPLETED: the 2- or 14-month data retention period actually configured in GA4]

Aggregated statistical reports that cannot be directly linked to an individual may remain available for longer.

13.6. Google Consent Mode

The Controller may use Google Consent Mode to communicate visitors’ cookie choices and regulate the operation of Google tags.

Solution used: [# TO BE COMPLETED: Google Consent Mode v2 basic or advanced mode, together with a brief description of the configuration]

The consent management system must ensure that Google Analytics does not place statistics cookies without the visitor’s appropriate consent.

14. Google Search Console

The Controller uses Google Search Console to monitor the website’s appearance in Google Search, its indexing status and its technical condition.

Google Search Console may provide aggregated information including:

  • the website’s appearances in Google Search;
  • clicks on search results;
  • search queries associated with the website;
  • average search positions;
  • indexing and technical errors;
  • the website’s mobile and technical usability.

Google Search Console does not operate through a separate visitor tracking code placed on the website and does not itself place Search Console cookies on website visitors’ devices.

The search data displayed by Search Console are generally aggregated. For privacy reasons, Google does not display certain rare or personally identifying search queries.

Where Google Search Console and Google Analytics accounts are linked, the linked data may be accessed by persons who have the appropriate permissions in the relevant Google account.

Method used to verify Search Console ownership: [# TO BE COMPLETED: DNS record, HTML file, HTML tag, Google Analytics or Google Tag Manager]

15. Technical Processing of Web Forms

Form data submitted through the website may be technically processed by the website’s content management system, hosting provider and the email or SMTP service provider used to forward the messages.

System used for forms: Fluent Forms

Storage of form submissions in WordPress: Yes

If yes, storage location: Forms > Form Entries (database)

If yes, retention period: Until the data are deleted

Recipient email address for form messages: info@chessenergy.hu

SMTP or email service provider: [# TO BE COMPLETED]

Spam protection: Cloudflare Turnstile

Where an external spam protection service is connected to the forms, the section of this Notice concerning processors must be supplemented with the details of the actual service provider and any transfer of data outside the EEA.

16. Processors and Other Service Providers

The Controller may engage external service providers to perform certain technical, IT and communication-related tasks.

Processors may process personal data only on the Controller’s instructions, to the extent necessary to provide the service, and subject to appropriate contractual, confidentiality and data security obligations.

16.1. Hosting Provider

Name of service provider: DotRoll Kft.

Registered office: 1148 Budapest, Fogarasi út 3-5, Hungary

Website: www.dotroll.com

Activity: hosting the website, database, files, log data and, where applicable, form submissions.

Data concerned: data processed through the website and technical log data.

16.2. Email and SMTP Service Provider

Name of service provider: DotRoll Kft.

Registered office: 1148 Budapest, Fogarasi út 3-5, Hungary

Website: www.dotroll.com

Activity: transmission, delivery and storage of electronic mail.

Data concerned: name, email address, message and attachment contents, and technical delivery data.

16.3. Website Developer and Maintenance Provider

Name of service provider: Artsolution (Miltenov Petrov Norbert, sole proprietor)

Registered office: 1174 Budapest, Jósika utca 17/A, Hungary

Website: www.artsolution.hu

Activity: website development, maintenance, troubleshooting, security and technical support.

Data concerned: personal data accessible through the website’s administration interface, database or logs, solely where necessary to perform the relevant tasks.

16.4. Backup Service Provider

Name of service provider: DotRoll Kft.

Registered office: 1148 Budapest, Fogarasi út 3-5, Hungary

Activity: storage of website and database backups.

Backup retention period: 30 days

16.5. Consent Management Service Provider

Name of service provider: [# TO BE COMPLETED]

Registered office: [# TO BE COMPLETED]

Activity: management and recording of visitors’ cookie choices.

16.6. Spam Protection Service Provider

Name of service provider: Cloudflare, Inc.

Registered office: 101 Townsend St, San Francisco, CA 94107, USA

Activity: detecting and preventing automated or abusive form submissions.

Data concerned: IP address, device and browser data, and technical data relating to form use.

16.7. Google Analytics and Google Search Console

Service provider: Google Ireland Limited

Registered office: Gordon House, Barrow Street, Dublin 4, Ireland

Activity: provision of web analytics, search performance measurement and technical services.

Depending on the service, functionality and data-sharing settings used, Google may act as either a processor or an independent controller.

16.8. System Used to Store Job Applications

Name of service provider or system: [# TO BE COMPLETED: for example, email account, Google Drive, Microsoft 365, local server or HR system]

Exact name of service provider: [# TO BE COMPLETED]

Registered office: [# TO BE COMPLETED]

Activity: storage, management and availability of CVs and application documents to persons involved in the selection process.

17. Recipients of the Data and Persons Authorised to Access Them

Within the Controller’s organisation, personal data may be accessed only by employees, managers and other contributors who need access in order to perform their duties.

Access is limited in each case to the extent necessary for the relevant task.

The Controller may also disclose personal data to an authority, court, investigative authority or another public body where required by law or where necessary for the establishment, exercise or defence of legal claims.

18. Transfers Outside the European Economic Area

Where possible, the Controller uses service providers and data storage locations operating within the European Economic Area.

Certain international service providers, particularly Google and other cloud-based IT service providers, may process personal data in, or make them accessible from, countries outside the European Economic Area, including the United States of America.

Such transfers may take place only on the basis of an appropriate legal ground and subject to the safeguards required under Chapter V of the GDPR, including:

  • an adequacy decision adopted by the European Commission;
  • transfer to a service provider appropriately certified under the EU–US Data Privacy Framework;
  • the use of standard contractual clauses adopted by the European Commission;
  • or another transfer mechanism permitted by the GDPR.

At the data subject’s request, the Controller will provide information about the safeguards applied to the transfer.

19. Data Security

The Controller implements technical and organisational measures proportionate to the risks in order to protect personal data.

Such measures may include, in particular:

  • making the website available over an HTTPS connection;
  • user accounts protected by passwords and appropriate access controls;
  • multi-factor authentication where available;
  • regular software and security updates;
  • creating backups;
  • virus and malware protection;
  • firewalls and other network security solutions;
  • limiting access to those who require it;
  • confidentiality obligations for persons who have access to the data;
  • regular deletion of data that are no longer required;
  • appropriate contractual obligations imposed on processors.

The Controller notes that complete security of data transmitted over the internet cannot be technically guaranteed. Nevertheless, the Controller takes all measures that may reasonably be expected of it to reduce the risks.

20. Automated Decision-Making and Profiling

In connection with the processing activities covered by this Notice, the Controller does not use decision-making based solely on automated processing that produces legal effects concerning the data subject or similarly significantly affects them.

Job applications are assessed by persons participating in the selection process and not by an automated system.

21. Rights of Data Subjects

Data subjects may request to exercise their rights using the Controller’s contact details set out in this Notice.

21.1. Right to Information and Access

A data subject may request information as to whether the Controller processes their personal data. Where it does, the data subject is entitled to receive information including:

  • the purposes of processing;
  • the categories of personal data processed;
  • the recipients or categories of recipients of the data;
  • the retention period or the criteria used to determine it;
  • the rights available to the data subject;
  • the right to lodge a complaint;
  • the source of the data where they were not obtained directly from the data subject;
  • information about any automated decision-making;
  • the safeguards applied to transfers outside the European Economic Area.

The data subject may request a copy of the personal data being processed.

21.2. Right to Rectification

The data subject may request the rectification of inaccurate personal data concerning them and the completion of incomplete data.

21.3. Right to Erasure

The data subject may request the erasure of their personal data, in particular where:

  • the data are no longer necessary for the purposes for which they were collected;
  • the data subject withdraws consent and there is no other legal basis for processing;
  • the data subject objects to processing based on legitimate interests and there are no overriding lawful grounds for continuing the processing;
  • the processing is unlawful;
  • the data must be erased to comply with a legal obligation.

The right to erasure does not apply, among other cases, where processing is necessary for compliance with a legal obligation, the performance of a task carried out in the public interest, or the establishment, exercise or defence of legal claims.

21.4. Right to Restriction of Processing

The data subject may request restriction of processing where:

  • they contest the accuracy of the personal data;
  • the processing is unlawful, but they oppose erasure of the data;
  • the Controller no longer needs the data, but the data subject requires them for a legal claim;
  • the data subject has objected to processing based on legitimate interests, pending assessment of the objection.

21.5. Right to Data Portability

Where processing is based on consent or a contract and is carried out by automated means, the data subject may request to receive the data they have provided to the Controller in a structured, commonly used and machine-readable format and may request that those data be transmitted to another controller where technically feasible.

21.6. Right to Object

The data subject may object at any time, on grounds relating to their particular situation, to processing based on legitimate interests pursuant to Article 6(1)(f) of the GDPR.

Following an objection, the Controller may no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing that override the data subject’s interests, rights and freedoms, or grounds relating to the establishment, exercise or defence of legal claims.

21.7. Right to Withdraw Consent

Where processing is based on consent, the data subject may withdraw consent at any time without giving reasons.

Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

21.8. Rights Relating to Automated Decision-Making

The data subject has the right not to be subject to a decision based solely on automated processing that produces legal effects concerning them or similarly significantly affects them, except in the cases specified by the GDPR.

22. Handling Data Subject Requests

A data subject may submit a data protection request using the following contact details:

Email address: info@chessenergy.hu

Postal address: 6723 Szeged, Római körút 21, Hungary

The Controller will inform the data subject of the action taken on the request without undue delay and in any event within one month of receipt.

Where necessary, taking into account the complexity and number of requests, this period may be extended by a further two months. The Controller will inform the data subject of the extension and the reasons for it within the original one-month period.

Before complying with a request, the Controller may take reasonable steps to verify the identity of the data subject where it has reasonable doubts concerning the identity of the person making the request.

As a general rule, exercising data subject rights is free of charge. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, the Controller may charge a reasonable fee or refuse to act on the request.

23. Complaints and Legal Remedies

Where a data subject considers that the processing of their personal data infringes data protection legislation, they may contact the Controller directly with their complaint.

Controller’s contact details: info@chessenergy.hu

The data subject also has the right to lodge a complaint with the supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information

Registered office: 1055 Budapest, Falk Miksa utca 9–11, Hungary

Postal address: 1363 Budapest, PO Box 9, Hungary

Email address: ugyfelszolgalat@naih.hu

Telephone: +36 1 391 1400

Website: https://www.naih.hu

The data subject may also bring court proceedings if they consider that their rights have been infringed in connection with the processing of their personal data.

Data protection proceedings fall within the jurisdiction of the regional courts. At the data subject’s choice, proceedings may also be brought before the regional court with jurisdiction over the data subject’s place of residence or temporary residence.

24. Amendments to this Notice

The Controller is entitled to amend this Privacy Notice, in particular where its processing activities, services used, IT systems or applicable legal requirements change.

The version currently in force is available on the website.

Where an amendment materially affects the rights of data subjects or essential circumstances of the processing, the Controller will also inform the data subjects separately in an appropriate manner.

Date of the last amendment to this Notice: 15 July 2026

Széchenyi Terv Plusz pályázati információs blokk