
PRIVACY NOTICE
for the greencompass.hu website and Green Compass services
Effective from 1 July 2026
1. Purpose and Scope of this Notice
The purpose of this Privacy Notice is to explain, in a transparent and easily understandable manner, how Andrea Gecseg, sole proprietor, processes the personal data of visitors to the greencompass.hu website, prospective customers, customers, contractual partners, newsletter subscribers and other natural persons who come into contact with Green Compass services.
This Notice applies in particular to:
- the use of the greencompass.hu website and online store;
- contact enquiries and requests for quotations;
- free consultations;
- the ordering and performance of services;
- the Virtual Agricultural Assistant service;
- agricultural advisory, product development, regulatory approval, market research and marketing activities;
- webinars and professional events;
- the sending of newsletters;
- invoicing and payments;
- the use of cookies and web analytics services;
- the management of customer relationships and contractual documentation.
The Controller processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council, the General Data Protection Regulation - hereinafter referred to as the GDPR - and the applicable Hungarian legislation.
2. Details of the Controller
Name of the Controller: Andrea Gecseg, sole proprietor
Trading name: Green Compass
Registered office: 27 Rákóczi Ferenc Street, 9764 Csempeszkopács, Hungary
Tax number: 60583477-1-38
Website: greencompass.hu
Email address: info@greencompass.hu
Telephone number: +36 20 3635 178
Language of this Notice: English
For data protection enquiries and the exercise of data subject rights, the Controller can be contacted at info@greencompass.hu.
The Controller has not appointed a data protection officer. Data protection enquiries are handled directly by the Controller.
3. Details of the Hosting and Website Service Provider
Service provider: Webnode AG
Registered office: Badenerstrasse 47, 8004 Zurich, Switzerland
Company identification number: CH-170.3.036.124-0
Service: provision of the website and online store platform, hosting, technical operation, forms and related website functions.
In providing its services, Webnode may act as a processor on behalf of the Controller and, in relation to certain processing activities carried out for its own purposes, as an independent controller.
4. Principles of Personal Data Processing
When processing personal data, the Controller observes in particular the following principles:
- lawfulness, fairness and transparency;
- purpose limitation;
- data minimisation;
- accuracy;
- storage limitation;
- integrity and confidentiality;
- accountability.
The Controller processes only personal data that are necessary for the relevant purpose and retains them only for as long as justified by that purpose, the performance of a contract, a legal obligation or a legitimate interest.
The Controller does not sell personal data and does not use data received from customers for its own data-mining purposes or for business modelling of which the customer has not been informed.
5. Sources of Personal Data
The Controller primarily collects personal data directly from the data subject, for example:
- through a contact or quotation request form;
- by email or telephone;
- when entering into a contract;
- during the performance of a service;
- when placing an order through the online store;
- when subscribing to the newsletter;
- when registering for a webinar or consultation.
In certain cases, data may be provided by the data subject's employer, principal, business partner or a contractual customer of the Controller, for example for contact or project implementation purposes.
The Controller may also collect business contact details from lawfully accessible public registers or other public sources where this is necessary for a specific business enquiry or the performance of a contract.
Where personal data are not obtained directly from the data subject, the Controller informs the data subject about the processing in the cases specified in Article 14 of the GDPR.
6. Technical Data Processing Related to Visits to the Website
6.1. Purpose of the Processing
The purposes of processing technical data are:
- to ensure the operation of the website;
- to maintain the security of the website;
- to identify and resolve errors;
- to prevent unauthorised access and misuse;
- to monitor the performance and availability of the website.
6.2. Categories of Data Processed
When the website is used, the following data in particular may be processed automatically:
- IP address;
- date and time of the visit;
- address of the page visited;
- browser type and version;
- type of operating system;
- technical characteristics of the device;
- address of the referring page;
- technical event logs and error logs;
- session identifiers.
6.3. Legal Basis for the Processing
The legal basis for processing necessary to ensure the secure and proper operation of the website is the legitimate interest of the Controller under Article 6(1)(f) of the GDPR.
The Controller's legitimate interest is to maintain the IT security of the website, identify operational errors and prevent misuse.
6.4. Retention Period
Technical log data accessible to the Controller may be retained for a maximum of 12 months, unless a longer retention period is justified by a security incident, misuse or a legal claim.
The retention of the website platform's and hosting provider's own technical logs is governed by their applicable privacy and data processing terms.
7. Cookies and Similar Technologies
7.1. What is a Cookie?
A cookie is a small data file that a website places on, or reads from, the visitor's device. Some cookies are necessary for the operation of the website, while others may serve statistical, convenience or marketing purposes.
7.2. Strictly Necessary Cookies
Strictly necessary cookies enable, among other things:
- the basic operation of the website;
- website security;
- session management;
- the operation of the shopping basket and ordering process;
- the storage of cookie preferences;
- the technical operation of forms.
These cookies are necessary to provide a service expressly requested by the visitor and therefore do not always require separate consent.
7.3. Statistical and Analytics Cookies
With the visitor's consent, the website may use web analytics services, in particular Google Analytics.
The purposes of analytics processing are:
- to measure website traffic;
- to understand visitor behaviour;
- to improve the usability of the website;
- to analyse the performance of content and services.
The legal basis for the use of analytics cookies is the visitor's consent under Article 6(1)(a) of the GDPR.
Analytics cookies may not be activated before consent has been given.
7.4. Marketing Cookies
Marketing cookies may be used only where the visitor has given prior consent.
Their purposes may include in particular:
- measuring the effectiveness of advertisements;
- displaying advertisements tailored to the interests of website visitors;
- integrating social media or advertising services.
7.5. Cookie Settings and Withdrawal of Consent
When first visiting the website, the visitor may use the cookie management interface to:
- accept all cookies;
- reject non-essential cookies;
- adjust settings by category.
Consent may be withdrawn or modified at any time through the Cookie Settings interface available on the website.
Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
The current name, provider, purpose, category and duration of each cookie used can be viewed in the cookie settings interface on the website.
8. Contact Enquiries and General Enquiries
8.1. Purpose of the Processing
- to receive and respond to an enquiry;
- to establish contact;
- to provide information;
- to discuss a potential cooperation;
- to arrange an appointment.
8.2. Categories of Data Processed
- name;
- email address;
- telephone number;
- company name;
- content of the message;
- other information voluntarily provided in the enquiry;
- date and time of contact.
8.3. Legal Basis for the Processing
Where the enquiry concerns entering into a contract or using a service, the legal basis is taking steps at the request of the data subject prior to entering into a contract under Article 6(1)(b) of the GDPR.
For other general enquiries, the legal basis is the Controller's legitimate interest in responding to enquiries and conducting business communications under Article 6(1)(f) of the GDPR.
8.4. Retention Period
If contact is not followed by the conclusion of a contract, the Controller retains the enquiry and related correspondence for no longer than one year after the matter has been closed.
If the enquiry is followed by the conclusion of a contract, the data may be processed as part of the contractual documentation.
8.5. Consequences of Not Providing the Data
Without the necessary contact details, the Controller cannot respond to the enquiry or communicate with the interested person.
9. Free Consultation and Requests for Quotations
9.1. Purpose of the Processing
- to carry out a preliminary assessment of the customer's requirements;
- to arrange a consultation appointment;
- to prepare a personalised quotation;
- to determine the content and terms of the service.
9.2. Categories of Data Processed
- name;
- email address;
- telephone number;
- company or farm name;
- registered office or operating site;
- subject of the enquiry;
- basic details of the farm, product or project;
- additional information voluntarily provided for the preparation of the quotation.
9.3. Legal Basis for the Processing
The legal basis is taking steps at the request of the data subject prior to entering into a contract under Article 6(1)(b) of the GDPR.
9.4. Retention Period
If no contract is concluded, the Controller retains the quotation and the data relating to the request for a quotation for no longer than one year after the expiry of the quotation or the conclusion of the discussions.
If a contract is concluded, the data may become part of the contractual documentation.
10. Contract Formation and Performance of Services
10.1. Purpose of the Processing
- to prepare and conclude the contract;
- to perform the service;
- to maintain contact;
- to document tasks, deadlines and performance;
- to fulfil rights and obligations arising from the contract;
- to carry out quality and professional checks;
- to manage legal claims.
10.2. Categories of Data Processed
In the case of an individual customer or sole proprietor:
- name;
- home address or registered office;
- tax number;
- registration number;
- telephone number;
- email address;
- bank account details, where necessary;
- data provided in the contract and during performance.
In the case of a representative or contact person of a legal entity customer:
- name;
- position or authority to represent;
- business telephone number;
- business email address;
- signature;
- other information necessary for contact purposes.
10.3. Legal Basis for the Processing
For an individual customer, the legal basis is the performance of a contract under Article 6(1)(b) of the GDPR.
For a representative or contact person of a legal entity, the legal basis is the legitimate interest of the Controller and the contracting partner in performing the contract and maintaining business contact under Article 6(1)(f) of the GDPR.
10.4. Retention Period
The Controller retains contractual data for the duration of the contract and thereafter until the expiry of the general civil-law limitation period calculated from the termination or performance of the contract, generally five years.
In the event of a legal claim or administrative or judicial proceedings, the data may be processed until the proceedings have been finally concluded or until the claim can no longer be enforced.
11. Orders Placed Through the Online Store
11.1. Purpose of the Processing
- to record and confirm the order;
- to provide the service;
- to process payment and invoicing;
- to manage customer relations and complaints;
- to document performance of the order.
11.2. Categories of Data Processed
- name;
- email address;
- telephone number;
- billing name and address;
- company name;
- tax number;
- service or product ordered;
- order identifier;
- date and time of the order;
- payment method;
- payment status;
- information voluntarily provided in the comments field.
11.3. Legal Basis for the Processing
The legal basis for processing related to the performance of an order is the performance of a contract under Article 6(1)(b) of the GDPR.
The legal basis for processing accounting data is compliance with a legal obligation applicable to the Controller under Article 6(1)(c) of the GDPR.
11.4. Retention Period
The Controller retains data relating to orders and contracts for five years from performance and accounting documents for eight years.
12. Invoicing and Accounting
12.1. Purpose of the Processing
- to issue invoices;
- to comply with accounting and tax obligations;
- to maintain accounting records;
- to maintain financial records;
- to comply with official inspections.
12.2. Categories of Data Processed
- billing name;
- billing address;
- tax number;
- description of the service ordered;
- amount payable;
- date of performance and payment;
- invoice number;
- payment and accounting data.
12.3. Legal Basis for the Processing
The legal basis is compliance with a legal obligation applicable to the Controller under Article 6(1)(c) of the GDPR.
12.4. Retention Period
The Controller retains invoices and accounting documents for the period prescribed by accounting legislation, for at least eight years.
12.5. Recipients
The data may be accessed by the Controller, its accountant, the invoicing software provider, the payment service provider and, where required by law, the competent authorities.
13. Online Payments
Where online card payment is available, the payment transaction is carried out by the external payment service provider identified in the online store.
As a general rule, the Controller does not have access to the full card number, security code or other authentication data processed by the payment service provider in its own system.
The Controller may receive the following data:
- payment transaction identifier;
- date and time of payment;
- amount paid;
- payment status;
- payment method;
- information on whether the transaction was successful or unsuccessful.
The online payment service provider may also act as an independent controller in relation to the processing purposes it determines. Before initiating payment, the customer may review the payment service provider's own privacy notice.
14. Virtual Agricultural Assistant, Agricultural Administration and Professional Advisory Services
14.1. Purpose of the Processing
The purpose of the processing is to perform the agricultural administration, compliance, documentation, advisory or audit-preparation service ordered by the customer, including in particular:
- support with maintaining farm records;
- management of spraying and crop protection documentation;
- nitrate and nutrient-management calculations;
- preparation for inspections by competent authorities;
- preparation for sustainability and ESG audits;
- preparation of grant documentation;
- professional and compliance advisory services;
- risk analysis;
- organisation and review of documents.
14.2. Categories of Data That May Be Processed
A. Farm Identification and Business Data
- company name or name of the sole proprietor;
- registered office and operating site;
- tax number;
- primary producer identification number;
- customer and registration identifiers used by the Hungarian State Treasury or another authority;
- contact details.
B. Farm and Production Data
- area of land;
- land registry parcel number;
- type of land use;
- cropping pattern;
- crops grown;
- crop protection treatments;
- nutrient application data;
- nitrogen balance;
- classification as a nitrate-vulnerable area;
- number of livestock;
- livestock unit calculations;
- farm and technological data.
C. Subsidy and Grant Data
- agri-environmental documentation;
- documents relating to the Agro-ecological Programme;
- subsidy and grant data;
- payment applications;
- monitoring data;
- official inspection reports;
- inspection documents.
D. ESG and Sustainability Data
- greenhouse-gas emission estimates;
- energy and agricultural input use data;
- soil and water protection measures;
- sustainability indicators;
- environmental and operational performance data.
14.3. Legal Basis for the Processing
Where the data relate to the customer as a natural person or sole proprietor and are necessary for the performance of the service, the legal basis is the performance of a contract under Article 6(1)(b) of the GDPR.
Where the data relate to the customer's employees, contact persons, subcontractors or other data subjects, the legal basis may be the legitimate interest of the Controller or the customer in performing the contract, supporting documentation obligations and protecting legal claims.
The Controller relies on compliance with a legal obligation only where the relevant processing obligation applies directly to the Controller.
14.4. Roles as Controller and Processor
Where Green Compass determines the purposes and essential means of the processing, it acts as an independent controller.
Where Green Compass processes personal data contained in the customer's documents solely on the customer's instructions and on the customer's behalf, it acts as a processor.
Where a processor relationship exists, the Controller and the customer enter into a separate data processing agreement complying with Article 28 of the GDPR.
14.5. Retention Period
The Controller retains the data for as long as necessary to perform the service and thereafter until the expiry of the general civil-law limitation period calculated from the termination of the contract, generally five years.
Where sector-specific legislation, a subsidy condition, a grant requirement or an official obligation applicable to the customer requires a longer document retention period, that period shall be specified in the individual contract or data processing agreement.
14.6. Confidential Farm and Business Data
The Controller treats the following data in particular as strictly confidential:
- farm-level nutrient balances;
- production cost data;
- the agricultural input procurement structure;
- technology and formulation data;
- ESG performance indicators;
- non-public information relating to the operation of the farm.
These data may be disclosed to a third party only:
- with the customer's authorisation;
- to the extent necessary to perform the service;
- subject to contractual confidentiality obligations;
- or where required by law, a competent authority or a court.
15. Product Development and Regulatory Approval Projects
In connection with the development, regulatory approval or market launch of agricultural products, fertilisers, biostimulants, microbial products, algae-based technology solutions and other agricultural inputs, the Controller may process:
- data relating to the customer's contact persons;
- contact details of experts and subcontractors;
- personal data contained in test reports;
- details of regulatory and laboratory contact persons;
- project communications;
- signatures;
- contractual and financial data.
The purpose of the processing is to prepare, coordinate and document the project, maintain regulatory and professional contacts and perform the contract.
For an individual customer, the legal basis is the performance of a contract; for business contact persons, it is the legitimate interest of the Controller and the customer.
The data are retained for five years after completion of the project, unless legislation, a regulatory procedure, a product-documentation obligation or the individual contract requires a longer retention period.
16. Market Research, Business Development and Professional Networking
In the course of its business market research and networking activities, the Controller may process publicly available business contact details of companies, institutions and sole proprietors.
Purpose of the Processing
- to identify potential professional partners;
- to initiate business cooperation;
- to map market participants and professional opportunities;
- to make personalised B2B contact.
Data Processed
- name;
- position;
- company name;
- business email address;
- business telephone number;
- publicly available professional information;
- data relating to contact and responses.
Legal Basis
The legal basis is the Controller's legitimate interest in presenting its services, professional networking and business development under Article 6(1)(f) of the GDPR.
The Controller makes contact in a targeted manner, in relation to the data subject's professional role, and respects any objection raised by the data subject.
Retention Period
If the data subject does not respond or indicates that they do not wish to remain in contact, the Controller deletes the data within no more than one year, except for the minimum suppression data necessary to prevent further contact.
17. Webinars, Professional Events and Consultation Appointments
17.1. Purpose of the Processing
- to record the registration;
- to confirm eligibility to participate;
- to process payment and invoicing;
- to provide information relating to the event;
- to provide technical access;
- to issue a certificate of participation, where applicable;
- to send professional materials.
17.2. Categories of Data Processed
- name;
- email address;
- telephone number;
- company name;
- billing data;
- registration and payment data;
- participation data;
- questions and comments submitted during the event.
17.3. Legal Basis
The legal basis is the performance of a contract under Article 6(1)(b) of the GDPR.
17.4. Recordings
If an audio, image or video recording is made of the event, the Controller provides separate information before the event.
The image or voice of an individually identifiable participant may be used for marketing purposes only on an appropriate legal basis.
17.5. Retention Period
The Controller retains participation and contractual data for five years and billing data for eight years.
The retention period for recordings is specified in the separate notice relating to the event.
18. Newsletters and Direct Marketing Communications
18.1. Purpose of the Processing
- to send professional newsletters;
- to share agricultural, biotechnology, sustainability and ESG content;
- to provide information about webinars and events;
- to present Green Compass services and offers.
18.2. Categories of Data Processed
- name, where provided by the data subject;
- email address;
- date and time of subscription;
- consent statement;
- IP address and log data necessary to provide technical evidence of consent;
- date and time of unsubscribing.
18.3. Legal Basis for the Processing
The legal basis is the data subject's freely given, specific, informed and unambiguous consent under Article 6(1)(a) of the GDPR.
Subscription to the newsletter is not a condition for using any other service.
18.4. Withdrawal of Consent
The data subject may withdraw consent at any time, without giving a reason and free of charge:
- using the unsubscribe link at the bottom of each newsletter;
- or by sending a message to info@greencompass.hu.
18.5. Retention Period
The Controller processes the data required for newsletter distribution until consent is withdrawn.
The Controller may retain the minimum data evidencing the giving and withdrawal of consent for a period aligned with the enforceability of legal claims, for no longer than five years.
An unsubscribed email address may be retained in a restricted suppression list to ensure that no further newsletters are sent to it.
19. Complaint Handling and Customer Service
19.1. Purpose of the Processing
- to investigate complaints and objections;
- to respond to customer enquiries;
- to resolve contractual disputes;
- to comply with consumer protection obligations;
- to establish, exercise or defend legal claims.
19.2. Categories of Data Processed
- name;
- contact details;
- order or contractual data;
- content of the complaint or enquiry;
- documents necessary to investigate the matter;
- responses and measures taken;
- dates and times of case handling.
19.3. Legal Basis
The legal basis is compliance with the Controller's legal obligations, the performance of the contract and the legitimate interest in managing legal claims.
19.4. Retention Period
The Controller retains complaint-handling documents for the period prescribed by the applicable legislation or, in the absence of such a prescribed period, for five years after the matter has been closed.
20. Processors and Recipients
The Controller may engage processors and other service providers to operate and provide its services.
Recipients or categories of recipients of personal data include in particular:
Website, Hosting and Online Store
Webnode AG
Badenerstrasse 47, 8004 Zurich, Switzerland
Function: provision of the website, hosting, online store, forms and technical infrastructure.
Web Analytics
Google Ireland Limited
Gordon House, Barrow Street, Dublin 4, Ireland
Function: provision of Google Analytics, solely where the visitor has given consent.
Accounting and Taxation
The Controller's current accounting and tax advisory service provider may access personal data to the extent necessary to perform accounting and tax-related tasks.
Invoicing Software
The provider of the invoicing software used by the Controller may process personal data for the purposes of issuing, transmitting and retaining invoices.
Payment Service Providers and Banks
Banks and payment service providers involved in bank transfers, online payments and financial transactions may process transaction data in accordance with their own privacy terms.
Email and Cloud Service Providers
The Controller's email service provider and any document storage or cloud service provider used by it may access data to the extent necessary to provide the relevant technical service.
Professional Subcontractors
The Controller may engage an expert, laboratory, consultant or other professional subcontractor where this is necessary to perform the service.
Subcontractors may access only the data necessary to perform their tasks and are subject to contractual confidentiality and data protection obligations.
Authorities and Courts
The Controller may disclose personal data to a court, public prosecutor, investigative authority, tax authority, consumer protection authority, data protection authority or other authorised body where disclosure is required by law or by a binding official request.
In such cases, the Controller discloses only the data necessary for the purpose of the request and only to the extent required.
21. Transfers Outside the European Economic Area
Webnode AG is a service provider established in Switzerland. Switzerland is a country outside the European Economic Area whose level of data protection has been recognised as adequate by the European Commission.
In connection with services provided by Google and other international technology providers, personal data may be transferred to, or accessed from, a country outside the European Economic Area, in particular the United States of America.
Such transfers may take place only under the conditions set out in Chapter V of the GDPR, in particular on the basis of:
- an adequacy decision adopted by the European Commission;
- the EU-US Data Privacy Framework;
- standard contractual clauses adopted by the European Commission;
- or another appropriate safeguard recognised by law.
The data subject may request further information about the safeguards applied to international data transfers by contacting the Controller.
22. Automated Decision-Making and Profiling
The Controller does not make decisions based solely on automated processing that produce legal effects concerning the data subject or similarly significantly affect them.
The Controller does not carry out profiling for such purposes.
Web analytics or marketing systems may perform technical categorisation where the data subject has consented to it; however, this does not in itself result in an automated decision made by the Controller that produces legal effects.
23. Special Categories of Personal Data
As a general rule, the Controller does not request or intend to process special categories of personal data under Article 9 of the GDPR for the performance of its services, including in particular health, biometric, genetic, political, religious or trade-union-related data.
Data subjects are requested to provide such data only where this is strictly necessary and an appropriate legal basis exists for processing them.
24. Data Security
The Controller implements technical and organisational measures appropriate to the risks of the processing in order to protect personal data.
The purposes of these measures include in particular:
- preventing unauthorised access;
- ensuring confidentiality;
- preserving the integrity of the data;
- ensuring the availability of the data;
- reducing the risk of loss, destruction or unauthorised alteration of the data;
- detecting and managing personal data breaches.
The Controller may apply in particular the following measures:
- password-protected access;
- access-rights management;
- backups;
- up-to-date IT equipment and software;
- virus and malware protection;
- confidentiality obligations;
- secure document storage;
- regular review of access rights;
- data minimisation.
The Controller does not provide an unlimited guarantee of data security but applies reasonable and appropriate protective measures proportionate to the risks associated with processing personal data.
25. Personal Data Breaches
A personal data breach is a breach of security leading to the following in relation to personal data transmitted, stored or otherwise processed:
- accidental or unlawful destruction;
- loss;
- alteration;
- unauthorised disclosure;
- or unauthorised access.
The Controller investigates and documents personal data breaches and, where necessary, makes the notification to the supervisory authority and communicates the breach to the affected data subjects as required by the GDPR.
26. Rights of the Data Subject
The data subject may exercise the following rights in relation to the processing of personal data.
26.1. Right to Information
The data subject has the right to receive clear and easily understandable information about the processing of their personal data.
26.2. Right of Access
The data subject may request confirmation as to whether the Controller processes their personal data and may request access to:
- the personal data being processed;
- the purposes of the processing;
- the categories of data processed;
- the recipients;
- the retention period;
- the source of the data;
- information concerning the rights of the data subject;
- the safeguards applied to any international data transfers.
26.3. Right to Rectification
The data subject may request the rectification of inaccurate personal data and the completion of incomplete data.
26.4. Right to Erasure
The data subject may request the erasure of their personal data, in particular where:
- the purpose of the processing has ceased to exist;
- the data subject has withdrawn consent and there is no other legal basis for the processing;
- the data subject has validly objected to the processing;
- the processing is unlawful;
- erasure is required by law.
The right to erasure does not apply, among other cases, where the processing is necessary:
- for compliance with a legal obligation;
- for the establishment, exercise or defence of legal claims;
- or for another reason specified in the GDPR.
26.5. Right to Restriction of Processing
The data subject may request restriction of processing where:
- the accuracy of the data is contested;
- the processing is unlawful but the data subject opposes erasure;
- the Controller no longer needs the data, but the data subject requires them for a legal claim;
- the data subject has objected to the processing and the assessment of that objection is still pending.
26.6. Right to Data Portability
The data subject has the right to receive personal data provided by them in a structured, commonly used and machine-readable format where the processing:
- is based on consent or a contract;
- and is carried out by automated means.
The data subject may also request that the data be transmitted to another controller where this is technically feasible.
26.7. Right to Object
The data subject may object at any time, on grounds relating to their particular situation, to processing based on legitimate interests.
Where an objection is raised, the Controller shall no longer process the data unless it demonstrates compelling legitimate grounds for the processing that override the rights of the data subject, or unless the processing is necessary for legal claims.
The data subject may object at any time and without giving reasons to processing for direct marketing purposes. In such a case, the Controller shall no longer process the data for that purpose.
26.8. Withdrawal of Consent
Where processing is based on consent, the data subject may withdraw that consent at any time.
Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
26.9. Rights Relating to Automated Decision-Making
The data subject has the right not to be subject to a decision based solely on automated processing that produces legal effects concerning them or similarly significantly affects them, except in the cases specified in the GDPR.
27. Submission and Handling of Data Subject Requests
The data subject may submit a request using the following contact details:
Email: info@greencompass.hu
Postal address: 27 Rákóczi Ferenc Street, 9764 Csempeszkopács, Hungary
The Controller responds to the request without undue delay and no later than one month after receipt.
Where necessary, taking into account the complexity and number of requests, this period may be extended by a further two months. The Controller informs the data subject of any extension within one month of receipt of the request.
Requests are generally handled free of charge.
Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, the Controller may charge a reasonable fee or refuse to act on the request.
Where necessary and proportionate, the Controller may request additional information to verify the identity of the data subject.
28. Remedies and Complaints
28.1. Complaint to the Controller
The data subject may first contact the Controller using the following details:
Email: info@greencompass.hu
Postal address: 27 Rákóczi Ferenc Street, 9764 Csempeszkopács, Hungary
28.2. Complaint to the Supervisory Authority
The data subject may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information.
Hungarian National Authority for Data Protection and Freedom of Information
Registered office: 9-11 Falk Miksa Street, 1055 Budapest, Hungary
Postal address: PO Box 9, 1363 Budapest, Hungary
Email: ugyfelszolgalat@naih.hu
Telephone: +36 1 391 1400
Website: naih.hu
28.3. Judicial Remedies
The data subject has the right to bring court proceedings where they consider that the processing of their personal data infringes the GDPR or other data protection legislation.
At the data subject's choice, proceedings may also be brought before the court having jurisdiction at the Controller's registered office or at the data subject's place of residence or habitual residence.
29. Amendments to this Notice
The Controller may amend this Privacy Notice, in particular in the event of:
- changes in legislation;
- changes in the practice of competent authorities;
- the introduction of a new service;
- the engagement of a new processor;
- changes to the operation of the website or online store;
- changes to data processing activities.
The version of this Notice currently in force is available on the greencompass.hu website.
The Controller informs data subjects of material changes in a manner appropriate to the circumstances, for example through a notice published on the website or a direct electronic message.
30. Final Provisions
Where a new processing activity is not described in this Notice, the Controller provides appropriate supplementary information before the processing begins or at the time the data are collected.
This Privacy Notice enters into force on 27 July 2026.