Privacy and Data Protection Policy

The protection of personal data is of paramount importance to VIRGO Systems Kft. This Privacy Policy explains the types of personal data that we process as a data controller as well as data processor when providing IT development and capacity enhancement services to our clients, the purpose and legal basis of such processing operations, and the organizational and technical measures we implement to comply with data protection regulations.

This policy applies to all data processing activities conducted by VIRGO Systems Kft. in its capacity as a data controller and/or data processor for clients who engage our IT services, as the case may be.

The policy also sets out the data protection rights that natural persons (data subjects) are entitled to exercise.

1. Data Controller

Data Processor: VIRGO Systems Kft.
Registered seat and mailing address: H-1055 Budapest, Szent István Boulevard. 17. 1. floor 6.
Registration authority: Company Registry Court of Budapest
Company registration number: 01-09-391374
Tax number: 12497278-2-41
E-mail address: info@virgo.hu
Website: https://virgo.hu/

VIRGO Systems Kft. acts as a data controller whenever it will independently determine the means and purposes of any data processing operations, such as recruitment processes, HR processes, engaging the services of suppliers etc.
VIRGO Systems Kft. acts as a data processor when providing IT services to clients. Our clients, who determine the purposes and means of personal data processing, act as data controllers. We process personal data (access/edit/transmit etc.) solely on behalf of and according to the documented instructions of our clients. We mostly interact with client personal data exclusively in client IT environments, though services might be provided remotely.

2. Main Legislation Relating to Data Processing

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons concerning the processing of personal data and on the free movement of such data (General Data Protection Regulation – GDPR)
  • Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (Privacy Act)
  • Act I of 2012 on the Labour Code (Labour Code)
  • Act V of 2013 on the Civil Code (Civil Code)

3. Data Processing as Processor for Client Services

3.1. Purpose of Data Processing

VIRGO Systems Kft. processes personal data exclusively as instructed by our clients for the following purposes:

  • Providing IT development services and software solutions
  • Capacity enhancement and technical support services
  • System maintenance, testing, and quality assurance
  • Technical implementation of client business processes
  • Data migration, integration, and transformation services

The specific purposes of processing are determined by each client (data controller) in accordance with their business needs and legal obligations. We do not process personal data for our own purposes beyond what is necessary to fulfill our contractual obligations.

3.2. Categories of Personal Data Processed

The categories of personal data we may process on behalf of clients include, but are not limited to:

  • Identification data (name, employee ID, customer reference numbers)
  • Contact information (email address, phone number, business address)
  • Professional information (job title, department, organizational unit)
  • Technical data (system access logs, user credentials, IP addresses)
  • Transaction data related to client business processes
  • Any other personal data categories as specified in client data processing agreements

The exact scope of personal data processed depends on the specific services provided to each client and is documented in our data processing agreements.

3.3. Legal Basis of Data Processing

The legal basis for our data processing activities as a processor is:

  • Article 28 GDPR – Processing by a processor on behalf of a controller
  • Contractual agreements with our clients that define the scope, nature, purpose, and duration of processing
  • Legitimate instructions from data controllers regarding the processing of personal data

We process personal data only in accordance with documented instructions from our clients and do not process data for any other purpose without prior written authorization.

3.4. Duration of Data Processing

We process personal data for the duration specified in our agreements with clients, which typically includes:

  • The term of the service agreement with the client
  • Any additional retention period required by applicable law or contractual obligations
  • Until the client instructs us to delete or return the personal data

4. Recruitment and Employment Data Processing

4.1. Purpose of Recruitment Data Processing

VIRGO Systems Kft. processes personal data of job applicants for the purpose of:

  • Evaluating candidates for employment positions
  • Conducting recruitment and selection processes
  • Communicating with applicants regarding job opportunities
  • Maintaining a talent pool for future opportunities

4.2. Scope of Recruitment Data

The following data are processed for recruitment purposes:

  • Identification data (name, date and place of birth)
  • Contact information (phone number, email address, postal address)
  • Professional information (educational background, work experience, skills, certifications, language proficiency, references, project portfolio)
  • Application materials (CV, cover letter, professional profiles on social media platforms)

Applicants may provide additional information during the recruitment process, such as availability, salary expectations, and other relevant details. All such information is processed in accordance with this policy.

4.3. Legal Basis for Recruitment Processing

The legal basis for processing applicant data is the consent of the applicant, provided by:

  • Submitting an application for employment
  • Providing consent during the application process
  • Agreeing to this Privacy Policy

Consent may be withdrawn at any time by contacting us using the details provided in Section 1. Withdrawal of consent will result in the deletion of the applicant’s data and cessation of recruitment services for that individual.

4.4. Retention Period for Recruitment Data

Recruitment data is retained:

  • Until the applicant withdraws consent, or
  • For a maximum of 2 years from the date of consent

After 2 years, if the applicant does not renew their consent, all personal data will be permanently deleted. Applicants may withdraw consent at any time, which will result in immediate deletion of their data (see Section 8).

4.5. Source of Recruitment Data

Personal data of applicants may be received:

  • Directly from the applicant
  • Through recruitment agencies or employment platforms (acting as independent data controllers)
  • Via referrals from natural persons

When data is received through third-party intermediaries, we presume that the applicant has been informed of the data transfer and has consented to the processing in accordance with this Privacy Policy. Third-party recruitment agencies are independent data controllers responsible for their own compliance with data protection legislation.

5. Data Processing Methods and Systems

Personal data is processed using secure electronic systems and software platforms. For recruitment activities, we utilize Zoho Recruit (hiring software platform). Information about Zoho’s data protection and security principles can be found at: Zoho Data Privacy (https://www.zoho.com/privacy.html) and Zoho Recruit GDPR Guide (https://www.zoho.com/recruit/gdpr.html).
For client services, we employ industry-standard development tools, secure cloud infrastructure, and encrypted communication channels. All processing systems are regularly updated and monitored for security compliance.

6. Data Transmission and Disclosure

6.1. Data Transmission for Client Services

Personal data processed on behalf of clients may be transmitted:

  • To clients (data controllers) as part of our contractual service delivery
  • To sub-processors only with prior written authorization from the client and under appropriate data processing agreements
  • To authorities, courts, or other public entities when required by law, while notifying the controller, if permitted by law.

We maintain a register of all sub-processors and notify clients of any intended changes to sub-processors, allowing them to object to such changes.

7. Data Security Measures

VIRGO Systems Kft. implements comprehensive security measures to protect personal data from unauthorized access, alteration, disclosure, or destruction:

  • Technical measures
    Encryption of data in transit and at rest, secure authentication mechanisms, access controls, firewall protection, intrusion detection systems, regular security updates and patches
  • Organizational measures
    Data protection policies and procedures, employee training on data protection, confidentiality agreements, incident response procedures, regular security audits and assessments
  • Personnel measures
    Background checks for employees with data access, role-based access controls, logging and monitoring of data access activities, mandatory data protection training

Access to personal data is restricted to authorized personnel who require such access to perform their job functions. All access is logged and can be audited to verify who accessed which data and when.
We implement appropriate measures to ensure a level of security appropriate to the risk, including protection against unauthorized or unlawful processing, accidental loss, destruction, or damage.

8. Rights of Data Subjects

Data subjects whose personal data we process have the following rights under the GDPR. These rights can be exercised by contacting us using the details provided in Section 1.

8.1. Right to Access and Information

Data subjects have the right to request information about:

  • The categories of personal data being processed
  • The purposes of processing
  • The legal basis for processing
  • The source of the data
  • The retention period
  • The recipients or categories of recipients to whom data has been or will be disclosed
  • Information about data transfers to third countries or international organizations

We will respond to access requests within one month of receipt. If the request is complex or numerous, we may extend this period by two additional months, informing the data subject of such extension.
If the exercise of the right to access adversely affects the rights and freedoms of others (such as business secrets or intellectual property), we may refuse the request to the necessary and proportionate extent.

8.2. Right to Rectification

Data subjects may request the correction of inaccurate personal data or the completion of incomplete data. We will respond to such requests within one month and notify the data subject of the outcome.
We will inform any recipients to whom the data has been disclosed about the rectification, unless this proves impossible or requires disproportionate effort.

8.3. Right to Erasure (Right to be Forgotten)

Data subjects may request the deletion of their personal data. We will comply with such requests unless legal obligations require continued storage of the data.
We will respond to erasure requests within one month and inform the data subject of the outcome. We will also notify any recipients to whom the data has been disclosed about the erasure, unless this proves impossible or requires disproportionate effort.

8.4. Right to Restriction of Processing

Data subjects may request restriction of processing when:

  • The data subject contests the accuracy of the data (during verification)
  • The processing is unlawful, but the data subject opposes erasure and requests restriction instead
  • We no longer need the data, but the data subject requires it for legal claims
  • The data subject has objected to processing (pending verification of whether our legitimate grounds override those of the data subject)

When processing is restricted, data will be stored but not processed further (except with the data subject’s consent or for legal claims). We will inform the data subject before lifting any restriction.

8.5. Right to Object

Data subjects may object to processing of their personal data for purposes other than those specified in our agreements or this policy, particularly for direct marketing purposes.
We will assess objections within one month and cease processing unless we can demonstrate compelling legitimate grounds that override the interests, rights, and freedoms of the data subject.

8.6. Right to Data Portability

Where processing is based on consent or contract and is carried out by automated means, data subjects have the right to receive their personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.

8.7. Right to Withdraw Consent

Where processing is based on consent, data subjects have the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
For recruitment data, withdrawal of consent will result in deletion of all personal data and cessation of recruitment services.

9. Automated Decision-Making

VIRGO Systems Kft. does not engage in automated decision-making or profiling that produces legal effects or similarly significantly affects data subjects. Any processing involving automated tools is subject to human oversight and review.

10. Data Protection Officer

While VIRGO Systems Kft. is not legally required to appoint a Data Protection Officer, we have designated internal personnel responsible for data protection compliance. Data subjects and controllers may contact us using the details in Section 1 for any data protection inquiries.

11. International Data Transfers

Personal data may be transferred to or accessed from countries outside the European Economic Area (EEA). Such transfers are conducted in accordance with Chapter V of the GDPR and only when:

  1. The European Commission has determined that the third country ensures an adequate level of protection, or
  2. Appropriate safeguards are in place (such as Standard Contractual Clauses approved by the European Commission), or
  3. The data subject has explicitly consented to the transfer after being informed of the possible risks.

We ensure that all international data transfers comply with applicable data protection laws and that appropriate safeguards are implemented to protect personal data.

12. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of data subjects, we will:

  1. Notify the relevant client (data controller) without undue delay and, where feasible, within 72 hours of becoming aware of the breach
  2. Provide all necessary information to enable the client to fulfill their notification obligations to supervisory authorities and affected data subjects
  3. Cooperate fully with the client in investigating and mitigating the breach

We maintain documented procedures for detecting, reporting, and investigating personal data breaches.

13. Cooperation with Supervisory Authorities

VIRGO Systems Kft. cooperates with supervisory authorities and makes available all information necessary to demonstrate compliance with data protection obligations. We assist clients in responding to requests from supervisory authorities concerning processing activities.

14. Legal Remedies and Enforcement

If data subjects believe their rights have been violated, they may:

  1. Contact us directly using the details in Section 1 to resolve the matter
  2. Lodge a complaint with the competent supervisory authority: Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
    Address: H-1055 Budapest, Falk Miksa utca 9-11.
    Postal address: H-1363 Budapest, Pf. 9.
    Phone: +36 (1) 391-1400
    Website: www.naih.hu
    Email: ugyfelszolgalat@naih.hu
  3. Initiate judicial proceedings before a competent court. Actions may be brought before the regional court (törvényszék) having jurisdiction over the data subject’s domicile. Contact information for regional courts: https://birosag.hu/torvenyszekek

15. Cookie Policy

15.1. What are Cookies and Web Beacons?

A cookie is a small data file consisting of letters and numbers that a web server automatically sends to a visitor’s browser upon first loading a website. The visitor’s computer or mobile device stores the cookie for a period defined by the entity placing the cookie. When the visitor returns to the website, the browser sends the cookie back to the web server, allowing the server to identify the device and connect cookies sent by the same device.
A web beacon is a small, often invisible image placed on a website that provides statistical data about visitor movements on the site.
VIRGO Systems Kft. uses cookies and web beacons on our website to recognize returning visitors, monitor visitor interests, improve user experience, display personalized content, and enhance website security.

15.2. Legal Basis and Purposes

The purposes of cookie processing are:

  • To identify and differentiate users
  • To identify users’ active sessions
  • To store data shared by users and prevent data loss
  • To ensure basic website functionality

The legal basis for cookie processing is user consent, which can be managed or withdrawn at any time through browser settings.

15.3. Types of Data Processed and Retention

Cookie processing includes personal identification numbers, session identifiers, timestamps, and usage statistics. All visitors and users of the website are subject to cookie processing.

The following table describes the cookies used on our website:

Cookie Types and Retention Periods

  1. Cookie Name: SESS#
    Purpose: Session cookie required to display the site and ensure basic functionalities
    Expiration: Session
  2. Cookie Name: _ga
    Purpose: Unique measuring code that generates statistical data on website usage
    Expiration: 2 years
  3. Cookie Name: _gat
    Purpose: Google Analytics measuring code accelerator
    Expiration: Session
  4. Cookie Name: _gid
    Purpose: Unique measuring code that generates statistical data on website usage
    Expiration: 1 day
  5. Cookie Name: collect
    Purpose: Sends visitor device data to Google Analytics
    Expiration: Session
  6. Cookie Name: pll_language
    Purpose: Stores language preference
    Expiration: 1 year

15.4. Recipients of Cookie Data

Regarding cookie data:

  • We do not use automated decision-making based on cookie data
  • We do not collect personal data about visitors from third parties
  • Cookie data is processed by authorized employees of VIRGO Systems Kft.
  • Some cookies are placed by third-party services (e.g., Google Analytics) subject to their own privacy policies

15.5. Managing Cookie Preferences

Users can manage or delete cookies through their browser settings. Please note that disabling certain cookies may affect website functionality. Instructions for managing cookies can be found in your browser’s help documentation.

16. Updates to this Privacy Policy

VIRGO Systems Kft. reserves the right to update this Privacy Policy to reflect changes in:

  • Applicable legislation or regulatory guidance
    Data protection authority practices
    Business needs or service offerings
    Identified security risks or best practices

The current version of this Privacy Policy is always available on our website. Material changes will be communicated to affected parties through appropriate channels.
Last updated: 07/08/2026