Privacy Policy
Effective: 13 June 2026
Version 1.3 - Google Analytics processor clarification
This Privacy Policy explains how Avenir Facility Management Kft. processes the personal data provided through the www.afm.hu website, in particular during the contact and quote-request process. Its purpose is to provide data subjects with concise, transparent, intelligible and easily accessible information about the processing.
The scope of this Policy covers the contact and quote-request process on the www.afm.hu website and the contractual administration following a successful quote request. Other processing activities of the Controller - in particular CCTV monitoring at client sites, private investigation activity, employee data processing and data processing carried out in client projects - are governed by separate privacy notices. These are available on request at info@afm.hu, and on-site notices are available at the relevant service locations.
Authoritative language: the authoritative version of this Policy is the Hungarian text published at https://www.afm.hu/hu/adatvedelem. The English version is provided for the convenience of non-Hungarian-speaking readers; in the event of any discrepancy between language versions, the Hungarian text prevails.
1. Controller
Controller: Avenir Facility Management Kft.
Legal name: Avenir Facility Management Szolgáltató Korlátolt Felelősségű Társaság
Registered office: Királyok útja 291, building B, door 15, 1039 Budapest, Hungary
Company registration number: 01-09-328046
Company court: Court of Registration of the Budapest-Capital Regional Court (1051 Budapest, Nádor u. 28., Hungary)
Tax ID: 26395124-2-41
EU VAT ID: HU26395124
Date of incorporation: 31 July 2018
Email: info@afm.hu
Phone: +36 70 316 8218
Website: https://www.afm.hu
2. The Controller's Representative
Representative: Attila Kovács, Managing Director
Email: info@afm.hu
Phone: +36 70 312 5868
3. Data Protection Officer (DPO)
The Controller has appointed a Data Protection Officer pursuant to GDPR Article 37(1)(b) and (c).
Data Protection Officer: Fanni Csegény
Email: dpo@afm.hu
Phone: +36 70 622 6242
Postal contact: Királyok útja 291, building B, door 15, 1039 Budapest, Hungary
The Data Protection Officer can be contacted regarding questions relating to data processing and the exercise of data subject rights. Notification to NAIH has been completed pursuant to Section 25/L of the Hungarian Infotv. Remedies are described in a separate section.
5. Exclusion of Special, Criminal and Third-Party Data
Please do not submit special-category data, criminal-offence data, classified data, trade secrets, or detailed private-life information about third parties via the contact form.
The Controller does not request and does not process such data in the website's contact process. If a submitted message contains such data, the Controller may delete the data not necessary for handling the enquiry, or may ask the data subject to resubmit the enquiry without such data.
6. Our Data Processors (GDPR Article 28)
To operate the website and the contact process, the Controller engages data processors. The data processors act on the Controller's instructions. The Controller keeps records of the data-processor terms and the data-transfer safeguards; the data subject may request further information about their content.
6.1. Resend - Plus Five Five, Inc.
Role: transactional email delivery.
Registered office: 2261 Market Street #5039, San Francisco, CA 94114, USA
Place of processing: EU Frankfurt (sending region)
Safeguard for third-country transfer: the Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914, i.e. SCCs, pursuant to GDPR Article 46(2)(d), together with supplementary technical and organisational measures.
6.2. Vercel - Vercel Inc.
Role: hosting, edge/CDN service and server-side logging.
Registered office: 440 N Barranca Avenue #4133, Covina, CA 91723, USA
Place of processing: EU edge regions (configured)
Safeguard for third-country transfer: at the time this Policy was prepared, Vercel Inc. appears on the EU-U.S. Data Privacy Framework list; transfers may therefore take place on the basis of the adequacy decision under GDPR Article 45.
6.3. Neon (an affiliate of Databricks, Inc.) - Neon, LLC
Role: PostgreSQL database service.
Registered office: 160 Spear Street, Suite 1300, San Francisco, CA 94105, USA
Place of processing: EU AWS Frankfurt (eu-central-1)
Safeguard for third-country transfer: the Standard Contractual Clauses under Commission Implementing Decision (EU) 2021/914, i.e. SCCs, pursuant to GDPR Article 46(2)(d), together with supplementary technical and organisational measures.
6.4. Google Analytics 4 (GA4) - Google Ireland Limited / Google LLC
Processor / provider: Google Ireland Limited / Google LLC, as applicable under the contractual and service terms for Google Analytics.
Service: Google Analytics 4 (GA4).
Purpose: consent-based aggregated analysis of website traffic and usage.
Data categories: online identifiers, such as cookie identifiers, IP addresses, device identifiers, client identifiers and technical browsing event data.
Restriction: Avenir does not send names, email addresses, phone numbers, company names, message text or free-text form content to Google Analytics.
Legal basis: GDPR Article 6(1)(a) - consent.
7. International Data Transfers
Some of the service providers engaged to operate the website are located outside the European Economic Area, in particular providers with a U.S. background. In such cases, the Controller transfers personal data only where an appropriate safeguard under the GDPR is available.
Such safeguards may include in particular:
- an adequacy decision of the European Commission, for example under the EU-U.S. Data Privacy Framework;
- the Standard Contractual Clauses (SCCs) adopted by the European Commission;
- supplementary technical and organisational measures.
When Google Analytics is used, data may be transferred to or accessed by Google group entities or subprocessors outside the European Economic Area. According to Google's published information, the Data Privacy Framework and/or Standard Contractual Clauses may be relevant safeguards for such transfers. The applicable safeguards should be assessed based on Google's current data processing terms and transfer frameworks.
For more detailed information on how the EU-U.S. Data Privacy Framework works and on how to verify the certification of U.S. providers, see the information of the European Data Protection Board:
https://www.edpb.europa.eu/system/files/2026-01/edpb_dpf_faq-for-individuals_v2_en.pdf
8. Cookies and Similar Technologies
The website uses analytics cookies or similar technologies only on the basis of the user's consent. Analytics is currently performed using Google Analytics 4 (GA4).
Analytics does not start before consent is given. If analytics is rejected, Google Analytics does not load. Analytics events do not include name, email address, phone number, company name, message text or free-text form content.
Technical solutions necessary for the operation and security of the contact form do not serve advertising-related tracking. The user may change the choice through Cookie settings.
The website currently does not use Google Tag Manager, LinkedIn Insight Tag or other marketing tracking pixels.
9. Rights of the Data Subject (GDPR Articles 12-22)
The data subject may exercise their rights through the contact details provided in this Policy.
Right of access
The data subject has the right to request information from the Controller as to whether their personal data are being processed. If such processing is taking place, they are entitled to know which of their personal data the Controller processes, on what legal basis, for what processing purpose and for how long.
The data subject is further entitled to be informed about: to whom, when, on what legal basis and to which of their personal data the Controller has granted access, or to whom it has transferred the personal data; the source of their personal data; and whether the Controller applies automated decision-making or profiling.
The Controller provides a copy of the personal data undergoing processing free of charge on the first occasion at the data subject's request. For further copies, a reasonable fee based on administrative costs may be charged.
Right to rectification
The data subject may request that the Controller modify or correct a personal datum. If the data subject can credibly demonstrate the accuracy of the corrected data, the Controller fulfils the request within one month at the latest and notifies the data subject accordingly.
Right to restriction of processing (blocking)
The data subject may request that the Controller restrict the processing of their personal data where: they contest the accuracy of the data; the processing is unlawful but the data subject opposes erasure; the Controller no longer needs the data but the data subject requires them for the establishment, exercise or defence of legal claims; or the data subject has objected to the processing, for the period during which it is established whether the Controller's legitimate grounds override those of the data subject.
Right to object
The data subject may object at any time, on grounds relating to their particular situation, to processing based on GDPR Article 6(1)(f). In such a case, the Controller must demonstrate that the processing is justified by compelling legitimate grounds which override the interests, rights and freedoms of the data subject, or that the processing relates to the establishment, exercise or defence of legal claims.
Right to erasure ("right to be forgotten")
The data subject may request the erasure of their personal data where: the data are no longer needed; they have objected to the processing and there is no overriding legitimate ground; the Controller processes the data unlawfully; or the data must be erased under a legal or EU provision.
Right to data portability
Where the legal basis of processing is the performance of a contract or steps taken prior to entering into a contract, and the processing is carried out by automated means, the data subject may request to receive the personal data they have provided in a structured, commonly used, machine-readable format.
Withdrawal of consent
In the contact process, the Controller does not primarily process data on the basis of consent. If any future processing were based on consent, the data subject would be entitled to withdraw it at any time.
10. Automated Decision-Making and Profiling
The Controller does not apply automated decision-making within the meaning of GDPR Article 22, and does not carry out profiling, on the basis of the personal data provided through the website.
11. How to Exercise Your Rights
The Controller responds to data-subject requests without undue delay, but within one month at the latest from receipt of the request. Where necessary, taking into account the complexity and the number of requests, this period may be extended by a further two months. The Controller informs the data subject of any such extension within one month.
In order to meet data-security requirements and to protect the data subject's rights, the Controller is entitled to verify that the request was indeed submitted by the data subject or their authorised representative. If there are reasonable doubts concerning the identity of the data subject, the Controller may request additional information necessary for identification, pursuant to GDPR Article 12(6).
If a request is manifestly unfounded or excessive, in particular due to its repetitive character, the Controller may charge a reasonable fee or refuse to act on the request, pursuant to GDPR Article 12(5).
12. Remedies
For any question or complaint relating to data processing, the data subject may first turn to the Controller or the Data Protection Officer.
Supervisory authority:
National Authority for Data Protection and Freedom of Information (NAIH)
Address: Falk Miksa utca 9-11, 1055 Budapest
Postal address: P.O. Box 9, 1363 Budapest
Phone: +36 1 391 1400
Email: ugyfelszolgalat@naih.hu
Web: https://www.naih.hu
The data subject may also turn to the courts. At the data subject's choice, the action may be brought before the regional court (törvényszék) of their place of residence or stay.
13. Handling of Data Breaches
The Controller records and investigates data breaches and, where necessary, takes the notification and communication steps required by the GDPR.
If the breach is likely to result in a risk to the rights and freedoms of natural persons, the Controller notifies NAIH without undue delay and, where feasible, within 72 hours. If the breach is likely to result in a high risk to data subjects, the Controller also informs the data subjects.
14. Data Security Measures
To ensure the security of processing, the Controller applies in particular the following measures: data minimisation, encrypted data transmission and storage, access restriction, identity and access management, logging, backups, vulnerability management, an incident-handling process, and organisational data-protection and information-security measures.
The Controller holds ISO 9001 and ISO/IEC 27001 certifications, which support documented, controlled and continuously improved operation.
15. Modification of this Policy
The Controller reserves the right to modify this Policy. The version in force at any given time is available at https://www.afm.hu. The Controller provides appropriate notice of any material modification on the website.
Version history: Version 1.3 - Effective from 13 June 2026. Google Analytics 4 processor and transfer clarification; analytics runtime behaviour did not change, and the website still does not use Google Tag Manager, LinkedIn Insight Tag, Google Ads remarketing or other marketing tracking pixels. Version 1.2 - Effective from 1 June 2026. Parity with Hungarian version 1.2; scope clarification; Controller and DPO details added; cookies and analytics wording aligned with consent-gated Google Analytics. Version 1.1 - Effective from 6 May 2026. On the basis of the DPO's comments: processing activities clarified, GDPR references made more intelligible, third-country transfer safeguards and data-subject rights revised. Version 1.0 - Effective from 28 April 2026. First publication.