Privacy notice

Effective: 20 September 2026

Bremotech Kft. (hereinafter: the Controller) considers the protection of personal data to be of particular importance. The purpose of this privacy notice is to give data subjects adequate information about what personal data Bremotech Kft. processes, for what purpose, on what legal basis and for how long.

In its processing, the Controller takes into account in particular Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and the applicable Hungarian data protection legislation. The principles and legal bases of the GDPR are set out, among other places, in Articles 5 and 6 of the Regulation.

1. DETAILS OF THE CONTROLLER

Name of the Controller: Bremotech Korlátolt Felelősségű Társaság
Short name: Bremotech Kft.
Registered office: 1044 Budapest, Ezred utca 7, building 2, ground floor 4.
Company registration number: 01-09-289943
Tax number: 25802397-2-41
Representative: Dr. Horváth Alpár Zsolt
Email:bremotech@gmail.com

Phone: +36 70 248 7997
Website: bremotech.hu

2. THE NAME “INNOMEDIC RESEARCH CENTRE”

In connection with its activities, Bremotech Kft. uses the name “Innomedic Research Centre”. For the purposes of this privacy notice, “Innomedic Research Centre” is not a separate legal person, not a separate company and not an independent controller. Bremotech Kft., as controller, is in every case responsible for processing carried out under the name “Innomedic Research Centre”.

3. PROCESSING RELATED TO USE OF THE WEBSITE

While the website is used, certain technical data may be generated automatically, and the web server may process the technical information required for operation.

Such data may include in particular:

  • IP address;
  • the time of the visit;
  • the pages viewed;
  • technical information about the browser and the operating system;
  • log data related to the operation of the website;
  • data of technical and security events.

Purpose of the processing:

  • operation of the website;
  • ensuring information security;
  • identifying and remedying faults;
  • detecting and investigating abuse and attacks;
  • ensuring the performance and operation of the website.

Legal basis: the legitimate interest of the Controller, point (f) of Article 6(1) GDPR, or, where the processing of certain data is required by law, point (c) of Article 6(1) GDPR. The Controller processes technical data only for the time necessary to achieve the purpose, taking information-security and legal considerations into account.

4. CONTACT FORM

A contact form operates on the website.

The following data may be provided on the form:

  • name;
  • company or institution name;
  • email address;
  • telephone number;
  • subject of the enquiry;
  • further data voluntarily provided by the data subject in the message.

On the website, name and email address are required, while company name, telephone number and other data may be processed depending on the nature of the enquiry.

Purpose of the processing:

  • making contact;
  • answering an enquiry;
  • professional consultation;
  • handling a request for a quotation or a cooperation opportunity;
  • further communication with the data subject.

Legal basis: legitimate interest under point (f) of Article 6(1) GDPR, or, where the enquiry relates to steps prior to entering into a contract, point (b) of Article 6(1) GDPR.

The Controller processes the data until the enquiry and the matter arising from it are closed, and thereafter retains them only if further retention is required by law or on another demonstrable legitimate interest.

5. ENQUIRIES BY EMAIL AND TELEPHONE

Enquiries may also be sent to the Controller by email or telephone.

In the case of contact by email or telephone, the Controller may process the data provided by the data subject or becoming necessary during the communication, in particular:

  • name;
  • email address;
  • telephone number;
  • job title or organisation;
  • the content of the enquiry;
  • further data necessary for handling the matter.

The purpose of the processing is to handle and answer the enquiry, to maintain the business or professional relationship, and to prepare a possible contract.

Depending on the nature of the matter, the legal basis may be point (b), (c) or (f) of Article 6(1) GDPR.

6. DATA OF BUSINESS AND CONTRACTUAL CONTACTS

In its relationships with business partners, suppliers, customers and other contractual partners, the Controller may process the data of natural persons acting as contact persons.

This may include in particular:

  • name;
  • job title;
  • company email address;
  • company telephone number;
  • other information necessary for the working relationship.

Purpose: maintaining contractual and business relationships, preparing and performing contracts, and ensuring business communication.

Legal basis: point (b), (c) or (f) of Article 6(1) GDPR, depending on the circumstances of the processing.

7. PROCESSING RELATED TO INVOICING, ACCOUNTING AND LEGAL OBLIGATIONS

The Controller may also process personal data in order to fulfil its accounting, tax, employment-law and other statutory obligations.

The processing may cover, among other things:

  • invoicing data;
  • contractual data;
  • data of natural-person business partners;
  • data of contact persons;
  • personal data appearing in documents required by law.

Legal basis: compliance with a legal obligation, point (c) of Article 6(1) GDPR.

The Controller processes the data for the retention period prescribed by the applicable legislation.

8. COOKIES

The website uses cookies. Based on the current interface of the website, in addition to strictly necessary cookies the system also offers the visitor the use of cookies for web analytics and personalised advertising.

Strictly necessary cookies are required for the website to function.

The website uses analytics, statistics and advertising cookies only on the basis of the visitor’s prior consent, where the applicable legislation requires consent for the use of the cookie in question.

The visitor may change or withdraw consent to cookies that are not strictly necessary at any time in the cookie settings.

9. WEB HOSTING AND TECHNICAL OPERATION

NeoSoft Informatikai Szolgáltató Kft. takes part in the technical operation and hosting of the website.

NeoSoft Kft. provides web hosting and server operation services.

NeoSoft Informatikai Szolgáltató Kft.

Registered office: 8000 Székesfehérvár, Távírda utca 2/A
Company registration number: 07-09-010206
Tax number: 13235109-2-07
Email: info@neosoft.hu
Phone: +36 22 503 603.

Where, in the course of hosting or server operation, NeoSoft Kft. can access personal data processed by Bremotech Kft. or processes them on behalf of Bremotech Kft., NeoSoft Kft. acts as a processor.

The processor may carry out its activity only on the instructions of the Controller and in compliance with the applicable data protection and data security requirements.

10. CCTV SURVEILLANCE

A camera surveillance system operates at the registered office of Bremotech Kft.

The image recording made by the camera system may qualify as personal data, so the provisions of the GDPR apply to its processing. In the case of camera processing, the NAIH particularly emphasises purpose limitation, necessity, proportionality, an appropriate retention period, and the importance of a balancing test where the legal basis is legitimate interest.

Purpose of camera processing

The purpose of the camera system is in particular:

  • protection of persons and property;
  • prevention and subsequent investigation of unauthorised entry;
  • prevention and investigation of acts against property;
  • documentation of security incidents;
  • clarifying the circumstances of possible damage or unlawful conduct.

The camera system must not be used for general, purposeless or disproportionate monitoring of employee performance.

Legal basis

The legal basis of camera processing may be legitimate interest under point (f) of Article 6(1) GDPR, provided that the Controller has properly weighed the legitimate interest, the necessity of the processing and the fundamental rights of data subjects.

Information

In areas monitored by cameras, information about camera surveillance must be provided to data subjects in a clearly visible manner.

The Controller may also set out the detailed rules of camera processing — in particular the exact location and field of view of the cameras, the retention period of the recordings, the persons authorised to access them and the rules of data transfer — in a separate camera processing policy.

11. RESEARCH, CLINICAL AND HEALTHCARE PROJECTS

Based on its website, Bremotech Kft. also carries out research and development, clinical investigation, device validation and health-industry activities.

In the course of such projects, personal data and, in certain cases, special categories of personal data, such as health data, may also be processed.

The general provisions of this notice do not automatically apply to such processing. The data-processing terms, legal basis, controller/processor roles, retention period and information for data subjects of the given research or clinical project must be determined on the basis of the specific project.

Where Bremotech Kft. acts in a project as a processor or as a joint controller on behalf of another organisation, the documentation of that project contains the detailed rules.

12. PROCESSORS AND DATA TRANSFERS

The Controller may use processors for individual processing tasks, for example:

  • hosting and server operator;
  • IT service provider;
  • accountant or accounting service provider;
  • legal service provider;
  • other professional service provider necessary for the performance of the given service.

Processors may access personal data only to the extent necessary to achieve the purpose of the processing.

13. TRANSFER TO A THIRD COUNTRY

The Controller aims to process personal data within the European Economic Area.

If, because of the use of a service provider, personal data are transferred to a third country, the Controller carries out or permits such a transfer only if the conditions set out in Chapter V of the GDPR are met.

14. DATA SECURITY

The Controller applies appropriate technical and organisational measures to protect personal data.

The measures aim, among other things, to:

  • prevent unauthorised access;
  • prevent unauthorised alteration or erasure of the data;
  • reduce the risk of data loss and data damage;
  • maintain the security of the IT systems;
  • restrict access according to authorisation.

15. RIGHTS OF DATA SUBJECTS

Under the GDPR, data subjects have, among others, the following rights:

  • the right to be informed and the right of access;
  • the right to rectification;
  • the right to erasure;
  • the right to restriction of processing;
  • the right to data portability, where the conditions are met;
  • the right to object to processing based on legitimate interest;
  • where processing is based on consent, the right to withdraw consent.

The data subject may submit a request through the Controller’s contact details.

As a general rule, the Controller handles the request within the time limit set by the GDPR, without undue delay.

16. REMEDIES

If the data subject considers that the processing of their personal data infringes the GDPR or other applicable data protection legislation, they may lodge a complaint with the supervisory authority.

In Hungary the supervisory authority is:

National Authority for Data Protection and Freedom of Information (NAIH)
1055 Budapest, Falk Miksa utca 9–11.
Postal address: 1363 Budapest, Pf. 9.
Email: ugyfelszolgalat@naih.hu
Phone: +36 (1) 391 1400.

The data subject may also bring the matter before a court under the conditions set out in the GDPR.

17. AMENDMENT OF THE PRIVACY NOTICE

The Controller reserves the right to amend this privacy notice, in particular in the event of a change in legislation, a change in the practice of the authorities, the introduction of a new service or a change in the processing operations.

The privacy notice in force at any time is available on the website of Bremotech Kft.