Plain-language summary: This notice explains what Personal Data Cevolarion collects as an independent Controller, why it is used, how long it is kept, who receives it, how international transfers are protected, and how individuals can exercise their rights. It does not replace a Client's own notice where Cevolarion handles Personal Data only as that Client's Processor.
Purpose and scope
This Privacy Policy and Data Processing Notice (Notice) is issued by Cevolarion Korlátolt Felelősségű Társaság (Cevolarion, we, us or our) under Articles 12, 13 and 14 of Regulation (EU) 2016/679 (GDPR) and Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (Infotv.).
It applies to Personal Data about:
- visitors to www.cevolarion.com and people who contact us through the website, email, telephone, social media or another communication channel;
- prospects and representatives, personnel or contacts of clients, suppliers, subcontractors, professional advisers and other business partners;
- participants in meetings, events, webinars, surveys and business-development activities;
- job applicants, candidates, referees and recruitment contacts; and
- people who submit a privacy request, complaint, security report or legal communication.
This Notice does not govern internal employee administration, which is covered by separate workforce notices. It also does not govern Client Personal Data that Cevolarion Processes only on a Client's documented instructions as a Processor. In that situation, the Client is responsible for its privacy notice and Cevolarion's Processing is governed by the applicable agreement, SOW and Data Processing Agreement.
Controller identity and contact details
Full legal name: Cevolarion Korlátolt Felelősségű Társaság
Short name: Cevolarion Kft.
Registered seat: 4025 Debrecen, Simonffy utca 4-6., ground floor, door 41, Hungary
Company registration number: 09-09-036798
Tax number: 32766981-2-09
Website: https://www.cevolarion.com
Privacy and Data Subject requests: info@cevolarion.com
Cevolarion has not designated a separate statutory Data Protection Officer as of the effective date. All privacy matters, including any communication that would otherwise be directed to a DPO, are handled through the privacy contact above. If this changes, the published Notice will be updated.
Our data-protection principles
Cevolarion applies the following principles to all Controller Processing:
- lawfulness, fairness and transparency;
- purpose limitation and no incompatible reuse;
- data minimisation and privacy by design and by default;
- reasonable accuracy and correction of material errors;
- retention only for defined business or legal needs;
- confidentiality, integrity, availability and resilience proportionate to risk; and
- accountability, including documented decisions, contracts, access controls and evidence of compliance.
Sources and categories of Personal Data
We may obtain Personal Data:
- directly from the individual, including through email, meetings, calls, applications, forms and signed documents;
- from the individual's employer, organisation, colleagues, authorised representatives, referees or recruitment agencies;
- from Clients where a contact or participant is identified for a project or business process;
- from public professional sources, such as corporate websites, business registries, professional directories and professional social-media profiles, where relevant to a legitimate business purpose;
- automatically from the website, including online identifiers, device and browser information, timestamps, referring pages, security logs and consented analytics; and
- from service providers, public authorities, courts, advisers or counterparties where lawful and necessary.
The categories used in a particular activity are described below. Cevolarion does not intentionally request special-category data or criminal-offence data for ordinary business activities. If such data is genuinely necessary, it will be handled only under an applicable Article 9 or Article 10 GDPR condition, with additional access and security restrictions and a more specific notice where appropriate.
Where Personal Data is obtained from a source other than the individual, Cevolarion provides this Notice or a more specific Article 14 notice within a reasonable period and no later than one month after obtaining the data, at the first communication with the individual, or before the first disclosure to another recipient, as applicable. An Article 14(5) exemption is used only where its conditions are met and the reasoning is documented.
How and why we use Personal Data
Website delivery, security and diagnostics
People concerned: Website visitors and people who interact with content embedded in the website.
Personal Data: IP address, date and time, requested page, referring page, browser and device type, language, approximate region, cookie or similar identifiers, security events and diagnostic logs.
Purposes: Deliver the Wix-hosted website; maintain availability; render pages and requested functions; remember necessary choices; prevent spam, fraud, abuse and attacks; diagnose faults; and preserve evidence of security incidents.
Legal basis: GDPR Article 6(1)(f) - Cevolarion's legitimate interests in operating a secure, reliable and accessible public website. Storage or access that is strictly necessary for the service requested is used without consent; non-essential technologies require consent where applicable.
Sources: The visitor's browser or device and Wix hosting, security and delivery infrastructure.
Retention: Ordinary Cevolarion-controlled security logs are retained for up to 30 days. Relevant records may be isolated and retained for up to 5 years where necessary to investigate an incident, establish facts, comply with law or protect legal claims. Provider-controlled cookie periods are described in the cookie section.
Recipients: Wix.com Ltd., relevant Wix affiliates and Wix infrastructure providers; security and professional advisers if an incident requires support; authorities where legally required.
Is provision required?: Basic technical data is necessary to deliver the website. The website cannot function without strictly necessary processing.
Website analytics and cookie preferences
People concerned: Website visitors in locations where analytics is available and the visitor has made the relevant cookie choice.
Personal Data: Cookie identifiers, online identifiers, approximate location, browser/device data, visited pages, navigation, engagement, consent choice and aggregated traffic statistics.
Purposes: Measure traffic and engagement, understand which content is useful, improve the website and remember the visitor's cookie choice.
Legal basis: GDPR Article 6(1)(a) - consent for non-essential analytics and similar technologies. Necessary storage of the consent choice and basic preference functionality is based on Article 6(1)(f) and the applicable electronic-communications exemption.
Sources: The visitor's browser/device, Wix Analytics where enabled, and Wix's consent service used by the custom Cookie settings panel.
Retention: Cevolarion-controlled analytics reports are retained for no more than 14 months. The Cookie Policy at https://www.cevolarion.com/legal/cookie-policy documents website-controlled storage and its duration, and distinguishes Wix-managed storage whose expiry is not specified by the website code. Any separately retained consent evidence is kept for the lifetime of the choice and up to 5 years thereafter where needed to demonstrate compliance; this is not the expiry period of the browser's consent preference.
Recipients: Wix.com Ltd., relevant Wix affiliates and infrastructure providers; and Cevolarion's authorised website administrators for aggregated reports.
Is provision required?: Optional. Rejecting analytics does not prevent access to the public website.
Enquiries, proposals and pre-contract communications
People concerned: Individuals who request information and contacts at prospective clients, suppliers or partners.
Personal Data: Name, role, employer/organisation, work contact details, correspondence, meeting notes, service interests, project context, requested scope, budget/timing information and records of follow-up.
Purposes: Respond to an enquiry; arrange meetings; assess requirements; prepare a proposal, quotation, NDA, SOW or contract; conduct proportionate conflict, sanctions, credit or counterparty checks; and maintain an audit trail of negotiations.
Legal basis: GDPR Article 6(1)(b) where the individual requests steps before entering a contract; Article 6(1)(f) for B2B relationship management, proposal administration, due diligence, security and protection of legal interests; Article 6(1)(c) where a check or record is legally required.
Sources: The individual, their organisation, authorised representatives, referrals, public professional sources and lawful counterparty-check sources.
Retention: Unsuccessful or inactive enquiries are retained for 12 months after the last substantive contact. Negotiation records needed for legal protection may be retained for 5 years after the matter closes. Records that become part of a contract follow the contract retention period.
Recipients: Relevant Cevolarion personnel; contracted business-infrastructure, email, communications, collaboration and document-management providers; advisers; and screening providers or authorities where a lawful check is required.
Is provision required?: Information marked or reasonably identified as necessary is required to respond or prepare a reliable proposal. Without it, Cevolarion may be unable to proceed.
Client, supplier and business-partner relationship management
People concerned: Direct counterparties and representatives, personnel and contacts of corporate clients, suppliers, subcontractors, advisers and partners.
Personal Data: Identity, job title, authority, organisation, work contact details, signature, communication history, meeting notes, purchasing information, approvals, access status, performance information and relationship history.
Purposes: Form and administer contracts; verify authority; manage contacts, orders, changes, approvals, delivery, quality, supplier oversight, audits, complaints, renewals and relationship governance.
Legal basis: GDPR Article 6(1)(b) for contracts with individuals; Article 6(1)(f) for administration of contracts with organisations, efficient B2B communication, supplier governance, quality assurance and legal protection; Article 6(1)(c) for statutory records.
Sources: The individual, their organisation, the relevant contract or order, colleagues, project systems, business registries and professional advisers.
Retention: For the relationship and 5 years after termination or the last transaction, subject to longer accounting, tax, regulatory, audit, security or active-claim requirements.
Recipients: Relevant Cevolarion personnel and authorised subcontractors; the counterparty organisation; contracted business-infrastructure, communications, collaboration, document-management, project-administration and workflow providers; accountants, auditors, banks, insurers and advisers; and authorities where required.
Is provision required?: Core identity, authority, contact and transaction data is needed to enter and administer the relationship.
Engineering-service delivery and project administration
People concerned: Client and supplier personnel, project participants, technical contacts, approvers, repository users and persons named in project records.
Personal Data: Business identity and contacts; project role; account or access identifier; tickets, timesheets, decisions, approvals, meeting records, audit logs, code-review attribution, delivery evidence, training status and security/access records. Client system content may also be Processed under the Client's control and DPA.
Purposes: Plan and deliver engineering services; allocate capacity; control access; collaborate; document requirements and decisions; maintain traceability; report progress; secure repositories and environments; evidence acceptance; investigate defects; and satisfy quality, cybersecurity and contractual requirements.
Legal basis: GDPR Article 6(1)(f) - Cevolarion's and the Client's legitimate interests in secure, accountable and effective B2B service delivery; Article 6(1)(b) where the individual is a contracting party; Article 6(1)(c) for legal or regulatory records. Client-controlled project Personal Data is Processed under Article 28 GDPR and the DPA rather than for Cevolarion's independent purposes.
Sources: The individual, Client, configured business-communication, collaboration, project, ticketing and documentation systems, repositories, access systems and delivery personnel.
Retention: Operational project records are retained for the project and normally 5 years after the applicable SOW ends. Security logs ordinarily follow the 30-day period unless isolated for an incident. Client-controlled Personal Data is returned or deleted under the DPA and SOW.
Recipients: The relevant Client, authorised project team and subcontractors; contracted communication, collaboration and document-management providers; project, ticketing and knowledge-management providers; approved repository, hosting, cloud and engineering-tool providers; and auditors or advisers where necessary.
Is provision required?: Necessary project identity, access, communication and evidence data is required for secure delivery. Access may be refused if required information or training is not provided.
Billing, accounting, tax and payments
People concerned: Clients, suppliers, individual contractors, payees, signatories and financial contacts.
Personal Data: Name, role, organisation, billing address, tax identifiers where applicable, bank/payment details, purchase-order and invoice data, timesheet or acceptance references, payment status and correspondence.
Purposes: Issue and receive invoices; process and reconcile payments; maintain accounting records; handle debt collection, audits and tax reporting; and prevent financial fraud.
Legal basis: GDPR Article 6(1)(c) - compliance with accounting, tax and recordkeeping duties; Article 6(1)(b) - performance of contracts with individuals; Article 6(1)(f) - financial control, fraud prevention, credit management and legal claims.
Sources: The individual, their organisation, contracts, purchase orders, banks, payment providers, accountants and public authorities.
Retention: Accounting records and supporting documents are retained for at least 8 years under Section 169(2) of Act C of 2000 on Accounting. Records relevant to an unresolved audit, investigation or claim are kept until final closure where longer.
Recipients: Accountants, auditors, banks, payment providers, tax and other competent authorities, legal advisers, insurers and debt-recovery providers where necessary.
Is provision required?: Required billing, tax and payment information must be provided; otherwise Cevolarion may be unable to invoice, pay or complete the transaction.
B2B marketing, newsletters and business development
People concerned: Existing and prospective professional contacts, subscribers and persons who request business updates.
Personal Data: Name, role, organisation, professional contact details, service interests, event or content interactions, communication preferences, consent evidence, campaign engagement and objection/suppression status.
Purposes: Send requested newsletters or updates; provide relevant information about Cevolarion services; invite professional contacts to events; measure campaign effectiveness; maintain business relationships; and honour opt-outs.
Legal basis: GDPR Article 6(1)(a) - consent where electronic-marketing law requires it. GDPR Article 6(1)(f) may be used for carefully targeted, relevant B2B relationship communications to professional contacts where permitted by applicable electronic-marketing law, after a balancing assessment and with an immediate right to object. Cevolarion does not rely on legitimate interest to send unsolicited bulk marketing to personal email addresses.
Sources: The individual, their organisation, prior business interactions, event registrations, referrals and relevant public professional sources.
Retention: Until consent is withdrawn, the person objects, the communication is repeatedly undeliverable or 24 months pass without meaningful engagement, whichever occurs first. Minimal consent, objection and suppression evidence may be retained for 5 years to demonstrate compliance and prevent renewed contact.
Recipients: Authorised Cevolarion business-development personnel; contracted email, communications, collaboration, event or campaign providers acting under appropriate terms.
Is provision required?: Optional. Marketing consent may be withdrawn and B2B marketing objected to at any time without affecting services or prior lawful Processing.
Meetings, events, webinars and surveys
People concerned: Registrants, attendees, speakers, hosts, invitees and survey respondents.
Personal Data: Name, role, organisation, work contact details, registration and attendance, accessibility or dietary information volunteered for the event, questions, feedback, recordings, photographs and consent choices.
Purposes: Organise and secure the activity; communicate logistics; provide materials; obtain feedback; document attendance; and publish recordings, quotations or photographs only where the person has been appropriately informed and a valid basis applies.
Legal basis: GDPR Article 6(1)(b) for requested participation; Article 6(1)(f) for event administration, security and service improvement; Article 6(1)(a) for optional marketing, identifiable testimonials, publicity images or recordings where consent is appropriate; Article 6(1)(c) for financial records.
Sources: The individual, their organisation, event hosts or registration providers.
Retention: Ordinary registration, attendance and feedback records: 12 months after the activity. Financial records: 8 years. Published material is retained until consent is withdrawn or the material is no longer used, subject to lawful archival or legal-claim needs. Raw recordings not selected for use are deleted within 90 days.
Recipients: Event hosts, venues, communications/platform providers, authorised attendees where necessary, and the public only for material expressly intended for publication.
Is provision required?: Core registration data may be necessary to participate. Marketing, publicity and non-essential survey responses are optional.
Recruitment and talent-pool administration
People concerned: Applicants, candidates, referees, recruiters and persons who express interest in working with Cevolarion.
Personal Data: Identity and contact details; CV, education, skills and employment history; portfolio and professional-profile information; work authorisation and availability; salary expectations; interview and assessment records; communications; reference information where authorised; and recruitment-source information. Cevolarion does not request unnecessary special-category data.
Purposes: Receive and assess applications; communicate with candidates; conduct interviews and proportionate skills assessments; verify information and references; select candidates; prepare an offer; operate an optional talent pool; and establish, exercise or defend recruitment-related legal claims.
Legal basis: GDPR Article 6(1)(b) - steps at the candidate's request before an employment or service contract; Article 6(1)(f) - fair and efficient recruitment, verification, record integrity and legal defence; Article 6(1)(a) - optional talent-pool retention beyond the active process. Additional Article 9 conditions will be identified if special-category data becomes necessary.
Sources: The candidate; recruitment agencies; authorised referees; public professional profiles; and the candidate's current or former organisation where lawful and appropriately notified.
Retention: The full application and interview file is retained for 6 months after the role closes. A restricted minimum record needed to demonstrate fair recruitment and defend claims may be retained for 3 years. Talent-pool information is retained for 2 years from consent, unless withdrawn earlier. Hired-candidate information moves to the applicable workforce notice and personnel file.
Recipients: Authorised hiring personnel and relevant technical interviewers; recruitment agencies; communications and document providers; referees contacted with the candidate's knowledge; and advisers or authorities where legally necessary.
Is provision required?: Core application information is necessary to assess the candidate. Talent-pool consent, optional demographic information and publicity are not required and do not affect the active application.
Social-media and external-platform interactions
People concerned: People who follow, message, mention or interact with Cevolarion or its authorised representatives on professional platforms.
Personal Data: Profile name, professional information made available by the user, platform identifier, messages, reactions, comments, shared content and interaction statistics provided by the platform.
Purposes: Respond to messages and comments; maintain professional relationships; manage Cevolarion's public presence; moderate abuse; and understand aggregate engagement.
Legal basis: GDPR Article 6(1)(f) - legitimate interests in professional communication, reputation, moderation and business development; Article 6(1)(a) for optional direct marketing where consent is required.
Sources: The individual and the relevant platform.
Retention: Direct-message records needed for business follow-up are normally retained for 24 months after the last interaction. Public content remains subject to the platform's controls and the user's own deletion choices. Legal or security evidence may be retained for up to 5 years.
Recipients: The relevant platform provider, its users according to the chosen visibility, and authorised Cevolarion personnel. The platform separately determines its own Processing under its privacy policy.
Is provision required?: Optional. Individuals can use other contact methods instead of social media.
Compliance, security incidents, legal claims and corporate transactions
People concerned: Business contacts, website users, project participants, complainants, counterparties, persons connected to an incident, and individuals whose data appears in relevant records.
Personal Data: Identity and contact data, communications, contracts, access and security logs, incident facts, investigation material, audit evidence, sanctions or conflict results, claim and litigation records, and transaction due-diligence information.
Purposes: Comply with law and binding requests; maintain cybersecurity; prevent and investigate fraud, misconduct and unauthorised access; protect rights, property and safety; manage insurance, disputes and claims; and conduct lawful financing, restructuring, merger, acquisition or asset-transfer due diligence.
Legal basis: GDPR Article 6(1)(c) - legal obligations; Article 6(1)(f) - network and information security, fraud prevention, legal protection, insurance and lawful corporate transactions; Article 6(1)(d) only where urgently necessary to protect vital interests.
Sources: Operational systems, the individual, counterparties, advisers, insurers, security providers, public records and competent authorities.
Retention: For the investigation or proceeding and 5 years after final closure, unless a longer period is required by law, a regulator, an insurer, litigation hold or an unresolved claim. Data not relevant to the matter is removed or segregated as soon as practicable.
Recipients: Security specialists, insurers, auditors, legal and professional advisers, transaction counterparties under confidentiality, courts, regulators, law-enforcement and other competent authorities.
Is provision required?: Information may be required by law, contract or a legitimate investigation. Failure to provide required information may result in refusal of access, suspension of a process or legal action.
Privacy requests and complaints
People concerned: Individuals exercising data-protection rights, their authorised representatives and complainants.
Personal Data: Identity and contact details, request or complaint content, proof of identity or authority where necessary, search and response records, correspondence, decision reasoning and delivery evidence.
Purposes: Authenticate and respond to the request; locate and protect relevant data; comply with GDPR and Infotv.; prevent unauthorised disclosure; and demonstrate compliance.
Legal basis: GDPR Article 6(1)(c) - legal obligations under data-protection law; Article 6(1)(f) - secure authentication, consistent case management and legal defence.
Sources: The requester, their representative, Cevolarion systems, processors and relevant counterparties.
Retention: 5 years after final closure of the request or complaint, unless an authority or court proceeding requires longer retention.
Recipients: Relevant Cevolarion personnel and processors, advisers, the competent supervisory authority or court, and the requester's authorised representative.
Is provision required?: Sufficient information is required to identify the request and, where reasonably necessary, verify identity or authority. Excessive identity documents will not be requested.
Cookies and similar technologies
The current website is hosted on Wix. Its custom Cookie settings panel offers Essential and Analytics information, with Review choices, Reject analytics and Accept analytics controls. Essential remains enabled. Accept analytics enables only the analytics category in the Wix consent policy; functional, advertising and data-to-third-party categories remain disabled. The website reads and saves choices through Wix's consent service. It does not use an Accept All button, wider category toggles or a Usercentrics panel. Rejecting analytics does not prevent browsing or using the contact and application forms.
| Category | Provider and examples | Purpose / legal basis | Typical duration and control |
|---|---|---|---|
| Essential infrastructure and navigation | Wix hosting infrastructure and the website's Careers return-state storage. | Secure delivery, request routing and core navigation. Legitimate interest and applicable strictly-necessary exemption. | Website-controlled storage durations and legacy entries are listed in the Cookie Policy. Wix-managed cookie names and lifetimes depend on the deployed platform configuration and are not specified by the website code. |
| Consent preference | Wix consent service, used by the custom Cookie settings panel. | Remember the visitor's analytics choice and allow it to be changed. Legal obligation and legitimate interest in compliance evidence. | Platform-managed expiry; no separate Cevolarion consent cookie or expiry is set by the website. A visitor can change the choice or clear site data in the browser. |
| Analytics | Custom website events sent through an available analytics integration only after an explicit saved analytics choice. | Audience measurement and content improvement. Consent under GDPR Article 6(1)(a). | The Cookie Policy describes the implemented analytics behavior. Cevolarion-controlled analytics reports are kept no longer than 14 months; this is not a browser cookie lifetime. |
The Cookie Policy at https://www.cevolarion.com/legal/cookie-policy is the single website-controlled storage inventory and duration reference. The choice panel does not contain a cookie inventory or site scan. Platform-managed cookies can change with Wix updates; contact info@cevolarion.com for details of a particular cookie shown by your browser. Cevolarion does not knowingly deploy advertising or cross-site behavioural-profiling cookies on the current website. A new non-essential technology must be classified, blocked pending consent where required, and reflected in the Cookie Policy and this Notice before activation.
Managing or withdrawing cookie consent
- Select Review choices to read the Essential and Analytics descriptions. Choose Reject analytics for essential-only use, or Accept analytics to allow optional analytics. A successful save reloads the page so the updated Wix policy can take effect.
- Use Cookie settings in the footer or on the Cookie Policy page to reopen the panel and change or withdraw an earlier analytics choice.
- Use the browser's site-specific cookie settings to delete or block cookies. After clearing the stored choice, reload the website to receive the banner again.
- Be aware that blocking strictly necessary technologies may impair security, language, embedded content or other requested functionality.
Lawful bases and legitimate-interest assessments
Cevolarion uses only a legal basis appropriate to the specific purpose:
- Consent - freely given, specific, informed and unambiguous permission for an optional activity. Consent can be withdrawn at any time without affecting earlier lawful Processing.
- Contract or pre-contract steps - Processing objectively necessary to enter or perform a contract with the individual.
- Legal obligation - Processing necessary to comply with EU or Hungarian law, a binding regulatory duty or a valid authority requirement.
- Legitimate interests - Processing necessary for a lawful, clear, real and current interest that is not overridden by the individual's interests, rights or freedoms.
- Vital interests - used only in an exceptional emergency where necessary to protect a person's life or physical safety.
Before relying on Article 6(1)(f), Cevolarion identifies the interest, tests whether Processing is necessary, considers reasonable expectations and possible impact, and applies safeguards such as minimisation, restricted access, short retention, opt-outs and contractual controls. An individual may request information about the balancing assessment relevant to their data, subject to protection of others' rights and confidential information.
Recipients and service providers
Personal Data is disclosed only on a need-to-know basis and under an appropriate legal or contractual framework. A recipient may act as Cevolarion's Processor, an independent Controller, a joint Controller or a person acting under Cevolarion's authority, depending on the service and facts.
Cevolarion does not sell or rent Personal Data and does not disclose it to third parties for their unrelated direct marketing.
| Recipient / category | Why and what may be shared | Role and location |
|---|---|---|
| Wix.com Ltd., Wix affiliates and infrastructure providers | Website hosting, content delivery, security, essential cookies, forms or business functions, cookie choices and Wix Analytics where enabled; online identifiers, device/browser, usage and submitted form data. | Processor for visitor data handled on Cevolarion's instructions and independent Controller for certain platform, security and account data. Processing may occur in Israel, the EEA, the United States and approved support locations. Israel benefits from an EU adequacy decision; other transfers use applicable adequacy, Data Privacy Framework or SCC safeguards. |
| Business infrastructure, email, communications, collaboration and document-management providers | Email, calendar, meetings, file storage, document collaboration and business administration; business contacts, communications, files, meeting and administrative records. | Processors for Cevolarion-controlled content and, where applicable, independent Controllers for limited account, security, diagnostics or billing data. Locations and transfer safeguards are recorded in the Service Provider and Transfer Register; EEA or EU residency is selected where available and appropriate. |
| Project, ticketing, knowledge-management, repository, hosting and engineering-tool providers | Project coordination, requirements, documentation, issue and defect tracking, code/repository workflows, cloud infrastructure and service operations; account identifiers, work contact data, tickets, comments, attachments, logs and project records. | Processors or independent Controllers according to the service. Provider-specific locations, further processors and Chapter V safeguards are assessed and recorded before use. Marketplace apps, plug-ins and integrations require separate approval. |
| Banks, payment and financial-service providers | Payments, reconciliation, fraud prevention and financing; transaction, payer/payee and billing data. | Independent Controllers and/or Processors in relevant financial jurisdictions. |
| Accountants, auditors, tax advisers and insurers | Accounting, statutory audit, tax, coverage and claims; invoices, transactions, contacts, contracts and claim records. | Independent Controllers or Processors, normally in the EEA. |
| Clients, suppliers and authorised subcontractors | Contract and service delivery, access, project coordination, quality and security; professional contact and project evidence data. | Independent Controllers or Processors according to the arrangement; locations specified by the relationship and SOW. |
| Recruitment agencies, referees and assessment providers | Candidate sourcing, verification and assessment; application, professional and interview data. | Independent Controllers or Processors; normally EEA unless separately disclosed. |
| Legal and professional advisers, courts, regulators, law enforcement and competent authorities | Legal advice, compliance, investigations, claims and binding requests; only data relevant and necessary to the matter. | Independent Controllers, recipients exercising official authority or persons subject to professional confidentiality. |
| Transaction counterparties | Confidential due diligence and implementation of a merger, financing, restructuring or asset transfer. | Independent Controllers or advisers under confidentiality and data-minimisation controls. |
This Notice names a provider where its identity is materially relevant to direct website collection, hosting, cookie/consent operation or another Processing activity for which naming improves transparency. Other operational providers are described using specific recipient categories so this Notice remains accurate when Cevolarion changes or adds tools.
Cevolarion maintains a controlled Service Provider and Transfer Register recording the relevant provider identity, service, role, Personal Data, Processing locations, sub-processors, security review, retention and transfer safeguard. A current list relevant to an individual's Personal Data will be supplied on request where required, subject to proportionate security and confidentiality limitations. When Cevolarion acts as a Processor for a Client, the actual authorised Sub-processors and transfer mechanisms are governed by the applicable SOW, DPA Schedule 3 and SCC execution package, including the agreed change-notification and objection process.
International transfers
Cevolarion seeks to keep Controller Personal Data in the European Economic Area (EEA), but global cloud, support, professional or Client arrangements may involve remote access or transfers outside the EEA. Cevolarion permits such a transfer only where Chapter V GDPR requirements are satisfied.
Depending on the destination and recipient, Cevolarion may rely on:
- a European Commission adequacy decision, including the EU-US Data Privacy Framework for a participating United States recipient where the certification covers the relevant data;
- the European Commission Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914, with the correct module and completed annexes;
- Binding Corporate Rules or another approved Article 46 safeguard; or
- an Article 49 derogation only for an occasional transfer where its strict conditions are met.
Where required, Cevolarion or the relevant provider assesses the destination law and transfer circumstances and applies supplementary contractual, technical or organisational measures. Individuals may request information about the applicable mechanism and a copy or summary of the relevant safeguard, subject to lawful redactions.
Before an operational service provider, cloud product, integration, plug-in or Marketplace application may Process Personal Data, Cevolarion records the provider's legal entity, service, role, data categories, locations, sub-processors, security review, retention position and applicable Chapter V transfer safeguard in its Service Provider and Transfer Register. EEA or EU data residency is selected where available and appropriate. Extensions and third-party integrations are assessed separately because their Processing, storage locations and terms may differ from the underlying platform.
Retention schedule
Cevolarion deletes, anonymises or securely segregates Personal Data when it is no longer needed for the stated purpose, subject to legal holds, statutory preservation, active disputes and demonstrable security needs. The principal periods are summarised below.
| Record category | Standard retention | Trigger / exception |
|---|---|---|
| Website security and diagnostic logs | 30 days | Relevant incident evidence: investigation plus up to 5 years after closure. |
| Analytics reports | 14 months | Provider cookies may remain for the provider-defined period or until deleted/rejected. |
| Inactive enquiries and unsuccessful proposals | 12 months | Negotiation/legal evidence: up to 5 years after closure. |
| Contracts, business contacts, delivery and supplier records | Relationship plus 5 years | Longer where an active claim, audit, regulatory duty or legal hold applies. |
| Accounting and supporting financial documents | At least 8 years | Longer if a tax audit, investigation or claim remains open. |
| Marketing contact data | Until withdrawal/objection or 24 months without engagement | Minimal consent, objection and suppression evidence: 5 years. |
| Event registration and feedback | 12 months after event | Financial evidence: 8 years; raw recordings: 90 days unless selected for authorised use. |
| Recruitment file | 6 months after role closes | Restricted fair-recruitment/legal-defence record: 3 years; talent pool: 2 years with consent. |
| Social-platform direct messages | 24 months after last interaction | Public content follows platform/user controls; legal/security evidence up to 5 years. |
| Privacy requests and complaints | 5 years after closure | Longer during an authority or court proceeding. |
| Security, compliance and legal matters | Matter plus 5 years | Longer where law, regulator, insurer, court or unresolved claim requires. |
Security measures
Cevolarion applies risk-based technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures are selected according to the nature, scope, context and purpose of Processing and the likely impact on individuals.
- role-based access, least privilege, account-lifecycle controls and multi-factor authentication where appropriate;
- encryption in transit and at rest where appropriate, with controlled key and credential handling;
- confidentiality commitments, security awareness and joiner/mover/leaver controls;
- logging, monitoring, secure backup, recovery and incident-response procedures proportionate to risk;
- secure repositories, code review, vulnerability and dependency management where software development is in scope;
- data minimisation, logical segregation, controlled retention and secure deletion;
- supplier due diligence, written Processing terms and proportionate oversight; and
- periodic testing, assessment and improvement of controls.
No system is completely secure. If Cevolarion becomes aware of a Personal Data Breach, it will contain and assess the event, document the response, notify the competent authority and affected individuals where required, and cooperate with Clients where Cevolarion acts as Processor.
Artificial intelligence and automated decision-making
Cevolarion may use approved AI-assisted tools for low-risk productivity, software-development assistance, quality assurance, security monitoring, summarisation or drafting, subject to human review and data-classification controls. Personal Data, confidential information or Client proprietary material is not submitted to an external AI service unless the specific use is lawful, necessary, covered by appropriate provider and transfer terms, and permitted by the applicable contract, SOW or DPA where Client data is involved.
Cevolarion does not use solely automated decision-making that produces legal effects or similarly significant effects for the individuals covered by this Notice. Recruitment, contracting, access, complaint and legal decisions include meaningful human involvement. If this changes, Cevolarion will provide specific information about the logic involved, significance, expected consequences, safeguards and right to obtain human intervention before the Processing begins.
Your data-protection rights
Subject to the conditions and exemptions in applicable law, an individual may request:
- Access - confirmation of whether Personal Data is Processed and a copy with the information required by Article 15 GDPR.
- Rectification - correction of inaccurate data and completion of incomplete data.
- Erasure - deletion where no legal basis or retention ground remains, including after valid withdrawal or objection where applicable.
- Restriction - temporary limitation while accuracy, lawfulness, an objection or a legal-claim need is assessed.
- Portability - receipt or direct transfer of data provided by the individual where Processing is automated and based on consent or contract.
- Objection - cessation of Processing based on legitimate interests unless compelling legitimate grounds or legal claims justify continuation.
- Direct-marketing objection - immediate cessation of Processing for direct marketing, including related profiling, without a balancing test.
- Withdrawal of consent - withdrawal at any time, without affecting Processing lawfully completed before withdrawal.
- Human intervention - the safeguards in Article 22 GDPR if solely automated significant decision-making is introduced.
- Complaint and judicial remedy - complaint to a competent supervisory authority and access to an effective court remedy.
How to exercise a right
- Email info@cevolarion.com or write to Cevolarion Kft., 4025 Debrecen, Simonffy utca 4-6., ground floor, door 41, Hungary.
- Describe the relationship, data or activity concerned and the right being exercised. A preferred response channel may be stated.
- Cevolarion may request proportionate identity or authority evidence only where there are reasonable doubts or disclosure risk. Unnecessary identity documents should not be sent with the initial request.
- Cevolarion normally responds within one month. The period may be extended by up to two further months for a complex or numerous request; the individual will be informed within the first month with reasons.
- Requests are normally free. A reasonable fee or refusal may apply only where a request is manifestly unfounded or excessive, particularly because of repetition, and Cevolarion bears the burden of demonstrating that condition.
Supervisory authority
Individuals may lodge a complaint with the supervisory authority in their habitual residence, place of work or place of the alleged infringement. Cevolarion's lead Hungarian authority is:
Authority: Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9-11, Hungary
Postal address: 1363 Budapest, Pf. 9, Hungary
Email: ugyfelszolgalat@naih.hu
Telephone: +36 (1) 391-1400
Website: https://www.naih.hu
We encourage individuals to contact Cevolarion first so that we can address the concern promptly, but doing so is not a condition of filing a complaint or seeking a judicial remedy.
Required and optional information
Where Personal Data is required by law, necessary for a contract or objectively needed to provide a requested service, Cevolarion will identify that requirement when it is not obvious. Failure to provide required information may prevent Cevolarion from responding, entering or performing a contract, granting system access, making or receiving payment, or meeting a legal obligation. Consent-based information is optional and refusal or withdrawal will not disadvantage the individual in relation to unrelated services.
Children
Cevolarion provides B2B engineering services and does not knowingly offer an information-society service directly to children or intentionally collect children's Personal Data through the public website. If such data is received unintentionally, contact info@cevolarion.com so it can be assessed and deleted where appropriate. A project involving children's data requires a specific Client instruction, DPA, lawful basis and safeguards before Processing begins.
Third-party websites and embedded content
The website may link to or embed third-party content. The third party may collect data independently when a visitor opens or interacts with that content. Cevolarion does not control the third party's separate Processing and recommends reviewing the applicable privacy and cookie information. Embedded non-essential content should be activated only under the appropriate consent mechanism where required.
Changes to this Notice
Cevolarion reviews this Notice at least annually and when a material new Processing activity, provider, transfer, legal requirement or website technology is introduced. The current version and effective date will be published on www.cevolarion.com. Where a change materially affects an existing consent, purpose or individual expectation, Cevolarion will provide additional notice and obtain new consent where required. Earlier versions will be retained for accountability.
Legal and platform references
- EU General Data Protection Regulation - official EUR-Lex text
- Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
- European Commission guidance on information to individuals
- EDPB transparency guidelines under Regulation (EU) 2016/679
- Wix - Cookies and Your Wix Site
- Wix - Displaying a Usercentrics for Wix Cookie Banner
- Wix Privacy Policy
- Service Provider and Transfer Register - relevant provider and transfer information is available on request at info@cevolarion.com, subject to proportionate security and confidentiality limitations.
- Client-controlled data - actual Sub-processors and transfer mechanisms are identified in the applicable SOW, DPA schedules and SCC execution package.
- European Commission Standard Contractual Clauses
Contact: Questions about this Notice or Cevolarion's Processing may be sent to info@cevolarion.com or by post to Cevolarion Kft., 4025 Debrecen, Simonffy utca 4-6., ground floor, door 41, Hungary.
