Adatvédelem

Adatkezelési Tájékoztató

Intelstellar Park Korlátolt Felelősségű Társaság

Hatályos: 2026. május 29.

Az Intelstellar Park Korlátolt Felelősségű Társaság (a továbbiakban: „Adatkezelő" vagy „Társaság") elkötelezett a személyes adatok védelme és az információs önrendelkezési jog tiszteletben tartása mellett. Jelen Adatkezelési Tájékoztató célja, hogy a www.intelstellar.com weboldal látogatói, üzleti partnerei és érdeklődői számára átlátható és közérthető tájékoztatást nyújtson a személyes adatok kezelésének módjáról, céljáról, jogalapjáról, időtartamáról, valamint az érintetteket megillető jogokról. Az Adatkezelő minden esetben a hatályos magyar és európai uniós adatvédelmi jogszabályoknak megfelelően jár el, különös tekintettel az Európai Parlament és Tanács (EU) 2016/679 rendeletére (GDPR).

1. Bevezetés

Az Intelstellar Park Kft. elkötelezett a személyes adatok védelme és az információs önrendelkezési jog tiszteletben tartása mellett. Jelen tájékoztató a www.intelstellar.com weboldalon megvalósuló adatkezelésekre vonatkozik, és a hatályos magyar, valamint európai uniós adatvédelmi jogszabályokon, különösen a GDPR-on alapul.

2. Az adatkezelő adatai

Cégnév: Intelstellar Park Korlátolt Felelősségű Társaság

Rövidített név: Intelstellar Park Kft.

Székhely: 8000 Székesfehérvár, III. Béla király tér 5. 3. em. 1. ajtó

Adószám: 25337772-2-07

Főtevékenység: 7112 Mérnöki tevékenység, műszaki tanácsadás

Weboldal: www.intelstellar.com

Kapcsolattartó e-mail: [email protected]

Tárhelyszolgáltató: Deebox Kft.

Tárhelyszolgáltató címe: 1089 Budapest, Korányi Sándor utca 4. 4. ajtó

3. Az adatkezelésre vonatkozó jogszabályok

A Társaság adatkezelése különösen az alábbi jogszabályokon alapul:

  • az Európai Parlament és Tanács (EU) 2016/679 rendelete (GDPR),
  • az információs önrendelkezési jogról és az információszabadságról szóló 2011. évi CXII. törvény,
  • az elektronikus kereskedelmi szolgáltatások egyes kérdéseiről szóló 2001. évi CVIII. törvény,
  • az elektronikus hírközlésről szóló 2003. évi C. törvény,
  • valamint az adatkezelésre vonatkozó egyéb hatályos jogszabályok.

4. Az adatkezelés alapelvei

A Társaság az adatkezelés során az alábbi alapelveket alkalmazza:

  • jogszerűség, tisztességes eljárás és átláthatóság,
  • célhoz kötöttség,
  • adattakarékosság,
  • pontosság,
  • korlátozott tárolhatóság,
  • integritás és bizalmas jelleg,
  • elszámoltathatóság.

A Társaság kizárólag olyan személyes adatokat kezel, amelyek az adott adatkezelési cél megvalósításához szükségesek és alkalmasak.

5. A weboldal használata során megvalósuló adatkezelések

5.1. Szervernaplózás

A weboldal meglátogatásakor a szerver automatikusan technikai adatokat rögzít.

Kezelt adatok köre
  • IP-cím,
  • a látogatás időpontja,
  • a meglátogatott oldalak címe,
  • böngésző típusa,
  • operációs rendszer adatai,
  • hivatkozó oldal címe.
Az adatkezelés célja
  • a weboldal biztonságos működésének biztosítása,
  • informatikai incidensek kivizsgálása,
  • jogosulatlan hozzáférések felismerése,
  • rendszerüzemeltetés.
Jogalap

GDPR 6. cikk (1) bekezdés f) pont – az Adatkezelő jogos érdeke.

Megőrzési idő

Legfeljebb 90 nap.

5.2. Kapcsolatfelvétel e-mail útján

A weboldalon található elérhetőségeken keresztül az érdeklődők közvetlenül kapcsolatba léphetnek a Társasággal.

Kezelt adatok
  • név,
  • e-mail cím,
  • cégnév (ha megadásra kerül),
  • telefonszám (ha megadásra kerül),
  • az üzenet tartalma,
  • az érintett által önkéntesen megadott további adatok.
Az adatkezelés célja
  • kapcsolattartás,
  • érdeklődések megválaszolása,
  • üzleti egyeztetések előkészítése,
  • ajánlatadást megelőző kommunikáció.
Jogalap

GDPR 6. cikk (1) bekezdés b) pont.

Megőrzési idő

Az utolsó kommunikációtól számított legfeljebb 2 év.

5.3. Google Analytics

A weboldal a Google Analytics szolgáltatást használja a látogatottsági adatok elemzésére. A szolgáltatás segítségével a Társaság információkat kap többek között:

  • az oldallátogatások számáról,
  • a látogatók földrajzi elhelyezkedéséről,
  • a látogatók által használt eszközökről,
  • a weboldalon eltöltött időről,
  • a leggyakrabban megtekintett oldalakról.

A Google Analytics használata kizárólag az érintett hozzájárulása alapján történik.

Jogalap

GDPR 6. cikk (1) bekezdés a) pont.

Hozzájárulás visszavonása

Az érintett a hozzájárulását bármikor visszavonhatja a cookie-beállítások módosításával.

5.4. Google Maps

A weboldalon Google Maps térképszolgáltatás jelenhet meg. A szolgáltatás használata során a Google saját adatkezelési szabályzata szerint kezelhet személyes adatokat, ideértve az IP-címet, a helymeghatározással kapcsolatos adatokat és egyes eszközazonosítókat. A Google adatkezelésével kapcsolatos további információk a Google adatvédelmi tájékoztatójában érhetők el.

6. Adatfeldolgozók

Az Adatkezelő jogosult olyan külső szolgáltatókat igénybe venni, amelyek az adatkezeléshez kapcsolódó technikai vagy informatikai szolgáltatásokat nyújtanak. Ilyen adatfeldolgozó lehet különösen:

  • a tárhelyszolgáltató,
  • a weboldal fejlesztését vagy üzemeltetését végző szolgáltató,
  • a Google Analytics szolgáltatás üzemeltetője.

Az adatfeldolgozók kizárólag az Adatkezelő utasításai szerint jogosultak eljárni.

7. Adattovábbítás és nemzetközi adattovábbítás

Az Adatkezelő személyes adatokat harmadik személy részére kizárólag:

  • jogszabályi kötelezettség alapján,
  • hatósági vagy bírósági megkeresésre,
  • adatfeldolgozók részére,
  • az érintett hozzájárulása alapján

továbbít. A Google szolgáltatásainak használata során egyes adatok az Európai Gazdasági Térségen kívüli országokba is továbbításra kerülhetnek. Az ilyen adattovábbítások a GDPR által megkövetelt garanciák mellett történnek.

8. Adatbiztonság

A Társaság minden ésszerű technikai és szervezési intézkedést megtesz annak érdekében, hogy a személyes adatok:

  • bizalmasak maradjanak,
  • sértetlenek legyenek,
  • rendelkezésre álljanak,
  • illetéktelenek számára ne váljanak hozzáférhetővé.

Az alkalmazott intézkedések különösen: hozzáférés-kezelés, jogosultságkezelés, naplózás, biztonsági mentések, vírusvédelem, tűzfalas védelem.

9. Az érintettek jogai

Az érintett jogosult:

  • tájékoztatást kérni,
  • hozzáférést kérni személyes adataihoz,
  • helyesbítést kérni,
  • törlést kérni,
  • az adatkezelés korlátozását kérni,
  • tiltakozni az adatkezelés ellen,
  • élni az adathordozhatóság jogával,
  • hozzájárulását visszavonni.

Az Adatkezelő a kérelmeket indokolatlan késedelem nélkül, de legkésőbb 30 napon belül megválaszolja.

9/A. Az érintett hozzáférési joga

Az érintett jogosult arra, hogy visszajelzést kapjon arról, hogy az Adatkezelő kezeli-e a rá vonatkozó személyes adatokat. Amennyiben személyes adatok kezelése folyamatban van, az érintett jogosult megismerni különösen:

  • az adatkezelés célját;
  • a kezelt személyes adatok kategóriáit;
  • az adattovábbítások címzettjeit;
  • az adatmegőrzés időtartamát;
  • az érintettet megillető jogokat;
  • a felügyeleti hatósághoz fordulás lehetőségét;
  • az adatok forrását;
  • az esetleges automatizált döntéshozatal tényét.

Az Adatkezelő az érintett kérésére másolatot biztosít a kezelt személyes adatokról.

9/B. Helyesbítéshez való jog

Az érintett kérheti a rá vonatkozó pontatlan személyes adatok helyesbítését, valamint a hiányos adatok kiegészítését. Az Adatkezelő indokolatlan késedelem nélkül intézkedik a szükséges módosítások végrehajtásáról.

9/C. Törléshez való jog („az elfeledtetéshez való jog")

Az érintett jogosult kérni személyes adatainak törlését különösen akkor, ha:

  • az adatkezelés célja megszűnt;
  • a hozzájárulását visszavonta;
  • az adatkezelés jogellenes;
  • az adat törlését jogszabály írja elő;
  • az érintett eredményesen tiltakozott az adatkezelés ellen.

A törléshez való jog nem korlátlan. Az Adatkezelő bizonyos esetekben köteles megőrizni adatokat jogi kötelezettség teljesítése vagy jogi igények érvényesítése érdekében.

9/D. Az adatkezelés korlátozásához való jog

Az érintett kérheti az adatkezelés korlátozását, amennyiben:

  • vitatja az adatok pontosságát;
  • az adatkezelés jogellenes, de nem kéri a törlést;
  • az Adatkezelőnek már nincs szüksége az adatokra, de az érintett jogi igényhez igényli azokat;
  • tiltakozott az adatkezelés ellen.

Korlátozás esetén az adatok tárolhatók, de egyéb adatkezelési művelet kizárólag meghatározott feltételek fennállása esetén végezhető.

9/E. Adathordozhatósághoz való jog

Az érintett jogosult arra, hogy az általa rendelkezésre bocsátott személyes adatokat tagolt, széles körben használt, géppel olvasható formátumban megkapja. Az érintett jogosult arra is, hogy kérje ezen adatok közvetlen továbbítását egy másik adatkezelő részére, amennyiben ennek technikai feltételei rendelkezésre állnak.

9/F. Tiltakozáshoz való jog

Az érintett saját helyzetével kapcsolatos okból bármikor tiltakozhat a jogos érdek alapján végzett adatkezelés ellen. Ilyen esetben az Adatkezelő megvizsgálja a tiltakozás indokoltságát, és amennyiben nem áll fenn olyan kényszerítő erejű jogos ok, amely elsőbbséget élvez az érintett érdekeivel szemben, az adatkezelést megszünteti.

9/G. Hozzájárulás visszavonása

Amennyiben az adatkezelés jogalapja hozzájárulás, az érintett jogosult azt bármikor visszavonni. A visszavonás nem érinti a visszavonást megelőző adatkezelés jogszerűségét.

9/H. Automatizált döntéshozatal és profilalkotás

Az Intelstellar Park Kft. nem alkalmaz olyan automatizált döntéshozatali rendszert vagy profilalkotást, amely az érintettre nézve joghatással járna vagy őt jelentős mértékben érintené.

10. Adatvédelmi incidensek kezelése

Az Adatkezelő minden szükséges technikai és szervezési intézkedést megtesz az adatvédelmi incidensek megelőzése érdekében. Adatvédelmi incidensnek minősül különösen:

  • személyes adatok jogosulatlan hozzáférése;
  • személyes adatok elvesztése;
  • személyes adatok megsemmisülése;
  • személyes adatok jogosulatlan továbbítása.

Incidens bekövetkezése esetén az Adatkezelő a GDPR rendelkezéseinek megfelelően jár el, és szükség esetén értesíti a felügyeleti hatóságot, valamint az érintetteket.

11. Nemzetközi adattovábbítás

A Google Analytics és a Google Maps szolgáltatások használata során bizonyos adatok az Európai Gazdasági Térségen kívüli országokba, különösen az Amerikai Egyesült Államokba továbbításra kerülhetnek. Az ilyen adattovábbítások megfelelő garanciák mellett történnek, különösen az Európai Bizottság megfelelőségi határozatai, illetve a Google által alkalmazott adatvédelmi mechanizmusok alapján.

12. Eljárási szabályok

Az Adatkezelő az érintetti kérelmeket indokolatlan késedelem nélkül, de legkésőbb a beérkezéstől számított egy hónapon belül megválaszolja. Szükség esetén ez a határidő további két hónappal meghosszabbítható, amelyről az érintett tájékoztatást kap. Amennyiben az Adatkezelő nem tesz intézkedést az érintett kérelme alapján, erről indokolással ellátott tájékoztatást küld.

13. Kártérítés és felelősség

Minden olyan személy, aki a GDPR megsértésének eredményeként vagyoni vagy nem vagyoni kárt szenved, jogosult az elszenvedett kár megtérítésére a vonatkozó jogszabályok szerint. Az Adatkezelő mentesül a felelősség alól, amennyiben bizonyítani tudja, hogy a kárt előidéző eseményért semmilyen módon nem felelős.

14. Jogorvoslati lehetőségek

Az érintett jogosult panaszt tenni a felügyeleti hatóságnál:

Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)

1055 Budapest, Falk Miksa utca 9–11.

Levelezési cím: 1363 Budapest, Pf. 9.

www.naih.hu

[email protected]

Az érintett jogosult továbbá bírósághoz fordulni, ha megítélése szerint személyes adatainak kezelése sérti a hatályos jogszabályokat.

15. Záró rendelkezések

Jelen Adatkezelési Tájékoztató 2026. május 29. napjától hatályos. Az Intelstellar Park Kft. fenntartja a jogot arra, hogy jelen tájékoztatót egyoldalúan módosítsa. A módosítások a weboldalon történő közzététellel lépnek hatályba.

16. A tájékoztató módosítása

Az Intelstellar Park Kft. fenntartja a jogot jelen Adatkezelési Tájékoztató módosítására. Az aktuális verzió minden esetben a www.intelstellar.com weboldalon érhető el.

Intelstellar Park Limited Liability Company (hereinafter referred to as the "Company" or the "Controller") is committed to protecting personal data and respecting the privacy rights of all individuals who interact with its website and services. The purpose of this Privacy Notice is to provide transparent and comprehensive information regarding the processing of personal data through the website www.intelstellar.com, including the types of personal data collected, the purposes and legal bases of processing, retention periods, and the rights available to data subjects under applicable data protection laws. The Company processes personal data in accordance with applicable Hungarian and European Union legislation, including Regulation (EU) 2016/679 (GDPR).

1. Introduction

Intelstellar Park Kft. is committed to protecting personal data and respecting privacy rights. This Privacy Notice applies to the processing of personal data through the website www.intelstellar.com and is based on applicable Hungarian and European Union data protection law, in particular the GDPR.

2. Controller Information

Company Name: Intelstellar Park Limited Liability Company

Hungarian Name: Intelstellar Park Korlátolt Felelősségű Társaság

Short Name: Intelstellar Park Kft.

Registered Office: 8000 Székesfehérvár, III. Béla király tér 5., 3rd Floor, Door 1, Hungary

Tax Number: 25337772-2-07

Principal Business Activity: 7112 – Engineering Activities and Related Technical Consultancy

Website: www.intelstellar.com

Contact E-mail: [email protected]

Hosting Provider: Deebox Kft.

Hosting Provider Address: 1148 Budapest, Bánki Donát u. 60-62.

3. Applicable Legislation

The Company's processing of personal data is governed primarily by the following legislation:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR);
  • Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information of Hungary;
  • Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services;
  • Act C of 2003 on Electronic Communications;
  • any other applicable Hungarian and European Union legislation relating to data protection and privacy.

4. Principles of Data Processing

The Company processes personal data in accordance with the following principles:

  • lawfulness, fairness and transparency;
  • purpose limitation;
  • data minimisation;
  • accuracy;
  • storage limitation;
  • integrity and confidentiality;
  • accountability.

The Company only processes personal data that are necessary and proportionate for achieving a specific and legitimate purpose. Personal data are processed in a manner that ensures an appropriate level of security, including protection against unauthorised or unlawful processing, accidental loss, destruction or damage.

5. Data Processing Activities Related to the Website

5.1. Server Log Files

When visiting the website, certain technical information is automatically recorded by the web server.

Categories of Data Processed
  • IP address;
  • date and time of the visit;
  • URL of visited pages;
  • browser type and version;
  • operating system information;
  • referring website address.
Purpose of Processing
  • ensuring the secure operation of the website;
  • detecting and investigating technical incidents;
  • preventing unauthorised access and cyber security threats;
  • maintaining system integrity and stability;
  • troubleshooting technical errors.
Legal Basis

Article 6(1)(f) GDPR – legitimate interests pursued by the Controller. The Company has a legitimate interest in maintaining the security, availability and proper functioning of its website and information systems.

Retention Period

Server log data are retained for a maximum period of ninety (90) days unless a longer retention period is required for the investigation of a security incident or compliance with legal obligations.

5.2. Contacting the Company by E-mail

Visitors may contact the Company using the contact details published on the website.

Categories of Data Processed
  • name;
  • e-mail address;
  • company name (if provided);
  • telephone number (if provided);
  • content of the message;
  • any other personal information voluntarily supplied by the sender.
Purpose of Processing
  • responding to enquiries;
  • communicating with prospective business partners;
  • preparing business discussions and consultations;
  • taking steps prior to entering into a contract;
  • maintaining professional correspondence.
Legal Basis

Article 6(1)(b) GDPR – processing necessary to take steps at the request of the data subject prior to entering into a contract.

Retention Period

Correspondence and related personal data are retained for a maximum period of two (2) years following the last communication, unless a contractual relationship is established or legal obligations require longer retention.

5.3. Google Analytics

The website uses Google Analytics, a web analytics service provided by Google, to understand how visitors interact with the website and to improve the quality and effectiveness of the online content. Through Google Analytics, the Company may receive aggregated statistical information regarding:

  • website traffic volumes;
  • visitor demographics and geographical regions;
  • devices and browsers used by visitors;
  • duration of visits;
  • navigation patterns;
  • most frequently viewed pages.

The Company does not use Google Analytics to identify individual visitors. Google Analytics is activated only after the visitor has provided consent through the website's cookie management platform.

Legal Basis

Article 6(1)(a) GDPR – consent of the data subject.

Withdrawal of Consent

Visitors may withdraw their consent at any time by changing their cookie preferences. Withdrawal of consent shall not affect the lawfulness of processing carried out before such withdrawal.

5.4. Google Maps

The website may display map content provided by Google Maps. When Google Maps is loaded, Google may process certain technical information, including but not limited to IP address, browser information, device information, location-related information, and interaction data relating to map usage. Such processing is carried out by Google in accordance with its own privacy policies and terms of service. Further information regarding Google's processing of personal data can be found in Google's Privacy Policy.

6. Data Processors

The Company may engage third-party service providers to perform certain technical, administrative, or information technology-related functions connected to the operation of the website and the provision of its services. Such data processors may include, in particular:

  • the hosting service provider;
  • website developers and maintenance providers;
  • providers of website analytics services, including Google Analytics;
  • providers of cloud-based or information technology infrastructure services where applicable.

Data processors are authorised to process personal data solely on behalf of and in accordance with the documented instructions of the Controller. The Company ensures that all processors engaged provide appropriate guarantees regarding the implementation of suitable technical and organisational measures required under the GDPR.

7. Data Transfers and International Data Transfers

The Company may disclose personal data to third parties only in the following circumstances:

  • where required by applicable law;
  • in response to requests from competent authorities, courts, or public bodies;
  • to authorised data processors acting on behalf of the Company;
  • with the explicit consent of the data subject;
  • where necessary for the establishment, exercise, or defence of legal claims.

The Company does not sell, rent, or otherwise commercially disclose personal data to third parties. Certain services used on the website, including Google Analytics and Google Maps, may involve the transfer of personal data outside the European Economic Area (EEA). Where such transfers occur, the Company takes reasonable steps to ensure that appropriate safeguards are implemented in accordance with Chapter V of the GDPR. Such safeguards may include adequacy decisions adopted by the European Commission, Standard Contractual Clauses (SCCs), participation in approved international data transfer frameworks, and additional technical and organisational protection measures where appropriate.

8. Data Security

The Company is committed to maintaining the security and confidentiality of personal data. Appropriate technical and organisational measures are implemented to protect personal data against unauthorised access, accidental or unlawful destruction, loss, alteration, disclosure, misuse, corruption or unauthorised processing.

The security measures implemented by the Company may include, among others: access control systems; role-based authorisation management; secure authentication procedures; firewall protection; malware and antivirus protection; encrypted communications where appropriate; system monitoring and logging; regular backups; and periodic review of security procedures.

While the Company takes all reasonable precautions to protect personal data, no internet-based system can be guaranteed to be completely secure. Consequently, users should also take appropriate precautions when transmitting information electronically.

9. Rights of Data Subjects

Data subjects are entitled to exercise the rights granted by the GDPR and other applicable data protection legislation. Requests relating to personal data may be submitted to [email protected]. The Company will respond without undue delay and, in any event, within one month of receiving a valid request. Where necessary, this period may be extended by up to two additional months, taking into account the complexity and number of requests.

9/A. Right of Access

Data subjects have the right to obtain confirmation as to whether personal data concerning them are being processed. Where personal data are processed, the data subject has the right to access information including:

  • the purposes of processing;
  • categories of personal data concerned;
  • recipients or categories of recipients;
  • retention periods;
  • rights available under the GDPR;
  • the source of the data;
  • information concerning automated decision-making, where applicable.

Upon request, the Company shall provide a copy of the personal data undergoing processing.

9/B. Right to Rectification

Data subjects have the right to request the correction of inaccurate personal data and the completion of incomplete personal data. The Company shall take reasonable steps to ensure that inaccurate or outdated information is corrected without undue delay.

9/C. Right to Erasure ("Right to be Forgotten")

Data subjects may request the deletion of their personal data where:

  • the data are no longer necessary for the purposes for which they were collected;
  • consent has been withdrawn and there is no other legal basis for processing;
  • the processing is unlawful;
  • erasure is required by applicable law;
  • the data subject has successfully objected to processing.

This right is not absolute and may be limited where continued processing is required by law or for the establishment, exercise, or defence of legal claims.

9/D. Right to Restriction of Processing

Data subjects may request the restriction of processing where:

  • the accuracy of personal data is contested;
  • processing is unlawful but erasure is opposed;
  • the Controller no longer requires the data but the data subject requires them for legal claims;
  • an objection to processing is pending verification.

Where processing is restricted, personal data may generally only be stored unless further processing is permitted by law.

9/E. Right to Data Portability

Where applicable, data subjects have the right to receive personal data they have provided in a structured, commonly used, and machine-readable format. Subject to technical feasibility, data subjects may also request the direct transmission of such data to another controller.

9/F. Right to Object

Where processing is based on the legitimate interests of the Controller, data subjects may object at any time on grounds relating to their particular situation. The Company shall cease processing unless it demonstrates compelling legitimate grounds overriding the interests, rights, and freedoms of the data subject.

9/G. Right to Withdraw Consent

Where processing is based on consent, data subjects may withdraw such consent at any time. Withdrawal shall not affect the lawfulness of processing carried out prior to the withdrawal.

9/H. Automated Decision-Making and Profiling

The Company does not engage in automated decision-making or profiling that produces legal effects concerning individuals or similarly significantly affects them.

10. Personal Data Breaches

The Company takes all reasonable steps to prevent personal data breaches and to minimise their potential impact. A personal data breach may include, among other things:

  • unauthorised access to personal data;
  • accidental loss of personal data;
  • destruction of personal data;
  • unauthorised disclosure of personal data;
  • unauthorised alteration of personal data.

In the event of a personal data breach, the Company shall act in accordance with Articles 33 and 34 of the GDPR and, where required, notify the competent supervisory authority and affected individuals.

11. International Data Transfers

Certain services used by the website may involve transfers of personal data to countries outside the European Economic Area, including the United States. Where such transfers occur, the Company relies on safeguards recognised by the GDPR, including adequacy decisions adopted by the European Commission, Standard Contractual Clauses, and other legally recognised transfer mechanisms. The Company continuously monitors developments in international data protection law and adjusts its practices where necessary.

12. Procedural Rules

Requests submitted by data subjects shall be handled free of charge unless they are manifestly unfounded or excessive. Where the Company decides not to act upon a request, the data subject shall be informed of the reasons for the decision, available remedies, and the right to lodge a complaint with a supervisory authority. Responses are generally provided electronically unless another format is specifically requested.

13. Liability and Compensation

Any individual who has suffered material or non-material damage as a result of an infringement of the GDPR may be entitled to compensation in accordance with applicable law. The Company shall not be liable where it demonstrates that it is not responsible for the event giving rise to the damage. Nothing in this Privacy Notice shall limit any statutory rights available to data subjects under applicable legislation.

14. Legal Remedies

If a data subject believes that the processing of personal data violates applicable law, he or she may lodge a complaint with the competent supervisory authority.

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)

1055 Budapest, Falk Miksa utca 9–11., Hungary

Postal Address: 1363 Budapest, Pf. 9.

www.naih.hu

[email protected]

In addition, data subjects have the right to seek judicial remedy before the competent courts.

15. Final Provisions

This Privacy Notice shall enter into force on 29 May 2026. The Company reserves the right to amend this Privacy Notice at any time in order to reflect changes in legislation, regulatory guidance, business operations, or data processing activities. Any amendments shall become effective upon publication on the website unless otherwise required by law.

16. Updates to this Privacy Notice

The most recent version of this Privacy Notice is always available on www.intelstellar.com. Visitors are encouraged to review this Privacy Notice periodically to remain informed about how personal data are processed and protected.