DR. LOJKÓ BENCE ZOLTÁN
INDIVIDUAL ATTORNEY

PRIVACY NOTICE

I. Details of the Data Controller

This privacy notice applies to the processing of personal data carried out by Dr. Bence Zoltán Lojkó, attorney-at-law (sole practitioner) (hereinafter: the Controller) in connection with the operation of the website https://ljklegal.hu (hereinafter: the Website).

Name of the Controller:
Dr. Bence Zoltán Lojkó, attorney-at-law (sole practitioner)

Bar registration number (KASZ):
36083618

Registered office:
1067 Budapest, Teréz körút 23. II/10.

E-mail address:
iroda@ljklegal.hu

Telephone number:
+36 70 630 7443

Website:
https://ljklegal.hu

Registering bar association:
Budapest Bar Association

The Controller carries out his legal practice in accordance with the applicable Hungarian legislation, in particular Act LXXVIII of 2017 on the Practice of Attorneys (the “Attorneys Act”), and Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: the GDPR). The Controller has not appointed a data protection officer (DPO), as the conditions set out in Article 37 of the GDPR are not met.

II. Purpose and Scope of this Notice

The purpose of this notice is to describe the most important information regarding the processing of personal data carried out in connection with the operation of the Website, in particular:

  • the purposes of the processing;
  • its legal basis;
  • the categories of personal data processed;
  • the duration of the processing;
  • any data processors and data transfers; and
  • the rights of data subjects and the available remedies.

This notice applies to all visitors of the Website, as well as to any natural person who contacts the Controller through the Website or via the contact details published on it.

The Controller processes personal data exclusively in accordance with the applicable legislation and with due regard to the principles of purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability.

III. Legislation Governing the Processing

In processing personal data, the Controller applies in particular the provisions of the following legislation:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR);
  • Act CXII of 2011 on the Right to Informational Self-Determination and on Freedom of Information (the “Privacy Act” / Infotv.);
  • Act LXXVIII of 2017 on the Practice of Attorneys (the “Attorneys Act” / Üttv.);
  • Act CVIII of 2001 on Certain Issues of Electronic Commerce Services;
  • Act C of 2003 on Electronic Communications;
  • and other applicable Hungarian and European Union legislation.

IV. Important Information Concerning the Use of the Website

The Website contains information of an informative nature only regarding the Controller’s legal practice and the legal services he provides.

Contacting the Controller through the Website – including in particular completing the contact form, sending an e-mail or making a telephone enquiry – does not in itself create an attorney-client (retainer) relationship, does not constitute acceptance of an engagement, and does not result in the provision of legal advice.

An attorney-client (retainer) relationship is created exclusively by a separate agreement between the parties to that effect.

If a visitor of the Website sends documents or other information to the Controller in the course of making contact, such data are processed solely for the purpose of handling the enquiry and preparing a possible engagement.

V. Data Processing Related to the Operation of the Website

Where the legal basis of the processing is the Controller’s legitimate interest (Article 6(1)(f) GDPR), the Controller has carried out the related legitimate-interest (balancing) test, the outcome of which the data subject may request information about via the contact details set out in Section I.

1. Visiting the Website

When the Website is visited, technical data necessary for the operation of the Website may be automatically logged. Such data are processed in order to ensure the secure operation of the Website, protect the IT system, detect errors and maintain the uninterrupted operation of the service.

The automatically processed data may include in particular:

  • the data subject’s IP address;
  • the time of the visit;
  • the address (URL) of the page visited;
  • the type and version of the browser used;
  • the type of the operating system;
  • the address of the referring page (referrer);
  • other technical data transmitted by the browser.

The Controller does not use these data to identify visitors of the Website individually.

Purpose of processingEnsuring the secure operation of the Website, protecting the IT system, detecting errors and preventing abuse.
Legal basisArticle 6(1)(f) GDPR – the legitimate interest of the Controller.
Data processedIP address, time, URL, browser, operating system and other technical log data.
Duration of processingNo longer than 30 days, in accordance with the logging practice applied by the hosting provider.
RecipientsThe hosting provider, acting as data processor.

2. Contact via the Website

The contact form available on the Website enables interested persons to contact the Controller directly.

Completing the form is voluntary.

The data subject is only required to provide personal data that are necessary for responding to the enquiry.

The Controller processes the personal data provided in the course of making contact solely for the purpose of responding to the enquiry, preparing a possible engagement and maintaining contact.

The Controller draws attention to the fact that, where possible, no special categories of personal data or documents that are not necessary for the initial contact should be sent via the contact form.

Purpose of processingEnabling contact, responding to the enquiry, and preparing a possible engagement (retainer relationship).
Legal basis– Article 6(1)(b) GDPR, where the enquiry is aimed at taking steps prior to entering into a contract;
– Article 6(1)(f) GDPR, where the enquiry concerns a general query or contact request.
Data processedName, e-mail address, telephone number (if provided), the content of the message, and any other data voluntarily provided by the data subject.
Duration of processingNo longer than 1 year after the enquiry has been closed, unless legislation or an established engagement justifies longer retention.
RecipientsThe Controller and the data processors involved in operating the website.

3. Electronic Correspondence

The Controller processes personal data contained in enquiries sent to him electronically for the purpose of responding to the enquiry, maintaining contact and – where necessary – preparing an attorney-client (retainer) relationship.

The Controller requests that only personal data necessary for assessing the enquiry be communicated by e-mail.

If an attorney-client (retainer) relationship is established between the parties, any further processing shall be governed by the data-processing rules applicable to the engagement.

Purpose of processingMaintaining contact and responding to enquiries.
Legal basisArticle 6(1)(b) and Article 6(1)(f) GDPR.
Data processedPersonal data contained in the correspondence, attachments, and contact details.
Duration of processingNo longer than 1 year after the enquiry has been closed, or, where an engagement is established, for the period prescribed by the applicable legislation.
RecipientsThe Controller and the data processors involved in operating the Website and the electronic mail service.

4. Google Maps

The Google Maps map service is used on certain pages of the Website to facilitate orientation.

When Google Maps is used, Google may process certain technical data, in particular the IP address and data relating to the device and the browser.

Google Maps is loaded only after the data subject has given consent, provided the data subject grants such consent via the cookie management interface.

Purpose of processingDisplaying the geographical location of the office shown on the Website.
Legal basisArticle 6(1)(a) GDPR – the consent of the data subject.
Data processedIP address, browser data, technical data, and further data collected by Google.
Duration of processingUntil the data subject withdraws consent; information on the retention periods applied by Google is available in Google’s privacy policy.
RecipientGoogle Ireland Limited.
Transfers to third countriesData may be transferred outside the European Economic Area to companies within the Google group, subject to safeguards compliant with Chapter V of the GDPR.

5. Google reCAPTCHA

To protect the contact form on the Website, the Controller uses the Google reCAPTCHA service.

The purpose of reCAPTCHA is to determine whether the form is being used by a natural person or by an automated program.

When the service is used, Google may process various technical data.

Purpose of processingProtecting the IT system of the Website and preventing automated abuse.
Legal basisArticle 6(1)(f) GDPR – the legitimate interest of the Controller.
Data processedIP address, mouse movements, browser and device data, and other technical data required by Google for the operation of the service.
Duration of processingThe retention period applied by Google; details are available in Google’s privacy policy.
RecipientGoogle Ireland Limited.
Transfers to third countriesData may be transferred outside the European Economic Area to companies within the Google group, subject to safeguards compliant with Chapter V of the GDPR.

6. Cookies

The Website uses cookies to ensure its proper functioning, improve the user experience and enable statistical analyses.

For managing cookies, the Controller uses the Complianz cookie management system.

When the Website is first opened, a cookie management interface is displayed, allowing visitors to accept or reject cookies by category.

With the exception of strictly necessary cookies, the Website places cookies only on the basis of the data subject’s prior consent.

Consent may be modified or withdrawn at any time via the cookie settings available on the Website.

Main categories of cookies used on the Website

  • cookies necessary for operation;
  • statistical cookies (Google Analytics);
  • cookies related to external services (e.g. Google Maps).

The Website uses Google Consent Mode v2 technology to ensure that Google services operate in accordance with the consents given by the data subject.

The data subject is entitled to modify or withdraw consent at any time via the cookie settings available on the Website. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.

A detailed list of the cookies used on the Website – including their names, purposes, providers and lifetimes – is available on the cookie management interface of the Website and in the cookie notice published there.

7. Google Analytics 4

The Controller uses the Google Analytics 4 service to analyse the traffic of the Website.

The service enables the collection of statistical data on the use of the Website, in particular the analysis of the number of visits, the most popular pages and the way the Website is used.

The Controller uses the Google Analytics service exclusively on the basis of the data subject’s prior consent.

The information collected by Google Analytics is not used by the Controller to identify visitors of the Website individually.

Purpose of processingAnalysing the use of the Website, preparing statistics and improving the services.
Legal basisArticle 6(1)(a) GDPR – the consent of the data subject.
Data processedCookie identifiers, IP address (as processed by Google), browser data, device data, visit data, page views, events.
RecipientGoogle Ireland Limited.
Transfers to third countriesData may be transferred to companies within the Google group, subject to safeguards compliant with Chapter V of the GDPR.
Retention periodNo longer than 14 months (the data retention period set in the Google Analytics 4 service); thereafter, the data are retained only as anonymous, aggregated statistics.

VI. Data Processors

In operating the Website, the Controller engages data processors for the performance of certain tasks. Data processors may process personal data exclusively on the instructions of the Controller and in accordance with the applicable data protection legislation.

1. Hosting Provider

The hosting of the Website is provided by the following service provider:

Websupport Magyarország Kft.
Registered office: 1119 Budapest, Fehérvári út 97–99.
Website: https://www.websupport.hu

The data processor’s task is to provide the server infrastructure required for the operation of the Website and the technical storage of the data stored on the Website.

2. Google Ireland Limited

In the course of operating the Website, the Controller uses certain services provided by Google Ireland Limited, in particular:

  • Google Analytics 4;
  • Google Maps;
  • Google reCAPTCHA.

When Google’s services are used, certain personal data may be processed in accordance with Google’s data processing terms.

Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland

Google’s privacy policy:
https://policies.google.com/privacy

3. Complianz B.V.

The Controller uses the Complianz system to manage cookie consents.

Complianz B.V.
Registered office: Kalmarweg 14-5, 9723 JG Groningen, the Netherlands
Website: https://complianz.io

The tasks of Complianz are:

  • managing cookie categories;
  • keeping records of consents;
  • supporting the operation of Google Consent Mode.

4. WordPress and Elementor

The Website operates using the WordPress content management system and the Elementor website builder plugin.

The Elementor contact form transmits the data provided by the visitor exclusively to the Controller.

Elementor does not itself become a data controller.

VII. Transfers of Data to Third Countries

When certain Google services used in the operation of the Website (in particular Google Analytics, Google Maps and Google reCAPTCHA) are used, certain personal data may also be transferred to countries outside the European Economic Area.

Such data transfers are governed by the appropriate data protection safeguards provided by Google. The detailed rules of the data transfers and the safeguards applied are available in Google’s privacy policy as in force from time to time. Where applicable, the legal basis of the transfer is provided in particular by:

  • an adequacy decision of the European Commission;
  • standard contractual clauses adopted by the European Commission (Standard Contractual Clauses);
  • certification under the EU–US Data Privacy Framework.

VIII. Data Security

The Controller takes all reasonable technical and organisational measures to ensure an appropriate level of protection of personal data.

In this context, the Controller in particular:

  • applies access-rights management;
  • uses password-protected IT systems;
  • uses HTTPS encrypted connections;
  • regularly updates the software used for the operation of the Website;
  • ensures the protection of personal data against unauthorised access, alteration, disclosure, erasure or destruction.

When selecting data processors, the Controller also takes into account whether they provide adequate data security guarantees.

IX. Automated Decision-Making and Profiling

In connection with the data processing related to the Website, the Controller does not apply automated decision-making or profiling within the meaning of Article 22 of the GDPR.

X. Rights of Data Subjects

Under the provisions of the GDPR, the data subject has in particular the following rights:

  • to request information about the processing of his or her personal data;
  • to request access to the personal data relating to him or her;
  • to request their rectification;
  • to request their erasure;
  • to request the restriction of processing;
  • to object to processing based on legitimate interest;
  • to exercise the right to data portability;
  • to withdraw consent at any time, where the processing is based on consent.

The Controller assesses data subjects’ requests without undue delay, and in any event within one month of receipt of the request.

XI. Remedies

If the data subject considers that the processing of his or her personal data infringes the law, he or she may lodge a complaint with:

Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság – NAIH)

Registered office: 1055 Budapest, Falk Miksa utca 9–11.

Postal address: 1363 Budapest, Pf. 9.

Telephone: +36 (1) 391-1400

E-mail: ugyfelszolgalat@naih.hu

Website: https://www.naih.hu

The data subject is also entitled to bring the matter before a court in accordance with the provisions of the GDPR and the Privacy Act (Infotv.).

XII. Amendment of this Notice

The Controller is entitled to amend this privacy notice unilaterally where this is justified by a change in legislation, a change in the operation of the Website, or a change in the services used.

The privacy notice in force from time to time is continuously available on the Website.

This privacy notice is effective from 13 July 2026.