Privacy Notice
on data processing related to the use of the smartsearch.hu website, contacting us and job applications
Smart Search International Kft.
This English version is a translation. In case of any discrepancy, the Hungarian version shall prevail.
Effective from 23rd September 2026 until revoked.
1. Introduction, purpose and scope
Smart Search International Vezetői Tanácsadó és Szolgáltató Kft. (“Controller”, “we”) operates the Hungarian and English language website available at https://smartsearch.hu (“Website”). The Controller provides executive search, middle management recruiting, leadership assessment, market mapping, business coaching and career counselling services. The purpose of the Website is to present the company and its services, to facilitate contact and to allow interested persons to submit their CV for future career opportunities.
In accordance with Article 13 of the General Data Protection Regulation (GDPR), this notice informs data subjects in a concise, transparent, intelligible and easily accessible form about what personal data we process in connection with the Website, contacting us and job applications, for what purposes, on what legal basis and for how long, to whom we disclose it, and what rights data subjects have.
This notice covers visits to the Website, contact initiated via the contact details published on the Website, CVs submitted as requested on the Job Opportunities page, and the secure operation of the Website. It does not cover the processing of data of candidates identified from other sources (e.g. professional social networks, referrals) during search assignments, about which the Controller provides separate information, nor the processing by third parties whose websites are linked from the Website.
2. Controller details and contact
| Company name | Smart Search International Vezetői Tanácsadó és Szolgáltató Kft. |
|---|---|
| Registered office | Maros utca 38. 3. em. 17., 1122 Budapest, Hungary |
| Company registration number | 01-09-192885 (Company Registry Court of the Budapest-Capital Regional Court) |
| Tax number | 24982599-2-43 |
| Represented by | András Péter Gábor, Managing Director |
| Data protection contact e-mail | agabor@smartsearch.hu |
| Website | https://smartsearch.hu |
The Controller is not obliged to designate a data protection officer under Article 37 GDPR and has not designated one. Data protection requests may be submitted using the contact details above.
3. Main applicable legislation
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR);
- Act CXII of 2011 on the right to informational self-determination and freedom of information (“Infotv.”);
- Act CVIII of 2001 on electronic commerce services (“Ekertv.”);
- Sections 10–11 of Act I of 2012 on the Labour Code – on the data that may be requested from job applicants;
- Act IV of 1991 on the promotion of employment and Government Decree 118/2001 (VI. 30.) – where the Controller’s activity qualifies as private employment agency activity;
- Act C of 2000 on accounting; Act V of 2013 on the Civil Code;
- Act C of 2003 on electronic communications – regarding access to information stored on terminal equipment (cookies).
4. Processing activities
4.1. Contact by e-mail and telephone
| Purpose | Receiving and answering enquiries and requests for proposals via the contact details published on the Website (e-mail, telephone), agreeing on the content of an assignment, preparing a possible contract and maintaining business contact. |
|---|---|
| Data processed | Name; e-mail address; telephone number; employer and position (if provided); content of the message and any further data voluntarily provided therein; time of correspondence. |
| Legal basis | For enquiries aimed at concluding a contract, Article 6(1)(b) GDPR (steps prior to entering into a contract); for other enquiries and for contact persons of legal entities, legitimate interest under Article 6(1)(f) GDPR (answering enquiries, business communication). |
| Retention period | If no contract is concluded: 1 year after answering the enquiry. If a contract is concluded: 5 years after termination of the relationship (Civil Code limitation period); accounting documents: 8 years under Section 169(2) of the Accounting Act. |
| Nature of data provision | Voluntary; without it, the enquiry cannot be answered. |
The Website has no contact form; it contains a link (mailto) to the Controller’s e-mail address, so messages are sent from the data subject’s own e-mail client directly to the Controller’s Microsoft 365 based mail system.
4.2. Job applications, submission of CVs (Job Opportunities)
| Purpose | Receiving CVs requested on the Job Opportunities page; assessing the applicant’s suitability for current or future positions of the Controller’s clients; keeping in contact with the applicant; subject to the applicant’s explicit consent, recording the applicant in the candidate database and presenting the applicant to a client. |
|---|---|
| Data processed | Name; contact details (e-mail address, telephone number, town of residence); data contained in the CV and cover letter (education, professional experience, employers, language skills, competences, salary expectations, link to professional social media profile); a photograph if voluntarily provided; assessments and interview notes relating to the application. |
| Legal basis | Assessment of the application and communication: consent under Article 6(1)(a) GDPR, given by voluntarily sending the CV, and steps prior to entering into an employment contract [Article 6(1)(b)]. For recording in the candidate database and for disclosure to a specific client (prospective employer), the Controller always requests prior, explicit, position-specific consent. |
| Retention period | Until consent is withdrawn, but no longer than 2 years after the last contact; after that the data are deleted unless the applicant consents to an extension. |
| Nature of data provision | Voluntary; without it, the application cannot be assessed. |
Please do not include special categories of personal data (e.g. data concerning health, religious or philosophical beliefs, trade union membership) or identity document numbers in your CV. Sending a photograph is not a condition for assessing an application.
Only the Controller’s staff responsible for recruitment have access to CVs. The Controller discloses applicants’ data to a client only with the applicant’s prior consent for the specific position; the client acts as an independent controller of the data disclosed.
4.3. Server logs and Website security
| Purpose | Ensuring the secure and proper operation of the Website, detecting and blocking unauthorised access attempts and abusive or automated traffic, investigating malfunctions. |
|---|---|
| Data processed | IP address; time of access; URL visited; browser and operating system type (user agent); referring URL; HTTP status code; events recorded by the security plugin (Wordfence) about blocked requests. |
| Legal basis | Article 6(1)(f) GDPR – the Controller’s legitimate interest in protecting the Website, the data stored on it and its visitors, and in ensuring continuous availability. |
| Retention period | Up to 30 days; in case of a suspected security incident, until the investigation is closed. |
| Nature of data provision | Logging is a technical necessity of operating the Website. |
5. Cookies and external content
A cookie is a small data file placed on the visitor’s device by the Website. The Website currently does not place cookies in visitors’ browsers and does not use analytics or marketing services (e.g. Google Analytics, Meta Pixel). Cookies are only created for editors logged in to the Website’s administration interface:
| Cookie name / group | Purpose | Type | Lifetime |
|---|---|---|---|
| wordpress_logged_in_*, wordpress_sec_*, wp-settings-* | Identifying the logged-in editor, storing interface settings | Strictly necessary | Session or up to 1 year |
| wfwaf-authcookie-*, wfls-* | Operation of the security plugin (firewall, two-factor authentication) | Strictly necessary | Session / up to 30 days |
The legal basis for strictly necessary cookies is Article 6(1)(f) GDPR and Section 155(4) of the Electronic Communications Act. The Website loads its fonts (Alegreya, Alegreya Sans) from the Google Fonts service; in doing so, the visitor’s browser connects to Google’s servers, which for technical reasons receive the visitor’s IP address. Google Fonts does not set cookies.
6. Processors and recipients
The Controller uses the following processors. Processors do not make independent decisions and act solely under their contract with, and the instructions of, the Controller.
| Processor | Registered office | Subject matter and data processed |
|---|---|---|
| Hostinger International Ltd. | 61 Lordou Vironos Street, 6023 Larnaca, Cyprus | Web hosting: data stored on the Website and server log files. Servers are located in Germany, backups in France. |
| Microsoft Ireland Operations Limited | One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland | Microsoft 365 (Exchange Online) e-mail and storage: incoming e-mails, attached CVs and contact data. |
| ININET Internet Kft. | Szinyei Merse utca 10., 1063 Budapest, Hungary | Registration of the smartsearch.hu domain name and DNS service (technical data of name resolution requests). |
| Valakimegcsinálja.hu Online Kereskedelmi Kft. | Szent László út 32. 4. em. 27., 1135 Budapest, Hungary (tax no. 25782677-2-41) | Website development, maintenance, IT support and troubleshooting; may access data stored on the Website to the extent necessary. |
Third-party service: the Google Fonts service is provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland); when fonts are loaded, Google processes the visitor’s IP address under its own privacy terms.
Recipients: applicants’ data are disclosed – exclusively with the data subject’s prior consent – to those clients (prospective employers) of the Controller for whose position the applicant applies or is proposed. Otherwise, the Controller discloses personal data to third parties only where required by law (e.g. at the request of an authority).
7. Transfers to third countries
The Controller stores and processes personal data primarily within the European Economic Area. When using Microsoft and Google services, data may also be transferred to the United States; such transfers are based on the European Commission’s adequacy decision on the EU–US Data Privacy Framework or on standard contractual clauses adopted by the European Commission. The Controller transfers candidate data to a client outside the EEA only with the data subject’s explicit consent and appropriate safeguards.
8. Security measures
In accordance with Article 32 GDPR, the Controller implements appropriate technical and organisational measures, in particular:
- the Website is available only via encrypted (HTTPS/TLS) connections with an automatically renewed certificate;
- a web application firewall (Wordfence WAF) detects and blocks unauthorised access attempts;
- the administration interface can be protected with two-factor authentication; passwords are stored only in hashed form;
- user enumeration requests are blocked and the XML-RPC interface is disabled;
- the hosting provider makes daily automated backups of the Website and its database, stored on servers in the European Union;
- the Website’s core, theme and plugins receive regular security updates;
- access to the mail system and to CVs is limited to those who need it for their duties.
In the event of a personal data breach, the Controller notifies the supervisory authority without undue delay and, where feasible, within 72 hours, unless the breach is unlikely to result in a risk. Where the breach is likely to result in a high risk, the Controller also informs the data subjects.
9. Data subject rights
- Right of access (Article 15 GDPR): you may request information on and a copy of your personal data, the purposes, recipients, retention period and your rights.
- Right to rectification (Article 16): you may request correction of inaccurate data and completion of incomplete data.
- Right to erasure (Article 17): you may request erasure if the data are no longer needed, you withdraw your consent, or the processing is unlawful; erasure cannot be requested for data required to comply with a legal obligation (e.g. accounting records).
- Right to restriction (Article 18): you may request restriction if you contest accuracy, the processing is unlawful or you have objected.
- Right to data portability (Article 20): you may receive data processed by automated means on the basis of consent or contract in a structured, machine-readable format and request its transmission to another controller.
- Right to object (Article 21): you may object to processing based on legitimate interest; we will stop unless there are compelling legitimate grounds that override your interests.
- Right to withdraw consent (Article 7(3)): you may withdraw your consent – in particular to being kept in the candidate database – at any time, free of charge and without giving reasons, without affecting the lawfulness of prior processing.
Requests may be submitted using the contact details in Section 2. We respond without undue delay and in any event within one month of receipt; this period may be extended by two further months where necessary, in which case we inform you within one month. Information and action are free of charge. We may ask you to confirm your identity before fulfilling a request.
10. Remedies
If you believe that the processing of your personal data infringes the law, you may lodge a complaint with the Controller. You also have the following remedies:
10.1. Complaint to the supervisory authority
| Authority | Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) |
|---|---|
| Address | Falk Miksa utca 9-11., 1055 Budapest, Hungary |
| Postal address | 1363 Budapest, Pf.: 9. |
| Telephone | +36 (1) 391-1400 |
| ugyfelszolgalat@naih.hu | |
| Website | www.naih.hu |
10.2. Court proceedings
You may bring an action before the courts. The regional court (törvényszék) has jurisdiction; at your choice, proceedings may also be brought before the regional court of your place of residence or stay.
11. Automated decision-making and profiling
The Controller does not carry out decision-making based solely on automated processing within the meaning of Article 22 GDPR – including automated screening of applicants – and does not use profiling. Applicants are always assessed with human involvement.
12. Children’s data
The Website’s services are not directed at persons under 16, and the Controller does not knowingly collect their data. If such data come to the Controller’s knowledge, they are deleted without delay.
13. Amendments and publication
The Controller reserves the right to amend this notice unilaterally, in particular in the event of changes in legislation, regulatory guidance, the Website’s functions or the service providers used. The notice in force is always available on the Website.
Budapest, 23rd September 2026
Smart Search International Kft.