Privacy Policy

Effective from: August 10, 2026

1. The Data Controller

Data Controller's name: Dr. Judit Marinovszky, attorney-at-law

Registered office: 82 Dózsa György út, Zebegény, 2627.

Phone: +36 30 222 3676

E-mail: judit.bankuti.dr@gmail.com

Tax number: 58562244-1-33

Chamber Identification Number (KASZ): 36057051

Registering regional bar association: Bar Association of Pest County

Address of the territorial chamber: 1132 Budapest, Visegrádi utca 3. II/1.

Website: https://lexpraxis.hu/

(hereinafter: Data Controller).

The Data Controller processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), Act CXII of 2011 on the Right to Information Self-Determination and Freedom of Information (Info Act), Act LXXVIII of 2017 on the Professional Activities of Attorneys-at-Law, Act LIII of 2017 on the Prevention and Combating of Money Laundering and Terrorist Financing (Pmt.), as well as other legal provisions applicable to specific data processing activities.

2. Principles of Data Processing

The Data Controller processes personal data in accordance with the principles set out in Article 5 of the GDPR, in particular lawfully, fairly and in a transparent manner; for specified, explicit and legitimate purposes; to the extent and for the period necessary; accurately and, where necessary, kept up to date; and by applying appropriate technical and organizational measures.

3. Data processing related to visiting the website

When visiting the website, technical data necessary for operation and IT security may be processed, in particular the IP address, the time of the visit, browser and operating system data, and the pages viewed.

The purpose of data processing is to ensure the operation and security of the website, resolve technical errors, and prevent and investigate security incidents.

The legal basis for data processing is the legitimate interest pursuant to Article 6(1)(f) of the GDPR.

4. Contact via email

The data subject may contact the Data Controller via the e-mail address indicated on the website. In particular, the name, e-mail address, telephone number, the content of the message, and any other data voluntarily provided by the data subject may be processed.

The purpose of data processing is to answer the inquiry, establish contact, and prepare for the conclusion of the attorney-client agreement and the requested legal service.

The legal basis for the data processing in the given case is point (b), (c), or (f) of Article 6(1) of the GDPR.

The Data Controller requests that the data subject provide only the personal data necessary for the assessment of the inquiry.

5. Data processing related to the preparation and performance of the attorney's retainer

The Data Controller processes the personal data necessary for the provision of legal services, in particular the client's identification, address, and contact details, data related to the subject matter of the case, as well as personal data contained in documents and other case files.

The purpose of data processing is, in particular, legal advice, drafting and countersigning of documents, legal representation, court and authority proceedings, company proceedings, real estate registration administration, management of attorney escrow, enforcement or defense of legal claims, as well as the fulfillment of legal obligations.

Depending on the specific data processing operation, the legal basis for data processing is primarily point (b), (c) or (f) of Article 6(1) of the GDPR.

6. Attorney-client confidentiality

The Data Controller is obliged to maintain the confidentiality of facts, information, and data that have come to its knowledge in the course of practicing legal activities and that qualify as attorney-client privilege pursuant to the Act on the Legal Profession.

Pursuant to Section 9 of the Act on the Activities of Attorneys-at-Law, attorney-client privilege applies to all facts, information, and data of which a practitioner of legal activities has gained knowledge in the course of pursuing such activities. The obligation of attorney-client confidentiality shall remain in effect indefinitely even after the termination of the legal activities.

7. Special categories of personal data

During the practice of law, it may become necessary to process special categories of personal data pursuant to Article 9 of the GDPR. Such data may be processed exclusively in the presence of an appropriate legal basis and to the extent necessary for the fulfillment of the legal assignment, or for the establishment, exercise, or defense of legal claims.

8. Data processing related to the prevention of money laundering and terrorist financing

In matters falling within the scope of the Pmt. (Act on the Prevention and Combating of Money Laundering and Terrorist Financing), the Data Controller is required to process data relating to customer due diligence, identification, determination of the beneficial owner, risk assessment, and other statutory obligations.

The legal basis for data processing is Article 6, paragraph 1, point c of the GDPR, and, where necessary, the appropriate legal basis under Article 9 of the GDPR.

9. Client management and legal document handling

Based on the Act on the Activities of Attorneys-at-Law, the Data Controller maintains a mandatory case register of the matters handled by it. The retention period for the data processed in the case register and the attorney's files shall be governed by the provisions of the Act on the Activities of Attorneys-at-Law and other applicable legislation.

10. Data processing for accounting and tax purposes

The Data Controller also processes personal data in order to fulfill its accounting and tax obligations. The legal basis for the processing of data is point (c) of Article 6(1) of the GDPR. The retention of accounting documents is governed by Act C of 2000 on Accounting, and the retention of tax documents and records is governed by the provisions of Act CL of 2017 on the Rules of Taxation.

11. Data transfer and recipients of data

The Data Controller shall transmit personal data solely in the presence of an appropriate legal basis, to the extent necessary for the purpose of data processing. In the course of the performance of legal activities, data transmission may take place, in particular, to courts, authorities, prosecutor's offices, notaries public, bailiffs, the real estate authority, the court of registration, the Hungarian Bar Association and the competent territorial bar association, experts, other lawyers and law firms, accountants, as well as contributors approved by the client, provided that an appropriate legal basis exists therefor.

12. Data processor – hosting provider

Rackhost Zrt.

Headquarters: 41 Tisza Lajos körút, Szeged 6722.

Tax number: 25333572-2-06

Company registration number: 06-10-000489

E-mail: info@rackhost.hu

Website: www.rackhost.hu

Rackhost Zrt. may process personal data as a data processor on behalf of the Data Controller during the provision of hosting services.

13. E-mail service

The Data Controller uses the e-mail address judit.bankuti.dr@gmail.com. The processing of personal data contained in messages sent and received by e-mail takes place for the purpose of electronic contact, answering inquiries, fulfilling attorney assignments, and preserving attorney-client privilege.

14. Data Security

The Data Controller applies appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, transmission, disclosure, deletion, or loss.

15. Personal Data Breach

In the event of a personal data breach, the Data Controller acts in accordance with Articles 33–34 of the GDPR and other applicable legislation.

16. Data Subject Rights

Under the conditions set out in the GDPR, the data subject is entitled to request access to, rectification, erasure, and restriction of processing of their personal data, exercise the right to data portability under the specified terms, object to processing based on legitimate interests, and withdraw consent at any time where processing is based on consent.

The exercise of data subject rights may be restricted by applicable legislation—in particular, the Act on Legal Practice (Üttv.) and the Anti-Money Laundering Act (Pmt.).

17. Submission of Data Subject Requests

The data subject may submit their request using the following contact details:

Dr. Judit Marinovszky Attorney at Law

2627 Zebegény, Dózsa György út 82.

E-mail: judit.bankuti.dr@gmail.com

Phone: +36 30 222 3676

The Data Controller shall examine the request within the deadline specified in the GDPR and inform the data subject of the measures taken.

18. Legal Redress

National Authority for Data Protection and Freedom of Information (NAIH)

Headquarters: 1055 Budapest, Falk Miksa utca 9–11., Hungary

Mailing address: 1363 Budapest, Pf. 9.

E-mail: ugyfelszolgalat@naih.hu

Phone: +36 (1) 391-1400

The data subject is also entitled to seek judicial remedy pursuant to Article 79 of the GDPR and applicable Hungarian laws.

19. Cookies

Technically necessary cookies may be used for the operation of the website. Non-essential cookies, particularly those for statistical, marketing, or tracking purposes, may only be used under conditions compliant with relevant legislation, subject to prior consent where required.

20. Data Transfer to Third Countries

The Data Controller shall transfer personal data to a third country or an international organization only if the conditions set out in Chapter V of the GDPR are met.

21. Data Protection Officer

The Data Controller is not required to appoint a Data Protection Officer; therefore, no Data Protection Officer has been designated.

22. Applicable Laws

The data processing activities described in this policy are governed in particular by the following legislation:

• GDPR;

• Act CXII of 2011;

• Act LXXVIII of 2017;

• Act LIII of 2017;

• Act C of 2000;

• Act CL of 2017;

• Act CVIII of 2001;

• applicable bar association rules and regulations regarding legal practice.

23. Amendments to the Privacy Policy

The Data Controller reserves the right to amend this privacy policy, particularly in the event of changes in legislation, regulatory or bar association practice, or changes to the website or data processing procedures.

The currently effective privacy policy is accessible on the website.

Effective date: August 10, 2026