PRIVACY POLICY
Dr. Dong Xinrui, Sole Practitioner Attorney-at-Law
Effective date: 1 November 2025
1. GENERAL PROVISIONS
This Privacy Notice (hereinafter referred to as the “Notice”) applies to the personal data collected and processed about you (hereinafter referred to as the “Data Subject”) by Dr. Dong Xinrui, sole practitioner attorney-at-law (registered office: 1052 Budapest, Deák Ferenc tér 3., Meyer & Levinson floor; KASZ: 36082451; tax number: 91011215-1-41; hereinafter referred to as the “Data Controller”).
The Data Subject may exercise the rights set out in this Notice via the following contact details of the Data Controller:
-
Phone: +36-30-956-6866
2. ACKNOWLEDGEMENT AND ACCEPTANCE OF THIS NOTICE
By providing the required personal data, the Data Subject expressly declares that they have read and expressly accepted the version of this Notice in force at the time of providing the data.
Accordingly, the Data Subject consents to the processing of their personal data and acknowledges that, in the framework of a subsequent legal mandate, the Data Controller may also process personal data in order to comply with its statutory obligations.
3. DEFINITIONS
-
Personal data: any information relating to an identified or identifiable natural person (Data Subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, number, location data, online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
-
Consent: any freely given, specific, informed and unambiguous indication of the Data Subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
-
Data controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its designation may be provided for by Union or Member State law.
-
Processing: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
-
Data processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller.
-
Data transfer: making personal data available to a specific third party.
-
Data erasure: rendering personal data unrecognisable in such a way that its restoration is no longer possible.
-
Third party: a natural or legal person, public authority, agency or body other than the Data Subject, the Data Controller, the Data Processor, or persons who, under the direct authority of the Data Controller or Data Processor, are authorised to process personal data.
-
Personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
4. DATA PROTECTION PRINCIPLES
-
Lawfulness, fairness and transparency: personal data shall be processed lawfully, fairly and in a transparent manner in relation to the Data Subject.
-
Purpose limitation: personal data shall be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall not be considered incompatible with the initial purposes in accordance with Article 89(1) of the GDPR.
-
Data minimisation: personal data shall be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed.
-
Accuracy: personal data shall be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that inaccurate personal data are erased or rectified without delay.
-
Storage limitation: personal data shall be kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the personal data are processed, unless further storage is required for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) of the GDPR, subject to appropriate technical and organisational measures.
-
Integrity and confidentiality: personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
5. CATEGORIES OF DATA PROCESSED, PURPOSE, LEGAL BASIS AND DURATION OF PROCESSING
* The Data Controller uses the invoicing software of KBOSS.hu Kereskedelmi és Szolgáltató Kft. (www.szamlazz.hu) for issuing invoices.
Information on the Use of Cookies
The Data Controller uses cookies that are strictly necessary for the secure operation of the website and cookies that support its operation (functional cookies).
The information collected by cookies does not identify visitors personally but makes their computer and internet connection recognisable during subsequent visits or while browsing other websites.
The following third-party cookies, independent of the Data Controller, may collect personal data on the website: Google Analytics, Wix.com. These cookies are necessary for secure operation and functionality and record analytical data such as website traffic, browsing duration and location.
The website may contain links to and from external servers. External service providers (such as Instagram) may use their own cookies, record IP addresses and other data, and display advertising content.
-
Instagram
Purpose: access to social media services
Privacy policy: https://help.instagram.com/1896641480634370
Providing data via cookies is not mandatory. Cookies may be disabled through browser settings; however, disabling all cookies may affect website functionality. Consent to cookie use may be withdrawn at any time, without affecting the lawfulness of processing prior to withdrawal.
6. PROFILING
Dr. Dong Xinrui, sole practitioner attorney-at-law, does not apply automated decision-making, does not create profiles based on available data, and does not use personal data for direct marketing purposes.
7. RECIPIENTS OF PERSONAL DATA, THIRD-COUNTRY RECIPIENTS
For telephone communication, the Data Controller uses Yettel Magyarország Zrt. (registered office: 2045 Törökbálint, Pannon út 1.) as a data processor; for postal services, Magyar Posta Zrt. (registered office: 1138 Budapest, Dunavirág utca 2–6.).
The Data Controller’s hosting provider is Microsoft Office 365 (registered office: Redmond, Washington; privacy policy: https://privacy.microsoft.com/hu-hu/privacystatement).
For website development and operation, the Data Controller uses Wix.com Ltd. (40 Namal Tel Aviv St., Tel Aviv 6350671, Israel) as a data processor. The European Commission has recognised Israel as ensuring an adequate level of data protection. Wix.com Inc. ensures appropriate safeguards through Standard Contractual Clauses in accordance with Commission Decision 2010/87/EU.
8. DATA CONTROLLER’S PRESENCE ON SOCIAL MEDIA
The Data Controller is present on Instagram. Visitors may follow or unfollow the page using the respective links on the platform.
9. DATA SECURITY MEASURES
The Data Controller does not link information stored in cookies with personal data provided during contact. The Data Controller takes all necessary measures to ensure data security, including protection against unauthorised access, alteration, disclosure, deletion or destruction, as well as accidental loss or damage, using appropriate technical and organisational measures.
10. RIGHTS OF DATA SUBJECTS
If you have any questions or objections regarding the processing of your data, please contact the Data Controller at: xinrui.dong@dongandpartners.com
Rights include:
-
Right of access
-
Right to rectification
-
Right to erasure
-
Right to restriction of processing
-
Right to object
-
Right to lodge a complaint with a supervisory authority
In Hungary, the competent authority is:
National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9–11
Postal address: 1363 Budapest, Pf. 9
Phone: +36 (1) 391-1400
Email: ugyfelszolgalat@naih.hu
Website: www.naih.hu
The Data Subject may also initiate court proceedings.
11. AMENDMENT OF THIS NOTICE
The Data Controller reserves the right to unilaterally amend this Notice at any time. The current version is always available at www.dongandpartners.com.
Budapest, 1 November 2025

