Data protection
Data controller
Name: A & P Ltd.
Headquarters: 9027 Győr, Csonka János Street 14.
Mailing address, complaint handling: 9027 Győr, Csonka János Street 14.
E-mail: hello@artandpress.hu
Phone number: +36 20 230 5180
Website: http://artandpress.hu
Hosting provider
Name: Shopify Inc.
Mailing address: 151 O'Connor Street, Ground floor, Ottawa, Ontario, K2P 2L8, Canada
Email address: email@email.shopify.com
Description of data processing carried out during the operation of the webshop
This document contains all relevant data management information regarding the operation of the webshop, in accordance with the General Data Protection Regulation of the European Union 2016/679 (hereinafter: Regulation, GDPR) and Act CXII of 2011 (hereinafter: Infotv.).Information about the use of cookies
What are cookies?
The Data Controller uses so-called cookies when visiting the website. A cookie is a package of information consisting of letters and numbers that our website sends to your browser in order to save certain settings, make our website easier to use and help us collect some relevant, statistical information about our visitors.
Some cookies do not contain personal information and are not suitable for identifying an individual user, but some contain a unique identifier - a secret, randomly generated string of numbers - that is stored on your device, thereby ensuring your identification. The operating period of each cookie is included in the relevant description of each cookie.
Legal background and legal basis of cookies:
We basically distinguish three types of cookies: cookies that are essential for the proper functioning of the Website, cookies for statistical purposes, and cookies for marketing purposes.
The legal basis for data processing is your consent pursuant to Article 6(1)(a) of the Regulation in the case of cookies for statistical and marketing purposes, and the legitimate interest necessary to ensure the operation of the Website pursuant to Article 6(1)(f) of the Regulation in the case of cookies necessary for operation.
The main characteristics of the cookies used by the website:
Google Consent Mode v2
The Data Controller has integrated Google Consent Mode v2 into its website and provides consent and rejection management based on the new version through its cookie panel. Based on Google Consent Mode v2, Google uses the previous two ( analytics_storage , In addition to the ad_storage flag, it uses two additional flags that will be used to store and read cookies for statistical and advertising purposes:
- ad_user_data: Any user data may be sent to Google for advertising purposes.
- ad_personalization: User data can be used for personalized advertising purposes, such as remarketing.
These two switches are used to determine whether the storage and reading of cookies for statistical and advertising purposes is permitted.
Data processed for the purpose of concluding and fulfilling contracts
In order to conclude and fulfill a contract, several data processing cases may be implemented. We inform you that data processing related to complaint handling and warranty administration will only be implemented if you exercise one of the aforementioned rights.
If you do not make a purchase through the webshop, but are only a visitor to the webshop, then the provisions on data processing for marketing purposes may apply to you if you give us your consent for marketing purposes.
Data processing carried out for the purpose of concluding and fulfilling contracts in more detail:
Contact us
For example, if you contact us via email, contact form, or phone with a question about a product. Prior contact is not mandatory, and you can order from the webshop at any time without doing so.
Managed data
We process the personal data provided during contact (name, email address, telephone number) solely for the purpose of responding to your inquiry.
In order to fulfill orders, data is processed by Airtable and Google Cloud services in addition to Shopify. These are used exclusively for operations necessary to process the order, including supporting shipping processes and automatically generating invoices. Data is only transferred to these service providers to the extent necessary to fulfill the order.
Duration of data processing
We only process the data until the purpose of contacting you is fulfilled.
Legal basis for data processing
Your voluntary consent, which you provide to the Data Controller by contacting us. [Data processing pursuant to Article 6(1)(a) of the Regulation]
Registration on the website
By storing the data provided during registration, the Data Controller can provide a more convenient service (e.g. the data subject does not have to enter their data again when making a new purchase). Registration is not a prerequisite for concluding a contract.
Managed data
During data processing, the Data Controller processes your name, address, telephone number, e-mail address, the characteristics of the purchased Goods and the date of purchase.
Duration of data processing
Until you withdraw your consent.
Legal basis for data processing
Your voluntary consent, which you provide to the Data Controller by registering [Data processing pursuant to Article 6(1)(a) of the Regulation]
Order processing
When processing orders, data processing activities are necessary to fulfill the contract.
Managed data
During data processing, the Data Controller processes your name, address, telephone number, e-mail address, the characteristics of the purchased Goods, the order number and the date of purchase.
If you have placed an order in the webshop, data processing and providing data is essential for the fulfillment of the contract.
Duration of data processing
We process the data for 5 years according to the civil law statute of limitations.
Legal basis for data processing
Performance of the contract. [Data processing pursuant to Article 6(1)(b) of the Regulation]
Issuance of the invoice
The data processing process is carried out in order to issue invoices in accordance with the law and to fulfill the obligation to retain accounting documents. Pursuant to Section 169 (1)-(2) of the Accounting Act, business companies must retain accounting documents that directly and indirectly support the accounting settlement.
Managed data
Name, address, email address, phone number.
Duration of data processing
Issued invoices must be kept for 8 years from the date of issue of the invoice, pursuant to Section 169 (2) of the Hungarian Revenue Act.
Legal basis for data processing
Pursuant to Section 159 (1) of Act CXXVII of 2007 on Value Added Tax, the issuance of an invoice is mandatory and it must be kept for 8 years pursuant to Section 169 (2) of Act C of 2000 on Accounting [Data processing pursuant to Article 6 (1) c) of the Regulation].
Data processing related to the transport of goods
The data processing process takes place in order to deliver the ordered product.
Managed data
Name, address, email address, phone number.
Duration of data processing
The Data Controller processes the data until the delivery of the ordered goods.
Legal basis for data processing
Performance of a contract [Data processing pursuant to Article 6(1)(b) of the Regulation].
Recipients and data processors of data processing related to the transport of goods
Name of the recipient: GLS General Logistics Systems Hungary Package Logistics Ltd.
Address of the recipient: 2351 Alsónémedi, GLS Európa u. 2.
Recipient's phone number: 06-29-88-67-00
Recipient's email address: info@gls-hungary.com
Recipient's website: https://gls-group.eu/HU/hu/home
The courier service assists in the delivery of the ordered goods based on a contract concluded with the Data Controller. The courier service processes the personal data received in accordance with the data processing information available on its website.
Name of the recipient: Hungarian Posta Private Limited Company
Address of the recipient: 1138 Budapest, Dunavirag Street 2-6.
Recipient's phone number: +36-1/767-8200
Recipient's email address: ugyfelszolgalat@posta.hu
Recipient's website: posta.hu
The courier service assists in the delivery of the ordered goods based on a contract concluded with the Data Controller. The courier service processes the personal data received in accordance with the data processing information available on its website.
Data processing for marketing purposes
Data processing related to sending newsletters
The data processing process is carried out for the purpose of sending newsletters.
Managed data
Name, address, email address, phone number.
Duration of data processing
Until the data subject withdraws their consent.
Legal basis for data processing
Your voluntary consent, which you provide to the Data Controller by subscribing to the newsletter [Data processing pursuant to Article 6(1)(a) of the Regulation]
Shopify website data management
Managed data
For example, name, email address, etc.
Duration of data processing
Changes to this Privacy Policy
We may update this Privacy Policy from time to time, including to reflect changes in our practices or for other operational, legal or regulatory reasons. We will post the revised Privacy Policy on the Site, update the date of adoption, and take other steps as required by applicable law.
Legal basis for data processing
Collection and use of your personal information
In order to provide the Services, we collect personal information about you from various sources, as described below. The information we collect and use varies depending on how you interact with us.
In addition to the specific uses set forth below, we may use the information we collect about you to communicate with you, provide, develop or improve the Services, comply with applicable legal obligations, enforce applicable terms of service, and protect the Services, our rights, and the rights of our users or others.
Personal data we collect
The type of personal information we collect about you depends on how you interact with our Site and use our Services. When we use the term “personal information,” we mean information that identifies or describes you, relates to you, or can be associated with you. The following sections describe the categories and specific types of personal information we collect.
Data collected directly from you
The information you provide directly to us through our Services may include:
- Contact information , including your name, address, telephone number and email address.
- Order information , including your name, billing address, shipping address, payment confirmation, email address, and phone number.
- Account information , including your username, password, security questions, and other information used for account security purposes.
- Customer Service Data , including data you provide in your communications with us, such as when you send a message through the Services.
Some features of the Services may require you to directly provide certain information about yourself. You may choose not to provide this information, but doing so may prevent you from using or accessing those features.
Data collected about your usage
We may also automatically collect certain information about your interaction with the Services (“ Usage Data ”). We may use cookies, pixels, and similar technologies (“ Cookies ”) to do this. Usage Data may include information about how you access and use our Site and your account, including device information, browser information, network connection information, your IP address, and other information related to your interaction with the Services.
Data received from third parties
Finally, we may obtain information about you from third parties, including vendors and service providers who may collect information on our behalf, such as:
- Companies that support our Site and Services, such as Shopify.
- Our payment processors, who collect payment information (e.g. bank account, credit or debit card details, billing address) in order to fulfill our contract with you, to process your payment in order to fulfill orders and provide the products or services you have requested.
- When you visit our Site, open or click on emails we send, or interact with our Services or advertisements, we or third parties we work with may automatically collect certain information using online tracking technologies such as pixels, web beacons, software development kits, third-party libraries, and cookies.
Any data we obtain from third parties will be handled in accordance with this Privacy Policy. Please see the section below: Third-party websites and links .
Use of your personal data
- Providing products and services. We use your personal information to provide you with Services in order to perform our contract with you, including processing payments, fulfilling orders, sending you notifications regarding your account, purchases, returns, exchanges or other transactions, creating, maintaining and otherwise managing your account, arranging for shipping, facilitating returns and exchanges, and other services and features related to your account.
- Marketing and advertising. We may use your personal data for marketing and promotional purposes, such as sending you marketing, advertising and promotional communications by email, text message or post, and displaying advertisements for products or services. This may include using your personal data to better personalize the Services and advertisements that appear on our Website and other websites. If you are an EEA resident, the legal basis for these processing activities is our legitimate interest in selling our products, pursuant to Article 6(1)(f) of the GDPR.
- Security and fraud prevention. We use your personal information to detect, investigate or take action regarding possible fraudulent, illegal or malicious activities. If you choose to use the Services and register for an account, you are responsible for the security of your account credentials. We strongly advise you not to share your username, password or other access details with anyone else. If you believe that your account has been compromised, please contact us immediately. If you are an EEA resident, the legal basis for these data processing activities is our legitimate interest in maintaining the security of our website for you and your other customers, pursuant to Article 6(1)(f) of the GDPR.
- Communication with you and service development. We use your personal data to provide customer service and improve our Services. This is our legitimate interest in being able to respond to you, provide you with efficient services and maintain our business relationship with you in accordance with Article 6(1)(f) of the GDPR.
Cookies
Like many websites, we use cookies on our Website. You can find detailed information about Cookies in connection with the operation of our store using Shopify on the following website: https://www.shopify.com/legal/cookies . We use cookies to operate and improve our Site and Services (including recording your activities and preferences), to run analytics, and to better understand how users interact with the Services (in our legitimate interest in managing, improving, and optimizing the Services). We may allow third parties and service providers to use Cookies on our Site to better personalize the services, products, and advertisements on our Site and other websites.
Most browsers automatically accept Cookies by default, but you can set your browser to remove or reject Cookies through your browser settings. Please note that removing or disabling Cookies may negatively impact your user experience and some Services, including certain features and general functionality, may not function properly or may not be available. In addition, disabling Cookies may not completely prevent the sharing of your data with third parties, such as our advertising partners.
Disclosure of personal data
In certain circumstances, we may disclose your personal information to third parties for contract performance, legal purposes, and other reasons covered by this Privacy Policy. Such circumstances may include:
- With suppliers or other third parties who provide services on our behalf (e.g. IT management, payment processing, data analytics, customer service, cloud storage, fulfillment and delivery).
- With business and marketing partners to provide services and advertising. Our business and marketing partners use your information in accordance with their own privacy statements.
- When you instruct or request us to do so, or otherwise consent to us sharing certain information with third parties, such as for the delivery of products or through the use of social media widgets or login integrations.
- For our legitimate interests in running our business successfully, with our subsidiaries or otherwise within our corporate group.
- In connection with a business transaction, such as a merger or bankruptcy, to comply with applicable legal obligations (including responding to subpoenas, search warrants, and similar requests), to enforce applicable terms of service, and to protect the Services, our rights, the rights of our users, or the rights of others.
disclosed for the purposes specified above: “Collection and Use of Your Personal Information” and “Disclosure of personal data” .
| Category | Recipient categories |
|---|---|
|
|
We do not use or disclose sensitive personal information without your consent or to infer characteristics about you.
Third-party websites and links
Our Site may contain links to websites operated by third parties or other online platforms. If you follow links to websites that are not affiliated with us or under our control, please review their privacy and security policies and other terms and conditions. We make no warranties or representations and are not responsible for the privacy or security of such websites, including the accuracy, completeness or reliability of the information on such websites. Information you provide in public or semi-public places, including information shared on third-party social platforms, may be viewed by other users of the Services and/or users of such third-party platforms, without any restriction on their use by us or any third party. The inclusion of such links does not, in itself, constitute an endorsement of the content on such platforms or their owners or operators, except as otherwise disclosed in the Services.
Children's data
The Services are not intended for use by children and we do not knowingly collect any personal information from children. If you are the parent or guardian of a child who has provided us with personal information, you may contact us at the contact details below to request deletion of the information.
As of the effective date of this Privacy Policy, we are not aware of any actual “sharing” or “selling” (as such terms are defined by applicable law) personal information of individuals under the age of 16.
Security and preservation of your data
Please note that no security measure is perfect or impenetrable, and we cannot guarantee “perfect security.” In addition, the information you send to us may not be secure in transit. We recommend that you do not use unsecured channels to communicate sensitive or confidential information.
How long we retain your personal information depends on various factors, such as whether we need the information to maintain your account, provide the Services, comply with legal obligations, resolve disputes, or enforce other applicable contracts and policies.
Your rights
Depending on where you live, you may have some or all of the rights listed below in relation to your personal information. However, these rights are not absolute, may only apply in certain circumstances, and in some cases we may refuse your request as permitted by law.
- Right of access : You have the right to request access to the personal data we hold about you, including how your data is used and shared.
- Right to erasure : You have the right to request the erasure of personal data stored about you.
- Right to rectification : You have the right to request that we rectify inaccurate personal data we hold about you.
- Right to portability : In certain circumstances and with certain exceptions, you may have the right to receive a copy of the personal data we hold about you and request that we transmit it to a third party.
- Restriction of processing : You have the right to request that we stop or restrict the processing of your personal data.
- Withdrawing consent : If we rely on consent to process your personal data, you have the right to withdraw that consent.
- Appeal : If we refuse to process your request, you have the right to appeal our decision. You can do this by responding directly to the refusal.
- Manage your communication preferences : We may send you promotional emails, and you may opt out of these at any time by using the unsubscribe option in the emails we send you. If you opt out, we may still send you non-promotional emails, such as emails related to your account or orders you have placed.
You can exercise any of these rights where indicated on our Website or by contacting us using the contact details provided below.
We will not discriminate against you for exercising these rights. We may need to collect information from you to verify your identity, such as your email address or account details, before we can respond to your request in a meaningful way. In accordance with applicable law, you may designate an authorized agent to submit a request on your behalf to exercise your rights. Before we will accept such a request from an agent, we will require the agent to verify that you have authorized them to act on your behalf and may require them to verify their identity directly with us. We will respond to your request in a timely manner, in accordance with applicable law.
Further data processing
If the Data Controller intends to carry out further data processing, it will provide prior information on the essential circumstances of the data processing (legal background and legal basis of data processing, purpose of data processing, scope of data processed, duration of data processing).
Recipients of personal data
Data processing for the storage of personal data
Name of the data processor: Shopify Inc.
Contact details of the data processor:
Phone number: -
Email address: email@email.shopify.com
Headquarters: 151 O'Connor Street, Ground floor, Ottawa, Ontario, K2P 2L8, Canada
Website: https://www.shopify.com/
The Data Processor stores personal data based on a contract concluded with the Data Controller. It is not authorized to view personal data.
Data processing activities related to sending newsletters
Name of the company operating the newsletter sending system: Shopify Inc.
Headquarters of the company operating the newsletter sending system: 151 O'Connor Street, Ground floor, Ottawa, Ontario, K2P 2L8, Canada
Telephone number of the company operating the newsletter sending system: -
Email address of the company operating the newsletter system: email@email.shopify.com
Website of the company operating the newsletter sending system: https://www.shopify.com/
The Data Processor participates in sending newsletters based on a contract concluded with the Data Controller. In doing so, the Data Processor processes the name and e-mail address of the data subject to the extent necessary for sending the newsletter.
Billing-related data processing
Name of the data processor: Billingo
The data processor's registered office is: 1133 Budapest, Árbóc street 6, 1st floor
Data processor's telephone number: +36-1/500-9491
Email address of the data processor: hello@billingo.hu
Data processor's website: https://www.billingo.hu/tudastar/olvas/egyeni-vallalkozo-adozasa-masodallasban?utm_source=google&utm_medium=cpc&utm_campaign=Search%20-%20DSA%20-%20Blog%20-%20reg&utm_id=22248431991&gad_source=1&gad_campaignid=22248431991&gbraid=0AAAAADouQx5lYCLOp7zDklWJd
The Data Processor cooperates in the registration of accounting documents based on a contract concluded with the Data Controller. In the course of this, the Data Processor processes the name and address of the data subject to the extent necessary for the accounting registration, for a period in accordance with Section 169 (2) of the Personal Data Act, and then deletes it.
Data processing related to online payments
Name of the data controller: Shopify Payments
The data controller's registered office is at: 151 O'Connor Street, Ground floor, Ottawa, Ontario, K2P 2L8, Canada
Data controller's telephone number:
Data controller email address: email@email.shopify.com
Data controller website: https://help.shopify.com/en/manual/payments/shopify-payments
The payment service provider participates in the implementation of the Online payment based on a contract concluded with the Data Controller, for which purpose data is transferred to the online payment service provider during the purchase process. In the process, the online payment service provider processes the billing name, name and address of the data subject, the order number and date in accordance with its own data management rules.
The purpose of data transmission is to provide the online payment service provider with the transaction data necessary for the payment transaction initiated by the online payment service provider related to the purchase.
Legal basis for data transfer: performance of the contract concluded between you and the Data Controller pursuant to Article 6(1)(b) of the Regulation, which includes payment by the buyer, and in the case of online payment, data transfer pursuant to this point is required for payment
Your rights during data processing
Within the period of data processing, you have the following rights in accordance with the provisions of the Regulation:
- the right to withdraw consent
- access to personal data and information about data processing
- right to rectification
- restriction of data processing,
- right to erasure
- right to protest
- right to portability.
If you wish to exercise your rights, this will involve your identification, and the Data Controller will necessarily have to communicate with you. Therefore, for the purpose of identification, it will be necessary to provide personal data (but identification may only be based on data that the Data Controller already processes about you), and your complaints regarding data processing will be available in the Data Controller's email account within the period specified in this information regarding complaints. If you were our customer and would like to identify yourself for the purpose of complaint management or warranty administration, please also provide your order ID for identification. Using this, we can also identify you as a customer.
The Data Controller will respond to complaints related to data processing within 30 days at the latest.
Right to withdraw consent
You have the right to withdraw your consent to data processing at any time, in which case we will delete the data you have provided from our systems. However, please note that in the case of an order that has not yet been fulfilled, withdrawal may result in us not being able to deliver it to you. In addition, if the purchase has already been made, we cannot delete billing-related data from our systems based on accounting regulations, and if you have a debt to us, we may process your data based on our legitimate interest in collecting the debt even if you withdraw your consent.
Access to personal data
You have the right to receive feedback from the Data Controller as to whether your personal data is being processed and, if processing is in progress, you have the right to:
- obtain access to the personal data processed and
- The Data Controller shall inform you of the following information:
- the purposes of data processing;
- the categories of personal data processed about you;
- information about the recipients or categories of recipients to whom the personal data have been or will be disclosed by the Data Controller;
- the planned period for which the personal data will be stored or, if this is not possible, the criteria for determining this period;
- your right to request from the Data Controller the rectification, erasure or restriction of processing of personal data concerning you, and to object to the processing of such personal data where processing is based on legitimate interest;
- the right to lodge a complaint with the supervisory authority;
- if the data was not collected from you, all available information about its source;
- the fact of automated decision-making (if such a procedure is used), including profiling, and at least in these cases, understandable information about the logic involved and the significance and likely consequences of such processing for you.
The purpose of exercising the right may be to establish and verify the lawfulness of data processing, therefore, in the event of multiple requests for information, the Data Controller may charge a fair fee in exchange for providing the information.
The Data Controller provides access to personal data by sending you the processed personal data and information by email after you have been identified. If you have registered, we provide access by logging into your user account to view and check the personal data processed about you.
Please indicate in your request whether you are requesting access to personal data or information related to data processing.
Right to rectification
You have the right to request that the Data Controller correct inaccurate personal data concerning you without delay.
Right to restrict data processing
You have the right to request that the Data Controller restrict data processing if one of the following applies:
- You dispute the accuracy of the personal data, in which case the restriction shall apply for a period of time that allows the Data Controller to verify the accuracy of the personal data; if the accuracy of the data can be determined immediately, the restriction shall not apply;
-
the data processing is unlawful, but you oppose the deletion of the data for any reason (for example, because the data is important to you for the enforcement of a legal claim), therefore you do not request the deletion of the data, but instead request the restriction of its use;
-
the Data Controller no longer needs the personal data for the specified data processing purposes, but you require them for the establishment, exercise or defense of legal claims; or
- You have objected to the data processing, but the legitimate interest of the Data Controller may also justify the data processing, in which case, until it is determined whether the legitimate grounds of the Data Controller override your legitimate grounds, the data processing must be restricted.
Where processing is subject to restrictions, such personal data may be processed, with the exception of storage, only with the consent of the data subject, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for important public interest reasons of the Union or of a Member State.
The data controller will inform you in advance (at least 3 working days before the restriction is lifted) about the lifting of the restriction on data processing.
Right to erasure - right to be forgotten
You have the right to have the Data Controller erase personal data concerning you without undue delay if one of the following reasons applies:
- the personal data are no longer necessary for the purposes for which they were collected or otherwise processed by the Data Controller;
- You withdraw your consent and there is no other legal basis for the processing;
- You object to processing based on legitimate interest and there is no overriding legitimate reason (i.e. legitimate interest) for the processing,
- the personal data was processed unlawfully by the Data Controller and this was established based on the complaint,
- the personal data must be erased to comply with a legal obligation under Union or Member State law applicable to the Controller.
If the Data Controller has made personal data processed about you public for any legitimate reason and is obliged to erase them for any of the reasons indicated above, it is obliged to take reasonable steps, taking into account available technology and the cost of implementation, including technical measures, to inform other data controllers processing the data that you have requested the erasure of links to the personal data in question or of copies or replications of these personal data.
Erasure does not apply if data processing is necessary:
- for the purpose of exercising the right to freedom of expression and information;
- for the purpose of fulfilling an obligation under Union or Member State law to which the controller is subject to which the personal data must be processed (such as processing in the context of invoicing, as the retention of the invoice is required by law), or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- to submit, enforce or defend legal claims (e.g. if the Data Controller has a claim against you and has not yet fulfilled it, or a consumer or data processing complaint is in progress).
Right to object
You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on legitimate interest. In such a case, the Controller shall no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims.
If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such purposes, including profiling, insofar as it is related to direct marketing. If you object to the processing of your personal data for direct marketing purposes, your personal data will no longer be processed for such purposes.
Right to portability
If the data processing is carried out by automated means or if the data processing is based on your voluntary consent, you have the right to request from the Data Controller to receive the data you have provided to the Data Controller, which the Data Controller will make available to you in xml, JSON, or csv format, if this is technically feasible, you may request that the Data Controller transmit the data in this form to another data controller.
Automated decision-making
You have the right not to be subject to a decision based solely on automated processing (including profiling) which produces legal effects concerning you or similarly significantly affects you. In such cases, the Controller shall take suitable measures to safeguard the rights, freedoms and legitimate interests of the data subject, including at least the right to obtain human intervention on the part of the controller, to express his or her point of view and to object to the decision.
The above does not apply if the decision:
- Necessary for the conclusion or performance of a contract between you and the Data Controller;
- is permitted by Union or Member State law applicable to the Controller, which also lays down suitable measures to protect your rights and freedoms and legitimate interests; or
- based on your express consent.
Logging into the data protection register
According to the provisions of the Infotv., the Data Controller had to report certain data processing operations to the data protection register. This reporting obligation ceased on May 25, 2018.
Data security measures
The Data Controller declares that it has taken appropriate security measures to protect personal data against unauthorized access, alteration, transmission, disclosure, deletion or destruction, as well as against accidental destruction and damage, as well as against inaccessibility resulting from changes in the technology used.
The Data Controller will do everything within its organizational and technical capabilities to ensure that its Data Processors also take appropriate data security measures when working with your personal data.
Legal remedies
If you believe that the Data Controller has violated any legal provision relating to data processing or has not fulfilled any of your requests, you may initiate an investigation procedure with the National Data Protection and Freedom of Information Authority in order to terminate the allegedly unlawful data processing (correspondence address: 1363 Budapest, Pf. 9., e-mail: ugyfelszolgalat@naih.hu, telephone numbers: +36 (30) 683-5969 +36 (30) 549-6838; +36 (1) 391 1400).
We also inform you that in the event of a violation of the legal provisions relating to data processing, or if the Data Controller has not fulfilled any of your requests, you may file a civil lawsuit against the Data Controller in court.
Modification of data processing information
The Data Controller reserves the right to amend this data management information in a way that does not affect the purpose and legal basis of the data management. By using the website after the amendment comes into force, you accept the amended data management information.
If the Data Controller intends to carry out further data processing in relation to the collected data for a purpose other than the purpose for which it was collected, it will inform you of the purpose of the data processing and the following information prior to further data processing:
- the duration of storage of personal data or, if this is not possible, the criteria for determining the duration;
- the right to request access to, rectification, erasure or restriction of processing of your personal data from the Data Controller, and to object to the processing of your personal data in the case of processing based on legitimate interest, and to request the right to data portability in the case of processing based on consent or a contractual relationship;
- in the case of data processing based on consent, that you can withdraw your consent at any time,
- the right to lodge a complaint with the supervisory authority;
- whether the provision of personal data is based on a legal or contractual obligation or is a prerequisite for entering into a contract, and whether you are obliged to provide the personal data, as well as the possible consequences of failure to provide the data;
- the fact of automated decision-making (if such a procedure is used), including profiling, and at least in these cases, understandable information about the logic involved and the significance and likely consequences of such processing for you.
Data processing can only begin after this, if the legal basis for data processing is consent, you must also consent to data processing in addition to being informed.