top of page

Data Controller

 

Name: ZSUZSA GULYÁS

Headquarters / complaints centre: 1133, Budapest, Thurzo Street, 9/B

TAX NUMBER: 69489631-1-41

Tax identification number: 8436250427

Registration Number: 5241919532

Phone Number: +36-30-849-7927

Website: http://www.zsuzsigulyas.com

Hosting provider

Name: Wix.com Ltd.

Mailing address: 40 Namal Tel Aviv Street, Tel Aviv Tel Aviv 6350671

 

Description of the data processing carried out during the operation of the webshop Information about the use of cookies

 

What is a cookie?

 

The Data Controller uses so-called cookies when visiting the website. A cookie is a set of letters and numbers that our website sends to your browser in order to save certain settings, facilitate the use of our website and help us collect some relevant statistical information about our visitors.

 

Some cookies do not contain personal information and are not suitable for identifying the individual user, but some contain a unique identifier - a secret, accidentally generated sequence of numbers - stored on your device to ensure your identity. The duration of each cookie is described in the relevant description of each cookie.

 

Legal background and legal basis for cookies:

 

The legal basis for data processing is your consent under Article 6(1)(a) of the Regulation.

 

The main features of the cookies used by this website are:

 

Cookies strictly necessary for operation: Thesecookies are essential for the use of thewebsite and allow you to use the basic functions of the website. Due to their absence, many of the site's features will not be available to you. The lifetime of these types of cookies is limited to the duration of the session.

 

Cookies to improve your experience: These cookies collect information about your use of the website, such as which pages you visit most often or what error message you receive from the website. These cookies do not collect information that identifies the visitor, i.e. they work with completely general, anonymous information. We use the data obtained from them to improve the performance of the website. The lifetime of these types of cookies is limited to the duration of the session.

 

If you do not accept the use of cookies, certain features will not be available to you. For more information on how to delete cookies, please visit the following links:

 

Internet Explorer: http://windows.microsoft.com/en-us/internet-explorer/delete-manage-cookies#ie=ie-11

Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer 

Mozilla: https://support.mozilla.org/hu/kb/weboldalak-altal-elhelyezett-sutik-torlese-szamito 

Safari: https://support.apple.com/guide/safari/manage-cookies-and-websitedata-sfri11471/mac

Chrome: https://support.google.com/chrome/answer/95647

Edge: https://support.microsoft.com/hu-hu/help/4027947/microsoft-edge-delete-cookies

 

Data processed for the conclusion and performance of contracts

 

In order to conclude and perform the contract, several data processing cases may take place. Please note that data processing in connection with complaint handling and warranty administration is only carried out if you exercise one of these rights. If you do not make a purchase through the webshop, you are only a visitor to the webshop, you may be subject to the information provided for marketing purposes if you give us your consent for marketing purposes.

 

Data processing for the purpose of contracting and performance in more detail:

  • Contact

  • For example, if you contact us by email, contact form, or phone with a question about a product.

  • Pre-contact is optional, you can order from the webshop at any time without this.

  • Managed data

  • The information you provide during the contact.

  • Duration of data processing

The data will only be processed until the end of the contact.

 

Legal basis for data processing

 

Your voluntary consent, which you give to the Data Controller by contacting you. [Processing under Article 6(1)(a) of the Regulation]

 

Website Registration

By storing the data provided during registration, the Data Controller can provide a more convenient service (e.g. the data of the data subject do not need to be re-entered on another. Registration is not a condition for entering into a contract

 

Managed data

 

In the course of data processing, the Data Controller manages your name, address, telephone number, e-mail address, the characteristics of the product purchased and the date of purchase.

 

Duration of data processing

 

Until your consent is withdrawn.

 

Legal basis for data processing

 

Your voluntary consent to the Data Controller by registering [Regulation

Article 6(1)(a) processing]

 

 

Processing the order

 

Processing activities necessary for the performance of the contract in the processing of orders

 

Managed data

 

In the course of data processing, the Data Controller manages your name, address, telephone number, e-mail address, characteristics of the product purchased, order number and date of purchase.

If you have placed an order in the webshop, the processing and data is essential for the performance of the contract.

 

Duration of data processing

 

The data will be processed for 5 years according to the civil limitation period.

 

Legal basis for data processing

 

Performance of the contract. [Processing under Article 6(1)(b) of the Regulation]

 

Issues with invoices

The data management process is done in order to issue an invoice in accordance with the law and to fulfil the obligation to keep accounting documents. Pursuant to Articles 169(1) to (2) of the STV, companies must keep an accounting document directly and indirectly supporting the accounts.

 

Managed data

 

  • Name, address, e-mail address, phone number.

  • Duration of data processing

 

The invoices issued shall be kept for 8 years from the date of issue of the invoice pursuant to Article 169(2) of the STV.

 

Legal basis for data processing

 

Pursuant to Section 159(1) of the Vat Act 2007 CXXVII, the issue of an invoice is mandatory and must be retained for 8 years under Section 169(2) of the Accounting Act 2000 [Processing under Article 6(1)(c) of the Regulation].

 

Data processing related to the transport of goods

The data management process is done in order to deliver the ordered product.

 

Managed data

 

  • Name, address, e-mail address, phone number.

  • Duration of data processing

 

The Data Controller will process the data for the duration of the delivery of the ordered goods.

 

Legal basis for data processing

 

Performance of a contract [Processing under Article 6(1)(b) of the Regulation]

 

 

Handling warranty and warranty claims

 

Warranty and warranty claims are made in accordance with Regulation (EC) No 19/2014 (IV. 29) we must act according to the rules of the NGM Regulation, which also sets out how we should deal with its needs.

 

Managed data

 

19/2014 (IV. 29) when handling warranty and warranty claims we must act in accordance with the rules of the NGM Regulation.

 

Under this regulation, we are obliged to record a record of your warranty or warranty claim with us, in which we record:

 

(a) your name, address and statement that you consent to the processing of your data recorded in the Protocol as set out in this Regulation,

(b) the description, purchase price and purchase price of the movable property sold under the contract between you and us,

(c) the date of performance of the contract,

(d) the date of notification of the defect,

(e) a description of the error,

(f) the right you wish to enforce on the basis of your warranty or warranty claim, and

(g) the manner in which the warranty or warranty claim is settled or the reason for rejecting the claim or the right to enforce it.

 

 

If we receive the purchased product from you, we will have to draw up a receipt to indicate:

(a) your name and address,

(b) the particulars necessary to identify the thing,

(c) the date of receipt of the goods, and

(d) the date on which you may receive the corrected thing.

Duration of data processing

 

The undertaking shall keep a record of the consumer's warranty or warranty claim for a period of three years from the date of its inclusion and present it at the request of the control authority.

 

Legal basis for data processing

 

Legal basis for data processing is 19/2014 (IV. 29) NGM Regulation [Compliance with legal obligations under § 4(1) and §6(1)] [Processing under Article 6(1)(c) of the Regulation].

 

Handling other consumer complaints

 

The data processing process is done in order to handle consumer complaints. If you have complained to us, the processing and the providing of data are essential.

 

Managed data

 

  • Customer's name, phone number, email address, complaint content.

  • Duration of data processing

Warranty complaints are retained for 5 years under the Consumer Protection Act.

 

Legal basis for data processing

 

Whether or not you make a complaint to us is a voluntary decision, but if you contact us, we are obliged to comply with the complaint for 5 years under Section 17/A(7) of the Consumer Protection Act 1997 [Processing under Article 6(1)(c) of the Regulation].

 

Data processed in relation to the variability of consent

When registering, ordering or subscribing to a newsletter, the IT system stored the IT data related to the consent in order to prove it later.

 

Managed data

 

Date of consent and IP address of the data subject.

Duration of data processing

 

Due to legal requirements, consent must be verified at a later date, so the duration of the data storage will be stored for the limitation period after the end of the processing.

 

Legal basis for data processing

 

Article 7(1) of the Regulation provides for this obligation. [Processing under Article 6(1)(c) of the Regulation.

 

 

Data processing for marketing purposes

Data management related to the sending of newsletters

 

Managed data

 

  • Name, address, e-mail address, phone number.

  • Duration of data processing

  • Until the data subject's consent is withdrawn.

  • Legal basis for data processing

 

Your voluntary consent to the Data Controller by subscribing to the newsletter [Processing under Article 6(1)(a) of the Regulation]

 

Remarketing

Data processing as a remarketing activity is carried out through cookies.

 

Managed data

 

The data processed by the cookies specified in the cookie notice.

Duration of data processing

 

The duration of the cookie's storage period, more information is available here:

 

Google General Cookie Notice: https://www.google.com/policies/technologies/types/

 

Google Analitycs factsheet: https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage?hl=hu

 

Facebook factsheet:

https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen

 

Legal basis for data processing

 

Your voluntary consent to the Data Controller using the website [Processing under Article 6(1)(a) of the Regulation].

 

Sweepstakes

The data management process is carried out for the purpose of conducting the sweepstakes.

 

Managed data

 

  • Name, email address, phone number.

  • Duration of data processing

 

The data will be deleted after the closing of the sweepstakes, except for the winner's data, which the Data Controller is obliged to keep under the Accounting Act for 8 years.

 

Legal basis for data processing

 

Your voluntary consent, which you give to the Data Controller using the website. [Processing under Article 6(1)(a) of the Regulation]

 

Loyalty program

 

The range of data processed is:

 

In the course of data processing, the Data Controller manages your name, address, telephone number, e-mail address, the characteristics of the product purchased and the date of purchase.

 

Duration of data processing:

 

Until the data subject's consent is withdrawn.

 

Legal basis for data processing:

 

More data management

 

If the Data Controller wishes to carry out further processing, he/she will provide prior information on the relevant circumstances of the processing (legal background and legal basis of the processing, purpose of the data processing, scope of data processed, duration of data processing). We inform you that the data controller must comply with written requests for data from the authorities based on statutory authority. The Data Controller informs Infotv. In accordance with § 15(2) to (3), it maintains a register (to which authority, what personal data, on what legal basis, when transmitted by the Data Controller), the content of which the Data Controller shall provide information on at his request, unless his information is excluded by law.

 

Recipients of personal data

Processing of personal data

 

Name of processor: Mailchimp

Contact details of the processor:

E-mail address:personaldatarequests@mailchimp.com

Website: https://mailchimp.com/dsar-requests/

 

The Processor stored personal data under a contract with the Data Controller. You are not entitled to know your personal data.

 

Data processing activities related to the sending of newsletters

 

Name of the company operating the newsletter system: Mailchimp

E-mail address of the company operating the newsletter system: personaldatarequests@mailchimp.com

Website of the company operating the newsletter system: un https://mailchimp.com/dsar-requests/

The Data Processor contributes to the sending of newsletters on the basis of a contract with the Data Controller. In doing so, the Data Processor manages the data subject's name and e-mail address to the extent necessary for the newsletter.

Invoicing data processing

Online billing software name: Számlázz.hu

Biller availability: https://www.szamlazz.hu/

Name of service provider: KBOSS.hu Kft.

Tax number of the company providing the service: 13421739-2-41

Registration Number: 01-09-303201

Email: info@szamlazz.hu

Phone Number: +3630 35 44 789

E-mail address of the processor: info@szamlazz.hu

 

The Processor contributes to the recording of accounting documents on the basis of a contract with the Data Controller. In doing so, the Processor shall process the name and address of the data subject to the extent necessary for the accounting records for a period corresponding to § 169(2) of the STV and subsequently delete it.

Your rights in the processing of data

Within the period of data processing, you have the following rights as provided for in the Regulation:

the right to withdraw consent

right to rectification of personal data and information relating to data processing

restriction of data processing, right to object to the right to erasure, right to portability.

 

If you wish to exercise your rights, this will involve your identification and the Data Controller will have to communicate with you as necessary. Therefore, in order to be identified, personal data will be required (but the identification can only be based on data that the Data Controller already handles about you) and your complaint about the processing will be available in your email account within the period specified in this notice in connection with the complaints. If you were a customer and would like to identify yourself for complaints or warranty, please also provide your order ID for identification. We can use this to identify you as a customer.

 

Complaints about data processing will be answered by the Data Controller no later than 30 days.

 

Right to withdraw consent

 

You have the right to withdraw your consent to the processing at any time, in which case the data provided will be deleted from our systems. Please note, however, that in the case of an order that has not yet been fulfilled, the withdrawal may result in us not being able to deliver to you. In addition, if the purchase has already been made, we cannot delete billing information from our systems under accounting requirements, and if you owe us money, we may process your data on the basis of a legitimate interest in recovering the claim even if consent is withdrawn.

 

Access to personal data

 

You have the right to receive feedback from the Data Controller as to whether your personal data are being processed and, if processing is ongoing, you have the right to:

 

  • access to the personal data processed and

  • inform the Data Controller of the following information:

  • the purposes of the processing;

  • categories of personal data we process about you;

  • information about the recipients or categories of recipients with whom the personal data have been or will be communicated by the Controller;

  • the intended duration of the storage of personal data or, if this is not possible, the criteria for determining that period;

  • your right to request the Controller to rectify, delete or restrict the processing of personal data relating to you and to object to the processing of such personal data in the event of processing based on a legitimate interest;

  • the right to lodge a complaint addressed to the supervisory authority;

  • if the data was not collected from you, all available information about their source; information on the fact of automated decision-making (if such a procedure is used), including profiling, and, at least in these cases, understandable information on the logic used and the significance of such processing and the likely consequences for you.

 

The purpose of exercising the right may be to establish and verify the legality of the processing, so if repeated information is requested, the Data Controller may charge a reasonable fee in exchange for the performance of the information.

 

Access to personal data is provided by the Data Controller by sending you the personal data and information processed by e-mail after your identification. If you have a registration, access will be provided in such a way that you can log in to your user account to view and verify the personal information we process about you.

 

Please indicate in your request whether you are requesting access to personal data or requesting information about the processing.

 

Right to rectification

 

You have the right to request that the Data Controller correct inaccurate personal data concerning you without delay.

Right to restrict data processing

 

You have the right to request that the Data Controller restrict the processing if one of the following is fulfilled:

 

You dispute the accuracy of the personal data, in which case the limitation applies to the period of time that allows the Controller to verify the accuracy of the personal data, if the exact data can be established immediately, then the restriction will not take place;

 

the processing is unlawful, but you are opposed to the deletion of the data for any reason (for example, because the data is important to you because of the enforcement of a legal claim), so you do not ask for the deletion of the data, but instead ask for restrictions on their use;

 

the Data Controller no longer needs the personal data for the purposes of the indicated processing, but you require them to make, enforce or defend legal claims; Or

 

You have objected to the processing, but the legitimate interest of the Data Controller may also give the basis for the processing, in which case, until it is established whether the legitimate reasons of the Data Controller take precedence over your legitimate reasons, the processing should be restricted.

 

Where processing is restricted, such personal data may be processed only with the consent of the data subject, with the exception of storage, or in order to make, enforce or defend legal claims or to protect the rights of another natural or legal person, or in the important public interest of the Union or of a Member State.

 

The Data Controller will inform you in advance (at least 3 working days before the restriction is lifted) of the lifting of the restriction on data processing.

Right to erasure - right to be forgotten

 

You have the right to delete your personal data without undue delay if one of the following reasons exists:

 

personal data are no longer needed for the purposes from which they were collected or otherwise processed by the Controller;

You withdraw your consent and there is no other legal basis for the processing;

You object to processing based on a legitimate interest and there is no overt legitimate reason (i.e. a legitimate interest) for the processing,

the personal data have been unlawfully processed by the Controller and this has been established on the basis of the complaint,

personal data must be deleted in order to comply with the legal obligation imposed on the Controller by Union or Member State law.

 

If for any legitimate reason, the Controller has made public the personal data processed of you and is obliged to delete it for any of the reasons stated above, he shall take reasonable steps, including technical measures, taking into account the available technology and the costs of implementation, to inform other controllers handling the data that you have requested the deletion of links to the personal data in question or of a copy or a copy of such personal data.

 

Erasure shall not apply where processing is necessary:

 

exercising the right to freedom of expression and information;

fulfilment of an obligation under Union or Member State law applicable to the controller to process personal data (such as invoicing, as the retention of the invoice is required by law) or for the performance of a task carried out in the public interest or in the exercise of a public authority conferred on the controller;

to make, enforce or defend legal claims (e.g. if the Data Controller has a claim against you and has not yet complied with it, or if a consumer or data processing complaint is pending).

 

Right to object

 

You have the right to object at any time to the processing of your personal data on the basis of legitimate interests for reasons related to your situation. In this case, the Data Controller may no longer process personal data unless it proves that the processing is justified by compelling legitimate reasons which take precedence over your interests, rights and freedoms or which relate to the submission, enforcement or defence of legal claims.

 

 

If your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data relating to you for this purpose, including profiling, in so far as it relates to direct marketing. If you object to the processing of personal data for direct marketing purposes, the personal data will no longer be processed for this purpose.

 

Right to portability

 

If the processing is carried out in an automated manner, or if the processing is based on your voluntary consent, you have the right to ask the Data Controller to receive the data you have provided to the Data Controller, which the Data Controller will provide to you in xml, JSON or csv format, if technically feasible, you may request that the Data Controller transfer the data in this form to another data controller.

 

Automated decision-making

 

You have the right not to be subject to a decision based solely on automated processing (including profiling) that would have legal effects on you or similarly significantly affect you. In such cases, the Controller shall take appropriate measures to protect the rights, freedoms and legitimate interests of the data subject, including at least the right of the data subject to request human intervention on the part of the controller, to express his or her views and to object to the decision.

The foregoing shall not apply where the decision:

 

necessary for the conclusion or performance of a contract between you and the controller;

is made possible by EU or Member State law applicable to the controller which also lays down appropriate measures to protect your rights and freedoms and legitimate interests; Or

based on your express consent.

 

Log in to the Data Protection Register

 

Az Infotv. the Data Controller had to declare certain data processing in the data protection register. This notification obligation ceased on 25 May 2018.

 

NAIH number registered before 25 May 2018:

Data Protection Registration No:NAIH-115537/2017.

Data security measures

 

The Data Controller declares that it has taken appropriate security measures to protect personal data against unauthorised access, alteration, transmission, disclosure, deletion or destruction, as well as accidental destruction and damage, as well as inaccessibility due to changes in the technique used.

 

the Data Controller shall make every effort, in relation to the organisational and technical possibilities, to ensure that its processors also take appropriate data security measures when working with your personal data.

 

Remedies

 

If you believe that the Data Controller has violated a statutory provision on data processing or has not complied with any of your requests, you may initiate the investigation procedure of the National Data Protection and Freedom of Information Authority (mailing address: 1363 Budapest, Pf. 9, e-mail: ugyfelszolgalat@naih.hu).

 

We also inform you that in the event of a breach of the legal provisions on data processing or if the Data Controller has not complied with one of his requests, he may bring a civil action against the Data Controller in court.

 

Change data management information

 

The Data Controller reserves the right to modify this data management notice in a manner that does not affect the purpose and legal basis of the data processing. By using the website after the amendment takes effect, you agree to the revised data management notice. If the Data Controller wishes to carry out further processing of the collected data for purposes other than the purpose for which they were collected, he/she shall inform you of the purpose of the data processing and of the following information prior to further processing:

 

the duration of the storage of personal data or, if this is not possible, the criteria for determining the period;

the right to request the Controller to access, rectify, delete or restrict the processing of personal data relating to you and, in the case of processing based on a legitimate interest, to object to the processing of personal data and to request the right to data portability in the case of processing based on consent or contractual relationship;

consent-based processing, that you may withdraw consent at any time,

the right to lodge a complaint addressed to the supervisory authority;

 

whether the provision of personal data is based on a legal or contractual obligation or is a prerequisite for the conclusion of a contract, whether you are obliged to provide the personal data and the possible consequences of non-provision of data;

information on the fact of automated decision-making (if such a procedure is used), including profiling, and, at least in these cases, understandable information on the logic used and the significance of such processing and the likely consequences for you.

 

The processing can only begin after that, if the legal basis for the processing is consent, you must consent to the processing in addition to the information.

 

This document contains all relevant data management information relating to the operation of the webshop in accordance with the General Data Protection Regulation 2016/679 of the European Union (hereinafter referred to as the "Regulation"). ('Infotv.') and CXII.tv. ('Infotv.') of 2011.

 

Post office and post-point delivery

Please note that Magyar Posta Zrt. identifies the recipient in accordance with the applicable data management information, so you may ask for your personal data to be provided at the time of delivery by post or post.

bottom of page