Privacy Policy

 

k-beautyforyou.hu Data Protection Notice

Green Mentha Ltd.

Data protection notice

Introduction

The Green Mentha Ltd. (2011 Budakalász, Szent László Street 57., tax number: 24824143-2-13, company registration number: 13-09-168128) (hereinafter: Service Provider, data controller) processes data in accordance with the provisions set out in this notice.

In accordance with REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL (April 27, 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), we provide the following information.

This privacy notice regulates the data processing of the following websites/mobile applications: https://kbeautyforyou.hu, https://kbeautyforyou.com

The data protection notice is available at the following page: https://kbeautyforyou.hu/adatvedelem

Modifications to this notice shall take effect upon publication at the above address.

The data controller and its contact details

Name: Green Mentha Ltd.

Headquarters: 2011 Budakalász, Szent László Street 57.

E-mail: ugyfelszolgalat@kbeautyforyou.hu

Phone: +36 20 526 4011

 

Definitions

 

  1. personal data: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person;
  2. data processing: any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction;
  3. data controller: a natural or legal person, public authority, agency, or any other body that alone or jointly with others determines the purposes and means of processing personal data; where the purposes and means of processing are determined by Union or Member State law, the data controller or the specific criteria for its designation may also be laid down by Union or Member State law;
  4. data processor: a natural or legal person, public authority, agency, or any other body that processes personal data on behalf of the data controller;
  5. recipient: a natural or legal person, public authority, agency, or any other body to whom the personal data are disclosed, whether a third party or not. Public authorities which may receive personal data in the context of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities must comply with the applicable data protection rules in accordance with the purposes of the processing;
  6. consent of the data subject: any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which they, by statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them;
  7. data breach: a security breach leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed.
  8. profiling: any form of automated processing of personal data consisting of the evaluation of certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that person’s work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movements;
  9. “third party”: a natural or legal person, public authority, agency, or any other body other than the data subject, the controller, the processor, or persons authorized to process personal data under the direct authority of the controller or processor.

Principles relating to the processing of personal data

Personal data:

  1. processing must be lawful and fair, and transparent to the data subject (lawfulness, fairness, and transparency);
  2. collection must only take place for specified, explicit, and legitimate purposes, and the data must not be processed in a manner incompatible with those purposes; according to Article 89(1), further processing for public interest archiving purposes, scientific or historical research purposes, or statistical purposes shall not be considered incompatible with the original purpose (purpose limitation);
  3. They must be appropriate and relevant for the purposes of data processing and limited to what is necessary (data minimization);
  4. Data must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that inaccurate personal data are erased or rectified without delay in relation to the purposes of processing (accuracy);
  5. Storage must be in a form that permits identification of data subjects only for as long as necessary to achieve the purposes of processing personal data; longer storage is only allowed if personal data will be processed for public interest archiving, scientific or historical research, or statistical purposes in accordance with Article 89(1), taking into account appropriate technical and organizational measures to protect the rights and freedoms of data subjects (limited storage);
  6. Processing must be carried out in a way that ensures the appropriate security of personal data through suitable technical or organizational measures, including protection against unauthorized or unlawful processing, accidental loss, destruction, or damage (integrity and confidentiality).

The data controller is responsible for compliance with the above and must be able to demonstrate this compliance (accountability).

The data controller declares that data processing is carried out in accordance with the principles set out in this section.



Data processing related to operating the online store

1. The fact of data collection, the scope of processed data, and the purpose of data processing:

Personal data Purpose of data processing Legal basis
Username Identification, enabling registration. Data subject's consent, GDPR Article 6(1)(a).
Password Serves secure login to the user account.
Last and first name Necessary for contact, purchase, issuing a proper invoice, and exercising the right of withdrawal. Performance of the contract, GDPR Article 6(1)(b).
 
Email address Contact.
Phone number Communication to facilitate more effective coordination regarding invoicing or delivery issues.
Billing name and address Issuing a proper invoice, as well as creating the contract, defining its content, modifying it, monitoring its performance, invoicing fees arising from it, and enforcing related claims.

Fulfillment of legal obligation, GDPR Article 6(1)(c).

(Legal obligation under Act C of 2000 on Accounting, Section 169(2))

Delivery name and address Enabling home delivery. Performance of the contract, GDPR Article 6(1)(b).
Date and time of purchase/registration Execution of technical operation. Performance of the contract, GDPR Article 6(1)(b).
IP address at the time of purchase/registration Execution of technical operation.

2. Scope of data subjects: All individuals registered/purchasing on the webshop website. Neither the username nor the email address needs to contain personal data.

3. Duration of data processing, deadline for data deletion: If any of the conditions in Article 17(1) of the GDPR apply, data processing lasts until the data subject's deletion request. The data controller will inform the data subject electronically about the deletion of any personal data provided, according to Article 19 of the GDPR. If the deletion request includes the provided email address, the data controller will delete the email address after notification. Except for accounting documents, which must be retained for 8 years according to Section 169(2) of Act C of 2000 on Accounting. Contractual data of the data subject can be deleted upon request after the civil statute of limitations expires.

Accounting documents directly and indirectly supporting bookkeeping (including general ledger accounts, analytical and detailed records) must be kept in a readable form for at least 8 years, retrievable based on bookkeeping references.

4. Explanation of the data subjects' rights related to data processing:

  • The data subject may request from the data controller access to their personal data, correction, deletion, or restriction of processing, and
  • The data subject has the right to data portability and to withdraw consent at any time.

5. You can initiate access to personal data, deletion, modification, restriction of processing, or data portability in the following ways:

  • by postal mail at 2011 Budakalász, Szent László utca 57.,
  • by e-mail at ugyfelszolgalat@kbeautyforyou.hu,
  • by phone at +36 20 526 4011.

6. We inform you that

  • Data processing is necessary for contract performance and offer provision.
  • You are required to provide personal data so that we can fulfill your order.
  • Failure to provide data results in us being unable to process your order.


Cookie management

1. Prior consent from data subjects is not required for the use of "password-protected session cookies," "shopping cart cookies," "security cookies," "necessary cookies," "functional cookies," and "cookies responsible for managing website statistics."

2. Fact of data processing, scope of processed data: Unique identification number, dates, times.

3. Scope of data subjects: All visitors to the website.

4. Purpose of data processing: Identification of users, tracking visitors, ensuring personalized operation.

5. Duration of data processing, deadline for data deletion:

Type of cookie

Legal basis for data processing

Data processing

Duration

Session cookies or other cookies essential for the operation of the website

No data processing occurs through the use of this cookie.

The period lasts until the relevant visitor session ends, so the cookie remains on the computer only until the browser is closed.

Statistical, marketing cookies

Article 6(1)(a) of the GDPR

Data processing lasts from 1 day to 2 years, according to the cookie notice, or until the data subject withdraws consent.

6. Description of the data subjects' rights related to data processing: Data subjects have the option to delete cookies in the browser's Tools/Settings menu, usually under the Privacy settings.

7. Most browsers used by our users allow you to set which cookies should be saved and allow certain cookies to be deleted again. If you restrict cookie saving on certain websites or do not allow third-party cookies, this may under certain circumstances result in our website no longer being fully usable. Here you can find information on how to customize cookie settings in common browsers:

Google Chrome (https://support.google.com/chrome/answer/95647?hl=hu)

Microsoft Edge (https://support.microsoft.com/...)

Firefox (https://support.mozilla.org/hu/kb/sutik-engedelyezese-es-tiltasa-amit-weboldak-haszn)

Safari (https://support.apple.com/hu-hu/guide/safari/sfri11471/mac)



Use of Google Ads conversion tracking

  1. The data controller uses the online advertising program called "Google Ads" and within its framework uses Google's conversion tracking service. Google conversion tracking is an analytical service provided by Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google").
  2. When the User reaches a website via a Google ad, a cookie necessary for conversion tracking is placed on their computer. These cookies have limited validity and do not contain any personal data, so the User cannot be identified by them.
  3. When the User browses certain pages of the website and the cookie has not yet expired, both Google and the data controller can see that the User clicked on the ad.
  4. Each Google Ads client receives a different cookie, so they cannot be tracked across the websites of Ads clients.
  5. The information obtained through conversion tracking cookies serves the purpose of providing conversion statistics to clients who choose Ads conversion tracking. This allows clients to learn the number of users who clicked on their ad and were directed to a page tagged for conversion tracking. However, they do not gain access to any information that could identify any individual user.
  6. If you do not wish to participate in conversion tracking, you can refuse this by disabling the installation of cookies in your browser. You will then not be included in the conversion tracking statistics.
  7. Based on Google Consent Mode v2, Google uses two new types of cookies: ad_user_data and ad_personalization, which are based on the user's consent and relate to the use and sharing of data. The ad_user_data cookie is used to obtain the user's consent for advertising purposes by Google. The ad_personalization cookie controls whether the data can be used for ad personalization (e.g., remarketing). The data controller ensures the proper collection and withdrawal of consents via the cookie banner/panel. Withdrawal of consent does not affect the lawfulness of data processing based on consent prior to withdrawal. 
  8. Further information and Google’s privacy policy are available at the following page:  https://policies.google.com/privacy


Use of Google Analytics

  1. This website uses the Google Analytics application, which is a web analytics service provided by Google Inc. (“Google”). Google Analytics uses so-called “cookies,” text files saved to your computer, which help analyze the use of the website visited by the User.
  2. Information created by cookies related to the website used by the User is usually transmitted to and stored on one of Google’s servers in the USA. By activating IP anonymization on the website, Google shortens the User’s IP address within the member states of the European Union or other states party to the Agreement on the European Economic Area beforehand.
  3. The transmission of the full IP address to Google’s servers in the USA and its shortening there only occurs in exceptional cases. On behalf of the operator of this website, Google will use this information to evaluate how the User uses the website, to prepare reports related to website activity for the website operator, and to provide other services related to website and internet usage.
  4. Within the framework of Google Analytics, the IP address transmitted by the User’s browser is not combined with other data held by Google. The User can prevent the storage of cookies by adjusting their browser settings accordingly; however, please note that in this case, not all functions of this website may be fully available. The User can also prevent Google from collecting and processing data related to their website usage via cookies (including the IP address) by downloading and installing the browser plugin available at the following link. https://tools.google.com/dlpage/gaoptout?hl=hu


Newsletter, DM activities based on consent

1. According to Section 6 of Act XLVIII of 2008 on the basic conditions and certain restrictions of economic advertising activities, unless otherwise provided by a separate law, advertising may only be communicated to a natural person – the User – as the recipient of the advertisement by direct approach (hereinafter: direct business solicitation), in particular by electronic mail or other equivalent individual communication tools, if the recipient of the advertisement has given their prior clear and explicit consent.

2. Furthermore, the User may consent, considering the provisions of this information, to the Service Provider processing the personal data necessary for sending advertising offers.

3. The Service Provider does not send unsolicited advertising messages, and the User can unsubscribe from receiving offers without restriction or justification and free of charge. In this case, the Service Provider deletes all personal data necessary for sending advertising messages from its records and will not contact the User with further advertising offers. The User can unsubscribe from advertisements by clicking the link in the message.

4. Fact of data collection, scope of processed data, and purpose of data processing:

Personal data

Purpose of data processing

Legal basis

Name, email address.

Identification, enabling subscription to the newsletter/promotional coupons.

Data subject's consent, GDPR Article 6(1)(a).

Date and time of subscription

Execution of technical operation.

IP address at the time of subscription

Execution of technical operation.

5. Newsletter sending is carried out in compliance with the provisions of Act XLVIII of 2008 on the basic conditions and certain restrictions of economic advertising activities.

6. Scope of data subjects: All data subjects subscribed to the newsletter.

7. Purpose of data processing: sending electronic messages containing advertisements (email, SMS, push notifications) to the data subject, providing information about current news, products, promotions, new features, etc.

8. Duration of data processing, deadline for data deletion: Data processing lasts until withdrawal of consent (unsubscription, data subject's deletion request) or until the newsletter ends.

9. Explanation of the data subjects' rights related to data processing:

  • The data subject may request access to their personal data, correction, deletion, or restriction of processing from the data controller, as well as
  • The data subject has the right to data portability and to withdraw consent at any time.

10. The data subject can initiate access to personal data, deletion, modification, restriction of processing, and data portability in the following ways:

  • by postal mail at 2011 Budakalász, Szent László utca 57.,
  • by e-mail at ugyfelszolgalat@kbeautyforyou.hu,
  • by phone at +36 20 526 4011.

11. The data subject can unsubscribe from the newsletter at any time free of charge.

12. We inform you that

  • Data processing is based on your consent.
  • You are required to provide personal data if you wish to receive newsletters from us.
  • Failure to provide data will result in us being unable to send you the newsletter.
  • Please note that you can withdraw your consent at any time by clicking unsubscribe.
  • Withdrawal of consent does not affect the lawfulness of data processing based on consent before the withdrawal.


Complaint handling

1. The fact of data collection, the scope of data processed, and the purpose of data processing:

Personal data

Purpose of data processing

Legal basis

Last and first name

Identification, contact.

Fulfillment of legal obligation, GDPR Article 6(1)(c).

(the relevant legal obligation: Section 17/A (7) of Act CLV of 1997 on Consumer Protection)

Email address

Contact.

Phone number

Contact.

Billing name and address

Identification, handling of quality complaints, questions, and problems related to ordered products/services.

2. Scope of data subjects: All data subjects who purchase on the website and raise quality complaints or file complaints.

3. Duration of data processing, deadline for data deletion: Copies of the minutes, transcripts, and responses related to the complaint must be kept for 3 years based on Section 17/A (7) of Act CLV of 1997 on Consumer Protection.

4. Explanation of the data subjects' rights related to data processing:

  • The data subject may request from the data controller access to their personal data, correction, deletion, or restriction of processing, and
  • The data subject has the right to data portability and to withdraw consent at any time.

5. Access to personal data, their deletion, modification, restriction of processing, and data portability can be initiated by the data subject in the following ways:

  • by postal mail at the address 2011 Budakalász, Szent László utca 57.,
  • by e-mail at ugyfelszolgalat@kbeautyforyou.hu,
  • by phone at +36 20 526 4011.

6. We inform you that

  • Providing personal data is based on a legal obligation.
  • The processing of personal data is a prerequisite for concluding the contract.
  • You are required to provide personal data so that we can process your complaint.
  • Failure to provide data will result in us being unable to handle your complaint submitted to us.


Recipients with whom personal data is shared

"recipient": a natural or legal person, public authority, agency, or any other body to whom or which the personal data is disclosed, regardless of whether they are a third party.

1. Data processors (who carry out data processing on behalf of the data controller)

The data controller uses data processors to facilitate its own data processing activities and to fulfill contractual and legal obligations towards the data subjects.

The data controller places great emphasis on only engaging data processors who provide appropriate guarantees for compliance with the data processing requirements set out in the GDPR and ensure the protection of the rights of the data subjects through adequate technical and organizational measures.

The data processor and any person acting under the direction of the data controller or data processor with access to personal data shall process the personal data contained in this policy solely in accordance with the instructions of the data controller.

The data controller is legally responsible for the activities of the data processor. The data processor is only liable for damages caused by data processing if it failed to comply with the obligations specifically imposed on data processors by the GDPR, or if it ignored or acted contrary to the lawful instructions of the data controller.

The data processor has no substantive decision-making power regarding data processing.

The data controller may use a hosting service provider for IT support and a courier service as a data processor for delivering ordered products.

2. Certain data processors

Data processor activity

Name, address, contact information

Hosting service

 

Shopify Inc.
Headquarters: 150 Elgin St, Suite 800, Ottawa, ON, K2P 1L4, Canada
Phone: +1 888 746 7439
E-mail: support@shopify.com
Website: shopify.com



 

Other data processor (e.g., online invoicing, web development, marketing)

 

Online invoicing:
Számlázz.hu
Company: KBOSS.hu Ltd.
Website: https//www.szamlazz.hu
Email: info@szamlazz.hu
Phone: 06 30 35 44 789

Newsletter sender:
ActiveCampaign, LLC.
1 North Dearborn Street, 5th floor
Chicago, IL 60602
Web: https://www.activecampaign.com 
E-mail: privacy@activecampaign.com

ITACWT Limited
3 Cruise Park Rise, Tyrrelstown,
Dublin 15, Ireland
https://systeme.io/ 
Data management: https://systeme.io/privacy-policy

Heatmap:
Web: https://clarity.microsoft.com/
Data management: https://privacy.microsoft.com/hu-hu/privacystatement



 

 

third party”: a natural or legal person, public authority, agency, or any other body that is not identical with the data subject, the data controller, the data processor, or those persons authorized to process personal data under the direct authority of the data controller or data processor.

3. Data transfer to third parties

Third-party data controllers process the personal data we provide in their own name and in accordance with their own privacy policies.

Data controller activity

Name, address, contact information

Transportation

 

MPL Magyar Posta Logisztika Ltd.
1138 Budapest, Dunavirág Street 2-6.
ugyfelszolgalat@posta.hu 
Phone: (06-1) 767-82-82
Terms and Conditions: https://www.posta.hu/ugyfelszolgalat/aszf 
Privacy policy: https://www.posta.hu/adatkezelesi_tajekoztato

FoxPost Zrt.
3300 Eger, Maklári út 119.
Phone: 06-1-999-0-369 
Premises: 1097 Budapest, Könyves Kálmán körút 12-14.
E-mail: info@foxpost.hu



 

Online payment

 

Stripe Inc.
web: https://stripe.com email:support@stripe.com.
Headquarters 185 Berry Street Suite 550. San Francisco, CA 94107



 



Social media platforms

The data controller is also present on social media platforms to showcase its services and maintain contact with interested parties and customers.

Scope of processed data: Data publicly available on the data subject's social media profile, especially:

– name (username)

– public profile picture

– interactions published by the data subject or related to the data controller's page (e.g., comments, messages).

Scope of data subjects: Natural persons who follow the data controller's social media page, interact with it, or send messages through it.

Purpose of data processing:

– presentation of the data controller's activities and services,

– marketing and communication on social media platforms,

– communication with interested parties and customers.

Legal basis for data processing: The data subject's voluntary consent to the processing of their personal data on social media platforms.

Duration of data processing: Data processing lasts as long as the data subject's interaction exists or until the content published by the data subject is deleted. The data controller retains messages and communications for up to 2 years.

Additional data controllers: Social media platforms act as independent data controllers of users' data according to their own privacy policies.

Facebook / Meta joint data processing

The Data Controller has a Facebook / Meta profile related to the activity. The statistical data processing carried out on the Facebook social media platform is a joint data processing by the Data Controller and Facebook Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, D2 Dublin, Ireland). Detailed information about the joint data processing agreement can be found in the data controller appendix of the Facebook Page Insights feature. The appendix is available
at the following link: https://www.facebook.com/legal/terms/page_controller_addendum

The Data Controller communicates via private message on the social media platform only if you contact us there.

1. Categories of data subjects

  • the data subject who registered on the social media platform and "liked" the Data Controller's profile page,
  • the data subject who contacts the Data Controller via private message on the social media platform.

2. Purpose of data processing

The purpose of data processing on the Facebook social network is to share and promote the Data Controller’s activities and services. The Data Controller may use the data provided by the data subject in private messages to respond to the message; otherwise, the Data Controller does not collect or extract data from the social networks.

3. Legal basis of data processing

Data processing is based on Article 6(1)(a) of the GDPR; the legal basis for data processing is the data subject’s consent to the processing of their personal data on the Facebook social network.

4. Scope of processed data

  • registered name of the data subject,
  • public profile picture of the data subject user
  • other public data provided or shared by the data subject on the social network

5. Source of processed personal data: The source of the processed data is the data subject.

6. Withdrawal of consent: You may withdraw your consent to data processing at any time and delete your post or comment. Data processing takes place through social networks operated by third parties.
operates. If you withdraw your consent, the Data Controller will delete the conversation with you. Withdrawal of consent does not affect the lawfulness of data processing based on consent before its withdrawal.

The data subject can initiate access to personal data, deletion, modification, restriction of processing, or data portability in the following ways:

  • by postal mail at 2011 Budakalász, Szent László utca 57.,
  • by e-mail at ugyfelszolgalat@kbeautyforyou.hu,
  • by phone at +36 20 526 4011.

7. Duration of data processing

  • until the data subject withdraws consent,
  • if messaging occurs, then 2 years.

8. Transfer of personal data, recipients, and categories of recipients: See the definition of recipient in Article 4(9) of the GDPR. The Data Controller only transfers the data subject’s personal data to state bodies and authorities—such as courts, prosecutors, investigative authorities, administrative offense authorities, and the National Authority for Data Protection and Freedom of Information—in exceptional cases and based on legal obligations.

9. Possible consequences of failure to provide data

If data provision is omitted, the data subject cannot obtain information about the Data Controller's activities and services via the Facebook social network, nor send messages to the Data Controller via Facebook Messenger.

10. Automated decision-making (including profiling): No automated decision-making, including profiling, takes place during data processing.

11. Joint data controller agreement with Facebook Ireland Ltd.:

The Page Insights feature displays aggregated data that helps understand how data subjects use the Facebook page. Facebook Ireland Limited ("Facebook Ireland") and the Data Controller are joint controllers regarding the processing of analytics data. The Page Insights appendix defines the responsibilities of Facebook and the Data Controller concerning the processing of analytics data. Facebook Ireland assumes primary responsibility under the GDPR for processing analytics data and complies with all relevant GDPR obligations related to analytics data processing. Facebook Ireland also makes an extract of the Page Insights appendix available to all data subjects. The Data Controller ensures it has a proper legal basis under the GDPR for processing analytics data, identifies the page data controller, and complies with all other applicable legal obligations. Facebook Ireland is solely responsible for processing personal data related to the Page Insights feature, except for data covered by the Page Insights appendix. The Page Insights appendix does not grant the Data Controller the right to request personal data of Facebook users processed by Facebook Ireland, including page analytics data. The Data Controller may not act on behalf of Facebook Ireland or respond to privacy inquiries on its behalf.

Customer relations and other data processing

  1. If the data subject has any questions or problems while using the data controller’s services, they can contact the data controller through the methods provided on the website (phone, email, social media, etc.).
  2. The data controller deletes received emails, messages, and data provided via phone, Meta, etc., together with the inquirer's name, email address, and other voluntarily provided personal data, no later than 2 years after the data disclosure.
  3. Information about data processing not listed in this notice is provided at the time of data collection.
  4. In the case of exceptional official requests or requests from other authorities based on legal authorization, the Service Provider is obliged to provide information, disclose data, transfer data, or make documents available.
  5. In these cases, the Service Provider will only disclose personal data to the requester—provided they specify the exact purpose and scope of the data—only to the extent and amount strictly necessary to achieve the purpose of the request.

Rights of data subjects

1. The right of access

You have the right to receive feedback from the data controller on whether the processing of your personal data is ongoing, and if such processing is ongoing, you have the right to access the personal data and the information listed in the regulation.

2. The right to rectification

You have the right to request the data controller to rectify inaccurate personal data concerning you without undue delay. Considering the purpose of the data processing, you also have the right to request the completion of incomplete personal data – including by means of a supplementary statement.

3. The right to deletion

You have the right to request the data controller to delete your personal data without undue delay, and the data controller is obliged to delete your personal data without undue delay under certain conditions.

4. The right to erasure ("right to be forgotten")

If the data controller has made the personal data public and is obliged to delete it, taking into account the available technology and implementation costs, they will take reasonable steps – including technical measures – to inform other data controllers processing the data that you have requested the deletion of links to, copies, or duplicates of the personal data in question.

5. The right to restriction of processing

You have the right to request the data controller to restrict data processing if any of the following conditions are met:

  • you dispute the accuracy of the personal data, in which case the restriction applies for the period that allows the data controller to verify the accuracy of the personal data;
  • the data processing is unlawful, and you oppose the deletion of the data and instead request the restriction of their use;
  • the data controller no longer needs the personal data for processing purposes, but you require them for the establishment, exercise, or defense of legal claims;
  • You have objected to the data processing; in this case, the restriction applies for the period until it is determined whether the data controller’s legitimate grounds override your legitimate grounds.

6. The right to data portability

You have the right to receive the personal data you have provided to a data controller in a structured, widely used, machine-readable format, and you also have the right to transmit this data to another data controller without being hindered by the data controller to whom you provided the personal data (...)

7. The right to object

In cases of data processing based on legal interests or public authority mandates as legal grounds, you have the right to object at any time to the processing of your personal data for reasons related to your own situation, including profiling based on the mentioned provisions.

8. Objection in the case of direct marketing

If personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of your personal data for such purposes, including profiling to the extent that it is related to direct marketing. If you object to the processing of your personal data for direct marketing purposes, the personal data shall no longer be processed for such purposes.

9. Automated decision-making in individual cases, including profiling

You have the right not to be subject to a decision based solely on automated processing — including profiling — which produces legal effects concerning you or similarly significantly affects you.

The previous paragraph does not apply if the decision:

  • Necessary for the conclusion or performance of a contract between you and the data controller;
  • Its adoption is permitted by Union or Member State law applicable to the data controller, which also lays down suitable measures to protect your rights and freedoms and legitimate interests; or
  • Based on your explicit consent.

Deadline for action

The data controller shall inform you without undue delay, but in any case within one month from the receipt of the request, about the measures taken in response to the above requests.

If necessary, this may be extended by 2 months. The data controller will inform you of the extension within one month from the receipt of the request, stating the reasons for the delay.

If the data controller does not take action upon your request, they will inform you without delay, but no later than one month from the receipt of the request, of the reasons for not taking action, and that you may lodge a complaint with a supervisory authority and exercise your right to judicial remedy.

Security of data processing

The data controller and the data processor shall implement appropriate technical and organizational measures, taking into account the state of science and technology, the costs of implementation, the nature, scope, circumstances, and purposes of the data processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, in order to guarantee a level of data security appropriate to the risk, including, where applicable:

  1. pseudonymization and encryption of personal data;
  2. ensuring the continuous confidentiality, integrity, availability, and resilience of systems and services used for processing personal data;
  3. In the event of a physical or technical incident, the capability to restore access to personal data and data availability in a timely manner.
  4. A procedure for regularly testing, surveying, and evaluating the effectiveness of technical and organizational measures taken to guarantee data processing security.
  5. Processed data must be stored so that unauthorized persons cannot access it. For paper-based data carriers, this is ensured by establishing physical storage and filing procedures; for electronically managed data, by using a central authorization management system.
  6. The method of storing data electronically must be chosen so that deletion – considering any differing deletion deadlines – can be performed when the data deletion deadline expires or when otherwise necessary. Deletion must be irreversible.
  7. Paper-based data carriers must be destroyed using a shredder or by an external organization specialized in document destruction to remove personal data. For electronic data carriers, physical destruction must be carried out according to the rules for discarding electronic data carriers, and if necessary, data must be securely and irreversibly deleted beforehand.
  8. The data controller takes the following specific data security measures:

To ensure the security of personal data handled on paper, the Service Provider applies the following measures (physical protection):

  1. Documents must be stored in a secure, well-lockable, dry room.
  2. If personal data handled on paper is digitized, the rules applicable to digitally stored documents must be applied.
  3. During their work, the employee handling data processing may only leave the room where data processing takes place if they lock away the entrusted data carriers or lock the room.
  4. Personal data may only be accessed by authorized persons; third parties are not allowed access.
  5. The Service Provider's building and premises are equipped with fire protection and security devices.

 IT protection

  1. The computers and mobile devices (other data carriers) used during data processing are the property of the Service Provider.
  2. The computer system containing personal data used by the Service Provider is equipped with virus protection.
  3. To ensure the security of digitally stored data, the Service Provider applies data backups and archiving.
  4. Only authorized personnel designated for this purpose can access the central server machine.
  5. Access to data on computers is only possible with a username and password.

Informing the data subject about the data protection incident

If the data protection incident is likely to result in a high risk to the rights and freedoms of natural persons, the data controller shall inform the data subject without undue delay.

The information provided to the data subject must clearly and understandably describe the nature of the data protection incident and provide the name and contact details of the data protection officer or other contact person providing further information; describe the likely consequences resulting from the data protection incident; describe the measures taken or planned by the data controller to address the data protection incident, including, where appropriate, measures to mitigate any possible adverse effects resulting from the data protection incident.

The data subject does not need to be informed if any of the following conditions are met:

  • the data controller has implemented appropriate technical and organizational protection measures, and these measures have been applied to the data affected by the data protection incident, in particular those measures – such as encryption – that render the personal data unintelligible to unauthorized persons;
  • the data controller has taken further measures following the data protection incident that ensure that the high risk to the rights and freedoms of the data subject is unlikely to materialize further;
  • the information would require disproportionate effort. In such cases, the data subjects shall be informed by means of a public communication or similar measure ensuring that the data subjects are informed in a similarly effective manner.

If the data controller has not yet informed the data subject about the data protection incident, the supervisory authority, after assessing whether the data protection incident is likely to result in a high risk, may order the data subject to be informed.

Notification of data protection incident to the authority

The data controller shall notify the supervisory authority competent under Article 55 of the data protection incident without undue delay and, if possible, no later than 72 hours after becoming aware of the data protection incident, except where the data protection incident is unlikely to result in a risk to the rights and freedoms of natural persons. If the notification is not made within 72 hours, the reasons for the delay must be included.

Review required in case of mandatory data processing

If the mandatory duration of data processing or the necessity of periodic review is not defined by law, local government decree, or a binding legal act of the European Union, the data controller reviews at least every three years from the start of data processing whether the processing of personal data handled by them or by a data processor acting on their behalf or under their instructions is  necessary for achieving the purpose of the data processing.

Furthermore, the data controller  documents the circumstances and results of this review, retains this documentation for ten years following the completion of the review and makes it available to the National Authority for Data Protection and Freedom of Information (hereinafter: the Authority) upon request.

Complaint option

Complaints against possible violations by the data controller can be filed with the National Authority for Data Protection and Freedom of Information:

National Authority for Data Protection and Freedom of Information
1055 Budapest, Falk Miksa Street 9-11.
Mailing address: 1363 Budapest, Pf. 9.
Phone: +36 -1-391-1400
Fax: +36-1-391-1410
E-mail: ugyfelszolgalat@naih.hu

Closing remarks

In preparing this information, we took into account the following laws and recommendations:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation, GDPR) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (April 27, 2016);
  • Act CVIII of 2001 – on electronic commerce services and certain issues related to information society services (mainly §13/A);
  • Act XLVII of 2008 – on the prohibition of unfair commercial practices against consumers;
  • Act XLVIII of 2008 – on the basic conditions and certain restrictions of economic advertising activities (especially §6a);
  • Act XC of 2005 on electronic freedom of information;
  • Act C of 2003 on electronic communications (specifically §155a);
  • Opinion No. 16/2011 on the EASA/IAB recommendation regarding best practices for behavior-based online advertising;
  • Recommendation of the National Authority for Data Protection and Freedom of Information on the data protection requirements of prior information.


The document is authenticated and prepared by: Virtualjog.hu
View / download in PDF format: View / download
Date of last update: 2026.06.04