Welcome to the realm of stylish dogs

Privacy Policy

Privacy Policy 

Accepted by Pihepets Kft. (registered office: 1089 Budapest, Orczy út 12., company registration number: 01-09- 387984, tax number: 25481819-2-42, tel.: +3620-4010000, e-mail address: info@brizlo.co.uk; represented by: Másody Szabolcs managing director) (hereinafter: Data Controller) on 11 September 2024. 

1./ General provisions 

The subject of this privacy notice is the processing of personal data that came into the possession of the Data Controller in connection with the Data Controller’s commercial activities conducted on the www.brizlo.co.uk website, based on Act CXII of 2011 on the right to informational self-determination and freedom of information (hereinafter: Infotv.), Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR) and other applicable legislation. 

This Notice sets out the data protection and data processing principles applied by the Data Controller, by which the Data Controller ensures that the personal data of natural persons who come into contact with it are not compromised. 

The Data Controller reserves the right to unilaterally modify its data protection policy and hence the content of this Notice in the event of changes to the services it provides, and to comply with applicable legal provisions. The Data Controller will notify the Data Subjects of any change to this Notice simultaneously on the www.brizlo.co.uk website. 

2./ Legal background 

• Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation – GDPR) 

• Act CXII of 2011 on the right to informational self-determination and freedom of information 

• Act V of 2013 on the Civil Code 

• Act XLVIII of 2008 on the fundamental conditions and certain limitations of commercial advertising activities 

• Act CVIII of 2001 on certain issues of electronic commerce services and services related to the information society

3./ Definitions  

Personal data/Data subject: any information relating to an identified or identifiable natural person (‘Data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. 

Data processing: any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction. 

Data processing: the set of data processing operations carried out by a data processor acting on behalf of or under the instructions of the Data Controller. 

Data Controller: the natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law. 

Data Processor: a natural or legal person, public authority, agency or any other body which processes personal data on behalf of the controller. 

Data destruction: the complete physical destruction of the data carrier containing the data. 

Data transfer: making the data available to a specified third party. 

Data erasure: rendering the data unidentifiable in such a way that restoration is no longer possible. 

Data protection incident: a security breach which results in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data transmitted, stored or otherwise processed. 

EEA State: a Member State of the European Union and any other state party to the Agreement on the European Economic Area, and also any state whose nationals enjoy the same status as nationals of a state party to the Agreement on the European Economic Area under an international agreement concluded between that state and the European Union and the EEA states. 

Third party: a natural or legal person, public authority, agency or any other body which is not identical with the Data Subject, the Data Controller, the Data Processor or persons authorised to process personal data under the direct authority of the controller or the processor.

Third country: any state that is not an EEA State. 

Consent: the Data Subject’s voluntary, specific, informed and unambiguous indication of his or her wishes by which the Data Subject, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her. 

Disclosure: making the data accessible to anyone. 

4./ Categories of Data Subjects affected by the data processing: 

The data processing covers: 

– Natural persons who: 

• who register with the Data Controller on its online webshop accessible at www.bizlo.hu (hereinafter: website) in the online store (hereinafter: webshop) for the purposes of contact; advertising or other information; sending newsletters; • who register with the Data Controller in person or in the webshop for the purpose of ordering goods (hereinafter: order).  

The above are hereinafter collectively referred to as: Data Subject, Data Subjects. 

This notice applies to all data processing carried out by the Data Controller in which personal data are processed, regardless of the nature of the personal data. 

5./ Source of the data: 

Data voluntarily provided by the Data Subjects.  

6./ Principles of data processing: 

In the course of data processing, the Data Controller shall act in compliance with the following principles concerning the processing of personal data:  

a) personal data shall be processed lawfully and fairly, and in a transparent manner for the Data Subject; 

b) collection of personal data may be carried out only for specified, explicit and legitimate purposes, i.e. it must be purpose-limited; 

c) processing must in all cases be limited to what is necessary (‘data minimisation’); 

d) processed data must be accurate and, where necessary, kept up to date: every reasonable step must be taken to ensure that personal data that are inaccurate with regard to the purposes of processing are erased or rectified (‘accuracy’);

e) personal data shall be kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the personal data are processed (‘storage limitation’); 

f) personal data shall be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage (‘integrity and confidentiality’). 

7./ Categories of processed data, purposes of processing, duration of processing and legal basis for processing 

• Mandatory personal data to be provided for contact; advertising or other information; sending newsletters:  

Processed data 

Purpose of processing 

Duration of processing

Legal basis for processing

Surname and given name: 

For personal salutation in the newsletter

until withdrawn 

GDPR Article 6(1)(a) – the Data Subject’s consent to the processing

E-mail address: 

To communicate information to customers concerning the webshop’s offers, promotions, new products, and the operation and functioning of the webshop. From time to time – in the case of a previous purchase – sending offers in the event of possible marketing of similar new products. 

Sending an offer in the event of possible marketing of similar new products.

until withdrawn 

GDPR Article 6(1)(a) – the Data Subject’s consent to the processing.

• Personal data mandatory to provide for purchases in the webshop 

Processed data 

Purpose of processing 

Duration of processing 

Legal basis for processing

Surname and  

given name

1./  

Related to the order  

contract,  

delivery note

1./ For five years following the date of fulfilment of the order

1./ Regarding orders: GDPR Article 6(1)(b) – performance of the contract

 

for preparation,  

issuing a thank-you card,  

dispatching the package 

2./ Issuing an invoice for the order 

2./ With regard to the invoice: its issuance  

for eight years following

Section 13/A of Act CVIII of 2001 on certain issues of electronic commerce services and services related to the information society 

Section 6:22 of Act V of 2013 on the Civil Code (limitation period – five years) 

2./ With regard to invoicing: pursuant to Article 6(1)(c) of the GDPR – fulfilment of a legal obligation – Section 159 of Act CXXVII of 2007 on Value Added Tax and Section 169(2)-(3) of Act C of 2000 on Accounting. 

Section 13/A of Act CVIII of 2001 on certain issues of electronic commerce services and services related to the information society

Residential address 

1./  

Related to the order  

contract,  

delivery note  

for preparation,  

thank-you card  

issuing,  

package dispatch 

2./ Issuing an invoice for the order

1./ For five years following the date of fulfilment of the order 

2./ With regard to the invoice: its issuance  

for eight years following

1./ Regarding orders: GDPR Article 6(1)(b) – performance of the contract 

Section 13/A of Act CVIII of 2001 on certain issues of electronic commerce services and services related to the information society 

Section 6:22 of Act V of 2013 on the Civil Code (limitation period – five years) 

2./ With regard to invoicing: fulfilment of a legal obligation pursuant to Article 6(1)(c) of the GDPR – legal obligation pursuant to Section 159 of Act CXXVII of 2007 on Value Added Tax –

     

and Section 169(2)-(3) of Act C of 2000 on Accounting 

Section 13/A of Act CVIII of 2001 on certain issues of electronic commerce services and services related to the information society

Telephone number 

Related to the order  

notification,  

contact 

For five years following the date of fulfilment of the order placed in the webshop

GDPR Article 6(1)(b) – performance of the contract 

Section 6:22 of Act V of 2013 on the Civil Code (limitation period – five years)

E-mail address 

Related to the order  

notification,  

contact 

For five years following the date of fulfilment of the order placed in the webshop

GDPR Article 6(1)(b) – performance of the contract 

Section 6:22 of Act V of 2013 on the Civil Code (limitation period – five years)

Delivery address 

Order  

for delivery  

(If the  

delivery address  

differs from the residential address)

For five years following the date of fulfilment of the order placed in the webshop

GDPR Article 6(1)(b) – performance of the contract 

Section 6:22 of Act V of 2013 on the Civil Code (limitation period – five years)

The personal data listed above are necessary for the performance of the contract concluded in the webshop; they must be provided (are necessary) for the fulfilment of the order. If the personal data are not provided, the order cannot be fulfilled.  

8./ Data transfers and Recipients 

A. The Data Controller does not transfer personal data to third countries or to international organisations.  

B. The Data Controller transfers the processed data to the following recipients:

Data Processors of the Data Controller: 

Name and contact details 

Which data 

it concerns

Purpose of the data transfer

MŰISZ Holding 

Kft. 

(1089 Budapest 

Orczy út 12.)

all processed data 

accounting and 

payroll

GLS Courier Service (2351 Alsónémedi, GLS Európa utca 2.)

Name, delivery address, contact person(s) 

telephone number, e-mail address

Orders 

delivery

Magyar Posta Zrt. (1138 Budapest, 

Dunavirág utca 2- 6.)

Name, delivery address, contact person(s) 

telephone number, e-mail address

Orders 

delivery

számlázz.hu 

KBOSS.hu Kft. 

(1031 Budapest, 

Záhony utca 7.)

Name, address, telephone number, e-mail address

invoicing

CreatIT Solutions Background and 

Communication 

Limited 

Liability 

Company 

(6724 Szeged, 

Körtöltés utca 59.)

all processed data 

to Data Subjects 

relating to 

data controller’s 

software 

operation

X-COM 

Telecommunications, Commercial 

Developer and Manufacturer Limited 

Liability 

Company 

(1156 Budapest, 

Nyírpalota u. 12.)

all processed data 

to Data Subjects 

operation of e-mails relating to and the 

management of data controller domains

C. Other 

The consideration for products purchased in the webshop must be paid in favor of the Data Controller via the “SimplePay” application provided by OTP Mobil Szolgáltató Korlátolt Felelősségű Társaság (1138 Budapest, Váci út 135-139. B. ép. 5. em.) (hereinafter: OTP Mobil Kft.).

When placing an order, on the webshop’s “SimplePay” payment preparation page the personal data First name, Last name, Postal code, City, Address, Building, Floor, Door, Telephone number must be provided. After providing the data, the Data Subject will be redirected to the SimplePay secure payment page, where they must enter the card details necessary for payment. The payment then becomes possible.  

The Data Controller does not gain knowledge of either the data entered on the “SimplePay” payment preparation page or the data entered on the “SimplePay” payment page; these are independent and protected internet pages. 

Therefore, in the payment described above the Data Controller performs no data processing activities. The exclusive, independent data controller during the payment is OTP Mobil Kft.  

9./ Technical implementation of data processing: 

The Data Controller stores the Data Subjects’ personal data exclusively electronically on servers located in Hungary; personal data are not transferred to a processor in a third country. 

The Data Controller ensures the security of personal data with appropriate technical and organizational measures. The Data Controller equips the IT equipment used for processing and storing personal data with adequate protection (passwords, firewall); and ensures that only authorized persons can access these devices.  

The Data Controller also ensures that personal data will not be damaged, destroyed, or disclosed even in the event of force majeure. 

10./ Data Subjects’ rights related to data processing 

During data processing, the Data Controller ensures the Data Subjects’ right to the protection of their data. The Data Subjects are entitled to: 

a) right to be informed: The Data Subject is entitled to receive information related to the data processing before the commencement of the processing activity. 

b) right of access: The Data Subject is entitled to receive feedback from the Data Controller as to whether the processing of his/her personal data is taking place, and if such processing is taking place, is entitled to access the personal data and relevant information (purpose of processing, Data Subject’s personal data, retention period of personal data, etc.). 

c) right to rectification and erasure: The Data Subject is entitled to request that the Data Controller rectify inaccurate personal data concerning him/her without undue delay. The Data Subject is entitled to request that the Data Controller erase personal data concerning him/her without undue delay, and the Data Controller is obliged to erase personal data concerning the Data Subject without undue delay if the Data Subject has withdrawn his/her explicit consent, or the purpose of the data processing has otherwise ceased. Except where the data must be retained due to legal obligations. Furthermore, the Data Controller continues to process data that under the law cannot be erased or cannot yet be erased at the time of the request. 

d) right to restriction of processing: The Data Subject is entitled to request that the Data Controller restrict processing if he/she contests the accuracy of personal data (in which case the restriction shall apply for the period enabling the Data Controller to verify the accuracy of the personal data); if the processing is unlawful and the Data Subject opposes the erasure of the data and requests instead the restriction of their use; if the Data Controller no longer needs the personal data for processing purposes, but the Data Subject requires them for the establishment, exercise or defence of legal claims. 

e) obligation to notify recipients about rectification, erasure or restriction of processing: The Data Controller shall inform all recipients to whom the personal data have been disclosed about the rectification, erasure or restriction of processing, unless this proves impossible or requires disproportionate effort. 

f) right to data portability: The Data Subject is entitled to receive the personal data concerning him/her which he/she has provided to a Data Controller in a structured, commonly used and machine-readable format, and is entitled to transmit those data to another Data Controller. 

g) right to lodge a complaint and to legal remedy: Pursuant to Article 77 of the GDPR, the Data Subject is entitled to lodge a complaint with the supervisory authority if, in the Data Subject’s opinion, the processing of personal data concerning him/her violates the GDPR. Furthermore, pursuant to Infotv. Section 22, he/she may initiate an investigation by the supervisory authority for the purpose of examining the legality of the data controller’s measures if the Data Controller restricts the exercise of the above rights or rejects his/her request to exercise these rights, and may request the supervisory authority to conduct a data protection authority procedure if, in his/her opinion, the data controller or the processor acting on its behalf or under its instructions violates the provisions concerning the processing of personal data laid down in law or in a mandatory legal act of the European Union. 

The Data Subject may exercise his/her right to lodge a complaint at the following contact details:National Authority for Data Protection and Freedom of Information; address: 1055 Budapest, Falk Miksa utca 9-11.; Phone: +36 (1) 391-1400; Fax: +36 (1) 391-1410; www: http://www.naih.hu; email: ugyfelszolgalat@naih.hu 

If the Data Subject’s rights are violated, or in other cases specified in the Infotv., the Data Subject may turn to the courts (Infotv. Section 23). The adjudication of the case falls within the competence of the Court. The action may, at the Data Subject’s choice, also be brought before the court of the Data Subject’s place of residence or place of stay.

11./ Special rules for newsletter sending and advertising communications 

The Data Controller primarily sends messages to the Data Subjects containing information related to the purpose of data processing and to the services it provides, arising in connection with the use of the services.  

The Data Subject acknowledges that subscribing to the newsletter service constitutes consent pursuant to Section 6 (1) of Act XLVIII of 2008 on the basic conditions and certain limitations of commercial advertising activities, on the basis of which the Data Controller is entitled to send direct advertising and marketing messages to the electronic mail address provided by the Data Subject concerning services organized by the Data Controller. By subscribing to the newsletter service, the Data Subject expressly consents to receive news, newsletters, advertisements, and promotional offers from the Data Controller regarding the services it provides. 

If the Data Subject no longer wishes to receive messages that qualify as advertising in the future, he/she may unsubscribe at any time by using the option offered in the newsletter sent by the Data Controller, and may expressly prohibit the sending of advertising messages by postal or electronic mail addressed to the Data Controller. Such withdrawal does not affect the lawfulness of the data processing carried out on the basis of the consent prior to its withdrawal. 

12./ Provisions related to the use of Facebook, Google Analytics, Google Adwords, Hotjar applications 

12.1. Facebook 

You can find more information about cookies placed by Facebook at the following link: https://hu-hu.facebook.com/policies/cookies/ For more information on blocking cookies, please consult the attached link. 

12.2. Google Analytics 

Google Analytics is an analytics service provided by Google Inc. (“Google”) which, with the help of cookies stored on the user’s computer, examines user activities on the website. The legal basis for web analytics data processing is the voluntary consent of the website user. The cookies used for analytics produce anonymized and aggregated data, which makes it difficult to identify the specific device, but it is not excluded.  

The data collected by Google Analytics cookies are transmitted to and stored on Google’s servers. The collected information and data are processed by Google. Google’s purpose is to assess and evaluate users’ website visiting habits, to create reports on the frequency of website usage, and to provide other related services connected to website usage. In the application of Google Analytics, Google cannot link the IP address transmitted through the browser with other data.

Google Analytics uses cookies for analytical purposes. Further information about the cookies used by Google Analytics is available at the following link: https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie usage#analyticsjs 

12.3. Google Adwords 

The website uses Google Adwords remarketing tracking codes, which aim to target site visitors later with remarketing advertisements on websites belonging to the Google Display network. The remarketing code uses cookies to tag website visitors. Website users have the option to disable these cookies. They can do this by visiting Google’s ad settings manager and following the instructions found there. If they succeed in disabling the cookies, they will no longer see further personalized offers from the Service Provider.  

Further information about cookies used by Google can be viewed at the following link: https://policies.google.com/technologies/ads?hl=hu 

Google’s privacy policy can be viewed at the following link: https://policies.google.com/privacy?hl=hu 

12.4. Hotjar 

The website occasionally uses Hotjar web analytics to analyze users’ behavior. Hotjar examines user interactions on the website with the help of cookies on the user’s computer. The legal basis for web analytics data processing is the voluntary consent of the website user. The cookies used for analytics produce anonymized and aggregated data which makes it difficult to identify the specific device/computer, but it is not excluded.  

Hotjar uses cookies for analytical purposes. Further information about the cookies used by Hotjar is available at the following link: https://www.hotjar.com/legal/policies/cookie-information 

13./ Closing provisions 

When visiting the website, the Consumer’s IP address may be registered; however, the IT solutions used to operate the website do not allow the Data Controller to access the Consumer’s personal data, and these data are used solely for the development of the website and the improvement of services accessible through it (to prepare statistics and analyses). 

On first visit the website may install a so-called “cookie” (hereinafter: “süti”) on the Consumer’s computer or telephone hard drive or memory in order that on subsequent visits the page content and browsing/navigation become faster and simpler 

If the download of the “süti” is refused, some elements of the page may not be displayed. 

The Data Controller does not exchange “cookies” with websites operated by third parties, and does not allow them on its own website. The detailed rules of “cookie management” are contained in the cookie management pop-up windows on the www.brizlo.co.uk website.  

The Data Controller reserves the right to make changes and corrections to the website at any time without notice, and to discontinue the website or the information published on it in whole or in part. The Data Controller does not guarantee continuous or error-free access to the website, and the Data Controller is not liable for any damages that may occur due to malfunctions. 

The Data Controller is obliged to compensate for damage caused to others by the unlawful processing of the Data Subject’s data or by a breach of data security requirements, except where the damage resulted from the injured party’s intentional or grossly negligent conduct. 

14./ Applicable laws  

In matters not regulated in this Notice, the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), Act CXII of 2011 on the right to informational self-determination and freedom of information, Act V of 2013 on the Civil Code, and other applicable laws shall apply. 

This data processing notice was prepared in Hungarian.  

This data processing Notice is effective from today until revoked. 

Budapest, 11 September 2024.

Adopted by Pihepets Kft. (registered office: 1089 Budapest, Orczy út 12, tax number: 25481819-2-02, tel.: 0612109283, e-mail: info@brizlo.eu) (hereinafter: Data Controller).

1./ General provisions

 The subject of this privacy policy is the operation by the Data Controller of https://brizlo.co.uk/ The processing of personal data that came into the possession of the Data Controller in connection with the operation of an online store (hereinafter: webstore) on an internet site (hereinafter: website) is governed by Act CXII of 2011 on the right to informational self-determination and freedom of information (hereinafter: Infotv.), Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), and other applicable laws.

This Policy sets out the data protection and data processing principles applied by the Data Controller, through which the Data Controller ensures that the personal rights of natural persons who come into contact with it in connection with the services provided in relation to the webstore are not violated.

The Data Controller reserves the right to unilaterally amend its data protection policy and thus the content of this Policy in the event of changes to the services it provides, and in accordance with applicable statutory provisions. The Data Controller will publish notice of any change to this Policy on the website at the same time as the change.

2./ Persons affected by data processing

Those natural persons (hereinafter: Data Subject) who purchase the Data Controller’s products through the webstore (hereinafter: product sales), and who explicitly register for the newsletter service on the website,

 3./ Purpose of data processing

The Data Controller records and processes the personal data voluntarily provided by the Data Subjects for the following purposes related to product sales: conclusion of contracts related to product sales in the webstore, performance of contracts, termination of contracts, sending newsletters, and promotional information.

4./ Legal basis for data processing and source of the data

The legal basis for data processing is primarily the prior, voluntary consent given by the Data Subjects after adequate information regarding the processing, as well as the conclusion, performance and termination of contracts related to product sales.

The source of the data is the data voluntarily provided by the Data Subjects.

By providing his or her personal data on the website, or by subscribing to newsletters/promotional information, with a declaration made having read this Policy, the Data Subject expressly consents to the Data Controller processing the personal data he or she has voluntarily provided in accordance with this Policy.

If the Data Subject provides his or her data for the purpose of product sales, then the data will be processed for the purposes of concluding, performing and terminating contracts related to product sales. The Data Subject acknowledges that his or her data the processing for multiple data processing purposes as described above with a single consent is accepted upon purchase.

If the Data Subject subscribes to newsletters/promotional information, his or her data will be processed for the purpose of sending newsletters and promotional information. The Data Subject acknowledges that his or her data – the processing for multiple data processing purposes as described above with a single consent is accepted by subscribing.

 5./ Data relating to Data Subjects, duration of data processing

The data processing covers the following data of the Data Subjects:

In the case of product sales:

  • name,
  • residential address, billing address,
  • date of birth,
  • identity card number, or passport number, or driver’s license number,
  • email address.

In case of subscribing to newsletters/promotional information:

  • name,
  • e-mail address.

In the case of product sales, the provision of the data set out above to the Data Controller is a prerequisite for the conclusion and performance of the contract related to product sales.

In the case of subscribing to newsletters/promotional information, providing the data set out above is a prerequisite for sending the given electronic communications.

If the data is not provided, the Data Subject cannot conclude a contract related to product sales, nor receive the given communications.

Data processing begins upon completion of the registration interface (providing data for product sales or subscribing to newsletters/promotional information).

In the case of product sales, the Data Controller processes the data for six years.  

In the case of subscribing to newsletters/promotional information, the Data Controller processes the data until withdrawal, but for no more than ten years.

Upon expiration of the data processing period, the Data Controller irrevocably and permanently deletes the Data Subjects’ personal data.

The Data Subject may withdraw his or her consent to data processing at any time, without justification, verbally, in writing, or by electronic communication. In that case the Data Controller will irrevocably and permanently delete all data, except in the case of product sales for those data whose longer retention is required by civil, tax or other legislation.    

6./ Types of data transmitted

The Data Controller may not use personal data for purposes other than those specified. Personal data may only be transferred to third parties with the Data Subjects’ prior and informed consent, except in cases of data transfer mandatory under law.

7./ Obligations of the Data Controller’s performance auxiliaries during data processing

Personal data that comes to the Data Controller’s attention may only be accessed by the Data Controller’s performance auxiliaries who assist in achieving the data processing purposes set out in this Policy, and who are bound by a confidentiality obligation in respect of all data they have become aware of by virtue of their employment contract, assignment contract, other contract for the performance of work, applicable employment legislation, or the Data Controller’s instructions.

Compliance with the data processing policy is mandatory for the Data Controller and all of its performance auxiliaries – including former performance auxiliaries – (hereinafter: performance auxiliary) in the handling of Data Subjects’ personal data.

Neither during nor after the existence of their legal relationship may a performance auxiliary disclose to the public, share with another person, or make accessible to another person any personal data concerning the Data Subjects that they became aware of during the legal relationship.

A performance auxiliary may share personal data learned during the legal relationship with another performance auxiliary only if necessary for the performance of the work. A performance auxiliary may disclose personal data learned during the legal relationship to other third parties only with the Data Controller’s permission. A performance auxiliary may transfer personal data learned during the legal relationship only with the Data Controller’s permission, regardless of the means or method of transfer.

The performance auxiliary is obliged to immediately report to the Data Controller if they become aware of a breach of this Policy.

8./ Technical implementation of data processing:

The Data Controller stores the Data Subjects’ personal data exclusively electronically on servers located in Hungary; personal data are not transferred to any domestic or third-country Data Controller or data processor.

The Data Controller ensures the security of personal data through appropriate technical and organizational measures. The Data Controller equips the IT equipment used for processing and storing personal data with appropriate protection (passwords, firewall), and ensures that only authorized persons can access this equipment. The Data Controller also ensures that personal data will not be damaged, destroyed, or become accessible in the event of force majeure.

9./ Rights of Data Subjects in relation to data processing

The Data Subject may request from the Data Controller:

  • Information about the processing of his/her personal data: upon request the Data Controller shall, within at most 30 days from receipt of the request, provide information to the Data Subject about the data it processes about him/her, their source, the purpose, legal basis and duration of the processing, and – in the case of transfer of the Data Subject’s personal data – the legal basis and the recipient of the transfer. The provision of information may only be refused in cases specified by law. The information is free of charge if the requester has not previously submitted a request for information to the Data Controller in the current year regarding the same set of data. In other cases the Data Controller may charge a fee.
  • Correction of his/her personal data: if the personal data is not in accordance with reality, and the correct personal data is available to the Data Controller, the personal data shall be corrected ex officio, otherwise at the Data Subject’s request.
  • Supplementation of his/her personal data: if the personal data requires supplementation, and the data to be supplemented is available to the Data Controller, the personal data shall be supplemented ex officio, otherwise at the Data Subject’s request.
  • Deletion of his/her personal data: the Data Controller shall delete personal data if its processing is unlawful; if the Data Subject requests it; if the purpose of the processing has ceased, or the storage period for the data has expired, or a court or authority has ordered it.
  • Locking (blocking) of his/her personal data: instead of deletion, the Data Controller shall lock the personal data if the Data Subject requests this, or if, based on the information at its disposal, it may be assumed that deletion would prejudice the Data Subject’s legitimate interests. Such locked personal data may only be processed for as long as the data processing purpose that precluded the deletion exists.
  • Portability of his/her personal data: the personal data provided to the Data Controller shall be received by the Data Subject from the Data Controller in a structured, commonly used, machine-readable format, and the Data Subject is also entitled to transmit these data to another Data Controller.

In addition to the above, the Data Subject may object to the processing of his/her personal data if the processing or transfer of personal data is carried out solely for the fulfilment of a legal obligation applicable to the Data Controller or is necessary for the enforcement of the legitimate interest of the Data Controller, the recipient, or a third party.

The Data Controller shall examine the objection as soon as possible after receipt of the request, but no later than 15 days, decide on its merits, and inform the applicant in writing of its decision.

The details of the above rights are contained in Sections 14–19 and Section 21 of the Infotv.

The data subject is entitled to initiate proceedings before the National Authority for Data Protection and Freedom of Information concerning any data processing he or she considers unlawful.

In the cases specified in the Infotv, the data subject may bring an action before the courts (Infotv. 23. §). Jurisdiction for adjudicating the action lies with the court. At the data subject’s choice, the action may also be brought before the court of the data subject’s place of residence or place of stay.

  10./ Data protection incident

The following constitutes a data protection incident:

a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.

Examples of incidents include in particular: theft or loss of a “company” laptop or mobile phone, customer databases falling into unauthorized hands, the hacking of the online store’s IT system and access to data.

The Data Controller – through its managing director – shall promptly take the necessary steps and make the notifications required to remedy the data protection incident and to mitigate the damage resulting from it. 

If a data protection incident is likely to result in a high risk to the rights and freedoms of natural persons, the Data Controller shall, without undue delay, inform the data subject of the data protection incident. The information provided to the data subject must clearly and plainly describe the nature of the data protection incident and set out the most important information and measures.

The data subject need not be informed as described in the previous paragraph if any of the following conditions are met:

a) the Data Controller had implemented appropriate technical and organisational protection measures and applied those measures to the personal data affected by the data protection incident, in particular those measures (such as the use of encryption) that render the personal data unintelligible to any person not authorised to access it;

b) after the data protection incident the Data Controller has taken further measures which ensure that the high risk to the rights and freedoms of the data subject referred to above is unlikely to materialise;

c) providing the information would require disproportionate effort. In such cases the data subjects shall instead be informed by means of a public communication or by similar measures, thereby ensuring that the data subjects are informed in an equally effective manner.

 11./ Special rules pertaining to newsletter sending and advertising communications

The Data Controller sends messages to data subjects containing information about its products, services and news.

The data subject acknowledges that subscribing to the newsletter service also constitutes consent pursuant to Section 6 (1)-(2) of Act XLVIII of 2008 on the basic conditions and certain limitations of economic advertising activities, whereby the Data Controller is entitled to send direct advertising and marketing communications to the e‑mail address provided by the data subject. By subscribing to the newsletter service, the data subject expressly consents to the Data Controller sending him/her news, newsletters, advertisements and promotional offers related to the services provided.

If the data subject does not wish to receive messages classified as advertising in the future, he or she may unsubscribe by using the option offered in the newsletter sent by the Data Controller, and may also expressly prohibit the sending of advertising communications by sending a postal or electronic letter addressed to the Data Controller or by notifying the Data Controller in person.

 12./ Final provisions

When visiting the website the Consumer’s IP address may be registered; however, the IT solutions used to operate the website do not allow the Data Controller to access the Consumer’s personal data, and such data are used solely for the purpose of website development and improving the services accessible through it (for the preparation of statistics and analyses).

On the first visit the website may install so‑called “cookies” on the Consumer’s computer or phone hard drive or memory in order to make the page content and browsing/navigation faster and easier on subsequent visits. If downloading “cookies” is refused, certain elements of the page may not be displayable.

We do not exchange cookies with websites operated by third parties, nor do we allow them on our website.

The operation of Google Analytics on our website is enabled. This provides us with information about how visitors use the site. Google Analytics compiles the website’s visitation patterns based on anonymised users. We do not permit Google to use (including for its own purposes or to share with anyone) the data you provide.

The Data Controller reserves the right to make changes and corrections to the website at any time without notice, and to discontinue the website or any information contained therein in whole or in part. The Data Controller does not guarantee continuous or error‑free access to the website and shall not be liable for any damages that may occur due to malfunctions.

The Data Controller shall be liable to compensate for damage caused to others by unlawful processing of the data subject’s data or by a breach of data security requirements, except where the damage resulted from the injured party’s intentional or grossly negligent conduct.

For matters not regulated in this policy, the provisions of Act V of 2013 on the Civil Code, Act CXII of 2011 on the right of informational self‑determination and freedom of information, Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), and other applicable legislation shall apply.

The managing director is responsible for the Data Controller’s activities and for compliance with this data processing policy.

This data processing policy is valid from the date indicated until revoked.

Budapest, 2021.06.01.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.