Privacy Policy
Privacy Notice
This is an English translation provided for information purposes. In the event of any discrepancy, the Hungarian version of this notice shall prevail.
DATA PROCESSING POLICY
DATA PROCESSING POLICYTable of contents
Table of contents- Introduction
- Scope of the policy
- Scope of the policy
- Temporal scope
- Personal scope
- Material scope
- Data provided online / in the shop
- Right to amend
- Scope of the policy
- Application of the relevant law
- Relevant legislation
- Definitions
- Personal data
- Data processing
- Controller
- Processor
- Filing system
- Recipient
- Consent
- Third party
- Personal data breach
- Partner
- Staff member
- Website
- Principles
- Lawfulness, fairness and transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and confidentiality
- Accountability
- Rights of data subjects
- Right to information
- Right to rectification
- Right to erasure
- Right to restriction of processing
- Procedural rules
- Right to data portability
- Right to object
- Automated individual decision-making, including profiling
- Security principles of data processing
- Data processing related to the operation of the Company
- Newsletter, direct marketing activity, registration on the website
- Newsletter, direct marketing
- Registration on the website
- Designation of processors
- Cookies
- What is a cookie?
- Types of cookies
- Google Adwords
- Google Analytics
- Use of social media sites
- Complaint handling
- Legal remedy
- Compensation and damages for infringement of personality rights
- Complaint to the data protection auditor
- Right to turn to court
- Details of the Data Protection Officer
- Supervisory authority
- Legal statement
- Introduction, details and contact information of the Controller
In accordance with REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), we provide the following information.
THE CONTROLLER AND ITS CONTACT DETAILS:
Company name: GPS Food Kft.
Registered office: Hősök tere 7., 2235 Mende, Hungary
Company registration number: 13-09-214456
Tax number: 27195989-2-13
E-mail: office@gpsfood.hu
CONTACT DETAILS OF THE DATA PROTECTION OFFICER:
Name: Péter Elekes-Nagy
Registered office: Hősök tere 7., 2235 Mende, Hungary
E-mail: elekes.peter@gpsfood.hu
Phone: +36706220112
The Controller strives to comply as closely as possible with the recommendations of the Hungarian National Authority for Data Protection and Freedom of Information, in particular its recommendation issued on 29 September 2015 on the data protection requirements of prior information. For this reason it sets out the data protection rules as clearly as possible, explaining them with examples where necessary, and presents each data processing activity in detail, so that the data subject can decide, in full knowledge of these, whether or not to give their voluntary consent to them.
If you wish to contact our Company, you may reach the Controller using the contact details given in this notice and published on the website, and by using the form found in the „Contact” menu of the www.gpsfood.hu
website.
The Company deletes every e-mail received by it, together with the sender's name, e-mail address, the date and time data and any other personal data given in the message, five years after the data was provided.
We provide information on any data processing not listed in this notice at the time the data is collected.
We inform data subjects that the court, the public prosecutor, the investigating authority, the authority acting in administrative offence cases, the public administration authority, the Hungarian National Authority for Data Protection and Freedom of Information, and other bodies authorised by law may contact the Controller in order to obtain information, to have data disclosed or transferred, or to have documents made available.
The Company discloses personal data to the authorities – provided that the authority has specified the precise purpose and the scope of the data – only to the extent and in the volume that is strictly necessary to achieve the purpose of the request.
- Scope of the policy (it covers data provided online and/or in the shop, right to amend)
- Scope of the policy
- Temporal scope:
This Policy is in force from 22 June 2018 until further provision or withdrawal.
- Personal scope
The personal scope of this Policy extends to:
- the Controller, furthermore
- those persons whose data is contained in the data processing operations falling within the scope of this Policy, furthermore
- those persons whose rights or legitimate interests are affected by the data processing
The Controller therefore primarily processes the data of those natural persons who
- through a channel or in a manner available to them – for example electronically, by sending their data to any e-mail address of the Controller, through a social media site, by telephone or in person –
- got in touch in order to establish contact,
- used or requested the services of the Controller; or
- got in touch for a reason or purpose other than establishing contact;
- are natural person Partners of the Controller, or the representatives, contact persons or other employees of its non-natural person Partners.
- Material scope:
The scope of this Policy extends to all data processing containing personal data carried out in every organisational unit of the Controller, irrespective of whether it takes place electronically and/or on paper. In the case of paper-based data processing, the Controller also introduces and operates an archiving policy formally separate from this policy, which supplements the general provisions of this Policy and to which the scope of this Policy extends; it is therefore to be regarded as an annex to this Policy.
- Data provided online / in the shop
The scope of this notice extends, on the one hand, to the processing of personal data provided on the Company's online portal available at www.gpsfood.hu and, on the other hand, to personal data provided at the Company's registered office/premises/shops in connection with the use of its services.
- Right to amend
The Company reserves the right to amend this notice at any time, and will inform its partners of any changes in good time. Amendments to the notice enter into force upon publication on the Company's website. If data subjects have a question that is not clear from this notice, please write to us and our colleague will answer it.
The Company is committed to keeping the quality of its services at the highest level; it does not, however, accept liability for any damage arising from the use of the system.
- Application of the relevant law
Any legal dispute concerning the Company and its services falls under Hungarian jurisdiction and the competence of the Hungarian courts, on the basis of Hungarian law.
- Relevant legislation
The Company's data processing principles are in line with the data protection legislation in force, in particular with the following:
- Act CLV of 1997 on consumer protection (Fgytv.);
- Act XIX of 1998 on criminal proceedings (Be.);
- Act C of 2000 on accounting (Számv. tv.);
- Act CVIII of 2001 on certain issues of electronic commerce services and information society services (Eker. tv.);
- Act C of 2003 on electronic communications (Eht.);
- Act CXXXIII of 2005 on the rules of personal and property protection and private investigation activities (SzVMt.);
- Act XLVIII of 2008 on the basic conditions and certain restrictions of business advertising activity (Grt.),
- Act XLVII of 2008 on the prohibition of unfair commercial practices against consumers,
- Act CXII of 2011 on the right to informational self-determination and freedom of information (Infotv.);
- Act CLIX of 2012 on postal services (Postatv.).
- Act V of 2013 on the Civil Code (Ptk.);
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).
- Definitions
- Personal data:
Any information relating to an identified or identifiable natural person („data subject”); a natural person is identifiable if they can be identified, directly or indirectly, in particular by reference to an identifier such as a name, a number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
- Data processing:
Any operation or set of operations performed on personal data or on sets of data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
- Controller:
The natural or legal person, or organisation without legal personality, who or which, alone or jointly with others, determines the purpose of the processing of the data, takes and implements the decisions concerning the processing (including the means used), or has them implemented by a processor engaged by it; thus, for the purposes of this Policy, the Controller means the persons defined in Chapter 1 jointly;
- Processor:
The natural or legal person, public authority, agency or any other body which processes personal data on behalf of the controller;
- Filing system:
The set of data processed in one register;
- Recipient:
The natural or legal person, public authority, agency or any other body to which the personal data is disclosed, whether or not a third party. Public authorities which may have access to personal data in the framework of a particular inquiry in accordance with Union or Member State law are not regarded as recipients; the processing of that data by those public authorities must comply with the applicable data protection rules according to the purposes of the processing;
- Consent:
The voluntary and specific indication of the data subject's wishes, based on adequate information, by which they give their unambiguous agreement to the processing – in full or in respect of certain operations – of personal data relating to them; consent therefore has 3 basic elements: it must be voluntary, specific, and adequately informed;
- Third party:
A natural or legal person, or organisation without legal personality, who or which is not the same as the data subject, the controller or the processor;
- Personal data breach:
The unlawful processing or handling of personal data, in particular unauthorised access, alteration, transmission, disclosure, erasure or destruction, as well as accidental destruction and damage;
- Partner:
Legal persons and business associations without legal personality which use the Controller's services under a contract and/or assist in the performance of the Controller's services (performance agents), to which the Controller – following the consent of the data subject – transfers or may transfer personal data, or which carry out or may carry out data storage, processing, related IT and other activities supporting secure data processing for the Controller;
- Staff member:
A natural person in a contractual, employment or other legal relationship with the Controller, who is entrusted with the task of providing or performing the Controller's services and who, in the course of their data processing or data handling tasks, comes or may come into contact with personal data, and for whose activities the Controller accepts full responsibility towards the data subjects and third parties;
- Website:
The portal and all of its subpages, operated by the Controller;
- Social media page:
The page found on the portal, linked to the website and its content, which is maintained by the Controller.
- List of principles (purpose limitation, accuracy, etc.)
- Lawfulness, fairness and transparency:
Personal data must be processed lawfully, fairly and in a transparent manner in relation to the data subject;
- Purpose limitation:
Personal data must be collected only for specified, explicit and legitimate purposes and must not be processed in a manner that is incompatible with those purposes; in accordance with Article 89(1), further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes is not considered incompatible with the original purposes;
- Data minimisation:
Personal data must be adequate and relevant in relation to the purposes of the processing, and limited to what is necessary;
- Accuracy:
Personal data must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that is inaccurate in relation to the purposes of the processing is erased or rectified without delay;
- Storage limitation:
Personal data must be stored in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data is processed; personal data may be stored for longer periods only where the personal data will be processed for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1), subject also to the implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of data subjects;
- Integrity and confidentiality:
Personal data must be processed in a manner that ensures appropriate security of the personal data by applying appropriate technical or organisational measures, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage.
- Accountability:
The controller is responsible for compliance with the above and must be able to demonstrate such compliance.
- Rights of data subjects (erasure, right to be forgotten, objection, etc.)
The data subject may request information about the processing of their personal data, and may request the rectification of their personal data and – with the exception of mandatory processing – its erasure or blocking, by filling in the relevant request form.
- Right to information:
At the request of the data subject, the Company, as Controller, provides information about the data it processes or that is processed by the processor engaged by it, about the source of that data, the purpose, legal basis and duration of the processing, the name and address of the processor and its activities related to the processing, the circumstances and effects of any personal data breach and the measures taken to remedy it, and, in the case of a data transfer, its legal basis and recipient.
The Company provides the information in the shortest possible time from the submission of the request, but no later than within 25 days, in an intelligible form and, at the data subject's request to that effect, in writing.
This information is free of charge if the person requesting it has not yet submitted a request for information relating to the same set of data to the controller in the current year. In other cases the Company sets a cost reimbursement.
The Company may refuse to inform the data subject only in the cases specified by law.) In the event of a refusal, the Company informs the data subject in writing of the provision of the Information Act on the basis of which the information was refused. In the event of a refusal, the Company informs the data subject of the possibility of judicial remedy and of turning to the Supervisory Authority (NAIH).
- Right to rectification:
If personal data does not correspond to reality, and the personal data corresponding to reality is available to the Company, the Company rectifies the personal data.
- Right to erasure:
The Company erases personal data if:
- its processing is unlawful;
- the data subject requests it (except where the processing is mandatory under law);
- it is incomplete or incorrect – and this state of affairs cannot lawfully be remedied – provided that erasure is not excluded by law;
- the purpose of the processing has ceased, or the statutory time limit for storing the data has expired (except for data whose medium must be handed over to archival custody under the legislation on the protection of archival material);
- it is ordered by the court or the Authority
The processing of data is unlawful if:
- the data is incomplete or incorrect – and this state of affairs cannot lawfully be remedied – provided that erasure is not excluded by law;
- the purpose of the processing has ceased, or the statutory time limit for storing the data has expired;
- it has been ordered by the court or the Authority.
- the personal data is no longer necessary for the purpose for which it was collected or otherwise processed;
- the data subject objects to the processing and there is no overriding legitimate ground for the processing;
Limits of erasure:
- exercising the right to freedom of expression and information;
- compliance with an obligation under Union or Member State law applicable to the controller which requires the processing of personal data, or the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- public interest in the area of public health;
- archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) of Regulation (EU) 2016/679, where the right to erasure is likely to render impossible or seriously impair the achievement of that processing; or
- the establishment, exercise or defence of legal claims.
- Right to restriction of processing:
The data subject has the right to obtain from the controller restriction of processing where one of the following applies:
- the data subject contests the accuracy of the personal data, in which case the restriction applies for a period enabling the controller to verify the accuracy of the personal data;
- the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of its use instead;
- the controller no longer needs the personal data for the purposes of the processing, but the data subject requires it for the establishment, exercise or defence of legal claims; or
- the data subject has objected to the processing; in this case the restriction applies for the period until it is established whether the legitimate grounds of the controller override those of the data subject.
Where processing is subject to restriction, such personal data may, with the exception of storage, be processed only with the data subject's consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State.
The Controller informs the data subject at whose request the processing was restricted before the restriction of processing is lifted.
- Procedural rules:
The Controller has 25 (twenty-five) days to erase, restrict or rectify personal data. Where necessary, taking into account the complexity of the request and the number of requests, this period may be extended by a further two months. The controller informs the data subject of the extension of the deadline, indicating the reasons for the delay, within one month of receiving the request. If the data subject submitted the request electronically, the information is provided electronically, unless the data subject requests otherwise.
If the Controller does not fulfil the data subject's request for rectification, blocking or erasure, it communicates the reasons for the refusal within 25 (twenty-five) days in writing or, with the data subject's consent, electronically.
In the event of a refusal of the request, the Controller informs the data subject of the possibility of judicial remedy and of turning to the Authority. In the event of an infringement of their rights, the data subject may turn to the court. It is for the Controller to prove that the processing complies with the provisions of the law. Adjudication of the case falls within the competence of the regional court. The action may also be brought – at the data subject's choice – before the regional court of the data subject's place of residence or place of stay.
The Controller notifies the data subject of any rectification, blocking, marking and erasure, as well as all those to whom it previously transferred the data for processing purposes. It omits the notification if this does not infringe the data subject's legitimate interest in view of the purpose of the processing.
- Right to data portability
The data subject has the right to receive the personal data concerning them which they have provided to the controller in a structured, commonly used, machine-readable format, and to transmit that data to another controller.
- Right to object:
The data subject may object to the processing of their personal data if
- the processing or transfer of the personal data is necessary solely for the fulfilment of a legal obligation applicable to the controller or for the enforcement of the legitimate interest of the controller, the recipient of the data or a third party, except where the processing was ordered by law;
- the personal data is used or transferred for the purpose of direct marketing, public opinion polling or scientific research;
- in any other case specified by law.
The Company examines the objection within the shortest possible time from the submission of the request, but no later than within 15 days, takes a decision on whether it is well founded, and informs the applicant of its decision in writing. If the Company establishes that the data subject's objection is well founded, it terminates the processing – including any further data collection and data transfer – and blocks the data, and notifies of the objection and of the measures taken on the basis of it all those to whom it previously transferred the personal data concerned by the objection and who are obliged to take action in order to enforce the right to object.
If the data subject does not agree with the decision taken by the Company, they may turn to the court within 30 days of its communication.
The Company may not erase the data subject's data where the processing was ordered by law. The data may not, however, be transferred to the recipient of the data if the Company agreed with the objection, or if the court established that the objection was justified.
- Automated individual decision-making, including profiling
The data subject has the right not to be subject to a decision based solely on automated processing – including profiling – which produces legal effects concerning them or similarly significantly affects them.
The above right does not apply if the processing is necessary for entering into or performing a contract between the data subject and the controller; if it is authorised by Union or Member State law applicable to the controller which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests; or if it is based on the data subject's explicit consent
- Security principles of data processing
The Company selects and operates the IT tools used for processing personal data in the course of providing the service in such a way that the processed data is:
- accessible to those entitled to it (availability);
- its authenticity and authentication are ensured (authenticity of the processing);
- its unchanged state can be verified (data integrity);
- protected against unauthorised access (confidentiality of the data).
The Company protects the security of the processing by technical, organisational and structural measures that provide a level of protection appropriate to the risks arising in connection with the processing.
In the course of the processing the Company preserves
- confidentiality: it protects the information so that only those entitled to it can access it;
- integrity: it protects the accuracy and completeness of the information and of the method of processing;
- availability: it ensures that when an authorised user needs it, they can actually access the required information and that the related tools are available.
The Company's IT system and network are equally protected against computer-assisted fraud, espionage, sabotage, vandalism, fire and flood, as well as computer viruses, computer intrusions and denial-of-service attacks. The operator ensures security by means of server-level and application-level protection procedures.
We inform data subjects that electronic messages transmitted over the internet are vulnerable, irrespective of the protocol (e-mail, web, ftp, etc.), to network threats that may lead to unfair activity, disputing of a contract, or the disclosure or modification of information. The Company takes every precaution that can reasonably be expected of it in order to protect against such threats. It monitors its systems so that it can record every security deviation and provide evidence in the case of every security event. System monitoring also makes it possible to check the effectiveness of the precautions applied.
- Data processing related to the operation of the Company[1]
|
Data subjects |
Data processed |
Purpose of the processing |
Legal basis of the processing |
|||||||||||||||||
|
Employees |
Administration related to the employment relationship. |
Act CXII of 2011 (Infotv.), Act I of 2012 (Labour Code), Act CL of 2017 (Act on Rules of Taxation) and the consent of the data subject. |
||||||||||||||||||
|
Partners |
Enabling and facilitating cooperation and contact between the Company and its partners. |
Act CXII of 2011 (Infotv.), Act CLXIV of 2005 (Act on Trade) and the consent of the data subject. |
||||||||||||||||||
|
Customers |
The purpose of the processing is to provide the data subject with appropriate information and offers and to keep in touch, to enable a complaint to be communicated, to identify the complaint, and to collect the obligations and mandatory data arising from the law. |
Act CXII of 2011 (Infotv.) and the consent of the data subject. |
||||||||||||||||||
|
Webshop customers |
|
Act CXII of 2011 (Infotv.), Act CVIII of 2001 (Eker. tv.) and the consent of the data subject. |
||||||||||||||||||
|
Newsletter subscribers |
Name, e-mail address |
The purpose of the processing related to sending the newsletter is to provide the recipient with full general or personalised information about the Controller's latest promotions, events and news, and to notify them of changes to or cancellation of services. |
Act CXII of 2011 (Infotv.), Act CVIII of 2001 (Eker. tv.) and the consent of the data subject. |
- Newsletter, direct marketing activity, registration on the website
- Newsletter and direct marketing
Pursuant to Section 6 of Act XLVIII of 2008 on the basic conditions and certain restrictions of business advertising activity, the data subject may give prior and express consent to the Company contacting them with advertising offers and other communications at the contact details provided at registration.
Furthermore, bearing in mind the provisions of this notice, the data subject may consent to the Company processing the personal data necessary for sending advertising offers.
The Company does not send unsolicited advertising messages, and the data subject may unsubscribe from receiving offers free of charge, without restriction and without giving reasons. In that case the Company erases from its records all personal data necessary for sending advertising messages and does not contact the data subject with further advertising offers. The data subject may unsubscribe from advertisements by clicking on the link in the message.
Scope of data subjects: all data subjects who subscribe to the newsletter.
Purpose of the processing: sending electronic messages containing advertising (e-mail, SMS, push message) to the data subject, providing information about current news, products, promotions and new functions.
Duration of the processing, deadline for erasing the data: the processing lasts until the consent statement is withdrawn, that is, until unsubscription.
- Registration on the website
Purpose of the processing: purchasing in the Company's web shop, issuing an invoice, distinguishing customers from one another, fulfilling orders, documenting the purchase and the payment, fulfilling accounting obligations, keeping in touch with customers, analysing customer habits, more targeted service, contacts with direct marketing content, and providing information about current news and offers.
Legal basis of the processing: the voluntary consent of the data subject, Section 13/A of Act CVIII of 2001, Section 169(2) of Act C of 2000 and Section 6(5) of Act XLVIII of 2008.
Type of personal data processed: customer number, salutation, NAME, other address, home address, e-mail address, telephone number, date of birth, the e-mail address and password required for login, the details of each purchase (date, time, product purchased, value of the purchase), billing address, delivery address, and the consent given to being contacted for direct marketing purposes.
Duration of the processing:
- for direct marketing consents, until the data subject withdraws their consent,
- for profile data, four years from the last login,
- for purchase data, eight years pursuant to Section 169(2) of Act C of 2000.
In the case of card payment, the bank card data and the data of the card payment transaction are processed by ConCardis GmbH (Helfmann-Park 7, 65760 Eschborn, Germany), and where payment via PayPal is chosen, by the PayPal financial intermediary system (PayPal Europe S.à r.l. & Cie, S.C.A. 5th Floor 22-24 Boulevard Royal, L-2449, Luxembourg).
Data transfer:
- where bank card payment is chosen, the payer's identifier, the amount, date and time of the transaction to ConCardis GmbH (Helfmann-Park 7, 65760 Eschborn, Germany),
- where payment via PayPal is chosen, the customer's name, the amount of the payment, the date and time to the PayPal financial intermediary system (PayPal Europe S.à r.l. & Cie, S.C.A. 5th Floor 22-24 Boulevard Royal, L-2449, Luxembourg),
- where products are delivered, the recipient's name and address and the value of the order to ……. (the carrier).
Legal basis of the data transfer: the voluntary consent of the data subject and, in respect of the ………. (carrier), Section 54(1) of Act CLIX of 2012.
Withdrawal of the consent given to the transmission of direct marketing messages and the erasure or modification of personal data may be requested at the following contact points:
- on the www.gpsfood.hu website, by logging in to My Account,
- by e-mail at info@gpsfood.hu, and
- by post at Hősök tere 7., 2235 Mende, Hungary.
- Designation of processors
|
Processor |
Information related to the processing |
Legal basis of the processing |
|
Carrier
|
The duration of the processing and the deadline for erasing the data is the completion of the home delivery. |
the User's consent, Act CXII of 2011 (Infotv.) |
|
Online payment service provider |
Scope of the data processed: billing name, billing address, e-mail address. The purpose of the processing is to complete the online purchase, to confirm transactions and to carry out fraud monitoring (checking for abuse) in order to protect users. Duration of the processing, deadline for erasing the data: the completion of the online payment. |
the data subject's consent, Act CXII of 2011 (Infotv.), Act CVIII of 2001 (Eker. tv.) |
|
Hosting provider
|
The purpose of the processing is to make the website available and to operate it properly. The processing lasts until the registration is deleted. |
the data subject's consent, Act CXII of 2011 (Infotv.), Act CVIII of 2001 (Eker. tv.) |
- Cookies
- What is a cookie?
Cookies are small text files in which websites store information relating to visits for a specified period and purpose. On repeat visits the website is able to recognise the text file and thereby identify the earlier visitor.
The primary function of cookies is to make browsing more convenient and personalised, since they allow various personal data and settings to be stored. Cookies also make well-targeted, personalised advertising campaigns possible.
The www.gpsfood.hu website, having regard to the provisions of Section 155(4) of Act C of 2003, according to which „data may be stored on, or accessed from, the electronic communications terminal equipment of a subscriber or user only with the consent of the user or subscriber concerned, given after clear and comprehensive information – also covering the purpose of the data processing – has been provided”, provides the following information in connection with the analytical tools, that is, cookies, used by it.
The Company created its website with the help of the portal, and the website uses the portal's engine. The portal and the pages created with the help of the portal may use the cookies specified below; the Controller, however, does not itself use these cookies in any way. The cookies used may communicate between the data subject's device and the portal, and do not transmit or hand over any data to the Controller; therefore, in respect of the cookies used, the portal's own data processing guide applies.
- Types of cookies
The cookies used on the Company's website can be classified into 4 different categories, in line with the classification of the International Chamber of Commerce: strictly necessary for operation, performance-improving, storing individual settings, and serving web analytics and the targeting of advertisements.
Types
- Strictly necessary for operation
This type of cookie is what makes browsing on the website possible. Without these cookies it becomes impossible to serve the content visited on the Company's website (including the use of secure protocols).
The Company's website identifies you while you use the site with the help of a cookie containing an encrypted character string. Every time you enter the data subject interface, we place a cookie containing this unique identifier on your machine. For example: session cookie
These cookies are strictly necessary for the operation of the website, so there is no possibility of blocking them.
Please do not continue to use the Company's website if you do not wish these cookies to be downloaded in your browser.
Please do not continue to use the Company's website if you do not wish these cookies to be downloaded in your browser.- Performance-improving
These cookies collect information about the way visitors use a website: for example, which of its pages they visit most often and where visitors run into error messages.
These cookies do not store information by which websites could identify visitors. The information collected with their help is used exclusively in aggregated, anonymous form. Their purpose is to improve the functions available on the Company's website and the user experience. For example: has_js__cdrop
Cookies collecting data about the performance of the website can be blocked and deleted in the browser settings. You can read further information here
- Storing individual settings
These cookies make it possible to store the user name used on the website and the selected language preference. For example, a website is able to serve local news on the basis of the visitor's geographical location stored in a cookie. These cookies are suitable for storing a changed font size and other similar settings. The settings stored in cookies are anonymous. Their stored values cannot be traced back to individual data subjects by the operator. For example: Drupal.tableDrag.showWeight Drupal.toolbar.collapsed
Cookies storing personal settings can be blocked and deleted in the browser settings. You can read further information here.
Blocking this cookie type affects the functions of the Company's website and thereby the user experience.
- Cookies serving web analytics and the targeting of advertisements
These cookies make it possible for visitors to encounter advertising messages matching their interests.
The operator of the Company's website uses the Google Analytics service for the statistical analysis of visitor behaviour. Although the information handed over to the third party does not contain personal data, traffic data can in certain cases be traced back to data subjects
The operator of the Company's website uses Google Adwords and other advertising systems to display its online advertisements. These service providers may store visitors' IP addresses and other identifying information – not qualifying as personal data – in order to display the Company's advertisement on external websites later on. For example: id, RSMKTO1, _mkto_trk, __utma, __utmb, __utmc, __utmz
You can read more detailed information about cookies serving web analytics and the targeting of advertisements, and about blocking them, here
- Google Adwords
The controller uses the online advertising programme called „Google AdWords” and, within its framework, also uses Google's conversion tracking service. Google conversion tracking is an analytics service of Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; „Google”).
When a data subject reaches a website through a Google advertisement, a cookie required for conversion tracking is placed on their computer. The validity of these cookies is limited and they do not contain any personal data, so the data subject cannot be identified by them.
When the data subject browses certain pages of the website and the cookie has not yet expired, both Google and the controller can see that the data subject clicked on the advertisement.
Every Google AdWords data subject receives a different cookie, so they cannot be tracked across the websites of AdWords data subjects.
The information obtained with the help of conversion tracking cookies serves the purpose of preparing conversion statistics for those data subjects who opt for AdWords conversion tracking. Data subjects thereby learn the number of data subjects who clicked on their advertisement and were forwarded to a page bearing a conversion tracking tag. They do not, however, gain access to information by which any data subject could be identified.
If you do not wish to take part in conversion tracking, you may refuse it by disabling the option of installing cookies in your browser. You will then not appear in the conversion tracking statistics.
Further information, as well as Google's privacy notice, is available on the following page: www.google.de/policies/privacy/
- Google Analytics
This website uses Google Analytics, a web analytics service of Google Inc. („Google”). Google Analytics uses so-called „cookies”, text files that are saved on your computer and thus help to analyse the use of the web page visited by the data subject.
The information created by the cookies relating to the website used by the data subject is usually transmitted to and stored on one of Google's servers in the USA. By activating IP anonymisation on the website, Google shortens the data subject's IP address beforehand within the member states of the European Union or in other states party to the Agreement on the European Economic Area.
The full IP address is transmitted to Google's server in the USA and shortened there only in exceptional cases. On behalf of the operator of this website, Google will use this information to evaluate how the data subject used the website, to prepare reports for the website operator relating to website activity, and to perform further services connected with website and internet use.
Within the framework of Google Analytics, the IP address transmitted by the data subject's browser is not combined with other Google data. The data subject may prevent the storage of cookies by setting their browser accordingly; please note, however, that in this case not all functions of this website may be fully usable. You may also prevent Google from collecting and processing the data generated by cookies relating to your use of the website (including your IP address) by downloading and installing the browser plugin available at the following link. https://tools.google.com/dlpage/gaoptout?hl=hu
- Use of social media sites
Pursuant to Section 20(1) of Act CXII of 2011 on the right to informational self-determination and freedom of information, the following must be specified in respect of data processing on social media sites:
- a) the fact of the data collection,
- b) the scope of the data subjects,
- c) the purpose of the data collection,
- d) the duration of the processing,
- e) the identity of the possible controllers entitled to access the data,
- f) a description of the data subjects' rights relating to the processing.
The fact of the data collection and the scope of the data processed: the name registered on social media sites such as Facebook/Google+/Twitter/Pinterest/Youtube/Instagram, and the data subject's public profile picture.
Scope of the data subjects: those natural persons who voluntarily follow, share or like the Controller's social media pages, in particular its page on the social media site facebook.com, or the content appearing on them.
Purpose of the data collection: sharing, „liking” and promoting individual content elements, products and promotions of the website, or the website itself, on social media sites.
Duration of the processing, deadline for erasing the data, the identity of the possible controllers entitled to access the data and a description of the data subjects' rights relating to the processing: the data subject can obtain information about the source of the data, its processing, the manner of transfer and its legal basis on the given social media site. The processing takes place on the social media sites, so the rules of the given social media site apply to the duration and manner of the processing and to the possibilities of erasing and modifying the data.
Legal basis of the processing: the voluntary consent of the data subject to the processing of their personal data on social media sites.
The Company is present on the Facebook social media portal and on other social media sites.
The use of social media sites, in particular the Facebook page, and making contact and keeping in touch with the Controller through it, as well as other operations permitted by the social media site, are based on voluntary consent.
The Controller communicates with data subjects only if the data subject contacts the Controller through the social media site, and the purpose of the data becomes relevant only in that case.
The purpose of being present on social media portals, in particular on Facebook, and of the related data processing, is the sharing, publication and marketing of the content found on the website on social media. With the help of the social media site the data subject can also learn about the latest promotions.
Under the terms of the social media site, the data subject voluntarily consents by following and liking the Controller's content. By way of example, the data subject may subscribe to the news feed published on the message wall of the Facebook page by clicking on the „like” link found on the page, thereby consenting to the publication of the Controller's news and offers on their own message wall, and may unsubscribe by clicking on the „dislike” link found in the same place; furthermore, they may delete unwanted news feeds appearing on the message wall using the settings of the message wall.
The data subject may rate the Controller in text and in numbers, if the social media site allows this.
On its social media page, in particular its Facebook page, the Controller also publishes photos/video recordings about various events, the Controller's services and other matters. The Controller may link the Facebook page with other social media sites in accordance with the rules of the facebook.com social media portal; publication on the Facebook page therefore also includes publication on such linked social media portals.
Where the recording is not of a crowd or of a public appearance (Section 2:48 of the Civil Code), the Controller always obtains the data subject's written consent before publishing the images.
The data subject can obtain information about the data processing of the given social media site on that social media site; accordingly, information about the data processing of the Facebook page can be obtained at the address indicated there.
Duration of the processing: until erasure at the data subject's request.
- Complaint handling
Compensation and damages for infringement of personality rights:
The Company compensates any damage caused to another person by the unlawful processing of the data subject's data or by breaching the data security requirements. In the event of an infringement of the data subject's personality rights, the data subject may claim damages for infringement of personality rights (Section 2:52 of the Civil Code).
The Company is also liable towards the data subject for damage caused by the processor.
The Company is released from liability if the damage was caused by an unavoidable cause outside the scope of the processing.
The Company does not compensate the damage, and no damages for infringement of personality rights may be claimed, to the extent that the damage or the infringement caused by the violation of personality rights resulted from the intentional or grossly negligent conduct of the injured party or the data subject.
Complaint to the Data Protection Officer:
If you have a question or a problem in connection with the Company's data processing, please feel free to turn to our Data Protection Officer.
Data protection authority procedure:
A complaint may be lodged with the Hungarian National Authority for Data Protection and Freedom of Information:
Name: Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság)
Registered office: Szilágyi Erzsébet fasor 22/C., 1125 Budapest, Hungary
Postal address: 1530 Budapest, P.O. Box 5.
Phone: 06.1.391.1400
Fax: 06.1.391.1410
E-mail: ugyfelszolgalat@naih.hu
Website: http://www.naih.hu
- Supervisory Authority
A legal remedy or a complaint may be sought from the Hungarian National Authority for Data Protection and Information:
- Name: Hungarian National Authority for Data Protection and Information
- Registered office: Szilágyi Erzsébet fasor 22/c., 1125 Budapest, Hungary
- Postal address: 1530 Budapest, P.O. Box 5.
- Phone: +36 (1) 391-1400
- Fax: +36 (1) 391-1410
- Website: http://naih.hu
- Legal statement
The Company publishes the information and documents displayed on the website for information purposes only. The trademarks and logos displayed, as well as the information and other materials available, are protected by copyright, and the related rights belong exclusively to the Controller.
The trademarks found on the website are protected as trademarks. Without express prior written consent, no third party may use, copy, distribute or publish them in any manner or on any legal basis. It is prohibited to create a link from the website to any other website without prior written consent. Unlawful use may entail the legal consequences set out in copyright, civil and criminal legislation.
The data subject may use the information in its original form, exclusively for their own purposes, download it to their computer and print it. This permission allows only the handling and archiving of one original copy of the website.
The Company does not give any guarantee of any kind – unless the law provides otherwise – as to the accuracy, reliability or content of the website displayed on the data subject's screen with regard to changes independent of the Company.
The Company reserves the right to modify the content displayed on the website and to discontinue its availability.
The Company does not guarantee, nor does it provide any assurance of, the continuity or error-free nature of access to the website.
The Company excludes liability for any damage or loss arising from access to the website or to the information and documentation appearing there, from their direct or indirect use, from the website being unfit for use, or from improper operation, deficiencies, any outage or ambiguity.
The Company accepts no liability for materials created, transmitted or published by a third party which are linked to, or referred to by, the Company's website.
If the data subject makes written material available to the Company, the data subject acknowledges that it is suitable for publication and accepts that the Company may publish it – without accepting any liability – and may use its content in whole or in part with an indication of authorship. By doing so, the data subject also undertakes that the document or content made available does not infringe the copyright or other rights of any third party, that they will not initiate legal proceedings against the Company in connection with them, will not submit any claim or enforce any right, and, in the event of a third-party claim, will indemnify the Company.
The Company's website may also lay down provisions differing from these rules, in line with the legislation in force; knowledge and acceptance of the rules and terms of use in force at any given time is therefore a condition of using and making use of the individual services.
This policy qualifies as a work protected by copyright; it is prohibited to copy, reproduce or re-communicate to the public the whole or any part or detail of the Policy, and to distort, mutilate, use, utilise, process or sell the work in whole or in part in any manner without the written consent of the author. The author of the Policy is the Controller.
[1] In the table, the scope of data subjects narrows or widens depending on the Company's services.