Privacy Notice
1. Introduction
1.1. The purpose of this privacy notice
The purpose of this Privacy Notice (hereinafter: „the Notice”) is to set out, in a transparent and detailed manner, how we process personal data in the course of the activities of ([company name],hereinafter referred to as the „Data Controller”) in the course of its activities, and to provide information on the rights of data subjects and how to exercise them.
1.2. Regulatory compliance (GDPR, Act CXII of 2011)
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR): lays down uniform EU rules on the protection of personal data.
- Act CXII of 2011 (Infotv.): the Act forming the basis of Hungarian data protection legislation, which deals with the right to informational self-determination and freedom of information.
This Prospectus is intended to comply with the requirements set out in the above legislation.
2. Details of the data controller
2.1. Name and contact details of the data controller
- Name:
- Registered office:
- Registration number:
- Tax number:
- Member of Parliament:
- Email: czigany.judit01@gmail.com
- Telephone number: +36 30 521 4188
2.2. Availability of the privacy notice
This Prospectus is available in electronic form at [page name] on the page.
3. Definitions
3.1. Basic concepts of the GDPR
- Personal data: any information relating to an identified or identifiable natural person („data subject”).
- Data Controller: a natural or legal person who determines the purposes and means of the processing of personal data.
- Data processor: a natural or legal person who processes personal data on behalf of the Data Controller.
- Consent: a voluntary and explicit expression of the data subject’s will, by which they give their consent to the processing of their personal data.
- Affected: any identified or identifiable natural person to whom the personal data relates.
3.2. Definition of a data breach
A data breach is defined as any incident resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data that has been transmitted, stored or otherwise processed.
4. Data processing guidelines
4.1. Legal bases and fundamental principles
- Legality, due process and transparency: We process data only for specific and lawful purposes.
- Purpose-driven: Only for a pre-determined purpose, and only to the extent necessary to achieve that purpose.
- Data efficiency: We collect and process only those personal data that are essential for achieving the purpose.
- Accuracy: We ensure that the personal data we process is accurate and, where necessary, kept up to date.
- Limited shelf life: We only retain personal data for as long as is necessary to fulfil the purpose for which it was collected.
- Integrity and confidentiality: We implement appropriate technical and organisational measures to protect personal data.
4.2. Accuracy and security of data
- Both the Data Controller and the data subject are responsible for ensuring that the data is updated regularly; the data subject is obliged to notify the Data Controller of any changes to their personal data.
- The Data Controller shall do everything in its power to ensure that the data on file is accurate and to protect it from unauthorised access by means of appropriate security measures.
5. Purposes and legal bases for data processing
5.1. Registration on the website
- Objective: Creating a user account and providing the associated services.
- Legal basis:
- Consent (Article 6(1)(a) of the GDPR) where registration is voluntary and the data subject requests it.
- Performance of a contract (Article 6(1)(b) of the GDPR), where registration is a prerequisite for the provision of the service.
- Scope of data processed: Name, email address, password (encrypted), date of registration, IP address.
5.2. Order processing
- Objective: Order processing, fulfilment of the contract, invoicing and delivery.
- Legal basis: Performance of a contract (Article 6(1)(b) of the GDPR).
- Scope of data processed: Name, delivery and billing address, contact details (telephone number, email), order details.
5.3. Invoicing
- Objective: Compliance with current accounting legislation (e.g. Act C of 2000).
- Legal basis: Compliance with a legal obligation (Article 6(1)(c) of the GDPR).
- Scope of data processed: Name/company name, address, tax registration number (in the case of a legal entity), and any other information required for invoicing.
5.4. Sending newsletters
- Objective: Marketing communications, information on new products and special offers.
- Legal basis: Consent (Article 6(1)(a) of the GDPR).
- Scope of data processed: Name, email address.
- Note: You can unsubscribe from the newsletter at any time by clicking on the link at the bottom of the newsletter or by contacting the Data Controller directly.
5.5. Use of cookies
- Objective: To ensure the website functions properly, to improve the user experience, to analyse visitor data, and for marketing purposes.
- Legal basis:
- Consent (Article 6(1)(a) of the GDPR) – for all cookies that are not essential to the functioning of the website.
- Legitimate interest or performance of a contract (Article 6(1)(f) or (b) of the GDPR) – in the case of technical cookies that are essential for the website to function.
- Further details: See the section entitled „Use of cookies” in this Notice (point 11).
Cloudflare Turnstile and Cloudflare cookies
To prevent unauthorised, automated use of our contact and other forms, and to filter out unsolicited messages and malicious bot traffic, our website uses the Cloudflare Turnstile uses the service.
During the operation of the service, certain technical data relating to visitors to the website may be transmitted to the Cloudflare, Inc. to them. The data transferred and processed may include, in particular:
- the user’s IP address,
- technical details of the browser and the device, such as User-Agent information,
- certain technical characteristics of the network connection,
- traffic and request data relating to the use of the website,
- as well as other technical information required for the detection of bot traffic.
The purpose of data processing is to determine whether the website and its forms are being used by a genuine user or an automated system, thereby ensuring the secure operation of the website and preventing misuse.
In the course of providing the service, Cloudflare collects the data necessary for its operation and security checks may use technical cookies and similar technologies. Depending on the Cloudflare configuration used, this could, for example, be the cf_clearance cookie, which may be used to store the result of a successfully completed security check. The purpose of these technologies is to maintain website security, detect automated and malicious traffic, and manage repeated security checks.
Further information on data processing carried out by Cloudflare Turnstile can be found in the following documents:
Cloudflare Privacy Policy:
https://www.cloudflare.com/privacypolicy/
Cloudflare Turnstile Privacy Notice:
https://www.cloudflare.com/turnstile-privacy-policy/
5.6. Data processing on social media platforms
- Objective: Keeping in touch, sharing information (Facebook, Instagram, etc.).
- Legal basis: Voluntary decision, consent (Article 6(1)(a) of the GDPR).
- Note: You should consult the relevant platform’s privacy policy to find out about its data processing practices.
6. Scope of data processed
6.1. Types of personal data
- Identification details: name, username, password (encrypted).
- Contact details: email address, telephone number, address.
- Technical specifications: IP address, browser type, cookies, time of login.
- Billing details: billing name, address, tax registration number (for companies).
6.2. Method and duration of data storage
- Stored electronically on secure servers, protected by passwords and other security measures.
- In paper form (if available) at the registered office or place of business, in a secure location.
- Retention period: until the statutory obligations have been fulfilled and the purpose of data processing has been achieved, or until consent is withdrawn. Thereafter, the data will be erased or anonymised.
7. The rights of data subjects
7.1. The right to information
The data subject is entitled to request information on the purposes for which their personal data is processed, the legal basis for such processing, the sources of the data, the duration of the processing, and who has access to it.
7.2. Right to rectification
If the data subject considers that their personal data being processed is inaccurate or incomplete, they may request that it be rectified or supplemented.
7.3. The right to erasure („the right to be forgotten”)
The data subject may request the erasure of their personal data if the data are no longer necessary for the purposes for which they were originally collected, or if the data subject withdraws their consent and there is no other legal basis for the processing.
7.4. Right to data portability
The data subject is entitled to receive the data they have provided in a widely used, machine-readable format, and may request that such data be transferred to another data controller.
7.5. The right to protest
- The data subject may object at any time to the processing of their personal data where the legal basis for the processing is the Data Controller’s legitimate interest.
- The data subject has the specific right to object to the processing of their personal data for the purposes of direct marketing.
8. Data security
8.1. Protection of electronic data
- A multi-level authorisation system.
- Regular backups.
- Virus protection and the use of firewalls.
8.2. Technical and organisational measures
- Use of a private office network and secure Wi-Fi.
- Storage of paper-based documents in a locked cupboard.
- Regular data protection training for employees and data processors.
9. Handling data protection incidents
9.1. Reporting incidents to the authorities (72-hour rule)
In the event of a data breach, the Data Controller shall notify the National Authority for Data Protection and Freedom of Information (NAIH) without undue delay and, where possible, within 72 hours at the latest, unless it is likely that there is no risk to the rights and freedoms of data subjects.
9.2. Informing data subjects in the event of a high risk
If the incident is likely to pose a high risk to the rights and freedoms of data subjects, the Data Controller shall inform the data subjects without delay, setting out the nature of the incident and the measures taken.
10. Data processors and third parties
10.1. Hosting provider
- Name:
- Registered office:
- Contact details:
- Data processing activities: operation of the web server, technical maintenance. It processes personal data solely in accordance with the Data Controller’s instructions.
The Data Controller always enters into a written contract with these partners (data processors) in accordance with the requirements of the GDPR. The contracts stipulate that the partners may process the data solely on the instructions of the Data Controller, for the specified purpose, and for the necessary period.
11. Use of cookies
11.1. The purpose and types of cookies
- Session cookies: these are essential for the website to function and are deleted when you close your browser.
- Functional cookies: they enhance the user’s convenience, for example by remembering login details or the selected language.
- Analytical cookies (e.g. Google Analytics): these are used for statistical purposes; they help us to understand user behaviour and improve the functioning of the website.
- Marketing cookies: they help to display relevant adverts and measure the effectiveness of those adverts.
11.2. Managing user settings
- Users can control how cookies are handled in their browser settings, allowing them to disable or delete them.
- If you change your cookie settings, some features of the website may not work properly.
- When you visit the website for the first time, you will be given the option to accept or reject non-essential (e.g. marketing) cookies via a pop-up window.
12. Data Protection Officer
12.1. Conditions and duties relating to appointment
Under Article 37 of the GDPR, the Data Controller is required to appoint a Data Protection Officer (DPO) if its core business is:
- involves data processing operations which, by their nature or scope, require regular and systematic monitoring, or
- are based largely on the handling of highly sensitive data.
The official’s duties include:
- ongoing monitoring of compliance with the GDPR,
- advice for the Data Controller and employees,
- maintaining contact with the supervisory authority (NAIH) and data subjects.
12.2. Legal status and contact details
The Data Protection Officer reports directly to senior management and may not be instructed in the performance of his or her duties.
- Name:
- Contact details:
Where the Data Controller is not required to appoint a DPO but nevertheless appoints an officer, it shall inform data subjects accordingly in this Notice.
13. Remedies available to data subjects
13.1. Lodging a complaint with the National Authority for Data Protection and Freedom of Information (NAIH)
If the data subject considers that the processing of their personal data infringes the applicable legislation, they may lodge a complaint with the National Authority for Data Protection and Freedom of Information:
- Title: 1055 Budapest, 9–11 Falk Miksa Street.
- Telephone: +36 (1) 391-1400
- Email: ugyfelszolgalat@naih.hu
13.2. The possibility of judicial redress
In the event of a breach of the data subject’s rights, they may bring a claim before a court. They may bring the claim – at their discretion – before the court with jurisdiction over their place of residence or place of stay.
14. The legislation forming the basis for data processing
14.1. GDPR (Regulation (EU) 2016/679)
Regulation (EU) 2016/679 of the European Parliament and of the Council, which aims to protect natural persons with regard to the processing of personal data and to ensure the free flow of such data within the EU.
14.2. Act CXII of 2011 on the right to informational self-determination
The Hungarian Data Protection Act, which sets out the fundamental principles and restrictions governing the processing of personal data in Hungary.
14.3. Other relevant Hungarian legislation
- Act C of 2000 on Accounting.
- Act V of 2013 on the Civil Code (Ptk.).
- Act XLVIII of 2008 on the fundamental conditions governing commercial advertising.
15. Final provisions
15.1. Scope of the privacy notice and options for amending it
- This Prospectus [dated] Effective from that date.
- The Data Controller is entitled to amend this Privacy Notice unilaterally, in particular to take account of changes in legislation, the introduction of new data processing activities, or the recommendations of the supervisory authority.
- Any amendments will be published on the website, and once they come into force, data subjects will be deemed to have accepted the new rules by continuing to use the services.
[Date]
[name]