Privacy Policy
1. General principles
- We collect and process personal data only in accordance with applicable legislation.
- We disclose personal data to third parties only with consent.
- Under no circumstances do we sell the personal data we process to third parties.
- We store data as securely as possible.
- We send newsletters only to those who have given their prior and explicit consent.
- Data subjects may request access to, rectification or deletion of the data stored about them at any time.
2. Details and contact information of our company (Data Controller, Service Provider)
Name of the Data Controller: Kocsányos Tölgy Kft.
Contact details of the Data Controller: 2016 Leányfalu, Farkas utca 3.
Phone: +36303107774
E-mail: info@nemcsakbutor.hu
Web: https://www.nemcsakbutor.hu
Tax number: 10667420-2-13
The Service Provider reserves the right to amend this Privacy Notice and will duly inform data subjects of any such changes. Information concerning data processing is published on the LINK MEGY IDE website.
3. Definitions under the GDPR (Regulation)
3.1. Data Subject/User:any identified or identifiable natural person who can be identified, directly or indirectly, on the basis of personal data;
3.2. Personal data: any information relating to the data subject, in particular the name of the data subject, an identification mark, and one or more pieces of information characteristic of the data subject’s physical, physiological, mental, economic, cultural or social identity, as well as any conclusion that can be drawn from such information concerning the data subject;
3.3. Consent: a freely given and specific indication of the data subject’s wishes, based on appropriate information, by which the data subject gives their unambiguous consent to the processing of personal data relating to them, either in full or for specific processing operations;
3.4.Data Controller:the natural or legal person, or organisation without legal personality, who or which, alone or jointly with others, determines the purposes of the processing of data, makes and implements decisions concerning data processing (including the means used), or has them carried out by a Data Processor;
3.5. Data processing: any operation or set of operations performed on data, irrespective of the procedure used, including in particular the collection, recording, organisation, storage, alteration, use, retrieval, transmission, disclosure, alignment or combination, blocking, erasure and destruction of data, as well as preventing further use of the data, making photographs, audio or video recordings, and recording physical characteristics suitable for identifying a person (e.g. fingerprints or palm prints, DNA samples, iris images);
3.6.Data transfer: making data available to a specific third party;
3.7. Disclosure: making data available to anyone;
3.8. Data erasure:rendering data unrecognisable in such a way that it can no longer be restored;
3.9.Data processing: performing technical tasks related to data processing operations, irrespective of the method, means or location used to perform the operations, provided that the technical task is performed on the data;
3.10. Data Processor: the natural or legal person, or organisation without legal personality, who or which processes data on the basis of a contract, including a contract concluded pursuant to a legal provision;
3.11. Personal data breach: unlawful processing or handling of personal data, including in particular unauthorised access, alteration, transfer, disclosure, erasure or destruction, as well as accidental destruction or damage.
4. Scope of processed data, purpose and duration of processing, and data processors
| Type of data processed | Purpose of data processing | Duration of data processing | Legal basis for data processing | Data processor of the respective personal data |
| Username | Identification, registration. | Until consent is withdrawn | Consent of the data subject. | |
| Password | Secure login to the user account. | Until consent is withdrawn | Consent of the data subject. | |
| Name | Contact and coordination of any questions that may arise. | Until consent is withdrawn | Consent of the data subject. | |
| E-mail address | Contact and coordination of any questions that may arise. | Until consent is withdrawn | Consent of the data subject. | |
| Phone number | Contact and coordination of any questions that may arise. | Until consent is withdrawn | Consent of the data subject. | |
| Billing name and address | Issuing a proper invoice, concluding and subsequently performing the contract. | We process the data for 5 years in accordance with the civil law limitation period. | The issuance of an invoice is mandatory pursuant to Section 159(1) of Act CXXVII of 2007 on Value Added Tax and under Section 169(2) of Act C of 2000 on Accounting. | |
| Shipping name and address | Enabling home delivery. | Until delivery of the ordered goods. | Performance of the contract. [Processing pursuant to Article 6(1)(b) of the Regulation] | |
| Date and time of purchase/registration | Proof of consent. | Until the limitation period following termination of the data processing expires | This obligation is prescribed by Article 7(1) of the Regulation. [Processing pursuant to Article 6(1)(c) of the Regulation] | |
| IP address at the time of purchase/registration | Proof of consent. | Until the limitation period following termination of the data processing expires | This obligation is prescribed by Article 7(1) of the Regulation. [Processing pursuant to Article 6(1)(c) of the Regulation] |
Scope of data subjects: All data subjects registered on or purchasing from the webshop website.
We share personal data only with the third party indicated in the “Data processor of the respective personal data” column, for the purpose of fulfilling the obligations set out in the contract.
Details and tasks of the Data Processors used during data processing
Hosting provider
Name: InfoNetfort Kft.
Address: 7900 Szigetvár, Szent István ltp 17. IV/25.
Phone: +36-30/530-2953
E-mail: kapcsolat@netfort.hu
Web: www.netfort.hu
Tax number: 26648082-2-02
Company registration number: 02 09 084205
Accounting services
Courier service
Direct marketing, newsletter
Name:
Address:
4.1 Contact form:
| Type of data processed | Purpose of data processing | Duration of data processing | Legal basis for data processing |
| Name | Contacting us | For 90 days after the data subject’s last contact | Consent of the data subject during contact |
| Email address | Contacting us | For 90 days after the data subject’s last contact | Consent of the data subject during contact |
| Phone number | Contacting us | For 90 days after the data subject’s last contact | Consent of the data subject during contact |
| Other personal data provided by the data subject during contact | For 90 days after the data subject’s last contact | Consent of the data subject during contact |
Scope of data subjects: Persons who contact us by phone, e-mail or through the contact form.
We do not share personal data with third parties.
5. Newsletter and direct marketing activities
We send newsletters only to Users who have given their prior and explicit consent. Consent is given using the “Newsletter subscription” form.
| Type of data processed | Purpose of data processing | Duration of data processing | Legal basis for data processing |
| Name | Sending newsletters | Until withdrawal (unsubscribe). | Consent of the data subject |
| E-mail address | Sending newsletters | Until withdrawal (unsubscribe). | Consent of the data subject |
| Date of consent and the data subject’s IP address. | Verifiability of consent | Until withdrawal (unsubscribe). | This obligation is prescribed by Article 7(1) of the Regulation. |
Scope of data subjects: All persons subscribed to the newsletter.
Operator of the newsletter sending system and Data Processor of the data:
Name:
Address:
5.1 Procedure for withdrawing consent (unsubscribe)
The data subject may unsubscribe from the newsletter at any time and free of charge. Unsubscription can be completed using the link provided in the newsletters or by sending an e-mail to EMAIL CÍM JÖN IDE.
6. Use of cookies
6.1 What is a cookie?
The Data Controller uses so-called cookies when the website is visited. A cookie is a package of information consisting of letters and numbers that our website sends to the data subject’s browser in order to save certain settings, make our website easier to use and help us collect some relevant statistical information about our visitors. Cookies do not contain personal information and are not suitable for identifying individual users. Cookies often contain a unique identifier – a secret, randomly generated sequence of numbers – which is stored on the data subject’s device.
Some cookies expire when the website is closed, while others are stored on your computer for a longer period of time.
6.2. Legal background and legal basis for the use of cookies
Typical cookies used by online stores include “password-protected session cookies”, “shopping cart cookies” and “security cookies”, the use of which does not require prior consent from data subjects.
Nature of the processing and scope of processed data: Unique identification number, dates and times
Scope of data subjects: All persons visiting the website.
Purpose of data processing: Identification of users and tracking of visitors.
Legal basis for data processing: the data subject’s consent in accordance with Section 5(1)(a) of the Infotv.
6.3 Duration of data processing and deadline for deletion of data: the website uses the following cookies:
- Security cookies: __cfduid, _biz_flagsA, _biz_nA3, _biz_pendingA, _biz_sid, _biz_uid
- Google Analytics cookies: _ga, _gid
- Cookies necessary for proper use of the website:
Possible Data Controllers authorised to access the data: The Data Controller does not process personal data through the use of cookies.
Information about the rights of data subjects concerning data processing: Data subjects can delete cookies in the Tools/Settings menu of their browsers, generally under the Privacy settings.
If a data subject does not accept the use of cookies, certain functions will not be available to them. More information about deleting cookies can be found at the following links:
• Internet Explorer: http://windows.microsoft.com/en-us/internet-explorer/delete-managecookies#ie=ie-11
• Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-yourcomputer
• Chrome: https://support.google.com/chrome/answer/95647?hl=en
• Safari: https://support.apple.com/kb/ph21411?locale=en_US
7. Google Analytics
7.1. This website uses Google Analytics, a web analytics service provided by Google Inc. (\"Google\"). Google Analytics uses so-called \"cookies\", text files that are stored on your computer and help analyse how the website visited by the User is used.
7.2. Information generated by cookies relating to the website used by the User is generally transferred to and stored on one of Google’s servers in the USA. When IP anonymisation is activated on the website, Google shortens the User’s IP address beforehand within the member states of the European Union or in other states party to the Agreement on the European Economic Area.
7.3. The full IP address is transferred to and shortened on Google’s server in the USA only in exceptional cases. On behalf of the operator of this website, Google will use this information to evaluate how the User used the website, to prepare reports for the website operator relating to website activity, and to provide further services related to website and internet use.
7.4. Within Google Analytics, the IP address transmitted by the User’s browser is not combined with other data held by Google. The User can prevent cookies from being stored by configuring their browser accordingly; however, please note that in this case not all functions of this website may be fully available. The User may also prevent Google from collecting and processing data related to their use of the website through cookies (including the IP address) by downloading and installing the browser plugin available at the following link. https://tools.google.com/dlpage/gaoptout?hl=hu
8. Google AdWords conversion tracking and remarketing
8.1. The Data Controller uses the online advertising programme called \"Google AdWords\" and also uses Google’s conversion tracking service within it. Google conversion tracking is an analytics service provided by Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; \"Google\").
8.2. When a User reaches a website through a Google advertisement, a cookie required for conversion tracking is placed on their computer. These cookies have a limited validity period and do not contain any personal data, so the User cannot be identified through them.
8.3. When the User browses certain pages of the website while the cookie has not yet expired, both Google and the Data Controller can see that the User clicked on the advertisement.
8.4. Each Google AdWords customer receives a different cookie, so they cannot be tracked through the websites of AdWords customers.
8.5. The information obtained through conversion tracking cookies is used to create conversion statistics for customers who use AdWords conversion tracking. This allows customers to see the number of users who clicked on their advertisement and were directed to a page containing a conversion tracking tag. However, they do not receive information that could be used to identify any individual user.
8.6. If you do not wish to participate in conversion tracking, you can opt out by disabling the installation of cookies in your browser. The data subject will then not be included in conversion tracking statistics.
8.7. Further information and Google’s privacy policy are available at: www.google.de/policies/privacy/
8.8. Google AdWords Remarketing
8.9. Data processing as part of remarketing is carried out using cookies.
Processed data
Data processed by the cookies specified in the cookie notice.
Duration of data processing
The data storage period of the respective cookie; further information is available here:
Google general cookie information: https://www.google.com/policies/technologies/types/
Google Analytics information:
https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage?hl=hu
Legal basis for data processing
The data subject’s voluntary consent, given to the Service Provider through the data subject’s use of the website.
9. Rights of data subjects
9.1 Right to information
At the request of the data subject, the Service Provider, as Data Controller, shall provide information about the data it processes, as well as data processed by a processor appointed by it, their source, the purpose, legal basis and duration of processing, the name and address of the Data Processor and its activities related to data processing, the circumstances and effects of any personal data breach and the measures taken to prevent or remedy it, and, in the case of data transfer, its legal basis and recipient. The Data Controller shall provide the information in writing, in an understandable form, as soon as possible after the request is submitted and within no more than 30 days. This information is provided free of charge if the person requesting it has not submitted a request for information concerning the same category of data to the Data Controller during the current year. In other cases, the Service Provider may charge a fee.
9.2 Right to rectification
The Service Provider shall rectify personal data if it is inaccurate and the correct personal data is available to it.
9.3 Right to blocking
The Service Provider shall block personal data if the data subject requests this, or if, based on the information available to it, it can be assumed that deletion would harm the legitimate interests of the data subject. Blocked personal data may only be processed for as long as the purpose of processing that prevented the deletion of the personal data exists. The Service Provider shall mark the personal data it processes if the data subject disputes its correctness or accuracy, but the incorrectness or inaccuracy of the disputed personal data cannot be clearly established.
9.4 Right to erasure
The Service Provider shall erase personal data if its processing is unlawful, if the data subject requests it, if the processed data is incomplete or incorrect and this cannot be lawfully remedied, provided that erasure is not excluded by law, the purpose of processing has ceased, the statutory retention period has expired, or the court or the National Authority for Data Protection and Freedom of Information has ordered it.
9.5 Procedural rules
The Data Controller has 30 days to erase, block or rectify personal data. If the Data Controller does not fulfil the data subject’s request for rectification, blocking or erasure, it shall communicate the reasons for the refusal in writing or electronically, with the data subject’s consent, within 30 days. The Service Provider shall notify the data subject, as well as all persons to whom the data was previously transferred for processing purposes, of the rectification, blocking, marking and erasure. Notification may be omitted if, in view of the purpose of processing, this does not prejudice the legitimate interests of the data subject.
9.6 Right to object
The data subject may object to the processing of their personal data if
a] the processing or transfer of personal data is necessary solely for compliance with a legal obligation applicable to the Data Controller or for the enforcement of the legitimate interest of the Data Controller, the recipient of the data or a third party, unless the processing has been ordered by law;
b] in other cases specified by law.
The Service Provider shall examine the objection as soon as possible, but no later than 15 days after the request is submitted, decide whether it is justified, and inform the applicant of its decision in writing. If the Data Controller determines that the data subject’s objection is justified, it shall cease the processing, including any further collection and transfer of data, block the data, and notify all persons to whom the personal data concerned by the objection had previously been transferred, who are required to take measures to ensure the exercise of the right to object.
If the data subject disagrees with the decision made by the Data Controller, they may bring the matter before a court within 30 days of the decision being communicated.
The Service Provider may not erase the data subject’s data if the processing has been ordered by law. However, the data may not be transferred to the recipient if the Data Controller has agreed with the objection or if a court has established that the objection was justified.
9.7 Right to data portability
Where processing is carried out by automated means, or where the processing is based on the data subject’s
voluntary consent, the data subject has the right to request that the Data Controller provide the data subject
with the data they have provided to the Data Controller in XML, JSON or CSV
format. Where technically feasible, the data subject may also request that
the Data Controller transfer the data in this format to another Data Controller.
9.8 Compensation and damages for non-material harm
The Service Provider shall compensate any damage caused to another person by the unlawful processing of the data subject’s data or by a breach of data security requirements. In the event of an infringement of the data subject’s personal rights, the data subject may claim damages for non-material harm under Section 2:52 of the Civil Code (Ptk.). The Data Controller is also liable to the data subject for damage caused by the Data Processor. The Data Controller is exempt from liability if the damage was caused by an unavoidable cause outside the scope of data processing.
The Data Controller shall not compensate the damage, and damages for non-material harm may not be claimed, to the extent that the damage or infringement of personal rights resulted from the intentional or grossly negligent conduct of the data subject.
9.9 Right to seek judicial remedy
In the event of a violation of their rights, the data subject may bring proceedings against the Data Controller before a court. The court shall deal with the matter as a matter of priority.
9.10 Complaints
Complaints may be submitted to the National Authority for Data Protection and Freedom of Information:
Name: National Authority for Data Protection and Freedom of Information
Registered office: 1125 Budapest, Szilágyi Erzsébet fasor 22/C.
Postal address: 1530 Budapest, P.O. Box 5.
Phone: +361/391-1400
Fax: +361/391-1410
E-mail: ugyfelszolgalat@naih.hu
Website: http://www.naih.hu
10. Data security
The Service Provider designs and carries out data processing operations in such a way as to ensure the protection of the privacy of data subjects.
The Service Provider, and the Data Processor within its scope of activities, shall ensure the security of the data, take the technical and organisational measures, and establish the procedures necessary to enforce the Info Act and other data and confidentiality protection rules.
The Service Provider protects the data through appropriate measures, in particular against unauthorised access, alteration, transfer, disclosure, erasure or destruction, accidental destruction or damage, and becoming inaccessible as a result of changes in the technology used.
During data processing, the Service Provider maintains:
• confidentiality: it protects the information so that only authorised persons can access it
• integrity: it protects the accuracy and completeness of the information and the processing method
• availability: it ensures that when an authorised user needs the information, they can actually access the requested information and the related resources are available.
The IT systems and networks of the Service Provider and its partners involved in data processing
are protected against computer-assisted fraud, espionage, sabotage, vandalism, fire and flood,
as well as computer viruses, computer intrusions and attacks leading to denial of service.
The operator ensures security through server-level and application-level protection procedures
and measures.
11. Applicable legislation used for this Privacy Notice
• Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Infotv.)
• Act V of 2013 on the Civil Code (Ptk.)
• Act CLV of 1997 on Consumer Protection (Fgytv.)
• Act XIX of 1998 on Criminal Procedure (Be.)
• Act CVIII of 2001 on Certain Issues Relating to Electronic Commerce Services and Information Society Services (Eker. tv.)
• Act C of 2003 on Electronic Communications (Eht.)
• Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Economic Advertising Activities (Grt.)
• Recommendation of the National Authority for Data Protection and Freedom of Information on the data protection requirements of prior information
• GDPR, Regulation (EU) 2016/679 of the European Parliament and of the Council on the processing and protection of personal data of natural persons and on the free movement of such data
[DATE]