Privacy Policy

www.dev.szalvetatervezes.hu

The Data Controller (Service Provider)

Service Provider Name: Flóra Higiénia Trading and Service Limited Liability Company 

Headquarters: 13 Fatelep Street, 2890 Tata.

Location: 2890 Tata, 13 Fatelep Street.

Mailing Address: 13 Fatelep Street, Tata 2890

Court of Registration: Tatabánya Commercial Court

Company Registration Number: 11-09-011372

Tax ID Number: 13661368-2-11

Email address: info@dev.szalvetatervezes.hu

Honlap:      www.dev.szalvetatervezes.hu

Phone number: 06-34/383-904

Name of web hosting provider: Tárhely.eu Szolgáltató Kft.

Hosting provider's address: 1097 Budapest, Könyves Kálmán Boulevard 12–14.

1. Principles of Data Processing; Data Security

1.1. The Service Provider, as the Data Controller (hereinafter: Data Controller) undertakes to process personal data obtained in the course of its activities in accordance with applicable legal provisions—as set forth in the privacy notice.

The data controller processes personal data solely for a specific purpose, for the purpose of exercising rights and fulfilling obligations.

The processing and collection of data—at every stage of data processing—comply with the requirements of fairness and lawfulness.

The data controller processes only personal data that is essential to achieving the purpose of the data processing and is suitable for achieving that purpose. The data controller processes personal data only to the extent and for the duration necessary to achieve that purpose.

The Data Controller shall ensure, at every stage of data processing, that the data subject may at any time learn which types of data the Data Controller processes and for what purposes, and may at any time prohibit such data processing—with the exception of mandatory data processing.

The purpose of data processing and the scope of the data processed are set forth in Section 2 of this Privacy Notice.

This Privacy Notice complies with and is consistent with the following laws:

· Act CVIII of on Certain Issues Concerning Electronic Commerce Services and Information Society Services

· Act CXII of on the Right to Informational Self-Determination and Freedom of Information

1.2. The Data Controller plans and carries out data processing operations in a manner that ensures the protection of the data subjects’ privacy.

The data controller ensures the security of the data, takes the necessary technical and organizational measures, and establishes the procedural rules required to enforce Act CXII of 2011, as well as other data protection and confidentiality regulations.

The data controller takes appropriate measures to protect the data against unauthorized access, alteration, disclosure, or deletion or destruction, as well as against accidental destruction, damage, and inaccessibility resulting from changes in the technology used.

2. Legal basis for data processing; purpose; data processed

2.1. Personal data may be processed if the data subject consents to such processing, or if it is required by law or—pursuant to authorization granted by law and within the scope specified therein—by a local government ordinance for purposes in the public interest.

2.2. The consent or subsequent approval of a minor’s legal representative is not required for the validity of a legal declaration containing the consent of the minor who has reached the age of 16.

2.3. A www.dev.szalvetatervezes.hu In the case of registration on the website and the sending of the newsletter, data processing is based on the data subject’s voluntary declaration of consent, provided that the data subject has been adequately informed. The data subject’s consent is required for registration and—if the data subject provides separate consent—for sending the newsletter.

The Data Subject must provide his or her consent to the Data Controller prior to registration by clicking the “X” in the small box that appears next to the Privacy Notice during the registration process. Before giving consent, the Data Subject may read and familiarize themselves in detail with the contents of this Privacy Notice. By giving the above consent, the Data Subject accepts the contents of the Privacy Notice.

This Privacy Notice is the www.dev.szalvetatervezes.hu It is always available in the website's footer.

If the User wishes to receive a newsletter, he or she may give consent during the registration process/or afterward by clicking the “X” in the small box next to “Subscribe to Newsletter.”

2.4. The data controller processes the following data:

For registration: the data subject’s name (last name, first name); email address; county and city; confirmation that the data subject is at least 16 years of age.

When sending a newsletter: the data subject's name (last name, first name); email address; county and city

2.5. Purposes of Data Processing: The www.dev.szalvetatervezes.hu Registration on the website (primary purpose) and sending newsletters (secondary purpose)

Legal basis for data processing: the data subject’s voluntary consent

Duration of data processing:

In the case of registration: Until the user account is deleted—at the user’s request—

If a newsletter is sent: until the date on which you unsubscribe from the newsletter

2.6. Persons Authorized to Control and Process Data: The service provider’s current managing director and employees. Only the current managing director and employees have access to the processed data.

2.7. The Data Controller shall not disclose any data related to the use of the service to any third party. The Data Controller shall not transfer the processed data to any data controller or data processor located in a third country.

2.8. The Data Controller reserves the right—and is also obligated—to unilaterally amend this Privacy Notice to ensure that it always complies with the requirements of applicable law.

3. Your Rights as a Data Subject

3.1. The data subject may request information from the data controller regarding the processing of his or her personal data. Upon the data subject’s request, the Data Controller shall provide information regarding the data it controls or processes, the purpose of the data processing, its legal basis, its duration, and the name, address, and activities of the data processor related to the data processing.

Upon receiving a written request from the data subject, the data controller shall provide the requested information as soon as possible after the request is submitted, but no later than 25 days thereafter.

3.2. The data subject may request that the data controller correct his or her personal data.

If the personal data is inaccurate and the Data Controller has access to accurate personal data, the Data Controller shall correct the personal data.

3.3. The data subject may request that the data controller delete or block his or her personal data.

Personal data must be deleted,

· if its processing is unlawful;

· the data subject requests it;

· incomplete or incorrect

· the purpose of the data processing has ceased to exist, or the retention period for the data has expired;

· it was ordered by a court or the Authority.

The data controller may refuse a data subject’s request to delete their data only in cases where data processing is mandatory (e.g., the obligation to retain invoices under the Accounting Act).

Instead of erasure, the data controller shall block the personal data if the data subject so requests, or if, based on the information available to the data controller, it can be presumed that erasure would harm the data subject’s legitimate interests. Personal data blocked in this manner may be processed only for as long as the purpose of data processing that precluded the erasure of the personal data remains valid. If the data controller does not comply with the data subject’s request for rectification, blocking, or erasure, the data controller shall, within 25 days of receiving the request, provide the factual and legal grounds for rejecting the request for rectification, blocking, or erasure, either in writing or electronically with the data subject’s consent. In the event of a refusal to comply with a request for rectification, erasure, or blocking, the data controller shall inform the data subject of the possibility of seeking judicial remedy and of appealing to the Authority.

4. Enforcement of rights through the courts; compensation for damages; compensation for pain and suffering

4.1. If the data subject’s rights are violated, he or she may bring a lawsuit against the Data Controller.

If the Data Controller causes harm to another person through the unlawful processing of the data subject’s data or by violating data security requirements, the Data Controller is obligated to compensate for such harm.

If the Data Controller violates the data subject’s right to privacy by unlawfully processing the data subject’s data or by breaching data security requirements, the data subject may claim compensation for damages from the Data Controller.

4.2. Anyone may file a complaint with the National Authority for Data Protection and Freedom of Information (NAIH) to initiate an investigation on the grounds that a violation of rights has occurred or is imminently likely to occur in connection with the processing of personal data.

NAIH Contact Information:

Mailing address: 1530 Budapest, P.O. Box 5.

Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c

Phone: +36 (1) 391-1400

Fax: +36 (1) 391-1410

E-mail: ugyfelszolgalat@naih.hu

URL: http://naih.hu

5.1. Terms Used in This Privacy Notice

Data subject: any natural person who is identified or can be identified—directly or indirectly—based on specific personal data

personal data: data that can be linked to the data subject—in particular, the data subject’s name, identification number, and one or more factors specific to the data subject’s physical, physiological, mental, economic, cultural, or social identity—as well as any conclusions regarding the data subject that can be drawn from such data;

Consent: a voluntary and explicit expression of the data subject’s will, based on adequate information, by which the data subject gives unambiguous consent to the processing of personal data concerning him or her—whether in its entirety or with respect to specific operations

objection: a statement by the data subject in which they object to the processing of their personal data and request that the processing be discontinued or that the processed data be erased

Data Controller: a natural or legal person, or an organization without legal personality, who or which, alone or jointly with others, determines the purposes of data processing, makes and implements decisions regarding data processing (including the means used), or has such decisions implemented by a data processor

data processing: any operation or set of operations performed on data, regardless of the procedure used, including, in particular, the collection, recording, organizing, storing, modifying, using, retrieving, transmitting, disclosing, aligning or combining, blocking, erasing, and destroying data, as well as preventing the further use of data, taking photographs, audio, or video recordings, as well as recording physical characteristics suitable for identifying a person (e.g., fingerprints or palm prints, DNA samples, iris scans);

data transfer: making data available to a specific third party;

data erasure: rendering data unrecognizable in such a way that it can no longer be recovered;

data blocking: marking data with an identifier for the purpose of permanently or temporarily restricting its further processing;

Data destruction: the complete physical destruction of the data storage medium containing the data

data processing: the performance of technical tasks related to data processing operations, regardless of the method or means used to carry out the operations or the location where they are performed, provided that the technical task is performed on the data

data processor: a natural or legal person, or an organization without legal personality, that processes data on the basis of a contract—including a contract entered into pursuant to a provision of law

data set: the totality of data managed within a single database

third party: a natural person, legal entity, or unincorporated organization that is not the data subject, the data controller, or the data processor.

EEA State: a Member State of the European Union and any other state that is a party to the Agreement on the European Economic Area, as well as any state whose nationals, pursuant to an international treaty concluded between the European Union and its Member States, as well as a state that is not a party to the Agreement on the European Economic Area, but whose citizens, pursuant to an international treaty concluded between the European Union and its member states and a state not party to the Agreement on the European Economic Area, enjoy the same legal status as citizens of a state party to the Agreement on the European Economic Area

third country: any state that is not an EEA state.

If you have any questions regarding our company’s data processing, please contact us. Our contact information is as follows:

Company Name: Flóra Hygiene Trading and Services Limited Liability Company

Headquarters: 13 Fatelep Street, 2890 Tata.

Location: 2890 Tata, 13 Fatelep Street.

Phone number: 06-34/383-904

Email address:  info@dev.szalvetatervezes.hu

Gábor Ferencz

Managing Director

Change cookie consent settings: Hozzájárulás visszavonása