Privacy Policy

GDPR Privacy Policy

Kertész Anett – Sole Proprietor

Effective from: 1 December 2022

1. Introduction

1.1. Purpose of the Privacy Notice

The purpose of this Privacy Notice (hereinafter referred to as the “Notice”) is to provide a transparent and detailed description of how personal data is processed in the course of the activities of Kertész Anett, sole proprietor (hereinafter referred to as the “Data Controller”), and to provide information on the rights of data subjects and how these rights may be exercised.

1.2. Compliance with Applicable Laws (GDPR, Act CXII of 2011)

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR): establishes uniform EU rules concerning the protection of personal data.

  • Act CXII of 2011 (Hungarian Data Protection Act): the principal Hungarian legislation governing informational self-determination and freedom of information.

This Notice aims to comply with the requirements set out in the above legislation.

2. Details of the Data Controller

2.1. Name and Contact Details of the Data Controller

  • Name: Kertész Anett

  • Sole proprietor registration number: 50603093

2.2. Availability of the Privacy Notice

This Notice is available electronically on www.adminangel.hu, and in printed form at the registered office upon request.

3. Definitions

3.1. Basic GDPR Definitions

  • Personal data: any information relating to an identified or identifiable natural person (“data subject”).

  • Data Controller: the natural or legal person which determines the purposes and means of the processing of personal data.

  • Data Processor: the natural or legal person which processes personal data on behalf of the Data Controller.

  • Consent: a freely given and explicit indication of the data subject’s wishes by which they signify their agreement to the processing of personal data relating to them.

  • Data subject: any identified or identifiable natural person to whom the personal data relates.

3.2. Definition of a Personal Data Breach

A personal data breach means any event resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to personal data that has been transmitted, stored or otherwise processed.

4. Principles of Data Processing

4.1. Legal Bases and Principles

  • Lawfulness, fairness and transparency: Data is processed only for specified and lawful purposes.

  • Purpose limitation: Data is processed only for predetermined purposes and to the extent necessary to achieve those purposes.

  • Data minimisation: We collect and process only the personal data that is essential for achieving the intended purpose.

  • Accuracy: We ensure that the personal data processed is accurate and, where necessary, kept up to date.

  • Storage limitation: Personal data is stored only for as long as necessary to fulfil the intended purpose.

  • Integrity and confidentiality: We apply appropriate technical and organisational measures to protect personal data.

4.2. Accuracy and Security of Data

  • Both the Data Controller and the data subject are responsible for regularly updating the data; the latter is required to notify the Data Controller if any changes occur to their personal data.

  • The Data Controller takes all reasonable measures to ensure that the recorded data is accurate and protects it against unauthorised access through appropriate security measures.

5. Purposes and Legal Bases of Data Processing

5.1. Registration on the Website

  • Purpose: Creating a user account and providing related services.

  • Legal basis:

    • Consent (Article 6(1)(a) GDPR) where registration is voluntary and requested by the data subject.

    • Performance of a contract (Article 6(1)(b) GDPR) where registration is a prerequisite for providing the service.

  • Categories of data processed: Name, email address, password (encrypted), registration date, IP address.

5.2. Processing Orders

  • Purpose: Processing orders, performing the contract, invoicing and delivery.

  • Legal basis: Performance of a contract (Article 6(1)(b) GDPR).

  • Categories of data processed: Name, delivery and billing address, contact details (telephone number, email address), order details.

5.3. Issuing Invoices

  • Purpose: Compliance with applicable accounting legislation (e.g. Act C of 2000).

  • Legal basis: Compliance with a legal obligation (Article 6(1)(c) GDPR).

  • Categories of data processed: Name/company name, address, tax number (in the case of legal entities), and other data necessary for invoicing.

5.4. Sending Newsletters

  • Purpose: Marketing communications and providing information about new products and promotions.

  • Legal basis: Consent (Article 6(1)(a) GDPR).

  • Categories of data processed: Name, email address.

  • Note: Users may unsubscribe from the newsletter at any time by clicking the unsubscribe link at the bottom of the newsletter or by contacting the Data Controller directly.

5.5. Use of Cookies

  • Purpose: Ensuring the proper functioning of the website, improving the user experience, analysing visitor statistics and marketing purposes.

  • Legal basis:

    • Consent (Article 6(1)(a) GDPR) for all cookies that are not essential for the operation of the website.

    • Legitimate interest or performance of a contract (Article 6(1)(f) or (b) GDPR) for technical cookies that are essential for the operation of the website.

  • Further information: See Section 11 of this Notice, “Use of Cookies”.

5.6. Data Processing on Social Media Platforms

  • Purpose: Communication and sharing information (Facebook, Instagram, etc.).

  • Legal basis: Voluntary decision and consent (Article 6(1)(a) GDPR).

  • Note: The data processing practices of social media platforms should be reviewed in the privacy notice of the relevant platform.

6. Categories of Data Processed

6.1. Types of Personal Data

  • Identification data: name, username, password (encrypted).

  • Contact details: email address, telephone number, address.

  • Technical data: IP address, browser type, cookies, login time.

  • Billing data: billing name, address, tax number (in the case of companies).

6.2. Method and Duration of Data Storage

  • In electronic form on secure servers, protected by passwords and other security measures.

  • In paper form (where applicable) at the registered office or business premises, in a secured location.

  • Retention period: Until the statutory obligations have been fulfilled and the purpose of the data processing has been achieved, or until consent is withdrawn. Thereafter, the data will be deleted or anonymised.

7. Rights of Data Subjects

7.1. Right to Information

The data subject has the right to request information about the purposes for which their personal data is processed, the legal basis for processing, the source of the data, the period of processing, and who may have access to the data.

7.2. Right to Rectification

If the data subject believes that their personal data is inaccurate or incomplete, they may request that it be corrected or supplemented.

7.3. Right to Erasure (“Right to be Forgotten”)

The data subject may request the deletion of their personal data where the data is no longer necessary for the original purpose for which it was collected, or where the data subject withdraws their consent and there is no other legal basis for processing the data.

7.4. Right to Data Portability

The data subject has the right to receive the data they have provided in a commonly used and machine-readable format and may request that such data be transmitted to another data controller.

7.5. Right to Object

  • The data subject may object at any time to the processing of their personal data where the legal basis for processing is the legitimate interest of the Data Controller.

  • The data subject has a specific right to object to the processing of their personal data for the purposes of direct marketing.

8. Data Security

8.1. Protection of Electronic Data

  • Multi-level access control system.

  • Regular backups.

  • Antivirus protection and firewall use.

8.2. Technical and Organisational Measures

  • Use of a secure office network and secure Wi-Fi.

  • Storage of paper documents in a locked cabinet.

  • Regular data protection training for employees and data processors.

9. Handling of Personal Data Breaches

9.1. Notification of a Breach to the Authorities (72-Hour Rule)

In the event of a personal data breach, the Data Controller shall notify the National Authority for Data Protection and Freedom of Information (NAIH) without undue delay and, where feasible, no later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of the data subjects.

9.2. Notification of Data Subjects in the Event of a High Risk

Where the personal data breach is likely to result in a high risk to the rights and freedoms of the data subjects, the Data Controller shall inform the data subjects without undue delay, describing the nature of the breach and the measures taken.

10. Data Processors and Third Parties

10.1. Hosting Provider

  • Name: Websupport Magyarország Kft.

  • Registered office: 1132 Budapest, Victor Hugo utca 18–22.

  • Contact: +36 1 700 2323; info@mhosting.hu

  • Data processing activities: Operation of the web server and technical maintenance. Personal data is processed only in accordance with the instructions of the Data Controller.

10.2. Accountant and Other Partners

The Data Controller may engage an accountant, courier service, marketing agency and other partners in connection with the processing of personal data.

The Data Controller always enters into a written agreement with these partners (data processors) in accordance with the requirements of the GDPR. The agreements specify that the partners may process data only in accordance with the instructions of the Data Controller, for the specified purpose and for the necessary period.

11. Use of Cookies

11.1. Purpose and Types of Cookies

  • Session cookies: Essential for the operation of the website and deleted when the browser is closed.

  • Functional cookies: Improve user convenience, for example by remembering login details or the selected language.

  • Analytics cookies (e.g. Google Analytics): Used for statistical purposes, helping to understand user behaviour and improve the operation of the website.

  • Marketing cookies: Support the display of relevant advertisements and the measurement of advertising effectiveness.

11.2. Management of User Preferences

  • Users can manage cookies through their browser settings, including disabling or deleting them.

  • When cookie settings are changed, some website functions may not operate properly.

  • During the first visit to the website, users have the option to accept or reject non-essential cookies (e.g. marketing cookies) through a pop-up window.

12. Data Protection Officer

12.1. Conditions for Appointment and Duties

Pursuant to Article 37 of the GDPR, the Data Controller is required to appoint a Data Protection Officer (DPO) where its core activities:

  • involve processing operations which, by their nature, scope and/or purposes, require regular and systematic monitoring of data subjects, or

  • consist of processing on a large scale of special categories of personal data.

The duties of the Data Protection Officer include:

  • continuously monitoring compliance with the GDPR,

  • providing advice to the Data Controller and employees,

  • liaising with the supervisory authority (NAIH) and data subjects.

12.2. Status and Contact Details

The Data Protection Officer reports directly to senior management and shall not receive instructions regarding the exercise of their tasks.

If the Data Controller is not required to appoint a DPO but nevertheless appoints one, the data subjects shall be appropriately informed thereof in this Notice.

13. Legal Remedies Available to Data Subjects

13.1. Lodging a Complaint with the National Authority for Data Protection and Freedom of Information (NAIH)

If the data subject believes that the processing of their personal data violates applicable legislation, they may lodge a complaint with the National Authority for Data Protection and Freedom of Information:

13.2. Judicial Remedies

In the event of an infringement of their rights, the data subject may bring proceedings before a court. At the data subject’s choice, the proceedings may also be initiated before the court having jurisdiction over their place of residence or habitual residence.

14. Legislation Governing Data Processing

14.1. GDPR (Regulation (EU) 2016/679)

Regulation (EU) 2016/679 of the European Parliament and of the Council, the purpose of which is to protect natural persons with regard to the processing of personal data and to ensure the free movement of such data within the European Union.

14.2. Act CXII of 2011 on Informational Self-Determination and Freedom of Information

The Hungarian data protection law governing the fundamental principles and limitations applicable to the processing of personal data in Hungary.

14.3. Other Relevant Hungarian Legislation

  • Act C of [2000] on Accounting.

  • Act V of [2013] on the Civil Code (Ptk.).

  • Act XLVIII of [2008] on the Basic Conditions and Certain Limitations of Economic Advertising Activities.

15. Final Provisions

15.1. Effective Date and Amendments to the Privacy Notice

  • This Notice has been effective since 1 December 2022.

  • The Data Controller is entitled to amend this Notice unilaterally, in particular in response to changes in legislation, the introduction of new data processing activities, or recommendations issued by the supervisory authority.

  • Amendments will be published on the website, and following their effective date, data subjects shall be deemed to have accepted the new provisions through their continued use of the services.

Executed in Gyömrő, 1 December 2022

Kertész Anett

as sole proprietor