Privacy Policy
In effect from: 20 July 2026How Pearly Quality collects, uses and protects personal data, and the rights you have under the GDPR.
This Privacy Policy (hereinafter: “Privacy Policy”) applies to the website operated by Imola Mészár, a sole trader (registered office: 2030 Érd, Szarkaláb utca 10; tax number: 59340580-1-33; EU VAT number: HU59340580; registration number: 57362151), hereinafter referred to as the “Data Controller”), and describes the characteristics of data processing carried out in connection with its services, in particular the collection, storage and use of data.
This Privacy Policy shall take effect on 20th July, 2026. The Data Controller shall make the current version of the Privacy Policy available on its Website and at its registered office.
This Privacy Policy has been drawn up in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: ‘GDPR’), considering the provisions of Hungarian Act CXII of 2011 on the Right to Informational Self-Determination and on Freedom of Information (hereinafter: ‘Info Act’). Its terminology corresponds to the definitions set out in Article 4 of the GDPR and, in certain respects, is supplemented by the interpretative provisions of Section 3 of the Info Act and the definitions contained in the Data Controller’s General Terms and Conditions. The Data Controller’s General Terms and Conditions are available at all times on the Data Controller’s website.
In matters not specified in this Privacy Policy, the GDPR shall apply; where permitted by the GDPR, the provisions of the Information Act shall apply on a supplementary basis.
The Data Controller is entitled to prepare an extract from the contents of this Privacy Policy in connection with specific data processing activities; furthermore, it may ensure that data subjects, in connection with the prior information provided regarding the processing of personal data, declare by signing this document that they have read and understood the contents of the extract. The Data Controller reserves the right to amend this Privacy Policy. Where an amendment affects the use of the personal data provided by the data subject, the Data Controller shall inform the data subject of the changes in an appropriate manner, for example by means of an information letter sent by email. Where the details of data processing also change as a result of an amendment to this Privacy Policy, the Data Controller shall specifically request the data subject’s consent.
Please read the information below carefully and only use the services available on the Website if you agree with the terms set out below.
Principles
In providing its services, the Data Controller pays particular attention to the protection of personal data, compliance with mandatory legal provisions, and the secure and fair processing of data. In accordance with Section 2 of this Privacy Policy, the Data Controller treats the personal data provided to it as confidential; in its procedures, it observes the principles of lawfulness, fairness and transparency under the GDPR; it processes personal data in a manner that is purpose-limited, whilst also bearing in mind the principle of data minimisation; it complies with the principle of limited storage; it protects the confidentiality and integrity of personal data; and it also takes into account the principle of accuracy under the GDPR.
Methods and security of data processing
The Data Controller ensures the security of the data and takes the technical and organisational measures and establishes the procedural rules necessary to enforce the data protection and confidentiality rules laid down in the GDPR, the Information Act and other legislation. The Data Controller protects personal data against unauthorised access; alteration; disclosure; or accidental erasure, destruction; damage; and inaccessibility resulting from changes in the technology used.
The Data Controller places particular emphasis on the protection of data files processed electronically in various registers to ensure that the data stored in these registers – unless permitted by law – cannot be directly linked to or attributed to the data subject.
Data processing in connection with the Data Controller’s Service and Website
Contact
The Data Controller provides visitors to the Website with the opportunity to contact the Data Controller via one of its contact details.
- Purpose of data processing
- To answer enquiries and, in connection with this, to establish and maintain contact.
- Scope of data processed
- The data subject’s name, email address and the content of the communication.
- Scope of data subjects
- Persons who contact the Data Controller.
- Legal basis for data processing
- Consent of the data subject pursuant to Article 6(1)(a) of the GDPR.
- Data retention period
- Until the enquiry has been successfully resolved or the purpose has been fulfilled, but no later than the time of erasure at the data subject’s request.
- Method of data processing
- Electronically.
- Source of data
- Data collected from the data subject.
- Possible consequences of failure to provide data
- If the data subject does not provide the data to the Data Controller, they will not be able to contact the Data Controller.
- Automated decision-making and profiling
- The Data Controller does not use automated decision-making and does not carry out profiling.
- Who may have access to personal data?
- Employees of the Data Controller and any data processors. The current list of the Data Controller’s data processors is set out in Section 4 of this Privacy Policy.
- Transfer of data to a third country or to an international organisation
- No data is transferred to a third country or to an international organisation.
Newsletter subscription
- Purpose of data processing
- To send a newsletter providing information about the Data Controller’s activities.
- Scope of data processed
- The email address provided by the data subject; the data subject’s consent.
- Data subjects
- Natural persons who subscribe to the Data Controller’s newsletter and marketing communications on the Data Controller’s website.
- Legal basis for data processing
- The data subject’s consent, in accordance with Article 6(1)(a) of the GDPR.
- Data retention period
- Until the data subject withdraws their consent, or until the sending of the newsletter ceases, whichever is later.
- Method of data processing
- Electronically
- Source of data
- Data collected from the data subject.
- Possible consequences of failure to provide data
- If the data subject does not provide the data to the Data Controller, the Data Controller will not send a newsletter to the data subject; failure to provide data will not result in any adverse legal consequences for the data subject.
- Automated decision-making and profiling
- The Data Controller does not use automated decision-making and does not carry out profiling.
- Who may have access to personal data?
- Employees of the Data Controller and its data processors. The current list of the Data Controller’s data processors is set out in Section 4 of this Privacy Policy.
- Data transfer
- Data may be transferred to a third country or to an international organisation when using SendPulse*.
*SendPulse applies the Standard Contractual Clauses (SCCs) approved by the European Commission for data transfers outside the European Union, thereby guaranteeing a high level of data protection in accordance with the provisions of the GDPR and ensuring that the rights of European users are fully safeguarded.
Further information on SendPulse’s data processing practices is available here:
Workshop registration
- Purpose of data processing
- Application and registration for a workshop organised by the Data Controller; maintaining contact in connection with the application
- Scope of data processed
- Personal data required for registration: name, email address, country, full address, tax number in the case of sole traders, and any additional personal data provided by the data subject during the registration process.
- Scope of data subjects
- Natural persons and sole traders who register for a workshop organised by the Data Controller.
- Legal basis for data processing
- The Data Controller processes personal data on the basis of Article 6(1)(b) of the GDPR, as the processing is necessary for taking steps at the request of the data subject prior to entering into a contract between the Parties.
- Data retention period
- The retention period for the processing of personal data is 5 years from the termination of the contract (limitation period).
- Method of data processing
- Electronically.
- Source of data
- Data collected from the data subject.
- Possible consequences of failure to provide data
- If the data subject does not provide the data to the Data Controller, the data subject will not be able to register for the workshop.
- Automated decision-making and profiling
- The Data Controller does not use automated decision-making and does not carry out profiling.
- Who may have access to the data?
- Personal data may be accessed by the Data Controller and its data processors. The current list of the Data Controller’s data processors is set out in Section 4 of this Privacy Policy.
- Transfer of data to a third country or an international organisation
- No data is transferred to a third country or to an international organisation.
Participation in the workshop
- Purpose of data processing
- Participation in a workshop organised by the Data Controller, and communication in connection with such participation
- Scope of data processed
- Name, email address, image, voice, and any other personal data shared by the data subject whilst participating in the workshop.
- Data subjects
- Natural persons and sole traders who participate in the workshop held by the Data Controller.
- Legal basis for data processing
- The Data Controller processes personal data on the basis of Article 6(1)(b) of the GDPR, as the processing is necessary for taking steps at the data subject’s request prior to entering into a contract between the Parties.
- Data retention period
- The retention period for the processing of personal data is 5 years from the termination of the contract (limitation period).
- Method of data processing
- Electronically.
- Source of data
- Data collected from the data subject.
- Possible consequences of failure to provide data
- If the data subject does not provide the data to the Data Controller, they will not be able to take part in the workshop.
- Automated decision-making and profiling
- The Data Controller does not use automated decision-making and does not carry out profiling.
- Who may have access to the data?
- Personal data may be accessed by the Data Controller and its data processors. The current list of the Data Controller’s data processors is set out in Section 4 of this Privacy Policy.
- Transfer of data to a third country or an international organisation
- No data is transferred to a third country or to an international organisation.
Processing of contact details
The Data Controller maintains a register of its contractual partners and clients. With regard to the maintenance of these records, it is important to note that, as a general rule, the Data Controller may process personal data contained in contracts concluded in the course of its activities only until the performance of the contract, on the legal basis set out in Article 6(1)(b) of the GDPR.
The Data Controller’s contractual partners include both legal entities and organisations without legal personality, the data of which, as a general rule, do not constitute personal data; the Data Controller stores such data for the purpose of performing the contract. However, the data of certain contact persons specified in the contract, as well as the data of persons who, as natural persons but representing the relevant legal entity, participate in the workshop and who do not have a contractual relationship with the Data Controller—but are merely employees, employees, subcontractors or representatives of the Data Controller’s contracted partners or clients. The Data Controller stores and records the contact details and personal data of these individuals in order to facilitate the Data Controller’s activities, on the basis of the Data Controller’s legitimate interest and in accordance with the data protection impact assessment carried out.
- Purpose of data processing
- The purpose of data processing is to maintain a register of the Data Controller’s contractual partners, clients and their contact persons.
- Scope of data processed
- The name and email address of the contractual partner or client, and the contact details of the contact person (name, email, telephone number).
- Data subjects
- The Data Controller’s contractual partners, clients and contact persons.
- Legal basis for data processing
- Regarding the contracting party, the conclusion or performance of the contract pursuant to Article 6(1)(b) of the GDPR; with regard to the contracting party’s contact persons, the Data Controller’s legitimate interests pursuant to Article 6(1)(f) of the GDPR.
- Data retention period
- For a period of 5 years following the termination of the contract.
- Method of data processing
- Electronically and/or on paper.
- Source of data
- Data collected from the data subject.
- Possible consequences of failure to provide data
- The provision of personal data is necessary for the performance of a contract; if the data subject does not make the data available to the Data Controller, the Data Controller will be unable to perform the contract or maintain contact with the business partner or customer.
- Automated decision-making and profiling
- The Data Controller does not use automated decision-making and does not carry out profiling.
- Who may have access to personal data?
- Personal data may be accessed by the Data Controller and its data processors. The current list of the Data Controller’s data processors is set out in Section 4 of this Privacy Policy.
- Transfer of data to a third country or an international organisation
- No data is transferred to a third country or to an international organisation.
Data processing relating to credit card payments and invoicing
- Purpose of data processing
- To facilitate the payment process, and to issue, manage and account for invoices.
- Scope of data processed
- The data specified in Section 167 of Act C of 2000 on Accounting and Section 169 of Act CXXVII of 2007 on Value Added Tax, in particular the data subject’s name, the date and period of the economic transaction, and their address.
- Scope of data subjects
- Users purchasing products on the Website (typically those registering for workshops).
- Legal basis for data processing
- Section 159 and Section 167 of Act C of 2000 on Accounting, in view of the fulfilment of a legal obligation under Article 6(1)(c) of the GDPR.
- Data retention period
- The Data Controller is obliged to retain accounting documents for at least 8 years in accordance with Section 169(2) of Act C of 2000 on Accounting. The Data Controller will automatically delete the data subject’s personal data after 8+1 years.
- Method of data processing
- Electronically.
- Source of data
- Data collected from the data subject.
- Automated decision-making and profiling
- The Data Controller does not use automated decision-making and does not carry out profiling.
- Who may have access to personal data?
- Personal data may be accessed by the Data Controller and its data processors. The current list of the Data Controller’s data processors is set out in Section 4 of this Privacy Policy.
- Data transfer
- No data is transferred to a third country or to an international organisation.
The Data Controller hereby states that it uses the services of Stripe Technology Europe, Limited as a data processor during the payment process. The Data Controller does not receive from Stripe or from any third parties any financial or bank card data that would enable it to debit the data subject’s bank account or payment account, or to withdraw any sum of money therefrom, without the data subject’s involvement and prior consent.
The Data Controller hereby informs the data subject that, when using Stripe or in connection with the receipt of a bank transfer, it does not gain access to the data subject’s password or security code (CVV/CVC code) associated with their bank card, bank account number or payment account; this information remains secure at all times.
The Data Controller receives from payment service providers the personal data specified in the Privacy Policy, the transfer of which is necessary to fulfil the Data Controller’s legal obligations (such as the transaction amount and the date of completion), as well as data (which may be personal) that enables the Data Controller to notify the data subject in the event of any error occurring during a payment transaction (for example, the card has expired or a time-out occurred during the payment transaction), so that the payment can be completed.
The data subject also acknowledges that the following personal data stored by the Data Controller during the purchase will be transferred to Stripe Technology Europe, Limited as the data processor: email address. The nature and purpose of the data processing activities carried out by the data processor are set out in Stripe Technology Europe, Limited’s Privacy Policy, which can be viewed at the following link: https://stripe.com/en-hu/privacy
The Data Controller hereby informs the data subject that the processing of credit card details used for online payments is carried out in accordance with the terms and conditions set by the card-issuing company. Neither the Data Controller nor Stripe Technology Europe, Limited has access to the full credit card details.
Data processing in relation to the Facebook page
The Data Controller operates a Facebook page on the website https://www.facebook.com/, which is accessible via the following link: https://www.facebook.com/pearlyquality
On its Facebook page, the Data Controller publishes information and informal news relating to its services and activities. Visitors to the page have the opportunity to share their opinions regarding the Data Controller’s services. The Data Controller uses the Page Insights feature on its Facebook page to collect data and analyse visitors’ activity.
Regarding personal data collected through Page Insights in connection with the Facebook page, the Data Controller and Meta Platforms Ireland Ltd. are considered joint controllers under Article 26 of the GDPR, as the Data Controller and Meta Platforms Ireland Ltd. jointly determine the purposes and means of data processing. In the case of any other processing of personal data relating to the Facebook page and associated content where the purposes and means have not been jointly determined, Meta Platforms Ireland Ltd. and – depending on the specific circumstances – the Data Controller remain independent, separate data controllers. The main obligations and responsibilities relating to joint data processing between the Data Controller and Meta Platforms Ireland Ltd. are divided as follows. Meta Platforms Ireland Ltd. assumes primary responsibility under the GDPR for the processing of analytics data and for complying with all relevant obligations set out in the GDPR in relation to the processing of analytics data. Meta Platforms Ireland Ltd. provides information to data subjects regarding data processing in the ‘Information about Page Insights data’ section on Facebook. Meta Platforms Ireland Ltd. designates the communication channels serving as the point of contact for data subjects.
Should data subjects exercise their rights against the Data Controller in relation to the processing of analytics data, or should the supervisory authority contact the Data Controller regarding the processing of analytics data, the Data Controller shall, without delay and no later than within 7 calendar days, forward to Meta Platforms Ireland Ltd. all relevant data relating to such requests without delay, but no later than within 7 calendar days. Meta Platforms Ireland Ltd. undertakes to respond appropriately to data subjects’ requests in fulfilment of its obligations. The Data Controller shall not act on behalf of, nor provide a response on behalf of, Meta Platforms Ireland Ltd.
The Data Controller ensures that it has a lawful basis under the GDPR for the processing of analytics data. The Data Controller does not request specific personal data processed during Site Analytics from Meta Platforms Ireland Ltd.; the Data Controller only views the statistics and reports produced by Meta Platforms Ireland Ltd., and not the personal data on which they are based.
The Data Controller uses the database of newsletter subscribers in connection with the operation of the Facebook page and in relation to advertisements appearing on Meta platforms, in order to ensure that marketing communications reach a wider audience; in this regard, the Data Controller acts with the utmost care and in full compliance with the law.
- Purpose of data processing
- To process data arising from the use of the Facebook page.
- Scope of data processed
- As a general rule, the Data Controller processes only statistical data, such as the number of people who have ‘liked’ the page, the number of new ‘likes’, and, in relation to posts published on the Facebook page, the number of people who have read, ‘liked’, commented on or shared the post, the number of times a post has been marked as spam; regarding visits to the Facebook page, how many times the page has been viewed and how many times visitors have come to the Facebook page from external sites or websites; and regarding videos posted on the Facebook page, how many times the video has been viewed and which videos are the most viewed. It also processes the age, gender and location of people who ‘like’ the Facebook page as statistical data.
- Data subjects
- Visitors to the Facebook page.
- Legal basis for data processing
- Consent of the data subject pursuant to Article 6(1)(a) of the GDPR.
- Data retention period
- Until the data subject withdraws their consent.
- Method of data processing
- Electronically.
- Source of data
- Data collected from the data subject.
- Who may have access to the personal data?
- The Data Controller, employees of Meta Platforms Ireland Ltd., and employees of any data processors. The current list of the Data Controller’s data processors is set out in Section 5 of this Privacy Policy.
- Data transfer
- No data is transferred to a third country or to an international organisation.
Further information on the joint data processing agreement between the Data Controller and Meta Platforms Ireland Ltd. regarding the Facebook page can be found at the following link:
https://www.facebook.com/legal/terms/information_about_page_insights_data
Data processing in relation to the Instagram page
The Data Controller operates an Instagram page on the website https://www.instagram.com, which is accessible via the following link: https://www.instagram.com/pearlyquality/
On its Instagram page, the Data Controller publishes information and informal news relating to its services and activities. Visitors to the page have the opportunity to express their opinions regarding the Data Controller’s services. The Data Controller collects data and analyses visitors’ activity on its Instagram page.
- Purpose of data processing
- To process data arising from the use of the Instagram page.
- Scope of data processed
- As a general rule, the Data Controller only processes statistical data, such as the number of people who have liked a post, the number of new likes, and, in relation to posts published on the Instagram page, the number of people who have viewed, liked, commented on or shared the post, the number of times a post has been marked as spam; regarding visits to the Instagram page, how many times the page has been viewed and how many times visitors have come to the Instagram page from external sites or websites; and regarding videos posted on the Instagram page, how many times the video has been viewed and which videos are the most viewed. It also processes the age, gender and location of people who ‘like’ the Instagram page as statistical data.
- Data subjects
- Visitors to the Instagram page.
- Legal basis for data processing
- Consent of the data subject pursuant to Article 6(1)(a) of the GDPR.
- Data retention period
- Until the data subject withdraws their consent.
- Method of data processing
- Electronically.
- Source of data
- Data collected from the data subject.
- Who may have access to the personal data?
- The Data Controller, employees of Meta Platforms Ireland Ltd., and employees of any data processors. The current list of the Data Controller’s data processors is set out in section 4 of this Privacy Policy.
- Data transfer
- No data is transferred to a third country or to an international organisation.
Data processing in relation to the LinkedIn page
The Data Controller operates a LinkedIn page on the https://www.linkedin.com/ website, which can be accessed via the following link: https://www.linkedin.com/company/pearly-quality/
On its LinkedIn page, the Data Controller publishes information and informal news relating to its services and activities. Visitors to the page have the opportunity to express their opinions regarding the Data Controller’s services. The Data Controller collects data and analyses visitors’ activity on its LinkedIn page.
- Purpose of data processing
- To process data arising from the use of the LinkedIn page.
- Scope of data processed
- As a general rule, the Data Controller only processes statistical data, such as the number of people who have ‘liked’ a post, the number of new ‘likes’, and, in relation to posts published on the LinkedIn page, the number of people who have read, ‘liked’, commented on or shared the post, the number of times a post has been marked as spam; regarding visits to the LinkedIn page, how many times the page has been viewed and how many times visitors have come to the LinkedIn page from external sites or websites; and regarding videos published on the LinkedIn page, how many times the video has been viewed and which videos are the most viewed. It also processes the age, gender and location of people who ‘like’ the LinkedIn page as statistical data.
- Data subjects
- Visitors to the LinkedIn page.
- Legal basis for data processing
- Consent of the data subject pursuant to Article 6(1)(a) of the GDPR.
- Data retention period
- Until the data subject withdraws their consent.
- Method of data processing
- Electronically.
- Source of data
- Data collected from the data subject.
- Who may access the personal data?
- The Data Controller, Microsoft, its employees, and the employees of any data processors. The current list of the Data Controller’s data processors is set out in Section 4 of this Privacy Policy.
- Data transfer
- No data is transferred to a third country or to an international organisation.
Data processing in relation to the YouTube page
The Data Controller operates a YouTube page at https://www.youtube.com/, which is accessible via the following link: https://www.youtube.com/@PearlyQuality
On its YouTube page, the Data Controller publishes information and informal news relating to its services and activities. Visitors to the page have the opportunity to express their opinions regarding the Data Controller’s services. The Data Controller collects data and analyses visitors’ activity on its YouTube page.
- Purpose of data processing
- To process data arising from the use of the YouTube page.
- Scope of data processed
- As a general rule, the Data Controller only processes statistical data, such as the number of people who have ‘liked’ a post, the number of new ‘likes’, and, in relation to videos posted on the page, the number of people who have viewed, ‘liked’, commented on or shared the video, the number of times a post has been marked as spam; regarding visits to the page, how many times the page has been viewed, and how many times visitors have arrived at the page from external sites or websites; and regarding videos posted on the page, how many times the video has been viewed, and which videos have been viewed most frequently at . It also processes the age, gender and location of people who ‘like’ the page as statistical data.
- Data subjects
- Visitors to the YouTube page.
- Legal basis for data processing
- Consent of the data subject pursuant to Article 6(1)(a) of the GDPR.
- Data retention period
- Until the data subject withdraws their consent.
- Method of data processing
- Electronically.
- Source of data
- Data collected from the data subject.
- Who may have access to personal data?
- The Data Controller, the staff of the data processor, and the staff of any sub-processors. The current list of the Data Controller’s data processors is set out in Section 4 of this Privacy Policy.
- Data transfer
- No data is transferred to a third country or to an international organisation.
Data processing in relation to the Spotify page
The Data Controller operates a Spotify account on the website https://www.spotify.com, which is accessible via the following link: https://open.spotify.com/show/46agoaFh7JDxsnnmI0oTTC
The Data Controller publishes information relating to its services and activities, as well as informal news and podcasts, on its Spotify account. Visitors to the page have the opportunity to share their opinions on individual podcast episodes published by the Data Controller. The Data Controller collects data and analyses visitor activity on its Spotify account.
- Purpose of data processing
- To process data arising from the use of the Spotify site.
- Scope of data processed
- As a general rule, the Data Controller only processes statistical data, such as:
- demographic data (the distribution of listeners by age group and the percentage breakdown by gender)
- geographical data (breakdown by country, region or city from which plays originate, playback behaviour (how many people listened to the episode, where they fast-forwarded, and at exactly which minute they stopped listening),
- devices (which platform and app were used to listen to the podcast)
- the overall average rating given to the podcast
Personal data collected in addition to the above:
- when using the Q&A module or the polls module, respondents’ Spotify display name, the text of their response, and their profile picture
- the number and list of public followers, and, depending on the user’s settings, the user’s profile.
- Data subjects
- Visitors to the Spotify website.
- Legal basis for data processing
- Consent of the data subject pursuant to Article 6(1)(a) of the GDPR.
- Data retention period
- Until the data subject withdraws their consent.
- Method of data processing
- Electronically.
- Source of data
- Data collected from the data subject.
- Who may have access to the personal data?
- The Data Controller, employees of Spotify, and employees of any data processors. The current list of the Data Controller’s data processors is set out in Section 4 of this Privacy Policy.
- Data transfer
- No data is transferred to a third country or to an international organisation.
Data processing in relation to the TikTok page
The Data Controller operates a TikTok page on the website https://www.tiktok.com, which is accessible via the following link: https://www.tiktok.com/@pearlyquality
On its TikTok page, the Data Controller publishes information and informal news relating to its services and activities. Visitors to the page have the opportunity to express their opinions regarding the Data Controller’s services. The Data Controller collects data on its TikTok page and analyses visitors’ activity.
- Purpose of data processing
- To process data arising from the use of the TikTok page.
- Scope of data processed
- As a general rule, the Data Controller only processes statistical data, such as the number of people who have liked a post, the number of new likes, and, in relation to posts published on the TikTok page, the number of people who have read, liked, commented on or shared the post, the number of times a post has been marked as spam; regarding visits to the TikTok page, how many times the page has been viewed and how many times visitors have come to the TikTok page from external sites or websites; and regarding videos published on the TikTok page, how many times a video has been viewed and which videos are the most viewed. It also processes the age, gender and location of people following the TikTok page as statistical data.
- Data subjects
- Visitors to the TikTok page.
- Legal basis for data processing
- Consent of the data subject pursuant to Article 6(1)(a) of the GDPR.
- Data retention period
- Until the data subject withdraws their consent.
- Method of data processing
- Electronically.
- Source of data
- Data collected from the data subject.
- Who may have access to the personal data?
- Authorised employees of the Data Controller, staff of TikTok Technology Ltd. and TikTok Information Technologies UK Limited, and staff of any data processors. The current list of the Data Controller’s data processors is set out in Section 4 of this Privacy Policy.
- Data transfer
- No data is transferred to a third country or to an international organisation.
Data processing in relation to complaints
The Data Controller provides the User with a complaints handling procedure. Customers of the Data Controller who qualify as consumers are entitled to the right to lodge a complaint as set out in Act CLV of 1997 on Consumer Protection (hereinafter: ‘CPA’). Under the CPA., the consumer (data subject) is entitled to lodge a complaint with the Data Controller via the contact details specified in point 1, as well as verbally or in writing by post to its registered office. The Data Controller shall handle complaints received in accordance with the provisions of the Consumer Protection Act and shall inform the consumer of the outcome of the investigation into the complaint within the specified time limit. The Data Controller notes that Users who are sole traders as defined in Section 3(17) of the Personal Income Tax Act shall be regarded as consumers under Section 2(10) of the Consumer Protection Act only if they act for purposes falling outside the scope of their self-employment and economic activities.
The Data Controller handles complaints via email and through the secure communication channel available within the System. In the event of a complaint sent to the Data Controller’s email address, the Data Controller shall examine the complaint and provide a substantive response within 30 (thirty) days of receipt, and shall ensure that the response is delivered to the Customer. If the complaint is rejected, the Data Controller shall inform the Customer of its position in its substantive reply regarding the rejection, together with the reasons for the rejection. The Data Controller shall retain the record of the complaint and a copy of the reply for five years.
- Purpose of data processing
- To receive, investigate and handle customer complaints and enquiries.
- Scope of data processed
- The data subject’s name, address, email address, other data relating to the complaint, and data relating to the enforcement of rights.
- Data subjects
- The person lodging the complaint.
- Legal basis for data processing
- In the case of data subjects who are consumers, the data subject’s consent pursuant to Article 6(1)(a) of the GDPR; and, having regard to the provisions of the Consumer Protection Act, compliance with a legal obligation pursuant to Article 6(1)(c) of the GDPR.
In the case of data subjects who are not consumers, the legal basis is the data subject’s consent pursuant to Article 6(1)(a) of the GDPR; where legal action is taken as a result of complaint handling, the legal basis is the Data Controller’s legitimate interests pursuant to Article 6(1)(f) of the GDPR.
- Data retention period
- If, following the dispatch of the reply, the data subject has not raised any further objections, the Data Controller shall erase the data upon expiry of the limitation period, i.e. five years from the date of dispatch of the reply; in the event of further claims being asserted, the data shall be erased upon expiry of the limitation period; and in the event of any civil law claims being asserted, once the relevant proceedings have been finally concluded.
- Method of data processing
- On paper and/or electronically
- Source of data
- Data collected from the data subject
- Possible consequences of failure to provide data
- The provision of personal data is mandatory; if the data subject does not make the data available to the Data Controller, the Data Controller will be unable to investigate complaints.
- Automated decision-making and profiling
- The Data Controller does not use automated decision-making and does not carry out profiling.
- Who may access personal data?
- The Data Controller’s authorised staff and any legal representatives may have access to it.
- Transfer of data to a third country or an international organisation
- No data is transferred to a third country or to an international organisation.
Data processing in connection with the maintenance of records relating to the exercise of data subjects’ rights under the GDPR
- Purpose of data processing
- Data processing in connection with the maintenance of records relating to the exercise of data subjects’ rights as set out in the GDPR.
- Scope of data processed
- The data subject’s name, place and date of birth, mother’s name, residential address, postal address, and the request to exercise their rights under the GDPR.
- Data subjects
- Any person exercising their rights as a data subject under the GDPR.
- Legal basis for data processing
- The legal basis for data processing is compliance with a legal obligation under Article 6(1)(c) of the GDPR, as well as a legitimate interest under Article 6(1)(f).
- Data retention period
- 5 years from the date of the decision on the request.
- Method of data processing
- On paper and/or electronically.
- Source of data
- Data collected from the data subject.
- Possible consequences of failure to provide data
- The processing of data is necessary for the Data Controller to comply with the provisions of the GDPR.
- Automated decision-making and profiling
- The Data Controller does not use automated decision-making and does not carry out profiling.
- Who may have access to personal data?
- Employees of the Data Controller and any data processors. The current list of the Data Controller’s data processors is set out in Section 4 of this Privacy Policy.
- Data transfer to a third country or to an international organisation
- No data is transferred to a third country or to an international organisation.
Cookies
The Data Controller uses so-called ‘cookies’ in the operation of the Website. A cookie is a small data file (hereinafter: ‘cookie’) which the Data Controller sends to the data subject’s web browser and which is stored on the data subject’s device. Some cookies are essential for the website to function properly; others collect statistics to make the website more user-friendly; whilst there are cookies designed to display targeted advertisements.
Detailed information regarding the Data Controller’s use of cookies can be found in the Data Controller’s Cookie Policy, which is available at all times on the Data Controller’s website.
Data Processors
The Data Controller hereby informs data subjects that data processors are not authorised to make independent decisions; they are authorised to act solely in accordance with the contract concluded with the Data Controller and the instructions received. Data processors shall record, manage and process the personal data transferred to them by the Data Controller and managed or processed by them in accordance with the provisions of the GDPR. Data processors carry out data processing operations on the personal data provided by data subjects within the retention period specified in this Privacy Policy and applicable to the respective data processing purposes.
In the course of data processing, the Data Controller engages the following data processors:
| Category of data processor | Purpose of data processing | Name | Registered office | Company / registration number |
|---|---|---|---|---|
| Hosting provider | Hosting service | Rackforest Zrt. (Rackforest Informatikai Kereskedelmi Szolgáltató és Tanácsadó Zrt.) | 1132 Budapest, Victor Hugo utca 11. 5. em. B05001. | 01-10-142004 |
| Google Account, operation of YouTube marketing cookies, operation of Google Analytics | Google Account, operation of YouTube marketing cookies, operation of Google Analytics | Google Ireland Ltd. | Gordon House, 4 Barrow St, Grand Canal Dock, Dublin 4, D04 V4X7, Ireland | — |
| Operation of Facebook and Instagram pages | Operation of Facebook and Instagram pages | Meta Platforms Technologies Ireland Limited | 6 Serpentine Ave, Dublin, D04 H0C9, Ireland | - |
| Operating a LinkedIn page | Operating a LinkedIn page | LinkedIn Ireland Unlimited Company | Wilton Place, Dublin 2, Ireland | - |
| Running a TikTok page | TikTok page operator | TikTok Technology Limited | 10 Earlsfort Terrace, Dublin, D02 T380, Ireland | — |
| Operating a Spotify page | Running a Spotify page | Spotify AB | Regeringsgatan 19 SE-111 53 Stockholm, Sweden | Reg. No.: 556703-7485 |
| Newsletter distribution | Provision of a newsletter service | SendPulse Inc. | 220 E 23rd St #401, New York, NY 10010, USA. | — |
| Carrying out accounting tasks | Performing accounting tasks | — | — | — |
| Invoicing software | Invoicing | Billingo Technologies Zrt. | 1133 Budapest, 6 Árbóc Street, 1st floor | 01-10-140802 |
| Payment service provider | Provision of payment processing | Stripe Technology Europe | The One Building, 1, Lower Grand Canal Street, Dublin 2, Ireland | - |
| Operating the development framework | Operating the development framework | GitHub | GitHub, Inc. 88 Colin P Kelly Jr St. San Francisco, CA 94107 USA | - |
Exercising data subjects’ rights
Data subjects may request information regarding the processing of their personal data; they may also request the rectification of their personal data; restriction of processing; erasure of their data directly from the Data Controller via the contact details specified in point 1; and are entitled to data portability, as well as the right to seek a judicial remedy and the right to withdraw consent. In the event of a complaint, the data subject may, within the territory of Hungary, lodge a complaint with the National Authority for Data Protection and Freedom of Information or, at their discretion, bring the matter before a court. In court proceedings, the regional court has jurisdiction.
When complying with a data subject’s request regarding the processing of personal data, the Data Controller shall verify the data subject’s identity in accordance with this Privacy Policy, taking into account the data subject’s status (customer, applicant, etc.), and the Data Controller is only entitled to comply with the data subject’s request once the data subject has been adequately identified.
If the applicant has not submitted their request relating to the processing of personal data in accordance with the provisions of this Privacy Policy, and the Data Controller has been unable to verify the applicant’s identity to the standard required for data security and/or confidentiality (as set out in this Privacy Policy) (i.e. was unable to identify them as the data subject), the Data Controller shall request the applicant to rectify the deficiencies; should the applicant fail to do so or not comply with such a request, the Data Controller will be unable to respond to the request.
The time elapsed between the Data Controller’s request for the provision of the necessary personal data or the completion of the missing action and the actual provision of the personal data shall not be included in the time limit for responding to the request.
The Data Controller shall inform all recipients to whom the personal data have been disclosed of any rectification, erasure or restriction of processing, unless this proves impossible or involves a disproportionate effort. At the data subject’s request, the Data Controller shall provide information regarding these recipients.
Right to information and access
In accordance with the obligation set out in Article 13 of the GDPR, the Data Controller is obliged – where the personal data originates from the data subject at the time of collection – to provide data subjects with the following information regarding the processing of personal data:
- the identity and contact details of the data controller and its representative;
- the contact details of the data protection officer, if any;
- the purposes of the intended processing of personal data and the legal basis for the processing;
- where applicable, the recipients or categories of recipients of the personal data, if any;
- the period for which the personal data will be stored, or, where this is not possible, the criteria used to determine that period;
- information regarding the data subject’s right to request from the data controller access to, rectification of, erasure of or restriction of the processing of personal data relating to them, and to object to the processing of such personal data, as well as the data subject’s right to data portability;
- in the case of data processing based on consent, the right to withdraw consent at any time, without this affecting the lawfulness of the data processing carried out on the basis of consent prior to withdrawal;
- the right to lodge a complaint with the supervisory authority;
- whether the provision of personal data is required by law or under a contractual obligation, or is a prerequisite for entering into a contract, and whether the data subject is obliged to provide personal data, as well as the possible consequences of failing to provide such data.
If the personal data has not been obtained from the data subject, the Data Controller shall provide the data subject with the above information and, in addition, the following information in accordance with Article 14 of the GDPR:
- the categories of personal data relating to the data subject;
- the recipients of the personal data, or the categories of recipients, if any;
- the source of the personal data and, where applicable, whether the data originates from publicly available sources.
If the personal data were not obtained from the data subject, the Data Controller shall provide the information:
- within a reasonable period of time following the acquisition of the personal data, but no later than one month;
- if the personal data are used for the purpose of communicating with the data subject, at the latest when first contacting the data subject; or
- if the data is expected to be disclosed to other recipients, no later than when the personal data is first disclosed.
The obligation to provide information set out above need not be fulfilled if:
- the data subject already possesses the information set out in these points,
- it proves impossible to provide the information in question or would require a disproportionate effort,
- the collection or disclosure of the data is expressly required by Union law or applicable Hungarian law applicable to the Data Controller, which also provides for appropriate measures to safeguard the data subject’s legitimate interests; or
- the personal data must remain confidential pursuant to a professional duty of confidentiality laid down in European Union law or applicable Hungarian law.
The data subject’s right of access – in accordance with Article 15 of the GDPR – extends to the provision of the following information:
- the purposes of the data processing;
- the categories of personal data concerning the data subject;
- the recipients to whom the personal data have been or will be disclosed;
- the envisaged period for which the personal data will be stored;
- the data subject’s rights in relation to the processing of personal data;
- the source of the data, where it has not been collected from the data subject;
- information regarding automated decision-making.
The Data Controller shall endeavour in all cases to ensure that the information provided to the data subject is, to the extent possible and whilst complying with the rules laid down by the GDPR, concise, transparent, intelligible, easily accessible, clear and plain. The Data Controller is responsible for providing this information and taking the necessary measures. The Data Controller shall provide all information to the data subject in writing, including by electronic means. In accordance with the data security rules set out in Articles 15 and 32 of the GDPR, the Data Controller shall provide information to the data subject only and exclusively if the Data Controller is satisfied as to the data subject’s identity. If identity cannot be verified, the Data Controller shall reject the data subject’s request to exercise their rights and shall also inform the data subject of how they may exercise their rights.
The Data Controller shall inform the data subject within one month of receiving the request, provided that the request relates to their rights and is set out in a duly communicated statement. Considering the complexity of the request and the number of requests, this one-month deadline may be extended by a further two months by the Data Controller, provided that the Data Controller sends a reasoned notification to the data subject within one month of the submission/receipt of the request.
A request shall be deemed to have been duly communicated or received if the data subject sends the written request to the Data Controller’s official address or to the email address provided for this purpose, and it is received there.
The Data Controller will not consider any request that is not communicated in accordance with the above.
Information and communication relating to the processing of personal data must be easily accessible and comprehensible and must be formulated in clear and simple language. This principle applies in particular to informing data subjects of the identity of the data controller and the purpose of data processing, as well as to providing further information aimed at ensuring the fair and transparent processing of the data subject’s personal data, as well as to information confirming that data subjects have the right to obtain confirmation and information regarding the data processed about them.
The Data Controller shall provide the information and take the measures set out in this clause free of charge; the Data Controller shall only charge a fee in the cases specified in Article 12(5) of the GDPR.
Right to rectification
The data subject has the right to have inaccurate personal data concerning them rectified by the Data Controller without undue delay upon request. Considering the purposes of the processing, the data subject has the right to request that incomplete personal data be completed, including by means of a supplementary statement.
Right to object
The data subject may object to the processing of their personal data by submitting a statement to the Data Controller if the legal basis for the processing
- a public interest pursuant to Article 6(1)(e) of the GDPR or
- a legitimate interest pursuant to Article 6(1)(f) of the GDPR.
Where the right to object is exercised, the Data Controller may no longer process the personal data, unless the Data Controller demonstrates that the processing is justified on compelling legitimate grounds which override the data subject’s interests, rights and freedoms, or which are related to the establishment, exercise or defence of legal claims. The decision as to whether the processing is justified by compelling legitimate grounds shall be taken by the Data Controller’s management.
It shall inform the data subject of its position on this matter in a written statement. For the duration until such a determination is made, the processing of personal data shall be restricted accordingly.
The right to restriction of data processing
Data processing may be restricted in the following circumstances:
- the data subject disputes the accuracy of the data; in such cases, the Data Controller shall restrict the processing of personal data for the period until the accuracy of the data is established;
- the processing is unlawful and the data subject requests the restriction of use rather than erasure;
- the data controller no longer needs the data, but the data subject requires it to assert legal claims;
- the data subject objects to the processing of personal data in accordance with Article 21 of the GDPR, pending the outcome of the assessment of the objection.
For the duration of the assessment of the data subject’s objection to the processing of their personal data – but for no longer than 5 days – the Data Controller shall suspend the processing, examine the merits of the objection and make a decision, of which the applicant shall be informed.
If the objection is justified, the Data Controller shall restrict the data, meaning that only storage, as a form of data processing, may take place until:
- the data subject consents to the processing;
- the processing of personal data is necessary for the establishment, exercise or defence of legal claims;
- the processing of personal data is necessary to protect the rights of another natural or legal person; or
- data processing is required by law in the public interest.
Where the Data Controller lifts the restriction on data processing, it shall, prior to lifting the restriction, inform in writing the data subject at whose request the restriction was imposed of the fact that the restriction has been lifted, unless this proves impossible or involves a disproportionate effort. Where the restriction on processing was requested by the data subject, the Data Controller shall inform the data subject in advance of the lifting of the restriction.
Right to erasure (‘right to be forgotten’)
The data subject has the right to have the Data Controller erase personal data relating to them without undue delay upon request, and the Data Controller is obliged to erase personal data relating to the data subject without undue delay if any of the following grounds apply:
- the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
- the data subject withdraws their consent on which the processing is based, and there is no other legal basis for the processing;
- the personal data has been processed unlawfully;
- the personal data must be erased in order to comply with a legal obligation under Union or Member State law to which the controller is subject;
the personal data were collected in connection with the offer of information society services.
The data subject’s right to erasure may only be restricted where the following exceptions set out in the GDPR apply; that is to say, where the above grounds apply, the continued retention of the personal data may be considered lawful,
- if it is necessary for the exercise of the right to freedom of expression and information, or
- compliance with a legal obligation (i.e. in the case of an activity recorded in the Data Processing Register on the legal basis of a legal obligation, for a period appropriate to the purpose of the data processing), or
- for the performance of a task carried out in the public interest, or
- in the exercise of official authority vested in the data controller, or
- where it is in the public interest in the field of public health,
- for archiving purposes in the public interest, or
- for the purposes of scientific and historical research or for statistical purposes, or
- where it is necessary for the establishment, exercise or defence of legal claims.
The right to data portability
The data subject has the right to receive the personal data concerning them, which they have provided to the Data Controller, in a structured, commonly used and machine-readable format, and is also entitled to transmit this data to another data controller without hindrance from the data controller to whom the personal data was provided, provided that:
- the legal basis for the processing is the data subject’s consent, or the processing was necessary for the performance of a contract to which the data subject is a party, or for taking steps at the request of the data subject prior to entering into a contract [Article 6(1)(a) or (b) of the GDPR, or Article 9(2)(a)]
- the processing is carried out by automated means.
The right set out in this point does not apply to the data subject if the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller, or if this right would adversely affect the rights and freedoms of others.
Where the Data Controller is required to disclose personal data to a person other than the data subject pursuant to the data subject’s right to data portability, the Data Controller shall, within the framework of this Privacy Policy, inform and remind that third-party recipient that they may not use the personal data transferred by the Data Controller in relation to the data subject for their own purposes, and may process such personal data solely in accordance with the provisions of the relevant data protection legislation and for the specified purpose. The Data Controller accepts no liability for the use by a third party of personal data duly transferred to that third party at the data subject’s request.
The right to withdraw consent
Where the legal basis for the Data Controller’s processing of a data subject’s personal data is the data subject’s consent, the data subject may withdraw their consent to such processing at any time. In this regard, the Data Controller informs data subjects that, even after the withdrawal of consent, the Data Controller may continue to process the data subject’s personal data for the purposes of complying with a legal obligation or pursuing its legitimate interests, provided that the pursuit of such interests is proportionate to the restriction of the right to the protection of personal data.
Remedies
The data subject may request information regarding the processing of their personal data; they may also request the rectification of their personal data; the restriction of processing; or the erasure of their data by submitting a written request via the contact details set out in point 1 or by post to the Data Controller’s registered office. The data subject has the right to object to the processing of data, , and may exercise their right to data portability. We also inform you that you may withdraw your consent at any time.
Should the data subject consider that the data processing contravenes the provisions of the GDPR or the Information Act, or if they consider the Data Controller’s processing of their personal data to be prejudicial, they may lodge a complaint with the Data Controller using the contact details specified in point 1, furthermore, the data subject is entitled to lodge a complaint regarding the Data Controller’s data processing procedures directly with the supervisory authority, and may submit a report to the National Authority for Data Protection and Freedom of Information (address: 1055 Budapest, Falk Miksa utca 9–11; postal address: 1363 Budapest, PO Box 9; telephone number: +36 (1) 391-1400, email:ugyfelszolgalat@naih.hu , website: www.naih.hu). The data subject has the option of bringing the matter before a court to protect their data, which will deal with the case as a matter of priority. In this case, they are free to decide whether to lodge their claim with the court (http://birosag.hu/torvenyszekek) corresponding to their place of residence (permanent address) or their place of stay (temporary address). You can find the court for your place of residence or temporary address at http://birosag.hu/ugyfelkapcsolati-portal/birosag-kereso.