Privacy Notice
Privacy Notice
For visitors and users of the website https://www.maganszallasaink.hu
Introduction
The service provider / data controller processes the data of individuals registered on the website to provide them with appropriate services.
The service provider fully intends to comply with the legal requirements regarding personal data processing, especially the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council.
This privacy notice is prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of personal data and the free movement of such data, as well as in line with the provisions of Act CXII of 2011 on informational self-determination and freedom of information.
Service Provider and Data Controller Information
Name / Company name:
Sándor Turcsány
Headquarters:
2459 Rácalmás, Fő utca 41.
Tax number:
76929304-1-27
Website name and address:
www.maganszallasaink.hu
The privacy notice is available at:
www.maganszallasaink.hu/adatkezelesitajekoztato
Data Controller Contact Information:
Name / Company Name:
Sándor Turcsány
Headquarters:
2459 Rácalmás, Fő utca 41.
Mailing address:
2459 Rácalmás, Fő utca 41.
Email: info@maganszallasaink.hu
Phone: +36706356727
Definitions
- GDPR (General Data Protection Regulation): The European Union's new Data Protection Regulation;
- Data Processing: Any operation or set of operations performed on personal data or data sets, whether automated or not, such as collection, recording, organization, structuring, storage, transformation, retrieval, consultation, usage, disclosure, transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction;
- Data Processor: A natural or legal person, public authority, agency, or any other body that processes personal data on behalf of the data controller;
- Personal Data: Any information related to an identified or identifiable natural person (data subject); an identifiable person is one who can be identified, directly or indirectly, especially by reference to an identifier such as name, number, location data, online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person;
- Data Controller: A natural or legal person, public authority, agency, or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; if the processing of personal data is governed by EU or member state law, the data controller or the specific criteria for the designation of the data controller may also be specified by EU or member state law;
- Data Subject's Consent: A voluntary, specific, informed, and unambiguous indication of the data subject's wishes, expressed by a statement or by a clear affirmative action, that signifies the data subject's agreement to the processing of their personal data;
- Data Protection Incident: A security breach leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to personal data transmitted, stored, or otherwise processed;
- Recipient: A natural or legal person, public authority, agency, or any other body to whom or with whom personal data is disclosed, regardless of whether it is a third party. Public authorities that may access personal data in the course of a specific investigation in accordance with EU or member state law are not considered recipients; the processing of personal data by these authorities must comply with applicable data protection rules as required by the processing purposes;
- Third Party: A natural or legal person, public authority, agency, or any other body that is not the data subject, the data controller, the data processor, or those persons authorized by the data controller or data processor to process personal data under their direct authority.
Data Processing Principles
The data controller declares that personal data processing will be conducted in accordance with the provisions outlined in this privacy notice and will comply with relevant legal requirements, with particular attention to the following principles:
- Personal data shall be processed lawfully, fairly, and transparently for the data subject.
- Personal data collection may only occur for specified, legitimate, and clear purposes.
- Personal data processing must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed.
- Personal data must be accurate and kept up to date. Any inaccurate personal data should be rectified or erased without delay.
- Personal data shall be stored in a form that permits identification of data subjects only for as long as necessary for the purposes for which the data is processed. Storage beyond this period may only occur for archival purposes in the public interest, scientific or historical research purposes, or statistical purposes.
- Personal data shall be processed in a way that ensures appropriate technical and organizational measures to ensure the security of personal data, including protection against unauthorized or unlawful processing, accidental loss, destruction, or damage.
- The principles of data protection must be applied to all information concerning identified or identifiable natural persons.
Important Information Regarding Data Processing
- Purpose of Processing: The data controller processes personal data in order to provide additional services to registered users of the website.
- Legal Basis for Processing: The legal basis for data processing is the consent of the data subject.
- Scope of Affected Individuals: The affected individuals are the registered users of the website.
- Duration of Processing and Data Deletion: The duration of data processing depends on the specific purpose for which the data is processed, but personal data must be deleted without undue delay once the original purpose has been fulfilled. The data subject may withdraw their consent at any time by sending an email to the contact address. If there are no legal obstacles to deletion, the data will be deleted.
- Authorized Recipients of Data: The data controller and their employees are authorized to access the data.
- Rights of the Data Subject: The data subject has the right to request access to, correction, deletion, or restriction of the processing of their personal data, as well as the right to object to the processing of their personal data and the right to data portability.
- The data subject may withdraw consent to data processing at any time, but this will not affect the lawfulness of data processing based on consent before its withdrawal.
- The data subject has the right to lodge a complaint with a supervisory authority.
If the data subject wishes to use the benefits of registration and avail of the website's services, providing the requested personal data is required. However, the data subject is not obligated to provide personal data, and failure to do so will not result in any disadvantage. Some website functions cannot be used without registration.
The data subject has the right to request the data controller to correct or complete any inaccurate personal data without undue delay.
The data subject has the right to request the data controller to delete inaccurate personal data without undue delay. The data controller is obliged to delete personal data without undue delay if there is no other legal basis for processing.
Requests for modifications or deletions of personal data can be initiated via email, phone, or mail at the contact details provided above.
Website Registration and Data Processing
Purpose of Data Processing: The purpose of processing personal data during registration is to provide additional services and facilitate communication.
Legal Basis for Data Processing: The legal basis for processing is the consent of the data subject.
Scope of Affected Individuals: The individuals involved are the registered users of the website.
Duration of Data Processing: Data processing will continue until the consent is withdrawn. The data subject may withdraw consent at any time by sending an email to the provided contact address.
Data Deletion: Upon withdrawal of consent, data will be deleted. The data subject can revoke their consent at any time by emailing the contact address.
Access to Data: The data controller and their employees have access to the data.
Storage Method: Data is stored electronically.
Personal Data Modification or Deletion: Requests for modification or deletion of personal data can be made via email, phone, or mail using the provided contact details.
Necessity of Personal Data: Providing personal data is necessary for identification and communication in the database. The exact company name and address are required for invoicing, which is a legal obligation.
Processed Data
Purpose of Data Processing:
- Name: Identification, communication, invoicing.
- Company Name: Identification, communication, invoicing.
- Address: Identification, communication, invoicing.
- Email: Identification, communication.
- Phone: Identification, communication.
- Registration Date: Technical information processing.
- IP Address: Technical information processing.
The data subject can give consent by intentionally checking the empty checkbox specifically provided for consent on the website.
Objection to Data Processing: The data subject has the right to object to the processing of their personal data, as described in the provided data processing information and the applicable legal procedures.
Order Placement and Data Processing
Purpose of Data Processing: The goal is to provide additional services, facilitate communication, and send confirmation emails. The order can only be processed if the data subject provides the required contact and billing information, which is necessary for communication and invoicing.
Legal Basis for Data Processing: The legal basis for processing is the consent of the data subject, and for invoicing, the legal basis is a statutory requirement.
Scope of Affected Individuals: The individuals involved are the registered users of the website.
Duration of Data Processing: Data processing will continue in accordance with legal requirements or until consent is withdrawn. The data subject may withdraw consent at any time by sending an email to the provided contact address.
Data Deletion: Data will be deleted upon withdrawal of consent. The data subject may withdraw consent at any time by emailing the contact address. Invoicing data will be deleted according to legal regulations.
Access to Data: The data controller and their employees have access to the data.
Storage Method: Data is stored electronically.
Personal Data Modification or Deletion: Requests for modification or deletion of personal data can be made via email, phone, or mail using the provided contact details.
Processed Data for Orders
Purpose of Data Processing:
- Name: Identification, communication, invoicing.
- Company Name: Identification, communication, invoicing.
- Address: Identification, communication, invoicing.
- Email: Identification, communication.
- Phone: Identification, communication.
- Ordered Product Information: Product identification.
- Registration Date: Technical information processing.
- IP Address: Technical information processing.
The data subject can give consent by intentionally checking the empty checkbox provided for consent on the website.
The data subject has the right to object to the processing of their personal data, as detailed in the data processing information and in the applicable legal procedures outlined in the privacy notice.
Invoice Issuance and Data Processing
Purpose of Data Processing: The purpose of data processing is to issue and send electronic invoices as email attachments.
Legal Basis for Data Processing: The legal basis for processing is a statutory obligation based on legal requirements.
Scope of Affected Individuals: The individuals affected are the service provider's customers.
Duration of Data Processing: Data processing will continue in accordance with legal requirements or until consent is withdrawn. The data subject may withdraw their consent at any time by sending an email to the provided contact address.
Data Deletion: Upon withdrawal of consent, data will be deleted. The data subject may revoke consent at any time by emailing the contact address. Invoicing data will be deleted according to legal regulations.
Access to Data: The data controller and their employees have access to the data.
Storage Method: Data is stored electronically.
Modification or Deletion of Invoice Data: Requests for modification or deletion of personal data can be made via email, phone, or mail using the provided contact details.
Processed Data for Invoice Issuance
Purpose of Data Processing:
- Name: Identification, communication, invoicing.
- Company Name: Identification, communication, invoicing.
- Address: Identification, communication, invoicing.
- Email: Identification, communication.
- Phone: Identification, communication.
- Tax ID: Identifying the customer.
- Invoice Data: Identifying the invoice.
- Invoice Issuance Date: Technical information processing.
The data subject can give consent by intentionally checking the empty checkbox provided for consent on the website.
Objection to Data Processing: The data subject has the right to object to the processing of their personal data, as detailed in the data processing information and in the applicable legal procedures outlined in the privacy notice.
Newsletter Subscription and Data Processing
Purpose of Data Processing: The purpose of data processing is to send professional updates, advertisements, informational emails, and newsletters. You may unsubscribe at any time without consequence. This includes cases where the company has ceased operations, you have left the company, or someone else has provided your contact information to us.
Legal Basis for Data Processing: The legal basis for processing is the consent of the data subject. You may give explicit consent during registration to allow the service provider to contact you via email with promotional offers and updates.
Duration of Data Processing: Data processing will continue until consent is withdrawn. You may withdraw consent at any time by sending an email to the provided contact address.
Data Deletion: Upon withdrawal of consent, data will be deleted. You can withdraw consent at any time by emailing the contact address, or by using the unsubscribe link in the newsletters.
Access to Data: The data controller and their employees have access to the data.
Storage Method: Data is stored electronically.
Modification or Deletion of Data: Requests for modification or deletion of personal data can be made via email, phone, or mail using the provided contact details.
Processed Data for Newsletter Subscription
Purpose of Data Processing:
- Name: Identification, communication.
- Email: Identification, communication.
- Subscription Date: Technical information processing.
- IP Address: Technical information processing.
You are not required to use a username or email address that contains personally identifying information. However, your email address is necessary for receiving newsletters or professional information.
Cookies
Cookies are placed on the user's computer by the websites they visit and contain information such as the site settings or login status.
Cookies are small files created by the websites visited. By saving browsing data, they improve the user experience. With cookies, the website remembers the site settings and offers locally relevant content.
The service provider sends a small file (cookie) to the visitor's computer to determine the visit's time and date. The service provider informs the website visitor about this.
Data subjects: Website visitors.
Purpose of data processing: Additional services, identification, and tracking visitors.
Legal basis for data processing: User consent is not required if the service provider absolutely needs the cookies.
Scope of data: Unique identification number, date and time, setting data.
The user can delete the cookies from their browser at any time via the Settings menu.
Authorized data controllers: The data controller does not process personal data using cookies.
Storage method: Electronic.
Social Media
A social media platform is a medium where messages are spread through social users. Social media uses the internet and online presence to enable users to become content creators rather than just receivers.
Social media platforms include user-generated content such as Facebook, Google+, Twitter, etc.
The forms of presentation in social media can include public speeches, lectures, product or service descriptions.
Information on social media can appear as forums, blog posts, images, videos, audio files, message boards, emails, etc.
Thus, the processed data may include personal data and the user's public profile picture.
Data subjects: All registered users.
Purpose of data collection: Promotion of the website or the connected webpage.
Legal basis for data processing: Voluntary consent of the data subject.
Duration of data processing: According to the regulations of the specific social media platform.
Data deletion deadline: According to the regulations of the specific social media platform.
Authorized data controllers: According to the regulations of the specific social media platform.
Rights regarding data processing: According to the regulations of the specific social media platform.
Storage method: Electronic.
It is important to note that when a user uploads or submits personal data, they grant permission to the social media platform operator worldwide to store and use such content. Therefore, it is crucial to ensure that the user has full authorization to share the published information.
Google Analytics
Our website uses the Google Analytics application:
[x] uses
[□] does not use
When Google Analytics is used:
Google Analytics uses internal cookies to generate reports for its clients on user habits on the website.
On behalf of the website operator, Google uses this information to evaluate how users use the site. Additionally, it creates reports related to website activity for the operator to improve services.
The data is stored in encrypted format on Google's servers to make it difficult and prevent misuse of the data.
To disable Google Analytics, users can install the Google Analytics opt-out browser extension. This extension prevents the Google Analytics JavaScript (ga.js, analytics.js, and dc.js) from sending information to Google Analytics. The extension works with most modern browsers. Disabling Google Analytics does not prevent the website or other online analysis services from collecting data.
Google Privacy Policy: https://policies.google.com/privacy?hl=en
For detailed information regarding the use and protection of data: Google Privacy Policy PDF.
Data Processors
Hosting Service Provider:
Name / Company Name: Webnode
Headquarters:
Phone:
Email:
The data you provide is stored on servers operated by the hosting service provider. Only our staff and the hosting provider's staff have access to the data, but all are responsible for securely managing the data.
Activity name: Hosting service, server service.
Purpose of data processing: To ensure the website operates properly.
Processed data: Personal data provided by the data subject.
Duration of data processing and data deletion deadline: The data processing lasts as long as the website operates or as per the contractual agreement between the website operator and the hosting service provider. The data subject may request data deletion by contacting the hosting provider.
Legal basis for data processing: The consent of the data subject or data processing based on legislation.
Rights Related to Data Processing
Right to information:
You have the right to request information from us about what data we process, the legal basis for processing, the purpose of processing, the source of the data, how long we store it, and more. We will provide the information within 30 days of your request via email.Right to rectification:
You have the right to request modification of your data. We will act on your request promptly, but no later than 30 days, and send you a notification.Right to erasure:
You have the right to request the deletion of your data. We will promptly delete it, but no later than 30 days, and notify you via email.Right to restriction:
You have the right to request the restriction of your data. The restriction will remain until it is necessary to store the data based on your specified reason. We will act on your request promptly, but no later than 30 days, and notify you via email.Right to object:
You have the right to object to the data processing. We will review your objection as soon as possible, but no later than 15 days, and inform you about the decision via email.Legal remedies regarding data processing:
If you believe the data processing is unlawful, please contact us, and we will do our best to resolve the issue promptly. If we are unable to restore the lawful status, you may contact the relevant authorities at the following address:
National Authority for Data Protection and Freedom of Information
Postal address: 1530 Budapest, P.O. Box 5
Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
Phone: +36 (1) 391-1400
Fax: +36 (1) 391-1410
Email: ugyfelszolgalat@naih.hu
URL: https://naih.hu
Laws Governing Data Processing
- EU Regulation (EU) 2016/679 of the European Parliament and the Council (April 27, 2016) on the protection of natural persons regarding the processing of personal data and the free movement of such data.
- Act CXII of 2011 on the Right of Informational Self-Determination and the Freedom of Information.
- Act LXVI of 1995 on the Protection of Public Records, Archives, and Private Archives.
- Government Decree 335/2005 (XII. 29.) on the General Requirements for File Management by Public Authorities.
- Act CVIII of 2001 on Electronic Commerce Services and Certain Issues of Information Society Services.
- Act C of 2003 on Electronic Communications.