CardEmpireHU Ltd.
DATA MANAGEMENT INFORMATION
Content
1. Preamble 3
2. Name of Data Controller: 3
3. Principles of data management - general information: 3
4. Description of data processing operations - detailed information: 5
4.1. Contact us 5
4.2. Data processing in relation to product sales 5
4.3. Mandatory data processing under the Accounting Act 6
4.4. Use of cookies 7
4.5. Handling complaints 7
5. Data subjects' rights in relation to data processing (Articles 15-22 GDPR) 8
5.1 Right to withdraw consent: 8
5.2 Right of access (information): 8
5.3 Right to rectification: 9
5.4 Right to erasure: 9
5.5 Right to restriction of processing: 10
5.6 Data portability: 10
5.7 Objection to the processing of personal data: 11
5.8. Complaints 11
5.9. Judicial enforcement 12
6. Data protection incident: 12
7. Data security: 13
8. Final provisions: 13
Annex I - Definitions: 15
Annex II - Data processors 17
DATA MANAGEMENT INFORMATION
- Preambulum
The present information contains the rights and obligations of natural persons (hereinafter collectively referred to as the "Data Subject") who contact CardEmpireHU Ltd. (hereinafter referred to as the "Data Controller") through the website at https://www.cardempire.hu/ or by any other means, who use the services or purchase the products, as well as detailed information on the processing of personal data.
Annexes:
I. concepts, definitions
II. the list and contact details of the data processors
- Name of data controller:
Name: CardEmpireHU Korlátolt Felelősségű Társaság
Headquarters: 1182 Budapest, Mályinka utca 50.
Tax number: 32673526-2-43
Company registration number: 01 09 443912
Registered with the Company Registry Court of the Budapest-Capital Regional Court.
European Unique Identifier: EUID: HUOCCSZ.08-09-037207.
Official electronic contact details: 32673526#cegkapu
Represented by Domonkos Kiss Azár, Managing Director
Data controller's email address: info@cardempire.hu
The controller does not employ a data protection officer.
- Principles of data management - general information:
The controller declares that:
- processes personal data lawfully and fairly and in a transparent manner for the data subject ("legality, fairness and transparency");
- collects personal data only for specified, explicit and legitimate purposes and does not process them in a way incompatible with those purposes; ("purpose limitation");
- only process data which are adequate and relevant for the purposes of the processing, and to reduce its processing activities to the minimum strictly necessary ("data saving");
- take all reasonable steps to ensure that personal data inaccurate for the purposes of the processing are erased or rectified without undue delay; ("Accuracy");
- store the personal data in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; ("limited shelf life");
- in processing personal data, applies technical or organisational measures to ensure adequate security of personal data, including protection against unauthorised or unlawful processing, accidental loss, destruction or damage ("integrity and confidentiality").
The controller processes special data only on the basis of a mandatory legal provision or the prior consent of the data subject (legal representative).
The data controller collects and processes the personal data of the data subjects in accordance with the purposes and legal basis detailed in point 4 and does not transfer them to third parties for any other purposes.
In addition to the administrator, the data may also be processed by the employees of the controller and its contractual partners (data processors, independent controllers) get to know (for the purposes and to the extent strictly necessary for the performance of their tasks), who assist in the implementation and monitoring of the purposes of data processing (recipients). In exceptional cases other than these, the controller will provide specific information on the identity/category of the recipients.
The person concerned by submitting personal data, you expressly acknowledge that provide only truthful information, and that the controller does not verify the accuracy of the personal data provided to it, does not supplement or combine them with data from other sources, so we cannot accept any liability for any damage caused by incorrect data.
Third parties (e.g. family members, friends) in the case of the provision of personal data, the person providing the data is solely responsible for the fact that the data subject was aware of the provision of the personal data to the controller and had the opportunity to acquaint himself/herself with this privacy statement of the controller.
In addition to the liability set out in the previous paragraph, any user is entitled to make data of other natural persons available to the controller.
Where the controller can demonstrate that it is not in a position to identify the data subject, the data subject may exercise the rights described in this notice by providing the controller with additional information that enables the data subject to be identified. The controller should not be required to obtain additional information in order to comply with a provision of the GDPR in order to establish the identity of the data subject.
The data controller does not carry out profiling and the processing is not automated.
This information notice Regulation (EU) 2016/679 of the European Parliament and of the Council (27 April 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such dataand repealing regulation 95/46/EC (General Data Protection Regulation, hereinafter "GDPR").
- Description of the processing operations - detailed information:
4.1. Contacting us
the range of stakeholders: a natural person who contacts the controller by any means (in particular: by filling in the contact form via the website or by telephone, e-mail or post)
the purpose of the processing: providing information to the person who contacts the data controller, answering questions about services and products, providing assistance in using the website
the legal basis for the processing: the data subject's consent in accordance with Article 6(1)(a) of the GDPR);
the scope of the data processed: full name, e-mail address, telephone number, location of installation or any other personal data provided by the data subject to the controller during the contact
the duration of the processing: for a maximum of 6 months after the case that is the subject of the contact
the recipients of the personal data and the categories of recipients:
- senior management of the controller
- employees of the controller
- depending on the nature of the case, the data processors
The data controller informs the data subject that the provision of personal data as described in this point is entirely voluntary and the data subject is not obliged to provide personal data when contacting the data controller. In the event of non-supply, the controller can only comply with the data subject's requests insofar as they do not require identification.
4.2. Data processing in connection with the sale of products
the range of stakeholders: natural persons who indicate their intention to purchase or conclude a contract for a product
the purpose of the processing: sale of products, conclusion of contracts, performance of contracts
the legal basis for the processing: processing is necessary for the performance of a contract to which the data subject is a party or for the purposes of taking steps at the request of the data subject prior to entering into a contract, pursuant to Article 6(1)(b) of the GDPR; and
the scope of the data processed: full name, e-mail address, telephone number, billing address, shipping address, tax identification number/tax number and other information voluntarily provided by the data subject during the ordering process to facilitate the performance of the contract
the duration of the processing: for 5 years after the conclusion of the contract in accordance with the provisions of the Civil Code on limitation ( Civil Code § 6:21 - § 6:25 )
the recipients of the personal data and the categories of recipients:
- senior management of the controller
- employees of the controller
- depending on the nature of the case, the data processors
The data controller informs the data subjects that the provision of the personal data described in this point is a prerequisite for the conclusion of a contract, and the data subject is obliged to provide them if he or she wishes to make a purchase. In case of failure to provide the data, the data subject cannot conclude a contract / purchase a product.
4.3. Mandatory data processing under the Accounting Act
the range of stakeholders: natural persons to whom the controller issues an invoice
the purpose of the processing: ensure compliance with the obligations of the controller under accounting law (the controller must keep accounting records that directly and indirectly support the accounting accounts)
the legal basis for the processing: processing is necessary for compliance with a legal obligation to which the controller is subject (Article 6(1)(c) GDPR), the law establishing the obligation: Act C of 2000 on the Accounting Act, § 169 (2) )
the scope of the data processed: full name, billing address, other additional information ( e.g. names of several persons concerned )
the duration of the processing: for 8 years after purchase
the recipients of the personal data and the categories of recipients:
- senior management of the controller
- employees of the controller
- depending on the nature of the case, the data processors
The data controller informs the data subject that the provision of personal data described in this point is based on law and that the data subject is obliged to provide it. In the event of failure to provide the data, the controller is not in a position to issue an invoice.
4.4. Use of cookies
The controller informs the data subject that the website https://www.cardempire.hu/ does not collect or process cookies containing personal data.
Any cookies necessary for the functioning of the website, which do not contain personal data, are processed on the computer of the user concerned, so that the user can decide at any time whether to allow or prohibit their use when browsing the website. The information content of the cookies is automatically read by the website during repeated visits to the website, so that the data controller does not have access to this information.
4.5. Handling complaints
the range of stakeholders: natural persons who wish to lodge a complaint under the Consumer Protection Act
the purpose of the processing: the handling of quality complaints that may arise in relation to the services provided by the controller
the legal basis for the processing: the processing is necessary for compliance with a legal obligation to which the controller is subject (Article 6(1)(c) GDPR); law establishing the obligation: § 17/A - § 17/C of Act CLV of 1997 on Consumer Protection
the scope of the data processed: the name and address of the consumer, the place, time and manner in which the complaint was lodged, a detailed description of the consumer's complaint, a list of the documents, records and other evidence produced by the consumer, a statement by the undertaking of its position on the consumer's complaint, where an immediate investigation of the complaint is possible, the signature of the person who took the record and, except in the case of an oral complaint by telephone or other electronic communications service, the consumer, the place and time of the taking of the record, and, in the case of an oral complaint by telephone or other electronic communications service, the unique identification number of the complaint; in the case of a complaint made orally (by telephone), the audio recording of the telephone conversation, if any.
the duration of the processing: 5 years after the minutes have been drawn up
the recipients of the personal data and the categories of recipients:
- senior management of the controller
- employees of the controller
- depending on the nature of the case, the data processors
The data controller informs the data subject that the provision of personal data described in this point is based on law, and the data subject is obliged to provide them in order to register a complaint or to follow the complaint handling procedure. Failure to provide the data shall render the controller unable to act on the complaint.
- Data subjects' rights in relation to data processing (Articles 15-22 GDPR)
5.1 Right to withdraw consent:
If the data subject has given his or her consent to the processing of his or her personal data, he or she may withdraw his or her consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent prior to withdrawal, and does not affect the lawfulness of ongoing data processing for other purposes (e.g. to comply with a legal obligation imposed on the controller).
5.2 Right of access (information):
The data subject shall have the right to obtain from the controller feedback as to whether or not his or her personal data are being processed and, if such processing is taking place, to be informed of the following:
- the purposes and legal basis of the processing;
- the data processed the categories of personal data and the personal data themselves;
- the recipients of the personal data and the categories of recipients;
- the duration of the processing;
- information on the rights of the data subject;
The controller may link the provision of information to the identification of the data subject., can meet the data subject's request if the data subject the request for information has been sent to the controller electronically by post, on paper, and the data contained in the request are sufficient to identify the data subject of the applicant, and if the telephone contact is successful in identifying the applicant.
In the event that the identification fails due to the incompleteness or inaccuracy of the data recorded in the request for information, the controller cannot provide the information on the processing of personal data.
This is because if the Data Controller is unable to without a doubt identify the person who made the request, cannot completely exclude the risk that personal data or, where applicable, sensitive data (in particular with regard to the nature and scope of the processing) may be disclosed to a third party who is not entitled to know them.
We can therefore only provide full information after the data subject has:
- the information has been requested by the controller on a personal, or if you contact us by e-mail, post or telephone identification was possible and successful,
- requests the information in person and at the same time provides credible proof of identity,
- submit your application through your legal representative ( in this case, your legal representative will carry out the identification in accordance with the provisions of Act LIII of 2017 on the Prevention and Combating of Money Laundering and Terrorist Financing ),
- sends your request electronically, and the document has been electronically signed.
A copy of your personal data will be sent to you by post or, upon your explicit request, electronically after informing you of the risks involved.
Pursuant to Article 12(5) of the Data Protection Regulation, where the data subject's request is manifestly unfounded or excessive, in particular because of its repetitive nature, the controller may, taking into account the administrative costs entailed in providing the information or information requested or in taking the action requested, charge a reasonable fee or refuse to act on the request.
5.3 Right to rectification:
The data subject shall have the right to obtain from the controller, at his or her request and without undue delay, the rectification or correction of inaccurate data or the completion of incomplete data.
5.4 Right to erasure:
The data subject may request the controller to erase personal data stored about him or her without undue delay where:
- the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
- the data subject withdraws his or her consent and there is no other legal basis for the processing;
- the data subject objects to the processing and there is no overriding legitimate ground for the processing or the data subject objects to processing of personal data for direct marketing purposes;
- the personal data have been unlawfully processed;
- the personal data must be erased in order to comply with a legal obligation under Union or Member State law to which the controller is subject;
- personal data were collected in connection with the processing of personal data in relation to information society services offered directly to children.
5.5 Right to restriction of processing:
The data subject shall have the right to obtain, at his or her request, restriction of processing by the controller if:
- contests the accuracy of the personal data ( in which case the restriction will last for the time necessary to verify the accuracy of the personal data );
- the processing is unlawful, but the data subject requests the restriction of the use of the data instead of their erasure;
- the controller no longer needs the personal data for the purposes of processing, but the data subject requires them for the establishment, exercise or defence of legal claims; or
- objected to the processing ( in this case, the restriction applies for the period until it is established whether the legitimate grounds of the controller prevail over those of the data subject )
The controller shall inform the data subject at whose request the processing has been restricted of the lifting of the restriction in advance.
5.6. Data portability:
The data subject shall have the right to receive personal data relating to him or her which are made available to the controller in a structured, commonly used, machine-readable format, provided that:
- the processing is based on the data subject's consent or on a contract within the meaning of Article 6(1)(b) of the GDPR; and
- the processing is carried out by automated means.
In exercising the right to data portability under this paragraph, the data subject shall have the right to request, where technically feasible, the direct transfer of personal data between controllers.
5.7 Objection to the processing of personal data:
The data subject shall have the right to object at any time on grounds relating to his or her particular situation, provided that the legal basis for the processing is:
- processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where those interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, in particular where the data subject is a child;
- profiling
The controller may no longer process personal data where the data subject objects, unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.
Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to the processing of personal data concerning him or her for such purposes, including profiling, where it is related to direct marketing. In such a case, the personal data may no longer be processed for that purpose.
Where personal data are processed for scientific or historical research purposes or statistical purposes pursuant to Article 89(1) of the GDPR, the data subject shall have the right to object, on grounds relating to his or her particular situation, to processing of personal data concerning him or her, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
5.8. Possibility to complain
Legal remedies and complaints can be lodged with the National Authority for Data Protection and Freedom of Information:
National Authority for Data Protection and Freedom of Information
Seat: 1055 Budapest, Falk Miksa utca 9-11.
Mailing address: 1363 Budapest, Pf.: 9.
Telephone: +36 (30) 683-5969
+36 (30) 549-6838
+36 (1) 391 1400
E-mail: ugyfelszolgalat@naih.hu
Website: http://www.naih.hu
5.9. Judicial enforcement
Every data subject shall have an effective judicial remedy if he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data not in accordance with this Regulation. Proceedings against the controller shall be brought before the courts of the Member State where the controller has its place of business or the Member State where the data subject has his or her habitual residence, according to the choice of the data subject.
- Data protection incident:
In the event of a personal data breach, the controller shall notify the competent supervisory authority without undue delay and, where possible, no later than 72 hours after becoming aware of the personal data breach, unless the personal data breach is unlikely to pose a risk to the rights and freedoms of natural persons.
The processor shall notify the controller of the personal data breach without undue delay after becoming aware of it.
The controller in the notification:
- describe the nature of the personal data breach, including, where possible, the categories and approximate number of data subjects and the categories and approximate number of data subjects affected by the breach;
- provide the name and contact details of the contact person;
- describes the likely consequences of a data breach;
- describe the measures taken or envisaged by the controller to remedy the personal data breach, including, where appropriate, measures to mitigate any adverse consequences of the personal data breach.
The data controller shall keep a record of the data breaches to demonstrate compliance with the Data Protection Regulation, indicating the facts relating to the data breach, its effects and the measures taken to remedy it.
Where the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall inform the data subject without undue delay of the personal data breach, the name and contact details of the contact person, the likely consequences of the personal data breach and, finally, of the measures taken or envisaged by the controller to remedy the personal data breach, including, where appropriate, measures to mitigate any adverse consequences of the personal data breach.
- Data security:
The controller shall implement appropriate technical and organisational measures and put in place the necessary safeguards to protect the rights of data subjects under the data protection principles when determining the means of processing and during processing, taking into account the state of the art and the cost of implementation, and the nature, scope, context and purposes of the processing (data protection by design and by default).
Where the processing is carried out using an IT system, the data controller shall grant access to its IT systems only to persons who have an employment or agency relationship with the data controller.
In order to ensure a high level of data security, the data controller shall establish separate levels of access rights, which shall be assigned to each user only to the extent and for the duration necessary for the performance of his or her duties (or as specified in the contract of engagement).
All employees of the data controller (including persons working under a contract of employment) are bound by strict confidentiality rules when they enter into an employment relationship and must act in accordance with these confidentiality rules in the course of their work.
If the processing is not carried out by means of an IT system (paper-based processing), the documents generated during the processing operation shall not be left unattended by the person carrying out the processing and shall be locked up after the operation is completed.
The data controller operates various systems (e.g. alarms, cameras, fire protection systems, etc.) to protect the premises it uses and thus the data processed and stored there.
The controller stores the data on its own or leased servers. The data controller shall make (have made) backups of the databases containing the processed data in order to protect them from destruction, loss, damage or unlawful destruction due to the failure of the IT equipment.
- Final provisions:
This information has been prepared on the basis of the legislation in force and the available opinions issued by the Supervisory Authority. In the event of a change in the legal environment in force at the time of the preparation of this notice, or in the event of a significant change in the applicable case law, the controller may revise and amend the contents of this notice.
If you have any questions about the processing of your data or your rights, you can contact the data controller.
Annex I - Definitions:
involved: any natural person who is identified or can be identified, directly or indirectly, on the basis of personal data, such as name, address, place of birth, time stamp, etc.
personal data: any information relating to an identified or identifiable natural person ('data subject'); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person
data controller: the natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of the processing are determined by Union or Member State law, the controller or the specific criteria for the controller's designation may also be determined by Union or Member State law;
data processor: a natural or legal person, public authority, agency or any other body which processes personal data on behalf of the controller;
data management: any operation or set of operations which is performed upon personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
data transmission: making the data available to a specified third party; that is, to any person other than the data subject and the controller
data deletion: an operation that renders data unrecognizable in such a way that its recovery is no longer possible;
data destruction: the complete physical destruction of the medium containing the data
the data subject's consent: a freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she signifies, by a statement or by an act expressing his or her unambiguous consent, that he or she signifies his or her agreement to the processing of personal data concerning him or her;
disclosure: making the data available to anyone;
special data: personal data revealing racial or ethnic origin, nationality, political opinions or opinions, religious or philosophical beliefs, membership of an interest group, sex life, health, pathological or mental disorder and personal data concerning criminal offences;
privacy incidents: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;
addressed to: the natural or legal person, public authority, agency or any other body with whom or to which the personal data are disclosed, whether or not a third party;
third party: a natural or legal person, public authority, agency or any other body other than the data subject, the controller, the processor or the persons who, under the direct authority of the controller or processor, are authorised to process the personal data;
supervisory authority: an independent public authority established by a Member State in accordance with Article 51;
a document of permanent value: a document containing data of economic, social, political, legal, defence, national security, scientific, cultural, technical or other significance, which is indispensable for research, knowledge and understanding of the historical past, for the continuous performance of public duties and for the exercise of citizens' rights, and which cannot be obtained from other sources or only partially;
Annex II - Data processors
The controller may transfer the data provided to it to one of its contracted processors for the performance of various subtasks. The data controller shall have the exclusive right to determine the coordination, the professional and quality control of each sub-process, and thus the method and means of data processing.
A processor or a person acting under his or her authority who has access to personal data may process those data only in accordance with the controller's instructions, unless he or she is required to do otherwise by Union or Member State law. The controller declares that its processors provide adequate safeguards to implement appropriate technical and organisational measures to ensure compliance of the processing with the requirements of the GDPR and to protect the rights of data subjects.
All processors are bound by a contract with the controller - or by a mandatory legal provision - to maintain strict confidentiality with regard to all personal data transferred to them.
1. Accounting tasks:
name / company name: Gódor Ágnes
email address: agnes.godor@gmail.com
2. Legal tasks:
name: dr. András Zimányi lawyer
headquarters: 9200 Mosonmagyaróvár, Kolbai Károly u. 2.
email address: dr.zimanyi.andras@gmail.com
Pursuant to Act LXXVIII of 2017 on the Activities of Lawyers, the data processor is bound by a strict confidentiality obligation with regard to all personal data disclosed.
3. Repository
name / company name: WebSupport s. r. o.
address / registered office: Karadžičova 12, 821 08 Bratislava
email address: helpdesk@websupport.sk
4. Online card payments
Company Name: Shoptet Kft.
Service: Shoptet Pay
Data Processing Activity: Processing online card payments and facilitating payment transactions.
https://www.shoptetpay.com/hu/
