DATA PROCESSING INFORMATION
FOR PURCHASES MADE ON THE WEBSHOP
The Data Controller provides the following information on the processing of personal data of natural persons in connection with purchases made on the webshop, based on Regulation (EU) 2016/679 of the European Parliament and of the Council (April 27, 2016) and the relevant national legislation.
The webshop deals with the sale of alcoholic products. According to Section 16/A of Act CLV of 1997 on Consumer Protection, the sale of alcoholic beverages to persons under the age of eighteen is prohibited. In view of the above, we draw the attention of the Data Subjects that if they have not reached the age of 18, they are not entitled to use the webshop!
1. Data Controller
Name: Etyeki Kúria Kft.
Address: 2091 Etyek, Báthori utca 21.
E-mail: webshop@etyekikuria.com
Data Controller’s representative: László Babarczi
Data Controller’s contact information regarding data protection: etyek@etyekikuria.com
Definitions:
“personal data”: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person;
“data processing”: any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction;
“data controller”: a natural or legal person, public authority, agency, or any other body that alone or jointly with others determines the purposes and means of processing personal data; if the purposes and means of processing are determined by Union or Member State law, the data controller or the specific criteria for its designation may also be laid down by Union or Member State law;
“data processor”: a natural or legal person, public authority, agency, or any other body that processes personal data on behalf of the data controller;
“recipient”: a natural or legal person, public authority, agency, or any other body to whom or to which the personal data are disclosed, regardless of whether they are a third party. Public authorities that may access personal data in the context of a specific inquiry in accordance with EU or Member State law are not considered recipients; the processing of such data by these public authorities must comply with the applicable data protection rules in line with the purposes of the data processing;
“consent of the data subject”: the data subject's voluntary, specific, informed, and unambiguous indication of their will by statement or clear affirmative action, by which the data subject signifies agreement to the processing of personal data relating to them;
third country: any state that is not an EEA state.
2. Purpose of data processing
2.1 In connection with the conclusion and performance of the contract
Identification of the Data Subject, distinguishing them from other customers, users, or inquirers,
Facilitation of purchases made in the webshop,
Creation, definition, modification, fulfillment, and monitoring of the contract,
Collection of the product price, enforcement of the Data Controller's contractual claims,
Fulfillment of the Data Controller's invoicing, tax, and accounting obligations,
Sending confirmations related to the service, sending system message(s),
Correspondence, notifications, and legal declarations related to performance,
Sending notifications related to product delivery,
Identification of the discount beneficiary, verification of the conditions for the discount, enforcement of the discount by the Data Subject,
Fulfillment of obligations imposed on the Data Controller, exercise of rights entitled to them,
Enforcement and protection of the Data Controller's rights and claims;
Complaint handling, investigation of warranty and product liability claims, legal protection against claims arising from these.
2.2. Marketing-related data processing
(especially: contact management, measuring customer satisfaction, survey inquiries for service development, database creation, direct business acquisition or marketing inquiries with advertising content about new or renewed services, event invitations, preparing analyses and statistics, service development)
2.3. In case of camera surveillance
Security of the Data Controller's premises,
Protection of the Data Controller's assets, protection of the physical safety and assets of its employees and visitors,
Prevention, investigation, and proof of circumstances of possible accidents, crimes, and violations of the law
3. Scope of processed data:
The data processed by the Company can be categorized into the following groups based on the purpose of data processing:
3.1. Data necessary for contract conclusion: Data Subject's last name, first name, address, phone number, email address, method of product receipt, payment-related data (in particular: payment method, payment instrument, bank account number, discount-related data), data related to the ordered product, product delivery address, and any data related to complaints.
3.2. Data necessary for contract performance:
3.2.1. Delivery data: Customer's name, phone number, email address, method of product receipt, payment method, product type, quantity, product price (purchase price and shipping fees and costs combined), delivery address, recipient identification (presentation of ID), recipient's name, signature, and any data related to complaints.
3.2.2. Data related to invoice issuance: within the framework of contract performance, the Company processes data related to payment and invoicing. This includes in particular the invoice content (Customer's name, address, invoice date, date of performance, order identifier, type, quantity, price of the ordered product, shipping fee, due date, discount-related data).
3.2.3. Data processing related to invoice settlement: payment method, payment instrument, bank account number, credit card payment details.
3.3. Marketing communications: The Data Controller processes the name and email address of the Data Subject for marketing communication purposes. The legal basis for data processing is the Data Subject's consent, and the primary purpose is marketing contact, information, newsletters, or sending direct communications pursuant to Section 6(1) of Act XLVIII of 2008.
3.4. Data from camera surveillance: the Data Controller conducts camera surveillance in its Wine Bar, capturing images and silent video recordings of natural persons.
4. Legal basis for data processing
4.1. Data processing necessary for the conclusion and performance of the contract involves processing the data specified in points 3.1 and 3.2.1 according to Article 6(1)(b) of the GDPR: data processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at the request of the data subject prior to entering into a contract. Providing data is a condition for the conclusion and performance of the contract. If data is not provided, the Data Controller cannot fulfill the ordered service.
4.2. Data processing necessary for the legitimate interests of the data controller or a third party involves processing the data specified in points 3.1, 3.2.1, and 3.2.3 according to Article 6(1)(f) of the GDPR. The data controller and the transport service provider it uses have a legitimate interest in enforcing claims against the Customer (especially purchase price, delivery fee, compensation), investigating customer complaints, product and warranty claims, consumer disputes, proving contractual performance, obtaining legal protection against claims, enforcing claims arising from the above, preventing credit card fraud, and settling accounts with the credit card service provider.
4.3. Data processing necessary for the legitimate interests of the data controller or a third party involves processing the data specified in point 3.4 according to Article 6(1)(f) of the GDPR. The data controller and those present on the Data Controller’s premises have a legitimate interest in ensuring personal and property security, preventing, and proving violations, accidents, offenses, and crimes.
4.3. Legal obligation applicable to the Data Controller (tax and accounting obligations) requires the processing of data related to invoicing and payment as specified in point 3.2.2, according to Article 6(1)(c) of the GDPR.
4.4. Consent of the Data Subject is the basis for processing the data specified in point 3.3 for marketing purposes, according to Article 6(1)(a) of the GDPR: the data subject has given consent to the processing of their personal data for one or more specific purposes. The data subject has the right to withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
The Data Controller does not perform profiling.
5. Duration of data processing
The Data Controller processes the Data Subject's data for the following period:
Billing data and documents to be retained according to the Accounting Act, especially accounting vouchers directly and indirectly supporting bookkeeping (including general ledger accounts, analytical, and detailed records) for 8 years (Accounting Act 169. § (1)-(3) paragraphs).
Personal data specified in the Taxation Act (Art.), such as performance certificates, for 5 years from the last day of the calendar year in which the tax is due (Art.78. § (3)-(4) paragraphs).
Data necessary for the creation and fulfillment of the contract with the data subject (data according to Chapter 3, points a) and b)) until the statute of limitations for warranty and product liability claims.
In the case of data processing based on consent: until the withdrawal of consent, but at most for the duration specified in the consent.
In the case of data processing based on legitimate interest: until the Data Subject objects (if the interests or fundamental rights and freedoms of the data subject take precedence over the interests of the Data Controller), but at most until the statute of limitations for claims related to data processing based on legitimate interest.
In the case of camera recordings, for a maximum of 3.5 months following the recording.
6. Information on the use of data processors, persons authorized to transfer data
The data controller does not transfer the personal data of the Data Subjects to third countries or international organizations.
During data processing, the data controller transfers data to contracted data processor(s) necessary for contract fulfillment: the company delivering the product, IT operators, web hosting providers, web content developers, accounting service providers, internet payment service providers.
The data controller uses the Google Analytics service to track site statistics and user demographic data, interests, and behavior on websites. The Organization also uses Google Search Console for website search engine optimization and measuring user satisfaction. Google provides an option to limit the use of analytics services. Visit Google's site to unsubscribe from data usage by Google Analytics.
https://tools.google.com/dlpage/gaoptout
7. The circle of persons authorized to access the data
The recorded data may only be accessed by the data controller's employees and the designated employees of the data processor(s). The data controller will not transfer the accessed data to any third party except for the data processor(s) specified in point 6.
Camera recordings may only be accessed by the data controller, designated employees of the data controller and data processor(s), and the data subject. The IT operator and the authorized executives of the Data Controller company may access recordings made by the electronic surveillance system. The Data Subject may access recordings made exclusively about themselves in the presence of one of the aforementioned persons upon request. Access must always be requested in writing. The data subject is obliged to prove their data subject status and identity to the Data Controller.
8. Common rules for exercising data subject rights, rights of the data subjects
8.1. Common rules for exercising data subject rights
The data controller facilitates the exercise of the data subject's rights under Articles 15–22 of the GDPR. The data controller may not refuse to comply with a request to exercise data subject rights unless it proves that it is unable to identify the data subject.
To fulfill the request, the Data Controller is obliged to verify the data subject status and identity of the requester.
The management shall inform the data subject in writing, in an understandable form, without undue delay but within one month of receipt of the request, about the measures taken in response to the request. If necessary, taking into account the complexity of the request and the number of requests, this deadline may be extended by a further two months. The data controller shall inform the data subject of the extension within one month of receipt of the request, stating the reasons for the delay. If the data subject submitted the request electronically, the information shall be provided electronically where possible, unless the data subject requests otherwise.
If the data controller has reasonable doubts about the identity of the person exercising the data subject's rights, it may request additional information necessary to confirm the identity of the data subject.
If the data subject's request is clearly unfounded or excessive, particularly because of its repetitive nature, the data controller, taking into account the administrative costs of providing the requested information or taking the requested action:
a) may charge a reasonable fee, or
b) may refuse to take action based on the request. The refusal must be justified.
The Data Controller may also refuse to comply with the request if it proves that it is unable to identify the data subject.
8.2. Rights of the data subjects
8.2.1. The data subject's right of access
The data subject has the right to receive feedback from the data controller on whether the processing of their personal data is ongoing, and if such processing is ongoing, they have the right to access the information pursuant to Article 15 of the GDPR.
8.2.2. The right to rectification
The data subject has the right to request that the Data Controller rectify inaccurate personal data concerning them without undue delay. Taking into account the purposes of the processing, the data subject has the right to request the completion of incomplete personal data – including by means of a supplementary statement.
8.2.3. The right to erasure ("the right to be forgotten")
The data subject has the right to request that the controller erase personal data concerning them without undue delay, and the controller is obliged to erase personal data concerning the data subject without undue delay if
a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
b) the data subject withdraws consent on which the processing is based and there is no other legal ground for the processing;
c) the data subject objects to processing for direct marketing purposes or objects to processing and there are no overriding legitimate grounds for the processing;
d) the personal data have been unlawfully processed;
e) the personal data must be erased for compliance with a legal obligation under Union or Member State law to which the controller is subject;
f) for the offer of information society services directly to a child;
The right to erasure shall not apply if processing is necessary
a) for the exercise of the right of freedom of expression and information;
b) for compliance with a legal obligation to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
c) on grounds of public interest in the area of public health;
d) for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, insofar as the right to erasure is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
e) for the establishment, exercise, or defense of legal claims.
8.2.4. The right to restriction of processing
The data subject has the right to request that the Data Controller restricts data processing if any of the following conditions are met:
a) the data subject disputes the accuracy of the personal data; in this case, the restriction applies for the period that allows the Data Controller to verify the accuracy of the personal data;
b) the processing is unlawful, and the data subject opposes the deletion of the data and instead requests the restriction of their use;
c) the controller no longer needs the personal data for processing purposes, but the data subject requires them for the establishment, exercise, or defense of legal claims,
d) the data subject has objected to the processing based on legitimate interests.
8.2.5. Right to data portability
The data subject has the right to receive the personal data concerning them, which they have provided to a data controller, in a structured, commonly used, and machine-readable format, and has the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, if
a) the processing is based on consent or contract; and
b) the processing is carried out by automated means.
8.2.6. Right to object
The data subject has the right to object at any time, for reasons related to their particular situation, to the processing of their personal data based on Article 6(1)(f). In this case, the data controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the data subject or for the establishment, exercise, or defense of legal claims.
8.2.7. Right to lodge a complaint, judicial remedy
The data subject has the right to lodge a complaint with a supervisory authority – particularly in the member state of their habitual residence, place of work, or the place of the alleged infringement – if the data subject considers that the processing of their personal data infringes the GDPR or to seek judicial remedy.
Contact details of the supervisory authority:
National Authority for Data Protection and Freedom of Information
Postal address: 1530 Budapest, P.O. Box 5.
Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
Phone: +36 (1) 391-1400
Fax: +36 (1) 391-1410
E-mail: ugyfelszolgalat@naih.hu
URL: https://naih.hu
Cookie management
To provide you with the best possible experience, we use "cookies" on our website. If you wish, you can change these settings at any time. Please note that if you change the "cookie" settings, we can no longer guarantee the proper functioning of our website. Some functions of the website may be lost, and subpages may become inaccessible.
