Special promotions are available! Don't miss out on great deals!

Privacy Policy

On the processing of personal data in connection with the operation of the Lincos webshop (lincos.shop)

Introduction

NeoLincos Zrt. (NeoLincos Hungary Private Limited Company; registered seat: 2142 Nagytarcsa, Csabai út 1252 hrsz., Hungary; hereinafter: the Service Provider, the Controller) is committed to protecting the personal data of its customers and visitors to its website, and considers respect for the right to informational self-determination to be of particular importance. NeoLincos Zrt. treats personal data confidentially and takes all security, technical and organisational measures necessary to ensure the security of the data.

The purpose of this notice is to inform data subjects of all facts relating to the processing of their personal data before they make use of the service, and to ensure that processing is carried out in accordance with the principles set out in this notice.

This notice governs processing carried out through the webshop available on the lincos.shop domain and all of its subdomains (hereinafter: the Webshop). Amendments to this notice take effect upon publication at the above address.

1. Identity of the controller

Name
NeoLincos Zrt.
Registered seat
2142 Nagytarcsa, Csabai út 1252 hrsz., Hungary
E-mail
[email protected]
Telephone
+36 70 608 1461

With regard to the processing operations described in this notice, the Service Provider is not obliged to designate a data protection officer under Article 37 GDPR, because its core activities do not consist of regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special categories of data. If the Service Provider designates a data protection officer in the future, its contact details will be published by way of a supplement to this notice.

2. Definitions

The terms used in this notice shall be interpreted in accordance with Article 4 GDPR. The most important of these are as follows:

“personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data or an online identifier;

“processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means (collection, recording, organisation, storage, use, erasure, etc.);

“controller” means the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data;

“processor” means a natural or legal person which processes personal data on behalf of the controller;

“recipient” means a natural or legal person to which the personal data are disclosed, whether a third party or not;

“consent of the data subject” means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;

“personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

3. Legal bases and principles of processing

Processing is governed primarily, but not exclusively, by the following legislation:

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, hereinafter: GDPR);

Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (hereinafter: Infotv.);

Act CVIII of 2001 on certain issues of electronic commerce services and information society services (hereinafter: Ektv.);

Act CLV of 1997 on Consumer Protection (hereinafter: Fgy.tv.);

Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities (hereinafter: Grtv.);

Act XLVII of 2008 on the Prohibition of Unfair Commercial Practices against Consumers (Fttv.);

Act CXXVII of 2007 on Value Added Tax (hereinafter: VAT Act / Áfa tv.), in particular the provisions on the issuance of invoices and their mandatory content;

Act C of 2000 on Accounting;

Act V of 2013 on the Civil Code (hereinafter: Ptk.)

In processing personal data, the Service Provider acts in accordance with the principles set out in Article 5 GDPR (lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality), and is responsible for, and able to demonstrate, compliance with those principles (accountability).

4. Processing in connection with the operation of the Webshop (registration and purchase)

4.1. Categories of data processed and purposes of processing

Personal dataPurpose of processing
Surname and first nameNecessary for contact, for the purchase and for the lawful issuance of invoices.
PasswordSecure access to the user account.
E-mail addressCommunication. It need not contain personal data.
Telephone numberCommunication; more efficient coordination of billing and delivery-related questions.
Billing name and address (and, in the case of a company, tax number)Lawful issuance of invoices; conclusion of the contract, determination and amendment of its content, monitoring of performance, invoicing of related charges, and enforcement of related claims.
Delivery name and addressEnabling home delivery of the ordered product.
Date and time of purchase/registrationPerformance of a technical operation.
IP address recorded at purchase/registrationPerformance of a technical operation; ensuring the IT security of the system.

4.2. Categories of data subjects

All data subjects who register or make a purchase in the Webshop.

4.3. Legal basis for processing

  • with regard to data provided during registration of a user account: the data subject’s consent [Article 6(1)(a) GDPR] and performance of a contract [Article 6(1)(b) GDPR];
  • with regard to conclusion of the contract (sale), determination and amendment of its content, monitoring of performance, and invoicing of related charges: Article 6(1)(b) GDPR;
  • with regard to the issuance of accounting documents: Article 6(1)(c) GDPR, in conjunction with Section 169(2) of Act C of 2000 on Accounting;
  • with regard to data that are technically indispensable for the provision of the service (e.g. IP address): Section 13/A(3) Ektv. and the legitimate interest under Article 6(1)(f) GDPR (ensuring the security of the system).

4.4. Duration of processing

Upon deletion of the registration, the Service Provider shall erase without delay the data relating to the user account. The Service Provider shall inform the data subject by electronic means of the erasure of any personal data provided by the data subject, in accordance with Article 19 GDPR.

Accounting documents that directly or indirectly support bookkeeping entries (including general ledger accounts and analytical and detailed records) shall be retained by the Service Provider in a readable and searchable form for at least 8 years pursuant to Section 169(2) of Act C of 2000 on Accounting. Data processed for the purpose of enforcing claims arising from the contract shall be processed by the Service Provider within the general 5-year limitation period under Section 6:22 of the Civil Code (Ptk.).

4.5. Information on the nature of the provision of data

  • processing is necessary for the performance of the contract;
  • the data subject is required to provide the personal data in order for the Service Provider to fulfil the order;
  • the consequence of failing to provide the data is that the Service Provider is unable to process the order.

4.6. Loyalty and price-category programme

The Service Provider operates a loyalty and price-discount programme for registered users. In that context, the Service Provider processes data relating to purchases that are necessary for the operation of the programme (in particular the fact and time of purchases and activity calculated under the programme rules) in order to assign the data subject to the appropriate discounted price category and to apply the corresponding prices in the Webshop.

Categories of data subjects: users registered in the Webshop who participate in the loyalty and price-discount programme.

Legal basis for processing: Article 6(1)(b) GDPR (conclusion and performance of the contract) and — with regard to the application of the programme rules and the prevention of abuse — the legitimate interest under Article 6(1)(f) GDPR.

Duration of processing: for the duration of the user account, or for as long as necessary to maintain the classification under the programme rules; for data relating to accounting documents, the retention periods set out in Section 4.4 apply.

Information on automated decision-making related to classification is set out in Section 14.9.

5. Processors engaged

The Service Provider engages processors for the activities indicated in this section. As the identity of processors may change from time to time in line with the Service Provider’s business, logistics and IT needs, this notice — in accordance with Article 13(1)(e) and Article 14(1)(e) GDPR, which also permit recipients to be indicated by categories — describes processors by category of activity rather than by individual name.

The current list of processors by name and contact details shall be made available by the Service Provider free of charge upon the data subject’s request via the contact details set out in Section 1. A change in the identity of a processor — where the categories and safeguards set out in this section remain unchanged — does not require amendment of this notice.

5.1. Delivery and courier services

Processing activity: delivery of ordered products, carriage, parcel-point or postal delivery.

Category of processors: economic operators providing parcel, courier, parcel-point and postal services in Hungary and, where necessary, in the European Economic Area, with which the Service Provider maintains a contractual processor relationship in line with its delivery needs from time to time.

Categories of data processed: delivery name, delivery address, telephone number, e-mail address.

Categories of data subjects: all data subjects who use home delivery (or collection at a parcel point/post office).

Purpose of processing: delivery of the ordered product, or enabling its collection.

Duration of processing: until completion of the delivery/hand-over.

Legal basis for processing: Article 6(1)(b) GDPR.

5.2. Hosting and IT operations

Processing activity: operation, storage and security of the Webshop website, IT systems and data stored thereon.

Category of processors: economic operators providing hosting, server operation or IT system operation services, with which the Service Provider maintains a contractual processor relationship.

Categories of data processed: all personal data provided by the data subject.

Categories of data subjects: all data subjects who use the website.

Purpose of processing: making the website available and ensuring its proper and secure operation.

Duration of processing: until termination of the agreement between the Service Provider and the relevant processor, or until the data subject’s erasure request.

Legal basis for processing: Article 6(1)(c) and (f) GDPR, and Section 13/A(3) Ektv.

5.3. Invoicing

Processing activity: provision and operation of electronic invoicing software/services, including related hosting and IT background services.

Category of processors: economic operators providing invoicing software and related IT operation (hosting) services, with which the Service Provider maintains a contractual processor relationship.

Categories of data processed: data necessary for issuing the invoice (in particular: billing name and address, itemised purchase data).

Categories of data subjects: data subjects for whom the Service Provider issues an invoice on the basis of a purchase in the Webshop.

Purpose of processing: issuance of invoices in accordance with statutory requirements on invoice issuance and mandatory content (invoice particulars).

Duration of processing: at least 8 years pursuant to Section 169(2) of Act C of 2000 on Accounting.

Legal basis for processing: Article 6(1)(c) GDPR, having regard to the provisions of Act CXXVII of 2007 on Value Added Tax (hereinafter: VAT Act / Áfa tv.) on the obligation to issue invoices and on the mandatory content of invoices (in particular Sections 159 and 169 of the VAT Act / Áfa tv.), as well as Act C of 2000 on Accounting.

We inform data subjects that, since the repeal of Section 17(2) of Government Decree 210/2009 (IX. 29.) on the conditions for pursuing commercial activities, webshops are no longer required to register in a data protection register; accordingly, this notice does not contain a data protection registration number.

5.4. Bookkeeping

Processing activity: performance of bookkeeping and accounting tasks related to the Service Provider’s operation of the Webshop.

Category of processors: economic operators or sole traders providing bookkeeping and accounting services, with which/whom the Service Provider maintains a contractual processor relationship.

Categories of data processed: data of invoices issued to Webshop customers (in particular billing name and address, itemised purchase data), as well as data relating to payments received from those customers (to the extent necessary to identify the payment and reconcile it with the invoices).

Categories of data subjects: customers of the Service Provider who purchase in the Webshop, hold an invoice, or make a payment.

Purpose of processing: bookkeeping records and reconciliation of invoices issued to customers and of related customer payments; fulfilment of the Service Provider’s accounting and tax law obligations.

Duration of processing: the retention period under Section 169(2) of Act C of 2000 on Accounting, which is at least 8 years.

Legal basis for processing: Article 6(1)(c) GDPR.

6. Recipients to whom personal data are disclosed (transfers)

6.1. Online payment

Activity performed by the Recipient: processing of online payments.

Identity and contact details of the Recipient: PayPal (Europe) S.à.r.l. et Cie, S.C.A., 22-24 Boulevard Royal, L-2449 Luxembourg, [email protected].

Categories of data processed: billing data, name, e-mail address. Categories of data subjects: all data subjects who choose online payment on the website. Purpose of processing: processing the online payment, confirming transactions, and fraud monitoring carried out to protect users. Duration: until completion of the online payment. Legal basis: Article 6(1)(b) GDPR, as processing is necessary for the performance of the payment at the data subject’s request.

In connection with this processing, the data subject is entitled to obtain information about the circumstances of processing, to receive confirmation as to whether or not personal data concerning him or her are being processed, to receive the data in a structured, commonly used and machine-readable format, and to request the rectification of inaccurate data without undue delay.

6.2. Statutory audit

Where the Service Provider is subject to a statutory audit under Section 155 of Act C of 2000 on Accounting, the Service Provider’s annual financial statements are examined by an independent auditor.

By reason of the auditor’s professional independence under Act LXXV of 2007 on the Chamber of Hungarian Auditors, the Activities of Auditors, and on Public Oversight of Auditors, the auditor independently determines the purpose and methodology of the examination and is therefore an independent controller in respect of the personal data entrusted to it, and not a processor of the Service Provider.

Categories of data transferred: personal data contained in the Service Provider’s accounting records that are necessary for the examination of the financial statements (where they relate to a natural person). Categories of data subjects: persons whose data appear in the documents under examination. Legal basis for the transfer: Article 6(1)(c) GDPR, having regard to the statutory obligation of mandatory audit.

7. Newsletter and direct marketing (DM)

Pursuant to Section 6 of Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities (Grtv.), the User may give prior and express consent to being contacted by the Service Provider with advertising offers and other communications at the contact details provided at registration.

7.1. Categories of data processed and purposes of processing

Personal dataPurpose of processing
Name, e-mail addressIdentification; enabling subscription to the newsletter.
Date and time of subscriptionPerformance of a technical operation.
IP address at the time of subscriptionPerformance of a technical operation.

7.2. Categories of data subjects

All data subjects who subscribe to the newsletter.

7.3. Legal basis for processing

The data subject’s consent [Article 6(1)(a) GDPR], and Section 6(5) Grtv.

7.4. Duration of processing

Until withdrawal of the consent statement, i.e. until unsubscription. The data subject may unsubscribe from the newsletter at any time, free of charge and without giving reasons, by clicking the link in the message or via the contact details set out in Section 1.

7.5. Information

  • processing is based on the data subject’s consent;
  • the data subject is required to provide the personal data if he or she wishes to receive a newsletter;
  • the consequence of failing to provide the data is that the Service Provider cannot send a newsletter to the data subject.

8. Complaint handling

8.1. Categories of data processed and purposes of processing

Personal dataPurpose of processing
Surname and first nameIdentification; communication.
E-mail addressCommunication.
Telephone numberCommunication.
Billing name and addressIdentification; handling quality complaints, questions and problems relating to the ordered product.

8.2. Categories of data subjects

All data subjects who purchase in the Webshop and raise a quality complaint or lodge a complaint.

8.3. Legal basis for processing

Article 6(1)(c) GDPR, in conjunction with Section 17/A Fgy.tv.

8.4. Duration of processing

Pursuant to Section 17/A(7) Fgy.tv., the Service Provider is obliged to retain the consumer complaint — in the case of an oral complaint, the minutes taken; in the case of a written complaint, the complaint itself — and a copy of the substantive response for three years, and to present them to the supervisory authorities upon request.

8.5. Information

  • the provision of personal data is based on a statutory and contractual obligation;
  • the data subject is required to provide the personal data in order for the Service Provider to handle the complaint;
  • the consequence of failing to provide the data is that the Service Provider cannot handle the complaint received.

9. Cookies

9.1. Categories of data processed and purposes of processing

Session cookies necessary for the operation of the Webshop, cookies necessary for the shopping cart, and security cookies are used. Prior consent of the data subjects is not required for their use, as they are strictly necessary for the provision of the service.

Type of cookieLegal basis for processingDuration of processingCategories of data processed
Session cookiesSection 13/A(3) Ektv.Until the end of the visitor sessionsession identifier

Detailed information on the use of cookies is available on the Cookies page.

9.2. Categories of data subjects

All data subjects who visit the website.

9.3. Purpose of processing

Identification of users, maintaining the shopping cart, and ensuring the secure and proper operation of the website.

9.4. Legal basis for processing

The data subject’s consent is not required where the sole purpose of the cookies is the transmission of a communication over an electronic communications network, or where the Service Provider strictly needs them in order to provide a service expressly requested by the user [Section 155 of Act C of 2003 on Electronic Communications; Section 13/A(3) Ektv.].

9.5. Description of the rights of data subjects

Beyond the foregoing, the Service Provider does not process personal data through the use of cookies. The data subject may at any time delete or disable cookies in the Tools/Settings menu of his or her browser, typically under the Privacy menu item.

10. Web analytics and advertising (marketing) processing

10.1. Google Analytics

The website uses Google Analytics, a web analytics service of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Google Analytics uses cookies to help analyse the use of the website. The information generated by the cookies is usually transmitted to and stored on a Google server; with IP anonymisation activated, Google truncates the User’s IP address beforehand within Member States of the European Union or in other States party to the Agreement on the European Economic Area.

The data subject may prevent the storage of cookies by appropriate settings of his or her browser, and may also prevent Google’s collection and processing of data by downloading and installing the browser add-on available at https://tools.google.com/dlpage/gaoptout?hl=en.

The legal basis for processing is the data subject’s consent [Article 6(1)(a) GDPR].

10.2. Google Ads conversion tracking

The Service Provider uses the Google Ads online advertising programme and the related conversion tracking service (Google Ireland Limited). When the User reaches the website via a Google advertisement, a cookie required for conversion tracking is placed on the device; such cookies have a limited validity and are not suitable for directly identifying the User.

The information thus collected is used solely for preparing conversion statistics; neither the Service Provider nor Google obtains data by which the User could be identified. Conversion tracking may be disabled by changing the browser’s cookie settings. Further information and Google’s privacy policy: https://policies.google.com/privacy .

The legal basis for processing is the data subject’s consent [Article 6(1)(a) GDPR].

10.3. Meta (Facebook) Pixel

The website uses the Facebook pixel (Meta Pixel) tracking code provided by Meta Platforms Ireland Limited, which helps analyse the use of the website and by means of which browsing events of Users identifiable via their Facebook accounts are transmitted for advertising (marketing) purposes to the Service Provider’s advertising management account.

The Service Provider uses the data solely for the display of personalised, targeted advertisements, in accordance with Meta’s advertising policies from time to time, which the User accepted when registering a Facebook/Meta account. Further information and Meta’s privacy policy: https://www.facebook.com/privacy/policy/ .

The legal basis for processing is the data subject’s consent [Article 6(1)(a) GDPR].

Please note that the above web analytics and advertising cookies and tracking codes are placed on the user’s device only with the data subject’s prior, informed consent; consent may be modified or withdrawn at any time in the cookie settings available on the website.

10.4. First-party webshop analytics (cookieless)

The Webshop records first-party page, product, category, and cart views for internal traffic analysis, inventory planning, abuse prevention, and service improvement. This processing uses no analytics or advertising cookies and does not read or write analytics identifiers in the browser (no cookies, localStorage, or sessionStorage for this purpose). Google Analytics and advertising trackers remain consent-gated (see 10.1–10.3).

Categories of data (typical): viewed path, event type, shop/hostname, device category (mobile/tablet/desktop), language, truncated referrer, and a pseudonymised, truncated hash of the visitor IP address (computed server-side with a site-specific key and daily rotation; the raw IP is not stored). If you are logged in, your account user identifier may also be linked to hits for internal statistics. We do not store full browser user-agent strings for this analytics.

Purpose: aggregate first-party traffic and product-interest statistics, detect abuse, and operate the Webshop securely — not cross-site profiling and not sharing with third-party ad networks for their own purposes.

Recipients: processed internally by the Controller (section 1); not sold or shared with analytics/ad vendors for their own purposes.

Retention: up to 180 days, then permanently deleted (automated purge).

Legal basis: legitimate interests of the Controller [GDPR Art. 6(1)(f)] following a balancing assessment (EDPB Guidelines 01/2024): limited first-party measurement, data minimisation, short retention, no third-party ad reuse. Where you are logged in, the same legitimate interest applies to linking hits to your account for internal reporting; contract performance [Art. 6(1)(b)] applies to account functions in section 4, not to this aggregate analytics.

Your rights: access, erasure, restriction, objection, and complaint — see section 14 and controller contact in section 1. Because hits are pseudonymised, please contact us with the e-mail address of your account (if logged in) or approximate visit time to help locate records.

Compliance note (2026-08-01): wording reviewed against public EU/HU GDPR and ePrivacy guidance (EDPB, CNIL, NAIH); not formal legal sign-off — external counsel may still be engaged.

10.5. Campaign attribution on cart / order

If you arrive with campaign parameters (e.g. utm_source, utm_medium, utm_campaign, gclid, fbclid), we may keep them temporarily in browser sessionStorage on first touch and then store them with the cart/order record (order_info.marketing) when the cart is synced or the order is placed — for first-party traffic and revenue attribution, abandoned-cart analysis, and newsletter effectiveness. This is not an analytics cookie and not Google Analytics; it is separate from the cookieless hit log in section 10.4. We do not share these parameters with third-party ad networks for their own purposes.

Legal basis: legitimate interests [GDPR Art. 6(1)(f)], and for placed orders also administration related to contract performance. Retention: follows cart/order retention (not the 180-day purge in 10.4).

11. Social media

Categories of data processed: the data subject’s name and public profile picture, which the data subject made public in the course of his or her own registration on the social media platform, and which become known to the Service Provider through interaction with the Service Provider’s social media presence (page, profile) — in particular likes, follows, shares and comments.

Categories of data subjects: all data subjects who are registered on a social media platform and who have “liked”/shared the Service Provider’s page or profile or its content there.

Purpose of processing: sharing and promoting the website or individual content elements, products and promotions on social media platforms in the form of posts or advertisements, and enabling data subjects’ reactions thereto (likes, shares, comments).

The duration of processing, the possibility of erasure and modification of data, and the rights of data subjects are in each case governed by the privacy notice of the relevant social media platform; the data subject may obtain information thereon from that platform’s own notice.

The legal basis for processing is the data subject’s voluntary consent given on the social media platform.

The social media platforms actually used by the Service Provider are available and identifiable at any time on the Webshop website via the social media icons.

12. Customer relations and other processing

If a question or problem arises in the course of using the Webshop’s services, the data subject may contact the Service Provider by the means indicated on the website (telephone, e-mail, social media, etc.).

The Service Provider processes data provided in incoming enquiries (e-mail, telephone, social media, etc.) — together with the enquirer’s name, e-mail address and any other personal data voluntarily provided — for as long as necessary to handle the enquiry from the time of disclosure, and erases them upon request.

In respect of processing not separately listed in this notice, the Service Provider provides information at the time of collection of the data.

In the event of an exceptional request by an authority, or a request by another body based on statutory authorisation, the Service Provider is obliged to provide information, disclose or transfer data, or make documents available; in such cases the Service Provider discloses personal data only to the extent and in the scope strictly necessary to achieve the purpose of the request.

13. Access to data and data security measures

13.1. Access and transfers

Personal data may be accessed by the Service Provider’s staff and by the processors listed above, to the extent necessary for the performance of their tasks, with due regard for the principles set out in this notice.

The Service Provider transfers personal data only in the manner and for the purposes specified by law, or to the processors and recipients named in this notice. In the event of an exceptional request by an authority (e.g. investigating authority, public prosecutor’s office), the Service Provider transfers the requested data in accordance with its statutory obligation.

13.2. Data security measures

Having regard to the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the Service Provider and its processors implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk.

14. Rights of data subjects in relation to processing

14.1. Right of access

The data subject is entitled to obtain from the Service Provider confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and to the information listed in Article 15 GDPR (purposes of processing, categories of data concerned, recipients, retention period, etc.). The Service Provider shall provide a copy of the personal data undergoing processing free of charge on the first occasion; thereafter it may charge a reasonable fee based on administrative costs.

14.2. Right to rectification

The data subject is entitled to obtain from the Service Provider without undue delay the rectification of inaccurate personal data concerning him or her, and to have incomplete personal data completed.

14.3. Right to erasure

The data subject is entitled to obtain from the Service Provider the erasure of personal data concerning him or her without undue delay where one of the grounds in Article 17 GDPR applies (e.g. the data are no longer necessary, the data subject withdraws consent, or the processing is unlawful). An erasure request cannot be fulfilled where the Service Provider has a legal basis for further processing of the personal data — in particular under a statutory (e.g. accounting) retention obligation.

14.4. Right to be forgotten

The right to be “forgotten” is an extension of the right to erasure to the online environment, under which, where the controller has made the personal data public and is obliged to erase them, the controller shall take reasonable steps to inform controllers which are processing the personal data that the data subject has requested the erasure of any links to, or copy or replication of, those personal data.

In connection with this data subject right, however, it is important to note that erasure and “being forgotten” are not available where any of the cases set out in Article 17(3) of the General Data Protection Regulation applies.

14.5. Right to restriction of processing

The data subject is entitled to obtain restriction of processing where he or she contests the accuracy of the personal data — in which case the restriction applies for a period enabling the Service Provider to verify the accuracy of the data; where the processing is unlawful and the data subject opposes erasure and requests restriction instead; where the Service Provider no longer needs the data but the data subject requires them for the establishment, exercise or defence of legal claims; or where the data subject has objected to processing — in which case the restriction lasts until it is verified whether the Service Provider’s legitimate grounds override those of the data subject.

14.6. Right to data portability

The data subject is entitled to receive the personal data concerning him or her, which he or she has provided to the Service Provider, in a structured, commonly used and machine-readable format, and to transmit those data to another controller without hindrance from the Service Provider. This right applies to processing based on the data subject’s consent or on the performance of a contract, and which is carried out by automated means.

14.7. Right to object

The data subject is entitled to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on the Service Provider’s legitimate interest, including profiling based thereon.

14.8. Objection in the case of direct marketing

Where personal data are processed for direct marketing purposes, the data subject may object at any time to processing of personal data concerning him or her for such marketing, including profiling related thereto. Where the data subject objects, the personal data shall no longer be processed for such purposes.

14.9. Automated decision-making

The data subject is entitled not to be subject to a decision based solely on automated processing — including profiling — which produces legal effects concerning him or her or similarly significantly affects him or her, except where the decision is necessary for entering into or performing a contract, is authorised by law with appropriate safeguards, or is based on the data subject’s explicit consent.

The Service Provider operates a loyalty and price-discount programme in the Webshop. In that context, the discounted price category to which the data subject belongs is determined automatically on the basis of the data subject’s purchasing activity. Assignment to a more favourable price category, as well as — where activity under the programme rules no longer justifies the more favourable classification (for example because of cancellation or deletion of a purchase) — reassignment to a lower price category, may also take place automatically. This classification affects the purchase prices displayed in the Webshop and applied at the order.

Such automated decision-making is necessary for the conclusion and performance of the contract [Article 6(1)(b) GDPR and Article 22(2)(a) GDPR]. The data subject is entitled to obtain human intervention from the Service Provider, to express his or her point of view, and to contest the decision via the contact details set out in Section 1.

15. Time limit for action

The Service Provider shall inform the data subject without undue delay and in any event within one month of receipt of the request of the action taken on the above requests. That period may be extended by two further months where necessary; the Service Provider shall inform the data subject of any such extension within one month of receipt of the request, together with the reasons for the delay.

If the Service Provider does not take action on the request of the data subject, it shall inform the data subject without delay and at the latest within one month of receipt of the request of the reasons for not taking action and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.

16. Handling of personal data breaches

Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Service Provider shall communicate the personal data breach to the data subject without undue delay, describing the nature of the breach, the contact point, the likely consequences, and the measures taken or proposed by the Service Provider.

Communication to the data subject may be dispensed with if the Service Provider has implemented appropriate technical and organisational protection measures (e.g. encryption) which render the personal data unintelligible to any person who is not authorised to access it; if the Service Provider has taken subsequent measures which ensure that the high risk is no longer likely to materialise; or if it would involve disproportionate effort — in which case there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.

The Service Provider shall notify the personal data breach to the supervisory authority competent under Article 55 GDPR (NAIH) without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification is not made within 72 hours, it shall be accompanied by reasons for the delay.

17. Remedies

If the data subject considers that the Service Provider has infringed applicable data protection legislation in the course of processing his or her personal data, he or she may lodge a complaint with the supervisory authority:

  • National Authority for Data Protection and Freedom of Information (NAIH — Nemzeti Adatvédelmi és Információszabadság Hatóság)
  • Registered seat: 1055 Budapest, Falk Miksa u. 9-11.
  • Postal address: 1363 Budapest, P.O. Box 9, Hungary
  • Telephone: +36 (1) 391-1400
  • Fax: +36 (1) 391-1410
  • E-mail: [email protected]
  • Website: www.naih.hu

In addition to the National Authority for Data Protection and Freedom of Information, the data subject is also entitled to lodge a complaint with the data protection supervisory authority of the Member State of his or her habitual residence, place of work, or place of the alleged infringement, if he or she considers that the processing of personal data relating to him or her infringes the provisions of the GDPR. Information on the supervisory authorities of the Member States of the European Union and their contact details is available on the website of the European Data Protection Board (EDPB): https://www.edpb.europa.eu/about-edpb/our-members_en

The data subject may also bring the matter before a court for the protection of his or her data; proceedings may, at the data subject’s choice, be brought before the tribunal competent according to the data subject’s place of residence or stay, or the Service Provider’s registered seat, or — where the data subject’s habitual residence is in another Member State of the European Union — before the competent court of that Member State.

18. Final provisions

The Service Provider reserves the right to update this notice unilaterally in the event of a change in the legal environment or in processing practice; the notice in force from time to time is available on the Service Provider’s website.

Effective date: 19 July 2026

This site uses cookies to offer you a better browsing experience. Find out more on how we use cookies. If you continue to use this site without explicit acceptance, we will assume that you accept only essential cookies.