Privacy Policy
1. Introduction
1.1. Purpose of the Privacy Policy
The purpose of this Privacy Policy (hereinafter: “Policy”) is to present in a transparent and detailed manner how personal data is processed during the activities of Téglásiné Rimóczi Erika Ágnes e.v. (hereinafter: “Data Controller”), as well as to provide information on the rights of data subjects and the methods of exercising them.
1.2. Legal Compliance (GDPR, Act CXII of 2011)
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR): defines uniform EU rules on the protection of personal data.
- Act CXII of 2011 (Infotv.): the law forming the basis of Hungarian data protection regulation, concerning the right of informational self-determination and freedom of information.
This Policy strives to comply with the requirements laid down in the above legislation.
2. Data Controller Details
2.1. Name and Contact Details of the Data Controller
- Name: Téglásiné Rimóczi Erika Ágnes e.v.
- Registered office: 1126 Budapest, Tartsay Vilmos utca 28. 2/1.
- Registration number: 52996355
- Tax number: 69308930-1-43
- Representative: Téglásiné Rimóczi Erika Ágnes
- E-mail: rimoczi.erikaa@gmail.com
- Phone number: +36202314026
2.2. Availability of the Privacy Policy
This Policy is available in electronic format on the www.kosarvilag.hu website, and can also be viewed in printed form upon request at our customer service office.
3. Definitions
3.1. Basic GDPR Concepts
- Personal data: any information relating to an identified or identifiable natural person (“data subject”).
- Data Controller: the natural or legal person which determines the purposes and means of the processing of personal data.
- Data Processor: a natural or legal person which processes personal data on behalf of the Data Controller.
- Consent: any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they signify agreement to the processing of personal data relating to them.
- Data subject: any identified or identifiable natural person to whom the personal data relates.
3.2. Definition of a Personal Data Breach
A personal data breach means any event leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.
4. Principles of Data Processing
4.1. Legal Bases and Principles
- Lawfulness, fairness and transparency: We process data only for specific and lawful purposes.
- Purpose limitation: Only for pre-determined purposes, to the extent necessary to achieve the purpose.
- Data minimisation: We collect and process only the personal data essential for achieving the purpose.
- Accuracy: We ensure that the processed personal data is accurate and, where necessary, kept up to date.
- Storage limitation: Personal data is stored only for the time necessary to achieve the purpose.
- Integrity and confidentiality: We apply appropriate technical and organizational measures to protect personal data.
4.2. Accuracy and Security of Data
- Both the Data Controller and the data subject are responsible for regular data updates; the latter is obliged to report any changes to their personal data.
- The Data Controller makes every effort to ensure the accuracy of recorded data and protects it from unauthorized access with appropriate security measures.
5. Data Processing Purposes and Legal Bases
5.1. Registration on the Website
- Purpose: Creation of a user account and provision of related services.
- Legal basis:
- Consent (GDPR Article 6(1)(a)) if registration is voluntary and requested by the data subject.
- Performance of a contract (GDPR Article 6(1)(b)) if registration is a prerequisite for providing the service.
- Scope of processed data: Name, e-mail address, password (encrypted), date of registration, IP address.
5.2. Order Management
- Purpose: Processing of orders, performance of the contract, invoicing, and delivery.
- Legal basis: Performance of a contract (GDPR Article 6(1)(b)).
- Scope of processed data: Name, billing and shipping address, contact details (phone number, e-mail), order details.
5.3. Invoicing
- Purpose: Compliance with applicable accounting laws (e.g., Act C of 2000).
- Legal basis: Compliance with a legal obligation (GDPR Article 6(1)(c)).
- Scope of processed data: Name/company name, address, tax number (for legal entities), other data necessary for invoicing.
5.4. Newsletter Sending
- Purpose: Marketing communication, information about new products and promotions.
- Legal basis: Consent (GDPR Article 6(1)(a)).
- Scope of processed data: Name, e-mail address.
- Note: You can unsubscribe from the newsletter at any time by clicking the link at the bottom of the newsletter or directly notifying the Data Controller.
5.5. Use of Cookies
- Purpose: Ensuring the proper functioning of the website, improving user experience, analyzing visitor data, marketing purposes.
- Legal basis:
- Consent (GDPR Article 6(1)(a)) – for all cookies that are not an essential condition for the website’s operation.
- Legitimate interest or performance of a contract (GDPR Article 6(1)(f) or (b)) – for essential technical cookies.
- Detailed description: See the “Use of Cookies” section (point 11) of this Policy.
Cloudflare Turnstile and Cloudflare cookies
Our website uses the Cloudflare Turnstile service to filter out unauthorized, automated use of contact and other forms, as well as spam and malicious bot traffic.
During the operation of the service, certain technical data of the website visitor may be transmitted to Cloudflare, Inc. The transmitted and processed data may include in particular:
- the user’s IP address,
- browser and device technical data, such as User-Agent information,
- certain technical characteristics of the network connection,
- traffic and request data related to the use of the website,
- and other technical information necessary for detecting bot traffic.
The purpose of data processing is to determine whether the website or its forms are used by a real user or an automated system, thereby ensuring the secure operation of the website and preventing abuse.
During the provision of the service, Cloudflare may use technical cookies or similar technologies necessary for operation and security checks. Depending on the Cloudflare configuration applied, this may be, for example, the cf_clearance cookie, which is used to store the result of a successfully completed security check. The purpose of these technologies is to maintain website security, detect automated and malicious traffic, and handle repeated security checks.
Further information on data processing by Cloudflare Turnstile can be found in the following documents:
Cloudflare privacy policy: https://www.cloudflare.com/privacypolicy/
Cloudflare Turnstile privacy policy: https://www.cloudflare.com/turnstile-privacy-policy/
5.6. Data Processing of Social Media Pages
- Purpose: Maintaining contact, sharing information (Facebook, Instagram, etc.).
- Legal basis: Voluntary decision, consent (GDPR Article 6(1)(a)).
- Note: The data processing practices of the social media platforms must be reviewed in the privacy policy of the respective platform.
6. Scope of Processed Data
6.1. Types of Personal Data
- Identification data: name, username, password (encrypted).
- Contact data: e-mail address, phone number, address.
- Technical data: IP address, browser type, cookies, login time.
- Billing data: billing name, address, tax number (for companies).
6.2. Method and Duration of Data Storage
- In electronic form on protected servers, secured with passwords and other protective solutions.
- On paper (if any) at the registered office or premises, in a locked location.
- Storage period: until the legal obligations and the data processing purpose are fulfilled, or until consent is withdrawn. Afterwards, the data is deleted or anonymized.
7. Rights of Data Subjects
7.1. Right to Information
The data subject has the right to request information about for what purpose, on what legal basis, from what source, for how long we process personal data relating to them, and who has access to it.
7.2. Right to Rectification
If the data subject believes that their processed personal data is inaccurate or incomplete, they may request its rectification or completion.
7.3. Right to Erasure (“Right to be Forgotten”)
The data subject may request the erasure of their personal data if the data is no longer needed for its original purpose, or if the data subject withdraws their consent and there is no other legal basis for data processing.
7.4. Right to Data Portability
The data subject has the right to receive the data provided by them in a widely used, machine-readable format, and may request its transmission to another data controller.
7.5. Right to Object
- The data subject may object to the processing of their personal data at any time if the legal basis for processing is the legitimate interest of the Data Controller.
- The data subject specifically has the right to object to the processing of personal data for direct marketing purposes.
8. Data Security
8.1. Protection of Electronic Data
- Multi-level authorization system.
- Regular backups.
- Use of antivirus and firewall.
8.2. Technical and Organizational Measures
- Closed office network and secure Wi-Fi usage.
- Storage of paper-based documents in a locked cabinet.
- Regular data protection training for employees and data processors.
9. Handling of Personal Data Breaches
9.1. Reporting Incidents to Authorities (72-hour rule)
In the event of a personal data breach, the Data Controller shall, without undue delay and, where feasible, not later than 72 hours, notify the breach to the National Authority for Data Protection and Freedom of Information (NAIH), unless the breach is unlikely to result in a risk to the rights and freedoms of data subjects.
9.2. Informing Data Subjects in Case of High Risk
If the incident is likely to result in a high risk to the rights and freedoms of data subjects, the Data Controller shall inform the data subjects without delay, explaining the nature of the incident and the measures taken.
10. Data Processors and Third Parties
10.1. Hosting Provider
Company name: Vitarex Stúdió Kft.
Address: Budapest, Aladár u. 17 Ground floor 1, 1016
Phone number: +36 1 385 1949
E-mail: vitarex@vitarex.hu
Data processing activity: operation of the web server, technical maintenance. Processes personal data only based on the instructions of the Data Controller.
10.2. Accountant and Other Partners
The Data Controller may use an accountant, courier service, marketing agency, and other partners to process personal data.
The Data Controller always concludes a written contract with these partners (data processors) in compliance with GDPR requirements. The contracts stipulate that the partners may only process data based on the instructions of the Data Controller, for the specified purpose, and for the necessary time.
11. Use of Cookies
11.1. Purpose and Types of Cookies
- Session cookies: essential for the functioning of the website, deleted when the browser is closed.
- Functional cookies: aid user convenience, e.g., remembering login details or selected language.
- Analytical cookies (e.g., Google Analytics): serve statistical purposes, help understand user behavior, and improve website operation.
- Marketing cookies: support the display of relevant advertisements and the measurement of ad effectiveness.
11.2. Management of User Settings
- Users can control the management of cookies in their browser settings, allowing them to disable or delete them.
- When modifying cookie settings, some functions of the website may not operate properly.
- Upon the first visit to the website, it is possible to enable or reject non-essential (e.g., marketing) cookies through a pop-up window.
12. Data Protection Officer (DPO)
12.1. Conditions of Designation and Tasks
Based on Article 37 of the GDPR, the Data Controller is obliged to designate a data protection officer (DPO) if its core activities:
- consist of processing operations which, by virtue of their nature or scope, require regular and systematic monitoring of data subjects on a large scale, or
- consist of processing on a large scale of highly sensitive data.
The tasks of the officer include:
- continuous monitoring of GDPR compliance,
- advising the Data Controller and employees,
- liaising with the supervisory authority (NAIH) and data subjects.
12.2. Legal Status and Contact
The data protection officer reports directly to top management and cannot be instructed regarding their duties.
- Name: Téglásiné Rimóczi Erika Ágnes e.v.
- Contact: rimoczi.erikaa@gmail.com, +36202314026
If the designation of a DPO is not mandatory for the Data Controller, but an officer is still appointed, data subjects will be properly informed in this Policy.
13. Enforcement Options for Data Subjects
13.1. Filing a Complaint with the National Authority for Data Protection and Freedom of Information (NAIH)
If the data subject believes that the processing of their personal data violates applicable laws, they may file a complaint with the National Authority for Data Protection and Freedom of Information:
- Address: 1055 Budapest, Falk Miksa utca 9-11.
- Phone: +36 (1) 391-1400
- E-mail: ugyfelszolgalat@naih.hu
13.2. Right to Judicial Remedy
In the event of an infringement of their rights, the data subject may turn to court. The lawsuit may be initiated – at the choice of the data subject – before the regional court having jurisdiction over their place of residence or stay.
14. Legislation Underlying Data Processing
14.1. GDPR (EU Regulation 2016/679)
Regulation (EU) 2016/679 of the European Parliament and of the Council, aimed at protecting natural persons regarding the processing of personal data and ensuring the free movement of such data within the EU.
14.2. Act CXII of 2011 on the Right of Informational Self-Determination
The Hungarian Data Protection Act regulating the domestic principles and limitations of personal data processing.
14.3. Other Relevant Hungarian Legislation
- Act C of 2000 on Accounting.
- Act V of 2013 on the Civil Code (Ptk.).
- Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities.
15. Final Provisions
15.1. Scope and Modification Options of the Privacy Policy
- This Policy is effective from July 22, 2026.
- The Data Controller is entitled to unilaterally modify this Policy, especially taking into account legislative changes, the introduction of new data processing activities, or the recommendations of the supervisory authority.
- Modifications will be published on the website, and following their entry into force, data subjects accept the new rules by continuing to use the services.
Dated: Budapest, July 22, 2026.
Téglásiné Rimóczi Erika Ágenes e.v.