Privacy Policy

1. Introduction

1.1. Purpose of the Privacy Notice

The purpose of this Privacy Notice (hereinafter referred to as the “Notice”) is to provide a transparent and detailed description of how personal data are processed in the course of the activities of Kelemen Zsolt, sole proprietor (hereinafter referred to as the “Data Controller”), and to provide information about the rights of data subjects and the manner in which those rights may be exercised.

1.2. Compliance with Applicable Legislation (GDPR and Act CXII of 2011)

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR): establishes uniform European Union rules concerning the protection of personal data.
  • Act CXII of 2011 (Privacy Act): the fundamental Hungarian data protection legislation concerning the right to informational self-determination and freedom of information.

This Notice is intended to comply with the requirements set out in the above legislation.

2. Details of the Data Controller

2.1. Name and Contact Details of the Data Controller

  • Name: Kelemen Zsolt, sole proprietor
  • Registered office: 5 Vasút Street, Polgárdi 8154, Hungary
  • Tax number: 64895024-1-27
  • Representative: Kelemen Zsolt
  • Email address: info@epiteszprojekt.hu
  • Telephone number: +36 20 358 2799

2.2. Availability of the Privacy Notice

This Notice is available electronically on the website www.epiteszprojekt.hu and may also be viewed in printed form at our customer service office upon request.

3. Definitions

3.1. Basic Terms under the GDPR

  • Personal data: any information relating to an identified or identifiable natural person (“data subject”).
  • Data Controller: the natural or legal person that determines the purposes and means of processing personal data.
  • Data Processor: the natural or legal person that processes personal data on behalf of the Data Controller.
  • Consent: any freely given and explicit indication of the data subject’s wishes by which they agree to the processing of personal data relating to them.
  • Data subject: any identified or identifiable natural person to whom the personal data relate.

3.2. Definition of a Personal Data Breach

A personal data breach means any event resulting in the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

4. Principles of Data Processing

  • Lawfulness, fairness and transparency: Personal data are processed only for specified and lawful purposes.
  • Purpose limitation: Personal data are processed only for predefined purposes and only to the extent necessary to achieve those purposes.
  • Data minimisation: We collect and process only the personal data that are essential for achieving the relevant purpose.
  • Accuracy: We ensure that the personal data processed are accurate and, where necessary, kept up to date.
  • Storage limitation: Personal data are stored only for as long as necessary to achieve the relevant purpose.
  • Integrity and confidentiality: We implement appropriate technical and organisational measures to protect personal data.

4.2. Accuracy and Security of Data

  • Both the Data Controller and the data subject are responsible for ensuring that personal data are regularly updated. The data subject is required to notify the Data Controller of any changes to their personal data.
  • The Data Controller makes every reasonable effort to ensure that the data recorded are accurate and protects them against unauthorised access by implementing appropriate security measures.

5. Purposes and Legal Bases of Data Processing

5.1. Registration on the Website

  • Purpose: To create a user account and provide the related services.
  • Legal basis:
    • Consent pursuant to Article 6(1)(a) of the GDPR where registration is voluntary and requested by the data subject.
    • Performance of a contract pursuant to Article 6(1)(b) of the GDPR where registration is a prerequisite for the provision of the service.
  • Categories of personal data processed: Name, email address, password in encrypted form, date of registration and IP address.

5.2. Processing Orders

  • Purpose: To process orders, perform the contract, issue invoices and arrange delivery.
  • Legal basis: Performance of a contract pursuant to Article 6(1)(b) of the GDPR.
  • Categories of personal data processed: Name, delivery and billing address, contact details including telephone number and email address, and order details.

5.3. Issuing Invoices

  • Purpose: To comply with the applicable accounting legislation, including Act C of 2000.
  • Legal basis: Compliance with a legal obligation pursuant to Article 6(1)(c) of the GDPR.
  • Categories of personal data processed: Name or company name, address, tax number in the case of a legal entity, and any other information required for invoicing.

5.4. Sending Newsletters

  • Purpose: Marketing communications and providing information about new products and promotions.
  • Legal basis: Consent pursuant to Article 6(1)(a) of the GDPR.
  • Categories of personal data processed: Name and email address.
  • Note: The data subject may unsubscribe from the newsletter at any time by clicking the unsubscribe link at the bottom of the newsletter or by contacting the Data Controller directly.

5.5. Use of Cookies

  • Purpose: To ensure the proper operation of the website, improve the user experience, analyse website traffic and carry out marketing activities.
  • Legal basis:
    • Consent pursuant to Article 6(1)(a) of the GDPR in the case of cookies that are not strictly necessary for the operation of the website.
    • Legitimate interest or performance of a contract pursuant to Article 6(1)(f) or Article 6(1)(b) of the GDPR in the case of technical cookies that are essential for the operation of the website.
  • Further information: See the “Use of Cookies” chapter of this Notice, under Section 11.

Cloudflare Turnstile and Cloudflare Cookies

Our website uses the Cloudflare Turnstile service to prevent the unauthorised and automated use of contact and other forms and to filter out unsolicited messages and malicious bot traffic.

During the operation of the service, certain technical data relating to the website visitor may be transferred to Cloudflare, Inc. The data transferred and processed may include, in particular:

  • the user’s IP address;
  • technical information relating to the browser and device, such as User-Agent information;
  • certain technical characteristics of the network connection;
  • traffic and request data relating to the use of the website; and
  • other technical information necessary for identifying bot traffic.

The purpose of the processing is to determine whether the website and its forms are being used by a genuine user or by an automated system, thereby ensuring the secure operation of the website and preventing misuse.

When providing the service, Cloudflare may use technical cookies and similar technologies that are necessary for its operation and security checks. Depending on the Cloudflare configuration used, this may include, for example, the cf_clearance cookie, which may be used to store the result of a successfully completed security check. The purpose of these technologies is to maintain the security of the website, identify automated and malicious traffic and manage repeated security checks.

Further information about the processing carried out by Cloudflare Turnstile can be found in the following documents:

Cloudflare Privacy Policy:
https://www.cloudflare.com/privacypolicy/

Cloudflare Turnstile Privacy Policy:
https://www.cloudflare.com/turnstile-privacy-policy/

5.6. Data Processing on Social Media Platforms

  • Purpose: Communication and sharing information through platforms such as Facebook and Instagram.
  • Legal basis: The data subject’s voluntary decision and consent pursuant to Article 6(1)(a) of the GDPR.
  • Note: Information about the data processing practices of social media platforms can be found in the privacy notice of the relevant platform.

6. Categories of Personal Data Processed

6.1. Types of Personal Data

  • Identification data: Name, username and password in encrypted form.
  • Contact details: Email address, telephone number and address.
  • Technical data: IP address, browser type, cookies and login time.
  • Billing information: Billing name, address and tax number in the case of companies.

6.2. Method and Duration of Data Storage

  • Personal data are stored electronically on protected servers secured by passwords and other security measures.
  • Personal data stored in paper form, where applicable, are kept in a locked and secure location at the registered office or business premises.
  • Retention period: Personal data are retained for as long as required by applicable legislation, for as long as necessary to achieve the purpose of the processing, or until consent is withdrawn. Thereafter, the data are deleted or anonymised.

7. Rights of Data Subjects

7.1. Right to Information

The data subject has the right to request information about the purposes for which their personal data are processed, the legal basis of the processing, the source of the data, the duration of the processing and the persons who may have access to the data.

7.2. Right to Rectification

Where the data subject considers that the personal data processed about them are inaccurate or incomplete, they may request the rectification or completion of those data.

7.3. Right to Erasure (“Right to Be Forgotten”)

The data subject may request the erasure of their personal data where the data are no longer required for the purposes for which they were originally collected or where the data subject withdraws their consent and there is no other legal basis for the processing.

7.4. Right to Data Portability

The data subject has the right to receive the personal data they have provided in a commonly used and machine-readable format and may request that those data be transmitted to another data controller.

7.5. Right to Object

  • The data subject may object at any time to the processing of their personal data where the legal basis of the processing is the legitimate interest of the Data Controller.
  • The data subject has the specific right to object to the processing of personal data for direct marketing purposes.