general data protection policy
TCoDo Limited Liability Company
GENERAL DATA PROTECTION POLICY AND PRIVACY NOTICE FOR DATA SUBJECTS
Effective from: 1 May 2024
INTRODUCTION
TCoDo Szolgáltató Korlátolt Felelősségű Társaság (registered office: 1029 Budapest, Köztársaság utca 34., Door 26, Hungary; company registration number: 01-09-188969; hereinafter referred to as the "Company" or the "Data Controller") is committed to protecting the personal data of its employees, business partners, and third parties with whom it comes into contact, including visitors to the Vitaltier webshops (vitaltier.hu and vitaltier.eu) (hereinafter collectively referred to as the "Data Subjects"). The Company considers respect for the right to informational self-determination to be of paramount importance.
The purpose of this Policy is to ensure that the Data Controller complies with the applicable legal requirements relating to data protection and provides adequate information to Data Subjects regarding the processing of their personal data.
In all of its data processing activities, the Data Controller acts in accordance with the provisions of this Data Protection Policy (hereinafter: the "Policy"), as well as its other internal policies and instructions.
The General Part of this Policy sets out the general rules applicable to all processing activities, while the Special Part contains rules and information relating to specific processing activities.
This General Data Protection Policy jointly covers the principal data processing activities carried out by the Data Controller. However, since not all of the processing activities listed herein necessarily apply to every Data Subject, the Data Controller may, where appropriate, provide a separate concise privacy notice at the time of data collection containing details relating to the specific processing activity concerned.
Please read this entire Policy carefully, as only by doing so can you obtain a complete understanding of the rules governing the processing of personal data.
The Data Controller shall treat all personal data recorded by or provided to it confidentially and in accordance with applicable data protection laws and the provisions of this Policy, thereby ensuring the achievement of the statutory objective that every individual retains control over his or her personal data.
Furthermore, during its processing activities, the Data Controller shall ensure the security of personal data and shall implement the technical and organisational measures, as well as establish the procedural rules through separate internal policies, necessary for compliance with data protection and confidentiality requirements.
Although the Company has sought to provide comprehensive regulation, this Policy may not necessarily cover every conceivable processing activity. If a need arises for a processing activity not covered by this Policy, the Company shall inform Data Subjects of the material circumstances relating to such processing activity through a separate privacy notice.
A current copy of this Policy shall be kept at the Company's registered office. This Policy and any amendments thereto are also available on the website www.vitaltier.eu under the footer menu.
The processing of personal data relating to the Company's employees (including job applicants, temporary agency workers, and workers engaged through cooperatives – collectively referred to as "employees") is governed by the Employee Data Protection Policy, which is available at the Company's registered office to all employees, former employees, and job applicants.
APPLICABLE LEGISLATION
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter: "GDPR")
Act CXII of 2011 on Informational Self-Determination and Freedom of Information (hereinafter: "Information Act")
Act V of 2013 on the Civil Code (hereinafter: "Civil Code")
Act C of 2000 on Accounting (hereinafter: "Accounting Act")
Act CL of 2017 on the Rules of Taxation (hereinafter: "Tax Procedure Act")
Act LIII of 2017 on the Prevention and Combating of Money Laundering and Terrorist Financing (hereinafter: "AML Act")
Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities (hereinafter: "Advertising Act")
Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (hereinafter: "E-Commerce Act")
Government Decree No. 45/2014 (II.26.) on the Detailed Rules of Contracts between Consumers and Businesses
Act XLVII of 2008 on the Prohibition of Unfair Commercial Practices against Consumers (hereinafter: "UCP Act")
Act CLV of 1997 on Consumer Protection (hereinafter: "Consumer Protection Act")
Ministry for National Economy Decree No. 19/2014 (IV.29.) on the Procedural Rules for Handling Warranty and Guarantee Claims Relating to Goods Sold under Contracts between Consumers and Businesses
PURPOSE OF THE POLICY
The purpose of applying and enforcing the rules set out in this Policy is to ensure practical compliance with the requirements laid down in applicable legislation, in particular the GDPR.
To this end, through this Policy, other internal policies, instructions, and established internal procedures, the Company:
ensures the effective exercise of the Data Subjects' fundamental rights relating to the protection of personal data and compliance with data security requirements;
regulates the prevention of unauthorised access to data and establishes rules ensuring the prevention of unlawful modification, unauthorised use, or unauthorised disclosure of data;
defines the precise and secure procedures for electronic data processing, use, transfer, and destruction;
provides Data Subjects with appropriate information concerning the processing of their personal data, their rights, and the means available for exercising those rights.
1. GENERAL PART
Definitions
For the purposes of this Policy:
"Personal Data"
Any information relating to an identified or identifiable natural person ("Data Subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
Accordingly, any information by which a Data Subject may be identified constitutes Personal Data, including, for example, name, address, telephone number, IP address, etc.
"Processing"
Any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Accordingly, Processing includes any activity involving Personal Data, such as collecting, reviewing, organising, or storing data.
"Profiling"
Any form of automated processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location, or movements.
"Pseudonymisation"
The processing of Personal Data in such a manner that the Personal Data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the Personal Data are not attributed to an identified or identifiable natural person.
"Filing System"
Any structured set of Personal Data which is accessible according to specific criteria, whether centralised, decentralised, or dispersed on a functional or geographical basis.
"Data Controller"
The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data.
Where the purposes and means of such Processing are determined by Union or Member State law, the Data Controller or the specific criteria for its designation may be provided for by Union or Member State law.
For the purposes of this Policy, the Data Controller is the Company.
"Data Processor"
A natural or legal person, public authority, agency, or other body which processes Personal Data on behalf of the Data Controller.
A Data Processor includes any person or undertaking that carries out specified operations involving Personal Data on behalf of and under the instructions of the Company, such as accountants, payroll providers, hosting providers, software providers, e-mail service providers, and similar service providers.
"Recipient"
A natural or legal person, public authority, agency, or another body to which Personal Data are disclosed, whether a third party or not.
Public authorities which may receive Personal Data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as Recipients.
Recipients include any person, company, authority, or organisation to whom Personal Data are transferred or who are granted access to such data, including, for example, tax authorities and Data Processors.
"Third Party"
A natural or legal person, public authority, agency, or body other than the Data Subject, the Data Controller, the Data Processor, and persons who, under the direct authority of the Data Controller or Data Processor, are authorised to process Personal Data.
In practical terms, a Third Party is any person or entity that is not ordinarily involved in the Processing activity concerned.
"Consent of the Data Subject"
Any freely given, specific, informed, and unambiguous indication of the Data Subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the Processing of Personal Data relating to him or her.
Examples include a written consent declaration or ticking a consent checkbox on a website. It is important to note that silence, inactivity, or pre-ticked boxes do not constitute valid consent under data protection law.
"Personal Data Breach"
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
Examples include hacking incidents, destruction of physical archives, loss of laptops, mobile phones, or storage devices containing Personal Data, sending Personal Data to the wrong e-mail recipient, or unauthorised copying of customer or client databases.
Principles Relating to Processing of Personal Data
Personal Data shall be:
processed lawfully, fairly, and in a transparent manner in relation to the Data Subject ("lawfulness, fairness, and transparency"). This means that Personal Data may be processed only in accordance with the applicable legal provisions, and the Data Subject must be able to obtain appropriate information about the circumstances of the Processing, including its purposes, legal basis, and duration;
collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes. Further Processing for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes is permitted ("purpose limitation"). This means that Personal Data processed for a specific purpose may be used for another purpose only in exceptional cases;
adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed ("data minimisation"). This means that Personal Data may be processed only where there is no other means of achieving the specified purpose;
accurate and, where necessary, kept up to date. Every reasonable step must be taken to ensure that Personal Data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay ("accuracy"). This means that any changes in the data must be recorded as soon as possible;
kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the Personal Data are processed ("storage limitation"). This means that after the specified purpose has been achieved, or after the maximum Processing period has expired, the data must either be erased or anonymised so that the Data Subject can no longer be identified from the data;
processed in a manner that ensures appropriate security of the Personal Data, including protection against unauthorised or unlawful Processing and against accidental loss, destruction, or damage, using appropriate technical or organisational measures ("integrity and confidentiality"). This requires appropriate IT and other security measures to prevent unauthorised access to the data;
processed under the responsibility of the Data Controller, who shall be responsible for, and able to demonstrate compliance with, the above principles ("accountability"). The Data Controller records its data processing processes in internal instructions and policies so that the procedures within the organisation can be accurately followed and, where necessary, demonstrated to the authorities.
Purposes and Legal Bases of Processing
Purposes of Processing
The Company determines the purpose of Processing separately for each individual Processing activity. These purposes are set out in the Special Part of this Policy.
As a general rule, the Company processes the Personal Data of Data Subjects for purposes related to its business operations, the exercise and performance of its contractual rights and obligations, and the enforcement of its legitimate interests.
Legal Bases of Processing
The Company also determines the legal basis of Processing separately for each individual Processing activity. These legal bases are also set out in the Special Part of this Policy.
The GDPR distinguishes six types of legal bases for Processing, as follows:
Processing Based on the Consent of the Data Subject
The consent of the Data Subject must always be voluntary and may be given only through an active action. Silence does not constitute consent.
Examples include written consent, whether in a separate declaration or, for example, by signing a contract that itself contains the consent, ticking a checkbox on an electronic interface, clicking an "I consent" button, and similar actions.
Consent must or may be given separately for each individual Processing activity.
The Data Subject has the right to withdraw consent at any time. Withdrawal of consent shall not affect the lawfulness of Processing based on consent before its withdrawal; therefore, consent may be withdrawn only with effect for the future.
It must be as easy to withdraw consent as to give it. Accordingly, consent may be withdrawn, for example, by written letter, by telephone, or by a declaration sent by e-mail.
A consent declaration made by a person under the age of 16, or by a person with limited legal capacity, shall be valid only if given by the person exercising parental responsibility over the child or, in the case of a person with limited legal capacity, by his or her guardian or conservator.
In case of doubt, it shall be presumed that the Data Subject has not given consent.
Processing Necessary for the Conclusion or Performance of a Contract to Which the Data Subject Is a Party
Where performance of a contract is not possible without the Processing of Personal Data, this may constitute a lawful ground for Processing. In such cases, the separate consent of the Data Subject is not required.
Processing activities arising in connection with the performance of contracts most commonly concern the Personal Data of the contracting parties recorded in the contract or on a web interface, such as name, residential address, delivery address, and similar data. Such Processing may also include data relating to the use of a service.
Processing Necessary for Compliance with a Legal Obligation Applicable to the Data Controller
The purpose of Processing based on legal provisions is to comply with obligations and exercise rights set out in the relevant legislation.
Processing activities connected with compliance with legal obligations constitute mandatory Processing activities. The scope and duration of such Processing are always determined by the applicable legal provisions.
A large number of legal provisions impose obligations that necessarily involve the Processing of Personal Data. It is important to note that compliance with legal obligations is not optional and must be fulfilled in all cases.
Such Processing activities may include, in particular, records kept by the Company, the data content of invoices and accounting documents, anti-money laundering identification, and similar statutory obligations.
Processing Necessary to Protect the Vital Interests of the Data Subject or of Another Natural Person
In special cases where the Data Subject is unable to protect his or her own interests or is prevented from acting, Personal Data may be processed solely to the extent necessary and solely for the duration of such impediment in order to protect vital interests.
Processing Necessary for the Performance of a Task Carried Out in the Public Interest or in the Exercise of Official Authority Vested in the Data Controller
Since the Company is not a public authority, it does not carry out Processing on this legal basis.
Processing Necessary for the Purposes of the Legitimate Interests Pursued by the Data Controller or by a Third Party
A legitimate interest is generally based on the enforcement of a right recognised by law, agreement, or a business interest deserving protection. However, this legal basis constitutes a possibility rather than an obligation, unlike Processing based on legal obligations.
Processing based on legitimate interests may include, in particular:
promoting the Company's activities and products;
optimising services on the website or electronic interface and collecting information relating to the use of such services, for example through the use of cookies.
An important condition for relying on legitimate interests is that such interests must not be overridden by the interests or fundamental rights and freedoms of the Data Subject requiring the protection of Personal Data, in particular where the Data Subject is a child.
Accordingly, in every case where the legal basis of Processing is the Company's legitimate interest, the Company decides on the permissibility of the Processing on the basis of a so-called legitimate interest assessment.
The essence of the legitimate interest assessment is that the Company identifies the purpose it wishes to achieve and the possible means of achieving it, and weighs these against the rights and legitimate interests of the Data Subjects. The Company may process the data only if its legitimate interest overrides the legitimate interests of the Data Subject.
The Company documents the legitimate interest assessment in writing in all cases, and the Data Subject may request information on its findings.
The Company processes data provided directly by Data Subjects with whom it comes into contact, including during webshop order placement and fulfilment, newsletter subscription, participation in promotional games, professional correspondence, and similar interactions.
The Company also processes data published in public databases, such as data contained in company extracts of business partners or in the register of sole traders, as well as data lawfully provided by third parties.
The Company processes children's data and special categories of Personal Data only with the explicit consent of the Data Subject or of the person exercising parental responsibility, as applicable, pursuant to Article 9(2)(a) of the GDPR.
The Company does not provide data processing services as a service activity; however, this does not exclude the possibility that, in certain legal relationships, the Company may qualify as a Data Processor.
General Information on the Company's Processing Activities
The Data Controller is obliged to provide Data Subjects with information concerning the Processing of their Personal Data in a concise, transparent, intelligible, and easily accessible form, using clear and plain language.
The Company fulfils this information obligation by adopting and publishing this Policy and, in the case of certain Processing activities, by making available a concise privacy notice at the time of data collection.
If you have any questions regarding the matters described herein, or if you wish to exercise any of your rights set out in this Policy or in an individual privacy notice, please contact us.
Contact Details of the Company
The official contact details of the Company are set out at the end of this Policy.
Data Processors
The details of the Data Processors used in the course of Processing are set out at the end of this Policy. In the Special Part, for each Processing activity, the category of Data Processor related to the relevant Processing activity is briefly identified in the "Recipients" column by reference to the service provided.
A Data Processor may only be a person or undertaking that undertakes, in a written contract, to perform data processing tasks and provides sufficient guarantees to implement appropriate technical and organisational measures ensuring that the Processing complies with the requirements of the GDPR and protects the rights of Data Subjects.
The purpose and legal basis of the Processing, the data processing tasks and circumstances, including the required security measures, are determined by the Company.
The Data Processor is not entitled to use the data processed by it for its own purposes.
Data Protection Officer
Pursuant to Article 37(1) of the GDPR, the Company is not required to appoint a Data Protection Officer. If such a person is appointed, the Company shall provide appropriate information on his or her contact details.
Purposes and Legal Bases
The purpose and legal basis of each Processing activity are indicated in the Special Part. If the Processing is based on the Company's legitimate interest, the Special Part specifically identifies that legitimate interest.
Access to Personal Data and Recipients
The Special Part also indicates who has or may have access to the Personal Data processed, and to whom, for what purpose, the data are transferred, including Data Processors, authorities, or third parties. These persons and entities constitute the Recipients of the Processing.
In connection with data transfers, the Company informs Data Subjects as follows:
In the course of and for the purpose of performing its contractual obligations and enforcing its rights, the Company may transfer Personal Data processed by it, depending on the nature of the matter, to the competent courts and authorities. In addition, compliance with certain legal obligations may also involve data transfers, such as the transfer of invoice and document data to the Hungarian tax authority, reporting in the event of suspected money laundering, or disclosure during authority inspections where necessary.
The Company is entitled to transfer data to courts and authorities for the purpose of enforcing its legitimate interests, such as claims relating to unpaid invoices, claims for damages, or data necessary for making reports in cases of suspected criminal offences.
The Company is entitled to use Data Processors and service providers acting as independent Data Controllers for the performance of its obligations and the enforcement of its rights, including hosting providers, accountants, payroll providers, administrative service providers, and attorneys-at-law. The list of such service providers is set out at the end of this Policy.
The Company transfers Personal Data outside the EEA only if the country concerned is subject to an adequacy decision by the European Commission, or if the transfer takes place subject to appropriate and suitable safeguards. Data Subjects may request information from the Company at any time regarding such safeguards and may find further information on the European Commission's website:
https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en
Retention Periods
The duration of each Processing activity and the retention period for the relevant data and documents are set out in the Special Part for each Processing activity.
Where an exact retention period cannot be determined for a particular data item or document, the criteria used to determine the period are specified.
Rights of Data Subjects
As described in more detail below, the Data Subject may request from the Data Controller access to Personal Data relating to him or her, rectification or erasure of such data, or restriction of Processing, and may object to the Processing of such Personal Data. In certain cases, the Data Subject also has the right to data portability.
In the case of Processing based on consent, the Data Subject may withdraw consent at any time free of charge. Consent may be withdrawn at any time, and withdrawal shall not affect the lawfulness of Processing carried out before the withdrawal.
The Data Subject has the right to lodge a complaint with the supervisory authority.
The rights of Data Subjects relating to Processing are set out in detail in Section 1.5 below.
Obligation to Provide Data
In the course of Processing the data of Data Subjects:
where Processing is based on legislation, the obligation to provide Personal Data is prescribed by law, and in such cases Data Subjects are obliged to provide the data;
where Processing is carried out for the performance of a contractual obligation, the provision of data is based on a contractual obligation. If, in such cases, the provision of data is a prerequisite for entering into the contract, the Company indicates this separately in the Special Part;
where Processing is based on legitimate interest, the Data Subject may object to the Processing at any time. In such case, if the data can no longer be processed on another legal basis and there are no compelling legitimate grounds overriding the interests, rights, and freedoms of the Data Subject, the data shall be erased.
Rights of Data Subjects in Relation to Processing
In connection with the Company's Processing activities, you have the rights set out below.
Right of Access by the Data Subject
The Data Subject has the right to obtain from the Data Controller confirmation as to whether Personal Data concerning him or her are being processed. Where such Processing is taking place, the Data Subject has the right to access the Personal Data and the following information:
the purposes of the Processing;
the categories of Personal Data concerned;
the Recipients or categories of Recipients to whom the Personal Data have been or will be disclosed, in particular Recipients in third countries or international organisations;
where possible, the envisaged period for which the Personal Data will be stored or, if this is not possible, the criteria used to determine that period;
the existence of the Data Subject's right to request from the Data Controller rectification or erasure of Personal Data, restriction of Processing, or to object to such Processing;
the right to lodge a complaint with a supervisory authority;
where the Personal Data are not collected from the Data Subject, any available information as to their source;
whether automated decision-making, including Profiling, is carried out;
where Personal Data are transferred to a third country or to an international organisation, the right to be informed of the appropriate safeguards relating to the transfer.
Accordingly, if you wish to know whether the Company processes your Personal Data and, if so, under what circumstances, you may request information in this regard.
Upon request, the Company shall provide the Data Subject with a copy of the Personal Data undergoing Processing. For any further copies requested by the Data Subject, the Company may charge an administrative fee.
Where the Data Subject makes the request by electronic means, the information shall be provided in a commonly used electronic format, unless otherwise requested by the Data Subject.
Right to Rectification
The Data Subject has the right to obtain from the Data Controller, without undue delay, the rectification of inaccurate Personal Data concerning him or her.
Taking into account the purposes of the Processing, the Data Subject has the right to have incomplete Personal Data completed, including by means of providing a supplementary statement.
If any of your Personal Data changes, please notify us so that we can correct the data in our records.
The Data Controller shall communicate any rectification to each Recipient to whom the Personal Data have been disclosed, unless this proves impossible or involves disproportionate effort.
Upon request, the Data Controller shall inform the Data Subject of those Recipients.
Right to Erasure ("Right to Be Forgotten")
The Data Subject has the right to obtain from the Data Controller the erasure of Personal Data concerning him or her without undue delay, and the Data Controller shall be obliged to erase such Personal Data without undue delay where one of the following grounds applies:
the Personal Data are no longer necessary in relation to the purposes for which they were collected or otherwise processed, meaning that the purpose of the Processing has been achieved;
the Data Subject withdraws the consent on which the Processing is based, and there is no other legal basis for the Processing;
the legal basis of the Processing is the legitimate interest of the Data Controller and the Data Subject objects to the Processing, and there are no overriding legitimate grounds for the Processing, or the Data Subject objects to Processing for direct marketing purposes;
the Personal Data have been unlawfully processed;
the Personal Data must be erased for compliance with a legal obligation under Union or Member State law to which the Data Controller is subject, for example where erasure is ordered by an authority.
Where the Data Controller has made the Personal Data public and is obliged to erase them under the above provisions, the Data Controller shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to inform other Data Controllers processing the Personal Data that the Data Subject has requested the erasure by such controllers of any links to, or copies or replications of, those Personal Data.
The Data Controller shall not be obliged to erase the data where Processing is necessary:
for exercising the right of freedom of expression and information;
for compliance with a legal obligation requiring Processing under law applicable to the Data Controller;
in certain cases, for reasons of public interest in the area of public health;
for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, where erasure would likely render impossible or seriously impair the achievement of the objectives of that Processing;
for the establishment, exercise, or defence of legal claims.
The Data Controller shall communicate any erasure to each Recipient to whom the Personal Data have been disclosed, unless this proves impossible or involves disproportionate effort.
Upon request, the Data Controller shall inform the Data Subject of those Recipients.
Accordingly, if you believe that the conditions for erasure are met, you may request the erasure of your data at any time.
Right to Restriction of Processing
The Data Subject has the right to obtain from the Data Controller restriction of Processing where one of the following applies:
the Data Subject contests the accuracy of the Personal Data, in which case the restriction applies for a period enabling the Data Controller to verify the accuracy of the Personal Data;
the Processing is unlawful, but the Data Subject opposes the erasure of the Personal Data and requests instead the restriction of their use;
the Data Controller no longer needs the Personal Data for the purposes of Processing, but the Data Subject requires them for the establishment, exercise, or defence of legal claims;
the Data Subject has objected to Processing based on legitimate interest, in which case the restriction applies pending verification of whether the legitimate grounds of the Data Controller override those of the Data Subject.
Where Processing has been restricted as described above, such Personal Data shall, with the exception of storage, be processed only with the Data Subject's consent, or for the establishment, exercise, or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest.
The Data Controller shall inform the Data Subject before the restriction of Processing is lifted.
The Data Controller shall communicate any restriction of Processing to each Recipient to whom the Personal Data have been disclosed, unless this proves impossible or involves disproportionate effort.
Upon request, the Data Controller shall inform the Data Subject of those Recipients.
If you request restriction of Processing and your request is granted, the Data Controller's right to process your data shall be limited to storing your data, and the data may otherwise be processed only with your consent or for the purpose of enforcing legal claims.
Right to Data Portability
The Data Subject has the right to receive the Personal Data concerning him or her, which he or she has provided to a Data Controller, in a structured, commonly used, and machine-readable format, and has the right to transmit those data to another Data Controller without hindrance from the Data Controller to which the Personal Data were provided, where:
the Processing is based on the consent of the Data Subject or on the performance of a contract; and
the Processing is carried out by automated means.
In exercising the right to data portability, the Data Subject has the right to have the Personal Data transmitted directly from one Data Controller to another, where technically feasible.
Accordingly, where Processing is based on your consent or is necessary for the performance of a contract, and the data are processed by automated means, you may request that we provide the data electronically to you or to a person designated by you.
Right to Object
The Data Subject has the right to object, on grounds relating to his or her particular situation, at any time to Processing of Personal Data concerning him or her which is carried out in the public interest or based on the legitimate interest of the Company, including Profiling based on those provisions.
In such case, the Data Controller shall no longer process the Personal Data unless it demonstrates compelling legitimate grounds for the Processing which override the interests, rights, and freedoms of the Data Subject, or unless the Processing is related to the establishment, exercise, or defence of legal claims.
Where Personal Data are processed for direct marketing purposes, such as marketing or newsletters, the Data Subject has the right to object at any time to the Processing of Personal Data concerning him or her for such purposes, including Profiling to the extent that it is related to such direct marketing.
Where the Data Subject objects to Processing for direct marketing purposes, the Personal Data shall no longer be processed for such purposes.
Accordingly, where the legal basis of Processing is the Company's legitimate interest, you may object to the Processing of your data at any time.
Automated Individual Decision-Making, Including Profiling
The Data Subject has the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
The above shall not apply if the decision:
is necessary for entering into, or performance of, a contract between the Data Subject and the Data Controller;
is authorised by Union or Member State law applicable to the Data Controller, which also lays down suitable measures to safeguard the Data Subject's rights and freedoms and legitimate interests; or
is based on the Data Subject's explicit consent.
Right to Lodge a Complaint with a Supervisory Authority
Without prejudice to any other administrative or judicial remedy, every Data Subject has the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work, or the place of the alleged infringement, if the Data Subject considers that the Processing of Personal Data relating to him or her infringes the GDPR.
The supervisory authority shall investigate the subject matter of the complaint and shall inform the complainant within a reasonable period of the progress and outcome of the investigation, in particular where further investigation or cooperation with another supervisory authority is necessary.
Following the complaint, the supervisory authority is entitled to initiate proceedings against the Data Controller.
If the Data Controller does not take action on the request of the Data Subject, the Data Controller shall inform the Data Subject without delay, and at the latest within one (1) month of receipt of the request, of the reasons for not taking action and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.
The exact contact details of the Hungarian supervisory authority are set out at the end of this Policy.
Restrictions
Union or Member State law applicable to the Data Controller or Data Processor may, in certain cases, restrict the rights of Data Subjects described above by legislative measures.
Records
The Data Controller shall keep records of requests submitted by Data Subjects and of the responses given to such requests.
Judicial Enforcement, Compensation, and Damages for Non-Material Harm
The Data Subject may bring court proceedings against the Data Controller or, in relation to Processing operations falling within the scope of the Data Processor's activities, against the Data Processor, if the Data Subject considers that the Data Controller or the Data Processor engaged by or acting on behalf of the Data Controller processes his or her Personal Data in breach of the requirements laid down in legislation or in a binding legal act of the European Union concerning the Processing of Personal Data.
The Data Controller or Data Processor shall bear the burden of proving compliance with the applicable requirements.
The Data Subject may, at his or her choice, bring proceedings before the regional court having jurisdiction according to his or her place of residence or habitual residence.
A person who otherwise lacks legal capacity to be a party to litigation may also be a party to such proceedings.
The Hungarian Data Protection Authority may intervene in the proceedings in order to support the success of the Data Subject's claim.
If the Data Controller causes damage to another person by unlawfully processing the Data Subject's data or by breaching data security requirements, the Data Controller shall compensate such damage.
If the Data Controller infringes the Data Subject's personality rights by unlawfully processing the Data Subject's data or by breaching data security requirements, the Data Subject may claim damages for non-material harm from the Data Controller.
As against the Data Subject, the Data Controller shall be liable for damage caused by the Data Processor, and the Data Controller shall also be obliged to pay damages for non-material harm due to an infringement of personality rights caused by the Data Processor.
The Data Controller shall be exempt from liability for the damage caused and from the obligation to pay damages for non-material harm if it proves that the damage or infringement of the Data Subject's personality rights was caused by an unavoidable event outside the scope of Processing.
No compensation shall be payable and no damages for non-material harm may be claimed to the extent that the damage, or the infringement of rights caused by the breach of personality rights, resulted from the intentional or grossly negligent conduct of the injured party or the Data Subject.
Data Security Requirements
The Personal Data processed by the Company are stored in electronic form and/or in paper-based form.
In order to ensure data security, the Company applies appropriate organisational and technical measures.
When determining the appropriate level of security, the Company expressly takes into account the risks arising from Processing, in particular risks arising from the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to Personal Data transmitted, stored, or otherwise processed.
Data stored in electronic form are recorded on servers located at the addresses of the server service providers acting as Data Processors, as indicated at the end of this Policy, and on appropriately protected hardware devices located at the Company's registered office.
The computers and workstations used by the Company are password-protected, and access to documents is restricted on the basis of access management rules.
All computer systems of the Company are equipped with protection against malicious software.
Regular periodic backups are made of the data, with continuous overwriting.
The physical document storage room is protected against water damage, fire, and unauthorised intrusion.
Further organisational and IT security measures applied to ensure the security of electronically stored data, as well as security measures applied in relation to entry into office premises, are set out in separate internal policies and instructions.
Paper-based documents containing Personal Data are filed in accordance with separate document management rules.
Folders containing Personal Data are stored in lockable cabinets at the Company's registered office. The filing cabinet may be opened only by authorised employees.
The Data Controller ensures compliance with data security requirements through this Policy and through separate instructions and policies.
The Data Controller ensures that its employees and third parties acting within its sphere of interest, including in particular Data Processors, are familiar with the current contents of this Policy and of the separate instructions and policies, and act in accordance with them.
Data Transfers
Personal Data processed by the Company may be transferred only in the following cases and only to the following Recipients:
to a Data Processor, for the purpose of achieving the purposes of Processing;
to another specified Data Controller, for the purpose of achieving the purpose of Processing;
at the request of the Data Subject concerned by the Processing, in order to comply with the provisions of the GDPR;
to the Recipient specified by law, on the basis of a legal provision or an order issued by an authority;
where suspicion of a criminal offence or minor offence is detected, or upon request, to the investigating authority, to the authority conducting proceedings in relation to a minor offence, and to the body conducting preparatory proceedings in relation to a minor offence.
Data Processing
In order to ensure its operation, the Company uses various services, such as server service providers, postal service providers, accountants, couriers, IT service providers, and similar service providers.
Such services often involve the Processing of Personal Data.
Where such services are used, the Company qualifies as the Data Controller and the service provider qualifies as the Data Processor.
The Company may use only Data Processors that provide sufficient guarantees to implement appropriate technical and organisational measures ensuring that the Processing complies with the requirements of the GDPR and protects the rights of Data Subjects.
Within the framework of the GDPR and the specific laws applicable to Processing, the rights and obligations of the Data Processor in relation to the Processing of Personal Data are determined by the Data Controller. Accordingly, the Company determines for the Data Processor(s) what operations are to be carried out in relation to which data.
The Data Controller is responsible for the lawfulness of the instructions given.
The Data Processor may engage another Data Processor only in accordance with the instructions of the Data Controller.
The Data Processor may not make substantive decisions concerning the Processing. The Data Processor may process Personal Data that come to its knowledge only in accordance with the instructions of the Data Controller, may not process data for its own purposes, and shall store, retain, and, where necessary, erase Personal Data in accordance with the instructions of the Data Controller.
The agreement relating to data processing shall be made in writing and shall specify at least the subject matter, duration, nature, and purpose of the Processing, the type of Personal Data, the categories of Data Subjects, and the obligations, rights, and liability of the Data Controller under the GDPR.
The detailed data of the Data Processors used by the Company are set out at the end of this Policy.
The server service provider and the IT service provider used by the Company have access, within their respective areas of responsibility and solely to the extent necessary for the performance of their tasks, to all electronically recorded data. Accordingly, these service providers are not separately indicated among the Recipients of Processing in the Special Part.
2. SPECIAL PART
Processing Activities Related to the Operation of the Vitaltier Webshop (www.vitaltier.eu), Purchases Made in the Webshop, and Services Provided Therein
The purpose of operating the Vitaltier.eu webshop is the sale of Vitaltier and other products in Hungary.
The provision of certain Personal Data is indispensable for purchases made in the webshop, as it is only through such data that customers can be identified and distinguished, ordered products can be delivered, services can be provided, invoices can be issued, payments can be processed, and, where necessary, complaints and guarantee or warranty claims can be handled.
The provision of data is voluntary, meaning that you are not obliged to provide such data. However, without the provision of data that are indispensable for entering into the contract, delivery, and invoicing, you will not be able to make purchases in the webshop. The provision of such data is a prerequisite for entering into the contract.
The use of convenience functions is also voluntary. If the relevant data are not provided, the User will not be able to use the convenience functions; however, orders may still be placed without using such functions.
No prior registration is required for purchases in the webshop. It is sufficient to provide the necessary data when placing the order.
If you intend to make purchases repeatedly, registration allows you to create your own account and save your Personal Data and previous purchase data. In such cases, during subsequent purchases, access to your own account data is possible following individual password authentication.
Registration is not a prerequisite for making purchases; it is merely a convenience option.
The Data Controller may send marketing messages, organise promotions, and provide discounts to registered customers.
The Data Subject may delete the registration/account at any time after logging in, under the Profile menu.
Confirmation e-mails are sent in respect of orders in accordance with the applicable legal provisions.
The purchase price of ordered products may be paid by bank card through a secure online payment interface provided by a third party or, in the absence thereof, by cash on delivery.
Ordered products are delivered using courier services.
|
Description of Processing |
Categories of Personal Data Processed |
Purpose of Processing |
Legal Basis |
Source of Data |
Recipients |
|
Vitaltier.eu webshop – Data processed during order placement |
SurnameFirst nameResidential addressTelephone numberE-mail addressOrder numberOrder details (ordered products, quantities, purchase price, payable fees, discounts)Date of orderLog files relating to acceptance of the Terms and Conditions and Privacy Notice |
Conclusion of the contract, online sale of products, identification of the customer and communication with the customer, mandatory order confirmation |
Necessary for the performance of a contract (Article 6(1)(b) GDPR); mandatory order confirmation: compliance with a legal obligation (Article 6(1)(c) GDPR, Section 18 of Government Decree 45/2014) |
Data Subject |
Website hosting and software service provider (Data Processor)Fulfilment service provider (Data Processor) |
|
|
Shipping data:SurnameFirst nameDelivery addressTelephone numberE-mail addressOrder numberInformation provided in the comments field |
Performance of the contract, delivery of orders |
Necessary for the performance of a contract (Article 6(1)(b) GDPR) |
Data Subject |
Website hosting and software service provider (Data Processor)Fulfilment service provider (Data Processor)Courier service provider (independent Data Controller) |
|
|
Billing data:SurnameFirst nameResidential addressInvoice data required by lawThe invoice is sent to the e-mail address provided during the order process |
Issuance and delivery of invoices |
Compliance with a legal obligation (Article 6(1)(c) GDPR); Accounting Act Sections 165–169; VAT Act Sections 159 and 169 |
Data Subject |
Website hosting and software service provider (Data Processor)Invoicing service provider (Data Processor)Accountant (Data Processor)National Tax and Customs Administration (NAV) as independent Data Controller |
|
Vitaltier.eu webshop – Registration / Account Creation |
SurnameFirst nameE-mail addressTelephone numberPassword (stored in encrypted form)Residential addressDelivery detailsBilling informationPrevious order history |
Convenience service, facilitating future purchases, storing purchase history, marketing activities |
Consent of the Data Subject (Article 6(1)(a) GDPR), given by activating the function and setting the required password |
Data Subject |
Website hosting and software service provider (Data Processor)Communication management service provider (Data Processor) |
|
Vitaltier.eu – Secure Online Payment (Stripe / SimplePay) |
SurnameFirst name |
Providing a secure payment interface and tracking payment transactions |
Consent of the Data Subject (Article 6(1)(a) GDPR), given by using the payment function |
Data Subject |
Website hosting and software service provider (Data Processor)Payment service provider |
|
Vitaltier.hu webshop – Cash on Delivery Payment |
SurnameFirst nameDelivery addressE-mail addressTelephone numberOrder numberAmount payablePayment method (cash or bank card)Date of payment |
Collection and settlement of amounts due where online payment is not used |
Necessary for the performance of a contract (Article 6(1)(b) GDPR) |
Data Subject |
Website hosting and software service provider (Data Processor)Fulfilment service provider (Data Processor)Courier service provider (independent Data Controller)Accountant (Data Processor) |
|
Vitaltier.eu webshop – Automatic Order Receipt Confirmation |
Order numberSurnameFirst nameE-mail addressTelephone numberOrder details |
Providing legally required information |
Compliance with a legal obligation (Article 6(1)(c) GDPR; Section 18 of Government Decree 45/2014) |
Data Subject |
Website hosting and software service provider (Data Processor) |
|
Vitaltier.eu webshop – Order Confirmation |
Order numberSurnameFirst nameE-mail addressTelephone numberOrder detailsExpected delivery date |
Confirmation of acceptance of the order |
Performance of a contract (Article 6(1)(b) GDPR) |
Data Subject |
Website hosting and software service provider (Data Processor)Fulfilment service provider (Data Processor) |
Retention Periods
Data provided during the ordering process, as well as data and documents related to the fulfilment of the order (including order confirmations, delivery documents, and payment-related records and documents), are retained for 5 years following fulfilment of the order (general limitation period).
Invoices issued in relation to orders are retained until the last day of the eighth year following the year of issuance of the invoice.
Data provided during registration/account creation are processed until the withdrawal of consent (deletion of the account).
Consent may be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of processing carried out prior to the withdrawal.
Customer Service and Communication
The Company maintains customer support services available by telephone and e-mail and operates a contact form on its website (inquiries received through the contact form are answered by e-mail). We kindly ask that you contact us primarily through these channels with any inquiries, complaints, or questions.
Customer support receives both inquiries and complaints and responds to them whenever possible without delay.
If any complaint, warranty claim, or statutory guarantee claim arises in connection with the Company's products and is submitted directly to the Company as distributor, the Company records the complaint in a report, investigates it, and informs the complainant of the outcome.
|
Description of Processing |
Categories of Personal Data Processed |
Purpose of Processing |
Legal Basis |
Source of Data |
Recipients |
|
Receiving and Responding to Inquiries – Telephone Customer Service |
No Personal Data are required when inquiring about our products and services. If the Data Subject voluntarily discloses any information (e.g. caller ID, name during introduction), such data are processed solely for the purpose of answering the inquiry and are not separately stored or retained. |
Receiving and responding to inquiries |
Consent of the Data Subject, provided by calling the customer service telephone number |
Data Subject |
– |
|
Receiving and Responding to Inquiries – E-mail Customer Service |
No Personal Data are required when inquiring about our products and services. However, in the case of e-mail inquiries, the Company necessarily processes the e-mail address, metadata relating to the e-mail transmission, the content of the e-mail, and any additional data voluntarily provided by the Data Subject (e.g. telephone number for a callback request, name provided during introduction). |
Receiving and responding to inquiries |
Consent of the Data Subject, provided by sending the inquiry |
Data Subject |
E-mail service provider (Data Processor) |
|
Receiving and Responding to Inquiries – Website Contact Form |
Name (optional)E-mail address (required)Telephone number (optional)Message contentDate of submissionLog files relating to message submission and consent to processing (checkbox selection) |
Receiving and responding to inquiries |
Consent of the Data Subject, provided through submission of the form and consent checkbox |
Data Subject |
Website hosting and software service provider (Data Processor)E-mail service provider (Data Processor) |
|
Complaint Handling and Warranty / Statutory Guarantee Claims |
NameResidential addressDetails of the complaint or warranty/statutory guarantee claim as required by law |
Handling complaints and warranty/statutory guarantee claims |
Legal obligation:Complaint handling: Section 17/A of the Consumer Protection ActWarranty/statutory guarantee claims: Section 4(1)(a) of NGM Decree 19/2014 (IV.29.) |
Data Subject |
– |
|
|
E-mail addressTelephone number |
Communication during complaint handling and enforcement of warranty/statutory guarantee claims |
Consent of the Data Subject, provided by making the data available |
Data Subject |
E-mail service provider (Data Processor) |
Where Processing is based on consent, consent may be withdrawn at any time. Withdrawal of consent does not affect the lawfulness of Processing carried out before such withdrawal.
Processing Related to the Exercise of the Right of Withdrawal
Pursuant to Government Decree 45/2014, consumers are entitled to exercise a right of withdrawal. The consumer may exercise this right by using the model withdrawal form contained in Annex 2 of the Decree or by submitting a clear statement of withdrawal, in accordance with the Terms and Conditions.
|
Description of Processing |
Categories of Personal Data Processed |
Purpose of Processing |
Legal Basis |
Source of Data |
Recipients |
|
Withdrawal Declarations |
NameResidential addressData relating to the product affected by the withdrawalDate of receipt of the productBank account number (where necessary if the refund is made by bank transfer)Date and signature in the case of paper-based declarations |
Documentation of withdrawals |
Legal obligation: Section 20 of Government Decree 45/2014 |
Data Subject |
E-mail service provider (Data Processor) for declarations submitted by e-mail and related communicationsAccountant (Data Processor) |
|
Credit Notes (Storno Invoices) Issued in Connection with Withdrawal |
Billing data |
Accounting and documentation of withdrawal |
Legal obligation:Accounting Act Sections 165–169VAT Act Sections 159 and 169 |
Internal invoicing records of the Data Controller |
Invoicing service provider (Data Processor)Accountant (Data Processor)National Tax and Customs Administration (NAV) as independent Data Controller |
Retention Periods
Withdrawal declarations are retained for 5 years from the date of communication of the withdrawal (general limitation period).
Credit notes are retained until the last day of the eighth year following the year of issuance.
Webshop Newsletter
The Company regularly sends newsletters containing news, information, and promotional offers relating to products sold in the webshop to Data Subjects who subscribe to the newsletter and voluntarily provide the data necessary for this purpose.
Subscription to the Newsletter is available both during the ordering process and separately through the "Newsletter" section of the website.
Newsletter subscription is entirely voluntary. Failure to subscribe only results in the customer not receiving direct marketing communications and not being informed about promotions, events, or special offers.
|
Description of Processing |
Categories of Personal Data Processed |
Purpose of Processing |
Legal Basis |
Source of Data |
Recipients |
|
Webshop Newsletter |
NameE-mail addressLog files relating to newsletter subscription and consent to Processing (checkbox selection) |
Sending newsletters |
Consent of the Data Subject, provided by selecting the subscription checkbox |
Data Subject |
Website hosting and software service provider (Data Processor) |
Retention Period
Data processed in connection with newsletter distribution are retained until the withdrawal of consent.
Customer Product Reviews
Users may submit product reviews through the Reviews section of the Website. Reviews relate to specific products rather than to the webshop itself.
Submission of a review requires the provision of a name and e-mail address. The Data Controller verifies the name and e-mail address of the reviewer against its database of completed orders and accepts reviews only where the reviewer can be identified as a verified purchaser.
Reviews may be submitted both as a star rating on a five-star scale and as free-text comments. The Company may respond to reviews and publish them on the Website. When published, the reviewer's name will be displayed alongside the review.
Providing a review is entirely voluntary and failure to do so has no adverse consequences for the Data Subject.
|
Description of Processing |
Categories of Personal Data Processed |
Purpose of Processing |
Legal Basis |
Source of Data |
Recipients |
|
Product Reviews |
NameE-mail addressLog files relating to submission of the review and consent to processing (checkbox selection) |
Administration and publication of product reviews |
Consent of the Data Subject, provided by selecting the checkbox displayed on the review form |
Data Subject |
Website hosting and software service provider (Data Processor) |
Reviews are published publicly on the Website and therefore become accessible to an indeterminate number of recipients.
Data relating to reviews are processed until consent is withdrawn. Upon withdrawal of consent, the relevant review will be removed from the published reviews section.
Personalized Marketing Messages and Notifications
The Company offers the possibility of receiving personalized marketing communications. These communications may include additional information relating to purchased products and related products, notifications based on the expected consumption period of previously purchased products, individual discount coupons, personalized promotional offers, and information regarding promotional campaigns and games.
Subscribers to Personalized Marketing Messages will also receive the information described under the Webshop Newsletter section above.
Subscription to Personalized Marketing Messages takes place at the end of the purchasing process by selecting the relevant checkbox. Subscription is entirely voluntary. Failure to subscribe has no consequences other than not receiving personalized communications.
The Data Controller sends personalized communications only where the Data Subject has expressly indicated such preference through the relevant checkbox.
This Processing involves automated profiling based on purchasing data. In this context, conclusions are drawn from purchasing behavior, including purchasing habits, loyalty to products, expected timing of future purchases, and customer satisfaction, for the purpose of providing relevant information, promotional offers, discounts, and participation opportunities in promotional campaigns.
|
Description of Processing |
Categories of Personal Data Processed |
Purpose of Processing |
Legal Basis |
Source of Data |
Recipients |
|
Personalized Marketing Messages |
NameE-mail addressPurchase data, including characteristics of purchased products, quantities, purchase values, purchase dates, and conclusions generated by automated systems based on such data |
Sending personalized marketing communications |
Consent of the Data Subject pursuant to Article 6(1)(a) GDPR; for profiling activities, Article 22(2)(c) GDPR |
Data Subject |
Website hosting and software service provider (Data Processor) |
Data relating to personalized marketing communications are processed until consent is withdrawn. Consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
Processing of Business Partners' and Suppliers' Data
In connection with its business activities, the Company processes the personal data of persons with whom it maintains or intends to establish a business relationship, including representatives of legal entities, for the purposes of entering into and performing contracts and fulfilling related obligations, including delivery and procurement arrangements, invoicing, payment processing, complaint handling, and warranty or guarantee administration.
Data contained in contracts concluded with business partners are processed through both paper-based filing at the Company's registered office and electronic storage on hosting infrastructure provided by the Company's service providers.
|
Description of Processing |
Categories of Personal Data Processed |
Purpose of Processing |
Legal Basis |
Source of Data |
Recipients |
|
Processing Data of Individual Contractual Partners |
NameResidential address / registered officeSole trader registration number, tax number or tax identification numberBusiness card information (where applicable)Bank account details (where necessary) |
Identification of the contracting party and performance of the contract |
Necessary for entering into and performing a contract pursuant to Article 6(1)(b) GDPR |
Data Subject |
Accountant (Data Processor) |
|
|
E-mail addressTelephone numberWhere a contact person is designated:• Name• E-mail address• Telephone number• Position• Business card information (where applicable) |
Communication with the contractual partner |
Necessary for entering into and performing a contract pursuant to Article 6(1)(b) GDPR |
Data Subject; where a separate contact person is designated, the contractual partner |
Accountant (Data Processor) |
|
|
Invoicing data |
Issuance of accounting documents |
Legal obligation pursuant to the Accounting Act Sections 165–169 and VAT Act Sections 159 and 169 |
Data Subject |
Accountant (Data Processor)Invoicing service provider (Data Processor)NAV as independent Data Controller |
|
Processing Data of Legal Entity Contractual Partners |
Name of the representative of the legal entityPositionBusiness card information (where applicable) |
Identification of the contracting party and performance of the contract |
Necessary for entering into and performing a contract pursuant to Article 6(1)(b) GDPR |
Data Subject |
Accountant (Data Processor) |
|
|
Name of contact personE-mail addressTelephone numberPositionBusiness card information (where applicable) |
Communication with the contractual partner |
Legitimate interest in maintaining communication through the contractual partner's designated contact person pursuant to Article 6(1)(f) GDPR |
Data Subject, or where different from the representative, the legal entity's representative |
Accountant (Data Processor) |
Provision of the relevant data is a prerequisite for entering into a contract.
Retention Periods
Customer and business relationship data are retained for 5 years following termination of the contractual relationship (general limitation period).
Accounting documents issued in connection with the contractual relationship are retained for 8 years from the last day of the year in which the document was issued.
The Company does not accept cash payments reaching or exceeding HUF 3 million (payment is accepted exclusively by bank transfer). Accordingly, the Company is generally not required to perform customer due diligence under the Anti-Money Laundering Act (Pmt.). Should such an obligation arise, the Company will provide separate information regarding the applicable identification requirements.
Cookie Management
A cookie is a small file (information package) that may be placed on the device used for browsing when a Data Subject visits a website. Cookies allow the collection of certain information about visitors and the recording of browsing habits.
In general, cookies may facilitate the use of a website, help provide relevant information to visitors, and enable website operators to monitor the operation of the website, including the prevention of misuse and ensuring the proper functioning of services available on the website.
When accessing the Vitaltier website, cookies may automatically be stored on the visitor's device if permitted by the browser settings used by the Data Subject or if expressly accepted during the first visit to the Website.
The use of cookies is voluntary. Cookies may generally be disabled through the browser's settings menu under privacy and/or cookie settings. In addition, when visiting the Website for the first time, a pop-up notice informs visitors about the use of cookies and enables cookie preferences to be configured.
A detailed description of the cookies used by the Data Controller is available in the Cookie Notice accessible through the cookie preference center and in the Website footer.
Information regarding cookie settings for popular browsers can be found at:
Google Chrome
Mozilla Firefox
Microsoft Edge
Safari
|
Description of Processing |
Categories of Personal Data Processed |
Purpose of Processing |
Legal Basis |
Source of Data |
Recipients |
|
Cookie Management |
As specified in the Cookie Notice |
Operation and management of cookies |
Legitimate interest pursuant to Article 6(1)(f) GDPR for ensuring the optimal operation of the Website and analysing consumer behaviour.For cookies requiring consent: consent of the Data Subject pursuant to Article 6(1)(a) GDPR, provided through the cookie settings interface. |
Data Subject |
In the case of third-party cookies, the relevant cookie provider |
Other Data Processing Activities
The Data Controller may carry out data processing activities that are not specifically described in this Privacy Policy.
In such cases, Data Subjects will always be informed prior to the commencement of the relevant processing activity, and such processing shall also be subject to the provisions of this Privacy Policy.
3. Important Information
Data Controller Information
TCoDo Service Limited Liability Company (TCoDo Kft.)
Registered Office:
1029 Budapest, Köztársaság utca 34. Door 26, Hungary
Tax Number:
13839002-2-41
Company Registration Number:
01-09-188969
Registering Authority:
Company Court of the Metropolitan Court of Budapest
Telephone:
+36 70 866 52 22
E-mail:
Managing Director:
Peter Marie Sterck
Data Processors and Other Data Controllers
Website Hosting and Software Provider (Data Processor)
Shopify International Limited
Address:
2nd Floor Victoria Buildings,
1-2 Haddington Road, Dublin 4, D04 XN32, Ireland
Registration Number:
560279
E-mail:
E-mail Service Provider (Data Processor)
Microsoft Corporation
Address:
One Microsoft Way, Redmond, WA 98052-6399, United States
Telephone:
+1 (800) 642-7676
Contact information is available through Microsoft's website.
Accounting and Bookkeeping Service Provider (Data Processor)
GP Audit Kft.
Address:
9024 Győr, Babits Mihály u. 3, Hungary
Registration Number:
08-09-008532
Telephone:
+36 96 618 528
E-mail:
Invoicing Service Provider (Data Processor)
Billingo Technologies Zrt.
Address:
1133 Budapest, Árbóc utca 6., 1st Floor, Hungary
E-mail:
Telephone:
+36 1 500 9491
Company Registration Number:
01-10-140802
Tax Number:
27926309-2-41
Hosting Provider:
Amazon Web Services EMEA SARL
38 Avenue John F. Kennedy, L-1855 Luxembourg
Delivery and Logistics Service Providers (Independent Data Controllers)
WEBSHIPPY Magyarország Kft.
Address:
2151 Fót, 0221/12, Hungary
Company Registration Number:
13-09-213880
Tax Number:
25569421-2-13
E-mail:
Telephone:
+36 1 99 88 099
Website:
GLS General Logistics Systems Hungary Kft.
Address:
2351 Alsónémedi, GLS Európa u. 2, Hungary
Company Registration Number:
13-09-111755
Telephone:
+36 29 88 66 70
E-mail:
FoxPost Zrt.
Address:
3200 Gyöngyös, Batsányi János utca 9, Hungary
Company Registration Number:
10-10-020309
Telephone:
+36 1 999 0369
E-mail:
Magyar Posta Zrt.
Address:
1138 Budapest, Dunavirág utca 2-6, Hungary
Company Registration Number:
01-10-042463
Telephone:
+36 1 767 8200
E-mail:
Online Payment Service Provider
SimplePay
The SimplePay Online Payment System is developed and operated by OTP Mobil Ltd., a member of the OTP Group.
Supervisory Authority
National Authority for Data Protection and Freedom of Information (NAIH)
Registered Office:
1055 Budapest, Falk Miksa utca 9-11, Hungary
Postal Address:
1363 Budapest, P.O. Box 9, Hungary
Telephone:
+36 1 391 1400
Fax:
+36 1 391 1410
E-mail:
Version 01 of this Privacy Policy is effective from 1 May 2024 until revoked or amended.
The Company reserves the right to amend this Privacy Policy.
The Company provides information regarding this Privacy Policy and its interpretation electronically. Questions relating to this Privacy Policy may be submitted to: