Privacy Policy
PURPOSE OF THIS POLICY The purpose of this Policy is to set forth the data protection and processing principles applied by Belső és Társa Kft. (“Company”)Details
PURPOSE OF THE POLICY
The purpose of this Policy is to lay down the data protection and data processing principles and the privacy policy applied by Belső és Társa Kft. (“Company”), which the Company recognizes as binding upon itself. When formulating these rules, the Company took into particular account the provisions of Act CXII of 2011 on the Right to Informational Self-Determination and on Freedom of Information (“Info Act”), Act CXIX of 1995 on the Processing of Name and Address Data Serving the Purpose of Research and Direct Marketing, Act VI of 1998 on the Promulgation of the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, signed in Strasbourg on January 28, 1981, Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities, as well as the recommendations of the “ONLINE PRIVACY ALLIANCE”. The purpose of this Policy is to ensure that across all areas of services provided by the Company, every individual—regardless of nationality or place of residence—has their rights and fundamental freedoms, particularly their right to privacy, respected during the automated processing of their personal data (data protection). Belső és Társa Kft. data protection and data processing registration numbers:
DEFINITIONS
Personal data: data that can be associated with a specific natural person (hereinafter referred to as "data subject"), in particular the name, identification mark, as well as one or more factors specific to the physical, physiological, mental, economic, cultural, or social identity of the data subject, including any inference regarding the data subject that can be drawn from the data. Personal data retains this quality during data processing as long as its connection to the data subject can be restored;
Data file: the totality of data managed in a single register;
Data processing: any operation or set of operations performed on data, regardless of the procedure applied, in particular the collection, recording, registration, organization, storage, alteration, use, retrieval, transmission, disclosure, alignment or combination, blocking, erasure, and destruction of personal data, as well as preventing the further use of data;
Data controller: Belső és Társa Kft. (registered office: H-1152 Budapest, Rákosmező u. 6.);
Data processing operations (sub-processing): the performance of technical tasks related to data processing operations, regardless of the method and means used to perform the operations and the place of application, provided that the technical task is performed on the data;
Data destruction: the complete physical destruction of the data medium containing the data;
Data transfer: making Personal Data accessible to a specified third party;
Disclosure: making Personal Data accessible to anyone;
Data processor: the natural or legal person, or organization without legal personality, that processes personal data on behalf of the data controller;
Data erasure: making data unrecognizable in such a way that its recovery is no longer possible;
Automated data file: a series of data to be processed automatically;
Automatic processing: includes the following operations where they are carried out in whole or in part by automated means: storage of data, logical or arithmetical operations with data, alteration, erasure, retrieval, and dissemination of data;
User: the natural person who registers on any of the Company's websites.
SCOPE OF PERSONAL DATA PROCESSED
- Data provided based on the User's choice: email address, phone number, name, place of residence/stay.
- Data technically recorded during the operation of the system: data of the User's logging-in computer generated during the use of the service, which are recorded by the Data Controller's system as an automatic result of technical processes. The automatically recorded data are logged automatically by the system upon login and logout, without any separate declaration or action by the User. These data cannot be linked with other user Personal Data—except in cases mandated by law. Access to these data is restricted exclusively to the Data Controller.
- In order to provide customized service, the Company places a small data packet (a so-called "cookie") on the User's computer. The purpose of the cookie is to ensure the highest possible quality of operation for the given page in order to enhance the user experience. The User is able to delete the cookie from their own computer and can configure their browser to disable the use of cookies. By disabling the use of cookies, the User acknowledges that without cookies, the functionality of the given page is not fully guaranteed.
LEGAL BASIS, PURPOSE, AND METHOD OF DATA PROCESSING
- Data processing is carried out on the basis of the voluntary, informed declaration of Users accessing the online content available on the websites of Belső és Társa Kft. This declaration includes the Users' explicit consent to the use of their Personal Data disclosed during the use of the site. The legal basis for Data Processing is the voluntary consent of the data subject pursuant to Section 5 (1) a) of Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information.
- The purpose of Data Processing is to ensure the provision of services available under the given URL on the websites of Belső és Társa Kft. The scope of Personal Data required to be provided for the use of these services can be found in the description of the relevant services.
- The purpose of the automatically recorded data (see Section 3.2) is to ensure the provision of services accessible through the Company's websites, to display personalized content and advertisements, to compile statistics, to execute technical developments of the IT system, and to protect users' rights. Data made available by Users during the use of the service may be used by the Data Controller to form user groups and to display targeted content and/or advertisements to these user groups on the Company's websites.
- The Data Controller shall not use the provided Personal Data for purposes other than those specified in these points. The release of Personal Data to third parties or authorities—unless otherwise mandated by law—is possible exclusively with the User's prior, explicit consent.
-
The Data Controller does not verify the Personal Data provided to it. The person providing the data is solely responsible for the accuracy and correctness of the data provided. Upon providing their email address, any User assumes responsibility that they are the sole individual using services from the specified email address. In light of this assumption of responsibility, any and all liability associated with logins made using a specified email address shall rest exclusively with the user who registered that email address.
PRINCIPLES OF DATA PROCESSING
- Personal Data may only be obtained and processed fairly and lawfully.
- Personal Data may only be stored for specified and lawful purposes, and may not be used in a manner incompatible with those purposes.
- Personal Data must be proportionate to and adequate for the purpose of their storage, and must not exceed that purpose.
- Personal Data must be stored in a form that permits identification of the data subject User for no longer than is necessary for the purpose for which the data are stored.
- Appropriate security measures must be taken for the protection of Personal Data stored in automated data files to prevent accidental or unlawful destruction, accidental loss, as well as unauthorized access, alteration, or dissemination.
DATA PROTECTION PRINCIPLES APPLIED BY THE COMPANY
- The Personal Data strictly necessary for the use of the services of Belső és Társa Kft. shall be used by the Company on the basis of the consent of the data subjects and exclusively for specified purposes.
- The Company, as Data Controller, undertakes to process the Personal Data that comes into its possession in accordance with the provisions of the Info Act and the data protection principles set forth in this Policy, and shall not transfer such data to third parties. With respect to data transfer, exceptions to the provisions in this point include the use of data in a statistically aggregated form, which may not contain in any form the name of the user concerned or any other data suitable for identification, as well as further exceptions regarding data transfers set out in Section 10.3 of this Policy. In certain cases—upon official requests from courts or the police, legal proceedings due to copyright, property, or other infringements, or the reasonable suspicion thereof, prejudice to the interests of the Company, endangerment of the provision of its services, etc.—the Company shall make the available data of the User concerned accessible to third parties.
- In certain cases—upon official requests from courts or the police, or in connection with legal proceedings resulting from copyright, property, or other infringements or the reasonable suspicion thereof, prejudice to the interests of the Company, or the endangerment of the provision of its services, etc.—the Company shall make the available data of the User concerned accessible to third parties.
- The system of Belső és Társa Kft. may collect data on the activity of Users, which cannot be linked to the Personal Data provided by Users during registration, nor to data generated through the use of other websites or services.
- The Company undertakes to publish a clear, prominent, and unambiguous notice prior to the collection, recording, or processing of any Personal Data of its Users, informing them of the method, purpose, and principles of data collection. In addition to all of the above, in every case where the collection, processing, or recording of data is not required by law, the Company shall draw the user's attention to the voluntary nature of the provision of data. In the event of mandatory provision of data, the statutory provision ordering the Data Processing must also be specified. The data subject shall be informed of the purpose of the Data Processing and of the entities that will manage or process the Personal Data. Provision of information regarding the Data Processing shall also be deemed to have occurred if a statutory provision provides for the collection of data from an existing Data Processing activity by means of transfer or interconnection.
- In every case where the Company intends to use the provided Personal Data for a purpose other than the original purpose of data collection, it shall inform the User thereof, obtain their prior explicit consent thereto, and provide them with the opportunity to prohibit such use.
- Belső és Társa Kft., as Data Controller, shall in all cases comply with the limitations laid down by statutory provisions during the collection, recording, and processing of data, and shall inform the data subject of its activities by email upon their request. The Company undertakes not to enforce any sanctions against a User who refuses to provide non-mandatory data.
- Belső és Társa Kft. undertakes to ensure the security of Personal Data, to implement the technical and organizational measures, and to establish the procedural rules that ensure the protection of collected, stored, or processed Personal Data, as well as to prevent their destruction, unauthorized use, and unauthorized alteration. It also undertakes to call upon every third party to whom it may transfer or hand over Personal Data to fulfill their obligations in this regard.
- If the Personal Data is inaccurate and the accurate Personal Data is available to the Data Controller, the Data Controller shall rectify the personal data.
- The Company, as the Data Controller, shall erase the Personal Data if (i) its processing is unlawful; (ii) the User requests the erasure of their Personal Data; (iii) the Personal Data is incomplete or incorrect and this state cannot be lawfully remedied, provided that erasure is not precluded by law; (iv) the purpose of data processing has ceased to exist, or the statutory deadline for storing the Personal Data has expired; or (v) the erasure of the Personal Data has been ordered by a court or authority.
- Instead of erasure, the Data Controller shall restrict (lock) the Personal Data if the data subject so requests or if, based on the available information, it can be assumed that erasure would harm the legitimate interests of the data subject. Personal Data restricted in this manner may only be processed for as long as the data processing purpose that precluded the erasure of the Personal Data continues to exist.
- The data subject and all recipients to whom the Personal Data was previously transmitted for data processing purposes must be notified of the rectification, restriction (blocking), marking, and erasure. The Data Controller may omit this notification if, considering the purpose of data processing, it does not infringe the legitimate interests of the User.
- If the Company, acting as the Data Controller, fails to comply with the data subject's request for rectification, restriction, or erasure, it shall inform the User in writing within 30 days of receipt of the request of the factual and legal grounds for the refusal of the request for rectification, restriction, or erasure, as well as the fact that the User may appeal against the decision of the Data Controller to a court or the National Authority for Data Protection and Freedom of Information.
DURATION OF DATA PROCESSING
- The processing of Personal Data provided by the User shall continue until the User unsubscribes from the service using the given username. The date of erasure shall be 10 working days from the receipt of the User's unsubscription request (request for erasure). In the event of unlawful or misleading use of Personal Data, or in the event of a criminal offense or system attack committed by the User, the Data Controller shall be entitled to erase the User's data immediately upon the termination of the registration; furthermore, in the event of a suspected criminal offense or civil liability, the Data Controller shall also be entitled to retain the Personal Data for the duration of the proceedings to be conducted.
- The Personal Data provided by the User—even if the User does not unsubscribe from the service—may be processed by the Company, as the Data Controller, until the User expressly requests in writing the termination of such processing. A request by the User to terminate data processing without unsubscribing from the service shall not affect their right to use the service; however, in the absence of Personal Data, certain services (e.g., auctions, leaderboards) may no longer be available to them. The erasure of Personal Data shall take place within 10 working days of receipt of the request to that effect.
- Data automatically and technically recorded during the operation of the system shall be stored in the system for a period justified for the purpose of ensuring the operation of the system, calculated from the time of their generation. The Company shall ensure that these automatically recorded data cannot be linked to other User Personal Data, except in cases mandated by law. If the User has withdrawn their consent to the processing of their Personal Data or has unsubscribed from the service, their identity will no longer be identifiable from the technical data thereafter.
DISPOSITION OF PERSONAL DATA
- Changes in Personal Data or requests for the erasure of Personal Data may be communicated by means of an explicit written statement sent via the service's internal messaging system. Newsletters can be unsubscribed from by modifying the user interface settings on the website.
- In addition, certain Personal Data may be modified by making changes on the page containing the personal profile.
- Following the fulfillment of a request for the erasure or modification of Personal Data, the previous (erased) data can no longer be restored.
DATA PROCESSING
- The Company may engage a data processor for the purpose of ensuring the continuous and proper operation of the website, fulfilling orders, and performing other activities closely related to the provision of webshop services.
-
Designation of data processors engaged by the Company:
GLS General Logistics Systems Hungary Kft. 2351 Alsónémedi, GLS Európa u. 2. Package delivery
TNT Express Hungary Kft. 1097 Ecseri út 97. Package delivery
POSSIBILITY OF DATA TRANSFER
- The Company, as the Data Controller, is entitled and obliged to transfer all Personal Data available to it and stored by it in a lawful manner to the competent authorities, provided that such data transfer is required by law or a final and binding official obligation. The Data Controller cannot be held liable for such data transfer or for any consequences arising therefrom.
- If the Company transfers the operation or utilization of the content service available on the belso.hu website, in whole or in part, to a third party, it may transfer the Personal Data managed by it to such third party for further processing in full, without requesting separate consent. This data transfer shall serve exclusively to ensure the continuity of the registration of already registered Users, but it may not place the User in a more disadvantageous position regarding the data processing and data security rules specified in the text of these Data Protection Regulations in force at any given time.
- Certain personal data of Users may be transferred for specific purposes, based on the explicit and unambiguous consent of the User, as follows:
- the Company may transfer the Users' name, telephone number, country, and e-mail address for the purposes of customer support assistance, transaction confirmation, and fraud monitoring carried out for the protection of Users. The personal data transferred in this manner shall be processed by the respective company in accordance with its own privacy and data protection policy.
- The Company shall transmit the personal data and order data of the Users recorded during registration exclusively to the courier companies for the purpose of delivering the ordered packages, and these companies shall process such data in accordance with their own privacy and data protection policies.
- The Company shall maintain a data transfer registry for the purpose of verifying the legality of the data transfer and informing the data subject, which registry shall contain the date of the transfer of the Personal Data managed by it, the legal basis and the recipient of the data transfer, the definition of the scope of the transmitted Personal Data, as well as any other data specified in the legislation prescribing the data processing.
AMENDMENT OF THE DATA PROTECTION REGULATIONS
Belső és Társa Kft. reserves the right to amend these Data Protection Regulations at any time by its unilateral decision. Following any amendment to the Data Protection Regulations, all Users shall be notified in an appropriate manner (via newsletter, popup window upon login). By continuing to use the service, Users acknowledge the modified data processing rules, and no further consent from them is required.
- Users may request information from the Company, as the Data Controller, regarding the processing of their personal data at any time in writing, by means of a registered letter or a letter with a return receipt requested sent to the Data Controller's address (H-1152 Budapest, Rákosmező u. 6.), or via an e-mail sent to the belso@belso.hu e-mail address. An information request sent via e-mail shall only be considered authentic by the Data Controller if it is sent from the User's registered e-mail address. The request for information may cover the user's data processed by the data controller, the source of such data, the purpose, legal basis, and duration of the data processing, the name and address of any data processors, the activities related to the data processing, and, in the event of the transfer of Personal Data, who has received or is receiving the User's data and for what purpose.
- The Data Controller is obliged to provide information in writing regarding any question related to data processing within the shortest possible time from receipt, but at the latest within 30 days. In the case of an e-mail, the date of receipt shall be considered the first business day following dispatch.
- The affected User and all persons to whom the data was previously transmitted for data processing purposes must be notified of the rectification, restriction (blocking), or erasure of the processed Personal Data. Such notification may be omitted if, considering the purpose of the data processing, it does not violate the legitimate interest of the data subject.
- The User may object to the processing of their Personal Data,
- if the processing or transfer of Personal Data is necessary solely for compliance with a legal obligation to which the Data Controller is subject, or for the enforcement of the legitimate interests of the Data Controller, the data recipient, or a third party;
- if the use or transfer of Personal Data is for direct marketing, public opinion polling, or scientific research purposes; as well as
- in other cases specified by law.
If the Company establishes the well-foundedness of the data subject's objection, it shall terminate the data processing—including any further data collection and data transfer—and block the Personal Data, as well as notify all parties to whom the Personal Data affected by the objection was previously transmitted of the objection and the measures taken on the basis thereof, who are likewise obliged to take action to enforce the right to object. If the User disagrees with the decision of the Data Controller, or if the Data Controller fails to meet the deadline referred to in this section, the User may turn to court within 30 days from the communication of the decision or the last day of the deadline.
