Privacy policy

The operator of www.ruzgarcosmetics.com is Rüzgar Import & Trade Ltd.

(Company Registration Number: 01-09-417632,

Tax Number: 32314601-2-421103, Kada Street 22), and applies the following data processing rules in relation to the handling of User data:

1. Purpose and Scope of the Information

1.1. What is the purpose of this Information?

The purpose of this information is to record and explain the data protection and data processing principles and policies applied by the Service Provider.

1.2. On the basis of which legal provisions was this Information adopted?

When adopting this Information, the Service Provider particularly took into account the following legal provisions:

The Fundamental Law of Hungary;

Act V of 2013 on the Civil Code (hereinafter referred to as the Civil Code);

Act CXII of 2011 on the Right to Self-Determination and Freedom of Information (hereinafter referred to as the Info Act);

Act CVIII of 2001 on Electronic Commerce Services and Services Related to the Information Society (hereinafter referred to as the E-Commerce Act),

Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions of Economic Advertising Activities (hereinafter referred to as the Advertising Act);

Act C of 2000 on Accounting (hereinafter referred to as the Accounting Act);

Act CXXVII of 2007 on Value Added Tax (hereinafter referred to as the VAT Act);

Act CLV of 1997 on Consumer Protection (hereinafter referred to as the Consumer Protection Act);

Act CLIX of 2012 on Postal Services (hereinafter referred to as the Postal Act)

Act CXIX of 1995 on the Processing of Name and Address Data for Research and Direct Marketing Purposes;

Act VI of 1998 on the Promulgation of the Convention on the Protection of Individuals with regard to the Processing of Personal Data by Automatic Means, signed in Strasbourg on 28 January 1981;

Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the GDPR).

2.1. What is data processing?

Data processing refers to any operation or set of operations performed on personal data or data sets, whether automated or not. This includes the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure, transmission, dissemination, or any other form of making available, alignment or combination, restriction, erasure, or destruction.

2.2. Who is the data controller?

The data controller is the individual or entity who determines the purposes and means of processing personal data, either alone or jointly with others.

In the context of this Information, the Service Provider identified in point 1.1. is considered the data controller.

2.3. Who is the data subject?

The data subject refers to any identified or identifiable natural person based on personal data, whether directly or indirectly.

2.5. Who is the data processor?

The data processor refers to any natural or legal person, public authority, agency, or any other body that processes personal data on behalf of the Service Provider, who acts as the data controller.

2.6. Which authority supervises the data processing carried out by the Service Provider?

The supervisory authority for the data processing conducted by the Service Provider is the National Authority for Data Protection and Freedom of Information (1125 Budapest, Szilágyi Erzsébet fasor 22/c).

 

III. Scope of Personal Data

3.1. What personal data does the Service Provider collect?

As a data controller, the Service Provider collects the data voluntarily provided by the user (hereinafter referred to as the "User") during the purchase or order process on the webshop operated on the www.PBSdepo.hu website (hereinafter referred to as the "Website"), which includes the following:

For natural persons:

Mandatory data: username, last name, first name, place and date of birth, email address, phone number, address (country, postal code, city, street, house number);

Optional data: gender, tax number (tax identification number), password provided by the User.

For legal entities and other organizations:

Mandatory data: username, name, registration number, email address, phone number, registered office (country, postal code, city, street, house number);

Optional data: password provided by the User, delivery address (if different from the registered office).

The User is not obliged to provide the above data, but without them, they cannot perform the mandatory registration required to purchase, use, or order products and services available on the webshop operated on the Website.

The Service Provider's data processing system also records the IP address of visitors to the Website who do not register.

After registration, depending on the User's decision, the Service Provider may also process the date and IP address of the User's last login.

3.2. How does the Service Provider collect personal data?

The Service Provider collects the personal data of the User through registration on the operated Website, as well as through the viewing of certain data on the Website.

3.3. What does "cookie" mean?

In order to offer products and services in a customized manner, the Service Provider places a small data package, known as a "cookie," on the computer of individuals using the Website, with the aim of enhancing the user experience of the Website.

Naturally, the user of the Website has the option to adjust their browser settings to disable the use of cookies or delete already installed cookies. However, if the user disables the use of cookies, they acknowledge and accept that the Website will not function fully, and the Service Provider shall not be held responsible in this regard.

The Service Provider only manages the following data through the use of cookies: products visited on the website, time spent on the website, and purchasing preferences for products distributed by the Service Provider based on browsing history.

3.4. What is personal data?

Personal data refers to any information relating to an identified or identifiable natural person ("data subject"). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.

 

Purpose and Legal Basis of Data Processing

4.1. What is the purpose of data processing by the Service Provider?

The purposes of data processing include:

- Identifying the data subject;
- Identifying the data subject's entitlements;
- Maintaining contact with the data subject;
- Managing and processing unique requests from the data subject;
- Protecting the data subject's rights;
- Creating statistics and analyses;
- Conducting the Service Provider's business activities;
- Upholding the legitimate interests of the Service Provider.

4.2. What does conducting the Service Provider's business activities as a data processing purpose entail?

This includes processing data related to product sales (such as purchase and payment documentation), fulfilling accounting obligations, delivering ordered products, providing payment options, and detecting potentially fraudulent transactions conducted through the online platform. The Service Provider may also use the provided personal data for internal accounting, auditing, and other functions.

4.3. Can the Service Provider use personal data for other purposes?

The Service Provider may use personal data for other purposes, but will provide separate notification and request consent from the data subject at the time of data collection if necessary.

4.4. What is the legal basis for the data processing by the Service Provider?

The Service Provider processes personal data only if at least one of the following conditions is met regarding the data processing:

the data subject has given consent for the processing of their personal data for one or more specific purposes;

the data processing is necessary for the performance of a contract in which the data subject is a party, or for taking steps at the request of the data subject prior to entering into a contract;

the data processing is necessary for compliance with a legal obligation to which the Service Provider is subject;

the data processing is necessary to protect the vital interests of the data subject or another natural person;

the data processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Service Provider;

the data processing is necessary for the legitimate interests pursued by the Service Provider or a third party, except where such interests are overridden by the data subject's interests or fundamental rights and freedoms, which require the protection of personal data, in particular where the data subject is a child.

4.5. What does data processing based on the data subject's consent mean?

It means that the data processing is carried out based on the voluntary, informed declaration of the data subject, which includes the data subject's explicit consent for the Service Provider to use and process the personal data provided by the data subject.

4.6. Can the data subject withdraw their consent?

In the case of data processing based on consent, the data subject is entitled to withdraw their consent at any time, however, this does not affect the lawfulness of the processing prior to the withdrawal.

4.7. What does data processing necessary for the performance of a contract mean?

If the data subject enters into a contract with the Service Provider, the Service Provider is entitled to process the personal data of the data subject who enters into the contract for the purpose of concluding and performing the contract.

4.8. What does data processing necessary for compliance with a legal obligation of the Service Provider mean?

It means that the Service Provider carries out data processing in order to comply with legal obligations. Such obligations include, in particular, the documentation of product sales and service provision, and the preservation of these documents, in accordance with the Accounting Act and the VAT Act.

4.9. What does data processing necessary for the legitimate interests of the Service Provider or a third party mean?

In accordance with the GDPR provisions, the Service Provider has conducted and will conduct a balancing test to determine whether the legitimate interests of the Service Provider or a third party in the data processing are stronger than the data subject's interests or fundamental rights and freedoms that require the protection of personal data.

Such legitimate interests include, in particular, the detection of online transactions related to payment that may be suspected of abuse.

 

Principles of Data Management

5.1. What principles does the Service Provider apply in data management?

The Service Provider handles personal data lawfully, fairly, and transparently for the data subject (lawfulness, fairness, and transparency).

The Service Provider collects personal data only for specified, explicit, and legitimate purposes, and does not process them in a manner that is incompatible with those purposes (purpose limitation).

The purposes of data processing must be adequate, relevant, and limited to what is necessary (data minimization).

The Service Provider ensures that personal data are accurate and, where necessary, kept up to date. In this regard, the Service Provider takes every reasonable step to ensure that inaccurate personal data are erased or rectified without delay for the purposes of data processing (accuracy).

The Service Provider ensures that personal data are stored in a form that permits identification of data subjects for no longer than is necessary for the purposes of data processing (limited storage).

The Service Provider processes personal data in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing, accidental loss, destruction, or damage, using appropriate technical or organizational measures (integrity and confidentiality).

The Service Provider is responsible for complying with the principles set out in points (a) to (f) and is able to demonstrate compliance (accountability).

5.2. Can the Service Provider deviate from the original purpose of data processing?

In the event that the Service Provider intends to use personal data for a purpose other than the original data collection purpose, they are obliged to inform the data subject and obtain their prior, express consent, while also allowing them to prohibit the use of data for the different purpose.

5.3. Does the Service Provider verify the accuracy of personal data?

The Service Provider only verifies the personal data provided by the data subject in cases prescribed by law. The data subject is responsible for the accuracy, precision, and adequacy of the personal data provided by them.

5.4. Does the Service Provider disclose personal data to individuals other than the data processor?

The Service Provider does not disclose personal data to third parties outside of the data processor, except for the exceptions mentioned in this Information.

The Service Provider discloses personal data to third parties outside of the data processor in the following exceptional cases:

- Official requests from courts or law enforcement agencies
- Use of personal data in statistically aggregated form that does not contain any other data capable of identifying the data subject, and therefore does not qualify as data processing or data transmission.

5.5. Does the Service Provider notify the data subject about the correction, restriction, or deletion of personal data?

The Service Provider notifies the data subject, as well as any individuals to whom the personal data has previously been transmitted, about the correction, restriction, or deletion of the personal data it manages. This notification may be omitted if it does not violate the legitimate interests of the data subject, considering the purpose of the data processing.

5.6. Is there a data protection officer at the Service Provider?

In accordance with the provisions of the GDPR, there is no data protection officer at the Service Provider.

The Duration of Data Processing

6.1. The Service Provider shall process personal data until any of the following conditions occur:

the personal data is no longer necessary for the purpose for which it was collected or otherwise processed;

the data subject withdraws their consent, which was the basis for the data processing, and there is no other legal basis for the processing;

the data subject objects to the processing, and there is no prevailing legitimate reason for the processing;

the Service Provider has unlawfully processed the personal data;

the personal data must be deleted in order to comply with a legal obligation applicable to the Service Provider;

the storage period prescribed by law for the personal data has expired;

the personal data is incomplete or inaccurate, and this condition cannot be lawfully rectified, provided that deletion is not excluded by law;

the responsible data protection authority or court has ordered the deletion of the personal data.

6.2. Taking the above into consideration, the Service Provider shall process lawfully processed personal data, taking into account the 5 (five) year limitation period specified in Section 6:22 of the Civil Code, starting from the date of purchase, provided that the data subject has withdrawn their consent, the contract has been fulfilled, and there is no reason that would require data processing for a longer period.

Data that must be retained in accordance with the provisions of the Accounting Act shall be deleted by the Service Provider after 8 (eight) years from the termination of the User's registered account, regardless of the data subject's consent.

The Service Provider is obliged to retain the minutes of the complaint submitted by the data subject and the related response for a period of 5 (five) years.

 

VII. Rights of the data subject and their enforcement

7.1. What rights does the data subject have in relation to data processing?

The data subject has the following rights in relation to data processing:

- Right to be informed (Articles 13 and 14 of the GDPR)
- Right to access personal data (Article 15 of the GDPR)
- Right to rectification and supplementation of personal data (Article 16 of the GDPR)
- Right to erasure of personal data (Article 17 of the GDPR)
- Right to restriction of processing (Article 18 of the GDPR)
- Right to data portability (Article 20 of the GDPR)
- Right to object to the processing of personal data (Article 21 of the GDPR).

7.2. What does the right to information mean?

During the data processing period, the data subject may request information from the Service Provider regarding the processing of their personal data.

The data subject may request information in writing at the Service Provider's registered office by sending a registered or certified letter, or by sending an electronic mail to the contact details specified in this Information Notice.

The Service Provider considers the request for information to be authentic and fulfillable if i) the data subject can be clearly identified in the case of a letter sent by post, and ii) in the case of an electronic mail, if the mail is sent from the data subject's previously registered email address. The Service Provider reserves the right to identify the data subject in other ways before fulfilling the request for information.

The information provided by the Service Provider covers the information regulated by the GDPR, which includes, in particular, the following information: the Service Provider's data (including the name and contact details of its representative), the purpose and legal basis of the data processing, the source of the data, the duration of the storage of personal data (or the criteria for determining it), the data subject's rights (to access personal data, to request correction, deletion or restriction of processing, or to object to the processing of personal data, as well as the right to data portability), the right to withdraw consent, the right to legal remedy (complaint, judicial remedy), the legitimate interest of the Service Provider as a data controller or third party (if the data processing is based on this), the recipients of personal data (if any), and the fact that the Service Provider, as a data controller, intends to transfer personal data to a third country or international organization (if any).

7.3. What does the right to access personal data mean?

The data subject is entitled to receive feedback from the Service Provider regarding whether the processing of their personal data is ongoing. If such data processing is ongoing, the data subject is entitled to access their personal data and the information detailed in the previous section.

7.4. What does the right to rectification and supplementation of personal data mean?

The data subject is entitled to request the Service Provider to promptly rectify any inaccurate personal data concerning them.

The data subject is entitled to request the supplementation of incomplete personal data, including through the submission of a supplementary statement, taking into account the purpose of the data processing.

If the Service Provider becomes aware that the personal data it processes is incorrect, it shall rectify the data based on available documents or public records, or if necessary, after consultation with the data subject.

If rectification of the data is not possible, the Service Provider shall delete it. In case there are any obstacles to rectification or deletion, the data shall be permanently blocked with an indication of the need for rectification.

7.5. What does the right to erasure of personal data mean?

Following appropriate identification, the data subject is entitled to request that the Service Provider promptly erase their personal data. The Service Provider may refuse to comply with the data subject's request for erasure if the processing of the data is necessary:

- for the exercise of the right to freedom of expression and information;
- for compliance with a legal obligation that requires the processing of personal data applicable to the Service Provider, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller;
- for reasons of public interest in the area of public health;
- for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, where erasure is likely to render impossible or seriously impair the achievement of such processing; or
- for the establishment, exercise or defence of legal claims.

If the Service Provider refuses to comply with the data subject's request for erasure, the data subject shall be informed of the reasons for the refusal and of their right to seek redress.

In the event of erasure, the personal data must be deleted in such a way that it cannot be restored.

7.6. When is personal data blocked instead of deleted?

Personal data must be blocked instead of deleted if the data subject requests it or if it can be assumed, based on the information available, that deletion would violate the data subject's legitimate interests.

7.7. What does the right to restrict processing mean?

The data subject is entitled to request the Service Provider to restrict the processing of personal data if:

the data subject disputes the accuracy of the personal data (In this case, the restriction shall apply for a period that allows the data controller to verify the accuracy of the personal data); or

the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead; or

the purpose of the processing has been achieved, but the data subject requires them for the submission, enforcement, or defense of legal claims; or

the data subject has objected to the processing (In this case, the restriction shall apply until it is determined whether the legitimate grounds of the Service Provider prevail over the data subject's legitimate grounds).

7.8. What does the right to data portability mean?

The data subject has the right to receive the personal data concerning them, which they have provided to the Service Provider, in a structured, commonly used, and machine-readable format. The data subject is also entitled to transmit these data to another data controller without hindrance from the Service Provider, to whom the personal data have been provided, if:

the processing is based on the data subject's consent or on a contract in which the data subject is a party, or the processing is necessary for the performance of pre-contractual steps at the data subject's request; and

the processing is carried out by automated means.

The data subject's right to data portability also includes the right for the data subject - where technically feasible - to request the direct transmission of the personal data by the Service Provider to another data controller.

7.9. What does the right to object to the processing of personal data mean?

The data subject is entitled to object at any time to the processing of their personal data, including profiling, if:

- the processing of personal data is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Service Provider; or
- the processing is necessary for the legitimate interests pursued by the Service Provider or a third party, except where such interests are overridden by the data subject's interests or fundamental rights and freedoms which require the protection of personal data; or
- the processing or transmission of personal data is necessary for the fulfillment of a legal obligation applicable to the Service Provider, except in cases of mandatory data processing; or
- the processing of personal data is carried out for direct marketing, opinion polling, or scientific research purposes; in this case, the data subject is entitled to object at any time to the processing of their personal data for such purposes, including profiling, if it is related to direct marketing.

If the Service Provider accepts the objection of the data subject, it shall cease the processing of data - including further data collection and transmission - and shall block the data. The Service Provider shall also inform all those to whom the personal data affected by the objection has been previously transmitted, and who are obliged to take measures to enforce the right to object, about the objection and the measures taken based on it.

7.10. How does the Service Provider proceed in exercising the rights mentioned above?

The Service Provider informs the data subject without undue delay, but no later than 1 (one) month from the receipt of the request or application, about the measures taken based on their request. Depending on the complexity of the request and the number of requests received, the Service Provider may extend this deadline by a maximum of 2 (two) months, and shall inform the data subject of the reasons for the delay within the original deadline. In the case of requests submitted electronically, unless otherwise requested by the data subject, the Service Provider shall provide the information electronically.

If the Service Provider fails to fulfill this obligation within the specified deadline, the data subject may avail themselves of the remedies described in this Information.

The Service Provider provides the information free of charge to the data subject.

 

VIII. Rules regarding individuals who have not reached the age of 16

8.1. Individuals who have not reached the age of 16 can only provide their personal data with written consent from the person exercising parental authority.

This means that individuals who have not reached the age of 16 are not entitled to independently disclose their personal data and are required to obtain consent from their legal representative. Without such consent, the personal data of individuals who have not reached the age of 16 can only be processed based on a different legal basis, separate from consent.

In cases where individuals who have not reached the age of 16 do not come into personal contact with the Service Provider when using their services, the individual is obligated to ensure compliance with this provision. The Service Provider shall not be held responsible for any failure to comply. The provision of personal data shall be considered by the Service Provider as an indication that the individual has declared that they are not subject to any restrictions regarding the disclosure of personal data.

However, the Service Provider reserves the right to verify the lawfulness of data processing and the existence of the legal basis for data processing, including the existence of consent from the person exercising parental authority.

8.2. The Service Provider naturally takes all necessary measures to delete the personal data of individuals who have not reached the age of 16 and have been unlawfully transferred or made available to the Service Provider, and ensures that such data cannot be further transmitted or processed.


VIX. Profiling

9.1. What does profiling mean?

Profiling refers to any form of automated processing of personal data, where personal data is used to evaluate certain personal characteristics related to the user (particularly related to work performance, economic situation, health condition, personal preferences, interests, reliability, behavior, place of residence, or movement) or to predict such characteristics.

In order to provide the Users with offers that fully meet their needs and interests, the Service Provider conducts profiling based on consent.

The offers developed based on profiling are sent to Users through email newsletters or via the Website by the Service Provider.

 

X. Data Processing

10.1. The Service Provider utilizes data processors as specified in this Information Notice for the data processing it carries out. The data processors engaged by the Service Provider may perform technical operations on personal data without the consent of the data subject, but they may not make substantive decisions independently and must act solely in accordance with the contract concluded with the Service Provider and the instructions of the Service Provider.

10.2. The Service Provider engages only data processors who comply with the GDPR and relevant legislation during data processing and meet the requirements set out therein.

10.3. The data processors engaged by the Service Provider may not engage further data processors without the prior written authorization of the Service Provider, either on a case-by-case or general basis.

10.4. The Service Provider monitors the data processing carried out by the data processor(s), including the activities of the data processors.

Data Processor Details

The scope of data accessible by the data processor and the manner of their use (activity performed by the data processor)

Package Point Logistics Limited Liability Company (1067 Budapest, Szondi utca 15. basement level)

Delivery of orders placed on the website.

 

XI. Data transmission

11.1. If the User chooses to use the online payment option when using the Website, they accept that the Service Provider will transmit the data related to the purchase to OTP Bank Nyrt. (1051 Budapest, Nádor utca 16.) as the data controller, for the purpose of online product sales as a data processing activity.

In this case, the Service Provider transmits the following data of the User: last name, first name, billing address (if different from the shipping address), phone number, email address, and payment transaction-related data.

The purpose of data transmission is to provide customer service assistance to Users, confirm transactions, and perform checks to detect potentially fraudulent transactions for the protection of Users.

11.2. In the case of delivery of products ordered by the User, the Service Provider transmits the recipient's last name and first name, shipping address, phone number, and order value to the following third-party data controllers:

Csomagpont Logisztika Korlátolt Felelősségű Társaság (1067 Budapest, Szondi utca 15. basement level)

11.3. The Service Provider is entitled and obliged to transmit the available and lawfully processed data to the competent authorities and courts if the GDPR, relevant legislation, or a legally binding and enforceable decision obliges the Service Provider to do so. The Service Provider shall not be held responsible for the consequences arising from the mandatory data transmission under this section.

11.4. The Service Provider shall not transmit personal data to a third country or an international organization during data processing.

11.5. The Service Provider is obliged to keep a record of data transmission, which includes the information specified in the GDPR and relevant legislation, particularly:

the identification data of the data subject and the data requester;

the purpose and legal basis of the data transmission;

the type of data transmitted; and

the time of data transmission.

11.6. The data subject may access and request information from the record regarding their own data, unless the law prohibits it.

 

XII. Authorized individuals to access personal data

12.1. Who has access to the personal data managed by the Service Provider?

Only designated employees of the Service Provider with appropriate authorization and the data processors specified in this Information Notice, as well as the recipients of data transmission, have access to the data managed by the Service Provider for the sole purpose of fulfilling their duties.


XIII. Data protection, data security

13.1. How does the Service Provider ensure the protection of personal data?

Taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of data processing, as well as the varying likelihood and severity of risks to the rights and freedoms of natural persons, the Service Provider implements appropriate technical and organizational measures to ensure a level of data security that is commensurate with the risk.

The purpose of these technical and organizational measures is to protect the personal data managed by the Service Provider and prevent their accidental loss, unauthorized destruction, unauthorized access, unauthorized use, alteration, or dissemination.

The Service Provider applies password protection on the computers and servers used for processing personal data in order to achieve these objectives.

Furthermore, the Service Provider calls upon all third parties who receive the personal data managed by the Service Provider to comply with and enforce the requirements of data security. The Service Provider also imposes the obligation on its employees involved in data processing, as well as on the data processors, to fulfill the requirements of data protection and data security.

 

XIV. Data Protection Incident

14.1. What constitutes a data protection incident?

Security breaches that result in accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access to personal data transmitted, stored, or otherwise processed.

14.2. When is the Service Provider obligated to notify the data subject of a data protection incident?

If the data protection incident is likely to result in a high risk to the rights and freedoms of natural persons, the Service Provider shall inform the data subject without undue delay. The notification to the data subject shall clearly and understandably describe the nature of the data protection incident and provide the most important information and measures.

14.3. Under what circumstances is the Service Provider not obligated to provide notification?

The affected party does not need to be informed if any of the following conditions are met:

The Service Provider has implemented appropriate technical and organizational security measures, and these measures have been applied to the data affected by the data breach, particularly measures such as encryption that render the data unintelligible to unauthorized individuals accessing the personal data.

The Service Provider has taken additional measures following the data breach to ensure that the high risk to the rights and freedoms of the affected party is unlikely to materialize in the future.

Providing notification would require disproportionate effort. In such cases, the affected parties must be informed through publicly available information or similar measures that ensure effective communication to the affected parties.

 

XV. Comments, Remedies

15.1. The Service Provider can be contacted with any questions or comments regarding the data processing carried out by the Service Provider using the following contact information.

Rüzgar Import & Trade Ltd.

Address: 22 Kada Street, Budapest 1103 (not a store, no customer service on site)
Email: info@ruzgarimport.com

15.2. Complaints regarding data processing can be directly submitted to the National Authority for Data Protection and Freedom of Information using the following contact information:

National Authority for Data Protection and Freedom of Information

Address: 22/c Szilágyi Erzsébet fasor, Budapest 1125

Phone: +36 (1) 391-1400

Website: www.naih.hu

Email: ugyfelszolgalat@naih.hu

15.3. The data subject may also directly appeal to the competent court for the violation of their rights. The jurisdiction and competence to adjudicate the data subject's claim depends on their place of residence or stay, as chosen by the data subject.

15.4. Upon the data subject's request, the Service Provider shall provide information on the available remedies and their means.

 

XVI: Modification of Information and Introduction of a New Information Statement

16.1 The Service Provider reserves the right to unilaterally modify or withdraw this Information Statement and introduce a new one.

16.2 By providing their consent or entering into a contract with the Service Provider, the concerned party accepts all provisions of the Information Statement that are in effect at the time.