Adatvédelmi irányelvek

Data Controller

Name: Ász Bt.

Registered office: 1038 Budapest, Papírgyár u. 15.

Postal address, complaint handling: 1038 Budapest, Papírgyár u. 15.

Tax number: 28327239-2-41

Email: info@aszbtacs.hu

Hosting Provider

Name: Rackhost Zrt.

Postal address: HU 6722 Szeged, Tisza Lajos krt. 41.

Contact: https://www.rackhost.hu/

Description of data processing carried out during the operation of the website

Information on the use of cookies

What is a cookie?

During visits to the website, the Data Controller uses so-called cookies. A cookie is an information package consisting of letters and numbers, which our website sends to your browser in order to save certain settings, make the use of our website easier, and help us collect some relevant statistical information about our visitors.

Some cookies do not contain personal information and are not suitable for identifying individual users, while others contain a unique identifier — a secret, randomly generated number sequence — which is stored on your device and can therefore also enable your identification. The operating duration of each cookie is specified in the relevant description of the respective cookie.

Legal background and legal basis for cookies:

The legal basis for data processing is your consent pursuant to Article 6(1)(a) of the Regulation.

Main characteristics of the cookies used by the website:

Google Ads cookie: When someone visits our website, the visitor’s cookie ID is added to the remarketing list. Google uses cookies, such as NID and SID cookies, to personalize ads in Google products, including ads displayed in Google Search. For example, such cookies are used to remember your most recent searches, your previous interactions with certain advertisers’ ads or search results, and your visits to advertisers’ websites. The AdWords conversion tracking feature uses cookies. To track sales and other conversions generated by advertisements, cookies are saved on the user’s computer when the person clicks on an ad. Common uses of cookies include selecting ads based on what is relevant to a given user, improving campaign performance reports, and avoiding showing ads that the user has already seen.

Google Analytics cookie: Google Analytics is Google’s analytics tool, which helps website and app owners gain a more accurate understanding of their visitors’ activities. The service may use cookies to collect information and compile reports from statistical data relating to website usage, without individually identifying visitors to Google. The main cookie used by Google Analytics is the “__ga” cookie. In addition to reports generated from website usage statistics, Google Analytics — together with some of the advertising cookies described above — may also be used to display more relevant advertisements in Google products, such as Google Search, and across the internet.

Remarketing cookies: These may be used to display ads to previous visitors or users while they browse other websites on the Google Display Network or search for terms related to your products or services.

Strictly necessary cookies: These cookies are essential for using the website and enable the use of its basic functions. Without them, many functions of the website will not be available to you. The lifespan of these types of cookies is limited exclusively to the duration of the session.

Cookies used to improve user experience: These cookies collect information about the user’s website usage, such as which pages they visit most frequently or what error messages they receive from the website. These cookies do not collect information that identifies the visitor; they work with completely general, anonymous information. The data obtained from these cookies is used to improve the performance of the website. The lifespan of these types of cookies is limited exclusively to the duration of the session.

Session cookie: These cookies store the visitor’s location, browser language, and payment currency. Their lifespan lasts until the browser is closed or for a maximum of 2 hours.

Referrer cookies: These record which external website the visitor arrived from. Their lifespan lasts until the browser is closed.

Last viewed product cookie: Records the products last viewed by the visitor. Its lifespan is 60 days.

Last viewed category cookie: Records the last viewed category. Its lifespan is 60 days.

Recommended products cookie: In the “recommend to a friend” function, it records the list of products to be recommended. Its lifespan is 60 days.

Mobile version, design cookie: Detects the device used by the visitor and switches to full view on mobile. Its lifespan is 365 days.

Cookie acceptance cookie: When arriving on the website, it records acceptance of the statement regarding the storage of cookies in the warning window. Its lifespan is 365 days.

Logout #2 cookie: According to option #2, the system logs the visitor out after 90 days. Its lifespan is 90 days.

Backend identifier cookie: The identifier of the backend server serving the website. Its lifespan lasts until the browser is closed.

employee_login_last_email: Stores the email address during login until the browser is closed.

Ealrm, ealem, ealpw: Provides permanent login. Its lifespan is 180 days.

come_from: Performs redirection after login. Its lifespan is 10 minutes.

predictionio: User identifier cookie for recommending personalized advertisements. Its lifespan is 3 months.

Facebook pixel (Facebook cookie): The Facebook pixel is a code that helps the website generate reports on conversions, build target audiences, and provide the website owner with detailed analytical data about visitors’ use of the website. With the help of the Facebook pixel, the website may display personalized offers and advertisements to website visitors on Facebook. You can read Facebook’s data processing policy here: https://www.facebook.com/privacy/explanation

If you do not accept the use of cookies, certain functions will not be available to you. You can find more information about deleting cookies at the following links:

Internet Explorer: http://windows.microsoft.com/en-us/internet-explorer/delete-manage-cookies#ie=ie-11
Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer
Mozilla: https://support.mozilla.org/hu/kb/weboldalak-altal-elhelyezett-sutik-torlese-szamito
Safari: https://support.apple.com/guide/safari/manage-cookies-and-website-data-sfri11471/mac
Chrome: https://support.google.com/chrome/answer/95647
Edge: https://support.microsoft.com/hu-hu/help/4027947/microsoft-edge-delete-cookies

Data processed for the purpose of concluding and performing contracts

Several data processing cases may occur for the purpose of concluding and performing contracts. Please note that data processing related to complaint handling or warranty administration only takes place if you exercise one of the aforementioned rights.

If you are only a visitor to the website, the provisions described under marketing-related data processing may apply to you.

Data processing carried out for the purpose of concluding and performing contracts in more detail:

Contact

For example, if you contact us by email, contact form, or telephone with a question regarding one of our services.

Data processed

The data provided by you during contact.

Duration of data processing

We process the data only until the contact process has been completed.

Legal basis of data processing

Your voluntary consent, which you provide to the Data Controller by contacting us. [Data processing pursuant to Article 6(1)(a) of the Regulation]

Issuing an invoice

Payment and the issuing of an invoice become relevant during a personal meeting, therefore we do not request billing data through the website.

Further data processing

If the Data Controller intends to carry out further data processing, it will provide prior information on the essential circumstances of the data processing, including the legal background and legal basis of the data processing, the purpose of the data processing, the scope of the data processed, and the duration of data processing.

We inform you that the Data Controller is required to comply with written data requests from authorities based on statutory authorization. The Data Controller keeps records of data transfers in accordance with Section 15(2)-(3) of the Hungarian Information Act, recording which authority received which personal data, on what legal basis, and when the transfer was made. Upon request, the Data Controller will provide information about the content of this record, unless disclosure is excluded by law.

Recipients of personal data

Data processing related to the storage of personal data

Name: Rackhost Zrt.

Postal address: HU 6722 Szeged, Tisza Lajos krt. 41.

Contact: https://www.rackhost.hu/

The Data Processor stores personal data on the basis of a contract concluded with the Data Controller. The Data Processor is not entitled to access the personal data.

Your rights during data processing

Within the duration of data processing, you are entitled to the following rights under the Regulation:

the right to withdraw consent;
access to personal data and information related to data processing;
the right to rectification;
restriction of data processing;
the right to erasure;
the right to object;
the right to data portability.

If you wish to exercise your rights, this will involve your identification, and the Data Controller will necessarily need to communicate with you. Therefore, in order to identify you, it will be necessary to provide personal data, although identification may only be based on data that the Data Controller already processes about you. Your complaint related to data processing will be available in the Data Controller’s email account within the period specified in this notice in relation to complaints. If you were our customer and wish to identify yourself for complaint handling or warranty administration, please also provide your order ID for identification. This will allow us to identify you as a customer.

The Data Controller will respond to complaints related to data processing within 30 days at the latest.

Right to withdraw consent

You are entitled to withdraw your consent to data processing at any time. In such cases, the data provided will be deleted from our systems. Please note, however, that in the case of a service that has not yet been completed, withdrawal may result in our inability to provide the service to you. In addition, if the service has already been performed, we may not delete billing-related data from our systems based on accounting regulations. Furthermore, if you have an outstanding debt to us, we may continue to process your data on the basis of legitimate interest related to debt collection even after consent has been withdrawn.

Access to personal data

You are entitled to receive confirmation from the Data Controller as to whether your personal data is being processed. If data processing is in progress, you are entitled to:

access the personal data being processed; and
receive information from the Data Controller about the following:

the purposes of data processing;
the categories of personal data processed about you;
information about the recipients or categories of recipients to whom the Data Controller has disclosed or will disclose the personal data;
the planned storage period of the personal data or, if this is not possible, the criteria used to determine that period;
your right to request from the Data Controller the rectification, erasure, or restriction of processing of your personal data, and, in the case of data processing based on legitimate interest, to object to the processing of such personal data;
the right to lodge a complaint with a supervisory authority;
if the data was not collected from you, all available information regarding its source;
the existence of automated decision-making, if such a procedure is used, including profiling, and at least in such cases, meaningful information about the logic involved and the significance and expected consequences of such data processing for you.

The purpose of exercising this right may be to establish and verify the lawfulness of data processing; therefore, in the event of repeated requests for information, the Data Controller may charge a reasonable fee in exchange for fulfilling the request.

The Data Controller provides access to personal data by sending the processed personal data and related information to you by email after identifying you.

Please indicate in your request whether you are requesting access to the personal data itself or information related to data processing.

Right to rectification

You are entitled to request that the Data Controller correct inaccurate personal data concerning you without undue delay.

Right to restriction of data processing

You are entitled to request that the Data Controller restrict data processing if any of the following applies:

you dispute the accuracy of the personal data, in which case the restriction applies for the period that enables the Data Controller to verify the accuracy of the personal data; if the accurate data can be established immediately, no restriction will take place;
the data processing is unlawful, but you oppose the deletion of the data for any reason, for example because the data is important for you in order to assert a legal claim, and therefore you request restriction of its use instead of deletion;
the Data Controller no longer needs the personal data for the stated purpose of data processing, but you require it for the establishment, exercise, or defense of legal claims; or
you have objected to data processing, but the Data Controller may also have a legitimate interest in the data processing; in this case, data processing must be restricted until it is determined whether the Data Controller’s legitimate grounds override your legitimate grounds.

If data processing is subject to restriction, such personal data may, with the exception of storage, only be processed with the consent of the data subject, or for the establishment, exercise, or defense of legal claims, or for the protection of the rights of another natural or legal person, or for important public interest reasons of the Union or of a Member State.

The Data Controller will inform you in advance of the lifting of the restriction on data processing, at least 3 working days before the restriction is lifted.

Right to erasure — right to be forgotten

You are entitled to request that the Data Controller erase personal data concerning you without undue delay if any of the following grounds apply:

the personal data is no longer necessary for the purpose for which it was collected or otherwise processed by the Data Controller;
you withdraw your consent and there is no other legal basis for the data processing;
you object to data processing based on legitimate interest, and there is no overriding lawful ground, that is, legitimate interest, for the data processing;
the personal data has been processed unlawfully by the Data Controller, and this has been established on the basis of the complaint;
the personal data must be erased in order to comply with a legal obligation under Union or Member State law applicable to the Data Controller.

If the Data Controller has made the personal data processed about you public for any lawful reason and is required to erase it for any of the reasons listed above, then, taking into account the available technology and the cost of implementation, it is required to take reasonable steps, including technical measures, to inform other data controllers processing the data that you have requested the deletion of links to the personal data in question or the deletion of copies or replications of such personal data.

Erasure does not apply where data processing is necessary:

for exercising the right to freedom of expression and information;
for compliance with a legal obligation under Union or Member State law applicable to the Data Controller requiring the processing of personal data, such as data processing carried out in relation to invoicing, as the retention of invoices is required by law, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
for the establishment, exercise, or defense of legal claims, for example if the Data Controller has a claim against you and you have not yet fulfilled it, or if a consumer or data protection complaint is being processed.

Right to object

You are entitled to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on legitimate interest. In this case, the Data Controller may no longer process the personal data unless it proves that the processing is justified by compelling legitimate grounds that override your interests, rights, and freedoms, or that are related to the establishment, exercise, or defense of legal claims.

If personal data is processed for direct marketing purposes, you are entitled to object at any time to the processing of personal data concerning you for this purpose, including profiling insofar as it is related to direct marketing. If you object to the processing of personal data for direct marketing purposes, the personal data may no longer be processed for this purpose.

Right to data portability

If data processing is carried out by automated means, or if the data processing is based on your voluntary consent, you have the right to request from the Data Controller the data that you have provided to the Data Controller. The Data Controller will provide this data to you in XML, JSON, or CSV format. If technically feasible, you may request that the Data Controller transmit the data in this format to another data controller.

Automated decision-making

You are entitled not to be subject to a decision based solely on automated data processing, including profiling, which would produce legal effects concerning you or similarly significantly affect you. In such cases, the Data Controller is required to take appropriate measures to protect the rights, freedoms, and legitimate interests of the data subject, including at least the right of the data subject to request human intervention on the part of the Data Controller, to express their point of view, and to contest the decision.

The above does not apply if the decision:

is necessary for entering into or performing a contract between you and the Data Controller;
is authorized by Union or Member State law applicable to the Data Controller, which also lays down suitable measures to protect your rights, freedoms, and legitimate interests; or
is based on your explicit consent.

Notification to the data protection register

Under the provisions of the Hungarian Information Act, the Data Controller was required to notify certain data processing activities to the data protection register. This notification obligation ceased on 25 May 2018.

Data security measures

The Data Controller declares that it has taken appropriate security measures to protect personal data against unauthorized access, alteration, transfer, disclosure, deletion, or destruction, as well as against accidental destruction or damage, and against inaccessibility resulting from changes in the technology used.

The Data Controller makes every effort, within its organizational and technical capabilities, to ensure that its data processors also take appropriate data security measures when working with your personal data.

Remedies

If you believe that the Data Controller has violated any legal provision relating to data processing or has failed to fulfill any of your requests, you may initiate an investigation procedure with the Hungarian National Authority for Data Protection and Freedom of Information in order to terminate the presumed unlawful data processing. Mailing address: 1363 Budapest, Pf. 9.; email: ugyfelszolgalat@naih.hu.

We also inform you that in the event of a breach of legal provisions relating to data processing, or if the Data Controller has not fulfilled any of your requests, you may bring a civil lawsuit against the Data Controller before a court.

Amendment of the Privacy Notice

The Data Controller reserves the right to amend this Privacy Notice in a manner that does not affect the purpose or legal basis of the data processing. By using the website after the amendment enters into force, you accept the amended Privacy Notice.

If the Data Controller intends to carry out further data processing in relation to the collected data for a purpose other than the purpose for which the data was collected, it will inform you before the further data processing about the purpose of the data processing and the following information:

the period for which the personal data will be stored or, if this is not possible, the criteria used to determine that period;
your right to request from the Data Controller access to, rectification or erasure of, or restriction of processing of personal data concerning you, and, in the case of data processing based on legitimate interest, your right to object to the processing of personal data, as well as your right to data portability in the case of data processing based on consent or a contractual relationship;
in the case of data processing based on consent, the fact that you may withdraw your consent at any time;
the right to lodge a complaint with a supervisory authority;
whether the provision of personal data is based on a legal or contractual obligation, or is a prerequisite for entering into a contract, whether you are obliged to provide the personal data, and what possible consequences failure to provide the data may have;
the existence of automated decision-making, if such a procedure is used, including profiling, and at least in such cases, meaningful information about the logic involved and the significance and expected consequences of such data processing for you.

Data processing may only begin after this. If the legal basis of the data processing is consent, you must also provide your consent in addition to receiving the information.

This document contains all relevant data processing information related to the operation of the website, based on Regulation (EU) 2016/679 of the European Union, the General Data Protection Regulation (hereinafter: Regulation or GDPR), and Act CXII of 2011 (hereinafter: the Hungarian Information Act).