Privacy policy

Privacy Notice

Bécsi Zsófi E.V. Registered office: 9024 Győr, Babits Mihály utca 14/A Fsz 2. TAX NUMBER: 91771191-1-28 (hereinafter: Data Controller) processes the data of visitors to the www.sophiemassage.hu
website (hereinafter: Website), users of the Website, and registered users who use the services available on the Website (hereinafter collectively: Data Subject) during the operation of the Website.
In connection with data processing, the Data Controller hereby informs the Data Subjects about the personal data processed by it on the Website, the principles and practice it follows in the processing of personal data, as well as the ways and possibilities for exercising the rights of the data subjects. By using the Website, the Data Subject accepts the provisions of this Privacy Notice and consents to the data processing operations defined below.

1. Definitions

  1. Data Subject: any identified or identifiable natural person who is identified or can be identified – directly or indirectly – on the basis of personal data;
  2. Personal data: any data relating to the data subject – in particular the data subject’s name, identification mark, and one or more pieces of information characteristic of his or her physical, physiological, mental, economic, cultural or social identity – as well as any inference that can be drawn from the data relating to the data subject;
  3. consent: the freely given and specific indication of the data subject’s wishes, based on appropriate information, by which he or she gives unambiguous agreement to the processing of personal data relating to him or her – either fully or with respect to specific operations;
  4. objection: a statement by the data subject by which he or she objects to the processing of his or her personal data and requests the termination of the processing and/or the deletion of the processed data;
  5. data controller: the natural or legal person, or an organisation without legal personality, who or which, alone or jointly with others, determines the purposes of the processing of data, makes and implements decisions regarding the processing (including the means used), or has them implemented by a processor commissioned by it;
  6. data processing: any operation or set of operations performed on data, irrespective of the procedure applied, including in particular collection, recording, storage, organisation, retention, alteration, use, retrieval, transmission, disclosure, alignment or combination, restriction, erasure and destruction, as well as preventing further use of the data;
  7. data handling/processing activity: performance of technical tasks related to data processing operations, regardless of the method and tools used to carry out the operations and the place of application, provided that the technical task is performed on the data;
  8. data processor: a natural or legal person, or an organisation without legal personality, who or which processes data on the basis of a contract with the data controller – including a contract concluded on the basis of a statutory provision;
  9. data transfer: making data accessible to a specific third party;
  10. disclosure: making data accessible to anyone;
  11. data erasure: rendering data unrecognisable in such a way that restoration is no longer possible;
  12. data restriction (blocking): marking data with an identifier for the purpose of limiting its further processing permanently or for a specific period;
  13. data destruction: complete physical destruction of the data carrier containing the data;
  14. third party: a natural or legal person, or an organisation without legal personality, who or which is not identical with the data subject, the data controller or the data processor.

2. Purpose of data processing

The Data Controller stores and processes the data provided by the Data Subject during registration in a purpose-limited manner exclusively for the provision of the service available on the Website, communication, identification of the user, and, if the Data Subject subscribes to the newsletter, for sending the newsletter. The purpose of automatically recorded data is the preparation of statistics and the technical development of the IT system. The Data Controller does not use and may not use the provided personal data for purposes other than those defined above.

Disclosure of personal data to third parties or authorities – unless a law provides otherwise with mandatory force – is possible only with the Data Subject’s prior express consent. In all cases where the Data Controller intends to use the provided data for a purpose different from the original purpose of data collection, it shall inform the Data Subject thereof and obtain his or her prior express consent, and/or provide the opportunity to prohibit such use.

3. Legal basis of data processing

Data processing by the Data Controller is carried out on the basis of the Data Subject’s voluntary consent pursuant to Section 5(1)(a) of Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (hereinafter: Info Act), and pursuant to Act CVIII of 2001 on Electronic Commerce Services and Certain Issues Related to Information Society Services.

The Data Controller does not verify the authenticity of the personal data provided to it. Responsibility for the accuracy and adequacy of the data provided rests solely with the person providing it, i.e. the Data Subject / contracting party. By providing an email address, any Data Subject also assumes responsibility that only he or she uses the service via the provided email address. In view of this assumption of responsibility, any and all liability related to logins performed using a provided email address shall rest exclusively with the Data Subject who provided that email address.

4. Data Controller details

Bécsi Zsófi E.V.
Registered office: 9024 Győr, Babits Mihály utca 14/A Fsz 2.
TAX NUMBER: 91771191-1-28

5. Duration of data processing

5.1. Registration data

Processing of the personal data that must be provided during registration continues until the Data Subject requests deletion of his or her registration. The registration may be deleted at any time after sending the deletion request (by post or email). In such case, the deadline for erasing the data is 5 working days from receipt of the request.

5.2. Duration of processing (newsletter)

The Data Controller processes the data provided by the Data Subject when subscribing to the newsletter until the Data Subject unsubscribes by clicking the “Unsubscribe” button in the information email or requests removal from the newsletter subscribers list by email or post. Otherwise, the processing lasts for 2 years. In the event of unsubscription, the Data Controller records the request upon receipt (by email, post, or by clicking the “Unsubscribe” button) and will not send further emails to the Data Subject.

5.3. Technical data

Logged data are stored by the system – except for the date of the last visit, which is automatically overwritten – for 2 years from the time of logging.

5.4. Data provided when submitting the electronic contact form

Processing of the personal data that must be provided when submitting the contact form continues until the Data Subject requests deletion of the data provided in this way. Data may be deleted at any time after sending the deletion request (by post or email). In such case, the deadline for erasing the data is 5 working days from receipt of the request.

6. Scope of processed personal data

6.1. Data required during registration

To use the services on the Website, the Data Subject must provide the following data:

Name, Phone number, Email, Company name, Billing address, Delivery address

6.2. Newsletter

In the case of newsletter subscription, the Data Subject must provide his or her email address and full name to the Data Controller.

6.3. Technical data

Data of the Data Subject’s computer generated during use of the service and recorded by the Data Controller’s system as the automatic result of technical processes. These include, in particular, the date and time of the visit, the IP address of the Data Subject’s computer, the type of browser, and the address of the viewed and previously visited website.

Automatically recorded data are logged automatically upon login and logout without any separate declaration or action by the Data Subject. These data cannot be linked with other personal user data – except in cases required by law. Only the Data Controller has access to these data.

The Data Controller may collect data on the Data Subjects’ activity that cannot be linked to other data provided by the Data Subject during registration, nor to data generated when using other websites or services.

The Website’s HTML code may contain links from external servers independent of the Data Controller and links pointing to external servers. The providers of such links may be able to collect user data due to the direct connection to their server.

External servers support the independent measurement and auditing of the Website’s traffic and other web analytics data (Google Analytics). The data controllers can provide detailed information to the Data Subject about the processing of measurement data. Availability: www.google.com/analytics/

If the Data Subject does not want Google Analytics to measure the above data in the manner and for the purposes described, he or she should install the browser add-on that blocks it.

6.4. Cookies

The Data Controller and/or the named external service providers place and read a small data package, a so-called cookie, on the Data Subject’s computer in order to provide customised service. If the browser returns a previously saved cookie, the service provider managing the cookie has the possibility to link the data stored during the Data Subject’s current visits with previous data, but only with regard to its own content.

The Data Controller uses the following cookies:

– Temporary (session) cookies: Session cookies are deleted automatically after the Data Subject’s visit. These cookies serve to ensure that the Data Controller’s Website can operate more efficiently and securely; therefore, they are essential for certain functions of the Website or certain applications to work properly.

– Permanent (persistent) cookies: The Data Controller also uses persistent cookies to improve the user experience (e.g. providing optimised navigation). These cookies are stored in the browser’s cookie file for a longer period. The duration depends on the settings used by the Data Subject in his or her internet browser.

– Cookie used for password-protected sessions.
– Security cookie.

In the “Help” function of most browsers’ menu bars, the Data Subject can find information on how to, in his or her browser:

– disable cookies,
– accept new cookies,
– instruct the browser to set a new cookie, or
– disable other cookies.

The Website uses Google Adwords remarketing tracking codes. This is based on the fact that visitors to the Website can later be reached with remarketing ads on websites belonging to the Google Display Network. The remarketing code uses cookies to tag visitors. Users of the Website may disable these cookies by visiting Google’s Ads Settings manager and following the instructions found there. After that, they will not see personalised offers from the Service Provider.

More information about cookies:
https://silktide.com/tools/cookie-consent/docs/

More information about Google Analytics:
https://www.google.hu/intl/hu/analytics/

7. Persons who may access the data

Scope of persons who may access the data, data transfer, processing: The data may primarily be accessed by the Data Controller and the Data Controller’s internal staff, however, they do not publish the data and do not transfer them to third parties.

The Service Provider may use data processors (e.g. system operators). The Service Provider is not responsible for the data processing practices of such external actors.

DATA PROCESSOR DETAILS:
Currently there is no such contributor

Beyond the above, transfer of personal data relating to the User may take place exclusively in cases required by law and/or based on the User’s consent.

Hosting provider details:

KTS Online Kft
Tax number: 29152106-2-08.
Company registration number: 08-09-032885
Registered at the Company Court of Győr.
Statistical number: 29152106-6311-113-08.
Community tax number: HU29152106.

HEADQUARTERS: 9024 Győr, Bartók Béla utca 26/B ground floor 2.
PHONE: +36-20/316-2431
E-MAIL: info@kts.hu

Beyond the above, personal data relating to the Data Subject may be transferred exclusively in cases required by law and/or based on the User’s consent.

8. User rights and enforcement options

8.1. Right to information

The Data Subject is entitled at any time to request information about the personal data relating to him or her processed by the Data Controller.

Upon the Data Subject’s request, the Data Controller provides information about the data relating to him or her processed by it, the purpose, legal basis and duration of the processing, and to whom and for what purpose the data are or have been disclosed. The Data Controller provides the requested information in writing within 30 days from submission of the request.

The Data Subject may contact the Data Controller’s employee regarding any questions or comments related to data processing via the contact details indicated below.

8.2. The Data Subject may request erasure, rectification, restriction

The Data Subject may at any time request rectification of incorrectly recorded data or erasure thereof via one of the contact details indicated below. The Data Controller deletes the data within 5 working days from receipt of the request; in such case the data can no longer be restored. Erasure does not apply to data processing required by law (e.g. accounting regulations); such data are retained by the Data Controller for the required period.

The Data Subject may also request restriction of processing. The Data Controller restricts the personal data if the Data Subject requests so, or if based on available information it can be assumed that erasure would violate the Data Subject’s legitimate interests. Such restricted personal data may be processed only for as long as the purpose of the processing exists that precluded erasure of the personal data.

The Data Subject and all persons to whom the data were previously disclosed for data processing purposes must be notified of rectification, restriction and erasure. Notification may be omitted if it does not harm the User’s legitimate interests in view of the purpose of the processing.

If the data controller does not comply with the data subject’s request for rectification, restriction or erasure, it shall communicate in writing within 30 days from receipt of the request the factual and legal reasons for refusing the request for rectification, restriction or erasure.

8.3. The Data Subject may object to processing of personal data

The Data Subject may object to the processing of his or her personal data. The Data Controller examines the objection as soon as possible, but no later than within 15 days from submission of the request, decides on its merits, and informs the applicant in writing of its decision.

The Data Subject may exercise his or her rights via the contact details indicated in Section 4.

8.4. The Data Subject may, on the basis of the Info Act and the Civil Code (Act V of 2013)

  1. contact the National Authority for Data Protection and Freedom of Information (1125 Budapest, Szilágyi Erzsébet fasor 22/c.; www.naih.hu ) or
  2. enforce his or her rights before a court.

If the Data Subject provided data of a third party to use the service or caused damage in any way during use of the Website, the Data Controller is entitled to enforce a claim for damages against the Data Subject. In such cases, the Data Controller provides all assistance it can to the competent authorities in order to establish the identity of the infringing person.

9. Use of email addresses

The Data Controller pays particular attention to the lawful use of electronic email addresses processed by it, and therefore uses them only in the manner defined below for sending emails.

Processing of email addresses primarily serves identification of the Data Subject and communication during the use of the service; therefore, emails are primarily sent for this purpose.

10. Data security

The Data Controller undertakes to ensure the security of the data and to take the technical measures that ensure that the collected, stored and processed data are protected, and to do everything possible to prevent their destruction, unauthorised use and unauthorised alteration. It also undertakes to call upon all third parties to whom it may transfer or hand over the data to comply with their obligations in this regard.

11. Other provisions

The Data Controller reserves the right to unilaterally amend this Privacy Notice with prior notification to the Data Subjects – by notice on the Website. After the amendment enters into force, the Data Subject accepts the provisions of the amended Privacy Notice by using the Website (by implied conduct).

Write to us

Contact us by phone, email or via the contact form.

Address

9024 Győr, Babits Mihály utca 14/a fsz.