- SCOPE OF PERSONAL DATA PROCESSED
2.1 User Registration
- name
- email address
- password (stored in encrypted form)
2.2 Orders (registered users and guest checkout)
- billing name and address
- shipping name and address
- email address
- phone number
- order details
2.3 Payments
During card payments, payment service providers (Barion, PayPal, Revolut) process bank card data.
The Data Controller does not have access to bank card details.
2.4 Transactional Emails
- “Your order has been placed”
- “Your order has been completed”
- “Handed over to the courier service”
- PURPOSE AND LEGAL BASIS OF DATA PROCESSING
User registration
Legal basis: Article 6(1)(b) GDPR – performance of a contract
Order processing
Legal basis: Article 6(1)(b) GDPR – performance of a contract
Invoicing
Legal basis: Article 6(1)(c) GDPR – legal obligation
System notifications
Legal basis: Article 6(1)(b) GDPR – performance of a contract
Internal analytics (Matomo)
Legal basis: Article 6(1)(f) GDPR – legitimate interest
Marketing (remarketing)
Legal basis: Article 6(1)(a) GDPR – consent
- DATA PROCESSORS AND DATA TRANSFERS
The Data Controller uses the following data processors:
- Courier services: MPL, GLS, Foxpost, FedEx
- Payment service providers: Barion, PayPal, Revolut
- Technical tool: Google Tag Manager (used for Barion payment integration)
- Image storage: Amazon Web Services (AWS S3)
- Analytics system: internally hosted Matomo with IP anonymization
Any data transfer outside the European Union is carried out with appropriate safeguards.
- COOKIES
Necessary cookies
These cookies are essential for the basic operation of the website (session handling, shopping cart, payment).
Statistical cookies
Website traffic is measured using an internally hosted Matomo system with IP anonymization, based on legitimate interest.
Marketing cookies
Marketing cookies are used only with the prior consent of the data subject.
Suggested cookie banner text:
“This website uses cookies for operational, statistical and marketing purposes.
Marketing cookies are activated only with your consent.”
Available options:
- Accept all
- Only necessary
- Settings
- RIGHTS OF THE DATA SUBJECT
The data subject has the right to:
- receive information about data processing
- access personal data
- request rectification
- request erasure
- request restriction of processing
- data portability
- object to processing
- withdraw consent at any time
- LEGAL REMEDIES
The data subject may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information.
- DATA SECURITY
The Data Controller applies appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure or destruction.
- VALIDITY
This Privacy Policy is effective from the date of publication and remains valid until revoked.
APPENDIX – SUMMARY OF LEGITIMATE INTEREST ASSESSMENT
- Internal analytics (Matomo): own server, IP anonymization
- Ensuring the technical operation of the webshop
- Sending transactional system messages