INFORMATION WE COLLECT
To fulfill your order we are provided with certain information (which you authorized Etsy to provide to us), such as your name, email address, postal address, payment information, and the details of the product that you’re ordering. A Phone number might be additionally requested so it could be provided to the couriers for scheduling the delivery time.
WHY WE NEED YOUR INFORMATION AND HOW WE USE IT
We rely on a number of legal bases to collect, use, and share your information, including:
- as needed to provide our services, such as when we use your information to fulfill your order, to settle disputes, or to provide customer support;
- when you have provided your affirmative consent, which you may revoke at any time, such as by signing up for our mailing list;
- if necessary to comply with a legal obligation or court order or in connection with a legal claim, such as retaining information about your purchases if required by tax law.
- as necessary for the purpose of our legitimate interests, if those legitimate interests are not overridden by your rights or interests, such as:
- providing and improving our services. We use your information to provide the services you requested and in our legitimate interests to improve our services; and
INFORMATION SHARING AND DISCLOSURE
Information about our customers is important to us. Therefore, we share your personal information for very limited reasons and in limited circumstances, as follows:
- Service providers. We engage certain trusted third parties to perform functions and provide services to our shop, such as delivery companies. We will share your personal information with these third parties, but only to the extent necessary to perform these services.
- Business transfers. If we sell or merge our business, we may disclose your information as part of that transaction, only to the extent permitted by law.
- Compliance with laws. We may collect, use, retain, and share your information if we have a good faith belief that it is reasonably necessary to: (a) respond to legal process or to government requests; (b) enforce our agreements, terms and policies; (c) prevent, investigate, and address fraud and other illegal activity, security, or technical issues; or (d) protect the rights, property, and safety of our customers, or others.
TRANSFERS OF PERSONAL INFORMATIONS OUTSIDE THE EU
We may store and process your information through third-party hosting services in the EU and other jurisdictions. As a result, we may transfer your personal information to a jurisdiction with different data protection and government surveillance laws than your jurisdiction.
In case you live in certain territories, including the EU, you have rights in relation to your personal information. Although some of these rights apply generally, certain apply only in certain limited cases. Here’s the information for these rights:
- Access. In case you request a copy of the personal information we have about you, just contact us and we’ll provide it to you.
- Change, restrict, delete. If you want to change, restrict our use of, or delete the information about you, you have these rights.
- Object. You can object to our processing of some of your information based on our legitimate interests and receiving marketing messages from us after providing your express consent to receive them. In such cases, we will delete your personal information unless we have compelling and legitimate grounds to continue using that information or if it is needed for legal reasons.
- Complain. If you reside in the EU and wish to raise a concern about our use of your information (and without prejudice to any other rights you may have), you have the right to do so with your local data protection authority.
HOW TO CONTACT US
For purposes of EU data protection law, we are the data controllers of your personal information. If you have any questions, you may reach out to us at firstname.lastname@example.org.
Name: BalkanBull Kft.
Headquarters: 1085 Budapest, József krt. 36. fsz. 5.
Company registration number: 01-09-320367
Tax number: 26254429-2-42
Representative: Zoltán Bréti
Telephone number: +36 1 244 3084
BalkanBull Kft., (1085 Budapest, József krt. 36. fsz. 5., hereinafter, service provider, data controller) The website's data management information is available on the following page: https://jelenakepic.com/informational_pages/privacy-policy/
as a data controller, recognizes the content of this legal notice as binding on itself. It undertakes to ensure that all data management related to its activities meets the requirements set out in these regulations and in the applicable national legislation, as well as in the legal acts of the European Union.
The data protection guidelines arising in connection with the data management of the Data Controller are continuously available at the address The Data Controller reserves the right to change this information at any time. Of course, you will notify your audience of any changes in good time.
If you have any questions related to this announcement, please write to us and our colleague will answer your question.
The Data Controller is committed to protecting the personal data of its customers and partners, and considers it of utmost importance to respect its customers' right to informational self-determination. The Data Controller treats personal data confidentially and takes all security, technical and organizational measures that guarantee data security.
The Data Controller describes its data management practices below.
Data of the data controller
If you would like to contact our Company, you can contact the data controller at email@example.com and +36 1 244 3084.
Scope of processed personal data
Personal data to be provided during registration:
Name, phone number, billing address, delivery address, e-mail address, password required for registration
The Data Controller selects and operates the IT tools used for the management of personal data during the provision of the service in such a way that the managed data:
accessible to those authorized to do so (availability);
its authenticity and authentication are ensured (authenticity of data management);
its immutability can be verified (data integrity);
be protected against unauthorized access (data confidentiality).
The Data Controller protects the data with appropriate measures against unauthorized access, alteration, transmission, disclosure, deletion or destruction, as well as against accidental destruction.
The Data Controller ensures the protection of the security of data management with technical, organizational and organizational measures that provide a level of protection corresponding to the risks associated with data management.
The Data Controller keeps it during data management
confidentiality: protects the information so that only those authorized to do so can access it;
integrity: protects the accuracy and completeness of the information and the method of processing;
availability: it ensures that when the authorized user needs it, he can really access the desired information and that the related tools are available.
It's the job of cookies to collect information about visitors and their devices;
they note the individual settings of the visitors, which will be used, e.g. when using online transactions, so you don't have to type them in again;
facilitate the use of the website;
they provide a quality user experience.
In order to provide customized service, a small data package, so-called it places a cookie and reads it back during the next visit. If the browser returns a previously saved cookie, the cookie management service provider has the opportunity to connect the user's current visit with previous ones, but only with regard to its own content.
Duration of data management
The data storage period of the given cookie, more information is available here:
Google general cookie information: https://www.google.com/policies/technologies/types/
Google Analytics information: https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage?hl=en
Facebook information: https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen
Legal background and legal basis of cookies:
The legal basis for data management is your consent based on Article 6 (1) point a) of the Regulation.
The main characteristics of the cookies used by the website:
Cookies strictly necessary for operation: These cookies are essential for the use of the website and enable the use of the basic functions of the website. In the absence of these, many functions of the site will not be available to you. The lifetime of these types of cookies is limited to the duration of the session.
Cookies to improve the user experience: These cookies collect information about the user's use of the website, for example, which pages are visited most often or what error message is received from the website. These cookies do not collect information that identifies the visitor, that is, they work with completely general, anonymous information. We use the data obtained from these to improve the performance of the website. The lifetime of these types of cookies is limited to the duration of the session.
Cookies placed by third parties (analytics)
Remarketing cookies: May be displayed to previous visitors or users when they browse other websites in the Google Display Network and search for terms related to your products or services
Session cookie: These cookies store the location of the visitor, the language of the browser, the currency of the payment, and their lifetime is until the browser is closed, or a maximum of 2 hours.
Mobile version, design cookie: Detects the device used by the visitor and switches to full view on mobile. Its lifespan is 365 days.
Cookie acceptance cookie: When you arrive at the page, you accept the statement on the storage of cookies in the warning window. Its lifespan is 365 days.
Data related to online ordering
Itemized list of personal data requested during online ordering: Name, phone number, billing address, delivery address, e-mail address
Data related to online administration Itemized list of personal data requested during online administration: Full name, delivery address, order number, phone number
Data related to the newsletter Data processing activity related to sending the newsletter Name of the company operating the newsletter sending system: MailChimp
The Data Processor participates in the sending of newsletters based on the contract concluded with the Data Controller. In doing so, the Data Processor processes the data subject's name and e-mail address to the extent necessary for the newsletter.
You can unsubscribe from our newsletter at any time. If there is a problem with the service provider sending the newsletter and the unsubscribe does not take place, please notify our customer service and your e-mail address will be removed from the list manually.
Purpose, method and legal basis of data management
General data management guidelines
The data management of the Data Controller's activities is based on voluntary consent and legal authorization. In the case of data processing based on voluntary consent, the data subjects may withdraw their consent at any stage of the data processing.
In some cases, the management, storage, and transmission of a range of the provided data is made mandatory by law, of which we notify our customers separately.
We draw the attention of informants to the Data Controller that if they do not provide their own personal data, the informant is obliged to obtain the consent of the data subject.
Its basic data management principles are in line with the applicable legislation on data protection, and in particular with the following:
CXII of 2011 law - on the right to self-determination of information and freedom of information (Infotv.);
Regulation (EU) 2016/679 of the European Parliament and of the Council (April 27, 2016) - on the protection of natural persons with regard to the processing of personal data and on the free flow of such data, and on the repeal of Regulation 95/46/EC ( general data protection regulation, GDPR);
Act V of 2013 - on the Civil Code (Ptk.);
Act C of 2000 - on accounting (Accounting Act);
LIII of 2017 Act - on the prevention and prevention of money laundering and terrorist financing (Pmt.);
CCXXXVII of 2013 Act - on credit institutions and financial enterprises (Hpt.).
The physical storage locations of the data
Your personal data (that is, the data that can be linked to your person) can be processed by us in the following way: on the one hand, in connection with maintaining the Internet connection, technical data related to the computer you use, browser program, Internet address, and visited pages are automatically generated in our computer system, on the other hand, you can also provide your name, contact information or other data if you wish to contact us personally when using the website.
Data that is technically recorded during the operation of the system: the data of the concerned applicant's computer, which are generated during the voting and which are recorded by the ... system as an automatic result of the technical processes. The data that is recorded automatically is automatically logged by the system upon entry and exit without a separate statement or action by the person concerned. This data cannot be combined with other personal user data, except in cases made mandatory by law. Only ... has access to the data.
Data transmission, data processing, the circle of those familiar with the data
Itemized list of companies that transmit, store, and learn data. List of data and contact information of the given companies. (e.g. accounting, invoicing, delivery of goods, crm system, online payment, etc.)
Name of the data processor: Wix.com
Name of the data processor: GLS, MyGls, DPD, DHL
Name of the data processor: PayPal
Name of the data processor: Billingo
The Data Processor participates in the registration of orders based on the contract concluded with the Data Controller. In doing so, the Data Processor processes the data subject's name, address, telephone number, number and date of orders within the civil law limitation period.
Your rights and remedies
Within the period of data management, you are entitled to the following rights according to the provisions of the Regulation:
the right to withdraw consent
access to personal data and information about data management
right to rectification
restriction of data management,
right to erasure
right to protest
right to portability.
If you wish to exercise your rights, it involves your identification, and the Data Controller must communicate with you as necessary. Therefore, for the purpose of identification, it will be necessary to provide personal data (but the identification can only be based on data that the Data Controller manages about you anyway), and your complaint about data management will be available in the Data Controller's email account within the period specified in this information regarding complaints. If you were a customer of ours and would like to identify yourself in order to handle complaints or warranty, please enter your order ID for identification. Using this, we can also identify you as a customer.
The Data Controller will respond to complaints related to data management within 30 days at the latest.
Right to information
The Data Controller takes appropriate measures in order to provide the data subjects with all information regarding the processing of personal data referred to in Articles 13 and 14 of the GDPR and Articles 15-22. and provide each piece of information according to Article 34 in a concise, transparent, comprehensible and easily accessible form, clearly and comprehensibly worded.
The data subject's right of access
You are entitled to receive feedback from the Data Controller as to whether your personal data is being processed, and if it is being processed, you are entitled to:
get access to the processed personal data and
inform the Data Controller of the following information:
the purposes of data management;
categories of personal data processed about you;
information about the recipients or categories of recipients to whom the personal data has been or will be disclosed by the Data Controller;
the planned period of storage of personal data or, if this is not possible, the criteria for determining this period;
your right to request from the Data Controller the correction, deletion or restriction of processing of your personal data and, in the case of data processing based on legitimate interests, to object to the processing of such personal data;
the right to submit a complaint to the supervisory authority;
if the data was not collected from you, any available information about its source;
about the fact of automated decision-making (if such a procedure is used), including profiling, as well as, at least in these cases, comprehensible information about the logic used and the significance of such data management and the expected consequences for you.
The purpose of exercising the right may be aimed at establishing and checking the legality of data management, therefore, in case of multiple requests for information, the Data Controller may charge a fair fee in exchange for providing the information.
Access to personal data is ensured by the Data Controller by sending the processed personal data and information to you by email after your identification. If you have registered, we provide access so that you can view and check your personal data by logging into your user account.
Please indicate in your request that you are requesting access to personal data or information related to data management.
Right to rectification
You have the right to request that the Data Controller correct inaccurate personal data concerning you without delay.
Right to erasure
If one of the following reasons exists, the data subject has the right to request that the Data Controller delete his/her personal data without undue delay:
personal data are no longer needed for the purpose for which they were collected or otherwise processed;
the data subject withdraws the consent that forms the basis of the data management, and there is no other legal basis for the data management;
the data subject objects to data processing and there is no overriding legal reason for data processing;
personal data has been processed unlawfully;
the personal data must be deleted in order to fulfill the legal obligation prescribed by the EU or Member State law applicable to the data controller;
the collection of personal data took place in connection with the offering of services related to the information society.
Data deletion cannot be initiated if data management is necessary: for the purpose of exercising the right to freedom of expression and information; for the purpose of fulfilling the obligation under the EU or Member State law applicable to the data controller requiring the processing of personal data, or for the execution of a task performed in the public interest or in the context of the exercise of public authority conferred on the data controller; affecting the field of public health, or for archival, scientific and historical research purposes or for statistical purposes, on the basis of public interest; or to submit, assert or defend legal claims.
The right to restrict data processing
At the request of the data subject, the Data Controller restricts data processing if one of the following conditions is met:
the data subject disputes the accuracy of the personal data, in this case the limitation is for that period of time
applies, which allows checking the accuracy of personal data;
the data processing is illegal and the data subject opposes the deletion of the data and instead requests the restriction of its use;
the data controller no longer needs the personal data for the purpose of data management, but the data subject requires them to present, enforce or defend legal claims; obsession
the data subject objected to data processing; in this case, the restriction applies to the period until it is determined whether the legitimate reasons of the data controller take precedence over the legitimate reasons of the data subject.
If data management is subject to restrictions, personal data may only be processed with the consent of the data subject, with the exception of storage, or to submit, enforce or defend legal claims, or to protect the rights of another natural or legal person, or in the important public interest of the Union or a member state.
Right to data portability
If the data management is carried out in an automated way or if the data management is based on your voluntary consent, you have the right to ask the Data Controller to receive the data you have provided to the Data Controller, which the Data Controller sends in xml, JSON or csv format to your at your disposal, if this is technically feasible, you can request that the Data Controller forward the data in this form to another data controller.
Right to protest
The data subject has the right to object at any time for reasons related to his own situation to the processing of his personal data necessary for the performance of a task carried out in the public interest or within the framework of the exercise of public authority granted to the data controller, or the processing necessary to enforce the legitimate interests of the data controller or a third party, including profiling based on the aforementioned provisions too. In the event of a protest, the data controller may no longer process the personal data, unless it is justified by compelling legitimate reasons that take precedence over the interests, rights and freedoms of the data subject, or that are related to the presentation, enforcement or defense of legal claims.
Automated decision-making in individual cases, including profiling
The data subject has the right not to be covered by the scope of a decision based solely on automated data management, including profiling, which would have a legal effect on him or affect him to a similar extent.
Right of withdrawal
The data subject has the right to withdraw his consent at any time.
Right to go to court
In the event of a violation of their rights, the data subject may apply to the court against the data controller. The court acts out of sequence in the case.
Data protection official procedure
You can file a complaint with the National Data Protection and Freedom of Information Authority:
Name: National Data Protection and Freedom of Information Authority
Headquarters: 1125 Budapest, Szilágyi Erzsébet fasor 22/C. Mailing address: 1530 Budapest, Pf.: 5.
We provide information on data management not listed in this information when the data is collected.
We inform our customers that the court, the prosecutor, the investigative authority, the infringement authority, the public administrative authority, the National Data Protection and Freedom of Information Authority, the Hungarian National Bank, or other bodies based on the authorization of the law, provide information, communicate data, transfer documents, or they can contact the data controller to make it available.
If the authority has specified the exact purpose and scope of the data, the Data Controller will only release personal data to the authorities to the extent and to the extent that is absolutely necessary to achieve the purpose of the request.
This document contains all relevant data management information regarding the operation of the webshop in accordance with the European Union's General Data Protection Regulation No. 2016/679 (hereinafter: Regulation. GDPR) and CXII of 2011. TV. (hereinafter: Infotv.) based on