Data protection information
I.1. Volvex Kereskedelmi Korlátolt Felelősségű Társaság (registered office: 1139 Budapest, Rozsnyai utca 31., tax number: 12536366-2-41, contact: tel.: +361 451 0042, e-mail: info@volvex.hu, hereinafter referred to as the "Operator") attaches great importance to the website www.volvex.hu (hereinafter referred to as the "Website") operated by the Operator, the protection of the personal data provided by its visitors, those placing and registering orders on the Website and those visiting the Operator's sales premises in person (hereinafter referred to as the "User") during registration / ordering / requesting electronic information by the User / visiting the sales premises, and the protection of the Users' right to information self-determination, which is ensured in the manner set out in these Rules.
Through the Website you can buy a wide range of shoes online. The Operator processes the data received during the identification of Users for the purpose of fulfilling their orders. The Operator is the data controller of all data which is considered personal data and which is uploaded by Users during their visit to the Website or during the use of any of the Services of the Website.
The Operator processes the personal data of Users in full compliance with the applicable laws in force, which contributes to the creation of safe Internet access for Users.
The Operator shall treat the personal data of Users confidentially, in accordance with the applicable legal provisions, in particular the provisions of Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (Info tv.), and Regulation (EU) 2016/679 of the European Parliament and of the Council of 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (2016. (EU) Regulation (EU) No 2016/679/EC of the European Parliament and of the Council of 27 April 2016 (hereinafter "GDPR")), ensure their security, take the technical and organisational measures and establish the procedural rules necessary to give effect to the relevant legal provisions and other recommendations.
I.2. This Policy summarizes the principles that define the Operator's policy and daily practice regarding the protection of personal data, describes the services in the course of which the Operator requests personal data from the Users of the Website, and provides a statement of the purposes for which and how the Operator uses such data and how it ensures the preservation and protection of personal data.
I.3. In developing the Code, the Operator has taken into account the relevant legislation in force and the main international recommendations, in particular:
Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information;
Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC;
Act No VI of 1998 on the proclamation of the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, Strasbourg, 28 January 1981;
Act CXIX of 1995 on the processing of name and address data for the purposes of research and direct marketing;
Act C of 2003 on electronic communications;
Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions on Economic Advertising (Act XLVIII of 2008);
The recommendations, positions and data protection practices of the EDPS.
I.4. Upon Users' request, the Operator shall in any case provide detailed information on the personal data processed, the purpose, legal basis, duration and activities related to the processing, as specified in the request.
The Operator shall only process personal data that is necessary to quantify the number of visits to the Website, to exercise its rights and obligations in its legal relationship with Users, to communicate with them and to conduct direct business with Users.
II. Concepts and key principles relating to the processing of personal data
II.1. Concepts
II.1.1. Data processing: any operation or set of operations which is performed upon data, regardless of the procedure used, in particular any collection, recording, recording, organisation, storage, alteration, use, retrieval, disclosure, transmission, alignment or combination, blocking, erasure or destruction of data, prevention of their further use, taking of photographs, sound recordings or images and physical features which can be used to identify a person (e.g. fingerprints, palm prints, DNA samples, iris scans).
II.1.2. Transfer: making data available to a specified third party.
II.1.3. Data controller: the natural or legal person or unincorporated body which, alone or jointly with others, determines the purposes for which the data are to be processed, takes and implements decisions regarding the processing (including the means used) or has the data processed by a processor.
II.1.4. Data subject: any natural person who is identified or can be identified, directly or indirectly, on the basis of personal data.
II.1.5. Personal data: data which can be associated with the data subject, in particular the name, the identification mark and one or more factors specific to his or her physical, physiological, mental, economic, cultural or social identity, and the inference which can be drawn from the data concerning the data subject.
II.1.6. Data breach: unlawful processing or handling of personal data, in particular unauthorised access, alteration, disclosure, transmission, disclosure, erasure or destruction, accidental destruction or accidental damage.
II.1.7. Profiling: any form of automated processing of personal data in which personal data are used to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict characteristics associated with that person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
II.1.8. De-identification: processing of personal data in such a way that it is no longer possible to identify the natural person to whom the personal data relate without further information, provided that such further information is kept separately and technical and organisational measures are taken to ensure that no association with an identified or identifiable natural person is possible;
II.2 Principles
II.2.1. Legality, fairness and transparency
Personal data may only be processed for specific purposes, for the exercise of rights and the performance of obligations. The collection and processing of data must be fair and lawful.
Personal data may only be processed if the data subject consents to it or if it is ordered by law or - on the basis of a statutory authorisation and within the scope specified therein - by a local government decree for a purpose in the public interest (hereinafter: mandatory processing).
II.2.2. Specificity of purpose
At all stages of the processing, the purpose of the processing must be fulfilled.
II.2.3. Data economy
Only personal data that is necessary for the purpose of the processing and is suitable for achieving that purpose may be processed.
II.2.4. Accuracy
The controller is obliged to take measures to ensure the accuracy (correctness) of the data it processes.
II.2.5. Limited shelf life
Personal data may only be processed to the extent and for the duration necessary for the purpose.
Personal data must be erased if the processing is unlawful; the data subject requests it; it is incomplete or inaccurate - and this situation cannot be lawfully remedied - provided that erasure is not excluded by law; the purpose of the processing has ceased or the statutory time limit for storing the data has expired; or it has been ordered by a court or the National Authority for Data Protection and Freedom of Information (NAIH).
II.2.6. Integrity and confidentiality
In particular, appropriate measures must be taken to protect the data against unauthorised access, alteration, disclosure, disclosure, erasure or destruction, accidental destruction or accidental damage and against inaccessibility resulting from changes in the technology used.
If a User provides personal data to the Operator, the Operator will take all necessary steps to ensure the security of such data - both during network communication (i.e. online data management) and during storage and retention (i.e. offline data management).
Personal data can only be accessed by persons holding the relevant job titles - with a high level of access controls.
II.2.7. Accountability
The data subject may request from the controller (i) information about the processing of his or her personal data, (ii) rectification of his or her personal data, and (iii) erasure or blocking of his or her personal data, except for mandatory processing.
II.2.8. As a general principle, the Operator declares that in all cases where it requests personal data from its Users, they are free to decide whether or not to provide the requested information after reading and understanding the required information text. It should be noted, however, that if a User does not provide personal data, he/she will not be able to use the services of the Site subject to registration.
The Operator respects the principles of data management and strives to enforce them at all times.
III. Legal basis for processing
The Operator processes the data in Chapter V on the following legal grounds:
III.1. Legal basis for data processing: article 13/A (3) of Act CVIII of 2001 on certain aspects of electronic commerce services and information society services and article 6 (1) (c) of GDPR (name, delivery address, billing address).
With regard to point IV.2., the legal basis for processing is also: in addition to the voluntary consent of the data subject (Article 6 (1) (a) GDPR), the legitimate interest of the Operator and the User (Article 6 (1) (d) and (f) GDPR; image capture), processing based on a contract (Article 6 (1) (b) GDPR; name, delivery address, billing address), the legal basis of the Grt. Article 6 (5) GDPR (Article 6 (1) (c) GDPR; name, e-mail address), and in the case of a request for information by e-mail, Article 6 (1) (b) and (f) GDPR (name, e-mail address).
The Operator confirms that the legal basis for processing under Article 6(1)(b) of the GDPR (based on contract) shall be transformed into a legal basis under Article 6(1)(b) and (f) of the GDPR (legitimate interest) in the event of a breach.
III.2. The Operator shall process the User's data described in Section V.1. on the basis of the data subject's voluntary consent (Article 6(1)(a) GDPR) and on the basis of contractual obligations (Article 6(1)(b) GDPR; name, delivery address, billing address) and in accordance with the rules of Act CVIII of 2001 on certain aspects of electronic commerce services and information society services.
The User gives his/her consent in person or in electronic form1 during the use of the Website in the process of registration / order / electronic information request by the User by signing the Data Protection Declaration / ticking the tickbox2. The User may withdraw his/her consent at any time and thereby request the deletion / forgetting of his/her data or modify the data to which he/she has given his/her consent. In the case of an ongoing order, the withdrawal of consent to data processing shall be deemed to constitute withdrawal from the order, which the Operator shall specifically draw the User's attention to in the request for deletion / forgetting, with the Operator being entitled to process the User's data pursuant to Article 6 (1) (f) GDPR until the pre-contractual situation has been restored by the parties as a result of the withdrawal. The withdrawal of consent pursuant to Articles 7(3) and 13(2)(c) of the GDPR shall not affect the lawfulness of the processing prior to the withdrawal.
III.3. The Operator shall use the User's personal data (image recording) recorded in Section V for the purposes of quality assurance, asset security, crime prevention and detection in accordance with Article 6(1)(b) of the Info Act and Article 6(1)(f) of the GDPR, in proportion to the restriction of the rights to the protection of personal data, for the purposes of the legitimate interests of the Operator and third parties, and in addition in accordance with Section V.7.. in accordance with Article 6(1)(c) of the GDPR by reference to Article 17/B(3) of the Consumer Protection Act.
IV. Purpose of data processing
The Operator processes the data in Chapter V for the following purposes:
IV.1. Purpose of the Processing: i) to fulfil orders (name, delivery address); ii) to monitor the functioning of the service (name, telephone number, e-mail address); iii) to prevent abuse (name, telephone number, e-mail address); (iv) to identify and distinguish Users (name, date of birth, telephone number, delivery address, billing address, e-mail address, username, password); (v) to contact them (name, telephone number, e-mail address); (vi) to generate statistics (pseudonymisation per order); (vii) to send targeted advertising messages (name, e-mail address); (viii) exercise of rights related to the legal relationship with Users (customers) (name, billing address, telephone number, e-mail address); (ix) fulfilment of obligations (name, delivery address, billing address, date of birth, telephone number, e-mail address); (x) issuing of invoices (name, billing address); xi) monitoring and recording traffic and user habits, thereby offering personalised advertisements to Website Users (name, order details); xii) detecting and preventing theft of property and unlawful acts (image capture).
IV.2. By providing their data in person, or in electronic form during the registration/ordering/user electronic information request process when using the Website, Users may give their consent to the Operator to contact them with direct marketing offers, electronic advertisements (newsletter, e-mail, SMS, etc.) on the contact details provided. Consent may be withdrawn at any time, free of charge, without restriction and without giving any reason, and may also be withdrawn in the manner indicated in the electronic advertisement. Consent may also be withdrawn by means of a declaration addressed to the Operator and sent by post to the Operator's head office. In the case of an ongoing order, the withdrawal of consent to the processing of the data (in relation to the newsletter) provided for in this point shall not affect the fulfilment of the order. Pursuant to Articles 7(3) and 13(2)(c) of the GDPR, the withdrawal of consent shall not affect the lawfulness of the processing that preceded it.
IV.3. In all cases where the Operator intends to use the personal data provided for purposes other than those for which they were originally collected, the Operator shall inform the User thereof and obtain his/her prior explicit consent or provide the User with the opportunity to prohibit such use.
V. Subject matter of the processing
V.1. Registration is not a prerequisite for placing an order on the Website. Depending on the User's needs, there are therefore two levels of use of the Site, which require the provision of different data, for the purposes of the legal form referred to in point III and the purposes referred to in point IV.1:
V.1.1. For non-registered Users:
Name, Shipping address, Billing address, Phone number, E-mail address, Date of birth, Personal photo (snapshot) - if applicable
The scope of the data processed is defined by the User's proof of capacity (date of birth), the fulfilment of the order (name, delivery address), contact (name, telephone number, e-mail address) and the provision of billing conditions (name, billing address). The justification for the use of the image as the data processed is set out in point V.
V.1.2. For Registered Users:
Name, Shipping Address, Billing Address, Phone Number, Email Address, Date of Birth, Username, Password, Personal Image (photo) - if applicable
The scope of the data processed is defined by the User's proof of capacity (date of birth), the fulfilment of the order (name, delivery address), contact (name, telephone number, e-mail address) and the conditions for billing (name, billing address), as well as the condition of using the Website as a registered user (username, password). The justification for the use of image capture as processed data is set out in Section V.
V.2. The provision of personal data is based on a legal and contractual obligation and is a prerequisite for the conclusion of a contract for the order. The User is obliged to provide personal data if he wishes to make an online purchase. Failure to provide the data will prevent the online order.
V.3. Parental consent is required for the processing of data provided by users under the age of 16 and for the making of statements. The consent of the legal representative of a minor over the age of 16 is not required for the validity of a declaration of consent by the data subject.
V.4. Under no circumstances will the Operator collect any special data concerning racial origin, national, ethnic or national minority origin, political opinions or political party affiliations, religious or other beliefs, health, medical conditions, pathological addiction, sexual life or criminal history.
V.5. The Operator does not supplement or combine the personal or other data provided by Users with data or information from other sources.
V.6. The Operator shall record events on the premises for security, detection and crime prevention purposes on camera and store the material for 3 working days. The Operator shall also warn the User of the fact of the image recording by means of a sign posted in a clearly visible place in the premises of the vendor. The User consents to the image recording by entering the sales premises and by signing the Data Management Declaration / ticking the tickbox1. If the User does not consent to the recording of the image as set out in point III.3, he/she may use the online ordering and customer service (chat, e-mail). The legal basis for the processing of the data is Article 6(1)(d) and (f) of the GDPR.
V.7. Some of the Users' data, such as their IP address, other traffic data and behavioural data are also recorded in order to quantify the number of visits to the Website and to enable the Operator to identify possible errors and intrusions. These data will be processed by the Operator only for the necessary period of time and will not be linked to other data that would allow the identification of the User (pseudonymisation). The data may also be processed on servers located abroad.
VI. Duration of processing
VI.1. Duration of data processing:
VI.1.1. In the case of non-registered users (see V.1.1.), for 3 years after the purpose of the processing (delivery of the order and payment of the invoice) (expiry of the warranty period), or until any other date specified by law. Invoicing data (name, invoicing address) will be stored for 8 years from the date of invoice issue in accordance with § 169 (2) of the Accounting Act.
VI.1.2. In the case of a registered user (see V.1.2.), for 3 years after the date of cancellation of the registration, or, if an order was placed prior to the cancellation of the registration and has not been fulfilled by the date of cancellation of the registration, for the period of time specified in VI.1.1.
Invoicing data (name, billing address) will be kept for 8 years from the date of issue of the invoice in accordance with Section 169 (2) of the Accounting Act.
VI.1.3. In the case of images recorded at the Operator's sales premises in accordance with point V.6, the period of data processing is 3 working days. If during this period there is no need to store the recorded material, it will be automatically deleted at the end of the 5th working day. In justified cases, the Operator (if it has become aware of content to be used as evidence in official proceedings) shall process the image recording until the purpose is achieved (until a final decision is taken).
VI.2. The User may at any time withdraw his/her consent to data processing, request the deletion of the data concerned by the consent or modify his/her data. In the case of an ongoing order, the withdrawal of consent to data processing shall constitute withdrawal from the order, which the Operator shall specifically draw the User's attention to in the request for deletion / cancellation, with the Operator being entitled to process the User's data pursuant to Article 6 (1) (f) of the GDPR until the pre-contractual situation has been restored by the parties as a result of the withdrawal. The withdrawal of consent pursuant to Articles 7(3) and 13(2)(c) of the GDPR shall not affect the lawfulness of the processing prior to the withdrawal.
VI.3. If the personal data has been collected with the consent of the User, the Operator shall, unless otherwise provided by law,.
(a) for the purpose of complying with a legal obligation to which it is subject; or
(b) for the purposes of the legitimate interests pursued by the Operator or by a third party, where such interests are proportionate to the restriction of the right to the protection of personal data
without any further specific consent and even after the withdrawal of the data subject's consent.
VII. Exercise of the data subject's rights
VII.1. If any User requests the deletion of personal data from the Operator's system in accordance with VII.2, the Operator shall promptly comply by deleting from its database the corresponding data previously indicated by the User.
VII.2. The request for cancellation/forgetting may be submitted electronically via the e-mail address of the Customer Service or via the chat window on the Website, in paper form by letter sent to the Operator's headquarters, orally via the telephone helpdesk or at the sales premises. The Operator will send the User a written confirmation of the request for deletion/forgetting communicated orally.
In the event of a request for erasure (withdrawal of consent), the data processed by the Operator may no longer be processed from the date of receipt of the request.
In the event of a request for oblivion, the Operator shall delete from the system all contacts involving data lawfully processed prior to the receipt of the request, the profile created for the User and the automatic decision.
VII.3. If there has been a change in the data processed, the User may request that it be amended in the database. The request for modification may be made electronically via the e-mail address of the Customer Service or via the chat window on the Website, in paper form by letter sent to the Operator's head office, orally via the telephone helpdesk or at the sales offices. The Operator will send a written confirmation of the request for modification communicated orally to the User.
VII.4. Instead of deletion, the Operator shall block the personal data if the User so requests or if, on the basis of the information available to it, it can be assumed that deletion would harm the legitimate interests of the User. The personal data blocked in this way may be stored only for as long as the purpose of the processing, which precluded the deletion of the personal data, persists. Except for storage, the restricted data may be processed only with the consent of the User or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for important public interests (right to restriction of processing).
VII.5. If the Operator fails to comply with the User's request for rectification, blocking or erasure, it shall, within 25 days of receipt of the request, inform the User in writing, using one of the contact details provided by the User, of the factual and legal grounds for refusing the request for rectification, blocking or erasure. In the event of rejection of a request for rectification, erasure or blocking, the Operator shall inform the User of the possibility of judicial remedy and of recourse to the supervisory authority.
VII.6. The User may object to the processing of his/her personal data,
(a) where the processing or transfer of personal data is necessary solely for compliance with a legal obligation to which the Operator is subject or for the purposes of the legitimate interests pursued by the controller, the recipient or a third party, except in the case of mandatory processing;
(b) where the personal data are used or disclosed for direct marketing, public opinion polling or scientific research purposes; and
c) in other cases provided by law.
In the event of the User's objection, the Operator is not entitled to further processing, unless it proves that the processing is justified by compelling legitimate grounds which override the interests and rights of the User or are related to the establishment, exercise or defence of legal claims.
With regard to data processed on the basis of Article 6 (1) (d) and (f) (legitimate interest) of the GDPR, the User may object to the processing of his/her data instead of requesting deletion / withdrawing consent.
The Operator, as the data controller, shall examine the objection within the shortest possible time, but not later than 15 days from the submission of the request, shall decide on its validity and shall inform the requesting User in writing of its decision.
VII.7. Users may request information about the processing of their personal data. The request for information can be made electronically via the e-mail address of the customer service or the chat window on the Website, in paper form by sending a letter to the Operator's headquarters, or orally via the telephone helpdesk or at the sales premises. The Operator will send a written confirmation of the request for information communicated orally to the User.
Upon the User's request, the Operator shall provide information about the User's data processed by it, their source, the purpose, legal basis and duration of data processing, the fact and legal basis of data transfer, the name and address of the recipient and all its activities related to data processing. The Operator shall provide the information in writing in an intelligible form within the shortest possible time from the date of the request, but not later than 30 days from the date of the request, upon the User's request.
The information described above is free of charge if the person requesting the information has not yet submitted a request for information to the Operator for the same data set in the current year. In other cases, a fee may be charged. The fee already paid shall be refunded if the data have been processed unlawfully or if the request for information has led to a correction.
The Operator may refuse to provide the data subject with information only in the cases specified in the Info. In the event of refusal to provide information, the Operator shall inform the data subject in writing of the provision of this Act on the basis of which the information was refused. In the event of refusal to provide information, the Operator shall inform the User of the possibility of judicial remedy and of recourse to the National Authority for Data Protection and Freedom of Information. The Data Controller shall notify the Authority of rejected requests annually by 31 January of the year following the year in question.
VII.8. Data portability
Pursuant to Article 20 of the GDPR, the User is entitled to receive the data provided by him/her to the Operator in a structured, commonly used, machine-readable format and to transmit it to another data controller.
The User may request the direct transfer of the data to another controller - if technically feasible.
The request for data transfer can be made electronically via the e-mail address of the Customer Service or the chat window on the Website, in paper form by sending a letter to the Operator's headquarters, orally via the telephone helpdesk or at the sales premises. The Operator will send the User a written confirmation of the oral request for data transfer.
If the Operator does not comply with the User's request for data transfer, the Operator shall, within 30 days of receipt of the request, inform the User in writing, using one of the contact details provided by the User, of the factual and legal reasons for the refusal. In the event of refusal of a request for data transfer, the Operator shall inform the User of the possibility of judicial remedy and of recourse to the supervisory authority.
The User has no right to data portability with regard to data processed on the basis of Article 6(1)(d) and (f) of the GDPR (legitimate interest).
IX. Placement of Anonymous User Identification (cookie) and web beacons
IX.1. The Operator, like many other businesses, uses cookies on the Website. Details of how to set "cookies" and "web beacons" when using the Website are set out in the Information Notice on the setting of anonymous user identifiers ("cookies") and web beacons ("web beacons"), which is set out in a separate document.
X. Data storage, processing and transmission
X.1. Storage of data
The Operator stores the processed data in an Internet cloud created for this purpose and accessible only by our company, or on its own server designated for this purpose.
The location where the server is stored and operated:
BPC Rendszerház Kft.
Our address:1138 Budapest, Váci út 152-156.
Telephone: +36 1 226 2993
Email: info@bpcrendszerhaz.hu
X.2. Data processing
The operator does not use a data processor.
X.3. Data transmission
The User gives his/her consent to the transfer of data/transfer of data abroad in person or electronically during the use of the Website in the registration/ordering process1 by signing the Data Processing Declaration / ticking the tickbox2. The User may withdraw his/her consent at any time. In the case of an ongoing order, the withdrawal of consent to the transfer of data shall constitute withdrawal from the order, which the Operator shall specifically draw the User's attention to in the request for cancellation, stating that the Operator is entitled to process the User's data pursuant to Article 6 (1) (f) of the GDPR until the pre-contractual situation has been restored by the parties as a result of the withdrawal. The withdrawal of consent pursuant to Articles 7(3) and 13(2)(c) of the GDPR shall not affect the lawfulness of the processing prior to the withdrawal.
X.4. Guarantees provided by the Operator
The Operator undertakes to protect the User's personal data unconditionally and irrevocably. It is the responsibility of the Operator to verify the adequacy of the partners used for further processing and processing of personal data, thus ensuring the required protection of personal data.
The recipient of the data transfer to the third country and the data processors have committed themselves in a specific agreement with the Operator on the protection of personal data to take measures to ensure a level of protection in accordance with the data protection legislation in force and in force in the EU. Such contracts provide the Operator with sufficient opportunity and means to enforce adequate protection of personal data, guaranteeing the User the protection and exercise of his rights.
It is the responsibility of the Operator to submit the agreements provided for in this clause and any amendments thereto to the National Authority for Data Protection and Freedom of Information and the competent supervisory authority for approval pursuant to Article 46(3) of the GDPR.
XI. Data security measures, Data Protection Officer
XI.1. Data security measures
The Operator shall exercise the utmost care in handling and storing the personal data provided by Users. In the field of IT security, the Operator shall use the most effective and up-to-date tools and procedures reasonably available.
The Controller shall design and implement the processing operations in such a way as to ensure the protection of the privacy of the Users concerned. The Operator shall ensure the security of the data, and shall take the technical and organisational measures and have established the procedural rules necessary to enforce the Info Act and other data protection and confidentiality rules.
XI.1.1. The Operator shall take appropriate measures to protect the data against, in particular, unauthorised access, alteration, disclosure, disclosure, deletion or destruction, accidental destruction or damage, and inaccessibility due to changes in the technology used.
XI.1.2. In order to protect the data files managed electronically in various registers, the Operator shall ensure by means of appropriate technical solutions that the data stored in the registers cannot be directly linked and attributed to the User concerned, unless permitted by law.
XI.1.3. The Operator has chosen and operates the IT tools used to process personal data in the course of providing the service in such a way that the data processed:
a) accessible to authorised persons (availability);
b) its authenticity and authenticity is assured (authenticity of processing);
c) its immutability can be verified (data integrity);
d) be protected against unauthorised access (data confidentiality).
XI.1.4. The Operator shall ensure the security of data management by technical, organisational and organisational measures that provide a level of protection appropriate to the risks associated with data management.
XI.1.5. The Operator's IT systems and network are protected against computer fraud, espionage, sabotage, vandalism, fire and flood, computer viruses, computer intrusions and denial of service attacks. The Operator shall ensure security through server-level and application-level protection procedures.
XI.1.6. Electronic messages transmitted over the Internet, regardless of the protocol (e-mail, web, ftp, etc.) are vulnerable to network threats that could lead to fraudulent activity or to the disclosure or modification of information. The Operator will take all reasonable precautions to protect against such threats. It shall monitor systems in order to record and provide evidence of any security incidents. However, the Internet is not, as is well known to Users, 100% secure. The Operator shall not be liable for any damage caused by an unprotected attack, despite the utmost care.
XI.2. Data Protection Officer
The Operator declares that it is not obliged to employ a Data Protection Officer under the GDPR and therefore does not employ a Data Protection Officer.
XII. Renaming, statistics
XII.1 The Operator may use the data for statistical purposes after pseudonymisation. The use of the data in aggregate statistical form shall not include the name or any other identifiable data of the User concerned.
XIII Automated decision-making
The User gives his/her consent to the automated decision-making in person or in electronic form during the use of the Website in the process of registration / order / electronic information request by the User by signing the Data Processing Declaration / ticking the tickbox. The User may withdraw his/her consent at any time. In the case of an ongoing order, the withdrawal of consent shall constitute withdrawal from the order, which the Operator shall specifically draw the User's attention to in the request for cancellation, stating that the Operator shall be entitled to process the User's data pursuant to Article 6 (1) (f) GDPR until the pre-contractual situation has been restored by the parties as a result of the withdrawal. The withdrawal of consent pursuant to Articles 7(3) and 13(2)(c) of the GDPR shall not affect the lawfulness of the processing prior to the withdrawal.
XIV. Consumer complaints
XIV.1. The Operator's customer service receives complaints and user enquiries regarding the Operator's services and personal data protection partly on the dedicated telephone customer service line and by e-mail, at +361 451 0042 and at info@volvex.hu.
XIV.2. The User sending a complaint may seek redress by lodging a complaint with the competent court or the National Authority for Data Protection and Freedom of Information (NAIH): 1024 Budapest, Szilágyi Erzsébet fasor 22/C. (www.naih.hu).
XV. Execution of official requests
XV.1. The court, the prosecutor, the investigating authority, the administrative authority, the data protection commissioner, or other bodies authorised by law may request the Operator to provide information, to disclose or transfer data, or to make documents available.
XV.2. The Operator shall disclose to the public authorities - if the public authority has indicated the precise purpose and scope of the data - personal data only to the extent and to the extent strictly necessary for the purpose of the request.
If you do not agree with the above, please do not use the Website.
If you have any further questions about data protection, please contact us.
These Rules are publicly available on the Website from the date of their publication, from which date they shall take effect.
Budapest, 2018.05.24.
Data protection information
I.1. Volvex Kereskedelmi Korlátolt Felelősségű Társaság (registered office: 1139 Budapest, Rozsnyai utca 31., tax number: 12536366-2-41, contact: tel.: +361 451 0042, e-mail: info@volvex.hu, hereinafter referred to as the "Operator") attaches great importance to the website www.volvex.hu (hereinafter referred to as the "Website") operated by the Operator, the protection of the personal data provided by its visitors, those placing and registering orders on the Website and those visiting the Operator's sales premises in person (hereinafter referred to as the "User") during registration / ordering / requesting electronic information by the User / visiting the sales premises, and the protection of the Users' right to information self-determination, which is ensured in the manner set out in these Rules.
Through the Website you can buy a wide range of shoes online. The Operator processes the data received during the identification of Users for the purpose of fulfilling their orders. The Operator is the data controller of all data which is considered personal data and which is uploaded by Users during their visit to the Website or during the use of any of the Services of the Website.
The Operator processes the personal data of Users in full compliance with the applicable laws in force, which contributes to the creation of safe Internet access for Users.
The Operator shall treat the personal data of Users confidentially, in accordance with the applicable legal provisions, in particular the provisions of Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (Info tv.), and Regulation (EU) 2016/679 of the European Parliament and of the Council of 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (2016. (EU) Regulation (EU) No 2016/679/EC of the European Parliament and of the Council of 27 April 2016 (hereinafter "GDPR")), ensure their security, take the technical and organisational measures and establish the procedural rules necessary to give effect to the relevant legal provisions and other recommendations.
I.2. This Policy summarizes the principles that define the Operator's policy and daily practice regarding the protection of personal data, describes the services in the course of which the Operator requests personal data from the Users of the Website, and provides a statement of the purposes for which and how the Operator uses such data and how it ensures the preservation and protection of personal data.
I.3. In developing the Code, the Operator has taken into account the relevant legislation in force and the main international recommendations, in particular:
Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information;
Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC;
Act No VI of 1998 on the proclamation of the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, Strasbourg, 28 January 1981;
Act CXIX of 1995 on the processing of name and address data for the purposes of research and direct marketing;
Act C of 2003 on electronic communications;
Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions on Economic Advertising (Act XLVIII of 2008);
The recommendations, positions and data protection practices of the EDPS.
I.4. Upon Users' request, the Operator shall in any case provide detailed information on the personal data processed, the purpose, legal basis, duration and activities related to the processing, as specified in the request.
The Operator shall only process personal data that is necessary to quantify the number of visits to the Website, to exercise its rights and obligations in its legal relationship with Users, to communicate with them and to conduct direct business with Users.
II. Concepts and key principles relating to the processing of personal data
II.1. Concepts
II.1.1. Data processing: any operation or set of operations which is performed upon data, regardless of the procedure used, in particular any collection, recording, recording, organisation, storage, alteration, use, retrieval, disclosure, transmission, alignment or combination, blocking, erasure or destruction of data, prevention of their further use, taking of photographs, sound recordings or images and physical features which can be used to identify a person (e.g. fingerprints, palm prints, DNA samples, iris scans).
II.1.2. Transfer: making data available to a specified third party.
II.1.3. Data controller: the natural or legal person or unincorporated body which, alone or jointly with others, determines the purposes for which the data are to be processed, takes and implements decisions regarding the processing (including the means used) or has the data processed by a processor.
II.1.4. Data subject: any natural person who is identified or can be identified, directly or indirectly, on the basis of personal data.
II.1.5. Personal data: data which can be associated with the data subject, in particular the name, the identification mark and one or more factors specific to his or her physical, physiological, mental, economic, cultural or social identity, and the inference which can be drawn from the data concerning the data subject.
II.1.6. Data breach: unlawful processing or handling of personal data, in particular unauthorised access, alteration, disclosure, transmission, disclosure, erasure or destruction, accidental destruction or accidental damage.
II.1.7. Profiling: any form of automated processing of personal data in which personal data are used to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict characteristics associated with that person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
II.1.8. De-identification: processing of personal data in such a way that it is no longer possible to identify the natural person to whom the personal data relate without further information, provided that such further information is kept separately and technical and organisational measures are taken to ensure that no association with an identified or identifiable natural person is possible;
II.2 Principles
II.2.1. Legality, fairness and transparency
Personal data may only be processed for specific purposes, for the exercise of rights and the performance of obligations. The collection and processing of data must be fair and lawful.
Personal data may only be processed if the data subject consents to it or if it is ordered by law or - on the basis of a statutory authorisation and within the scope specified therein - by a local government decree for a purpose in the public interest (hereinafter: mandatory processing).
II.2.2. Specificity of purpose
At all stages of the processing, the purpose of the processing must be fulfilled.
II.2.3. Data economy
Only personal data that is necessary for the purpose of the processing and is suitable for achieving that purpose may be processed.
II.2.4. Accuracy
The controller is obliged to take measures to ensure the accuracy (correctness) of the data it processes.
II.2.5. Limited shelf life
Personal data may only be processed to the extent and for the duration necessary for the purpose.
Personal data must be erased if the processing is unlawful; the data subject requests it; it is incomplete or inaccurate - and this situation cannot be lawfully remedied - provided that erasure is not excluded by law; the purpose of the processing has ceased or the statutory time limit for storing the data has expired; or it has been ordered by a court or the National Authority for Data Protection and Freedom of Information (NAIH).
II.2.6. Integrity and confidentiality
In particular, appropriate measures must be taken to protect the data against unauthorised access, alteration, disclosure, disclosure, erasure or destruction, accidental destruction or accidental damage and against inaccessibility resulting from changes in the technology used.
If a User provides personal data to the Operator, the Operator will take all necessary steps to ensure the security of such data - both during network communication (i.e. online data management) and during storage and retention (i.e. offline data management).
Personal data can only be accessed by persons holding the relevant job titles - with a high level of access controls.
II.2.7. Accountability
The data subject may request from the controller (i) information about the processing of his or her personal data, (ii) rectification of his or her personal data, and (iii) erasure or blocking of his or her personal data, except for mandatory processing.
II.2.8. As a general principle, the Operator declares that in all cases where it requests personal data from its Users, they are free to decide whether or not to provide the requested information after reading and understanding the required information text. It should be noted, however, that if a User does not provide personal data, he/she will not be able to use the services of the Site subject to registration.
The Operator respects the principles of data management and strives to enforce them at all times.
III. Legal basis for processing
The Operator processes the data in Chapter V on the following legal grounds:
III.1. Legal basis for data processing: article 13/A (3) of Act CVIII of 2001 on certain aspects of electronic commerce services and information society services and article 6 (1) (c) of GDPR (name, delivery address, billing address).
With regard to point IV.2., the legal basis for processing is also: in addition to the voluntary consent of the data subject (Article 6 (1) (a) GDPR), the legitimate interest of the Operator and the User (Article 6 (1) (d) and (f) GDPR; image capture), processing based on a contract (Article 6 (1) (b) GDPR; name, delivery address, billing address), the legal basis of the Grt. Article 6 (5) GDPR (Article 6 (1) (c) GDPR; name, e-mail address), and in the case of a request for information by e-mail, Article 6 (1) (b) and (f) GDPR (name, e-mail address).
The Operator confirms that the legal basis for processing under Article 6(1)(b) of the GDPR (based on contract) shall be transformed into a legal basis under Article 6(1)(b) and (f) of the GDPR (legitimate interest) in the event of a breach.
III.2. The Operator shall process the User's data described in Section V.1. on the basis of the data subject's voluntary consent (Article 6(1)(a) GDPR) and on the basis of contractual obligations (Article 6(1)(b) GDPR; name, delivery address, billing address) and in accordance with the rules of Act CVIII of 2001 on certain aspects of electronic commerce services and information society services.
The User gives his/her consent in person or in electronic form1 during the use of the Website in the process of registration / order / electronic information request by the User by signing the Data Protection Declaration / ticking the tickbox2. The User may withdraw his/her consent at any time and thereby request the deletion / forgetting of his/her data or modify the data to which he/she has given his/her consent. In the case of an ongoing order, the withdrawal of consent to data processing shall be deemed to constitute withdrawal from the order, which the Operator shall specifically draw the User's attention to in the request for deletion / forgetting, with the Operator being entitled to process the User's data pursuant to Article 6 (1) (f) GDPR until the pre-contractual situation has been restored by the parties as a result of the withdrawal. The withdrawal of consent pursuant to Articles 7(3) and 13(2)(c) of the GDPR shall not affect the lawfulness of the processing prior to the withdrawal.
III.3. The Operator shall use the User's personal data (image recording) recorded in Section V for the purposes of quality assurance, asset security, crime prevention and detection in accordance with Article 6(1)(b) of the Info Act and Article 6(1)(f) of the GDPR, in proportion to the restriction of the rights to the protection of personal data, for the purposes of the legitimate interests of the Operator and third parties, and in addition in accordance with Section V.7.. in accordance with Article 6(1)(c) of the GDPR by reference to Article 17/B(3) of the Consumer Protection Act.
IV. Purpose of data processing
The Operator processes the data in Chapter V for the following purposes:
IV.1. Purpose of the Processing: i) to fulfil orders (name, delivery address); ii) to monitor the functioning of the service (name, telephone number, e-mail address); iii) to prevent abuse (name, telephone number, e-mail address); (iv) to identify and distinguish Users (name, date of birth, telephone number, delivery address, billing address, e-mail address, username, password); (v) to contact them (name, telephone number, e-mail address); (vi) to generate statistics (pseudonymisation per order); (vii) to send targeted advertising messages (name, e-mail address); (viii) exercise of rights related to the legal relationship with Users (customers) (name, billing address, telephone number, e-mail address); (ix) fulfilment of obligations (name, delivery address, billing address, date of birth, telephone number, e-mail address); (x) issuing of invoices (name, billing address); xi) monitoring and recording traffic and user habits, thereby offering personalised advertisements to Website Users (name, order details); xii) detecting and preventing theft of property and unlawful acts (image capture).
IV.2. By providing their data in person, or in electronic form during the registration/ordering/user electronic information request process when using the Website, Users may give their consent to the Operator to contact them with direct marketing offers, electronic advertisements (newsletter, e-mail, SMS, etc.) on the contact details provided. Consent may be withdrawn at any time, free of charge, without restriction and without giving any reason, and may also be withdrawn in the manner indicated in the electronic advertisement. Consent may also be withdrawn by means of a declaration addressed to the Operator and sent by post to the Operator's head office. In the case of an ongoing order, the withdrawal of consent to the processing of the data (in relation to the newsletter) provided for in this point shall not affect the fulfilment of the order. Pursuant to Articles 7(3) and 13(2)(c) of the GDPR, the withdrawal of consent shall not affect the lawfulness of the processing that preceded it.
IV.3. In all cases where the Operator intends to use the personal data provided for purposes other than those for which they were originally collected, the Operator shall inform the User thereof and obtain his/her prior explicit consent or provide the User with the opportunity to prohibit such use.
V. Subject matter of the processing
V.1. Registration is not a prerequisite for placing an order on the Website. Depending on the User's needs, there are therefore two levels of use of the Site, which require the provision of different data, for the purposes of the legal form referred to in point III and the purposes referred to in point IV.1:
V.1.1. For non-registered Users:
Name, Shipping address, Billing address, Phone number, E-mail address, Date of birth, Personal photo (snapshot) - if applicable
The scope of the data processed is defined by the User's proof of capacity (date of birth), the fulfilment of the order (name, delivery address), contact (name, telephone number, e-mail address) and the provision of billing conditions (name, billing address). The justification for the use of the image as the data processed is set out in point V.
V.1.2. For Registered Users:
Name, Shipping Address, Billing Address, Phone Number, Email Address, Date of Birth, Username, Password, Personal Image (photo) - if applicable
The scope of the data processed is defined by the User's proof of capacity (date of birth), the fulfilment of the order (name, delivery address), contact (name, telephone number, e-mail address) and the conditions for billing (name, billing address), as well as the condition of using the Website as a registered user (username, password). The justification for the use of image capture as processed data is set out in Section V.
V.2. The provision of personal data is based on a legal and contractual obligation and is a prerequisite for the conclusion of a contract for the order. The User is obliged to provide personal data if he wishes to make an online purchase. Failure to provide the data will prevent the online order.
V.3. Parental consent is required for the processing of data provided by users under the age of 16 and for the making of statements. The consent of the legal representative of a minor over the age of 16 is not required for the validity of a declaration of consent by the data subject.
V.4. Under no circumstances will the Operator collect any special data concerning racial origin, national, ethnic or national minority origin, political opinions or political party affiliations, religious or other beliefs, health, medical conditions, pathological addiction, sexual life or criminal history.
V.5. The Operator does not supplement or combine the personal or other data provided by Users with data or information from other sources.
V.6. The Operator shall record events on the premises for security, detection and crime prevention purposes on camera and store the material for 3 working days. The Operator shall also warn the User of the fact of the image recording by means of a sign posted in a clearly visible place in the premises of the vendor. The User consents to the image recording by entering the sales premises and by signing the Data Management Declaration / ticking the tickbox1. If the User does not consent to the recording of the image as set out in point III.3, he/she may use the online ordering and customer service (chat, e-mail). The legal basis for the processing of the data is Article 6(1)(d) and (f) of the GDPR.
V.7. Some of the Users' data, such as their IP address, other traffic data and behavioural data are also recorded in order to quantify the number of visits to the Website and to enable the Operator to identify possible errors and intrusions. These data will be processed by the Operator only for the necessary period of time and will not be linked to other data that would allow the identification of the User (pseudonymisation). The data may also be processed on servers located abroad.
VI. Duration of processing
VI.1. Duration of data processing:
VI.1.1. In the case of non-registered users (see V.1.1.), for 3 years after the purpose of the processing (delivery of the order and payment of the invoice) (expiry of the warranty period), or until any other date specified by law. Invoicing data (name, invoicing address) will be stored for 8 years from the date of invoice issue in accordance with § 169 (2) of the Accounting Act.
VI.1.2. In the case of a registered user (see V.1.2.), for 3 years after the date of cancellation of the registration, or, if an order was placed prior to the cancellation of the registration and has not been fulfilled by the date of cancellation of the registration, for the period of time specified in VI.1.1.
Invoicing data (name, billing address) will be kept for 8 years from the date of issue of the invoice in accordance with Section 169 (2) of the Accounting Act.
VI.1.3. In the case of images recorded at the Operator's sales premises in accordance with point V.6, the period of data processing is 3 working days. If during this period there is no need to store the recorded material, it will be automatically deleted at the end of the 5th working day. In justified cases, the Operator (if it has become aware of content to be used as evidence in official proceedings) shall process the image recording until the purpose is achieved (until a final decision is taken).
VI.2. The User may at any time withdraw his/her consent to data processing, request the deletion of the data concerned by the consent or modify his/her data. In the case of an ongoing order, the withdrawal of consent to data processing shall constitute withdrawal from the order, which the Operator shall specifically draw the User's attention to in the request for deletion / cancellation, with the Operator being entitled to process the User's data pursuant to Article 6 (1) (f) of the GDPR until the pre-contractual situation has been restored by the parties as a result of the withdrawal. The withdrawal of consent pursuant to Articles 7(3) and 13(2)(c) of the GDPR shall not affect the lawfulness of the processing prior to the withdrawal.
VI.3. If the personal data has been collected with the consent of the User, the Operator shall, unless otherwise provided by law,.
(a) for the purpose of complying with a legal obligation to which it is subject; or
(b) for the purposes of the legitimate interests pursued by the Operator or by a third party, where such interests are proportionate to the restriction of the right to the protection of personal data
without any further specific consent and even after the withdrawal of the data subject's consent.
VII. Exercise of the data subject's rights
VII.1. If any User requests the deletion of personal data from the Operator's system in accordance with VII.2, the Operator shall promptly comply by deleting from its database the corresponding data previously indicated by the User.
VII.2. The request for cancellation/forgetting may be submitted electronically via the e-mail address of the Customer Service or via the chat window on the Website, in paper form by letter sent to the Operator's headquarters, orally via the telephone helpdesk or at the sales premises. The Operator will send the User a written confirmation of the request for deletion/forgetting communicated orally.
In the event of a request for erasure (withdrawal of consent), the data processed by the Operator may no longer be processed from the date of receipt of the request.
In the event of a request for oblivion, the Operator shall delete from the system all contacts involving data lawfully processed prior to the receipt of the request, the profile created for the User and the automatic decision.
VII.3. If there has been a change in the data processed, the User may request that it be amended in the database. The request for modification may be made electronically via the e-mail address of the Customer Service or via the chat window on the Website, in paper form by letter sent to the Operator's head office, orally via the telephone helpdesk or at the sales offices. The Operator will send a written confirmation of the request for modification communicated orally to the User.
VII.4. Instead of deletion, the Operator shall block the personal data if the User so requests or if, on the basis of the information available to it, it can be assumed that deletion would harm the legitimate interests of the User. The personal data blocked in this way may be stored only for as long as the purpose of the processing, which precluded the deletion of the personal data, persists. Except for storage, the restricted data may be processed only with the consent of the User or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for important public interests (right to restriction of processing).
VII.5. If the Operator fails to comply with the User's request for rectification, blocking or erasure, it shall, within 25 days of receipt of the request, inform the User in writing, using one of the contact details provided by the User, of the factual and legal grounds for refusing the request for rectification, blocking or erasure. In the event of rejection of a request for rectification, erasure or blocking, the Operator shall inform the User of the possibility of judicial remedy and of recourse to the supervisory authority.
VII.6. The User may object to the processing of his/her personal data,
(a) where the processing or transfer of personal data is necessary solely for compliance with a legal obligation to which the Operator is subject or for the purposes of the legitimate interests pursued by the controller, the recipient or a third party, except in the case of mandatory processing;
(b) where the personal data are used or disclosed for direct marketing, public opinion polling or scientific research purposes; and
c) in other cases provided by law.
In the event of the User's objection, the Operator is not entitled to further processing, unless it proves that the processing is justified by compelling legitimate grounds which override the interests and rights of the User or are related to the establishment, exercise or defence of legal claims.
With regard to data processed on the basis of Article 6 (1) (d) and (f) (legitimate interest) of the GDPR, the User may object to the processing of his/her data instead of requesting deletion / withdrawing consent.
The Operator, as the data controller, shall examine the objection within the shortest possible time, but not later than 15 days from the submission of the request, shall decide on its validity and shall inform the requesting User in writing of its decision.
VII.7. Users may request information about the processing of their personal data. The request for information can be made electronically via the e-mail address of the customer service or the chat window on the Website, in paper form by sending a letter to the Operator's headquarters, or orally via the telephone helpdesk or at the sales premises. The Operator will send a written confirmation of the request for information communicated orally to the User.
Upon the User's request, the Operator shall provide information about the User's data processed by it, their source, the purpose, legal basis and duration of data processing, the fact and legal basis of data transfer, the name and address of the recipient and all its activities related to data processing. The Operator shall provide the information in writing in an intelligible form within the shortest possible time from the date of the request, but not later than 30 days from the date of the request, upon the User's request.
The information described above is free of charge if the person requesting the information has not yet submitted a request for information to the Operator for the same data set in the current year. In other cases, a fee may be charged. The fee already paid shall be refunded if the data have been processed unlawfully or if the request for information has led to a correction.
The Operator may refuse to provide the data subject with information only in the cases specified in the Info. In the event of refusal to provide information, the Operator shall inform the data subject in writing of the provision of this Act on the basis of which the information was refused. In the event of refusal to provide information, the Operator shall inform the User of the possibility of judicial remedy and of recourse to the National Authority for Data Protection and Freedom of Information. The Data Controller shall notify the Authority of rejected requests annually by 31 January of the year following the year in question.
VII.8. Data portability
Pursuant to Article 20 of the GDPR, the User is entitled to receive the data provided by him/her to the Operator in a structured, commonly used, machine-readable format and to transmit it to another data controller.
The User may request the direct transfer of the data to another controller - if technically feasible.
The request for data transfer can be made electronically via the e-mail address of the Customer Service or the chat window on the Website, in paper form by sending a letter to the Operator's headquarters, orally via the telephone helpdesk or at the sales premises. The Operator will send the User a written confirmation of the oral request for data transfer.
If the Operator does not comply with the User's request for data transfer, the Operator shall, within 30 days of receipt of the request, inform the User in writing, using one of the contact details provided by the User, of the factual and legal reasons for the refusal. In the event of refusal of a request for data transfer, the Operator shall inform the User of the possibility of judicial remedy and of recourse to the supervisory authority.
The User has no right to data portability with regard to data processed on the basis of Article 6(1)(d) and (f) of the GDPR (legitimate interest).
IX. Placement of Anonymous User Identification (cookie) and web beacons
IX.1. The Operator, like many other businesses, uses cookies on the Website. Details of how to set "cookies" and "web beacons" when using the Website are set out in the Information Notice on the setting of anonymous user identifiers ("cookies") and web beacons ("web beacons"), which is set out in a separate document.
X. Data storage, processing and transmission
X.1. Storage of data
The Operator stores the processed data in an Internet cloud created for this purpose and accessible only by our company, or on its own server designated for this purpose.
The location where the server is stored and operated:
BPC Rendszerház Kft.
Our address:1138 Budapest, Váci út 152-156.
Telephone: +36 1 226 2993
Email: info@bpcrendszerhaz.hu
X.2. Data processing
The operator does not use a data processor.
X.3. Data transmission
The User gives his/her consent to the transfer of data/transfer of data abroad in person or electronically during the use of the Website in the registration/ordering process1 by signing the Data Processing Declaration / ticking the tickbox2. The User may withdraw his/her consent at any time. In the case of an ongoing order, the withdrawal of consent to the transfer of data shall constitute withdrawal from the order, which the Operator shall specifically draw the User's attention to in the request for cancellation, stating that the Operator is entitled to process the User's data pursuant to Article 6 (1) (f) of the GDPR until the pre-contractual situation has been restored by the parties as a result of the withdrawal. The withdrawal of consent pursuant to Articles 7(3) and 13(2)(c) of the GDPR shall not affect the lawfulness of the processing prior to the withdrawal.
X.4. Guarantees provided by the Operator
The Operator undertakes to protect the User's personal data unconditionally and irrevocably. It is the responsibility of the Operator to verify the adequacy of the partners used for further processing and processing of personal data, thus ensuring the required protection of personal data.
The recipient of the data transfer to the third country and the data processors have committed themselves in a specific agreement with the Operator on the protection of personal data to take measures to ensure a level of protection in accordance with the data protection legislation in force and in force in the EU. Such contracts provide the Operator with sufficient opportunity and means to enforce adequate protection of personal data, guaranteeing the User the protection and exercise of his rights.
It is the responsibility of the Operator to submit the agreements provided for in this clause and any amendments thereto to the National Authority for Data Protection and Freedom of Information and the competent supervisory authority for approval pursuant to Article 46(3) of the GDPR.
XI. Data security measures, Data Protection Officer
XI.1. Data security measures
The Operator shall exercise the utmost care in handling and storing the personal data provided by Users. In the field of IT security, the Operator shall use the most effective and up-to-date tools and procedures reasonably available.
The Controller shall design and implement the processing operations in such a way as to ensure the protection of the privacy of the Users concerned. The Operator shall ensure the security of the data, and shall take the technical and organisational measures and have established the procedural rules necessary to enforce the Info Act and other data protection and confidentiality rules.
XI.1.1. The Operator shall take appropriate measures to protect the data against, in particular, unauthorised access, alteration, disclosure, disclosure, deletion or destruction, accidental destruction or damage, and inaccessibility due to changes in the technology used.
XI.1.2. In order to protect the data files managed electronically in various registers, the Operator shall ensure by means of appropriate technical solutions that the data stored in the registers cannot be directly linked and attributed to the User concerned, unless permitted by law.
XI.1.3. The Operator has chosen and operates the IT tools used to process personal data in the course of providing the service in such a way that the data processed:
a) accessible to authorised persons (availability);
b) its authenticity and authenticity is assured (authenticity of processing);
c) its immutability can be verified (data integrity);
d) be protected against unauthorised access (data confidentiality).
XI.1.4. The Operator shall ensure the security of data management by technical, organisational and organisational measures that provide a level of protection appropriate to the risks associated with data management.
XI.1.5. The Operator's IT systems and network are protected against computer fraud, espionage, sabotage, vandalism, fire and flood, computer viruses, computer intrusions and denial of service attacks. The Operator shall ensure security through server-level and application-level protection procedures.
XI.1.6. Electronic messages transmitted over the Internet, regardless of the protocol (e-mail, web, ftp, etc.) are vulnerable to network threats that could lead to fraudulent activity or to the disclosure or modification of information. The Operator will take all reasonable precautions to protect against such threats. It shall monitor systems in order to record and provide evidence of any security incidents. However, the Internet is not, as is well known to Users, 100% secure. The Operator shall not be liable for any damage caused by an unprotected attack, despite the utmost care.
XI.2. Data Protection Officer
The Operator declares that it is not obliged to employ a Data Protection Officer under the GDPR and therefore does not employ a Data Protection Officer.
XII. Renaming, statistics
XII.1 The Operator may use the data for statistical purposes after pseudonymisation. The use of the data in aggregate statistical form shall not include the name or any other identifiable data of the User concerned.
XIII Automated decision-making
The User gives his/her consent to the automated decision-making in person or in electronic form during the use of the Website in the process of registration / order / electronic information request by the User by signing the Data Processing Declaration / ticking the tickbox. The User may withdraw his/her consent at any time. In the case of an ongoing order, the withdrawal of consent shall constitute withdrawal from the order, which the Operator shall specifically draw the User's attention to in the request for cancellation, stating that the Operator shall be entitled to process the User's data pursuant to Article 6 (1) (f) GDPR until the pre-contractual situation has been restored by the parties as a result of the withdrawal. The withdrawal of consent pursuant to Articles 7(3) and 13(2)(c) of the GDPR shall not affect the lawfulness of the processing prior to the withdrawal.
XIV. Consumer complaints
XIV.1. The Operator's customer service receives complaints and user enquiries regarding the Operator's services and personal data protection partly on the dedicated telephone customer service line and by e-mail, at +361 451 0042 and at info@volvex.hu.
XIV.2. The User sending a complaint may seek redress by lodging a complaint with the competent court or the National Authority for Data Protection and Freedom of Information (NAIH): 1024 Budapest, Szilágyi Erzsébet fasor 22/C. (www.naih.hu).
XV. Execution of official requests
XV.1. The court, the prosecutor, the investigating authority, the administrative authority, the data protection commissioner, or other bodies authorised by law may request the Operator to provide information, to disclose or transfer data, or to make documents available.
XV.2. The Operator shall disclose to the public authorities - if the public authority has indicated the precise purpose and scope of the data - personal data only to the extent and to the extent strictly necessary for the purpose of the request.
If you do not agree with the above, please do not use the Website.
If you have any further questions about data protection, please contact us.
These Rules are publicly available on the Website from the date of their publication, from which date they shall take effect.
Budapest, 2018.05.24.
