Privacy policy

Date of the latest update: 14 July 2026

Needletales.hu Privacy Policy

Jurth Emese e.v. (Sole Proprietor)

Privacy Policy

Introduction

The data processing activities of Jurth Emese e.v. (9400 Sopron, Póda Endre utca 6/C 2/6., tax number: 53721954-1-28, registration number: 62253004) (hereinafter: Provider, Data Controller) shall be carried out in accordance with the provisions of this policy.

We provide the following information pursuant to REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation / GDPR).

This privacy policy regulates the data processing of the following websites/mobile applications: https://www.needletales.hu/, https://needtales.com/

The privacy policy is available from the following page: https://www.needletales.hu//adatvedelem

Amendments to the policy shall enter into force upon their publication at the above address.

The Data Controller and its contact details

Name: Jurth Emese e.v.

Registered office: 9400 Sopron, Póda Endre utca 6/C 2/6.

E-mail: info@needletales.hu

Phone: +36 30 687 8456

Definitions

"personal data": means any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

"processing": means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

"controller": means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;

"processor": means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;

"recipient": means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;

"consent of the data subject": means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;

"personal data breach": means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;

"profiling": means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;

"third party": means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

Principles relating to processing of personal data

Personal data shall be:

  • processed lawfully, fairly and in a transparent manner in relation to the data subject ("lawfulness, fairness and transparency");
  • collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes ("purpose limitation");
  • adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed ("data minimisation");
  • accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay ("accuracy");
  • kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject ("storage limitation");
  • processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures ("integrity and confidentiality").
    The controller shall be responsible for, and be able to demonstrate compliance with the provisions above ("accountability").
    The Data Controller declares that its data processing operations are carried out in accordance with the principles set out in this section.

Data processing related to the operation of the webshop

1. The fact of data collection, the scope of processed data and the purpose of data processing:

Personal Data

Purpose of Data Processing

Legal Basis

Username

Identification, enabling registration.

Consent of the data subject, Article 6(1)(a) of the GDPR.

Password

Serves secure login into the user account.

Consent of the data subject, Article 6(1)(a) of the GDPR.

First and last name

Necessary for contact, purchase, issuing a lawful invoice, and exercising the right of withdrawal.

Performance of a contract, Article 6(1)(b) of the GDPR.

E-mail address

Communication.

Performance of a contract, Article 6(1)(b) of the GDPR.

Phone number

Communication, more efficient coordination of questions related to billing or delivery.

Performance of a contract, Article 6(1)(b) of the GDPR.

Billing name and address

Issuing a lawful invoice, as well as establishing the contract, defining its content, modifying it, monitoring its performance, billing the fees deriving from it, and enforcing related claims.

Compliance with a legal obligation, Article 6(1)(c) of the GDPR. (The legal obligation is Section 169 (2) of Act C of 2000 on Accounting)

Delivery name and address

Enabling home delivery.

Performance of a contract, Article 6(1)(b) of the GDPR.

Date of purchase/registration

Execution of a technical operation.

Performance of a contract, Article 6(1)(b) of the GDPR.

IP address at purchase/registration

Execution of a technical operation.

Performance of a contract, Article 6(1)(b) of the GDPR.

 

2. Scope of data subjects: All data subjects registered/purchasing on the webshop website. Neither the username nor the e-mail address needs to contain personal data.

3. Duration of data processing, deadline for data erasure: If any of the conditions set out in Article 17(1) of the GDPR exist, it lasts until the erasure request of the data subject. The Data Controller shall inform the data subject electronically of the erasure of any personal data provided by the data subject on the basis of Article 19 of the GDPR. If the data subject's erasure request also extends to the e-mail address provided by them, the Data Controller shall also erase the e-mail address following the notification. Except in the case of accounting documents, since based on Section 169 (2) of Act C of 2000 on Accounting, these data must be preserved for 8 years. The contractual data of the data subject can be erased following the expiry of the civil law limitation period based on the data subject's erasure request.

The accounting document directly and indirectly supporting the bookkeeping settlement (including general ledger accounts, analytical or detailed records) must be preserved in a legible form for at least 8 years, in a way that allows retrieval based on the references of the bookkeeping records.

4. Description of data subjects' rights related to data processing:

The data subject may request from the Data Controller access to, rectification, erasure, or restriction of processing of personal data concerning them, and the data subject has the right to data portability, furthermore to withdraw their consent at any time.

5. The data subject can initiate access to, erasure, modification, or restriction of processing of personal data, as well as data portability, in the following ways:

  • by post at the address: 9400 Sopron, Póda Endre utca 6/C 2/6.,
  • by e-mail at the e-mail address: info@needletales.hu,
  • by phone at the number: +36 30 687 8456.
    6. Please be informed that:
  • the data processing is necessary for the performance of a contract and providing an offer.
  • you are obliged to provide the personal data so that we can fulfill your order.
  • the failure to provide data will result in the consequence that we cannot process your order.

Management of Cookies

  1. It is not necessary to request prior consent from data subjects for the use of the so-called "cookie used for a password-protected session", "cookies required for the shopping cart", "security cookies", "necessary cookies", "functional cookies", and "cookies responsible for managing website statistics".
  2. The fact of data processing, the scope of processed data: Unique identification number, dates, times.
  3. Scope of data subjects: All data subjects visiting the website.
  4. Purpose of data processing: Identification of users, tracking visitors, ensuring customized operation.
  5. Duration of data processing, deadline for data erasure:

Cookie Type

Legal Basis of Processing

Duration of Processing

Session cookies, or other cookies strictly necessary for the operation of the website

No data processing takes place with the use of the cookie.

The period lasting until the closure of the relevant visitor session, meaning it remains on the computer only until the browser is closed.

Statistical, marketing cookies

Article 6(1)(a) of the GDPR

1 day – 2 years, in accordance with the cookie policy, or the data processing lasts until the withdrawal of the data subject's consent.

 

6. Description of data subjects' rights related to data processing: Data subjects have the opportunity to delete cookies in the Tools/Settings menu of browsers, generally under the settings of the Privacy menu item.

7. Most browsers used by our users allow setting which cookies should be saved and allow (specific) cookies to be deleted again. If you restrict the saving of cookies on specific websites or do not allow third-party cookies, this may under certain circumstances lead to our website no longer being fully usable. You can find information here on how to customize cookie settings for common browsers:

Use of Google Ads Conversion Tracking

The Data Controller uses the online advertising program called "Google Ads" and, within its framework, utilizes the conversion tracking service of Google. Google conversion tracking is an analytical service of Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; "Google").

When a User reaches a website via a Google advertisement, a cookie necessary for conversion tracking is placed on their computer. The validity of these cookies is limited, and they do not contain any personal data, so the User cannot be identified by them.

When the User browses certain pages of the website and the cookie has not yet expired, both Google and the Data Controller can see that the User clicked on the advertisement.

Each Google Ads customer receives a different cookie, so they cannot be tracked through the websites of Ads customers.

The information – obtained with the help of conversion tracking cookies – serves the purpose of creating conversion statistics for Ads customers who choose conversion tracking. In this way, customers get informed about the number of users who clicked on their advertisement and were forwarded to the page equipped with a conversion tracking tag. However, they do not get access to information with which any user could be identified.

If you do not wish to participate in conversion tracking, you can refuse it by disabling the option of installing cookies in your browser. After this, you will not be included in the conversion tracking statistics.

Based on Google Consent Mode v2, Google uses two new cookie types: ad_user_data and ad_personalization, which are based on the consent of the data subject and relate to the use and sharing of data. The ad_user_data serves to grant consent for user data to be sent to Google for advertising purposes. The ad_personalization controls whether the data can be used for personalized advertising (e.g., remarketing). The Data Controller ensures the acquisition or withdrawal of appropriate consents on its cookie banner / panel. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Further information and Google's privacy policy are available on the following page: https://policies.google.com/privacy

Application of Google Analytics

This website uses the Google Analytics application, which is a web analytical service of Google Inc. ("Google"). Google Analytics uses so-called "cookies", text files saved on your computer, thereby facilitating the analysis of the use of the website visited by the User.

The information generated by the cookies related to the website used by the User is usually transmitted to and stored on one of Google's servers in the USA. By activating IP anonymization on the website, Google shortens the User's IP address beforehand within the Member States of the European Union or in other states party to the Agreement on the European Economic Area.

The transmission of the full IP address to Google's server in the USA and its shortening there takes place only in exceptional cases. Commissioned by the operator of this website, Google will use this information to evaluate how the User used the website, furthermore to prepare reports connected to the website activity for the website operator, as well as to fulfill further services related to website and internet use.

Within the framework of Google Analytics, the IP address transmitted by the User's browser is not merged with other data of Google. The User can prevent the storage of cookies by the appropriate setting of their browser; however, we draw your attention to the fact that in this case it might happen that not all functions of this website will be fully usable. You can furthermore prevent Google from collecting and processing the data related to the website use by the User through cookies (including the IP address) if you download and install the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=hu

Newsletter, DM activity based on consent

  1. Pursuant to Section 6 of Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions of Economic Advertising Activity, unless a specific Act provides otherwise, advertisements may be communicated to a natural person – the User – as the recipient of the advertisement by the method of direct marketing (hereinafter: direct marketing), thus particularly via electronic mail or other equivalent individual communication means, exclusively if the recipient of the advertisement has expressly and clearly consented to it in advance.
  2. Furthermore, keeping the provisions of this policy in mind, the User may consent to the Provider processing their personal data necessary for sending advertising offers.
  3. The Provider does not send unsolicited advertising messages, and the User may unsubscribe from receiving offers free of charge, without restriction and justification. In this case, the Provider shall erase all personal data – necessary for sending advertising messages – from its registry and will not approach the User with further advertising offers. The User can unsubscribe from advertisements by clicking on the link located in the message.
  4. The fact of data collection, the scope of processed data and the purpose of data processing:

Personal Data

Purpose of Data Processing

Legal Basis

Name, e-mail address

Identification, enabling subscription to the newsletter/promotional coupons.

Consent of the data subject, Article 6(1)(a) of the GDPR.

Date of subscription

Execution of a technical operation.

Consent of the data subject, Article 6(1)(a) of the GDPR.

IP address at subscription

Execution of a technical operation.

Consent of the data subject, Article 6(1)(a) of the GDPR.

  1. Newsletter distribution takes place in compliance with the provisions of Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions of Economic Advertising Activity.

  2. Scope of data subjects: All data subjects subscribing to the newsletter.

  3. Purpose of data processing: sending electronic messages containing advertisements (e-mail, SMS, push message) to the data subject, providing information about current updates, products, promotions, new functions, etc.

  4. Duration of data processing, deadline for data erasure: The data processing lasts until the withdrawal of consent (unsubscribing, until the data subject's erasure request), or until the termination of the newsletter.

  5. Description of data subjects' rights related to data processing:
    The data subject may request from the Data Controller access to, rectification, erasure, or restriction of processing of personal data concerning them, as well as the data subject has the right to data portability, furthermore to withdraw their consent at any time.

  6. The data subject can initiate access to, erasure, modification, or restriction of processing of personal data, as well as data portability, in the following ways:

  • by post at the address: 9400 Sopron, Póda Endre utca 6/C 2/6.,
  • by e-mail at the e-mail address: info@needletales.hu,
  • by phone at the number: +36 30 687 8456.
  1. The data subject can unsubscribe from the newsletter at any time, free of charge.

  2. Please be informed that:

  • the data processing is based on your consent.
  • you are obliged to provide the personal data if you wish to receive newsletters from us.
  • the failure to provide data will result in the consequence that we cannot send you newsletters.
  • we inform you that you can withdraw your consent at any time by clicking on unsubscribe.
  • the withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Complaint Handling

  1. The fact of data collection, the scope of processed data and the purpose of data processing:

Personal Data

Purpose of Data Processing

Legal Basis

First and last name

Identification, communication.

Compliance with a legal obligation, Article 6(1)(c) of the GDPR. (The relevant legal obligation: Section 17/A (7) of Act CLV of 1997 on Consumer Protection)

E-mail address

Communication.

Compliance with a legal obligation, Article 6(1)(c) of the GDPR.

Phone number

Communication.

Compliance with a legal obligation, Article 6(1)(c) of the GDPR.

Billing name and address

Identification, handling quality objections, questions, and problems arising in connection with the ordered products/services.

Compliance with a legal obligation, Article 6(1)(c) of the GDPR.

  1. Scope of data subjects: All data subjects purchasing on the website and making a complaint or raising a quality objection.

  2. Duration of data processing, deadline for data erasure: The copies of the report drawn up on the objection, the transcript, and the response given to it must be preserved for 3 years based on Section 17/A (7) of Act CLV of 1997 on Consumer Protection.

  3. Description of data subjects' rights related to data processing:
    The data subject may request from the Data Controller access to, rectification, erasure, or restriction of processing of personal data concerning them, and the data subject has the right to data portability, furthermore to withdraw their consent at any time.

  4. The data subject can initiate access to, erasure, modification, or restriction of processing of personal data, as well as data portability, in the following ways:

  • by post at the address: 9400 Sopron, Póda Endre utca 6/C 2/6.,
  • by e-mail at the e-mail address: info@needletales.hu,
  • by phone at the number: +36 30 687 8456.
  • Please be informed that:
  • the provision of personal data is based on a legal obligation.
  • the processing of personal data is a precondition for the conclusion of the contract.
  • you are obliged to provide the personal data so that we can handle your complaint.
  • the failure to provide data will result in the consequence that we cannot handle your complaint received by us.

Recipients to whom personal data are disclosed

"recipient": means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not.

1. Data Processors (who perform data processing on behalf of the data controller)

The data controller utilizes data processors for the purpose of facilitating its own data processing activities, furthermore in order to comply with its obligations established by contracts concluded with the data subject or by legislation.

The data controller places great emphasis on utilizing exclusively such data processors who or which provide appropriate guarantees for implementing appropriate technical and organizational measures ensuring that the data processing complies with the requirements of the GDPR and protects the rights of data subjects.

The data processor and any person acting under the authority of the data controller or the data processor who has access to personal data shall process the personal data contained in this policy exclusively in accordance with the instructions of the data controller.

The data controller bears legal liability for the activities of the data processor. The data processor shall be held liable for damages caused by data processing only if it did not comply with the obligations specified in the GDPR specifically encumbering data processors, or if it ignored or acted contrary to the lawful instructions of the data controller.

The data processor has no substantive decision-making power regarding the processing of data.

The data controller may utilize a hosting service provider to ensure the IT background, and a courier service for delivering the ordered products, as a data processor.

2. Specific data processors

Data Processing Activity

Name, Address, Contact Details

Hosting services

Websupport Magyarország Kft.


1119 Budapest, Fehérvári út 97-99.


Tel.: +36 1 700 2323


E-mail: info@mhosting.hu



Shopify Inc.


Registered office: 150 Elgin St, Suite 800, Ottawa, ON, K2P 1L4, Canada


Phone: +1 888 746 7439


E-mail: support@shopify.com


Website: shopify.com

Other data processing (e.g., online invoicing, web development, marketing)

Online invoicing:


Billingo Technologies Zrt.


Registered office: 1133 Budapest, Árbóc utca 6. III. emelet


E-mail: hello@billingo.hu



Newsletter distribution:


Shopify Inc.


Registered office: 150 Elgin St, Suite 800, Ottawa, ON, K2P 1L4, Canada


Phone: +1 888 746 7439


E-mail: support@shopify.com


Website: shopify.com

Accounting

Stipendium Kft.


8878 Lovászi Lakótelep 53. door 2.


Phone: +36704090774


Email address: info@konyvelunk.co.hu

"third party": means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.

3. Data transmission to a third party

Third-party data controllers process the personal data communicated by us in their own name, in accordance with their own privacy policies.

Data Controller Activity

Name, Address, Contact Details

Transport / Shipping

MPL Magyar Posta Logisztika Kft.


1138 Budapest, Dunavirág utca 2-6.


ugyfelszolgalat@posta.hu


Phone: (06-1) 767-82-82


GTC: https://www.posta.hu/ugyfelszolgalat/aszf


Privacy Policy: https://www.posta.hu/adatkezelesi_tajekoztato



FoxPost Zrt.


1068 Budapest, Dózsa György út 84. Bldg. B.


Phone: 06-1-999-0-369


E-mail: info@foxpost.hu



Fürgefutár.hu Kft.


Registered office: 1122 Budapest, Városmajor u. 35.


Phone: (+36-1) 900-96-69


Email: ugyfelszolgalat@furgefutar.hu


Website: https://furgefutar.hu/



Packeta Hungary Kft.


1044 Budapest, Ezred u. 2 B2/11


E-mail: info@packeta.hu


Website: https://www.packeta.hu



UPS Hungary Kereskedelmi és Szolgáltató Kft.


2220 Vecsés, Lőrinci út 154.


E-mail: upshungary@ups.com



Fedex Express Hungary Kft.


1185 Budapest, Központi Repülőtér, Building 182


E-mail: hungary@fedex.com

Online payment

Shopify Payments


Shopify Inc.


Registered office: 150 Elgin St, Suite 800, Ottawa, ON, K2P 1L4, Canada


Phone: +1 888 746 7439


E-mail: support@shopify.com


Website: shopify.com



PayPal


Parent company: eBay Incorporated


Registered office: San Jose, California, USA


Contact details: https://www.paypal.com/hu

Social media interfaces

The data controller is also present on social media interfaces in order to present its services, as well as to keep contact with interested parties and customers.

Scope of processed data: Data publicly available on the data subject's social media profile, particularly:

– name (username)

– public profile picture

– interactions published by the data subject or related to the data controller's page (e.g., comment, message).

Scope of data subjects: Those natural persons who follow the data controller's social media page, interact with it, or send a message through it.

Purpose of data processing:

– presentation of the data controller's activity and services,

– marketing and communication on social media interfaces,

– keeping contact with interested parties and customers.

Legal basis of data processing: The data subject's voluntary consent to the processing of their personal data on social media sites.

Duration of data processing: The data processing lasts until the existence of the data subject's interaction, or until the deletion of the content published by the data subject. The data controller preserves messages and communication for a maximum of 2 years.

Further data controllers: Social media platforms process users' data as independent data controllers according to their own privacy policies.

Facebook / Meta joint controllership

The Data Controller possesses a Facebook / Meta profile regarding its activity. The data processing implemented on the Facebook social media site for statistical purposes constitutes joint controllership between the Data Controller and Facebook Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, D2 Dublin, Ireland). Detailed information on the joint controllership agreement is provided by the Data Controller Addendum for Facebook Page Insights. The addendum is available at the following link: https://www.facebook.com/legal/terms/page_controller_addendum

The Data Controller communicates via private message on the social media site exclusively if you approach us there.

1. Categories of data subjects

  • the data subject who registered on the social media site and "liked" the Data Controller's profile page,

  • the data subject who approaches the Data Controller via private message on the social media site.
    2. Purpose of data processing
    The purpose of data processing on the Facebook social media site is sharing and promoting the data controller's activity and service. The Data Controller may use the data subject's data provided in a private message to respond to the message; otherwise, the Data Controller does not collect data through social media sites and does not extract data from there.
    3. Legal basis of data processing
    The data processing is based on Article 6(1)(a) of the GDPR; the legal basis of data processing is the data subject's consent to the processing of their personal data on the Facebook social media site.
    4. Scope of processed data

  • the registered name of the data subject,

  • the public profile picture of the data subject user,

  • other public data provided or shared by the data subject on the social media site.
    5. Source of processed personal data: The source of the processed data is the data subject.
    6. Withdrawal of consent: You can withdraw your consent given for data processing at any time, and you can delete your post or comment. Data processing takes place through social media sites operated by a third party. If you withdraw your consent, the Data Controller deletes the conversation conducted with you. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
    The data subject can initiate access to, erasure, modification, or restriction of processing of personal data, as well as data portability, in the following ways:

  • by post at the address: 9400 Sopron, Póda Endre utca 6/C 2/6.,
  • by e-mail at the e-mail address: info@needletales.hu,
  • by phone at the number: +36 30 687 8456.

    7. Duration of data processing
  • until the withdrawal of the data subject's consent,
  • if an exchange of messages takes place, then 2 years.

    8. Transmission, recipients of personal data, or categories of recipients:
    For the definition of recipient, see: Article 4(9) of the GDPR. The Data Controller transfers the personal data of the Data Subject to state organs and authorities – thus particularly to courts, prosecutors, investigative authorities, and misdemeanor authorities, or the National Authority for Data Protection and Freedom of Information – exclusively in exceptional cases and based on a statutory obligation.

    9. Possible consequences of failure to provide data

    In the event of failure to provide data, the data subject cannot obtain information about the Data Controller's activities and services through the Facebook social media site, and cannot send a message to the Data Controller via Facebook Messenger.

    10. Automated decision-making (including profiling):
    Automated decision-making, including profiling, does not take place during data processing.

    11. Joint controller agreement concluded with Facebook Ireland Ltd.:

    The Page Insights function displays aggregated data that help understand how data subjects use the Facebook page. Facebook Ireland Limited ("Facebook Ireland") and the Data Controller are joint controllers regarding the processing of insights data. The Page Insights Addendum defines the responsibility of Facebook and the responsibility of the Data Controller regarding the processing of insights data. Facebook Ireland undertakes primary responsibility under the GDPR for processing insights data, and to comply with all relevant obligations prescribed in the GDPR regarding the processing of insights data. Facebook Ireland furthermore makes the extract of the Page Insights Addendum available to all data subjects. The Data Controller ensures that it possesses an appropriate legal basis under the GDPR for processing insights data, identifies the controller of the page, and complies with all other relevant legal obligations. Facebook Ireland has sole responsibility for processing personal data in connection with the Page Insights function, except for data falling within the scope of the Page Insights Addendum. The Page Insights Addendum does not grant the Data Controller the right to request personal data of Facebook users processed by Facebook Ireland in connection with Facebook, including page insights data. The Data Controller may not act on behalf of Facebook Ireland and may not provide answers during the fulfillment of data protection requests.

Customer relations and other data processing operations

If a question arises during the use of the data controller's services, or if the data subject has a problem, they may contact the data controller via the methods specified on the website (phone, e-mail, social media sites, etc.).

The Data Controller deletes received e-mails, messages, and data provided via phone, Meta, etc., together with the interested party's name and e-mail address, as well as other voluntarily provided personal data, after a maximum of 2 years from the communication of the data.

Information about data processing operations not listed in this policy will be provided at the time the data are collected.

Upon an exceptional request from an authority, or based on statutory authorization in the case of requests from other organs, the Provider is obliged to provide information, communicate or transfer data, or make documents available.

In these cases, the Provider discloses personal data to the requesting party – provided that it indicated the exact purpose and the scope of data – only as much and to such an extent as is indispensably necessary for achieving the purpose of the request.

Rights of data subjects

1. Right of access

You are entitled to receive feedback from the data controller as to whether processing of your personal data is in progress, and if such data processing is in progress, you are entitled to receive access to the personal data and the information listed in the regulation.

2. Right to rectification

You are entitled to have the data controller rectify inaccurate personal data concerning you without undue delay upon your request. Taking into account the purposes of the processing, you are entitled to have incomplete personal data completed, including by means of providing a supplementary statement.

3. Right to erasure ("right to be forgotten")

You are entitled to have the data controller erase personal data concerning you without undue delay upon your request, and the data controller is obliged to erase personal data concerning you without undue delay under specific conditions.

4. Right to be forgotten

Where the data controller has made the personal data public and is obliged to erase it, it shall, taking into account available technology and the cost of implementation, take reasonable steps – including technical measures – to inform controllers which are processing the personal data that you have requested the erasure by such controllers of any links to, or copy or replication of, those personal data.

5. Right to restriction of processing

You are entitled to have the data controller restrict processing upon your request where one of the following conditions applies:

  • the accuracy of the personal data is contested by you, for a period enabling the data controller to verify the accuracy of the personal data;
  • the processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead;
  • the data controller no longer needs the personal data for the purposes of the processing, but they are required by you for the establishment, exercise or defence of legal claims;
  • you have objected to processing; in this case, the restriction applies for a period enabling the verification of whether the legitimate grounds of the data controller override your legitimate grounds.
    6. Right to data portability
    You are entitled to receive the personal data concerning you, which you have provided to a data controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another data controller without hindrance from the data controller to which the personal data have been provided (...)

7. Right to object The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her which is based on legitimate interest or the exercise of official authority as legal bases, including profiling based on those provisions. 8. Objection in the case of direct marketing Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing. Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes. 9. Automated individual decision-making, including profiling The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her. The previous paragraph shall not apply if the decision:

  • is necessary for entering into, or performance of, a contract between the data subject and a data controller;
  • is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests; or
  • is based on the data subject's explicit consent.

Time limit for measures The data controller shall inform you of any measures taken following the above requests without undue delay and in any event within 1 month of receipt of the request. This period may be extended by 2 further months where necessary. The data controller shall inform you of any such extension within 1 month of receipt of the request, together with the reasons for the delay. Where the data controller does not take action on your request, the data controller shall inform you without delay and at the latest within one month of receipt of the request of the reasons for not taking action and on the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.

Security of processing Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the data controller and the data processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including inter alia, as appropriate:

  • the pseudonymisation and encryption of personal data;
  • the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
  • the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident;
  • a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing. The processed data must be stored in such a way that unauthorized persons cannot access them. In the case of paper-based data carriers, this is achieved by developing the rules for physical storage and archiving; in the case of data processed in electronic form, by applying a central authorization management system. The method of storing data by IT means must be chosen in such a way that their erasure – also taking into account potentially differing erasure deadlines – can be carried out upon the expiry of the data erasure deadline, or if it is necessary for other reasons. Erasure must be irreversible. Paper-based data carriers must be deprived of personal data with the help of a document shredder or by utilizing an external organization specialized in document shredding. In the case of electronic data carriers, physical destruction must be ensured in accordance with the rules on the scrapping of electronic data carriers, or, if necessary, the secure and irreversible erasure of data must be carried out in advance.

The data controller takes the following specific data security measures: In order to ensure the security of personal data processed on paper, the Provider applies the following measures (physical protection):

  • Placing the documents in a secure, well-lockable, dry room.
  • If personal data processed on paper are digitized, the rules applicable to digitally stored documents must be applied.
  • The employee of the Provider performing data processing may only leave the room where data processing takes place during their work in such a way that they lock away the data carriers entrusted to them or lock the given room.
  • Personal data may only be disclosed to authorized persons; third parties shall not have access to them.
  • The Provider's building and rooms are equipped with fire protection and property security equipment.

IT protection

  • The computers and mobile devices (other data carriers) used during data processing constitute the property of the Provider.
  • The computer system used by the Provider containing personal data is equipped with virus protection.
  • In order to ensure the security of digitally stored data, the Provider applies data backups and archivings.
  • The central server machine can only be accessed with appropriate authorization and exclusively by designated persons.
  • Data located on computers can only be accessed with a username and password.

Informing the data subject of a personal data breach When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the data controller shall communicate the personal data breach to the data subject without undue delay. The communication to the data subject shall describe in clear and plain language the nature of the personal data breach and contain the name and contact details of the data protection officer or other contact point where more information can be obtained; describe the likely consequences of the personal data breach; describe the measures taken or proposed to be taken by the data controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects. The communication to the data subject shall not be required if any of the following conditions are met:

  • the data controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption;
  • the data controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects is no longer likely to materialise;
  • it would involve disproportionate effort. In such a case, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner. If the data controller has not already communicated the personal data breach to the data subject, the supervisory authority, having considered the likelihood of the personal data breach resulting in a high risk, may require it to do so.

Reporting a personal data breach to the authority In the case of a personal data breach, the data controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay.

Review in the case of mandatory data processing If the duration of mandatory data processing or the periodic review of its necessity is not determined by an Act of Parliament, a local government decree, or a mandatory legal act of the European Union, the data controller shall review at least every three years from the start of the data processing whether the processing of personal data processed by it or by a data processor acting on its behalf or under its instructions is necessary for achieving the purpose of the data processing. The circumstances and result of this review shall be documented by the data controller; this documentation must be preserved for ten years following the execution of the review and shall be made available to the National Authority for Data Protection and Freedom of Information (hereinafter: Authority) at the request of the Authority.

Possibility to lodge a complaint Complaints against potential infringements by the data controller can be lodged with the National Authority for Data Protection and Freedom of Information: National Authority for Data Protection and Freedom of Information 1055 Budapest, Falk Miksa utca 9-11. Mailing address: 1363 Budapest, Pf. 9. Phone: +36 -1-391-1400 Fax: +36-1-391-1410 E-mail: ugyfelszolgalat@naih.hu

Closing words During the preparation of this policy, we took into account the following legislation and recommendations:

  • REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation / GDPR);
  • Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (mainly Section 13/A);
  • Act XLVII of 2008 on the Prohibition of Unfair Commercial Practices against Consumers;
  • Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions of Economic Advertising Activity (particularly Section 6);
  • Act XC of 2005 on Electronic Freedom of Information;
  • Act C of 2003 on Electronic Communications (specifically Section 155);
  • Opinion No. 16/2011 on the EASA/IAB Recommendation on Best Practice for Behavioural Online Advertising;
  • The Recommendation of the National Authority for Data Protection and Freedom of Information on the data protection requirements of prior information.

 

 

Date of the latest update: 14 July 2026