PRIVACY POLICY (DATA PROCESSING NOTICE)
1. Purpose of this Privacy Policy
The purpose of this privacy policy is to define the principles and rules governing the processing of personal and other data provided by visitors to the https://net-face.com website in the course of using the website and processed by Földesi Zsolt E.V. (sole proprietor; hereinafter referred to as the “Data Controller”), in order to ensure that the principles of data protection and the requirements of data security are upheld.
2. Details and Contact Information of the Data Controller
- Name of the Data Controller: Földesi Zsolt E.V. (sole proprietorship)
- Registered office of the Data Controller: 1095 Budapest, Boráros tér 6.
- Phone number of the Data Controller: +36 30 153 8944
- Tax number: 69395213-1-42
- E-mail address: hello@net-face.com
- Website operated by the Data Controller: net-face.com
3. General Provisions
The Data Controller processes personal data exclusively for the given lawful purpose and only to the extent necessary to achieve that purpose, confidentially, accurately and in an up-to-date manner, preserving their integrity, in accordance with the applicable legal provisions. It ensures the security of the data, takes the necessary administrative, logical, physical security and organizational measures, and establishes the procedural rules necessary to give effect to the relevant provisions of the applicable legislation.
In the course of data processing, the Data Controller preserves:
- confidentiality: it protects the information so that only those who are authorized may access it;
- integrity: it protects the accuracy and completeness of the information and of the method of processing;
- availability: it ensures that when an authorized user needs it, they can actually access the desired information, and that the tools required for this are available.
The Data Controller undertakes that all data processing related to its activities complies with the requirements set out in this privacy policy and in the relevant applicable legislation.
4. Legal Background
The Data Controller is obliged to comply with the legal provisions concerning the processing of personal data at every stage of the data processing. The data processing carried out by the Data Controller is governed primarily by the provisions laid down in the following legislation:
- Act V of 2013 on the Civil Code (the “Civil Code”);
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, GDPR);
- Act CXII of 2011 on the Right to Informational Self-Determination and on Freedom of Information (the “Data Protection Act”, “Info Act”).
5. Legal Background, Legal Basis and Purpose of the Data Processing Carried Out on the Website, the Scope of the Personal Data Processed, and the Duration of the Data Processing
5.1 Information on the Use of Cookies
What is a cookie? The Data Controller uses so-called cookies during visits to the website. A cookie is a package of information consisting of letters and numbers that the net-face.com site sends to your browser for the purpose of saving certain settings, making the use of our website easier, and helping us collect some relevant, statistical information about our visitors. Cookies do not contain personal information and are not suitable for identifying individual users. Cookies often contain a unique identifier – a secret, randomly generated sequence of numbers – which is stored on your device. Some cookies expire after the website is closed, while others are stored on your computer for a longer period.
Legal background and legal basis of cookies: The background of the data processing is provided by the provisions of Act CXII of 2011 on the Right to Informational Self-Determination and on Freedom of Information (Info Act) and of Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services. The legal basis of the data processing is your consent, in accordance with point a) of Section 5(1) of the Info Act.
Main characteristics of the cookies used by the website:
Session cookie: These cookies store the visitor’s location, the browser language and the payment currency. Their lifespan lasts until the browser is closed, or a maximum of 2 hours. Duration of data processing: 2 hours.
Referer cookies: They record the external site from which the visitor arrived at the website. Their lifespan lasts until the browser is closed.
Mobile version / design cookie: It detects the device used by the visitor and switches to full view on mobile. Lifespan: 365 days. Duration of data processing: 365 days.
Cookie acceptance cookie: Upon arriving at the site, the visitor accepts the statement on the storage of cookies in the notification window. Lifespan: 365 days. Duration of data processing: 365 days.
Smart offer cookie: It records the conditions for displaying smart offers (e.g. whether the visitor has already been to the site). Lifespan: 30 days. Duration of data processing: 30 days.
Backend identifier cookie: The identifier of the backend server serving the site. Its lifespan lasts until the browser is closed. Duration of data processing: until the browser is closed.
Google Analytics cookie: When someone visits our site, the visitor’s cookie identifier is added to the visitor list, which can be used for later remarketing. Google uses cookies – such as the NID and SID cookies – to customize the advertisements displayed in Google products, for example in Google Search. It uses such cookies, for example, to remember your most recent searches, your previous interactions with the advertisements of individual advertisers or with search results, and your visits to advertisers’ websites.
The conversion tracking function of Analytics uses cookies. In order to track sales and other conversions resulting from advertisements, it saves cookies onto the user’s computer when the given person clicks on an advertisement. Some common ways in which cookies are used: selecting advertisements on the basis of what is relevant for the given user, improving reports on campaign performance, and avoiding the display of advertisements the user has already viewed.
Google Analytics is Google’s analytics tool, which helps the owners of websites and applications to get a more accurate picture of their visitors’ activities. The service may use cookies to collect information and prepare reports from statistical data on the use of the website without individually identifying the visitors to Google. The main cookie used by Google Analytics is the “__ga” cookie. In addition to the reports prepared from website usage statistics, Google Analytics – together with some of the advertising cookies described above – may also be used to display more relevant advertisements in Google products (such as Google Search) and across the internet.
RTB personalized retargeting cookies: These may be displayed to previous visitors or users while they browse other websites on the Google Display Network, or when they search for terms related to its products or services.
Facebook Pixel: The tracking codes of the Facebook social network have also been placed on our site. When you visit our site, the remarketing tags establish a direct connection between your browser and the Facebook server. Facebook receives the data together with your IP address. As a result, Facebook may link the pages of ours that you have visited to your user account. We may use this information to display Facebook advertisements. Please note that, as the provider of the site, we have no knowledge of the content of the data transmitted or of how Facebook uses it. Further information can be found in Facebook’s privacy policy: https://www.facebook.com/about/privacy/. If you do not want Facebook to associate you with given lists via Custom Audiences targeting, you can disable the Custom Audiences setting there.
If you do not accept the use of cookies, certain functions will not be available to you. For more information on deleting cookies, please see the following links:
- Internet Explorer: http://windows.microsoft.com/en-us/internet-explorer/delete-manage-cookies#ie=ie-11
- Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer
- Chrome: https://support.google.com/chrome/answer/95647?hl=en
5.4 Scope of the Personal Data Processed
The Data Controller processes the following personal data, in accordance with the principles detailed below:
Name, e-mail address, phone number, IP address, browser, user’s device, cookies.
5.7 Data Processing Related to Contact by Phone or Online
Legal background and legal basis of the data processing: The legal basis of the data processing is the User’s voluntary consent to the data processing; the recording of the data is initiated by the User.
Purpose of the data processing: The purpose of the data processing is a one-time exchange of information.
Scope of the data processed: The personal data processed are the User’s name, phone number and own e-mail address. The data subjects of the processing are all interested persons who initiate contact.
Duration of the data processing: 5 working days, but no longer than until the question raised by the user has been answered in full.
Data processors involved: The data provided during registration are processed by the Data Controller.
5.8 Data Processing Related to Job Applications
Legal background and legal basis of the data processing: The legal basis of the data processing is the User’s voluntary consent to the data processing; the recording of the data is initiated by the User.
Purpose of the data processing: The purpose of the data processing is the User’s application for the advertised purpose.
Scope of the data processed: The personal data processed are the User’s name and own e-mail address. The data subjects of the processing are all interested persons who initiate contact.
Duration of the data processing: 15 years.
Data processors involved: The data provided are processed by the Data Controller.
6. Modifying Consents
Users may withdraw the consent they have given to the data processing:
6.1 Modifying Cookie Consents
For more information on deleting cookies, please see the following links:
- Internet Explorer: http://windows.microsoft.com/en-us/internet-explorer/delete-manage-cookies#ie=ie-11
- Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer
- Chrome: https://support.google.com/chrome/answer/95647?hl=en
7. Use of Data Processors and Their Activities Related to the Data Processing
7.1 Data Processor Related to Online Marketing Activities
- Company name of the data processor: Facebook Ireland Limited
- Registered office of the data processor: 4 Grand Canal Square, Grand Canal Harbour
- Tax number: IE9692928F
- Company name of the data processor: Google
- Registered office of the data processor: Dublin, Barrow Str. 4
- Tax number: IE6388047V
Scope of personal data concerned: IP address, cookies.
7.2 Data Processing Related to the Technical Maintenance of the Website
Hosting service:
- Company name of the data processor: Webline Services Inc
- Registered office of the data processor: 228 East RT 59, Suite 356, Nanuet, NY 10954
Scope of personal data concerned: IP address.
The Data Controller has a contractual relationship complying with the statutory requirements with each data processor, which ensures that personal data may be processed only on the basis of the Data Controller’s written instructions, that the data processor undertakes an obligation of confidentiality, that guarantees are laid down concerning the data processor’s IT and other security conditions, and that, upon request, the data processor makes all necessary information available to the Data Controller.
Users consent to the transfer of their data to all of the above data processors where the conditions detailed above are met.
8. The User’s Rights and Options for Enforcing Them
8.1 Right to Transparent Information
The User has a fundamental right to appropriate, transparent information, which appears as an obligation on the part of the Data Controller. The Data Controller informs the User about the circumstances of the data processing and the rights to which they are entitled concisely, transparently, intelligibly, in an easily accessible format, clearly and in plain language. In the case of a request for information, we provide the information without undue delay, but within 30 days at the latest.
8.2 Right of Access and to Copies
The User has the right to receive confirmation from the Data Controller as to whether their personal data are being processed and, where such processing is taking place, the right to access the personal data and the related information, in particular concerning the source of the personal data and whether the data have been transferred to a third party. The Data Controller provides the information within one month at the latest from the submission of the request.
The User may at any time request a copy of any personal data processed by the Data Controller, which the Data Processor is obliged to send to the User without delay.
8.3 Right to Data Portability
The User has the right to receive the personal data concerning them which they have provided to the Data Controller in a structured, commonly used, machine-readable format, and to transmit those data to another data controller.
The Data Controller complies with requests sent to the hello@net-face.com e-mail address within 15 days at the latest.
8.4 Right to Rectification and Modification
Users are entitled to have the data they have provided rectified or modified by sending an e-mail to hello@net-face.com.
8.5 Right to Be Forgotten and Right to Erasure
The Data Controller is obliged to erase the personal data concerning the User without undue delay if any of the following grounds applies:
- the personal data are no longer needed for the purpose for which they were collected or otherwise processed;
- the storage period determined by the Data Controller has expired;
- the User withdraws the consent forming the basis of the data processing, and there is no other legal basis for the processing;
- the User objects to the data processing, and there are no overriding legitimate grounds for the processing;
- the personal data have been processed unlawfully.
The Data Controller complies with requests sent to the hello@net-face.com e-mail address within 15 days at the latest.
The right to erasure does not extend to cases where the Data Controller is obliged by law to continue storing the data, nor to cases where, in accordance with Section 6(5) of the Info Act, the Data Controller is entitled to further process the personal data (for example, in connection with invoicing). Furthermore, the right to be forgotten and to erasure does not apply to the extent that the processing is necessary for the establishment, exercise or defense of legal claims.
In the course of erasure, the Data Controller is also obliged to notify the data processors involved of the erasure obligation.
8.6 Right to Object
The User has the right to object, on grounds relating to their particular situation, at any time to the processing of their personal data that is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller, or that is necessary for the purposes of the legitimate interests pursued by the data controller or by a third party, including profiling based on those provisions. In the event of an objection, the data controller may no longer process the personal data unless the processing is justified by compelling legitimate grounds which override the interests, rights and freedoms of the User, or which are related to the establishment, exercise or defense of legal claims.
The Data Controller examines the objection within the shortest possible time from the submission of the request to the hello@net-face.com e-mail address, but within 15 days at the latest, makes a decision as to whether it is well founded, and informs you of its decision in writing. If the Data Controller does not comply with the User’s request for rectification, blocking or erasure, it shall, within 25 days of receipt of the request, communicate in writing or, with the User’s consent, by electronic means, the factual and legal grounds for rejecting the request for rectification, blocking or erasure.
8.7 Right to Restriction of Processing
In the event of restriction, the personal data may merely be stored; any other processing may take place only with the User’s consent, for the purpose of establishing legal claims, or in the public interest.
The User has the right to obtain from the Data Controller, upon request, the restriction of the processing if any of the following applies:
- the processing is unlawful, and the User opposes the erasure of the data and requests the restriction of their use instead;
- the Data Controller no longer needs the personal data for the purposes of the processing, but the User requires them for the establishment, exercise or defense of legal claims;
- the User has objected to the processing; in this case, the restriction applies for the period until it is established whether the legitimate grounds of the Data Controller override those of the User.
8.8 Automated Individual Decision-Making, Including Profiling
The Data Controller does not use or carry out profiling, automated decision-making or automated mechanisms.
The Data Controller does not permit its data processors to carry out automated decision-making or profiling either, except where the User has given separate, written consent to this.
9. Data Security
The Data Controller makes every effort to ensure the security of the users’ personal data processed by it, both in the course of network communication and in the course of storing and safeguarding the data. At the same time, the Operator excludes any and all liability related to the data processing that concerns the operation of the servers and of the hosting space used to host the Service, and transfers all liability related to server and hosting operation to the Hosting Provider and the Maintainer.
Although the Data Controller implements security measures corresponding to industry standards to ensure this, the Data Controller does not guarantee that the personal data of individual users relating to their activities carried out within the framework of the Service, or displayed within the Service, will be processed exclusively in the manners set out in this privacy policy. Third parties, or even other Users, may be capable of unlawfully intercepting or spying out messages or data that fall under the protection of the legal provisions safeguarding data protection and personality rights. In addition, the User may also disclose their personal data to third parties, who may use them for unlawful purposes or in unlawful ways.
Users bear sole responsibility for the use of their personal data, including all activities connected with the use of their e-mail address. If the User nevertheless discloses these data to a third party, as a consequence they may lose the ability to control their data processed within the framework of the Service by the Data Controller and by other data controllers and data processors, and they may also become personally bound by legally binding transactions. In such a case, it is advisable to change the data concerned without delay.
10. Exclusion of the Data Controller’s Liability
If the Data Controller becomes aware that the User, in the course of using the Service, provides another person’s personal data in a manner violating this Notice, the rights of a third party or the law in general; uses personal or other data that are publicly accessible within the Service or were obtained unlawfully in a manner violating the rights of third parties or the law; or has otherwise breached the provisions contained in this privacy policy or has caused damage in the course of using the Service, the Data Controller will take the necessary legal steps to obtain compensation for the damage caused and to hold the perpetrator legally accountable. In such cases, the Data Controller provides all possible assistance to the acting authorities for the purpose of establishing the identity of the infringing person and with regard to holding them accountable.
11. Data Protection Incidents; Data Protection Log
The Data Controller is obliged to inform the competent Authority and, at the same time, the persons affected by the data protection incident, as soon as possible after becoming aware of any data protection incident, but within 72 hours at the latest. The Data Controller does everything within its means to reduce the data protection and other damage caused to the data subjects as a consequence of the incident.
The Data Controller is obliged to ensure that similar incidents cannot occur in the future. The Data Controller keeps a so-called data protection log of every data protection-related case – inquiries from data subjects concerning data protection and any data protection incidents – and provides information on its content relating to a given data subject upon request.
12. Taking Legal Action
In the event of a violation of their rights, the User may bring an action against the Data Controller before the courts. The court proceeds in such cases as a matter of priority. Adjudication of the case falls within the competence of the regional court (törvényszék). The action may be brought before the regional court competent according to the registered office of the Data Controller or, at the User’s choice, before the regional court competent according to the User’s place of residence or place of stay.
If the Data Controller causes damage to another person by the unlawful processing of the User’s data or by breaching the requirements of data security, it is obliged to compensate for it. If the Data Controller violates the User’s personality rights by the unlawful processing of the User’s data or by breaching the requirements of data security, the User may claim compensation for non-material damage (in Hungarian: “sérelemdíj”) from the Data Controller.
The Data Controller is exempted from liability for the damage caused and from the obligation to pay compensation for non-material damage if it proves that the damage, or the violation of the User’s personality rights, was caused by an unavoidable cause falling outside the scope of the data processing.
No compensation for damage shall be paid and no compensation for non-material damage may be claimed insofar as the damage suffered by the injured party, or the legal injury caused by the violation of personality rights, resulted from the User’s intentional or grossly negligent conduct.
13. Proceedings Before the Authority; Filing a Complaint
If, in your view, the Data Controller has violated a statutory provision concerning data processing, or has failed to comply with one of your requests, then, in order to put an end to the presumed unlawful data processing, you may initiate an investigation by the National Authority for Data Protection and Freedom of Information, and you may also request information from the competent Authority:
- Name: National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság)
- Registered office: 1125 Budapest, Szilágyi Erzsébet fasor 22/c.
- Postal address: 1530 Budapest, P.O. Box 5
- Mailing address: 1530 Budapest, P.O. Box 5
- Phone: +36 (1) 391-1400
- Fax: +36 (1) 391-1410
- E-mail: ugyfelszolgalat@naih.hu
- Website: http://naih.hu
14. Miscellaneous Provisions
We provide detailed information on any data processing operations not listed in this notice at the time the data are recorded. The Data Controller discloses personal data to the authorities – provided that the authority has indicated the exact purpose and the scope of the data – only in such quantity and to such extent as is strictly necessary for achieving the purpose of the request.
15. Amendment of this Privacy Policy
The data protection principles applicable to the Data Controller’s data processing operations are continuously available at net-face.com. The Data Controller reserves the right to amend this notice at any time.