DATA PROCESSING AND DATA PROTECTION
Data Protection Policy
for the use of the http://www.hooplsewing.com website and for purchases made in the webshop on the site

 

During your use of www.hooplsewing.com and during purchases made in the website's webshop, you provide personal data, which we process based on the following laws.

 

  • Act CXII of 2011 on the right to informational self-determination and freedom of information (hereinafter: "Info Act"),
  • Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) ("GDPR"),
  • Act CVIII of 2001 on certain issues of electronic commerce services and information society services ("Eker. Act"),
  • Act XLVIII of 2008 on the basic conditions and certain limitations of economic advertising activities ("Grt. Act"),
  • Act C of 2000 on Accounting ("Számv. Act"),
  • Act CXXVII of 2007 on Value Added Tax ("Áfa Act"),
  • Act V of 2013 on the Civil Code ("Ptk. Act"),
  • Act CLV of 1997 on Consumer Protection ("Fgy. Act"),
  • Act CLIX of 2012 on Postal Services ("Posta Act").

 

The purpose of this document is to inform you, in accordance with the above legal regulations, about the details of personal data processing and your related rights.

 

  1. IDENTITY OF THE DATA CONTROLLER

 

Orsolya Varró e.v. (registered office: 1163 Budapest, Gordonka utca 47. 2. ajtó., tax number: 59445173-1-42; telephone: 06 70 9333 973 e-mail: hello@hooplasewing.com; website: www.hooplasewing.com hereinafter: "Data Controller" or "data controller")

 

The Data Controller determines the scope, purpose, and duration of the data requested during purchases in the webshop, as well as other essential conditions of data processing.

 

This policy sets out the rules for the protection of natural persons with regard to the processing of personal data and the free movement of such data. The provisions of this policy shall apply to specific data processing activities and when issuing instructions and information regulating data processing. The Data Controller reserves the right to change and modify this policy at any time, but will always inform its audience in due time.

 

The organization does not employ a data protection officer.

 

The Data Controller always treats personal data confidentially and takes all security, technical, and organizational measures to guarantee data security.

 

  1. PROVISION OF DATA IS VOLUNTARY

 

You are not obliged to provide your personal data, however, without it, you will not be able to purchase the products available in the webshop.

 

  1. SCOPE OF THE POLICY

 

This policy is valid until revoked, and its scope extends to the users of the www.hooplasewing.com website who have accepted it, as well as to the officials and employees of the organization.

 

  1. PURPOSE OF THE POLICY

 

The purpose of this policy is to harmonize the protection of fundamental rights and freedoms of natural persons with regard to data processing activities and to ensure the proper handling of personal data.

 

During its activities, the organization fully intends to comply with the legal requirements for the processing of personal data, especially with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council.

 

Principles of data processing

 

Personal data must be processed lawfully, fairly, and in a transparent manner in relation to the data subject.

 

Personal data may only be collected for specified, explicit, and legitimate purposes.

 

The purpose of personal data processing must be adequate, relevant, and limited to what is necessary.

 

Personal data must be accurate and, where necessary, kept up to date. Inaccurate personal data must be deleted without delay.

 

Personal data must be stored in a form that permits identification of data subjects for no longer than is necessary. Personal data may be stored for longer periods only insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes.

 

Personal data must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organisational measures.

 

The principles of data protection should apply to all information concerning an identified or identifiable natural person.

 

The employee of the organization performing data processing is subject to disciplinary, compensation, misdemeanor, and criminal liability for the lawful processing of personal data. If the employee becomes aware that the personal data processed by them is incorrect, incomplete, or outdated, they are obliged to correct it or initiate its correction.

 

  1. PROCESSING OF PERSONAL DATA

 

Since natural persons can be associated with online identifiers provided by their devices, applications, tools, and protocols, such as IP addresses and cookie identifiers, these data, when combined with other information, are suitable and can be used to create a profile of natural persons and identify the given person.

 

Data processing can only take place if the data subject gives explicit affirmative consent to the processing of their data for one or more specific purposes, for example by a written – including electronic – or oral statement.

 

Consent to data processing is also considered to be given if the data subject checks a corresponding box when viewing the website. Silence, a pre-checked box, or inaction does not constitute consent.

 

Consent is also considered to be given if a user makes technical settings in connection with the use of electronic services or makes a statement or action that clearly indicates the data subject's consent to the processing of their personal data in the given context.

 

The personal data of children deserve special protection, as they may be less aware of the risks, consequences, and related safeguards and rights in connection with the processing of personal data. This special protection should mainly apply to the use of children's personal data for marketing purposes or for the purpose of creating personal or user profiles.

 

Personal data must be processed in a way that ensures an appropriate level of security and confidentiality, including to prevent unauthorized access to and use of personal data and the tools used for personal data processing.

 

All reasonable steps must be taken to rectify or erase inaccurate personal data.

 

  1. LAWfulness OF DATA PROCESSING

 

The processing of personal data is lawful if one of the following conditions is met:

  • the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
  • processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

 

  • processing is necessary for compliance with a legal obligation to which the controller is subject;

 

  • processing is necessary in order to protect the vital interests of the data subject or of another natural person;
  • processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  • processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

 

In accordance with the above, data processing is considered lawful if it is necessary within the framework of a contract or an intention to enter into a contract.

 

In the course of its activities, the Data Controller processes personal data based on voluntary consent or legal authorization. If the basis for data processing is voluntary consent, data subjects may withdraw this consent at any stage of the data processing.

 

In certain cases, however, laws make it mandatory to process, store, or transmit a certain scope of the provided data, about which we will inform you separately. We also draw your attention to the fact that if you do not provide your own personal data, it is your duty as a data provider to obtain the consent of the data subject.

 

If data processing is carried out within the framework of compliance with a legal obligation to which the controller is subject, or if it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, the data processing must have a legal basis in Union law or in the law of a Member State.

 

Data processing should be considered lawful when it is carried out in order to protect the life of the data subject or the interests of another natural person as mentioned above. In principle, personal data processing based on the vital interests of another natural person can only take place if the data processing in question cannot be carried out on another legal basis.

 

Some types of personal data processing may serve both an important public interest and the vital interests of the data subject, for example, in cases where data processing is necessary for humanitarian reasons, including when it is necessary for tracking epidemics and their spread, or in humanitarian emergencies, especially in the event of natural or man-made disasters.

 

The legitimate interest of the data controller – including the data controller to whom personal data may be communicated – or a third party may provide a legal basis for data processing. Such a legitimate interest may arise, for example, when there is a relevant and appropriate relationship between the data subject and the data controller, for example, in cases where the data subject is a client of the data controller or is employed by them.

 

The processing of personal data strictly necessary for the prevention of fraud also qualifies as a legitimate interest of the data controller concerned. The processing of personal data for direct marketing purposes can also be considered based on legitimate interest.

 

To establish the existence of a legitimate interest, it is necessary to carefully examine, among other things, whether the data subject could reasonably expect, at the time of data collection and in connection therewith, that data processing could take place for the given purpose. The interests and fundamental rights of the data subject may override the interests of the data controller if personal data is processed under circumstances where data subjects do not expect further data processing.

 

The personal data processing carried out by public authorities, computer emergency response teams, network security incident management teams, operators and providers of electronic communication networks, and security technology providers to the extent strictly necessary and proportionate to ensure network and information security, is considered a legitimate interest of the data controller concerned.

 

Processing of personal data for purposes other than the original purpose for which they were collected is only permitted if the data processing is compatible with the original purposes for which the personal data were originally collected. In this case, no separate legal basis other than that which permitted the collection of personal data is required.

 

The processing of personal data by authorities for the purpose of achieving the goals of officially recognized religious organizations as established in constitutional law or international public law is considered to be based on public interest.

 

  1. SCOPE OF PROCESSED DATA, PURPOSE, AND DURATION OF DATA PROCESSING

 

Purchases without registration or with registration:

 

Scope of data processed for purchases without registration:

 

Registration is not required for purchases on the website, however, an online order form must be filled out for the order, which includes the customer's name (surname and first name), billing and shipping address (country, zip code, city, street, house number, floor, door), email address, phone number, and the ordered product and its price.

 

Scope of data processed for purchases with registration:

 

The customer can also register on the website for purchases and can make purchases after registration. The scope of data processed during registration: customer's name (surname and first name), billing and shipping address (country, zip code, city, street, house number, floor, door), email address, phone number, and the ordered product and its price, username, and password for logging into their own account.

 

The above data are necessary for the fulfillment of the order, the purpose of data processing is the fulfillment of the order.

 

In case of undue payment, the Seller will need the Buyer's bank account number to which the amount can be transferred. The Data Controller does not disclose the data to third parties, they are only made available to service providers used for the fulfillment of the order.

 

The Data Controller retains the provided data until the fulfillment of the contract, the withdrawal of the data subject's consent, or for 5 years after the date of purchase (Civil Code Section 6:22). If the Data Controller is obliged to retain the data based on the Accounting Act, then the Data Controller will delete the data only after the expiration of the retention obligation prescribed by law, regardless of the data subject's consent.

 

The legal basis for the above data processing is the data subject's consent, Section 5 (1) a) of the Info Act, Article 6 (1) a)-c) of the GDPR, as well as Section 169 (2) of the Accounting Act and Section 169 of the VAT Act.

 

You can withdraw your consent at any time by sending a message to the email address hello@hooplasewing.com.

 

During complaint handling, we process the following personal data: a) the consumer's name, address, b) the place, time, and method of submitting the complaint, c) a detailed description of the consumer's complaint, a list of documents, papers, and other evidence presented by the consumer, d) the Data Controller's statement on its position regarding the consumer's complaint, if the complaint can be investigated immediately, e) the signature of the person taking the minutes and the consumer (unless the complaint was submitted by email or phone), f) the place and time of taking the minutes.

 

In this context, the purpose of data processing is to investigate and accurately document the circumstances of the complaint, in order to ensure that the Data Controller has access to requests and observations related to the Data Controller's activities. Communication is archived, so in case of any subsequent questions or disputes, the information is available in its original form and, if necessary, the Data Controller can contact the user in connection with the case. The Data Controller is obliged to retain the minutes of the complaint and a copy of the response for five years and present it to the controlling authorities upon their request. If the Data Controller is obliged to retain the data based on the Accounting Act, then the Data Controller will delete the data only 8 years after the submission of the complaint, regardless of the data subject's consent.

 

The legal basis for the processing of data processed during complaint handling activities is the data subject's consent, Section 5 (1) a) of the Info Act, Article 6 (1) a)-c) of the GDPR, and Section 17/A of the Consumer Protection Act.

 

Cookie management on www.hooplasewing.com

 

The data controller places an anonymous user identifier (cookie) on the data subject's computer, which is solely capable of recognizing the data subject's machine. Providing a name, email address, or any other personal information is not necessary, as when using this solution, the data subject does not transmit personal data to the data controller; data exchange occurs exclusively between machines. The service provider managing the cookie can link the data subject's current visit to previous ones, but only in relation to the data controller's own content.

 

The data controller processes cookies to learn more about the data subjects' information usage habits and thereby improve the quality of its services. Data subjects have the option to prevent the placement of unique identifiers (cookies) on their computer by adjusting their browser settings. Data subjects acknowledge that some services may not function properly if cookies are disabled.

 

Purpose of data processing: identification of data subjects, differentiation from each other, identification of data subjects' current session.

 

Legal basis for data processing: the data subject's consent in accordance with Article 6 (1) a) of the GDPR

 

Scope of data processed: identification number, date, time, and the previously visited page

Duration of data processing: cookies remain active until the browser is closed, but users can also modify this in the settings.

 

Possible consequences of not providing data: the services of www.hooplasewing.com may not be fully available.

 

Newsletter subscription