PRIVACY NOTICE
- Füstcsőmester Kft. / KARA & Co. webshop
- 1. INTRODUCTION AND DETAILS OF THE DATA CONTROLLER
- 1.1. 1.1. The Data Controller
- Company name: Füstcsőmester Gyártó és Kereskedő Korlátolt Felelősségű Társaság
- Short name: Füstcsőmester Kft.
- Registered office: 2366 Kakucs, Ipartelep utca 5., Hungary
- Company registration number: 13-09-099649
- Tax number: 13310945-2-13
- Website: www.karaand.com
- E-mail: hello@karaand.com
- Telephone: +36 30 600 5840
- 1.2. 1.2. Data Protection Contact Person
- Name: Kata Balázs
- E-mail: balazs.kata@karaand.com
- Telephone: +36 30 719 1477
- 1.3. 1.3. Purpose and scope of this Notice
- The purpose of this Privacy Notice (hereinafter: “Notice”) is to inform Data Subjects of the data processing practices of the KARA & Co. online shop (hereinafter: “Webshop”) operated by Füstcsőmester Kft. (hereinafter: “Data Controller”). The Notice applies to the services available through the Webshop and to the related processing of personal data. The Notice does not extend to the data processing practices of websites that may be reached via links placed on the Webshop. By using the Webshop or by registering, the Data Subject accepts the provisions of this Notice.
- 1.4. 1.4. Key definitions
- Data Subject: an identified or identifiable natural person who uses the Webshop, registers or makes a purchase.
- Personal data: any information relating to a Data Subject.
- Processing: any operation performed on personal data.
- Data Controller: the legal person which, alone or jointly with others, determines the purposes and means of processing personal data.
- Data Processor: the natural or legal person which processes personal data on behalf of the Data Controller.
- GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
- 2. PRINCIPLES AND LEGAL BASES
- 2.1. 2.1. Data processing principles
- The Data Controller observes the following principles when processing personal data:
- Lawfulness, fairness and transparency: Processing is carried out lawfully, fairly and in a transparent manner in relation to the Data Subject.
- Purpose limitation: Personal data are collected only for specified, explicit and legitimate purposes.
- Data minimisation: Processing is adequate, relevant and limited to what is necessary in relation to the purposes.
- Accuracy: Personal data are kept accurate and, where necessary, up to date.
- Storage limitation: Personal data are stored only for as long as is necessary for the purposes.
- Integrity and confidentiality: Personal data are processed in a manner that ensures appropriate security.
- Accountability: The Data Controller is responsible for compliance with the above principles and must be able to demonstrate such compliance.
- 2.2. 2.2. Legal bases of processing
- The Data Controller processes personal data on at least one of the following legal bases:
- Consent: The Data Subject’s freely given, specific, informed and unambiguous consent (e.g. newsletter subscription).
- Performance of a contract: Processing is necessary for the performance of a contract to which the Data Subject is party (e.g. purchase).
- Legal obligation: Processing is necessary for compliance with a legal obligation to which the Data Controller is subject (e.g. retention of accounting records).
- Legitimate interests: Processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party (e.g. prevention of misuse).
- 3. CATEGORIES OF DATA PROCESSED, PURPOSES AND LEGAL BASES
- 3.1. 3.1. Data processed during registration
- Categories of data: name, e-mail address, telephone number, country, postal code, city, street name, street type, house number or land registry number, password (in encrypted form).
- Purpose of processing: creating the user account, identification, contact, provision of the service.
- Legal basis: performance of a contract (Article 6(1)(b) GDPR).
- Retention period: until deletion of the registration, or after 3 years of inactivity counted from the last login.
- 3.2. 3.2. Data processed during purchase
- Categories of data: name, e-mail address, telephone number, delivery address (country, postal code, city, street name, street type, house number or land registry number), billing address (if different from the delivery address), purchase data (products, quantity, price, date).
- Purpose of processing: fulfilment of the order, documentation of the purchase and payment, compliance with accounting obligations, customer records, customer differentiation, contact.
- Legal basis: performance of a contract (Article 6(1)(b) GDPR), compliance with a legal obligation (Article 6(1)(c) GDPR).
- Retention period: for accounting records, 8 years (Section 169(2) of Act C of 2000 on Accounting); in other cases, 5 years from the date of fulfilment of the purchase (general civil law limitation period).
- 3.3. 3.3. Billing data
- Categories of data: name, billing address (country, postal code, city, street name, street type, house number or land registry number), tax number (if provided), purchase data (products, quantity, price, date).
- Purpose of processing: issuing invoices, compliance with accounting and tax obligations.
- Retention period: 8 years (Section 169(2) of Act C of 2000 on Accounting).
- 3.4. 3.4. Data processed in connection with newsletter subscription
- Categories of data: name, e-mail address, date of subscription, IP address used at the time of subscription.
- Purpose of processing: sending newsletters, marketing communications, providing information on news and offers.
- Legal basis: the Data Subject’s consent (Article 6(1)(a) GDPR).
- Retention period: until withdrawal of consent (unsubscription).
- 3.5. 3.5. Contact and customer service
- Categories of data: name, e-mail address, telephone number, content of the message.
- Purpose of processing: maintaining contact, responding to messages from the Data Subject.
- Legal basis: the Data Subject’s consent (Article 6(1)(a) GDPR), or performance of a contract (Article 6(1)(b) GDPR).
- Retention period: 30 days after the message has been answered; in case of a complaint, 5 years (Section 17/A(7) of Act CLV of 1997 on Consumer Protection).
- 3.6. 3.6. “Favourites” feature and purchase history
- Categories of data: data relating to products marked as favourites by the user, data of previous purchases.
- Purpose of processing: maintaining records of products preferred or previously purchased by the user, improvement of the customer experience.
- Legal basis: the Data Subject’s consent (Article 6(1)(a) GDPR) or the legitimate interests of the Data Controller (Article 6(1)(f) GDPR).
- Retention period: until deletion of the registration, or after 3 years of inactivity counted from the last login.
- 3.7. 3.7. Technical data, cookies
- Categories of data: time of visit, IP address, type of browser, type of operating system, pages visited, user activity.
- Purpose of processing: ensuring the proper operation of the website, statistics, development of the service, prevention of misuse.
- Legal basis: the Data Controller’s legitimate interests (Article 6(1)(f) GDPR), and for certain cookies the Data Subject’s consent (Article 6(1)(a) GDPR).
- Retention period: depending on the lifetime of the given cookie (see Section 9 for details).
- 4. DATA PROCESSORS
- The Data Controller engages data processors for the performance of certain processing operations. Data Processors do not make independent decisions and may process personal data exclusively in accordance with the contract concluded with the Data Controller and the instructions received from the Data Controller.
- 4.1. 4.1. Hosting provider
- Name: RackForest Kft.
- Registered office: 1132 Budapest, Victor Hugó utca 11., 5th floor B05001
- Activity: providing the hosting required for the operation of the webshop.
- 4.2. 4.2. Courier service
- Name: Packet Trans Kft.
- Registered office: 1239 Budapest, Ócsai út 1–3.
- Activity: delivery of ordered products.
- 4.3. 4.3. Accounting service provider
- Name: Geo-Solar Kft.
- Registered office: 2051 Biatorbágy, Székely utca 29.
- Activity: accounting and bookkeeping services.
- 4.4. 4.5. Online advertising service provider
- Name: Google Ireland Limited
- Registered office: Dublin 4, Barrow Street, Ireland
- Activity: online advertising.
- 4.5. 4.5. Online advertising service provider
- Meta Platforms Ireland Limited
- Registered office: Grand Canal Square, Grand Canal Harbour, Dublin D02X525, Ireland
- Activity: online advertising.
- 5. TRANSFER OF DATA
- 5.1. 5.1. Domestic data transfers
- The Data Controller transfers personal data to third parties only with the prior consent of the Data Subject or pursuant to a statutory provision, in the following cases:
- to the courier service for the purpose of delivering the ordered products;
- to the payment service provider for the purpose of settling the consideration of the purchase;
- to authorities and courts for the purpose of compliance with a statutory obligation.
- 5.2. 5.2. Data transfers within the EU
- In the event of internationally planned shipments, the Data Controller may transfer personal data to EU Member States for the purpose of fulfilling such deliveries. In such cases, the recipient of the transfer will be the courier service operating in the relevant country. During data transfers within the EU, the Data Controller ensures compliance with the requirements of the GDPR.
- 5.3. 5.3. Transfers to third countries
- The Data Controller does not transfer personal data to countries outside the European Union. Should this change in the future, the Data Controller will notify Data Subjects in advance and provide appropriate safeguards.
- 6. RIGHTS OF DATA SUBJECTS AND THEIR EXERCISE
- The Data Subject may exercise the following rights vis-à-vis the Data Controller:
- 6.1. 6.1. Right to information
- The Data Subject has the right to receive information about the processing in a concise, transparent, intelligible and easily accessible form.
- 6.2. 6.2. Right of access
- The Data Subject has the right to obtain confirmation from the Data Controller as to whether or not personal data concerning them are being processed, and, where that is the case, access to the personal data and to information related to the processing.
- 6.3. 6.3. Right to rectification
- The Data Subject has the right to obtain from the Data Controller, without undue delay, the rectification of inaccurate personal data concerning them, and the right to have incomplete personal data completed.
- 6.4. 6.4. Right to erasure (“right to be forgotten”)
- The Data Subject has the right to obtain from the Data Controller, without undue delay, the erasure of personal data concerning them, where one of the following applies:
- the personal data are no longer necessary in relation to the purposes for which they were collected;
- the Data Subject withdraws the consent on which the processing is based;
- the Data Subject objects to the processing and there are no overriding legitimate grounds for the processing;
- the personal data have been unlawfully processed;
- the personal data must be erased for compliance with a legal obligation.
- 6.5. 6.5. Right to restriction of processing
- The Data Subject has the right to obtain from the Data Controller restriction of processing where one of the following applies:
- the accuracy of the personal data is contested by the Data Subject;
- the processing is unlawful and the Data Subject opposes erasure of the personal data;
- the Data Controller no longer needs the personal data for the purposes of the processing, but they are required by the Data Subject for the establishment, exercise or defence of legal claims;
- the Data Subject has objected to the processing.
- 6.6. 6.6. Right to data portability
- The Data Subject has the right to receive the personal data concerning them, which they have provided to the Data Controller, in a structured, commonly used and machine-readable format, and has the right to transmit those data to another controller, where the processing is based on consent or on a contract and is carried out by automated means.
- 6.7. 6.7. Right to object
- The Data Subject has the right to object to the processing of personal data concerning them where the processing is necessary for the legitimate interests of the Data Controller or of a third party. In such cases, the Data Controller shall no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the Data Subject.
- 6.8. 6.8. Automated decision-making and profiling
- The Data Controller does not carry out automated decision-making or profiling. Should this change in the future, the Data Controller will provide separate information on the conditions thereof.
- 6.9. 6.9. Right to withdraw consent
- Where the processing is based on consent, the Data Subject has the right to withdraw their consent at any time. The withdrawal of consent does not affect the lawfulness of consent-based processing carried out before the withdrawal.
- 6.10. 6.10. How to exercise these rights
- Requests for the exercise of Data Subject rights may be submitted in the following ways:
- by e-mail: balazs.kata@karaand.com
- by post: 2366 Kakucs, Ipartelep utca 5., Hungary
- The Data Controller will inform the Data Subject of the action taken on the request within one month of receipt of the request. Where necessary, taking into account the complexity and number of the requests, that period may be extended by a further two months. The Data Controller will inform the Data Subject of any such extension within one month of receipt of the request, together with the reasons for the delay.
- Where the Data Subject submitted the request electronically, the information shall be provided by electronic means where possible, unless otherwise requested by the Data Subject.
- 7. DATA SECURITY
- The Data Controller implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
- the pseudonymisation and encryption of personal data;
- the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident;
- a process for regularly testing, assessing and evaluating the effectiveness of the technical and organisational measures put in place to ensure the security of the processing.
- The Data Controller ensures that any person acting under the authority of the Data Controller or of any data processor with access to personal data does not process them except on instructions from the Data Controller, unless required to do so by Union or Member State law.
- 7.1. 7.1. Handling of personal data breaches
- A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
- The Data Controller will notify the personal data breach to the Hungarian National Authority for Data Protection and Freedom of Information without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons.
- When a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Data Controller will inform the Data Subject of the breach without undue delay.
- 8. COOKIES
- The Webshop uses cookies in order to provide its services and to improve the user experience. A cookie is a small data packet sent by the web server to the browser, which the browser then sends back to the server with each request directed to it.
- 8.1. 8.1. Types of cookies
- 8.1.1. 8.1.1. Necessary cookies.
- These cookies are essential for the proper operation of the website. They make it possible to use the basic functions of the website, such as login or shopping cart functionality. These cookies may be placed without the consent of the Data Subject and cannot be disabled.
- 8.1.2. 8.1.2. Functional cookies.
- These cookies allow the website to remember the choices made by the user (such as user name, language or region). They provide a more personalised user experience.
- 8.1.3. 8.1.3. Statistical cookies.
- These cookies help us understand how visitors use the website. They collect information such as which pages are visited most often, or whether visitors encounter error messages. These cookies do not collect information that identifies the visitor; the information collected is aggregated and anonymous.
- The Webshop uses Google Analytics and the Meta (Facebook) pixel, both of which place cookies for statistical purposes.
- 8.1.4. 8.1.4. Marketing cookies.
- These cookies are used to track the visitor’s website usage habits in order to display relevant advertisements. The Webshop carries out personalised marketing activities, in the course of which it uses marketing cookies.
- 8.2. 8.2. Managing cookies
- Most browsers offer options for managing cookies, including the ability to accept, reject, or delete cookies. Detailed information about managing cookies can be found in the “help” section of each browser.
- On the first visit, the Webshop displays a pop-up cookie banner asking for the Data Subject’s consent to the use of non-essential cookies. The Data Subject may withdraw their consent at any time by changing their cookie settings.
- 9. SOCIAL MEDIA AND THIRD-PARTY SERVICES
- 9.1. 9.1. Social media plugins
- The Webshop contains social media buttons (Facebook, Instagram, TikTok) that enable content to be shared on these platforms. When using these features, the social media providers may place cookies that enable them to collect data.
- The Data Controller has no access to the data collected by the social media platforms and has no influence over how these data are processed. Information about the data processing practices of the social media platforms can be found in the privacy notices of the respective providers:
- – Facebook: https://www.facebook.com/privacy/explanation
- – Instagram: https://help.instagram.com/519522125107875
- – TikTok: https://www.tiktok.com/legal/privacy-policy
- 9.2. 9.2. Third-party service providers
- The Webshop uses third-party service providers to deliver certain functions (e.g. Google Analytics, Facebook Pixel). These providers may place their own cookies on the user’s device.
- The Data Controller endeavours to engage only third-party service providers that maintain appropriate data protection practices; however, the Data Controller does not assume responsibility for the data processing practices of such providers.
- 10. REMEDIES
- 10.1. 10.1. Complaint to the Data Controller
- The Data Subject may submit a complaint or remarks regarding the processing directly to the Data Controller using the following contact details:
- – E-mail: balazs.kata@karaand.com
- Postal address: 2366 Kakucs, Ipartelep utca 5., Hungary
- 10.2. 10.2. Complaint to the supervisory authority
- The Data Subject has the right to lodge a complaint with a supervisory authority if they consider that the processing of personal data concerning them infringes the GDPR. Such a complaint may be lodged with the supervisory authority of the Member State of the Data Subject’s habitual residence, place of work or place of the alleged infringement.
- In Hungary, the supervisory authority is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):
- Address: 1055 Budapest, Falk Miksa utca 9–11., Hungary
- Postal address: 1363 Budapest, Pf.: 9, Hungary
- Telephone: +36 1 391 1400
- E-mail: ugyfelszolgalat@naih.hu
- Website: https://naih.hu
- 10.3. 10.3. Judicial remedy
- In the event of a breach of their rights, the Data Subject may bring an action against the Data Controller before a court. The court will consider the case as a matter of priority. The case falls within the jurisdiction of the regional court (törvényszék). At the Data Subject’s choice, the action may also be brought before the regional court of the Data Subject’s place of residence or habitual stay.
- 10.4. 10.4. Damages and grievance award
- If, by way of unlawful processing of the Data Subject’s personal data or by breaching the requirements of data security, the Data Controller:
- causes damage to another person, it shall be obliged to compensate that damage;
- infringes the personality rights of the Data Subject, the Data Subject may claim a grievance award from the Data Controller.
- The Data Controller is exempt from liability if it proves that the damage or the infringement of the personality rights of the Data Subject was caused by an unavoidable event outside the scope of the data processing.
- 11. CLOSING PROVISIONS
- 11.1. 11.1. Amendments to this Notice
- The Data Controller reserves the right to amend this Notice. The Data Controller will publish a notice of any amendment on the Webshop. By using the Webshop after such amendment, the user accepts the modified Notice.
- 11.2. 11.2. Applicable laws
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, GDPR);
- Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Infotv.);
- Act V of 2013 on the Civil Code (Ptk.);
- Act CVIII of 2001 on Certain Issues Concerning Electronic Commerce Services and Information Society Services (Eker. tv.);
- Act CLV of 1997 on Consumer Protection (Fgytv.);
- Act C of 2000 on Accounting (Számv. tv.);
- Act XLVIII of 2008 on the Basic Conditions of and Certain Limitations on Commercial Advertising (Grt.).
- 11.3. 11.3. Entry into force
- This Privacy Notice is effective from 15 March 2025.
- Füstcsőmester Gyártó és Kereskedő Korlátolt Felelősségű Társaság Registered office: 2366 Kakucs, Ipartelep utca 5., Hungary Company registration number: 13-09-099649 Tax number: 13310945-2-13 E-mail: hello@karaand.com