Giveaway Rules
Table of Contents
- I. General Provisions
- II. Principles Relating to the Processing of Personal Data
- III. Identity of the Data Controller
- IV. Definitions
- V. Categories, Legal Basis, Purpose and Retention Period of Processed Personal Data
- VI. Data Processors
- VII. Cookies
- VIII. Google AdWords, Google Analytics and Facebook
- IX. Security of Data Processing
- X. Data Protection Officer
- XI. Rights of Data Subjects in Relation to Data Processing
- XII. Legal Remedies in Relation to Data Processing
Giveaway Rules
I. General Provisions
The purpose of this Privacy Policy is to ensure that Kabiri Kft. (hereinafter referred to as the “Data Controller”) processes personal data in all areas of its services in accordance with the provisions set out in this Privacy Policy. The Data Controller is committed to protecting the personal data of its users and customers and considers it particularly important to respect their right to informational self-determination.
The Data Controller treats personal data confidentially and implements all necessary security, technical and organizational measures to ensure the highest possible level of security for the personal data processed. The Data Controller protects personal data through appropriate measures against unauthorized access, alteration, transmission, disclosure, deletion or destruction, as well as against accidental destruction or damage.
In establishing these rules, the Data Controller has paid particular attention to the provisions of Act CXII of 2011 on Informational Self-Determination and Freedom of Information (hereinafter: the “Infotv.”), as well as Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”; hereinafter: the “General Data Protection Regulation”).
The scope of this Privacy Policy extends to all data processing activities of the Data Controller involving natural persons, in particular data processing activities carried out on its website: https://www.kabiricarpet.com/. This Privacy Policy shall enter into force on the date of its publication on the Data Controller’s website. The date of publication is 10 May 2019.
The Data Controller reserves the right to unilaterally amend this Privacy Policy without prior notice to users.
The Data Controller processes only the data provided by users or required by law for the purposes specified below. In the case of data processing based on the user’s voluntary consent, the user may withdraw their consent at any stage of the data processing. The scope of personal data processed must be proportionate to the purpose of the processing and may not exceed what is necessary for that purpose.
The Data Controller does not verify the personal data provided to it. The User is responsible for the accuracy and truthfulness of the data they provide. The Data Controller shall not be liable for any damage resulting from data that has been provided incorrectly or intentionally inaccurately, even if the incorrect nature of the data could have been recognized by the Data Controller.
Personal data may only be processed by employees of the Data Controller who are authorized to do so, in accordance with the provisions of this Privacy Policy. The Data Controller shall not disclose the personal data it processes to any third party other than the Data Processors specified in this Privacy Policy.
The Data Processors may act solely on the basis of their agreements with the Data Controller and the instructions received from the Data Controller. Data Processors may engage additional data processors only with the consent of the Data Controller.II. Principles Relating to the Processing of Personal Data
Personal data shall:
be processed lawfully, fairly and in a transparent manner in relation to the Data Subject (“lawfulness, fairness and transparency”);
be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, for scientific or historical research purposes or for statistical purposes in accordance with Article 89(1) shall not be considered incompatible with the original purposes (“purpose limitation”);
be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (“data minimization”);
be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (“accuracy”);
be kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as they are processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1), subject to the implementation of appropriate technical and organizational measures required by this Regulation in order to safeguard the rights and freedoms of the Data Subjects (“storage limitation”);
be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures (“integrity and confidentiality”).
The Data Controller shall be responsible for, and be able to demonstrate, compliance with the above principles (“accountability”).
III. Identity of the Data Controller
| Data Controller: | Kabiri Kft. |
| Registered Office / Postal Address: | 1122 Budapest, Krisztina körút 11. 1. em. 7., Hungary |
| Tax Number: | 12074578-2-43 |
| Company Registration Number: | 01 09 463512 |
| E-mail Address: | info@kabiricarpet.com |
| Telephone: | +36 1 212 4143 |
IV. Definitions
Personal Data: any information relating to an identified or identifiable natural person;
“any information relating to an identified or identifiable natural person (‘Data Subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person” [Article 4 of the General Data Protection Regulation].
Data Subject (User): any identified or identifiable natural person who can be identified, directly or indirectly, on the basis of personal data.
Consent of the Data Subject: the Data Subject’s voluntary, specific, informed and unambiguous consent to the processing of their personal data;
“any freely given, specific, informed and unambiguous indication of the Data Subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them” [Article 4 of the General Data Protection Regulation].
Processing: any operation performed on personal data, such as recording, categorization, modification, transmission or deletion;
“any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction” [Article 4 of the General Data Protection Regulation].
Data Controller: the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data. In relation to the services referred to in this Privacy Policy, the Data Controller is Kabiri Kft.
“the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the Data Controller or the specific criteria for its nomination may be provided for by Union or Member State law” [Article 4 of the General Data Protection Regulation].
Data Processor: “a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Data Controller” [Article 4 of the General Data Protection Regulation]; in relation to the services referred to in this Privacy Policy, Data Processors may include: Magyar Posta Zrt.
Personal Data Breach: an unexpected event during which personal data stored by the Data Controller may be damaged or destroyed, or accessed by unauthorized persons without authorization;
“a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed” [Article 4 of the General Data Protection Regulation].
Website: the website operated by the Data Controller at https://www.kabiricarpet.com/ and its subpages.
Service(s): the services operated and provided by the Data Controller that are available through the Website.
V. Categories, Legal Basis, Purpose and Retention Period of Processed Personal Data
- Personal Data Provided via the Contact Form
| Personal Data | Purpose of Data Processing |
| Name | Required for contacting the user, maintaining communication and identifying the user. |
| E-mail address | Required for contacting the user and maintaining communication. |
| Company name | Required for contacting the user, maintaining communication and identifying the user. |
| Telephone number | Required for contacting the user and maintaining communication. |
| Date and time of message submission | Performance of a technical operation. |
| Legal Basis for Data Processing | |
| The legal basis for processing personal data provided through the contact form is the voluntary consent of the Data Subject. | |
| Retention Period | |
| The data shall be processed until the Data Subject withdraws their consent or requests deletion, or until the Data Controller ceases its operations. | |
VI. Data Processors
- Hosting Provider / IT Service Provider
| Name of Data Processor: | TárhelyEu Szolgáltató Kft. |
| Registered Office: | 1144 Budapest, Ormánság utca 4. X. emelet 241., Hungary |
| Company Registration Number: | 01 09 909968 |
| Tax Number: | 23289903-2-43 |
| E-mail Address: | support@tarhely.eu |
| Telephone: | +36 1 789 2789 |
| Privacy Policy: | Available (https://tarhely.eu/dokumentumok/adatvedelmi_szabalyzat.pdf) |
| Services Provided by the Data Processor: | Web hosting, server services and domain services. |
| Categories of Data Processed: | The Data Subject’s network identity: the IP address of their computer and the software environment used by the Data Subject, as well as the date and time of their visit and the addresses of the pages viewed. |
| Categories of Data Subjects: | Natural persons visiting the website. |
| Purpose of Data Processing: | Ensuring the operation of the website. |
| Retention Period / Deadline for Deletion: | Data recorded by the server operated by the hosting provider are stored for 30 days. Thereafter, they are retained exclusively in anonymized form as website traffic statistics. |
| Legal Basis for Data Processing: | The consent of the Data Subject. |
VII. Cookies
For the purpose of providing a personalized service, the Data Controller and/or website operator places a small data package, known as a cookie, on the user’s computer with the consent of the user/Data Subject and reads it during subsequent visits. If the browser sends back a previously saved cookie, the service provider managing the cookie may link the user’s current visit to previous visits, but only with regard to its own content. Cookies therefore make the website easier to use by improving the user experience. As the data recorded by cookies cannot be linked to personal data, the Data Controller does not process personal data through the use of cookies. The processing of data serves exclusively statistical purposes.
The website operator may place and analyze cookies only if the visitor (Data Subject) gives their consent through the pop-up message displayed when the website is loaded, thereby authorizing such analysis. The legal basis for data processing is therefore the voluntary consent of the Data Subject.
The Data Controller’s system automatically records the following data after cookies have been accepted:
- IP address of the connected computer;
- Domain name;
- Date and time of the visit;
- Login details;
- HTTP response code;
- Pages visited;
- Individual page settings;
- Operating system and version;
- Browser and version;
- Screen resolution.
The following types of cookies may be distinguished:
The purpose of session / temporary cookies (session cookies) is to enable visitors to browse the Data Controller’s website fully and smoothly, use its functions and access the services available on the website. These cookies remain valid until the end of the session (browsing session). When the browser is closed, this type of cookie is automatically deleted from the computer or other device used for browsing.
Stored / persistent cookies are cookies that are used each time the user visits the website. Persistent cookies used for analytical purposes show which parts of the website the user has visited, which pages and products they have viewed, and what actions they have taken. Depending on the cookie’s lifespan, they remain on the user’s device for the specified period. Such cookies may be used by services such as Google Analytics. These cookies do not contain personal data and cannot be used to identify the visitor.
The user can delete cookies from their own computer or disable the use of cookies in their browser. Cookie settings are generally available under the Privacy settings in the Tools/Settings menu of browsers, under the terms “cookie” or “cookies”.
By disabling the use of cookies, the user acknowledges that without cookies, the functionality of the website may not be complete. If the user consents to the placement of cookies and does not subsequently delete them, the cookies will be automatically deleted after 180 days.
VIII. Google AdWords, Google analytics and Facebook
These cookies remain on the visitor’s computer or other device used for browsing, in the browser, until they expire or until the visitor deletes them. The cookies created by Google Analytics have a retention period of 30 days.
The User can prevent the storage of cookies by configuring their browser accordingly. However, in this case, some or all functions of the website may not be fully available. The User can prevent Google from collecting and processing data relating to their use of the website through cookies, including their IP address, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=en
The Data Controller runs so-called remarketing advertisements through the advertising systems of Facebook and Google AdWords. These service providers may collect or receive data from the Data Controller’s website and other websites through the use of cookies, web beacons and similar technologies. Using this data, they provide measurement services and enable targeted advertising. Such targeted advertisements may appear on other websites within the Facebook and Google partner networks. Remarketing lists do not contain visitors’ personal data and cannot be used to identify individual visitors.
The Data Controller uses cookies to display personalized advertisements to potential users through Google and Facebook.Further information about Google’s and Facebook’s privacy policies is available at the following links: Google: https://policies.google.com/privacy Facebook: https://www.facebook.com/about/privacy/
IX. Security of Data Processing
The Data Controller and the Data Processor shall, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, as well as the risk of varying likelihood and severity to the rights and freedoms of natural persons, implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including, where appropriate:
- the encryption of personal data;
- the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident;
- a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures in order to ensure the security of processing.
Notification of the Data Subject of a Personal Data Breach:
- If the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Data Controller shall notify the Data Subject of the personal data breach without undue delay.
- The information provided to the Data Subject shall describe the nature of the personal data breach in clear and plain language and shall include the name and contact details of the Data Protection Officer or other contact point where further information can be obtained. It shall also describe the likely consequences of the personal data breach and the measures taken or proposed by the Data Controller to address the breach, including, where appropriate, measures to mitigate its possible adverse effects.
The Data Subject does not need to be notified if any of the following conditions is met:
- the Data Controller has implemented appropriate technical and organizational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular measures such as encryption that render the personal data unintelligible to persons who are not authorized to access it;
- the Data Controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of the Data Subjects is no longer likely to materialize;
- notification would involve disproportionate effort. In such cases, the Data Subjects shall instead be informed by means of publicly available information or through a similar measure that ensures equally effective notification of the Data Subjects.
If the Data Controller has not yet notified the Data Subject of the personal data breach, the supervisory authority, having assessed whether the personal data breach is likely to result in a high risk, may require the Data Controller to inform the Data Subject.
X. Data Protection Officer
No Data Protection Officer has been appointed. The Data Controller is not a public authority or public body, its activities do not involve processing operations that require regular and systematic large-scale monitoring of users, and the Data Controller does not process special categories of personal data or personal data relating to criminal convictions and offences. Therefore, the Data Controller is not required to appoint a Data Protection Officer.
XI. Rights of Data Subjects in Relation to Data Processing
The Data Subject may request confirmation as to whether their personal data are being processed and, if so, may request information about which personal data the Data Controller processes, the legal basis and purpose of the processing, the source of the data, and the period for which the data are processed. Upon receiving such a request, the Data Controller shall provide the requested information without undue delay and, in any event, no later than 30 (thirty) days after receipt of the request, by e-mail to the address provided or, at the Data Subject’s request, by post to the specified mailing address. The Data Controller shall provide the information in a concise, transparent, intelligible and easily accessible form, using clear and plain language.
Right to Rectification
The Data Subject may request the Data Controller to correct or modify any personal data concerning them, or to complete incomplete personal data. The Data Controller shall take action on such a request without undue delay and, in any event, no later than 30 (thirty) days after receipt of the request. The Data Controller shall notify the Data Subject of the completion of the correction or modification by e-mail to the address provided or, at the Data Subject’s request, by post to the specified mailing address.
Right to Erasure
The Data Subject may request the erasure of personal data concerning them. Where the Data Subject withdraws their consent in relation to personal data processed on the basis of consent, the relevant personal data shall be erased. The Data Controller shall take action to erase the data without undue delay and, in any event, no later than 30 (thirty) days after receipt of the request. The Data Controller shall notify the Data Subject that the personal data have been erased by e-mail to the address provided or, at the Data Subject’s request, by post to the specified mailing address.
The Data Subject’s personal data shall also be erased if their processing is unlawful, if the purpose of the processing has ceased to exist, if the data are incomplete or inaccurate and the situation cannot be lawfully remedied, provided that erasure is not prohibited by law, or if the statutory retention period for the personal data has expired, or if erasure has been ordered by a court or the data protection authority.
Right to Restriction of Processing
The Data Subject may request that the Data Controller restrict the processing of their personal data if any of the following conditions applies:- the Data Subject contests the accuracy of the personal data, in which case the restriction shall apply for the period necessary to enable the Data Controller to verify the accuracy of the personal data;
- the processing is unlawful and the Data Subject opposes the erasure of the personal data and requests the restriction of their use instead;
- the Data Controller no longer needs the personal data for the purposes of processing, but the Data Subject requires them for the establishment, exercise or defence of legal claims;
- the Data Subject has objected to the processing, in which case the restriction shall apply for the period necessary to determine whether the legitimate grounds of the Data Controller override those of the Data Subject.
Right to Data Portability>
The Data Subject has the right to receive the personal data concerning them, which they have provided to the Data Controller, in a structured, commonly used and machine-readable format and to transmit those data to another Data Controller.
Right to Object
The Data Subject has the right to object to the processing of their personal data. The Data Controller shall examine the objection as soon as possible and, in any event, no later than 15 (fifteen) days from the submission of the request, and shall decide whether the objection is justified. The Data Controller shall notify the person who submitted the request of its decision by e-mail to the address provided or, at the Data Subject’s request, by post to the specified mailing address.XII. Legal Remedies in Relation to Data Processing
In the event of a violation of their rights, the Data Subject may bring legal proceedings against the Data Controller or in relation to its activities. The court shall handle the case as a matter of priority. The lawsuit falls within the jurisdiction of the regional court. The court shall proceed without undue delay. The court having jurisdiction over the lawsuit is the court of the Data Controller’s registered office; however, at the Data Subject’s choice, the proceedings may also be initiated before the regional court having jurisdiction over the Data Subject’s place of residence or habitual residence
The Data Subject may lodge a complaint against the Data Controller or in relation to the processing of their personal data with the Hungarian National Authority for Data Protection and Freedom of Information. The Authority’s contact details are as follows:
Hungarian National Authority for Data Protection and Freedom of Information
Registered Office: 1125 Budapest, Szilágyi Erzsébet fasor 22/C., Hungary
Postal Address: 1530 Budapest, P.O. Box 5, Hungary
E-mail: ugyfelszolgalat@naih.hu
Website: http://www.naih.hu
Telephone: +36 (1) 391-1400
Fax: +36 (1) 391-1410