Refund and Return Policy
Table of Contents
- I. General Provisions
- II. Principles Governing the Processing of Personal Data
- III. Identity of the Data Controller
- IV. Definitions
- V. Scope, Legal Basis, Purpose and Duration of Personal Data Processing
- VI. Data Processors
- VII. Cookies
- VIII. Google AdWords, Google Analytics, Facebook
- IX. Security of Data Processing
- X. Data Protection Officer
- XI. Rights of Data Subjects in Relation to Data Processing
- XII. Remedies and Legal Enforcement Options Related to Data Processing
Refund and Return Policy
I. General Provisions
The purpose of this policy is to ensure that Kabiri Kft. (hereinafter referred to as the “Data Controller”) processes personal data in all areas of the services it provides in accordance with the provisions set out in this policy. The Data Controller is committed to protecting the personal data of its users and customers and considers it particularly important to respect the right of its customers to informational self-determination.. The Data Controller treats personal data confidentially and takes all necessary security, technical and organisational measures to ensure the highest possible level of security for the personal data it processes. The Data Controller protects personal data through appropriate measures against unauthorised access, alteration, transmission, disclosure, deletion or destruction, as well as against accidental destruction or damage.. When establishing these rules, the Data Controller has paid particular attention to the provisions of Act CXII of 2011 on Informational Self-Determination and Freedom of Information.(hereinafter referred to as the “Hungarian Data Protection Act”), as well as Regulation (EU) 2016/679 of the European Parliament and of the Council (the “GDPR”, hereinafter referred to as the “General Data Protection Regulation”).. This policy applies to all data processing activities of the Data Controller involving natural persons, with particular regard to data processing activities carried out through its website: [https://www.kabiricarpet.com/] This policy shall enter into force on the date of its publication on the Data Controller’s website. The date of publication is 10 May 2019. The Data Controller reserves the right to unilaterally amend this policy without prior notice to users.. The Data Controller processes only the personal data provided by users or required by law, and only for the purposes specified below. Where data processing is based on the user’s voluntary consent, the user may withdraw such consent at any stage of the data processing. The scope of the personal data processed must be proportionate to the purpose of the processing and may not exceed what is necessary for that purpose.. The Data Controller does not verify the personal data provided to it. The user is responsible for the data provided, including its accuracy and authenticity. The Data Controller shall not be liable for any damage resulting from inaccurate or intentionally false information provided by the user, even if the Data Controller could have recognised the inaccurate nature of such information.. Personal data may only be processed by employees of the Data Controller who are duly authorised to do so and in accordance with the provisions of this policy. The Data Controller shall not disclose or transfer the personal data it processes to any third party other than the **Data Processors** specified in this policy.. The Data Processors may act solely on the basis of their agreements with the Data Controller and the instructions received from the Data Controller. Data Processors may only engage additional data processors with the consent of the Data Controller..
II. Principles Governing the Processing of Personal Data
Personal data shall: 1. be processed lawfully, fairly and in a transparent manner in relation to the data subject (“lawfulness, fairness and transparency”); 2. be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes shall not be considered incompatible with the original purposes in accordance with Article 89(1) (“purpose limitation”); 3. be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (“data minimisation”); 4. be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data which are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (“accuracy”); 5. be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods where the personal data are processed for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes in accordance with Article 89(1), subject to the implementation of appropriate technical and organisational measures required by the GDPR to safeguard the rights and freedoms of data subjects (“storage limitation”); 6. be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (“integrity and confidentiality”). The Data Controller shall be responsible for, and shall be able to demonstrate, compliance with the principles set out above (“accountability”).
III. Identity of the Data Controller
| Name of the Data Controller: | Kabiri Kft. |
| Registered Office / Mailing Address: | 1122 Budapest, Krisztina körút 11. 1. floor. 7. |
| Tax Number: | 12074578-2-43 |
| Company Registration Number: | 01 09 463512 |
| Email Address: | info@kabiricarpet.com |
| Telephone Number: | +36 1 212 4143 |
IV. Definitions
Personal Data: any information relating to an identified or identifiable natural person;
“any information relating to an identified or identifiable natural person (the ‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person” [Article 4 of the General Data Protection Regulation].
Data Subject (User): any identified or identifiable natural person whose personal data are processed by the Data Controller.
Consent of the Data Subject: the data subject’s freely given, specific, informed and unambiguous consent to the processing of their personal data;
“any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them” [Article 4 of the General Data Protection Regulation].
Processing: any operation or set of operations which is performed on personal data, whether by automated or non-automated means, such as recording, categorising, modifying, transmitting or deleting;
“any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction” [Article 4 of the General Data Protection Regulation].
Data Controller: the natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of personal data. With regard to the services referred to in this Privacy Policy, the Data Controller is Green Solartech Kft.;
“the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law” [Article 4 of the General Data Protection Regulation].
Data Processor: “a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Data Controller” [Article 4 of the General Data Protection Regulation]. In connection with the services referred to in this Privacy Policy, the Data Processors may include Magyar Posta Zrt.;
Personal Data Breach: an unexpected event as a result of which personal data stored by the Data Controller may be damaged or destroyed, or accessed unlawfully by unauthorised persons;
“a breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed” [Article 4 of the General Data Protection Regulation].
Website: the website operated by the Data Controller at https://www.kabiricarpet.com/, including all subpages of the website.
Service(s): the services operated and provided by the Data Controller and made available through the Website.
V. Scope, Legal Basis, Purpose and Duration of Personal Data Processing
- Personal Data Provided via the Contact Form
| Personal Data | Purpose of Data Processing |
| Name | Required for contacting and communicating with the user, as well as for user identification. |
| E-mail address | Required for contacting and communicating with the user. |
| Company name | Required for contacting and communicating with the user, as well as for user identification. |
| Telephone number | Required for contacting and communicating with the user. |
| Time of message submission | Performance of a technical operation. |
| Legal Basis for Data Processing | |
| The legal basis for processing the personal data provided via the contact form is the voluntary consent of the data subject. | |
| Duration of Data Processing | |
| The data will be processed until the data subject withdraws their consent or requests the deletion of their data, or until the Data Controller ceases its operations. | |
VI. Data Processors
- Web Hosting Provider / IT Service Provider
| Name of Data Processor: | TárhelyEu Szolgáltató Kft. | |
| Registered office: | 1144 Budapest, Ormánság utca 4, 10th floor, Apt. 241. | |
| Company registration number: | 01 09 909968 | |
| Tax number: | 23289903-2-43 | |
| E-mail address: | support@tarhely.eu | |
| Telephone: |
|
|
| Privacy Policy: | Available (https://tarhely.eu/dokumentumok/adatvedelmi_szabalyzat.pdf) | |
| Activities performed by the Data Processor: | Web hosting, server services, and domain services. | |
| Scope of data processed by the Data Processor: | The data subject’s network identity: the IP address of their computer and the software environment used by the data subject, as well as the time of their visit and the addresses of the pages viewed. | |
| Categories of data subjects: | Natural persons visiting the website. | |
| Purpose of data processing: | Ensuring the operation of the website. | |
| Duration of data processing, deadline for deletion of data: |
Data recorded by the server operated by the hosting provider are stored for 30 days, after which they are retained only in anonymized form as website traffic statistics. | |
| Legal basis for data processing: | The consent of the data subject. |
VII. Cookies
For the purpose of providing a personalized service, the Data Controller and/or website operator places a small data package, known as a cookie, on the user’s computer with the consent of the user/data subject and reads it during subsequent visits. If the browser sends back a previously saved cookie, the service provider managing the cookie may link the user’s current visit to previous visits, but only with regard to its own content. Cookies therefore make the website easier to use by improving the user experience. As the data recorded by cookies cannot be linked to personal data, the Data Controller does not process personal data through the use of cookies. The processing of data serves exclusively statistical purposes.
The website operator may place and analyze cookies only if the visitor (data subject) gives their consent through the pop-up message displayed when the website is loaded, thereby authorizing such analysis. The legal basis for data processing is therefore the voluntary consent of the data subject.
After the cookies have been accepted, the Data Controller’s system automatically records the following data:
– IP address of the connected computer
– Domain name
– Date and time of the visit
– Login details
– HTTP response code
– Pages visited
– Individual page settings
– Operating system and version
– Browser and version
– Screen resolution
The following types of cookies may be distinguished:
Session / temporary cookies (session cookies) are intended to enable visitors to browse the Data Controller’s website fully and smoothly, use its functions, and access the services available on the website. These cookies remain valid until the end of the session (browsing session). When the browser is closed, this type of cookie is automatically deleted from the computer or other device used for browsing.
Stored / persistent cookies are cookies that are used each time the user visits the website. Persistent cookies used for analytical purposes show which parts of the website the user has visited, which pages and products they have viewed, and what actions they have taken. Depending on the cookie’s lifespan, it remains on the client device for the specified period. Such cookies may be used by services such as Google Analytics. These cookies do not contain personal data and cannot be used to identify the visitor.
The user can delete cookies from their own computer or disable the use of cookies in their browser. Cookie settings are generally available under the Privacy settings in the Tools/Settings menu of browsers, under the terms “cookie” or “cookies”. By disabling the use of cookies, the user acknowledges that without cookies, the functionality of the website may not be complete. If the user consents to the placement of cookies and does not subsequently delete them, the cookies will be automatically deleted after 180 days.
VIII. Google AdWords, Google Analytics and Facebook
The User may prevent cookies from being stored by appropriately configuring their browser. However, in this case, some or all of the website’s functions may not be fully available. The User may prevent Google from collecting and processing data related to their use of the website through cookies, including their IP address, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=hu
The Data Controller uses so-called remarketing advertisements through the Facebook and Google AdWords advertising systems. These service providers may collect or receive data from the Data Controller’s website and other websites using cookies, web beacons and similar technologies. Using this data, they provide measurement services and target advertisements. These targeted advertisements may appear on other websites belonging to the Facebook and Google partner networks. Remarketing lists do not contain visitors’ personal data and cannot be used to identify individuals.
The Data Controller uses cookies to display personalized advertisements to potential users through Google and Facebook.
Further information about Google’s and Facebook’s privacy policies is available at the following links: https://policies.google.com/privacy and https://www.facebook.com/about/privacy/
IX. Security of Data Processing
The Data Controller and the Data Processor shall implement appropriate technical and organizational measures, taking into account the state of the art and the costs of implementation, as well as the nature, scope, circumstances and purposes of the processing and the risk of varying likelihood and severity to the rights and freedoms of natural persons, in order to ensure a level of data security appropriate to the degree of risk, including, where appropriate:
- encryption of personal data;
- the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
- the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident;
- a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures in order to ensure the security of processing.
Information to the Data Subject about a Personal Data Breach:
- If the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Data Controller shall inform the Data Subject of the personal data breach without undue delay.
- The information provided to the Data Subject shall describe the nature of the personal data breach in clear and plain language and shall include the name and contact details of the Data Protection Officer or other contact point from which further information can be obtained; it shall describe the likely consequences of the personal data breach; and it shall describe the measures taken or proposed by the Data Controller to address the personal data breach, including, where appropriate, measures to mitigate any possible adverse effects resulting from the breach.
The Data Subject does not need to be informed if any of the following conditions are met:
- the Data Controller has implemented appropriate technical and organizational protective measures, and those measures were applied to the data affected by the personal data breach, in particular measures such as encryption that render the personal data unintelligible to persons who are not authorized to access it;
- the Data Controller has taken subsequent measures following the personal data breach which ensure that the high risk to the rights and freedoms of the Data Subject is no longer likely to materialize;
- providing the information would require disproportionate effort. In such cases, the Data Subjects shall be informed by means of publicly available information or by taking a similar measure that ensures equally effective notification of the Data Subjects.
If the Data Controller has not yet informed the Data Subject of the personal data breach, the supervisory authority may, after assessing whether the personal data breach is likely to result in a high risk, order the Data Controller to inform the Data Subject.
X. Data Protection Officer
No Data Protection Officer has been appointed. The Data Controller does not qualify as a public authority or public body, and its activities do not involve any processing operation that requires the regular and systematic monitoring of users on a large scale. Furthermore, the Data Controller does not process special categories of personal data or personal data relating to criminal convictions and offences. Therefore, the Data Controller is not required to appoint a Data Protection Officer.
XI. Rights of Data Subjects in Relation to Data Processing
Right of Access
The Data Subject may request information as to whether their personal data is being processed and, if so, which personal data the Data Controller processes, on what legal basis, for what purpose, from what source, and for how long. In response to the request, the Data Controller shall provide the information without undue delay, but no later than within 30 (thirty) days, to the e-mail address provided or, at the request of the Data Subject, to the specified postal address. The Data Controller shall provide the information in a concise, transparent, intelligible and easily accessible form, using clear and plain language.
Right to Rectification
The Data Subject may request the Data Controller to correct or modify any of their personal data or to complete incomplete data. The Data Controller shall take action on such a request without undue delay, but no later than within 30 (thirty) days, and shall notify the Data Subject of the modification of the data at the e-mail address provided or, at the request of the Data Subject, at the specified postal address.
Right to Erasure
The Data Subject may request the deletion of their personal data. If the Data Subject withdraws their consent with regard to data processed on the legal basis of consent, the relevant personal data will be deleted. The Data Controller shall arrange for the deletion of the data without undue delay, but no later than within 30 (thirty) days, and shall notify the Data Subject of the deletion at the e-mail address provided or, at the request of the Data Subject, at the specified postal address.
The Data Subject’s personal data will also be deleted if their processing is unlawful, if the purpose of the processing has ceased to exist, if the data are incomplete or inaccurate and cannot be lawfully corrected, provided that the deletion is not prohibited by law, or if the statutory retention period for the personal data has expired, or if deletion has been ordered by a court or the Data Protection Commissioner.
Right to Restriction of Processing
The Data Subject may request the restriction of the processing of their personal data if any of the following conditions applies:
- the Data Subject contests the accuracy of the personal data; in this case, the restriction shall apply for the period necessary to enable the Data Controller to verify the accuracy of the personal data;
- the processing is unlawful and the Data Subject opposes the erasure of the personal data and instead requests the restriction of their use;
- the Data Controller no longer needs the personal data for the purposes of processing, but the Data Subject requires the data for the establishment, exercise or defence of legal claims;
- the Data Subject has objected to the processing; in this case, the restriction shall apply for the period necessary to determine whether the legitimate grounds of the Data Controller override those of the Data Subject.
Right to Data Portability
The Data Subject has the right to receive the personal data concerning them, which they have provided to the Data Controller, in a structured, commonly used and machine-readable format and to transmit those data to another Data Controller.
Right to Object
The Data Subject has the right to object to the processing of their personal data. The Data Controller shall examine the objection as soon as possible after the request has been submitted, but no later than within 15 (fifteen) days, and shall make a decision on whether the objection is justified. The Data Controller shall notify the person who submitted the request of its decision at the e-mail address provided or, at the request of the Data Subject, at the specified postal address.
XII. Remedies and Legal Enforcement Options Related to Data Processing
In the event of a violation of their rights, the Data Subject may bring proceedings before a court against the Data Controller or in connection with its activities. The court shall deal with the case as a matter of priority. The proceedings fall within the jurisdiction of the regional court. The court having jurisdiction is the court competent at the registered seat of the Data Controller; however, at the Data Subject’s discretion, the proceedings may also be initiated before the regional court having jurisdiction over the Data Subject’s place of residence or stay.
The Data Subject may also lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) against the Data Controller or in relation to the processing of their personal data. The contact details of the Authority are as follows:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Registered office: 1125 Budapest, Szilágyi Erzsébet fasor 22/C.
Postal address: 1530 Budapest, P.O. Box 5.
E-mail: ugyfelszolgalat@naih.hu
Website: http://www.naih.hu
Telephone: +36 (1) 391-1400
Fax: +36 (1) 391-1410