Privacy policy
PRIVACY POLICY
This Privacy Policy defines the data processing of **Cell-Vitál Limited Liability Company **as a controller - hereinafter: Controller - and the www.cellvital.hu website operated by it, as well as the procedure for using the records and databases kept.
-
Data of the Data Controller
Cell-Vitál Limited Liability Company
registered office: 8143 Sárszentmihály, Kossuth utca 56.
Company registration number: Cg. 07-09-030071
Registering authority: Company Court of Székesfehérvár Court
Tax number: 26755085-2-07
Email: cellvital@cellvital.hu
contact: Doma Róbert
Phone number: 06-70-426-9818
Postal address/complaint handling: 8143 Sárszentmihály, Kossuth utca 56.
Website: https://cellvital.hu
II. Processing of personal data
The data controller performs the data processing of the www.cellvital.hu web store based on the voluntary consent of the Data Subjects or on the basis of legal authorization.
We inform the Data Subject clearly and in detail about all the facts related to the management of his data, including in particular the purpose and legal basis of data processing, the person entitled to data processing and data processing, the duration of data processing, and who can see the data.In the case of voluntary consent, you can request information on the scope of personal data handled and how they are used at any time. In the case of voluntary consent, you can withdraw your consent, except in cases where data processing continues based on a legal obligation. In such cases, we provide information on the further processing of the data.
In case of registration, purchase or use of the services in the online store, you must provide your own data, if you do not provide your own personal data, you must obtain the Data Subject's consent.
The www.cellvital.hu online store and Controller do not perform profiling.
III. Data processing by a data controller
1. Management of data provided during contact
Processing of personal data provided in email and provided via the www.cellvital.hu website on the contact form, email or telephone
Scope of processed personal data: name, email address, phone number, message content
We inform you that: - if you contact us, you hereby give your consent to the processing of your personal data and message provided during the contact in accordance with the provisions of this data processing information.
-
The withdrawal of your consent to data processing does not affect the existence of legal data processing prior to the withdrawal.
-
You can withdraw your consent to data processing at any time.
-
You can request access to your personal data, their correction, deletion, or restriction of the processing of your data.
-
The content of the message contains information freely formulated by the Data Subject. Therefore, if possible, the Data Subject should provide only such personal data in the message as is necessary to respond to his inquiry or to manage the given case.
Related persons: persons sending messages via e-mail and website
Purpose of data processing:
Receiving and responding to inquiries from the Data Subject, maintaining contact with the Data Subject, answering questions related to the use of the application or the service used, handling possible error reports, comments and other inquiries.If the request is related to an existing contractual relationship, subscription or service provided by the Data Controller, the purpose of data processing is also to provide the administration of the given service and the communication necessary to fulfill the contract.
Legal basis for data processing:
Article 6 (1) GDPR a.) "The data subject has given his consent to the processing of his personal data for one or more specific purposes." The Data Subject may withdraw his consent at any time. Withdrawal of consent does not affect the legality of data processing carried out on the basis of consent prior to the withdrawal.
Article 6 (1) GDPR b) "data processing is necessary for the performance of a contract in which the data subject is one of the parties, or it is necessary for taking steps at the request of the data subject prior to the conclusion of the contract."
Duration of data processing: 1 month or until the deletion request of the data subject (GDPR Article 17 para. 1)
Method of data processing: in electronic form
2. Management of data provided during ORDER/PURCHASE
Scope of processed personal data:
Surname, first name, address (country, postal code, street, house number) telephone number, email address, billing address, delivery address (country, postal code, street, house number)
Scope of persons concerned: contacts of private individuals and business companies that enter into a contract with the Data Controller
**Purpose of data processing:**Identification of the contractual partner, conclusion of a contract, fulfillment of contractual obligations, fulfillment of invoicing obligations, retrievability and verification of data in case of possible legal disputes or claims.
Accordingly, the primary purpose of data processing is to manage the service order, create and fulfill the contract, ensure the user's right to use the service, and fulfill the obligations related to the contract.
After the fulfillment of the contract, the Data Controller may also process the data for the purpose of handling possible contractual claims, in the event of a legal dispute, to verify the creation and fulfillment of the contract, and to enforce the rights of the Data Controller or the Data Subject.
Legal basis for data processing:
a) Article 6 (1) point b) GDPR, according to which "data processing is necessary for the performance of a contract in which the data subject is one of the parties, or it is necessary for taking steps at the request of the data subject prior to the conclusion of the contract; ".
b) After the contract has been fulfilled, the legal basis for data processing is Article 6 (f) of the GDPR, according to which: "data processing is necessary to enforce the legitimate interests of the data controller or a third party"
**Duration of data processing:**The controller stores the above-mentioned data for a period of 5 years + 1 year from the date of performance of the contract or failure of performance (until the statute of limitations for claims arising from the contract).
The purpose of determining the data retention period is to ensure that the Data Controller can retrieve and use the data necessary to enforce any contractual or other legal claims, or to defend against such claims, during the period open for claim enforcement.
After the data retention period has expired, the Data Controller deletes the personal data, unless their further retention is required by law, or the further processing of the data is necessary for the purpose of presenting, validating or defending an ongoing legal process or a legal claim that has already been initiated.
3. BILLING data processing
Scope of processed personal data:
In order to fulfill the obligations contained in Act C of 2000 on accounting, you will issue an invoice in which you will include the following personal data: name, address, tax number or tax identification number.
Purpose of data processing:
Fulfilling the obligations contained in Act C of 2000 on accounting.
Legal basis for data processing:
Article 6 (1) point c) GDPR, according to which: "data processing is necessary to fulfill a legal obligation"
Duration of data processing: 8 years.In order to fulfill accounting obligations, based on § 169 of Act C of 2000
"Accounting documents directly and indirectly supporting the bookkeeping (including ledger accounts, analytical and detailed records) must be kept in legible form for at least 8 years, in a way that can be retrieved by reference to the accounting records"
Method of data processing: in electronic form
The Data Controller transfers the Data Subject's data to a third party in the following cases:
a.) to NAV based on legal obligation.
b.) The transfer of data is necessary in order to fulfill the legal obligation of the Data Controller Article 6 (1) point c) of the GDPR
d.) As part of the fulfillment of the contractual obligation and invoicing, the Data Controller forwards the personal data provided by the Data Subject as part of the conclusion of the contract to the accountant,
4. www.cellvital.hu website hosting provider:
Name: Shopify International Limited
Registered Office: 2nd Floor, Victoria Buildings, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland
Company registration number / Registration number: 560279
Contact (E-mail): assistance@shopify.com or privacy@shopify.com
Website: www.shopify.com
Scope of processed data: All personal data provided by the data subject.
Scope of stakeholders: All stakeholders who use the website.
Purpose of data processing: Making the website available and operating it properly.Duration of data processing, deadline for data deletion:
Data processing lasts until the termination of the agreement between the data controller and the storage provider, or until the deletion request addressed to the storage provider by the data subject.
Legal basis for data processing:
the consent of the User is Article 6 (1) point a) of the GDPR and CVIII of 2001 on certain issues of electronic commerce services and services related to the information society. Act 13/A. (3) of §
5. Using the Shopify platform
The Data Controller uses Shopify's e-commerce platform to operate the online store. When using Shopify's services, the personal data of visitors and customers of the online store may also be processed through Shopify's system.
Detailed information on data processing by Shopify, the purpose and legal basis of data processing, the scope and duration of data processed, as well as the rights of data subjects can be found in Shopify's data protection information in force at all times:
Shopify Consumer Privacy Policy:
https://www.shopify.com/legal/privacy/consumers
6. Management of newsletter and marketing offer data
Scope of processed personal data: name, email address
Related persons: persons sending messages via e-mail and website
**Purpose of data processing:**Sending newsletters, informing the Data Subject about the Data Controller's products, business offers, promotions, current news and events, as well as sending and maintaining contact with electronic messages containing economic advertising and direct marketing inquiries.
Legal basis for data processing:
Article 6 (1) GDPR a.) "The data subject has given his consent to the processing of his personal data for one or more specific purposes." The Data Subject may withdraw his consent at any time. Withdrawal of consent does not affect the legality of data processing carried out on the basis of consent prior to the withdrawal.
CVIII of 2001 on the sending of electronic messages containing commercial advertising, especially on certain issues of electronic commercial services and services related to the information society. Act, as well as XLVIII of 2008 on the basic conditions and certain limitations of economic advertising activity. the provisions of the Act shall apply.
Duration of data processing: Until the Data Subject's consent is revoked.
The Data Subject may withdraw his consent to the sending of the newsletter and the related data processing at any time, without limitation or justification, free of charge, or may unsubscribe from the newsletter at any time.
Withdrawal of consent does not affect the legality of data processing based on consent prior to its withdrawal. Method of data processing: in electronic form
7. Publication of customer opinion, reference and opinion, recommendation
The Customer can give feedback in various forms, according to his choice, about his experiences, opinions and recommendations related to the Data Controller's products, the purchase, and the Data Controller's service.
Processed personal data:
In particular, the customer opinion can be published in the following ways:
-
publication of a text opinion written by the Buyer;
-
publication of the written opinion with the name or first name of the Buyer;
-
publication of the Buyer's photograph in connection with the opinion;
-
joint publication of a photograph and text opinion of the Buyer;
-
publication of a video, video message or video customer review created by or with the Customer's participation;
-
publication of the above on the website/webstore of the Data Controller;
-
publication of the above on the Data Controller's Facebook page and other social media platforms.
**Purpose of data processing:**Presenting and publicizing the Data Controller's products, services and activities, making customers' experiences and opinions known, and promoting the Data Controller's products and services by publishing textual, photographic and/or video opinions and recommendations given by the Customer on the Data Controller's website, online store and social media platforms.
Legal basis for data processing:
Article 6 (1) GDPR a.) "The data subject has given his consent to the processing of his personal data for one or more specific purposes." The Data Subject may withdraw his consent at any time. Withdrawal of consent does not affect the legality of data processing carried out on the basis of consent prior to the withdrawal.
The Data Subject declares the use of his personal data in the declaration of consent.
Duration of data processing: Until the Data Subject's consent is revoked.
The Data Subject may withdraw his consent to the sending of the newsletter and the related data processing at any time, without limitation or justification, free of charge, or may unsubscribe from the newsletter at any time.
Withdrawal of consent does not affect the legality of data processing based on consent prior to its withdrawal.
Method of data processing: in electronic form
8. Processing of personal data sent via a social siteThe data controller has a Facebook page with the address: Cell-Vitál
social media contact: https://www.facebook.com/profile.php?id=61573615770369&locale=hu_HU
Facebook's privacy policy is available here: https://www.facebook.com/privacy/explanation
Scope of processed personal data: Name registered on the social media site, or the user's public profile picture, name, e-mail address, phone number and the content of the message
Scope of affected persons: Affected persons who registered on social media sites and liked the Data Controller's social media page, made contact, sent messages, and commented there.
Purpose of data processing: Informing the Data Subjects about the Data Controller's activities
Sharing certain content elements of the www.cellvital.hu website or the website itself on social networks
Legal basis for data processing: GDPR Article 6 (1) point a) "the data subject has given his consent to the processing of his personal data for one or more specific purposes"
You can find out about the source of the data, its management, the method of transfer and its legal basis on the social page. Data processing takes place on the social media site, so the duration and method of data processing, as well as the options for deleting and modifying data, are governed by the regulations of the given social media site.
The data controller publishes the contact information found on the website of this data processing information sheet on its Facebook page and other social media pages.The rules of the given social media site govern the duration of data processing, deletion deadlines, and access to data, so Data Subjects can find out about the relevant data processing on the social media site.
9. Data processing related to the application of Google Ads
Its auditing is supported by the Google Analytics server as an external service provider. The data controller can provide detailed information on the management of measurement data at the address https://marketingplatform.google.com/about/analytics/. The online customer service chat server is operated by PromptSaaS Inc., (K7M 2J8 Ontario, Kingston, 48 Baiden Street, Canada). You can find out about the company's data processing on its website at [http://ugyfelchat.hu/](http://ugyfelchat.hu/].
In order to provide customized service, external service providers store a small data package on the user's computer, so-called cookies are placed and read back. If the browser returns a previously saved cookie, the service provider managing it has the opportunity to connect the user's current visit with previous ones, but only with regard to its own content.
The information created with cookies is usually sent to and stored on a Google server in the USA. By activating IP anonymization on the website, Google shortens the User's IP address within the member states of the European Union. The full IP address will only be transmitted to the Google server in exceptional cases. The user can delete the storage of cookies from his computer or disable the use of cookies in his browser. Cookies can usually be managed in the Tools/Settings menu of browsers under the Data Protection settings, under the name cookie or cookie.
The user can prevent Google from collecting and processing data related to website usage registered by cookies by downloading and installing the plugin available at the https://tools.google.com/dlpage/gaoptout?hl=hu link.
10. Management of cookies
they can serve the proper functioning of the www.cellvital.hu website, the identification of visitors and sessions, the preservation of the provided data and user settings, and the more convenient and efficient use of the website. Some cookies are essential for the proper functioning of the site (session cookie), others are used to facilitate the more convenient use of the website.
a) Session cookies
Session cookies or other cookies that are absolutely necessary for the operation of the website
Legal basis for data processing: consent of the data subject - Article 6 (1) point f) GDPR - legitimate interest of the Data Controller for the purpose of operating the website
Scope of processed data: identification number, date, time.
Duration of data processing: until the end of the session (PHPSESSID),
b) Convenience cookies that support use
Persistent or saved cookiesLegal basis for data processing: the consent of the data subject - Article 6 (1) point f) GDPR - the legitimate interest of the Data Controller in order to ensure the functionality of the website
Duration of data processing: until the data subject is deleted or the cookies expire
c) Statistical, marketing cookies:
Legal basis for data processing: Voluntary consent of the data subject Article 6 (1) point a) GDPR "the data subject has given his consent to the processing of his personal data for one or more specific purposes"
Duration of data processing: 1 month - 2 years
11. Data processors
11.1. Website hosting provider
Scope of processed data: All personal data provided by the data subject.
Scope of stakeholders: All stakeholders who use the website.
Purpose of data processing: Making the website available and operating it properly.
Duration of data processing, deadline for data deletion:
Data processing lasts until the termination of the agreement between the data controller and the storage provider, or until the deletion request addressed to the storage provider by the data subject.
Legal basis for data processing: GDPR Article 6 (1) point a) "the data subject has given his consent to the processing of his personal data for one or more specific purposes"
11.2. Accountant
Scope of processed data: name, billing address, tax number or tax ID.Purpose of data processing: Fulfilling the obligations contained in Act C of 2000 on accounting.
Duration of data processing, deadline for data deletion:
In order to fulfill the accounting obligations, based on § 169 of Act C of 2000, 8 years.
"Accounting documents directly and indirectly supporting the bookkeeping (including ledger accounts, analytical and detailed records) must be kept in legible form for at least 8 years, in a way that can be retrieved by reference to the accounting records"
Legal basis for data processing: Article 6 (1) point c) of Regulation 2016/679 of the European Parliament and of the Council, according to which: "data processing is necessary to fulfill a legal obligation"
The relevant legal obligation is contained in Act C of 2000 on accounting.
12. Other data processing
The Data Controller provides information on data processing not listed in this Information Sheet when the data is collected. The court, the prosecutor, the investigative authority, the infringement authority, the public administrative authority, the National Data Protection and Freedom of Information Authority, the Hungarian National Bank, or other bodies based on the authorization of the law, may contact the Data Controller for the purpose of providing information, communicating data, handing over documents, or making documents available.If the authority has specified the exact purpose and the scope of the data, the data controller will only disclose personal data to the authorities to the extent and to the extent that is absolutely necessary to achieve the purpose of the request.
IV. Method of storing personal data, security of data processing
Only the Controller has access to the data, only the Controller manages it, and uses it only in the manner and for the purpose specified in this data processing information.
The Controller's IT systems and other data storage locations are located at its headquarters and on its server.
The data controller selects and operates the IT tools used for the management of personal data during the provision of the service in such a way that the managed data:
-
a) accessible to those authorized to do so (availability);
-
b) its authenticity and authentication are ensured (authenticity of data processing);
-
c) its immutability can be verified (data integrity);
-
d) be protected against unauthorized access (data confidentiality).The controller and the data processor implement appropriate technical and organizational measures, taking into account the state of science and technology and the costs of implementation, as well as the nature, scope, circumstances and purposes of data processing, as well as the variable probability and severity of the risk to the rights and freedoms of natural persons, in order to guarantee a level of data security appropriate to the level of the risk, including, among other things, where applicable:
a)
pseudonymization and encryption of personal data;
b)
ensuring the continuous confidentiality, integrity, availability and resilience of the systems and services used to manage personal data;
c)
in the event of a physical or technical incident, the ability to restore access to and availability of personal data in a timely manner;
d)
a procedure for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures taken to guarantee the security of data processing.When determining the appropriate level of security, the risks resulting from data processing must be specifically taken into account, which in particular arise from the accidental or unlawful destruction, loss, alteration, unauthorized disclosure or unauthorized access to personal data transmitted, stored or otherwise managed.
The data controller takes measures to ensure that natural persons acting under its control and having access to personal data can only handle said data in accordance with the instructions of the data controller, unless they are required to deviate from this by EU or member state law.
The controller uses appropriate measures to protect the data, in particular against unauthorized access, alteration, transmission, disclosure, deletion or destruction, as well as against accidental destruction, damage, and inaccessibility resulting from changes in the technology used.
In order to protect the data files managed electronically in its various records, the data controller ensures with an appropriate technical solution that the stored data cannot be directly linked and assigned to the data subject, unless permitted by law.In view of the ongoing development of technology, the data controller ensures the protection of the security of data processing with technical, organizational and organizational measures that provide a level of protection corresponding to the risks associated with data processing.
The controller keeps it during the data processing
-
confidentiality: it protects the information so that only those who are authorized to do so can access it;
-
integrity: protects the accuracy and completeness of the information and the method of processing
-
availability: it ensures that when the authorized user needs it, he can really access the desired information and that the related tools are available.
The IT system and network of the Data Controller and its partners are both protected against computer-supported fraud, espionage, sabotage, vandalism, fire and flood, as well as computer viruses, computer intrusions and denial-of-service attacks. The operator ensures security with server-level and application-level protection procedures.
V. Rights of data subjects
Personal data may only be processed for a specific purpose, in order to exercise a right and fulfill an obligation. All stages of data processing must comply with this purpose, and the collection and handling of data must be fair.Only such personal data can be processed that is essential for the realization of the purpose of data processing, is suitable for achieving the purpose, and only to the extent and for the time necessary for the realization of the purpose.
The data controller takes appropriate measures in order to provide the data subject with each piece of information in a concise, transparent, comprehensible and easily accessible form, clearly and comprehensibly worded.
The information must be provided in writing or electronically.
Verbal information can also be provided at the request of the data subject, provided that the identity of the data subject has been verified in another way.
1. Right to information:
The Data Subject may request information about the management of his personal data, and may request the correction of his personal data, or - with the exception of mandatory data processing - deletion or withdrawal, he may exercise his right to data portability and protest in the manner indicated when the data was collected, or at the contact details of the Data Controller specified in this Privacy Policy.The Contact must be informed in a clear, comprehensible and detailed manner about all the facts related to the processing of his/her data, including, in particular, the purpose and legal basis of data processing, the person entitled to data processing and data processing, the duration of data processing, if his/her personal data is processed by the data controller with the consent of the data subject and for the purpose of fulfilling a legal obligation to the data controller or asserting the legitimate interests of a third party, as well as about who can access the data.
2. Right of access:
The Data Subject has the right to receive feedback from the Data Controller as to whether his personal data is being processed, and if such data processing is in progress, he is entitled to receive access to the personal data and the information listed in the regulation.
At the Data Subject's request, the Data Controller provides information on whether data processing is ongoing regarding the following:
- the personal data concerning him
- the purposes of data processing;
- categories of personal data concerned;
- the persons to whom the data subject's data has been disclosed or will be disclosed;
- duration of data storage;
- the right to correction, deletion, restriction of data processing and the right to protest;
- the right to submit a complaint addressed to the supervisory authority;
- the source of the processed data;- profiling and/or automated decision-making, as well as the details and practical effects of such application;
- transfer of processed data to a third country or international organization.
In the event of a data request from the Data Subject, the Data Controller is obliged to issue a copy of the data processed by the Data Subject corresponding to the request. The deadline for issuing the requested data is 30 days from the receipt of the request.
3. Right to rectification:
The Data Subject has the right to have inaccurate personal data corrected without undue delay upon request by the Data Controller. Taking into account the purpose of the data processing, you are entitled to request the completion of incomplete personal data, including by means of a supplementary statement.
4. Right to erasure:
The Data Subject has the right to have the data controller delete the personal data concerning him without undue delay at his request, and the Data Controller is obliged to delete the personal data concerning the Data Subject without undue delay under the following specified conditions:- personal data are no longer needed for the purpose for which they were collected or otherwise processed;
-
the Data Subject withdraws his consent, which is the basis of the data processing, and there is no other legal basis for the data processing;
-
the Data Subject objects to the data processing and there is no overriding legal reason for the data processing;
-
personal data were handled illegally;
-
personal data must be deleted in order to fulfill the legal obligation prescribed by EU or Member State law applicable to the data controller;
-
personal data was collected in connection with the offering of services related to the information society.
5. The right to restrict data processing:
The Data Subject has the right to request that the Data Controller restricts data processing if one of the following conditions is met:
-* The Data Subject disputes the accuracy of the personal data, in which case the limitation applies to the period that allows the data controller to check the accuracy of the personal data;
-
the data processing is illegal and the Data Subject opposes the deletion of the data and instead requests the limitation of its use;
-
the Data Controller no longer needs the personal data for the purpose of data processing, but requires them to present, enforce or defend legal claims;
-
The Data Subject objected to data processing; in this case, the restriction applies to the period until it is determined whether the data controller's legitimate reasons take precedence over the data subject's legitimate reasons.
**6. Right to data portability:**The data subject is entitled to receive the personal data concerning him/her that he/she has made available to the Data Controller in a segmented, widely used, machine-readable format, and is also entitled to transmit this data to another data controller without being hindered by the data controller to whom the personal data was provided, if the data processing is based on consent or a contract, if the data processing is automated and when exercising the right to data portability, the data subject is entitled to - if this is technically feasible - request the direct transfer of personal data between data controllers.
7. Right to protest:
If personal data is processed for direct business acquisition, the Data Subject is entitled to object at any time to the processing of his/her personal data for this purpose, including profiling, if it is related to direct business acquisition.
If the Data Subject objects to the processing of personal data for the purpose of direct business acquisition, then the personal data may no longer be processed for this purpose.The Data Subject has the right, for reasons related to his own situation, to object at any time to the processing of his personal data necessary for the execution of a task carried out in the public interest or within the framework of the exercise of public authority granted to the Data Controller, or to the processing necessary to enforce the legitimate interests of the data controller or a third party, including profiling based on the aforementioned provisions.
In the event of a protest, the Data Controller may no longer process the personal data, unless it is justified by compelling legitimate reasons that take precedence over the interests, rights and freedoms of the Data Subject, or that are related to the submission, enforcement or defense of legal claims.
8. Automated decision-making in individual cases, including profiling:
The Data Subject has the right not to be covered by the scope of a decision based solely on automated data processing, including profiling, which would have legal effects on him or affect him to a similar extent.
The previous paragraph does not apply if the decision:- Necessary in order to conclude or fulfill the contract between the Data Subject and the data controller;
-
its implementation is made possible by EU or Member State law applicable to the data controller, which also establishes appropriate measures to protect the rights and freedoms and legitimate interests of the Data Subject; you are
-
is based on the Data Subject's express consent.
9. Right of withdrawal:
The Data Subject has the right to withdraw his consent at any time. Withdrawal of consent does not affect the legality of data processing based on consent prior to withdrawal.
** VI. Informing the Data Subject about the data protection incident**
Notification of the data protection incident to the supervisory authority
The data controller shall report the data protection incident to the competent supervisory authority without undue delay and, if possible, no later than 72 hours after the data protection incident became known, unless the data protection incident is likely to pose no risk to the rights and freedoms of natural persons. If the notification is not made within 72 hours, the reasons justifying the delay must also be attached.
In the notification, at least:
| |
| - |- the nature of the data protection incident must be described, including – if possible – the categories and approximate number of those affected, as well as the categories and approximate number of data affected by the incident;
-
the name and contact details of the data protection officer or other contact person providing additional information must be provided;
-
the likely consequences of the data protection incident must be described;
-
the measures taken or planned by the data controller to remedy the data protection incident must be described, including, where appropriate, measures aimed at mitigating any adverse consequences resulting from the data protection incident.
If and to the extent that it is not possible to provide the information at the same time, it can be provided later in parts without further undue delay.
The data controller keeps records of data protection incidents, indicating the facts related to the data protection incident, its effects and the measures taken to remedy it. This register enables the supervisory authority to verify compliance with the requirements of this Article.
If the data protection incident likely involves a high risk for the rights and freedoms of natural persons, the data controller shall inform the data subject of the data protection incident without undue delay.In the information provided to the data subject, the nature of the data protection incident must be clearly and comprehensibly described, and at least the information and measures defined above must be communicated.
The data subject need not be informed of the data protection incident if any of the following conditions are met:
-
the data controller has implemented appropriate technical and organizational protection measures, and these measures have been applied to the data affected by the data protection incident, especially those measures - such as the use of encryption - that make the data unintelligible to persons not authorized to access personal data;
-
after the data protection incident, the data controller has taken additional measures to ensure that the high risk to the rights and freedoms of the data subject is unlikely to materialize in the future;
-
providing information would require a disproportionate effort. In such cases, the data subjects must be informed through publicly published information, or a similar measure must be taken that ensures similarly effective information to the data subjects.If the data controller has not yet notified the data subject of the data protection incident, the supervisory authority, after considering whether the data protection incident is likely to involve a high risk, may order the data subject to be informed, or establish that one of the conditions that do not require the information has been met.
** VII. Concepts related to personal data and their interpretation**
personal data: any information relating to an identified or identifiable natural person ("data subject"); the natural person who can be identified directly or indirectly, in particular by an identifier such as name, number, location data, online identifier or one or more factors relating to the physical, physiological, genetic, mental, economic, cultural or social identity of the natural person;
data processing: any operation or set of operations performed on personal data or data files in an automated or non-automated manner, such as collection, recording, systematization, segmentation, storage, transformation or change, query, insight, use, communication by means of transmission, distribution or other means of making available, coordination or connection, restriction, deletion or destruction;restriction of data processing: indication of stored personal data for the purpose of limiting their future management;
profiling: any form of automated processing of personal data in which personal data is used to evaluate certain personal characteristics of a natural person, in particular to analyze or predict characteristics related to work performance, economic situation, health, personal preferences, interests, reliability, behavior, location or movement;
registry system: the file of personal data divided in any way – centralized, decentralized or according to functional or geographical aspects – which is accessible based on specific criteria;
data controller: the natural or legal person, public authority, agency or any other body that determines the purposes and means of processing personal data independently or together with others; if the purposes and means of data processing are determined by EU or member state law, the data controller or the special aspects regarding the designation of the data controller may also be defined by EU or member state law;
data processor: the natural or legal person, public authority, agency or any other body that processes personal data on behalf of the data controller;recipient: the natural or legal person, public authority, agency or any other body to whom the personal data is communicated, regardless of whether it is a third party. Public authorities that have access to personal data in accordance with EU or member state law in the context of an individual investigation are not considered recipients; the handling of said data by these public authorities must comply with the applicable data protection rules in accordance with the purposes of the data processing;
third party: the natural or legal person, public authority, agency or any other body that is not the same as the data subject, the data controller, the data processor or the persons who have been authorized to process personal data under the direct control of the data controller or data processor;
consent of the data subject: the voluntary, concrete and clear declaration of the will of the data subject based on adequate information, with which the data subject indicates by means of a statement or an unmistakable act of confirmation that he gives his consent to the processing of personal data concerning him;data protection incident: a breach of security that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure or unauthorized access to personal data transmitted, stored or otherwise handled;
objection of the data subject: the statement of the data subject objecting to the processing of his personal data and requesting the termination of the data processing or the deletion of the processed data;
data transfer: making the data available to a specific third party;
disclosure: making the data available to anyone;
data deletion: making data unrecognizable in such a way that their recovery is no longer possible;
data marking: providing the data with an identification mark in order to distinguish it;
data blocking: provision of the data with an identification mark for the purpose of limiting the further processing of the data permanently or for a specified period of time;
data destruction: complete physical destruction of the data carrier containing the data;
third country: any state that is not an EEA state.
** VIII. Principles of personal data processing**
The processing of personal data must be carried out legally and fairly, as well as in a transparent manner for the data subject **("legality, fair procedure and transparency");**Personal data should only be collected for specific, clear and legitimate purposes, and they should not be handled in a way that is incompatible with these purposes; in accordance with Article 89 (1), further data processing for the purpose of archiving in the public interest, for scientific and historical research purposes or for statistical purposes is not considered incompatible with the original purpose ("purpose limitation");
Personal data must be appropriate and relevant for the purposes of data processing, and must be limited to what is necessary ("data saving");
Personal data must be accurate and, if necessary, up-to-date; all reasonable measures must be taken in order to immediately delete or correct inaccurate personal data for the purposes of data processing **("accuracy");**Personal data must be stored in a form that allows the identification of the data subjects only for the time necessary to achieve the goals of personal data processing; Personal data may only be stored for a longer period of time if the personal data will be processed for the purpose of archiving in the public interest, for scientific and historical research purposes or for statistical purposes in accordance with Article 89 (1), taking into account the implementation of the appropriate technical and organizational measures required in this regulation to protect the rights and freedoms of the data subjects ("limited storage");
The processing of personal data must be carried out in such a way that, by applying appropriate technical or organizational measures, adequate security of personal data is ensured, including protection against unauthorized or illegal processing, accidental loss, destruction or damage of data ("integrity and confidentiality").
The data controller is responsible for compliance with the above, and must also be able to prove this compliance ("accountability").
The data controller declares that it handles personal data in compliance with the principles contained in this point.
** IX. Rules of procedure**
Transparent information, communication and measures for exercising the rights of the data subjectIf the Data Controller receives a request from the data subject, the data controller will inform the data subject in writing as quickly as possible, but no later than within 30 days, of the measures taken based on the request.
If justified by the complexity of the application or other objective circumstances, the 30-day deadline can be extended once, up to a maximum of 60 days. The data controller shall inform the data subject of the extension of the deadline, indicating the reasons for the delay, within one month of receiving the request. If the data subject submitted the application electronically, the information must be provided electronically, if possible, unless the data subject requests otherwise.
If the data controller does not take measures following the data subject's request, it shall inform the data subject without delay, but at the latest within one month of the receipt of the request, of the reasons for the failure to take action, as well as that the data subject may file a complaint with a supervisory authority and exercise his right to judicial redress.Information according to Articles 13 and 14 of the GDPR Regulation and Articles 15–22 and information and measures according to Article 34 must be provided free of charge. If the data subject's request is clearly unfounded or - especially due to its repetitive nature - excessive, the data controller, taking into account the administrative costs associated with providing the requested information or information or taking the requested measure:
a)
may charge a reasonable fee, or
b)
can refuse to take action based on the request.
It is the responsibility of the data controller to prove that the request is clearly unfounded or excessive.
If the data controller has well-founded doubts about the identity of the natural person submitting the request, it may request the provision of additional information necessary to confirm the identity of the person concerned.
If the applicant requests the transfer of the data on paper or on an electronic data carrier (CD or DVD), the Data Controller will provide a copy of the relevant data in PDF format on an electronic data carrier free of charge. Transferring data on a paper basis would be technically disproportionately difficult, so the Data Controller always transfers the requested data in one copy on an electronic data carrier. For each additional requested copy, an administration fee of HUF 500 per CD-DVD is charged.The data controller notifies all persons to whom the relevant data were previously disclosed of the correction, deletion, or restriction it has implemented, unless the information is impossible or requires a disproportionately large effort.
The data controller shall respond to the request in electronic form, unless:
-
the data subject specifically requests the answer in a different way, and it does not cause unreasonably high additional expenses for the Data Controller;
-
the Data Controller does not know the electronic contact information of the data subject.
Exercising the right to object:
The data controller examines the objection as soon as possible, but no later than 15 days after the submission of the application, makes a decision on its validity, and informs the applicant of his decision in writing.
If the Data Controller determines that the User's protest is well-founded, the data processing - including further data collection and transmission - will be terminated and the data will be locked, and all those to whom the personal data affected by the protest were previously transmitted, and who are obliged to take measures to enforce the right to protest, will be notified of the protest and the measures taken based on it.
X. Remedy
If you have any objections or problems regarding your Data Management, please contact us at the following address:
Cell-Vitál Limited Liability Companyregistered office: 8143 Sárszentmihály, Kossuth utca 56.
Email: cellvital@cellvital.hu
contact: Doma Róbert
Phone number: 06-70-426-9818
Postal address/complaint handling: 8143 Sárszentmihály, Kossuth utca 56.
Website: https://cellvital.hu
1. Compensation and damages
Right to compensation and liability
Any person who has suffered material or non-material damage as a result of a violation of the GDPR regulation is entitled to compensation from the data controller for the damage suffered.
All data controllers involved in data processing are responsible for any damage caused by data processing that violates this regulation.
The Data Controller is released from liability if it proves that it is not responsible in any way for the event that caused the damage.
2. Right to go to court:
If, according to the data subject's point of view, his rights have been violated by the Data Controller, he is entitled to Pp. to apply to a court with jurisdiction and authority. The court acts out of sequence in the case.
3. Data protection official procedure:
You can file a potential complaint with the National Data Protection and Freedom of Information Authority:
Name: National Data Protection and Freedom of Information Authority
Headquarters: 1125 Budapest, Szilágyi Erzsébet fasor 22/C.
Mailing address: 1530 Budapest, Pf.: 5.
Phone: 06-1/391-1400; fax: 06-1/391-1410
Email: ugyfelszolgalat@naih.hu
Website: http://www.naih.hu4. Authority cooperation
If the Data Controller receives an official request from the authorized authorities, it will obligatorily hand over the specified personal data.
The Data Controller only transfers data that is absolutely necessary to achieve the goal indicated by the requesting authority.
5. Legislation on which data processing is based
-
Regulation (EU) 2016/679 of the European Parliament and of the Council (April 27, 2016) on the protection of natural persons with regard to the processing of personal data and on the free flow of such data, and on the repeal of Regulation 95/46/EC (General Data Protection Regulation; hereinafter: "GDPR")
-
2013. Act V on the Civil Code (hereinafter: "Civil Code")
-
2016. year CXXX. Act on Civil Procedure (hereinafter: "Pp.")
-
2001. year CVIII Act - on certain issues of electronic commercial services and services related to the information society (hereinafter: "Eker. tv.");
-
2008. year XLVIII Act - on the basic conditions and certain limitations of economic advertising activity (hereinafter: "Grt.").
Final Provisions
This Information Sheet serves as information for those concerned to present the data processing practices of the Data Controller, with the Data Controller reserving the right to change this information sheet.The Data Controller acknowledges the content of this legal notice as binding on itself and undertakes to ensure that all data processing related to its activities complies with the requirements set out in these regulations and the applicable legislation, as well as in the legal acts of the European Union.
The Data Controller is committed to protecting the personal data of its customers and partners, treats personal data confidentially, and takes all security, technical and organizational measures that guarantee data security.
The Data Controller undertakes to notify the Data Subjects in advance of any changes to its principles and practices regarding the handling of personal data. The changes must also be indicated on the Data Controller's website. Data processing must always reflect the actually applied principles and real practice.
The data controller declares that it fulfills its data processing obligations in accordance with the provisions of this regulation from the date of acceptance of this Privacy Policy.
The Data Controller informs the Data Subjects of the amendment and publishes the amended Data Protection Notice on its website.
Amendments to the data processing information will enter into force upon publication on the website.
Cell-Vitál Limited Liability Company
Managing cookiesWhen the visitor visits the website covered by this information, we place a small data file called cookie (hereinafter: cookie or cookie) on his computer, which can serve several purposes.
-
data record
-
identification of the user
-
facilitating further visits by the user
-
increasing the efficiency of the service
-
to deliver targeted advertising or other targeted content to the user or to identify and differentiate users for the purpose of market research,
-
identification of the users' current session, storage of the data entered during it,
-
data loss prevention (PHPSESSID),
-
the operation of the chat connection (PCJSF_Processor_SURL, PCJSF_Tracker_Key, PCJSF),
-
identification of visitors (PAPVisitorId).
Some of the cookies we use are essential for the proper functioning of the site (session cookie), others are used to facilitate the more convenient use of the website. By recording the visitor's settings and usage habits, navigation on the site and thereby facilitating the use of the website.
a) Session cookies
Session cookies or other cookies that are absolutely necessary for the operation of the websiteSession cookies are necessary for browsing the website and using the functions, among other things they allow the visitor to comment on the actions performed on a given page, function or service. Without the use of "session cookies", the smooth use of the website cannot be guaranteed. Their validity period extends to the duration of the given visit, "cookies" are automatically deleted at the end of the session or when the browser is closed.
Legal basis for data processing: **consent of the data subject - GDPR Article 6 (1) point f) ** - legitimate interest of the Data Controller for the purpose of operating the website
Scope of processed data: ID number, date, time.
Duration of data processing: until the end of the session (PHPSESSID),
2 hours (PCJSF_Processor_SURL)
1 hour (PCJSF_Tracker_Key, PCJSF), as well as
2 years (PAPVisitorId).
As a result of the use of the data files, the data transferred to the data controller is the data controller
does not link it to the identification data of the given user.
The so-called session cookies are automatically deleted at the end of the deadline set in the cookies.
In relation to cookies, the user has the following options in his browser:
1. you will be notified if the data controller wants to place a cookie on your computer
2. you can prohibit the sending of cookies at any time
In this context, it should be emphasized that not accepting cookies results inin connection with certain pages or functions not working properly, as well as
it is possible that the user is not authorized to access certain data.
b) Convenience cookies that support use
Permanent or saved cookies
Legal basis for data processing: consent of the data subject - Article 6 (1) point f) GDPR - the legitimate interest of the Data Controller in order to ensure the functionality of the website
Duration of data processing: until the data subject is deleted or the cookies expire
These cookies allow our website to remember which mode of operation you have chosen (for example: you have accepted the cookie information and according to which sorting method the results received in the search result list are displayed). This is done so that on the next visit you do not have to accept the cookie information again and again or set the sorting principle according to which you want to view the content displayed on the page. Without the information contained in the cookies that store preferences, our website may function less smoothly.
We do not record personal data in the convenience cookies, we only store an identification number, from which the site is informed that the cookie notice was previously accepted. The convenience cookie is stored in the browser of the client machine with an expiration date of 1 month. Even if cookies are accepted, the visitor can safely use the electronic services of the Site Operator.
Some of the cookies we use are only temporary and disappear when you close the browser, while there are convenience cookies that are stored on your computer for 1 month, so that if you regularly visit our website, your browser remembers the settings you used previously, so you do not need to accept our cookie information every time you visit or regularly set the filtering conditions according to your needs.
c) Statistical, marketing cookies:
**Legal basis for data processing: Voluntary consent of the data subject GDPR Article 6 (1) point a) "**the data subject has given his consent to the processing of his personal data for one or more specific purposes"
Duration of data processing: 1 month - 2 years
Modern browsers allow modification of cookie settings. Some browsers automatically accept cookies by default, but this setting can also be changed in order for the user to prevent automatic acceptance in the future. In case of conversion, the browser will offer the option to set cookies each time.Since the purpose of cookies is to support and facilitate the usability and processes of the website, if cookies are disabled, we cannot guarantee that the visitor will be able to fully use all the functions of the website. In this case, the website may function differently than planned in the browser.
More information can be found here:
Google Chrome (https://support.google.com/chrome/answer/95647?hl=hu)
Internet Explorer (https://support.microsoft.com/hu-hu/help/17442/windows-internet-explorer-delete-manage-cookies)
Firefox (https://support.mozilla.org/hu/kb/sutik-engedelyezese-es-tiltasa-amit-weboldak-haszn)
Safari (https://support.apple.com/hu-hu/guide/safari/sfri11471/mac)
We would like to draw the attention of our visitors to the fact that when using an ad-blocker, information about the cookie statement is not always displayed. If you want to view it, deactivate the ad blocking application!