PRIVACY POLICY
effective from 25 August 2026
Livepoint Kft. (hereinafter: the “Controller”) places particular emphasis on processing, storing and using personal data of natural persons in accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation, hereinafter: the “GDPR”).
In connection with the processing of personal data, Livepoint Kft. hereby informs data subjects using the website www.mezio.hu (hereinafter: the “Website”) and placing orders thereon (hereinafter: the “Data Subject”) about the personal data processed by it and the principles and practices it follows in relation to the processing of personal data.www.mezio.hu
Personal data collected by the Controller may only be processed for specified, explicit and legitimate purposes and may not be further processed in a manner incompatible with those purposes; moreover, it must be stored in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the personal data are processed.
The Controller shall ensure that unauthorised persons cannot access personal data and that the storage and retention arrangements for personal data are designed so that such data cannot be accessed, obtained, altered or destroyed by unauthorised persons.
- CONTROLLER’S DETAILS
Name: Livepoint Kommunikációs, Kereskedelmi és Szolgáltató Korlátolt Felelősségű Társaság
Registered office: 1095 Budapest, Soroksári út 110–112. Building E, 1st floor
Company registration number: 01-09-879217
Tax number: 13905297-2-43
Registering authority: Company Court of the Budapest-Capital Regional Court
E-mail: info@livepoint.hu
Telephone: +36 30 705 3907
Website: livepoint.hu
- TERMS USED IN THIS PRIVACY POLICY
- personal data: any information relating to an identified or identifiable natural person (the “Data Subject” in this document); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
- Data Subject: an identified or identifiable natural person on the basis of any information;
- Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the Controller or the specific criteria for its nomination may be provided for by Union or Member State law;
- processing: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
- recipient: a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not;
- restriction of processing: the marking of stored personal data with the aim of limiting their processing in the future;
- processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller;
- consent of the Data Subject: any freely given, specific, informed and unambiguous indication of the Data Subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
- personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;
- DESCRIPTION OF DATA PROCESSING ACTIVITIES
Registered users may use the convenience services available on the Website (e.g. saving delivery and billing addresses). Registration is not mandatory.
|
Categories of personal data processed |
Purpose of processing |
Legal basis for processing |
Retention period |
|
name, e-mail address, username, address, date and time of registration, IP address, date and time of last login |
Creation of a user account, identification, communication, information concerning the customer’s areas of interest, |
Article 6(1)(a) GDPR – the Data Subject’s freely given consent |
For as long as the registration remains in place, or until consent is withdrawn |
Deletion of registration: registration may be deleted in the user account or by submitting a deletion request to the Controller. Upon receipt of a deletion request, the Controller shall delete the Data Subject’s user account together with all personal data without undue delay. Deletion does not, however, affect the destruction of invoices relating to orders already placed, or the deletion of data which the Controller is legally required to retain (e.g. complaints must be retained for 3 years). Following deletion, the data cannot be restored.
Source of the data: collected directly from the Data Subject.
Possible consequences of failure to provide the data: the Data Subject will be unable to use the convenience features associated with registration and will not be entitled to create or use a user account.
- Login/registration using a Facebook account
If the Data Subject has a Facebook account, they may register by clicking the “Register with Facebook account” button or log in to the Website by clicking the “Log in with Facebook account” button. Registration is not mandatory in this case either.
The Data Subject is redirected to the external service provider’s login page, where they may log in to the Controller’s Website using the details previously registered on Facebook. The Controller does not have access to, and does not store, the password entered.
|
Categories of personal data processed |
Purpose of processing |
Legal basis for processing |
Retention period |
|
name, e-mail address, Facebook ID
|
Identification of the Data Subject and enabling the Data Subject to register/log in to the Website registration/login interface easily using the details of their existing Facebook account. |
Article 6(1)(a) GDPR – the Data Subject’s freely given consent |
Processing of the personal data required during registration commences upon registration and continues until deletion at the Data Subject’s request. If the Data Subject does not request deletion of the registration, the Controller will delete the Data Subject’s personal data from its system no later than 30 days after the Website ceases to operate. |
Source of the data: collected directly from the Data Subject.
Consequence of failure to provide the data: no adverse legal consequence.
- Login/registration using a Google account
If the User has a Google account, they may log in by clicking the “Log in with Google account” button or register on the Website by clicking the “Register with Google account” button in order to make purchases or use services. Registration is not mandatory in this case either.
The Data Subject is redirected to the external service provider’s login page, where they may log in to the Controller’s Website using the details previously registered on Google. The Controller does not have access to, and does not store, the password entered.
|
Categories of personal data processed |
Purpose of processing |
Legal basis for processing |
Retention period |
|
name, e-mail address, Google ID
|
Identification of the Data Subject and enabling the Data Subject to register/log in to the Website registration/login interface easily using the details of their existing Google account. |
Article 6(1)(a) GDPR – the Data Subject’s freely given consent |
Processing of the personal data required during registration commences upon registration and continues until deletion at the Data Subject’s request. If the Data Subject does not request deletion of the registration, the Controller will delete the Data Subject’s personal data from its system no later than 30 days after the Website ceases to operate. |
Source of the data: collected directly from the Data Subject.
Consequence of failure to provide the data: no adverse legal consequence.
- Login/registration using an Apple account
If the User has an Apple account, they may log in by clicking the “Log in with Apple account” button or register on the Website by clicking the “Register with Apple account” button in order to make purchases or use services. Registration is not mandatory in this case either.
The Data Subject is redirected to the external service provider’s login page, where they may log in to the Controller’s Website using the details previously registered on Apple. The Controller does not have access to, and does not store, the password entered.
|
Categories of personal data processed |
Purpose of processing |
Legal basis for processing |
Retention period |
|
name, e-mail address, Apple ID
|
Identification of the Data Subject and enabling the Data Subject to register/log in to the Website registration/login interface easily using the details of their existing Apple account. |
Article 6(1)(a) GDPR – the Data Subject’s freely given consent |
Processing of the personal data required during registration commences upon registration and continues until deletion at the Data Subject’s request. If the Data Subject does not request deletion of the registration, the Controller will delete the Data Subject’s personal data from its system no later than 30 days after the Website ceases to operate. |
Source of the data: collected directly from the Data Subject.
Consequence of failure to provide the data: no adverse legal consequence.
If the Data Subject is a registered customer and has forgotten their password, they may initiate a password reset via the webshop interface.
When a forgotten-password request is made, the Controller implements technical measures to prevent misuse. If the Data Subject did not request a password reminder but received such an e-mail, please disregard it or notify our customer service. The Controller’s staff will never ask the Data Subject for their password through any channel (e-mail or telephone).
|
Categories of personal data processed |
Purpose of processing |
Legal basis for processing |
Retention period |
|
username/e-mail address, time of the request, IP address, and the temporary, single-use password-reset link (token) |
Secure restoration of access to the user account and prevention of unauthorised access. |
Article 6(1)(f) GDPR – legitimate interests. (The Controller and the Data Subject have a shared legitimate interest in secure access to the account and maintaining data security.) |
The password-reset link (token) is valid for a limited period (24 hours), after which the temporary technical data are deleted. |
The Controller stores passwords in an irreversible, encrypted form (using a hashing procedure). During the forgotten-password process, the Controller cannot see the old password and merely enables a new password to be set. The Controller has carried out a legitimate interest assessment, which is available upon the Data Subject’s request.
Source of the data: data provided by the Data Subject (name/username, e-mail address). Technical data associated with the process (IP address, timestamp, reset token) are recorded by the Controller’s own IT system for the purpose of preventing misuse and ensuring data security.
Possible consequences of failure to provide the data: without the data, the password cannot be reset and access to the account is not possible. The Data Subject loses access to their registered account and the historical data stored there (order history, saved addresses). The Data Subject can thereafter make purchases only by creating a new registration.
- Purchasing on the Website
By using the service, a contract is concluded between the consumer and the Controller pursuant to Section 5 of Act CVIII of 2001 on certain issues relating to electronic commercial services and information society services (the “E-Commerce Act”) and Government Decree 45/2014 (II. 26.) on the detailed rules of contracts between consumers and businesses.
Purchases are subject to registration.
|
Categories of personal data processed |
Purpose of processing |
Legal basis for processing |
Retention period |
|
name |
identification, communication |
Article 6(1)(b) GDPR – performance of a contract |
5 years following performance of the contract |
|
delivery address |
ensuring delivery |
||
|
e-mail address |
identification, communication (sending notifications about the status of the parcel (SMS/e-mail), delivery |
||
|
telephone number |
communication (e.g. the courier calls in the event of delivery) |
||
|
order data, account settings, previous order history, favourite products (for registered customers) |
maintaining the user profile, convenience features (faster purchasing), providing order history |
||
|
uploaded image, prompt |
fulfilment of the order |
Saved designs: 1 month; data of ordered and manufactured designs: 6 months |
Source of the data: collected directly from the Data Subject.
Recipients/categories of recipients of personal data: database management partner; provider of the design software.
Possible consequences of failure to provide the data: provision of the personal data is necessary to complete the purchase. Without the data, the order cannot be fulfilled, the contract cannot be concluded, the profile cannot be created, and purchases will not be recorded in the profile.
Without recording the data in the Controller’s own database, the Controller cannot ensure that the customer’s purchase history can be retrieved. Consequently, the Data Subject cannot access the convenience features (saved addresses, previous orders), customer service and administrative processes will be significantly slower, and all data will have to be provided again for every subsequent enquiry or purchase.
- Invoicing
|
Categories of personal data processed |
Purpose of processing |
Legal basis for processing |
Retention period |
|
name, residential address, tax number (where required), e-mail address (in the case of an electronic invoice)
|
Issuing invoices, storing invoices, fulfilling reporting obligations to the Hungarian Tax and Customs Administration (NAV), preparing and maintaining accounting records |
Article 6(1)(c) GDPR – compliance with a legal obligation |
8 years pursuant to Section 169(2) of Act C of 2000 on Accounting. |
Source of the data: collected directly from the Data Subject.
Data transfer: no transfer of data takes place to a country outside the EU.
Recipients/categories of recipients of personal data: invoicing system/accountant (szamlazz.hu) – fulfilment of accounting obligations
Possible consequences of failure to provide the data: the Controller cannot comply with its legal obligations under applicable Hungarian legislation.
- Contact
|
Categories of personal data processed |
Purpose of processing |
Legal basis for processing |
Retention period |
|
name | e-mail address | telephone number
|
Where the Data Subject has a question relating to the Website or the Controller’s services, the contact form available under the Contact section of the Website may be used to contact the Controller. The purpose is to enable communication and contact between the Controller and the Data Subject in connection with the question raised. |
Article 6(1)(a) GDPR – the Data Subject’s freely given consent.
|
The Controller retains contact forms, e-mails and postal letters, together with the sender’s name, e-mail address and other personal data provided in the message, until the Data Subject’s question or comment has been resolved or answered. |
Source of the data: collected directly from the Data Subject.
Recipients/categories of recipients of personal data: customer service employee.
Possible consequences of failure to provide the data: the Controller cannot respond to the enquiry and the Data Subject will not receive the requested information or assistance.
The Controller regularly sends newsletters to subscribers in order to present the current products, promotions and new products of the MEZiO webshop and information relating to the services, and to inform interested persons about events relating to the webshop. The newsletter service may be requested by providing the following data:
|
Categories of personal data processed |
Purpose of processing |
Legal basis for processing |
Retention period |
|
name | e-mail address
|
Sending newsletters |
Article 6(1)(a) GDPR – the Data Subject’s freely given consent, given by ticking the checkbox on the online interface when subscribing |
Until withdrawal of the Data Subject’s consent. |
|
date and fact of subscription |
Demonstrating that consent was given |
The Controller processes these data until the Data Subject unsubscribes from the newsletter by clicking the unsubscribe link contained in the newsletter or requests removal by e-mail or post. Following unsubscribing, the Controller will not contact the Data Subject with further newsletters or offers. The Data Subject may unsubscribe from the newsletter at any time, free of charge and without restriction or justification.
Source of the data: collected directly from the Data Subject.
Recipients/categories of recipients of personal data: database management partner; employees carrying out data processing in connection with marketing and services
Possible consequences of failure to provide the data: the Data Subject will not receive newsletters from the Controller and will not have access to, or be informed of, the information contained therein.
- Processing relating to sending and displaying personalised advertising (DM newsletter)
|
Categories of personal data processed |
Purpose of processing |
Legal basis for processing |
Retention period |
|
name | address | e-mail address | telephone number
|
Sending advertising content tailored to the Data Subject’s interests. |
Article 6(1)(a) GDPR – the Data Subject’s freely given consent |
Until withdrawal of the Data Subject’s consent. |
The Controller processes these data until the Data Subject unsubscribes from the newsletter by clicking the unsubscribe link contained in the newsletter or requests removal by e-mail or post. Following unsubscribing, the Controller will not contact the Data Subject with further newsletters or offers. The Data Subject may unsubscribe from the newsletter at any time, free of charge and without restriction or justification.
Source of the data: collected directly from the Data Subject.
Recipients/categories of recipients of personal data: database management partner; employees carrying out data processing in connection with marketing and services
Possible consequences of failure to provide the data: the Data Subject will not receive direct-marketing newsletters from the Controller and will not have access to, or be informed of, the information and discounted offers or promotions contained therein.
- Product review
The Controller’s Website allows products to be reviewed in text and with a rating of 1–5 stars. The product review is displayed under the reviewing user’s username.
|
Categories of personal data processed |
Purpose of processing |
Legal basis for processing |
Retention period |
|
name | e-mail address | review text | rating associated with the review | date and time of review | technical identification data (e.g. IP address, if recorded by the system to prevent misuse)
|
The purpose of the processing is to collect and display customer opinions, reviews and comments relating to products sold on the Website, encourage purchases, measure customer satisfaction and provide information about the quality of the products distributed. |
Article 6(1)(a) GDPR – the Data Subject’s freely given consent |
Until withdrawal of the Data Subject’s consent. The data are automatically deleted one year after online sales of the reviewed product cease.
|
Source of the data: collected directly from the Data Subject.
Consequences of failure to provide the data: provision of the data is voluntary. If the data are not provided, the Data Subject cannot publish a product review on the Website.
- Complaint handling
The Controller shall respond to complaints relating to data processing within no later than 1 month, which may, where justified, be extended by a further 2 months.
|
Categories of personal data processed |
Purpose of processing |
Legal basis for processing |
Retention period |
|
name | e-mail address | telephone number (depending on the method of contact), complaint submitted by the Data Subject
|
Investigation of the consumer complaint, repair/replacement of the product complained about, communication with the Data Subject and fulfilment of the statutory obligation to prepare a record. |
Article 6(1)(c) GDPR – compliance with a legal obligation (under Section 17/A of Act CLV of 1997 on Consumer Protection, the business is obliged to record and respond to the complaint). |
3 years in respect of the record made of the complaint and a copy of the response, pursuant to Section 17/A(7) of Act CLV of 1997 on Consumer Protection. |
Source of the data: collected directly from the Data Subject.
Possible consequences of failure to provide the data: the reported claim cannot be investigated and communication with the Data Subject and any compensation cannot be provided.
- Data processed for the purpose of demonstrating the Data Subject’s consent to processing
On the Website, the Data Subject gives consent to processing separately for each processing purpose by ticking an empty checkbox; the Website stores IT data relating to the giving of consent for the purpose of enabling this to be evidenced at a later date.
|
Categories of personal data processed |
Purpose of processing |
Legal basis for processing |
Retention period |
|
Date and time of consent and the Data Subject’s IP address |
Demonstrating that consent to the processing was given |
Until the end of the limitation period following termination of the processing. |
Article 6(1)(c) GDPR and Article 7(1) GDPR – processing for the purpose of compliance with a legal obligation |
Source of the data: collected directly from the Data Subject.
Recipients/categories of recipients of personal data: National Authority for Data Protection and Freedom of Information (NAIH); legal representative.
Possible consequences of failure to provide the data: the Controller cannot demonstrate the lawfulness of the processing in the event of a regulatory inspection.
- PROCESSORS
In accordance with applicable legislation, the Controller is entitled to engage processors for certain technical operations or for the provision of services. A processor is authorised only to carry out the Controller’s instructions and decisions.
KBOSS.hu Kereskedelmi és Szolgáltató Kft. (szamlazz.hu)
Registered office: 1031 Budapest, Záhony utca 7. (Graphisoft Park)
Company registration number: 01-09-917452
Tax number: 14741369-2-41, info@szamlazz.huinfo@szamlazz.hu
Activity: operator of invoicing software
Privacy Policy: https://www.szamlazz.hu/adatvedelem/https://www.szamlazz.hu/adatvedelem/
GLS General Logistics Systems Hungary Kft.
Registered office: 2351 Alsónémedi, GLS Európa utca 2.
Company registration number: 13-09-111755
Tax number: 12369410-2-44
E-mail: info@gls-hungary.cominfo@gls-hungary.com
Activity: courier service, partner involved in delivery
Privacy Policy:
https://gls-group.com/HU/hu/adatkezelesi-tajekoztato/https://gls-group.com/HU/hu/adatkezelesi-tajekoztato/
Magyar Posta Zrt. (MPL)
Registered office: 1138 Budapest, Dunavirág utca 2–6.
Company registration number: 01-10-042463
Tax number: 10901232-2-44
E-mail: ugyfelszolgalat@posta.huugyfelszolgalat@posta.hu
Activity: courier service, partner involved in delivery
Privacy Policy:
https://www.posta.hu/adatkezelesi_tajekoztatohttps://www.posta.hu/adatkezelesi_tajekoztato
TOTÁL-TOP Szolgáltató és Kereskedelmi Korlátolt Felelősségű Társaság
Registered office: 2030 Érd, Hortenzia utca 18.
Company registration number: 13-09-145638
Tax number: 13490906-2-13
E-mail: totaltopkft@gmail.com
Dél-Kon-Tex Dress Kft.
Registered office: 6430 Bácsalmás, Korona utca 30.
Company registration number: 03-09-130939
Tax number: 29253771-2-4
E-mail: miklos.bana@dresspress.humiklos.bana@dresspress.hu
Website: https://dresspress.hu/https://dresspress.hu/
Activity: manufacturing, packaging
Privacy Policy: https://dresspress.hu/adatvedelmi-nyilatkozat/https://dresspress.hu/adatvedelmi-nyilatkozat/
Diavox Kft.
Registered office: 1204 Budapest, Vécsey utca 30
Telephone: +36 30 449 3537
E-mail: info@diavox.hu
Website: https://diavox.hu
Activity: hosting service provider
Privacy Policy: https://diavox.hu/hu/adatvedelem
- RECIPIENTS/CATEGORIES OF RECIPIENTS OF PERSONAL DATA
Personal data may be transferred to the following recipients or categories of recipients:
- Hosting and IT service provider – technical operation of the webshop
- Invoicing system/accountant (szamlazz.hu) – fulfilment of accounting obligations
- Tax authority / where necessary and upon request, other authorities and courts – invoicing
- DATA TRANSFERS
Personal data may primarily be accessed by the Controller and processors engaged by the Controller for the performance of their tasks. In addition, the Data Subject’s personal data may be transferred to another controller in the following case.
a. Transfers to authorities
The Controller informs the Data Subject that a court, public prosecutor, investigating authority, authority dealing with administrative offences, administrative authority, National Authority for Data Protection and Freedom of Information, or other bodies authorised by law may contact the Controller for the purpose of providing information, disclosing or transferring data, or making documents available.
The Controller shall disclose to authorities only such personal data, and only to the extent, that is strictly necessary to achieve the purpose of the request, provided that the authority has specified the precise purpose and scope of the data requested.
The data provided by the Data Subject will not be transferred for any other purpose.
b. Payment by bank card in the case of online purchases
The customer may pay for their purchase by bank card through the system of Stripe Payments Europe Ltd. (1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, Ireland, https://support.stripe.com/contact). During the payment process, the Data Subject enters their card details on Stripe’s secure interface.https://support.stripe.com/contact
The webshop uses the services of Stripe Payments Europe Limited to process bank-card payments for purchases, which is responsible for the technical processing and security of online payment transactions. In the case of online bank-card payment, the Controller does not have access to, and does not process, the bank-card details (card number, expiry date, CVV code); these are handled exclusively by Stripe. The Controller receives information only about the outcome of the transaction (successful/unsuccessful payment) and the transaction identifier for the purpose of performing the contract (Article 6(1)(b) GDPR) and complying with accounting obligations (Article 6(1)(c) GDPR). Stripe processes personal data relating to payment data in accordance with its own privacy policy, available at https://stripe.com/en-hu/privacy.https://stripe.com/en‑hu/privacy
Categories of data processed: name, e-mail address, transaction data relating to the payment (transaction amount, transaction date and time, transaction identifier)
Purpose of the data transfer: processing of online bank-card payments, identification and confirmation of transactions, handling payment errors, processing refunds
Legal basis for the data transfer: Article 6(1)(b) GDPR – performance of a contract; Article 6(1)(c) GDPR – compliance with a legal obligation
Purpose of the data transfer: proper operation of the payment service and the technical processing of payments, confirmation of transactions, and fraud monitoring carried out to protect users’ interests.
Transfer to a third country: as a global service provider, Stripe processes personal data relating to payment transactions within the European Union; however, data may be transferred to its parent company, Stripe, Inc., in the United States. The transfer is carried out on the basis of the EU–US Data Privacy Framework and the Standard Contractual Clauses (SCCs) approved by the European Commission.
- AUTOMATED DECISION-MAKING AND PROFILING
Automated decision-making: no automated decision-making takes place in the processing activities specified in this Privacy Policy. Even where automated operations are performed as part of processing, decisions relating to the processing are never made solely by automated means.
Profiling: no profiling within the meaning of the GDPR is carried out in the processing activities specified in this Privacy Policy.
- ACCESS TO DATA, DATA SECURITY MEASURES AND BACKUPS
- Data security measures
The data are stored on servers owned and/or operated by the Controller, which are located in Hungary. To protect the data, the Controller uses technical solutions including SSL encryption, firewalls and 24-hour physical security.
The Controller takes all necessary measures reasonably expected of it to ensure data security and provides an appropriate level of protection, in particular against unauthorised access, alteration, transmission, disclosure, erasure or destruction, as well as accidental destruction and damage. The Controller ensures data security by implementing appropriate technical and organisational measures.
The Controller selects and operates the IT equipment used to process personal data in the course of providing the service in such a way that the data processed are:
- accessible to authorised persons (availability);
- authenticity and authentication are ensured (authenticity of processing);
- their integrity can be demonstrated (data integrity);
- protected against unauthorised access (data confidentiality).
In the course of processing, the Controller preserves
- confidentiality: protecting information so that it can only be accessed by persons authorised to do so;
- integrity: protecting the accuracy and completeness of the information and the processing methods;
- availability: ensuring that, when an authorised user requires it, they can actually access the information requested and that the associated resources are available.
The Controller maintains a record of any personal data breaches. Where a breach within the meaning of the GDPR occurs, the Controller shall notify the supervisory authority without undue delay and, where feasible, not later than 72 hours after becoming aware of it (Article 33 GDPR). The Controller shall inform the Data Subject without undue delay where the breach is likely to result in a high risk to the rights and freedoms of natural persons (Article 34 GDPR).
- Backups
As part of its responsibilities relating to the protection of IT systems, the Controller takes measures to ensure, in particular, that data sets can be restored, including regular backups and the separate, secure storage of copies (backups).
Accordingly, in order to prevent the loss of electronically stored data, the Controller regularly makes daily and monthly backups of the data in its databases, including personal data, onto separate storage media.
Backups are deleted by automatically overwriting the previous backup. Access to backups is restricted and may only be exercised by persons with specified authorisation. Backups may be restored solely in the event of destruction of the system or data loss, with the approval of the current managing director.
- RIGHTS OF DATA SUBJECTS
The Controller does not apply an age restriction to the use of the Website and webshop services or to purchases. An incapacitated minor (a person under 14 years of age) is represented by their legal representative, who makes the legal declaration on their behalf. A minor with limited capacity to act (a person aged 14 or over but under 18) may independently enter into contracts of minor significance falling within the ordinary needs of everyday life—which generally includes the clothing products offered on the Website—without the involvement of their legal representative. Where processing is based on the Data Subject’s consent (e.g. newsletters, direct marketing communications, product reviews) and the Data Subject is under 16, the consent is lawful only with the consent or approval of the legal representative exercising parental responsibility. The Controller shall, taking into account the nature of the processing and where reasonably practicable using the means available to it, make reasonable efforts to verify that consent was given or approved by the person exercising parental responsibility. If the Controller becomes aware that a child under 16 has given consent to processing based on consent without the approval of the person exercising parental responsibility, the Controller shall erase the relevant data without undue delay. The legal representative may exercise the Data Subject rights set out in sections 6.2–6.7 on behalf of the minor Data Subject.
- Right to withdraw consent
The Data Subject may withdraw their consent to processing at any time, in which case the data provided will be deleted from our systems. Please note that this right may only be exercised in respect of processing activities based on the Data Subject’s consent.
- Right to request information and a copy (right of access)
The Data Subject has the right to obtain confirmation as to whether or not personal data concerning them are being processed and, where personal data are being processed, has the right to:
- access the personal data being processed (i.e. request a copy thereof); and
- be informed of the following:
- the purposes of the processing;
- the categories of personal data concerned;
- information about the recipients or categories of recipients to whom the personal data have been or will be disclosed;
- the envisaged period for which the personal data will be stored, or, where that is not possible, the criteria used to determine that period;
- the Data Subject’s right to request rectification or erasure of personal data concerning them or restriction of processing, and, where processing is based on legitimate interests, to object to such processing;
- the right to lodge a complaint with the supervisory authority;
- where the personal data are not collected from the Data Subject, any available information as to their source;
- information about the existence of automated decision-making (where such a procedure is used), including profiling, and, at least in such cases, meaningful information about the logic involved and the significance and envisaged consequences of such processing for the Data Subject.
The exercise of this right may be intended to establish and verify the lawfulness of processing; therefore, where requests for information are made repeatedly, we may charge a reasonable fee in return for providing the information.
Access to personal data will be provided in the form requested by the Data Subject, which may be electronic, by post or by providing the information in person.
- Right to rectification
Upon the Data Subject’s written request, the Controller shall rectify inaccurate personal data specified by the Data Subject in writing without undue delay and complete incomplete data with the content specified by the Data Subject. The Controller shall inform every recipient to whom the personal data were disclosed of the rectification or completion, unless this proves impossible or involves disproportionate effort. At the Data Subject’s written request, the Controller shall inform them of those recipients.
- Right to restriction of processing
The Data Subject has the right to obtain restriction of processing where one of the following applies:
- the accuracy of the personal data is contested, in which case the restriction shall apply for the period enabling us to verify the accuracy of the personal data (where verification is not necessary, no restriction will be applied);
- the processing is unlawful and the Data Subject opposes the erasure of the personal data and requests the restriction of their use instead;
- we no longer need the personal data for the stated processing purpose, but the Data Subject requires them for the establishment, exercise or defence of legal claims;
- the Data Subject has objected to processing based on our legitimate interests (in this case, processing must be restricted pending verification whether our legitimate interests override the Data Subject’s legitimate grounds).
Where processing has been restricted, such personal data, with the exception of storage, may be processed only with the Data Subject’s consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State. The Controller shall inform the Data Subject at whose request processing has been restricted before the restriction is lifted.
- Right to erasure – right to be forgotten
The Data Subject has the right to have personal data concerning them erased by the Controller without undue delay upon request where one of the following grounds applies:
- the personal data are no longer necessary in relation to the purposes for which the Controller collected or otherwise processed them;
- the Data Subject withdraws consent and there is no other legal ground for the processing;
- the Data Subject objects to processing based on legitimate interests and there are no overriding legitimate grounds (i.e. legitimate interests) for the processing;
- the personal data have been unlawfully processed and this has been established following a complaint;
- the personal data must be erased for compliance with a legal obligation in Union or Member State law to which we are subject.
Where the Controller has made personal data concerning the Data Subject public for any lawful reason and is obliged to erase them on any of the grounds specified above, the Controller shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to inform other controllers processing the data that the Data Subject has requested the erasure of any links to, or copy or replication of, those personal data. As a general rule, however, the Controller does not make the Data Subject’s personal data public.
The Controller does not make the Data Subject’s personal data public.
- The right to erasure shall not apply where processing is necessary:
- for exercising the right of freedom of expression and information;
- for compliance with a legal obligation requiring processing under Union or Member State law to which we are subject (such as processing in connection with invoicing, since invoices must be retained by law), or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller;
for the establishment, exercise or defence of legal claims (e.g. where the Data Subject owes us a debt which has not yet been paid, or a consumer or data-processing complaint is pending).
- Right to object
The Data Subject may object, by a statement addressed to the Controller, to the processing of their personal data where the legal basis for the processing is
- the public interest referred to in Article 6(1)(e) GDPR; or
- the legitimate interests referred to in Article 6(1)(f) GDPR.
Where the right to object is exercised, the Controller shall no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the Data Subject, or which relate to the establishment, exercise or defence of legal claims. The Controller shall determine whether compelling legitimate grounds justify the processing and shall inform the Data Subject of its position in a written statement.
The Data Subject may object to the processing of their personal data only by submitting a written request, which must be sent to the Controller by e-mail or post.
- Right to data portability
Where processing is necessary for the performance of a contract or is based on the Data Subject’s consent, the Data Subject has the right to request that the data provided by the Data Subject to the Controller be provided in a machine-readable format. The Controller shall provide the data to the Data Subject in XML, JSON or CSV format and, where technically feasible, the Data Subject may request that the Controller transmit the data in one of the formats specified above to another controller.
In all cases, this right is limited to data provided directly by the Data Subject; other data cannot be made portable (e.g. statistics, etc.).
The Data Subject’s personal data held in the Controller’s systems:
- may be received in a structured, commonly used and machine-readable format;
- may be transmitted to another controller;
- may be transmitted directly to another controller at the Data Subject’s request, where this is technically feasible in the Controller’s systems.
The Controller shall comply with a request relating to data portability only on the basis of a written request submitted by e-mail or post. To process the request, the Controller must satisfy itself that the Data Subject entitled to exercise the right is indeed the person making the request. In exercising this right, the Data Subject may request portability only of data provided by the Data Subject to the Controller. Exercising this right does not automatically result in deletion of the data from the Controller’s systems; therefore, following exercise of this right, the data will remain recorded in the Controller’s systems unless the Data Subject also requests their erasure.
- Remedies
The Data Subject may exercise their rights by submitting a written request by e-mail or post.
The Data Subject cannot exercise their rights if the Controller demonstrates that it is not in a position to identify the Data Subject. If the Data Subject’s request is manifestly unfounded or excessive (in particular because of its repetitive character), the Controller may charge a reasonable fee for complying with the request or refuse to act on the request. The burden of proof lies with the Controller. If the Controller has doubts as to the identity of the natural person making the request, it may request additional information necessary to confirm the requester’s identity.
Pursuant to the Hungarian Act on Information Self-Determination and Freedom of Information, the GDPR and the Civil Code (Act V of 2013), the Data Subject may
- contact the National Authority for Data Protection and Freedom of Information (1055 Budapest, Falk Miksa u. 9–11.; www.naih.hu); or
- enforce their rights before the courts. At the Data Subject’s option, proceedings may also be brought before the regional court having jurisdiction according to the Data Subject’s place of residence (the list and contact details of the regional courts are available at the following link: http://birosag.hu/torvenyszekek).
- TIME LIMIT FOR COMPLYING WITH REQUESTS
The Controller shall inform the Data Subject of the measures taken without undue delay and in any event within one month of receipt of any request referred to in section 6. Where necessary, taking into account the complexity and number of requests, this period may be extended by a further two months; in such case, the Controller shall inform the Data Subject of the extension and the reasons for the delay within one month of receipt of the request, and shall also inform the Data Subject of their right to lodge a complaint with the supervisory authority and to seek a judicial remedy.
If the Data Subject’s request is manifestly unfounded or excessive (in particular because of its repetitive character), the Controller may charge a reasonable fee for complying with the request or refuse to act on the request. The burden of proof lies with the Controller.
If the Data Subject submitted the request electronically, the Controller shall provide the information electronically, unless the Data Subject requests otherwise.
The Controller shall inform every recipient to whom the personal data were disclosed of any rectification, erasure or restriction of processing carried out by the Controller, unless this proves impossible or involves disproportionate effort. At the Data Subject’s request, the Controller shall inform them of those recipients.
- HANDLING OF PERSONAL DATA BREACHES
A personal data breach is a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. The Controller maintains a register for the purpose of monitoring measures taken in relation to personal data breaches, informing the supervisory authority and informing Data Subjects; the register contains the categories of personal data affected by the breach, the categories and number of Data Subjects affected, the time and circumstances of the breach, its effects and the measures taken to remedy it. In the event of a breach, the Controller shall notify the supervisory authority without undue delay and, at the latest, within 72 hours (Article 33 GDPR), unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. The Controller shall inform the Data Subject of the personal data breach without undue delay where it is likely to result in a high risk to the rights and freedoms of natural persons (Article 34 GDPR).
- OTHER PROVISIONS
The Controller reserves the right to amend this Privacy Policy unilaterally, with prior notice to the Data Subject, in particular, but not exclusively, in the event of changes in legislation. The amendments shall enter into force vis-à-vis the Data Subject on the date specified in the notice, unless the Data Subject objects to the amendments.
If the Data Subject provides the personal data of a third party for the purpose of using the service and thereby causes damage in any way, the Controller shall be entitled to enforce a claim for damages against the Data Subject.
The Controller does not verify the personal data provided to it. The person providing the data is solely responsible for their accuracy. When providing any Data Subject’s personal data, the person providing them simultaneously assumes responsibility that the data provided are true, that they are their own personal data and that only they use the service using those data.
The Controller reserves the right to amend this Privacy Policy in a manner that does not affect the purposes or legal bases of the processing.
However, if we intend to carry out further processing of the collected data for a purpose other than that for which they were collected, before carrying out the further processing we will inform you of the purpose of the processing and of the following information:
- the period for which the personal data will be stored or, where this is not possible, the criteria used to determine that period;
- your right to request access to personal data concerning you, their rectification, erasure or restriction of processing, and, where processing is based on legitimate interests, to object to the processing of the personal data, as well as, where processing is based on consent or a contractual relationship, to request the right to data portability;
- where processing is based on consent, that you may withdraw your consent at any time;
- your right to lodge a complaint with the supervisory authority;
- whether the provision of personal data is based on a statutory or contractual obligation or is a prerequisite for entering into a contract, and whether you are obliged to provide the personal data and the possible consequences of failing to provide them;
- information about the existence of automated decision-making (where such a procedure is used), including profiling, and, at least in such cases, meaningful information about the logic involved and the significance and envisaged consequences of such processing for you.
The processing may only then be commenced by the Controller; where the legal basis for the processing is consent, you must also give your consent to the processing in addition to receiving the information.
If you have any further questions or encounter any problems in relation to the processing of personal data, please e-mail info@livepoint.hu.info@livepoint.hu