Data Controller
Name: STARK AUTÓ Kft.
Registered office: 1113 Budapest, Kökörcsin u. 11.
Company registration number: 01-09-399549
Tax number: 27828892-2-43
Phone number: +36 20 324 4615
E-mail address: info@starkauto.hu
The data management principles of STARK AUTÓ Kft., hereinafter referred to as the Company, are in accordance with the applicable Hungarian legislation on data protection and the legislation of the European Union, which the Company respects and complies with in all circumstances.
Definitions of terms
Personal data:
Any information relating to a natural person that can be used to identify that person, directly or indirectly, by name, other personal data, location, online identifier or natural physical, physiological, genetic, mental, economic, social characteristics.
Special categories of personal data:
Data revealing the natural person's origin, political opinions, religious or philosophical beliefs, trade-union membership, sex life, sexual orientation and health. The processing of these data is prohibited. Exceptions are provided for in the legislation. Medical examinations at the workplace, assessment of fitness for work, medical diagnosis, which personal data may only be processed by a professional subject to the professional secrecy obligations laid down by law.
Disclosure: Making data accessible to anyone.
Data visualisation: The marking of data with an identifier to distinguish it.
Data storage: To identify the data for further processing or permanent restriction.
EEA country: A Member State of the European Union and another State party to the Agreement on the European Economic Area, i.e. a State whose nationals enjoy the same status as nationals of a State party to the EEA Agreement under an international treaty concluded between the European Union and its Member States and a State not party to the Agreement on the European Economic Area.
Third country: Any state that is not an EEA state.
Data protection incident: Unlawful processing or processing of personal data.
Data management: Any operation or set of operations which is performed on personal data, irrespective of the procedure used. In particular, the collection, recording, organisation, structuring, storage, adaptation, alteration, use, consultation, consultation, disclosure, transmission or otherwise making available, disclosure, restriction, erasure or destruction of data.
Affected: Natural or legal persons whose personal data the company processes.
Data Controller: The enterprise and its management - in this case STARK AUTÓ Kft. - which determines the purposes and means of the processing of personal data. This is set out in this policy.
Data processor: The natural or legal person who processes personal data on behalf of the controller. The processor shall ensure that the DPO (if appointed) is involved in an appropriate and timely manner in all matters relating to the protection of personal data.
Data Protection Officer: The controller shall ensure that the DPO does not accept instructions from anyone in the performance of his or her duties, as he or she is directly accountable to the controller's top management - the company. The DPO may also perform other tasks, but it must be ensured that no conflict of interest arises from these tasks.
Addressee: The natural or legal person, public authority, agency or any other body with whom personal data are shared.
Data file: The set of data managed in a single registry system.
Data processing: Performing technical tasks related to data processing operations, regardless of the method and means used to perform the operations and the place of application.
Data destruction: Destroying and rendering permanently inaccessible the data or data media to which the data relate.
Data transmission: If the data is made available to a specified third party.
Data deletion: Making data unrecognisable in such a way that it is no longer possible to recover it.
Data storage: Making it impossible to transmit, access, disclose, transform, alter, destroy, erase, interconnect or coordinate and use the data permanently or for a specified period.
Third party: A natural or legal person other than the data subject, the controller or the processor.
Registration system: A set of personal data, structured in any way, which is accessible on the basis of specific identifiers.
Consent of the data subject: A clear, voluntary, specific and informed indication of the data subject's wishes, expressed in a statement or other means of confirmation.
Protest: A statement by the data subject objecting to the processing of his or her personal data and requesting the cessation of the processing or the erasure of the processed data.
Principles for the processing of personal data
Personal data must be processed lawfully and fairly and in a transparent manner for the data subject. Data must be collected for specified, explicit and legitimate purposes and processed in a way compatible with those purposes. The following are not considered incompatible with the original purpose: archiving in the public interest, scientific and historical, research, statistical purposes. The purposes of processing must be relevant and limited to what is necessary. The processing of personal data must be lawful and fair. It must be transparent and clear to natural persons how personal data relating to them are collected and used. The principle of transparency requires that the information relating to the processing of personal data be provided and that the purposes for which the data are collected be easily accessible and clearly and simply stated. The natural person should be informed of the risks, rules and safeguards and rights associated with the processing of personal data and how to exercise his or her rights in relation to the processing. It should also be ensured that the storage of personal data is limited to the shortest possible period of time. Personal data should be processed only if the purpose of the data processing cannot be achieved by other means. Inaccurate data should be corrected, deleted and security and confidentiality of the data should be ensured to prevent unauthorised access and use.
The Data Controller shall process the personal data that comes to its knowledge in accordance with the above principles.
Lawfulness of processing
The processing of personal data is lawful only if at least one of the following conditions is met:
Consent of the data subject: If the processing is based on consent, the controller must provide evidence that the data subject has given his or her consent to the processing of his or her personal data. This should preferably be recorded in a written statement. The data subject should have the right to withdraw his or her consent at any time, without prejudice to the lawfulness of the processing prior to the withdrawal of consent. In the case of a child under the age of 16, processing is lawful only if the consent has been given or authorised by the person having parental authority over the child. Where the processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into the contract. This legal basis may be applicable to processing necessary for the performance of a contract (e.g. a contract for the provision of a service, an employment contract, etc.)
The processing is necessary for the fulfilment of a legal obligation to which the controller is subject, in particular under tax, social security and labour law;
Necessary to protect the vital interests of the data subject or of another natural person;
The processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
Other: processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party;
Except where the interest overrides the fundamental rights of the data subject, in particular where the data subject is a child.
In addition to the consent of the data subject, processing is lawful if it is based on a legal provision.
CONTACT
The controller is responsible for the lawfulness of the instructions for the processing operations.
STARK AUTÓ Ltd. (the Company) processes personal data in order to fulfil its legal obligations - taxation, social security, labour code, etc., so the legal basis for the processing is provided.
For the purpose of invoicing the consideration resulting from the sale of products and the contract for the provision of services arising from the activities of the company, it processes personal data relating to the use of information society services which are necessary for the purposes of invoicing.
In addition to the above, for the purposes of providing the service, it processes personal data that are technically necessary for the provision of the service (e.g. delivery address, etc.). The company will provide information on this in the GTC.
The service user gives his/her consent to the transfer of his/her data to other service providers (third parties) cooperating with the service provider for the purposes for which the service provider is entitled to process the data. If the service provider's right to process the data for a particular purpose ceases, it shall notify the third party thereof. In the event of termination of the data processing right, the service provider shall delete the data of the service user.
The company's task is to ensure that the conditions set out in EU and Hungarian law are met:
which ensure the lawfulness of the collection of personal data; specify the type of personal data that are subject to processing; the data subjects and the entities with which the personal data may be communicated; also specify the limitations of processing, taking into account the law; the duration of the storage; and the possibility for the data subject to request the rectification of inaccurate data or the correction of completed data. If necessary, ensure the erasure of personal data on the restriction of processing. Ensure the personal and material conditions necessary for the processing. Arrange, through the Data Protection Officer, for the erasure of personal data where the processing is unlawful or where the data subject requests that the data be incomplete or inaccurate and cannot be lawfully rectified, provided that erasure is not excluded by law; monitor and take action where the purpose of the processing has ceased or the period of retention of the data specified by law has expired or where ordered by a court or the Data Protection Commissioner; ensure rectification and erasure through the Data Protection Officer, inform the data subjects and all those to whom the data were previously disclosed; the undertaking must examine the data subject's objection within 15 days by clearly suspending the processing. It shall inform the applicant in writing of the outcome of this procedure. If the objection is justified, the enterprise is obliged to terminate the processing and block the data. The objection and the action taken on it shall be notified to all those to whom the personal data were previously disclosed.
The controller is responsible for the processing, secure storage, modification, deletion and transmission of personal data within the scope of its activities and within the limits set by the controller, in accordance with the law.
DATA PROCESSOR
The Data Controller also uses data processors in a number of cases in connection with the provision of services.
The personal data processed in the processors' systems are governed by the processor's own privacy notice. The Company will use its best endeavours to ensure that the personal data transmitted to it are processed by processors in accordance with the law and used for the purposes specified by the Company.
STARK AUTÓ Kft. uses external data processors to perform the following tasks:
Accounting | Courier services | Legal advice | Web hosting services, administrator services | Website maintenance and development | Invoicing
Contact details of data processors:
| Company name | Headquarters |
|---|---|
| Dinacontax Ltd. | 2120 Dunakeszi, Erkel u. 22. |
| Hungarian Hosting Ltd. | 1132 Budapest, Victor Hugo utca 18-22. |
| Magyar Posta Zrt. | 1138 Budapest, Dunavirág u. 2-6 |
| GLS General Logistics Systems Hungary Csomag-Logisztikai Kft. | 2351 Alsónémedi, GLS Europa u. 2. |
| KBOSS.hu Ltd. | 1031 Budapest, Záhony utca 7. |
TYPES OF PROCESSING
Registration in the webshop, ordering:
The company may request the following data when using the webshop, registering, concluding a contract, which it processes within the limits of the law. The purpose of requesting the data is to identify those who have logged in to the webshop, to ensure and verify their rights and benefits, to modify - if necessary - their previously provided data, to simplify the ordering process, to improve the customer experience, to legally perform the tasks arising from the contract concluded. The data are processed on the basis of the data subject's voluntary consent. The duration of data processing is until the data subject's request for deletion, except for the data included in the invoices issued, which must be kept for at least 8 years in accordance with the applicable accounting legislation.
The data processed:
User name (online shop registration), Password (online shop registration), E-mail address, Phone number, Billing name, Billing address, Tax number (for company orders), Shipping address, Vehicle details (type, year, registration number, chassis number, engine number).
Request a quote:
When requesting a quotation, the company may ask for the following data, which it will process within the limits of the law. The purpose of requesting the data is to provide the customer with the most accurate information possible, to ensure that the customer receives the best possible price, and, if the quotation is accepted, to fulfil the terms of the quotation. The data are processed on the basis of the data subject's voluntary consent. The data are processed until their deletion at the request of the data subject, except for the data contained in the invoices issued, which must be kept for at least 8 years in accordance with the relevant accounting legislation.
The data processed:
E-mail address, Telephone number, Billing name, Billing address, Tax number (for company orders), Delivery address, Vehicle details (type, year, registration number, chassis number, engine number).
Cookies (cookies) on the website:
During visits to the website https://www.starkautoszerviz.hu operated by STARK AUTÓ Ltd., the Service Provider sends one or more cookies - i.e. small files containing a series of characters - to the visitor's computer, which will allow the visitor's browser to be uniquely identified. These cookies are provided by Google and are used through the Google Adwords system. These cookies are only sent to the visitor's computer when visiting certain sub-pages, i.e. they only store the fact and time of the visit to the sub-page in question, and no other information.
The use of the cookies sent in this way is as follows: external service providers (including Google) use these cookies to store if the Data Subject has previously visited the advertiser's website and, on this basis, display advertisements to the Data Subject on the websites of partners of external service providers, including Google. The Data Subject may opt out of Google cookies by visiting the Google advertising opt-out page. Once disabled, they will not receive personalised offers from the Service Provider. The purpose of the data processing is to improve the user experience, to measure the number of visits to the website and to produce related web analytics. The processing of data is based on voluntary consent by accepting the cookie policy when visiting the website. The data is processed until the browser settings of the party concerned are changed. In the relevant menu of the browsers, you can usually find a description of how to change the cookie settings (e.g. disable, enable).
Cookies used on this website:
Session cookie: session cookies are automatically deleted after the Data Subject's visit. These cookies are used to enable the Service Provider's Website to function more efficiently and securely, and are therefore essential to enable certain functions of the Website or certain applications to function properly.
Persistent cookie: persistent cookies are also used by the Service Provider to improve the user experience (e.g. to provide optimised navigation). These cookies are stored for a longer period of time in the browser's cookie file. The duration of this cookie will depend on the settings of the Data Subject's web browser.
A cookie used for a password-protected session.
Shopping cart cookie.
Security cookie.
External servers facilitate the independent measurement and auditing of the Site's traffic and other web analytics data (Google Analytics). The data controllers can provide the Data Subject with detailed information on the management of the measurement data.
Contact: www.google.com/analytics
If you do not want Google Analytics to measure the above data in the way and for the purposes described, please install a browser add-on to block this.
Online card payment:
The company uses the services of an external data processor to process the online card payment chosen by the data subject during the order process. The purpose of requesting data is to ensure the secure processing of the payment method chosen by the data subject. The processing of the data is carried out with the voluntary consent of the data subject by choosing the online payment method. The data are processed for the period of time specified by law.
The data processed:
Card type, Cardholder name and expiry date, Order ID, Currency and amount, Language, Payment ID.
Sending a newsletter:
The data subject can subscribe to the newsletter by filling in the relevant details on the company's website (www.starkautoszerviz.hu) at the bottom footer of the main page and clicking on the "Subscribe" button. The purpose of requesting the data is to provide the recipient with complete general or personalised information about the company's latest promotions, services and products. The processing of data is based on voluntary consent by subscribing to the "Newsletter" by any means. The data is recorded until the subscription to the newsletter is completed. The unsubscribe can be done by clicking on the unsubscribe link at the bottom of the newsletter, which the data subject can do at any time.
The data processed:
Name, E-mail address.
Social networking sites:
The company processes data voluntarily registered and publicly provided by the data subject on Facebook, Youtube, Instagram. The purpose of processing the data is to promote the company's products, services, promotions or to share the website itself or to increase the number of "liking" users. The processing of the data is carried out with the voluntary consent of the data subject, which he or she gives by ticking the "like" (follow) function on the social networking site. The data is processed until the "like" on the social networking site is withdrawn.
Links to external sites on the website
The company's website may also contain links to external websites that are not operated by the company and are merely for the information of visitors. The company has no control over the content and security of websites operated by partner companies and is therefore not responsible for them. You should review the privacy policy and data protection statement of the sites you visit before providing any form of information on those sites.
THE RIGHTS OF DATA SUBJECTS
You can contact the company at any time to exercise your rights to:
- Under the right of access, you can obtain information about the processing of your data and request a copy of the data processed;
- You can request the correction of inaccurate data or the correction of completed data (right to rectification);
- You also have the right to request the erasure of your personal data, and to have your personal data disclosed to other data controllers;
- You have the right to request restriction of processing (right to restriction of processing);
- You have the right to obtain your personal data in a commonly used readable format and to request the transfer of these data to another controller;
- You have the right to object to the processing (right to object);
- You have the right to withdraw your consent at any time for processing based on consent (this does not affect the lawfulness of the processing in the previous period);
- You have the right to complain to the supervisory authority;
- Upon request, you may request information about the scope of the data processed, the purpose, legal basis and duration of the processing, the name of the data processor; in the case of data transfers, the legal basis and the recipient of the data;
- You may request the rectification of your personal data if it is inaccurate;
- Upon request, if the data subject's legitimate interests are affected, he or she may request the blocking of the data.
Upon request, the controller shall inform the data subject of the identity of the recipients and the purposes for which the personal data have been obtained. The controller shall inform the data subject in writing as soon as possible after the request is made, but not later than 30 days. The information may be refused only if it is provided by law in the interests of the internal and external security of the State, defence, national security, prevention of crime or law enforcement, or for the protection of the rights of the data subject or of others. The controller shall state the reasons for the disclosure. The controller shall notify the DPO annually of any refused requests.
The data subject may object to the processing of his or her personal data if:
- the processing and transfer of personal data is necessary solely for the purposes of the exercise of the rights and legitimate interests of the controller or recipient. Unless the processing is required by law.
- Your personal data is used for direct marketing, public opinion research or scientific research.
The exercise of the right to object is guaranteed by law for the data subject, who can take the controller to court if his or her rights are infringed. If the controller infringes the data subject's privacy rights by unlawfully processing his or her data or by breaching data security requirements, the data subject may claim damages and, if he or she causes damage, must pay compensation.
Security of data processing
The controller pays particular attention to ensure a level of data security appropriate to the level of risk. Where necessary, it shall, where appropriate, implement data pseudonymisation and encryption and ensure the ability to restore access to and availability of personal data in the event of a physical or technical incident. The controller shall take measures to ensure that natural persons who have access to personal data may process the data only in accordance with the controller's instructions.
Data protection incident
The Contractor shall notify the data protection incident to the competent supervisory authority without delay and no later than 72 hours after the incident is detected. Exceptions to this rule shall be made where the personal data breach is unlikely to pose a risk to the rights, freedoms and misuse of data of natural persons. The notification shall describe the nature of the incident, the categories of data subjects and their approximate number. Further information, the name and contact details of the contact person and the likely adverse consequences of the incident should be disclosed. The undertaking shall keep a record of the data breach, indicating the facts surrounding it, its effects and the measures taken to remedy it. If the personal data breach is likely to result in a high risk to the rights of the natural person(s) concerned, the undertaking shall inform the data subject(s) of the personal data breach without delay.
The data subject need not be informed if one of the following conditions is met:
- The controller has implemented appropriate security measures and as a result the data have been rendered unintelligible to persons who are not authorised to access the personal data.
- Additional measures have been introduced to ensure the rights of data subjects.
- Providing information would require a disproportionate effort.
YOGORVOSLAT
The data subject may object to the processing of his or her personal data if:
- the processing or transfer of personal data is necessary solely for the fulfilment of a legal obligation to which the Service Provider is subject or for the purposes of the legitimate interests pursued by the Service Provider, the data recipient or a third party, unless the processing is required by law;
- the personal data are used or disclosed for direct marketing, public opinion polling or scientific research purposes;
- in other cases specified by law.
The enterprise shall examine the objection within the shortest possible time from the date of the request, but not later than 15 days, decide whether it is justified and inform the applicant in writing of its decision.
If the enterprise establishes that the data subject's objection is justified, it shall cease processing, including further collection and further transfer, and block the data, and notify the objection and the action taken on it to all those to whom it has previously disclosed the personal data concerned by the objection and who are obliged to take measures to enforce the right to object.
If the User does not agree with the decision taken by the Company, he/she may, within 30 days of its notification, take the matter to court. The User may take legal action against the Company in case of infringement of his rights. The right of appeal and complaint may be lodged with the National Authority for Data Protection and Freedom of Information (NAIH).
Right to complain:
If the data subject considers that the processing of his or her personal data infringes the applicable data protection rules, he or she has the right to lodge a complaint with the National Authority for Data Protection and Freedom of Information (NAIH).
Right to compensation:
The company must compensate the controller for the material or non-material damage caused by the breach of the General Data Protection Regulation (GDPR) or the legal acts adopted in accordance with it.
Other means of redress:
The data subject has the right to lodge a complaint on behalf of a supervisory authority, to judicial review, to bring an action, to enforce his or her right to compensation, to a non-profit organisation or association established in accordance with European Union law, which is established for the protection of the rights and freedoms of data subjects, and which pursues an aim of public interest.
Name and contact details of the supervisory authority:
Hungarian National Authority for Data Protection and Freedom of Information / mailing address: 1534 Budapest, PO Box 834; address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c; telephone: +36 (1) 391-1400; website: http://www.naih.hu; e-mail: ugyfelszolgalat@naih.hu /
The Privacy Policy will enter into force on 01.06.2024 and will remain in force until revoked or amended.
Sign up to never miss our news and updates!