Purpose of the privacy notice
Marketing Astro Ltd. (2161 Csomád, Kossuth Lajos út 79., hereinafter referred to as the “service provider”, “data controller”) as the data controller, acknowledges the contents of this legal notice as binding. It undertakes to ensure that all processing of data related to its activities complies with the requirements set out in this Policy and the applicable national legislation and European Union acts.
The Data Controller reserves the right to change this information at any time. It will of course inform its audience of any changes in due time.
If you have any questions about this communication, please contact us and we will answer them.
The Data Controller is committed to protecting the personal data of its customers and partners, and attaches great importance to respecting the right to information self-determination of its customers. The Data Controller handles personal data confidentially and takes all security, technical and organisational measures to ensure the security of the data.
The Data Controller describes its data management practices below.
Data of the controller
If you wish to contact our Company, you can contact the data controller at firstname.lastname@example.org and +36303703411.
The Data Controller deletes all emails received by it, including the email address, name, telephone number and personal data, after a maximum of 5 years from the date of the communication.
Name: Marketing Astro limited liability company
Registered office: 2161 Csomád, Kossuth Lajos út 79.
Company registration number: 13-09-210700
Name of the registering court: Fővárosi Cégbíróság
Tax number: 25149205-2-13
Phone number: +36303703411
Data Protection Officer
Name: Előd Czakó
Phone number: +36303703411
Scope of personal data processed
Personal data to be provided during registration: name, email address, telephone number
The Data Controller shall select and operate the IT tools used to process personal data in the course of providing the service in such a way that the processed data:
- accessible to authorised persons (availability);
- authenticity and verification (authenticity of data processing);
- can be verified to be unchanged (data integrity);
- be protected against unauthorised access (data confidentiality).
The Controller shall take appropriate measures to protect the data against unauthorised access, alteration, disclosure, disclosure, erasure or destruction and against accidental destruction.
The Data Controller shall ensure the security of data processing by technical, organisational and institutional measures that provide a level of protection appropriate to the risks associated with the processing.
The Data Controller shall retain in the course of processing.
- confidentiality: it protects information so that only those who are entitled to it have access to it;
- integrity: it protects the accuracy and completeness of the information and the method of processing;
- availability: ensuring that when the authorised user needs it, he or she can actually access the information and has the means to do so.
What cookies do
- collect information about visitors and their devices;
- remember visitors’ individual preferences, which are used, for example, when making online transactions, so they do not need to be re-entered;
- make the website easier to use;
- provide a quality user experience.
In order to provide a personalised service, a small piece of data called a cookie is placed on the user’s computer and read back during a subsequent visit. When the browser returns a previously saved cookie, the cookie provider has the possibility to link the user’s current visit to previous visits, but only in relation to its own content.
Duration of processing
For more information on the retention period of a cookie, click here:
Google general cookie notice:
Google Analitycs brochure: https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage?hl=hu
Facebook information: https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen
Legal background and legal basis for cookies:
The legal basis for processing is your consent pursuant to Article 6(1)(a) of the Regulation.
Main features of the cookies used by the website:
Strictly necessary cookies: these cookies are essential for the use of the website and allow you to use its essential functions. Without them, many of the site’s features will not be available to you. The lifetime of these types of cookies is limited to the duration of the session.
Cookies to improve your user experience: these cookies collect information about your use of the website, such as which pages you visit most often or what error messages you receive from the website. These cookies do not collect any information that identifies the visitor, i.e. they are completely generic and anonymous. We use the information they provide to improve the performance of the website. The lifetime of these types of cookies is limited to the duration of the session.
Third-party cookies (analytics)
Remarketing cookies: may appear to previous visitors or users when browsing other sites on the Google Display Network or searching for terms related to your products or services.
Session cookie: these cookies store the visitor’s location, browser language, payment currency, and their lifetime is until the browser is closed or for a maximum of 2 hours.
Mobile version, design cookie: detects the device the visitor is using and switches to full view on mobile. Lifetime 365 days.
Cookie acceptance cookie: when you arrive at the site, you will be prompted to accept the cookie storage statement in the warning window. The cookie has a lifetime of 365 days.
- Internet Explorer: http://windows.microsoft.com/en-us/internet-explorer/delete-manage-cookies#ie=ie-11
- Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer
- Mozilla: https://support.mozilla.org/hu/kb/weboldalak-altal-elhelyezett-sutik-torlese-szamito
- Safari: https://support.apple.com/kb/ph21411?locale=en_US
- Chrome: https://support.google.com/chrome/answer/95647
Online ordering data: name, email address, telephone number, company name
Data related to the newsletter
Data processing activities related to the sending of newsletters
Name of company operating the mailing system: ActiveCampaign, LLC
The company operating the mailing system is located at 1 North Dearborn St, 5th Floor, Chicago, IL 60602
Phone number of the company operating the mailing system: +1 (800) 357-0402
Email address of the company operating the mailing system: –
The Data Processor contributes to the sending of newsletters on the basis of a contract with the Data Controller. In doing so, the Data Processor processes the name and email address of the data subject to the extent necessary to send the newsletter.
Users can subscribe to the newsletter via marketingastro.com or other landing pages. On these platforms, by filling in a form, the user’s data is uploaded to the newsletter sender’s database via a so-called API connection. Another option is manual uploading where a colleague manually enters the data.
Users can unsubscribe from the newsletter by clicking on the unsubscribe link in the newsletter.
Purpose, method and legal basis of processing
General data processing policy
The data processing of the Data Controller’s activities is based on voluntary consent or on legal authorisation. In the case of processing based on voluntary consent, data subjects may withdraw their consent at any time during the processing.
In certain cases, the processing, storage and transmission of some of the data provided is required by law, and we will notify our customers separately.
The attention of the Data Controller is drawn to the fact that if the data subject does not provide his/her own personal data, the data subject is obliged to obtain the consent of the data subject.
Its data management principles comply with the applicable data protection legislation, in particular:
- Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (Infotv.);
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Regulation (EC) No 95/46/EC (General Data Protection Regulation, GDPR);
- Act V of 2013 – on the Civil Code (Civil Code);
- Act C of 2000 – on Accounting (Accounting Act);
- Act LIII of 2017 – on the Prevention and Combating of Money Laundering and Terrorist Financing (Pmt.);
- Act CCXXXVII of 2013 – on Credit Institutions and Financial Undertakings (Hpt.).
Physical storage locations of data
Your personal data (i.e. data that can be associated with you personally) may be processed by us in the following ways: on the one hand, technical data relating to the computer, browser program, Internet address and pages visited in connection with the Internet connection are automatically generated in our computer system, and on the other hand, you may provide us with your name, contact details or other data if you wish to contact us personally when using the website.
Data transfers, data processing, data subjects
Name of data processor: Facebook Ireland Limited
Seat of the data processor: Hanover Reach, 5-7 Hanover Quay, Dublin 2, Ireland
Telephone number of the data processor: +353 (0)1 553 0550
Email address of the data processor: email@example.com
Name of data processor: Google Inc.
Seat of the data processor: Amphitheatre Parkway, Mountain View, CA 94043, USA
Phone number of the data processor: 650-253-0000
Email address of the data processor: firstname.lastname@example.org
Name of the data processor: ActiveCampaign, LLC
Seat of the data processor: 1 North Dearborn St, 5th Floor, Chicago, IL 60602
Phone number of the data processor: +1 (800) 357-0402
Email address of the data processor: –
Name of the data processor: SiteGround Spain S.L.
Seat of the data processor: Calle de Prim 19, 28004 Madrid, Spain
Phone number of the data processor: +44 20 71839093
Email address of the data processor: email@example.com
The Data Processor contributes to the registration of orders on the basis of a contract with the Data Controller. In doing so, the Data Processor shall process the name, address, telephone number, number and date of orders of the data subject within the limitation period under civil law.
Rights and means of redress
During the period of processing, you have the following rights under the Regulation:
- the right to withdraw consent
- access to personal data and information on data management
- right to rectification
- restriction of processing,
- right to erasure
- right to protest
- the right to portability.
If you wish to exercise your rights, this will involve your identification and the Data Controller will need to communicate with you as necessary. Therefore, in order to identify you, you will be required to provide personal data (but the identification will only be based on data that the Controller already holds about you) and your complaints about the processing will be available on the Controller’s email account within the time period indicated in this Notice in relation to complaints. If you have been a customer of ours and would like to be identified for the purposes of complaint handling or warranty handling, please also provide your order ID for identification purposes. We can use this to identify you as a customer.
The Data Controller shall respond to complaints about data processing within 30 days at the latest.
Right to information
The Controller shall take appropriate measures to provide data subjects with all the information on the processing of personal data referred to in Articles 13 and 14 of the GDPR and each of the disclosures referred to in Articles 15 to 22 and 34 of the GDPR in a concise, transparent, intelligible and easily accessible form, in clear and plain language.
Right of access of the data subject
You have the right to receive feedback from the Data Controller as to whether or not your personal data is being processed and, if it is being processed, you have the right to:
- have access to the personal data processed; and
- the following information to be provided by the Data Controller:
- the purposes of the processing;
- the categories of personal data processed about you;
- information about the recipients or categories of recipients to whom or with which the personal data have been or will be disclosed by the Data Controller;
- the envisaged period of storage of the personal data or, if this is not possible, the criteria for determining that period;
- your right to request the Controller to rectify, erase or restrict the processing of personal data concerning you and to object to the processing of such personal data where the processing is based on legitimate interests;
- the right to lodge a complaint with a supervisory authority;
- if the data was not collected from you, any available information about its source;
- the fact of automated decision-making (where such a process is used), including profiling, and, at least in these cases, clear information about the logic used and the significance and likely consequences for you of such processing.
The purpose of exercising the right may be to ascertain and verify the lawfulness of the processing, and therefore, in the event of repeated requests for information, the Data Controller may charge reasonable compensation for the provision of information.
Access to personal data is provided by the Data Controller by sending you the personal data and information processed by email after you have identified yourself. If you are registered, we will provide access so that you can view and verify the personal data we process about you by logging into your account.
Please indicate in your request whether you want access to your personal data or information about data management.
Right of rectification
You have the right to have inaccurate personal data relating to you corrected by the Data Controller without delay upon your request.
Right to erasure
The data subject shall have the right, upon request and without undue delay, to obtain the erasure of personal data concerning him or her by the Data Controller on one of the following grounds:
- the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
- the data subject withdraws the consent on which the processing is based and there is no other legal basis for the processing;
- the data subject objects to the processing and there are no overriding legitimate grounds for the processing;
- the personal data have been unlawfully processed;
- the personal data must be erased in order to comply with a legal obligation under Union or Member State law to which the controller is subject;
- personal data are collected in connection with the provision of information society services.
The erasure of data may not be initiated if the processing is necessary: for the exercise of the right to freedom of expression and information; for compliance with an obligation under Union or Member State law to process personal data or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; for public health purposes or for archiving, scientific or historical research purposes or statistical purposes in the public interest; or for the establishment, exercise or defence of legal claims.
Right to restriction of processing
At the request of the data subject, the Data Controller shall restrict processing if one of the following conditions is met:
- the data subject contests the accuracy of the personal data, in which case the restriction is limited to the period during which
- which allows the accuracy of personal data to be verified;
- the data processing is unlawful and the data subject opposes the erasure of the data and requests instead the restriction of their use;
- the controller no longer needs the personal data for the purposes of processing, but the data subject requires them for the establishment, exercise or defence of legal claims; or
- the data subject has objected to the processing; in this case, the restriction applies for the period until it is established whether the legitimate grounds of the controller override those of the data subject.
Where processing is restricted, personal data, other than storage, may be processed only with the consent of the data subject or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or of an important public interest of the Union or of a Member State.
Right to data retention
If the processing is automated or if the processing is based on your voluntary consent, you have the right to request the Data Controller to receive the data you have provided to the Data Controller, which the Data Controller will make available to you in xml, JSON or csv format, and if technically feasible, you may request that the Data Controller transfer the data in this format to another data controller.
Right to object
The data subject shall have the right to object at any time, on grounds relating to his or her particular situation, to processing of his or her personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, or necessary for the purposes of the legitimate interests pursued by the controller or by a third party, including profiling based on those provisions. In the event of an objection, the controller may no longer process the personal data, unless there are compelling legitimate grounds for doing so which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.
Automated decision-making on individual cases, including profiling
The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
Right of withdrawal
The data subject has the right to withdraw his or her consent at any time.
Right to apply to the courts
The data subject may take the controller to court if his or her rights are infringed. The court shall rule on the case out of turn.
Data Protection Authority procedure
You can lodge a complaint with the National Authority for Data Protection and Freedom of Information:
- Name: National Authority for Data Protection and Freedom of Information
- Registered office: 1125 Budapest, Szilágyi Erzsébet fasor 22/C. Postal address: 1530 Budapest, Pf.: 5.
- Phone: 0613911400
- Fax: 0613911410
- Email: firstname.lastname@example.org Website: http://www.naih.hu
Information about data processing not listed in this notice is provided at the time of collection.
We inform our customers that the court, the prosecutor, the investigating authority, the law enforcement authority, the administrative authority, the National Authority for Data Protection and Freedom of Information, the National Bank of Hungary, or other bodies authorised by law may contact the data controller to provide information, to disclose or transfer data, or to provide documents.
The Data Controller shall disclose to public authorities, where the public authority has indicated the precise purpose and scope of the data, only such personal data as are strictly necessary for the purpose of the request and to the extent strictly necessary for the purpose of the request.
This document contains all relevant information on data management in connection with the operation of the webshop in accordance with the European Union’s General Data Protection Regulation 2016/679 (hereinafter referred to as the Regulation. GDPR) and the 2011 CXII. (hereinafter: Infotv.).