Privacy Policy

1. General Principles

  • We collect and process personal data only in accordance with applicable laws.
  • We only transfer personal data to third parties with the consent of the data subject.
  • Under no circumstances do we sell the personal data we process to third parties.
  • We store the data as securely as possible.
  • We only send newsletters to those who have given their prior and explicit consent.
  • Data subjects may request access to, modification or deletion of the data stored about them at any time.

2. Details and contact information of our company (Controller, Service Provider]

Name of the data controller: PMG HUNGARY Kft.
Contact details of the data controller: 2030 Érd, Kossuth Lajos utca 122.
Phone: +36 70 285 7023
E-mail:@email
Web: https://www.pmghungary.hu
Tax number: 23806072-2-13

The service provider reserves the right to amend this Privacy Policy and will inform data subjects of any such changes in an appropriate manner. Information concerning data processing is published on the LINK GOES HERE website.

3. Definitions according to the GDPR (Regulation]

3.1. data subject/User: any identified or identifiable natural person who can be identified, directly or indirectly, on the basis of personal data;

3.2. personal data: any information relating to the data subject – in particular the name of the data subject, identification mark, and one or more elements of information characteristic of their physical, physiological, mental, economic, cultural or social identity – as well as any conclusion that can be drawn from such information concerning the data subject;

3.3. consent: a freely given, specific and informed indication of the data subject's wishes by which they signify their unambiguous agreement to the processing of personal data relating to them, either fully or for specific processing operations;

3.4. data controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes of the processing of data, makes and implements decisions concerning data processing (including the means used], or has them carried out by the data processor;

3.5. processing of personal data: any operation or set of operations performed on data, regardless of the procedure used, including in particular its collection, recording, organisation, storage, alteration, use, retrieval, transmission, disclosure, alignment or combination, blocking, deletion and destruction, as well as preventing further use of the data, making photographic, audio or video recordings, and recording physical characteristics suitable for identifying a person (e.g. fingerprint or palm print, DNA sample, iris image];

3.6. data transfer: making data available to a specified third party;

3.7. disclosure: making data available to anyone;

3.8. data deletion: rendering data unrecognisable in such a way that it can no longer be restored;

3.9. data processing: performing technical tasks related to data processing operations, regardless of the method and means used to perform the operations or the place of application, provided that the technical task is performed on the data;

3.10. data processor: the natural or legal person, public authority, agency or other body which processes data on the basis of a contract, including a contract concluded pursuant to a legal provision;

3.11. data protection incident: unlawful processing of personal data, including in particular unauthorised access, alteration, transmission, disclosure, deletion or destruction, as well as accidental destruction and damage.

4. Scope of the Data Processed, Purpose and Duration of Data Processing, and Data Processors

Type of Data ProcessedPurpose of Data ProcessingDuration of Data ProcessingLegal Basis for Data ProcessingProcessor of the Personal Data in Question
UsernameIdentification, registration.Until consent is withdrawnConsent of the data subject. 
PasswordSecure login to the user account.Until consent is withdrawnConsent of the data subject. 
NameCommunication and coordination regarding any questions that arise.Until consent is withdrawnConsent of the data subject. 
E-mail addressCommunication and coordination regarding any questions that arise.Until consent is withdrawnConsent of the data subject. 
Telephone numberCommunication and coordination regarding any questions that arise.Until consent is withdrawnConsent of the data subject. 
Billing name and addressIssuing a compliant invoice, concluding and subsequently performing the contract.We process the data for 5 years in accordance with the civil law limitation period.The issuance of an invoice is mandatory pursuant to Section 159 (1] of Act CXXVII of 2007 on Value Added Tax and must be retained pursuant to Section 169 (2] of Act C of 2000 on Accounting. 
Delivery name and addressEnabling home delivery.Until the ordered goods have been delivered.Performance of the contract. [Processing pursuant to Article 6 (1] (b] of the Regulation] 
Date of purchase/registrationProof of consent.Until the expiry of the limitation period following termination of data processingThis obligation is prescribed by Article 7 (1] of the Regulation. [Processing pursuant to Article 6 (1] (c] of the Regulation] 
IP address at the time of purchase/registrationProof of consent.Until the expiry of the limitation period following termination of data processingThis obligation is prescribed by Article 7 (1] of the Regulation. [Processing pursuant to Article 6 (1] (c] of the Regulation] 

Scope of data subjects: All data subjects who are registered on or purchase through the webshop website.

We share personal data solely with the third party indicated in the “Processor of the Personal Data in Question” column, for the purpose of fulfilling the obligations set out in the contract.

Details and Tasks of Data Processors Used in Data Processing

Hosting provider
Name: InfoNetfort Kft.
Address: 7900 Szigetvár, Szent István ltp 17. IV/25.
Phone: +36-30/530-2953
E-mail: @email
Web: www.netfort.hu
Tax number: 26648082-2-02
Company registration number: 02 09 084205

Accounting tasks
 

Courier service
 

Direct marketing, newsletter
Name:
Address:

4.1 Contact Form:

Type of Data ProcessedPurpose of Data ProcessingDuration of Data ProcessingLegal Basis for Data Processing
NameContacting usFor 90 days after the data subject's last contactConsent of the data subject when making contact
E-mail addressContacting usFor 90 days after the data subject's last contactConsent of the data subject when making contact
Telephone numberContacting usFor 90 days after the data subject's last contactConsent of the data subject when making contact
Other personal data provided by the data subject when making contact For 90 days after the data subject's last contactConsent of the data subject when making contact

Scope of data subjects: Persons who contact us by telephone, e-mail or through the contact form.

We do not share personal data with third parties.

5. Newsletter and Direct Marketing Activities

We only send newsletters to Users who have given their prior and explicit consent. Consent is provided using the “Newsletter subscription” form.

Type of Data ProcessedPurpose of Data ProcessingDuration of Data ProcessingLegal Basis for Data Processing
NameSending newslettersUntil withdrawal (unsubscribe].Consent of the data subject
E-mail addressSending newslettersUntil withdrawal (unsubscribe].Consent of the data subject
Date of consent and IP address of the data subject.Ability to prove consentUntil withdrawal (unsubscribe].This obligation is prescribed by Article 7 (1] of the Regulation.

Scope of data subjects: All data subjects subscribed to the newsletter.

Operator of the newsletter delivery system and processor of the data:
Name:
Address:

5.1 Procedure for Withdrawal of Consent (Unsubscribing]
The data subject may unsubscribe from the newsletter at any time and free of charge. Unsubscribing can be done using the link provided in the newsletters or by sending an e-mail to EMAIL ADDRESS GOES HERE the e-mail address.

6. Management of Cookies

6.1 What is a Cookie?

When visiting the website, the data controller uses so-called cookies. A cookie is a package of information consisting of letters and numbers that our website sends to the data subject's browser in order to save certain settings, make the website easier to use and help us collect certain relevant statistical information about our visitors. Cookies do not contain personal information and cannot be used to identify individual users. Cookies often contain a unique identifier – a secret, randomly generated string of numbers – which is stored by the data subject's device.
Some cookies expire when the website is closed, while others are stored on your computer for a longer period.

6.2. Legal Framework and Legal Basis for the Use of Cookies

Cookies typically used by online stores include “password-protected session cookies”, “shopping cart cookies” and “security cookies”, for which prior consent from data subjects is not required.

Fact of data processing and scope of data processed: Unique identification number, dates and times

Scope of data subjects: All data subjects visiting the website.

Purpose of data processing: Identification of users and tracking of visitors.

Legal basis for data processing: Consent of the data subject in accordance with Section 5 (1] (a] of the Info Act.

6.3 Duration of data processing and deadline for deletion: the website uses the following cookies:

  • Security cookies: __cfduid, _biz_flagsA, _biz_nA 3, _biz_pendingA, _biz_sid, _biz_uid
  • Google Analytics cookies: _ga, _gid
  • Cookies necessary for the proper use of the website:

Potential persons authorised to access the data: The data controller does not process personal data through the use of cookies.

Information on the rights of data subjects in relation to data processing: Data subjects may delete cookies in the Tools/Settings menu of their browsers, generally under the Privacy settings.
If a data subject does not accept the use of cookies, certain functions will not be available to them. Further information about deleting cookies can be found at the following links:
    • Internet Explorer: http://windows.microsoft.com/en-us/internet-explorer/delete-managecooki…
    • Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store…
    • Chrome: https://support.google.com/chrome/answer/95647?hl=en
    • Safari: https://support.apple.com/kb/ph21411?locale=en_US

7. Google Analytics

7.1. This website uses Google Analytics, a web analytics service provided by Google Inc. (\"Google\"). Google Analytics uses so-called \"cookies\", text files that are stored on your computer and help analyse the use of the website visited by the User.
7.2. The information generated by cookies relating to the website used by the User is generally transmitted to and stored on one of Google's servers in the USA. By activating IP anonymisation on the website, Google truncates the User's IP address beforehand within the Member States of the European Union or in other states that are parties to the Agreement on the European Economic Area.
7.3. Only in exceptional cases is the full IP address transmitted to and truncated on a Google server in the USA. On behalf of the operator of this website, Google will use this information to evaluate how the User has used the website, to compile reports on website activity for the website operator, and to provide other services related to website and internet use.
7.4. Within the framework of Google Analytics, Google does not combine the IP address transmitted by the User's browser with other Google data. The User can prevent cookies from being stored by appropriately configuring the browser; however, please note that in this case not all functions of this website may be fully usable. The User can also prevent Google from collecting and processing data generated by cookies relating to their use of the website (including the IP address] by downloading and installing the browser plugin available at the following link. https://tools.google.com/dlpage/gaoptout?hl=hu

8. Google AdWords Conversion Tracking and Remarketing

8.1. The data controller uses the online advertising programme called \"Google AdWords\" and also uses Google's conversion tracking service within this programme. Google conversion tracking is an analytics service provided by Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; \"Google\").
8.2. When the User reaches a website through a Google advertisement, a cookie required for conversion tracking is placed on their computer. These cookies have a limited validity period and do not contain any personal data, so the User cannot be identified through them.
8.3. When the User browses certain pages of the website while the cookie has not yet expired, Google and the data controller can see that the User clicked on the advertisement.
8.4. Each Google AdWords customer receives a different cookie, so cookies cannot be tracked through the websites of AdWords customers.
8.5. The information obtained using conversion tracking cookies is used to create conversion statistics for customers who have chosen AdWords conversion tracking. This enables customers to see the number of users who clicked on their advertisement and were redirected to a page with a conversion tracking tag. However, they do not receive any information that could be used to identify individual users.
8.6. If you do not wish to participate in conversion tracking, you can refuse it by disabling the installation of cookies in your browser. The data subject will then not be included in the conversion tracking statistics.
8.7. Further information and Google's privacy policy are available at: www.google.de/policies/privacy/

8.8. Google AdWords Remarketing

8.9. Data processing for remarketing purposes is carried out using cookies.

Data Processed
Data processed by the cookies specified in the Cookie Policy.
Duration of Data Processing
The data storage period of the given cookie; further information is available here:
Google general cookie information: https://www.google.com/policies/technologies/types/
Google Analytics information:
https://developers.google.com/analytics/devguides/collection/analyticsj…
Legal Basis for Data Processing
The voluntary consent of the data subject, given to the service provider through use of the website.

9. Rights of Data Subjects

9.1 Right to Information
At the request of the data subject, the Service Provider, as data controller, provides information about the data it processes and the data processed by processors commissioned by it, their source, the purpose, legal basis and duration of processing, the name and address of the data processor and its activities related to data processing, the circumstances and effects of any data protection incident and the measures taken to remedy it, as well as, in the case of data transfers, the legal basis and recipient of the transfer. The data controller provides the information in an understandable form and in writing upon request of the data subject as soon as possible and no later than 30 days from submission of the request. This information is free of charge if the person requesting the information has not submitted a request concerning the same category of data to the data controller during the current year. In other cases, the Service Provider may charge a fee.

9.2 Right to Rectification
The Service Provider rectifies personal data if it is inaccurate and accurate personal data is available to it.

9.3 Right to Restriction
The Service Provider restricts the processing of personal data if the data subject requests this or if, based on the available information, it can be assumed that deletion would harm the data subject's legitimate interests. Restricted personal data may only be processed for as long as the purpose of processing that prevented deletion of the personal data continues to exist. The Service Provider marks the personal data it processes if the data subject disputes its correctness or accuracy, but the inaccuracy or incorrectness of the disputed personal data cannot be clearly established.

9.4 Right to Erasure
The Service Provider deletes personal data if its processing is unlawful, the data subject requests it, the processed data is incomplete or incorrect – and this situation cannot be lawfully remedied – provided that deletion is not prohibited by law, the purpose of processing has ceased, the statutory retention period has expired, or deletion has been ordered by a court or by the National Authority for Data Protection and Freedom of Information.

9.5 Procedural Rules
The data controller has 30 days to delete, restrict or rectify personal data. If the data controller does not comply with the data subject's request for rectification, restriction or deletion, it shall communicate the reasons for the refusal in writing or, with the data subject's consent, electronically within 30 days. The Service Provider shall notify the data subject of the rectification, restriction, marking and deletion, as well as everyone to whom the data was previously transferred for data processing purposes. This notification may be omitted if, in view of the purpose of data processing, it does not prejudice the legitimate interests of the data subject.

9.6 Right to Object
The data subject may object to the processing of their personal data if

a] the processing or transfer of personal data is necessary solely for the fulfilment of a legal obligation applicable to the data controller or for the enforcement of the legitimate interest of the data controller, data recipient or third party, except where the processing is required by law;

b] in other cases defined by law.

The Service Provider shall examine the objection as soon as possible, but no later than 15 days after submission of the request, decide on its merits and inform the applicant of its decision in writing. If the data controller finds the data subject's objection to be justified, it shall cease the processing, including further data collection and transfer, restrict the data, and notify everyone to whom the personal data concerned by the objection was previously transferred about the objection and the measures taken as a result; they shall take the necessary measures to ensure the exercise of the right to object.

If the data subject disagrees with the decision made by the data controller, they may bring court proceedings within 30 days of being notified of the decision.

The Service Provider may not delete the data subject's data if its processing is required by law. However, the data may not be transferred to the data recipient if the data controller has agreed with the objection or if a court has established that the objection was justified.

9.7 Right to Data Portability
Where processing is carried out by automated means, or where processing is based on the data subject's
voluntary consent, the data subject has the right to request the data controller to provide the data that the data subject
has provided to the data controller, which the data controller shall make available in XML, JSON or CSV
format, if technically feasible; they may also request
that the data controller transfer the data in this format to another data controller.

9.8 Compensation and Solatium
The Service Provider shall compensate damage caused to others by unlawful processing of the data subject's data or by violating data security requirements. In the event of an infringement of the data subject's personal rights, the data subject may claim solatium (Civil Code, Section 2:52]. The data controller is also liable to the data subject for damage caused by the data processor. The data controller is exempt from liability if the damage was caused by an unavoidable reason outside the scope of data processing.

The data controller shall not compensate the damage, and solatium may not be claimed, to the extent that the damage or infringement of personal rights resulted from the intentional or grossly negligent conduct of the data subject.

9.9 Right to Bring Court Proceedings
If their rights are infringed, the data subject may bring court proceedings against the data controller. The court shall deal with the case as a matter of priority.

9.10 Complaint
A complaint may be lodged with the National Authority for Data Protection and Freedom of Information:

Name: National Authority for Data Protection and Freedom of Information
Registered office: 1125 Budapest, Szilágyi Erzsébet fasor 22/C.
Postal address: 1530 Budapest, P.O. Box 5, 1530 Budapest
Phone: +361/391-1400
Fax: +361/391-1410
E-mail: @email
Website: http://www.naih.hu

10. Data Security

The service provider designs and carries out data processing operations in a manner that ensures the protection of the privacy of data subjects.

The service provider and, within its area of activity, the data processor shall ensure data security, take the technical and organisational measures and establish the procedural rules necessary to enforce the provisions of the Info Act and other data and confidentiality protection rules.

The service provider protects the data through appropriate measures, in particular against unauthorised access, alteration, transmission, disclosure, deletion or destruction, accidental destruction and damage, as well as loss of accessibility resulting from changes in the technology used.

During data processing, the service provider maintains:
• confidentiality: protecting information so that only those authorised to access it can do so
• integrity: protecting the accuracy and completeness of information and the processing method
• availability: ensuring that when an authorised user needs it, they can actually access the requested information and that the related means are available.

The IT systems and network of the service provider and its partners involved in data processing
are protected against computer-assisted fraud, espionage, sabotage, vandalism, fire and flooding,
as well as computer viruses, computer intrusions and attacks resulting in denial of service,
from such attacks. The operator ensures security through server-level and application-level protection procedures
.

11. Applicable Legislation Used for this Privacy Policy

• Act CXII of 2011 – on informational self-determination and freedom of information (Info Act]
• Act V of 2013 – on the Civil Code (Civil Code]
• Act CLV of 1997 – on consumer protection (Consumer Protection Act]
• Act XIX of 1998 – on criminal proceedings (Act on Criminal Proceedings]
• Act CVIII of 2001 – on certain issues concerning electronic commerce services and information society services (E-Commerce Act]
• Act C of 2003 – on electronic communications (Electronic Communications Act]
• Act XLVIII of 2008 – on the basic conditions and certain limitations of economic advertising activity (Advertising Act]
• Recommendation of the National Authority for Data Protection and Freedom of Information on the data protection requirements of prior information
• GDPR, Regulation (EU) 2016/679 of the European Parliament and of the Council on the processing, protection and free movement of personal data of natural persons

25.03.2026.