This document provides information about the data processing activities carried out by HR Global Invest Ltd. as data controller (hereinafter: "Controller"), through the website it operates (tarkino.com).
Please read the following information carefully.
In the course of operating the webshop maintained by the Controller (tarkino.com, hereinafter: "Webshop"), the Controller processes the personal data of data subjects who register on the Webshop, make purchases through it, and/or visit the website (hereinafter: "Data Subject," "Customer," "User"), in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: "Regulation," "GDPR"), as well as any applicable national data protection legislation.
The Controller hereby informs Data Subjects about the data processing activities necessarily associated with registration on the Webshop, purchases, the sending of newsletters, as well as the personal data it processes, the purpose of the processing, the retention period, the manner of storage and transfer of the data, the principles and practices followed in the processing of personal data, and the ways and means by which Data Subjects can exercise their rights.
The Controller reserves the right to unilaterally amend this document at any time.
The controller of the data published on the Webshop is HR Global Invest Ltd., as data controller:
Purpose of processing: Collecting the data necessary for purchasing through the Webshop, for fulfilling orders placed by Data Subjects as customers, and, in the case of a purchase, for obtaining the data necessary for issuing an invoice.
Legal basis of processing: The Data Subject's voluntary, informed, and explicit consent, given by ticking the checkbox displayed during registration, based on the information provided in this document (Article 6(1)(a) GDPR).
Categories of data processed: billing name, billing address (postal code, city, address), phone number, email address.
Until the Data Subject withdraws their consent, which the User may request by sending a request to the contact details specified under Section 2.
Please note that if you make a purchase through the Webshop, the invoices issued in connection with that purchase (and thus the personal data they contain) will continue to be retained as set out below.
Place of processing: IT equipment located at the Controller's premises.
Method of storage: electronic.
Processor:
Legal basis of processing: The processing is necessary for the performance of a contract to which the Data Subject is party (Article 6(1)(b) GDPR). Once the sales contract between the parties has been fulfilled (the Data Subject as buyer has paid the purchase price, and the Controller as Seller has delivered the ordered product to the buyer, who has accepted it), the legal basis for processing is the applicable national accounting legislation implementing EU requirements on the retention of accounting records.
Categories of data processed: billing name, email address, phone number, billing address (postal code, city, address), shipping address (postal code, city, address).
Retention period: Under applicable national accounting legislation, until the last day of the 8th year following the year in which the invoice was issued.
Place of processing: IT equipment located at the Controller's premises; for paper-based documents and invoices, the Controller's archive.
Data transfers: The data covered by the processing described in this section is transferred to the following recipients:
Controller:
HR Global Invest Ltd., Registered office: 1195 Budapest, Batthyány u. 26., Hungary
Purpose of transfer: home delivery of ordered products; delivery of digital products to the customer's email address.
Categories of data transferred: the customer data shown on the invoice (name, shipping and billing address).
Legal basis for the transfer: the transfer is necessary for the performance of a contract to which the Data Subject is party.
Processors:
a)
Magyar Posta Zrt., registered office: 1138 Budapest, Dunavirág utca 2-6., Hungary, company registration no.: 01 10 042463
Processing activity carried out: home delivery of ordered products
b)
K-BOSS Kft., registered office: 1031 Budapest, Záhony utca 7., Hungary, company registration no.: 01 09 303201
Processing activity carried out: provision of the system required for issuing electronic invoices
c)
Shopify Inc., 151 O'Connor Street, Ottawa, ON K2P 2L8, Canada (with EU-based sub-processing infrastructure)
Processing activity carried out: webshop platform and hosting services. Shopify processes personal data in accordance with its own data processing terms and appropriate safeguards for international data transfers under the GDPR.
d)
GLS General Logistics Systems Hungary Kft., registered office: 2351 Alsónémedi, GLS Európa utca 2., Hungary, company registration no.: 13 09 111755
Processing activity carried out: home delivery of ordered products
e)
Express One Hungary Kft., registered office: 1239 Budapest, Európa utca 12., Hungary, company registration no.: 01 09 980899
Purpose of processing: Recording the User's orders placed through the Webshop, confirming, fulfilling, and delivering orders, issuing invoices and receipts for purchases, and complying with the Controller's recordkeeping and documentation obligations.
In accordance with applicable EU and national legislation on electronic commercial communications and direct marketing (in particular Directive 2002/58/EC on privacy and electronic communications, as implemented in national law), the User may give prior and explicit consent for the Controller, as service provider, to contact them with promotional offers and other communications at the contact details provided by the Data Subject. In addition, having regard to the provisions of this notice, the Data Subject may consent to the Controller processing the personal data necessary for sending such promotional offers.
The Controller does not send unsolicited promotional messages, and the User may unsubscribe from newsletters at any time, free of charge and without restriction or justification. In such a case, the Controller will delete from its records all personal data necessary for sending promotional messages and will no longer contact the User with further promotional offers. Users may unsubscribe from newsletters by clicking the link included in the message.
Within the framework of this notice, please note that the Controller, as well as the Controller's delivery partners engaged for the performance of the contract, and other processors engaged for the performance of the contract (K-BOSS Kft., https://www.szamlazz.hu), may send system messages, order and registration confirmations, delivery-related information, and electronic invoices to Users via electronic and SMS messages, in connection with the performance of the contract and the operation of the Webshop, to the email address provided by the User. Please note that such messages do not qualify as promotional messages and are therefore not subject to the legislation on direct marketing communications; accordingly, the Data Subject's consent is not required for them. For this reason, the following sections of this notice do not apply to such messages.
Purpose of processing: sending promotional electronic email messages to the Data Subject; providing information about current news, products, and promotions.
Legal basis of processing: the Data Subject's voluntary, informed, and explicit consent, given by clicking the hyperlink contained in the confirmation email sent following newsletter sign-up, based on the information provided in this document (Article 6(1)(a) GDPR).
Categories of data processed: last name, first name, email address.
Retention period: until the Data Subject withdraws their consent, which can be done by clicking the unsubscribe link at the bottom of the newsletter.
Place of processing: IT equipment located at the Controller's premises and at the premises of the processors engaged by the Controller.
Method of storage: electronic.
Data transfers: no transfer of the data covered by this section takes place.
Possible consequences of not providing data: informational messages relating to discounts and promotions can only be sent once the Data Subject's data and consent have been provided.
The Controller hereby informs the User that when certain parts of the website are downloaded, the web server automatically places small data files, so-called cookies ("Cookie"), on the User's device, which are then read back on subsequent visits. In certain cases, under the GDPR, these data files qualify as personal data, since when the browser sends back a previously stored cookie, the service provider managing the cookie is able to link the User's current visit with previous ones — but only with respect to its own content.
In addition, the Controller uses Google Analytics for statistical data collection purposes, which places cookies in your browser and thereby sends data to the Controller about what you have viewed on the site. These cookies do not store personal data; they are used to track what the Data Subject has done on the website.
The Controller also uses the online advertising program Google Ads, and, within that framework, makes use of Google's conversion tracking service. When this is used, if a User reaches a website via a Google ad, a cookie necessary for conversion tracking is placed on their computer. These cookies do not contain any personal data, so the User cannot be identified through them.
The placement of these last two types of cookies is based on the User's consent, so they are only placed once such consent has been given, which the Data Subject provides by clicking the "I Accept" button in the pop-up window. If you do not wish to participate in data collection by Google Analytics or conversion tracking by Google Ads, you can decline this by not giving your consent to the installation of these cookies in your browser.
Purpose, categories, and retention periods of the Cookies used by the Controller:
| Type of Cookie | Purpose of Use | Retention Period | Is Consent Required? |
|---|---|---|---|
| Google Analytics (cookies named _ga, _gat, _gid) | The Webshop's website uses Google Analytics to collect information and perform analysis on how the User accesses and uses the Webshop. This information is used to generate reports and helps improve the Webshop. Data collection — including the number of Webshop users, where the User came from, and which pages they visited within the Webshop — takes place anonymously. The collected data cannot be traced back to the User. More information on Google's privacy policies is available here. | Google Analytics first-party cookies are created when the User visits the webshop, since the Google Analytics tracking code has been installed on our site. The Cookies are stored on the User's device for a maximum of 2 years from the time indicated above. More information on this can be found by clicking here. | Yes, by clicking the "I Accept" button, the Data Subject consents to the placement of the cookie. |
| Google Ads (Google Remarketing) | A number of third-party providers, including Google, store data on the User's previous visits to the Webshop and use this information to display the Controller's ads when the User visits a website belonging to one of Google's partners. During your visit to the Website, one or more Cookies provided by Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA) are sent to the User's computer, enabling the User's browser to be uniquely identified. Google remarketing Cookies are used through the Google Ads advertising system. With the help of Cookies provided by Google, the fact and time of the visit to the Webshop, as well as which subpages of the Webshop the User viewed during the visit, are recorded. The data thus recorded is stored anonymously. Users can disable Google's remarketing Cookies on Google's ad settings page for disabling cookies, and can also disable third-party providers' cookies on the Network Advertising Initiative's opt-out page. | Ads cookies are stored for 90 days following the User's visit to the Webshop. | Yes, by clicking the "I Accept" button, the Data Subject consents to the placement of the cookie. |
| Session identifier (cookie named PHPSESSID) | Session cookies allow the Webshop to recognize the User, so the User does not have to re-enter data already provided. | Information is stored until the end of the current session. A session refers to the duration of the User's visit to the Webshop. Once the session ends, the collected data is no longer accessible. | No, placement of this cookie does not require the Data Subject's consent. |
| Persistent Cookies | To achieve a better user experience, the Controller uses persistent cookies (e.g., optimized site navigation, retaining specified language settings). | These cookies are stored for a longer period in the browser's cookie file. The duration depends on the settings applied by the Data Subject in their internet browser. | Yes, by clicking the "I Accept" button, the Data Subject consents to the placement of the cookie. |
The User may accept or reject the use of Cookies on a case-by-case basis, or may reject the use of all Cookies through the appropriate browser settings. More information on this and on Cookies in general is available at: https://www.youronlinechoices.eu/. If the User chooses to disable Cookies, certain pages of the Website may only be accessible to a limited extent, and certain functions or services of the Website may not work properly.
Purpose of processing: identifying users and distinguishing between them, identifying user sessions, storing data provided during a session, preventing data loss, identifying users, conducting web analytics measurements, ensuring the proper operation of the Website, enhancing user experience, and displaying advertisements to Users.
Legal basis of processing: the Data Subject's consent, given by clicking the "I Accept" button on the pop-up cookie notice, based on the appropriate information provided in this notice (Article 6(1)(a) GDPR).
Categories of data processed: identification number, date, time, and the previously visited page.
Method of storage: electronic.
Data transfers: no data transfer takes place.
Although, in our view, the data that comes to the Controller's knowledge in the course of the processing described in this section does not qualify as personal data, for the sake of complete transparency we wish to record that the Controller collects and stores, in aggregated form and not suitable for identifying individual users, statistical information relating to User activity on the site, by means of logging within its own system. The log includes, among other things, the IP address of the Data Subject's computer, the time of use, and the user's activity. The Controller does not disclose this data to third parties and may use the contents of the log solely for its own analytical purposes, to improve user experience, and for the technical development of its IT systems.
Please note that the Webshop contains links that lead to other websites. The use of such external websites is governed by that website's own privacy policy, and once you click on an external link or the corresponding button, the Controller is no longer able to influence the collection, storage, or processing of personal data.
The Controller respects the rules on the security of personal data, and both the Controller and any authorized processor implement all technical and organizational measures, and establish all procedural rules, necessary to give effect to the confidentiality and data-security requirements of the GDPR and applicable national legislation.
The Controller protects the data it processes with appropriate measures against unauthorized access, alteration, transfer, disclosure, deletion, or destruction, as well as against accidental destruction or damage.
In its data processing activities, the Controller safeguards:
a) confidentiality: it protects information so that only those authorized to do so can access it;
b) integrity: it protects the accuracy and completeness of information and of the method of processing;
c) availability: it ensures that when an authorized user needs it, they can indeed access the information they require, and that the related tools are available.
The Controller appropriately protects its IT systems and networks against computer fraud, espionage, fire and flood, as well as against viruses and computer break-ins. The operator ensures security through server-level and application-level protective procedures. The Controller monitors its systems in order to be able to record every security incident and provide evidence in the event of any security event. This system monitoring also makes it possible to check the effectiveness of the precautionary measures applied. The Controller requires and verifies compliance with its information-security measures based on the provisions of the contracts concluded with the processors it engages.
All personal information provided to the Controller by the Data Subject must be true, complete, and accurate in every respect.
The Data Subject may request information about the processing of their personal data, and may request the rectification of their personal data, as well as — except in the case of mandatory data processing — the erasure or withdrawal of their data, and may exercise their right to data portability and their right to object, in the manner indicated at the time the data was collected, or through the Controller's contact details set out above.
Right to information: The Controller takes appropriate measures to provide Data Subjects with all information referred to in Articles 13 and 14 GDPR concerning the processing of personal data, and all communications under Articles 15–22 and 34, in a concise, transparent, intelligible, and easily accessible form, using clear and plain language.
The right to information may be exercised in writing, through the contact details specified in Section 2 of this notice. Information may also be provided orally to the Data Subject upon request, following verification of their identity.
The Data Subject's right of access: The Data Subject has the right to obtain from the Controller confirmation as to whether personal data concerning them is being processed, and, where that is the case, to access the personal data and the following information: the purposes of the processing; the categories of personal data concerned; the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organizations; the envisaged period for which the personal data will be stored; the right to rectification, erasure, or restriction of processing and the right to object; the right to lodge a complaint with a supervisory authority; information regarding the source of the data; the existence of automated decision-making, including profiling, and meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the Data Subject. Where personal data is transferred to a third country or to an international organization, the Data Subject has the right to be informed of the appropriate safeguards relating to the transfer.
The Controller provides the Data Subject with a copy of the personal data undergoing processing. For any further copies requested by the Data Subject, the Controller may charge a reasonable fee based on administrative costs. At the Data Subject's request, the Controller provides the information in electronic form. The Controller provides this information within one month at the latest from receipt of the request.
Right to rectification: The Data Subject may request the rectification of inaccurate personal data concerning them processed by the Controller, and the completion of incomplete data.
Right to erasure: The Data Subject has the right to obtain from the Controller the erasure of personal data concerning them without undue delay where one of the following grounds applies:
Erasure cannot be requested where processing is necessary: for exercising the right of freedom of expression and information; for compliance with a legal obligation under EU or national law applicable to the Controller, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller; for reasons of public interest in the area of public health, or for archiving, scientific or historical research, or statistical purposes; or for the establishment, exercise, or defense of legal claims.
Right to restriction of processing: At the Data Subject's request, the Controller will restrict the processing where one of the following applies:
Where processing has been restricted, such personal data may, with the exception of storage, only be processed with the Data Subject's consent, or for the establishment, exercise, or defense of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the EU or a member state. The Controller will inform the Data Subject before the restriction of processing is lifted.
Right to data portability: The Data Subject has the right to receive the personal data concerning them, which they have provided to the Controller, in a structured, commonly used, machine-readable format, and to transmit that data to another controller.
Right to object: The Data Subject has the right to object, on grounds relating to their particular situation, at any time to the processing of personal data concerning them, where the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Controller, or where the processing is necessary for the purposes of the legitimate interests pursued by the Controller or a third party, including profiling based on these provisions. In the event of an objection, the Controller will no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the Data Subject, or unless the processing is necessary for the establishment, exercise, or defense of legal claims. Where personal data is processed for direct marketing purposes, the Data Subject has the right to object at any time to the processing of personal data concerning them for such purposes, including profiling, to the extent it is related to direct marketing. Where the Data Subject objects to processing for direct marketing purposes, the personal data will no longer be processed for such purposes.
Automated individual decision-making, including profiling: The Data Subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
The above right does not apply if the processing:
Right to withdraw consent: The Data Subject has the right to withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Procedural rules: The Controller will provide information to the Data Subject on the actions taken further to a request under Articles 15–22 GDPR without undue delay, and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of requests.
The Controller will inform the Data Subject of any such extension, together with the reasons for the delay, within one month of receipt of the request. Where the Data Subject makes the request by electronic means, the information will be provided by electronic means where possible, unless otherwise requested by the Data Subject.
If the Controller does not take action on the request of the Data Subject, it will inform the Data Subject without delay, and at the latest within one month of receipt of the request, of the reasons for not taking action, and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.
The Controller provides the requested information and communication free of charge. Where requests from a Data Subject are manifestly unfounded or excessive, in particular because of their repetitive character, the Controller may charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested, or may refuse to act on the request.
The Controller will communicate any rectification, erasure, or restriction of processing to each recipient to whom the personal data has been disclosed, unless this proves impossible or involves disproportionate effort. The Controller will inform the Data Subject about those recipients if the Data Subject requests it.
The Controller provides the Data Subject with a copy of the personal data undergoing processing. For any further copies requested by the Data Subject, the Controller may charge a reasonable fee based on administrative costs. Where the Data Subject has submitted the request electronically, the information will be provided in electronic format, unless otherwise requested by the Data Subject.
Compensation and damages: Any person who has suffered material or non-material damage as a result of an infringement of the Regulation has the right to receive compensation for the damage suffered from the Controller or the processor. A processor is liable for damage caused by processing only where it has not complied with obligations of the GDPR specifically directed to processors, or where it has acted outside or contrary to the Controller's lawful instructions.
Where more than one Controller or processor, or both a Controller and a processor, are involved in the same processing and are responsible for damage caused by the processing, each Controller or processor is held liable for the entire damage.
The Controller or processor is exempt from liability if it proves that it is not in any way responsible for the event giving rise to the damage.
Data protection supervisory proceedings: The Data Subject may lodge a complaint concerning the processing of their personal data with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), or with the competent supervisory authority of the EU member state of their habitual residence, place of work, or the place of the alleged infringement.
Name: National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság)
Registered office: 1125 Budapest, Szilágyi Erzsébet fasor 22/C., Hungary
Postal address: 1530 Budapest, Pf.: 5., Hungary
Phone: +36 1 391 1400
Fax: +36 1 391 1410
Email: ugyfelszolgalat@naih.hu
Website: http://www.naih.hu
Right to a judicial remedy: In the event of an infringement of their rights, the Data Subject may, irrespective of whether a complaint has been lodged, bring proceedings against the Controller before a court. The court will handle the matter as a priority.
If the User wishes to contact the Controller, they may do so using the contact details set out under Section 2 of this notice.