Privacy Policy

PRIVACY NOTICE AND COOKIE MANAGEMENT

1. INTRODUCTION

This Privacy Policy (hereinafter: Policy) applies to the processing of personal data arising in the course of the operation of the https://pick.hu/en website of PICK SZEGED Plc. (hereinafter: Data Controller). The Data Controller pays special attention to the protection of personal data, compliance with mandatory legal provisions and safe and fair data management.

Data of the Data Controller:

Name: PICK SZEGED Co.
Mailing address: 6725 Szeged, Szabadkai út 18.
E-mail address: titkarsag@pick.hu  
Website: https://pick.hu/en  
Phone number: +36-62/567-000

This Policy has been prepared in particular on the basis of the following effective legislation:

  1. Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (hereinafter: Infotv.);
  2. Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (hereinafter: Ektv.);
  3. Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions of Commercial Advertising Activities (hereinafter: Commercial Advertising Act);
  4. Act C of 2003 on Electronic Communications (hereinafter: );
  5. Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as the Regulation).

This Policy is available from the following website: https://pick.hu/en/privacy-policy

The Data Controller reserves the right to amend this Policy, in which case the amendments to this Policy shall enter into force upon publication on the following page: https://pick.hu/en


2. INTERPRETATIVE PROVISIONS

The terms used in this Notice shall have the following meanings:

Data Subject: an identified or identifiable natural person (Article 4(1) of the Regulation). In this case, the visitors and users of the website.

personal data: any information relating to an identified or identifiable natural person 'data subject'; an identifiable natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, a number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (Article 4(1) of the Regulation);

"processing" means any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction (Article 4(2) of the Regulation);

restriction of processing: means the marking of stored personal data to restrict their future processing. (Article 4(3) of the Regulation);

profiling: any form of automated processing of personal data in which personal data are used to assess certain personal characteristics associated with a natural person, in particular to analyse or predict characteristics relating to performance at work, economic situation, state of health, personal preferences, interests, reliability, behaviour, location or movement (Article 4(4) of the Regulation);  

pseudonymisation: the processing of personal data in such a way that, without the use of additional information, it is no longer possible to determine which specific natural person the personal data relates, provided that such additional information is stored separately and it is ensured, by taking technical and organisational measures, that such personal data cannot be linked to identified or identifiable natural persons (Article 4(5) of the Regulation);

"filing system" means a set of personal data disaggregated in any way, whether centralised, decentralised or disaggregated by functional or geographical criteria, accessible on the basis of specific criteria (Article 4(6) of the Regulation);

"controller" means the natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of the processing are determined by Union or Member State law, the controller or the specific criteria for the designation of the controller may also be determined by Union or Member State law (Article 4(7) of the Regulation);

data processor: the natural or legal person, public authority, agency or any other body that processes personal data on behalf of the controller (Article 4(8) of the Regulation);

recipient: the natural or legal person, public authority, agency or any other body to whom the personal data is disclosed, whether or not it is a third party. Public authorities that may have access to personal data in the context of an individual investigation in accordance with Union or Member State law are not considered recipients; the processing of such data by those public authorities must comply with the applicable data protection rules in accordance with the purposes for which they are processed (Article 4 of the Regulation. point 9);

third party: a natural or legal person, public authority, agency or any other body which is not the same as the data subject, the controller, the processor or the persons authorised to process personal data under the direct control of the controller or processor (Article 4(10) of the Regulation);

consent of the data subject: a freely given, specific, well-informed and unambiguous expression of the data subject's will, by which the data subject indicates by means of a statement or an unambiguous affirmative act that he/she gives his/her consent to the processing of personal data concerning him or her (Article 4(11) of the Regulation);

personal data breach: a  breach of security that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed (Article 4(12) of the Regulation);

health data: personal data concerning the physical or mental health of a natural person, including data relating to the health services provided to a natural person, which carry information about the state of health of the natural person (Article 4 (15) of the Regulation);

'representative' means any natural or legal person established or resident in the Union and designated in writing by the controller or processor pursuant to Article 27 who represents the controller or processor with respect to the obligations incumbent on the controller or processor under this Regulation (Article 4(17) of the Regulation);

"enterprise" means any natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships and associations engaged in regular economic activity (Article 4(18) of the Regulation);

group of undertakings: the controlling undertaking and the undertakings controlled by it (Article 4(19) of the Regulation);

sensitive data: all data belonging to special categories of personal data (sensitive personal data) including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, as well as genetic data, biometric data aimed at uniquely identifying natural persons, health data and personal data concerning the sex life or sexual orientation of natural persons (Infotv. Section 3(3));

data transmission: means making data available to a specific third party (Infotv. Section 3, Point 11);

data disclosure to the public: means making data available to anyone (Infotv. Section 3, Point 12);

deletion of data: making data unrecognizable in such a way that their restoration is no longer possible (Infotv. Section 3 (13));

data destruction: the complete physical destruction of the data carrier containing the data (Infotv. Section 3, Point 16);

data processing: the totality of data processing operations performed by a data processor acting on behalf of or on the basis of the order of the data controller (Infotv. Section 3 (17));

data file: the totality of the data managed in a single register (Infotv. Section 3, Point 21);

EEA state: a Member State of the European Union and another State party to the Agreement on the European Economic Area, as well as a state whose citizen enjoys the same legal status as a national of a State party to the Agreement on the European Economic Area on the basis of an international agreement concluded between the European Union and its Member States and a State not party to the Agreement on the European Economic Area (Infotv. Section 3, Point 23); third country: any state that is not an EEA state (Infotv. Section 3, Point 24).

oral complaints: data processing is carried out pursuant to Article 6(1)(c) Regulation, as it is necessary for compliance with a legal obligation.


3. MANAGEMENT OF COOKIES

3.1. Purpose of data processing

The Data Controller  uses  so-called cookies (hereinafter referred to as: cookies) during the visit to the https://pick.hu/en  website. Cookies are a package of information consisting of letters and numbers, which the Data Controller's website sends to the users' browsers in order to save certain settings, facilitate the use of the Data Controller's website and contribute to the collection of some relevant, statistical information about the users. Cookies do not contain any personal information and are not suitable for identifying an individual user.

The purpose of data processing related to cookies is to identify and distinguish users, identify the current session of users, store the data provided during the session, prevent data loss, get to know the specification of the browser and increase the efficiency of the service. In order to provide the service, to control the operation of the service, and to prevent misuse, the Data Controller records the visitor data that are technically essential for the provision of the service.

The Data Controller does not connect the data generated during the analysis of the log files with any other information, and does not seek to identify the person of the visitor. Cookies often contain a unique identifier - a secret, randomly generated string of numbers - that is stored on the user's device. Some cookies are deleted after the website is closed, and some are stored on the user's computer for a longer period of time.

 

3.2. Types and use of cookies

3.2.1. Grouping cookies by their lifespan

A. session cookies

"Session cookies" are automatically deleted when the user exits the browser.

B. persistent cookies

"Persistent cookies", on the other hand, remain stored in the user's terminal device until a specified expiration date (minutes, days, years) is reached, or until they are manually deleted by the user.

 

3.2.2. Grouping cookies by origin

A. first-party cookies

The term "own cookies" is used as a reference to cookies that have been installed by the data controller (or any of its data processors) operating the website visited by the user, as defined by the URL usually displayed in the address bar of the browser.

B. third-party cookies

"Third-party cookies" are cookies that are installed by a data controller other than the operator of the website visited by the user (as defined by the website address (URL) displayed in the browser's address bar).

3.2.3. Grouping cookies by the Data Protection Working Group

A. Cookies that do not require the user's consent ("cookies necessary for technical reasons")

1. User-input cookies

The term "user input" cookie can be used as a general term to describe session cookies that are used to consistently track user input during messages with the service provider. They usually use first-party cookies that are based on a session ID (a random temporary ID number) and expire at the end of the session at the latest.

"User input" first-party cookies are usually used to track user input when filling in multi-page online forms or, for example, in the case of a shopping cart, what goods the user has selected by clicking on a button (e.g. "add to cart"). These cookies are clearly necessary to provide the internet service that the user has explicitly requested. They are also tied to the user's activity (e.g., clicking on a button or filling in a form).

2. Authentication Session Cookies

Authentication cookies are used to identify the user when logging in (for example, on an online banking website). These cookies are necessary to enable users to identify themselves during their repeated visits to the website and to gain access to the permitted content, such as checking their account balance, transactions, etc.

Authentication cookies are usually session cookies. When a user signs in, they explicitly request access to the content or service that they are allowed to access. In the absence of an authentication token stored on the cookie, the user would have to enter their username/password on each page requested. Therefore, the authentication service is an essential part of the information society service that it expressly requests. However, it is important to note that the user is only requesting access to the website and the specific service required to perform the requested task. Authentication should not allow the cookie to be used for other secondary purposes, such as tracking behaviour or advertising without consent.

3. User Centric Security Cookies

The exemption for authentication cookies (as described above) may be extended to other cookies that are designed for specific tasks related to strengthening the security of the service explicitly requested by the user. These include, for example, cookies that are used to detect repeated failed login attempts to the website or other similar mechanisms that are designed to protect the login system from misuse.

However, this exemption does not extend to the use of cookies that are related to the security of websites or third-party services that the user has not explicitly requested. Although login cookies are usually set to expire at the end of the session, security cookies have a longer expected expiration time to achieve their security goal.

4. Multimedia Player Session Cookie

Multimedia player session cookies are used to store technical data necessary for the playback of video or audio content, such as image quality, network connection speed and buffering parameters. These multimedia session cookies are commonly known as "flash cookies". They got this name because Adobe Flash is currently the most widely used internet video technology. Since this information is not needed in the long term, these cookies should expire when the session ends. If the user visits a website that contains related text and video content, both content elements are both part of the service expressly requested by the user. In order to benefit from an exemption, the website operator must avoid adding additional information to "flash" or other cookies that is not strictly necessary for the playback of media content.

5. Load balancing session cookies

Load balancing is a technique that allows a single machine to be distributed across many computers to process requests to a web server. One of the techniques used to implement "load balancing" is based on a "load balancer": Web requests from users are routed to a load-balancing gateway, which forwards them to an available internal server in the computer pool. In some cases, this redirection must be maintained throughout the session: all requests from that user must always be forwarded to the same server in the computer pool to maintain consistency in processing.

Among many other techniques, a cookie can be used to identify a server in a computer pool so that the load balancer redirects requests correctly. In this case, we are talking about session cookies. The sole purpose of the information contained in the cookie is to identify one of the endpoints of the communication (one of the servers in the computer pool) and is therefore necessary for communication over the network.

6. User Interface Customization Cookies

User interface customization cookies are used to store user preferences for the service through websites that are not linked to other persistent identifiers, such as username. These are only activated if the user has explicitly requested the service of storing certain information, for example by clicking on a button or checking a box. These can be session cookies or, depending on their purpose, they can be set in weeks or months.

Typical examples of personalisation cookies include:

-Preferred language cookies, which are used to store the language selected by the user on a multilingual website (e.g. by clicking on a flag);

-Cookies for the desired display of results, which are used to store the user's preferences in relation to online search queries (e.g. selecting the number of results per page).

7. Social plug-in consent sharing cookies

Many social networks offer 'social sharing widgets' that website operators can integrate into their platform, in particular to allow users of the social network to share their favourite content with their friends (and also offer other related services, such as posting comments). These content-sharing modules store and place accessible cookies on the user's terminal device so that social networks can identify their members when they interact with these plugins. In order to clarify this usage issue, it is important to distinguish between users who are 'logged in' to a particular social network account through their browser and 'non-logged-in' users who are either not members of the particular social network or have disconnected from their social network account.

B. Cookies that require user consent (optional cookies)

1. Social plug-in tracking cookies

Many social networks offer "social content sharing modules" that website operators can incorporate into their platforms to provide services that their members are believed to have "explicitly requested". However, these modules can also be used to track individuals (members and non-members) and may also contain third-party cookies for additional purposes (e.g. behavioural advertising, analytics or market research).

2. Third-party advertising

This group includes third-party cookies used for behavioural advertising and all related third-party operational cookies used in advertising, including cookies used for frequency maximisation, financial logging, advertising partnerships, click fraud detection, research and market analysis, product improvement and debugging.

Do Not Track (DNT) is a browser-side opt-out option. If this function is turned on, the browser will indicate to the service providers (web analytics system, ad serving system, other service providers) by sending a Do Not Track header every time a page is requested, that these service providers cannot store online behavioral information about this user, i.e. they cannot set cookies with the user. In theory, this causes a similar operation as if the user had opted out of the given service provider, only in this case he can indicate to each service provider with a setting in the browser that he does not want to be tracked what he or she browses on the Internet and where. Therefore, if a user declares that they do not request tracking (DNT=1), no tracking identifier can be installed or any other processing can be carried out.

3. Own visit analyzers (first-party analytics)

Visitor analyzers are statistical tools that measure the number of visitors to websites, which often use cookies. In particular, website owners use these tools to estimate the number of unique visitors, identify the most frequently used keywords on search engines that lead to a particular website, and track certain web navigation queries.

3.2.4. Classification according to the International Chamber of Commerce (ICC UK)

The most common classification system for cookies used today - at least on English-language websites - was proposed and developed by the International Chamber of Commerce (ICC UK) in the ICC UK Cookie Guide:

A. strictly necessary cookies/necessary

These cookies are necessary for the use of the website and enable the use of the website's functions. This includes cookies that allow you to log in to secure areas of the website, use a shopping cart or use e-invoicing services.

B. performance cookies/statistics

These cookies collect information about how visitors use the websites, such as which pages they visit most often or whether they receive an error message from the website. These cookies do not collect any information that identifies the visitor. These cookies collect aggregated information and are therefore anonymous, they are only used to improve the functionality of the website.

C. functionality cookies/preferences

These cookies allow us to record user choices (such as the name, language or region you have entered) and to use enhanced, personalised features. These cookies may also enable certain functions embedded in the website (e.g. display YouTube videos) in order to function properly. The information collected by these cookies may be anonymous and cannot be used to track the user's activity on other websites visited by the user.

D. targeting cookies or advertising cookies/marketing

The purpose of using these cookies is to display advertisements on the website that are more interesting and relevant to the user. These cookies can be used, for example, to determine the number of times an advertisement is displayed and to measure the effectiveness of advertising campaigns. These cookies are usually placed on a website by advertising networks with the permission of the website operator. These cookies remember your visit to a particular website and share this information with other organisations, such as the publisher of the advertisement. Typically, targeting or advertising cookies are related to the functions provided by the organization that operates the website.

E. unclassified cookies

Cookies that are not yet classified, together with providers of individual cookies, are not classified.


3.3. Cookies used in particular on https://pick.hu/en website

3.3.1. Strictly necessary cookies/necessary

Purpose

Cookie name

Expiration Date

Learn more

Ensuring the basic operation of the website

ci_session

2 hours

User session identification cookie to help you navigate the website

Ensuring the basic operation of the website

csrf_cookie_name

2 hours

The forms on the site are essential for the security and operation of the cookies

Ensuring the basic operation of the website

locale

1 year

Ensuring the basic operation of the website

Cookie popup selection

cc_required

1 year

Record of the user’s consent to required cookies

Cookie popup selection

cc_stat

1 year

Record of the user’s consent to required cookies

Cookie popup selection

cc_ads

1 year

Record of the user’s consent to required cookies


3.3.2. Performance cookies/statistics

Name

Service Provider

Purpose

Type

Expiration

_ga, _gid,

_gat

Google Analytics

To collect information about how our visitors use our website.

Cookies for statistical purposes

2 years, 1 day, 1 minute

fr

Facebook

To collect information about how our visitors use our website.

Cookies for statistical purposes

4 months


3.3.3. Functional cookies (functionalitycookies/preferences)

Name

Service Provider

Purpose

Type

Expiration

XSRF TOKEN

Pick.hu/en

Ensuring the proper functioning of the website

Cookies ensuring secure operation of the website

Session End


3.4. Legal basis for data processing

With regard to cookies requiring consent, the legal basis for data processing is Article 6 (1) a) of the Regulation, Section 155. (4) of the Ehtv.  and according to Section 13/A (4) of the Ektv., the voluntary consent of the data subject, and Section 13/A (3) of the Ektv.

The data subject may withdraw or modify his/her consent to the use of cookies requiring consent at any time as described in Section 7.1.9 of this Privacy Policy.

In the case of the processing of cookies (strictly necessary cookies), server logs (e.g. logging of IP addresses) or other personal data that are necessary for the basic operation of the website and the security of the IT system, based on the legitimate interest of ensuring the security and functioning of the website pursuant to Article 6 (1) (f) of the Regulation.


3.5. Scope of data subjects:

The https://pick.hu/en data subjects  include those who have consented to the use of cookies requiring consent by accepting the cookie in the cookie settings menu and by pressing the "OK" button displayed on the website.

In  the  case of data processing necessary for the basic operation of the https://pick.hu/en website (strictly necessary cookies) and the security of the IT system (server logs, etc.), the data subjects also include  the visitors of the https://pick.hu/en/ website and  the administrators authorised to use the administrative interface of the https://pick.hu/en website.


3.6. Scope of processed personal data

Level 1: Functional cookie.

Level 2: Statistical cookies.


3.7. Duration of data processing

In the course of data processing necessary for the basic operation of the https://pick.hu/en website and the security of the IT system, the personal data specified in Section 3.6 are stored for their defined technical lifetime and are not subject to withdrawal of consent.


3.8. Recipients of personal data, categories of recipients


3.9. The Data Controller(s)

A business entity as defined in Section 1 of this Privacy Policy.


3.10. Processor(s)

  1. BONITÁS IT Ltd. (mailing address: 6725 Szeged, Szabadkai út 18., e-mail address: info@bonitasit.hu; website: https://bonitasit.hu/) as the infrastructure operator responsible for server operation.
  2. Invitech ICT Services Ltd. (mailing address: 2040 Budaörs, Edison utca 4.; e-mail address: fazekasb@invitech.hu; website: www.invitech.hu; phone number: 1444) as the business association providing the hosting service.
  3. Be Social Commercial Ltd. (mailing address: 1037 Budapest, Seregély utca 3-5.; e-mail address: info@besocial.hu; website: www.besocial.hu; phone number: +36 70 411 2343) as the business entity responsible for the operation of the website.


3.11. Data processing by external service providers

The html code of the portal may contain links to and from an external server. The servers of external providers may be connected directly to the visitor's computer. We would like to draw the attention of our visitors to the fact that the providers of these links are able to collect visitor data due to the direct connection to their server and the direct communication with the visitor's browser. Any content that may be personalized for the visitor is served by the servers of external service providers. Cookies used by external providers are in particular the Google Adwords cookie, the Google Analytics cookie or the cookies used by Facebook.

  1. You can read more about the cookies used by Google here:
    https://policies.google.com/technologies/types?hl=hu
  2. You can read more about the cookies used by Facebook here:
    https://hu-hu.facebook.com/policies/cookies/


3.12. Settings, deletion or disabling of cookies

The user can delete cookies that require consent from their own computer, or they can disable the use of cookies that require consent in their browser. The use of cookies that require consent is not mandatory. If the visitor of https://pick.hu/en website does not consent to the use of cookies that require consent, certain functions may not be available to him/her. If  you  would like to disable cookies requiring consent in part or in full by the visitor of the https://pick.hu/en website, you will have to do so separately on each of your browsing devices and programs.

  1. The settings regarding the cookies that require consent used on https://pick.hu/en website can be changed by the visitor: https://pick.hu/en "Cookie Settings" section of the website, or
  2. In the case of the Chrome browser, the graphical element "View page information" in front of the browser's address bar (in the case of a secure connection – https – a padlock, otherwise by clicking on a circled "i", in a pop-up window, or
  3. For Chrome browsers, you can view and change it in the following menu: Settings/Advanced/Privacy & Security/Content Settings/Cookies

For more information about cookies, please visit the following links:

  1. Microsoft Internet Explorer:
    https://support.microsoft.com/en-gb/help/17479/windows-internet-explorer-11-change-security-privacysettings
  2. Firefox:
    https://support.mozilla.org/hu/products/firefox/protect-your-privacy/cookies 
  3. Google Chrome:
    https://support.google.com/accounts/answer/61416?hl=hu
  4. Microsoft Edge
    https://privacy.microsoft.com/hu-HU/windows-10-microsoft-edge-and-privacy
  5. Opera
    https://help.opera.com/en/latest/web-preferences/#cookies
  6. Safari
    https://apple.com/legal/privacy/en-ww/


4. QUESTION, SUGGESTION, INQUIRY

Visitors to the https://pick.hu/en website have the opportunity to send their questions, suggestions or any problems that may arise to the Data Controller  to the contact details on the https://pick.hu/en/contact-us subpage.


4.1. Purpose of data processing

The purpose of data processing is  to inform the visitors of the https://pick.hu/en website electronically, to contact them, to answer the questions they ask, to take their suggestions into account, to coordinate more efficiently, to facilitate administration, to serve their needs to the maximum and to increase their satisfaction.


4.2. Legal basis for data processing

According to Article 6(1)(a) of the Regulation, the voluntary consent of the data subject.

Visitors  to the https://pick.hu/en website can submit  their questions and suggestions to the Data Controller by accepting the Privacy Policy by ticking  the box and filling in the form on https://pick.hu/en/contact-us page.

The visitor can send his message to the Data Controller by clicking on the send e-mail button and consents to data processing. If the message is sent successfully, the visitor will receive a confirmation of this in a pop-up window.

The data subject may withdraw his or her voluntary consent to the processing of data at any time, however, in this case, the Data Controller will not be able to inform the data subjects or answer the questions they have asked with regard to questions not answered until the possible withdrawal of the consent.


4.3. Scope of data subjects

The affected people include https://pick.hu/en visitors.


4.4. Scope of processed personal data

Visitors to the https://pick.hu/en voluntarily provide their personal information. The person providing the data is responsible for the authenticity of the personal data provided. https://pick.hu/en visitors generally provide the following personal data:  

Name
Email address
Phone number 

4.5. Duration of data processing

The data processing will take place until the date of withdrawal of the consent. The Data Controller keeps a register of the persons who have consented to data processing by sending e-mails and comments. If the Data Subject withdraws his/her consent, the Data Controller shall delete the Data Subject's personal data from its records and any existing database.


4.6. Recipients of personal data, categories of recipients

Persons authorised to process personal data on behalf of the Controller and Processors.

4.7. The Data Controller

A business entity as defined in Section 1 of this Privacy Policy.


4.8. Processor(s)

  1. BONITÁS IT Ltd. (mailing address: 6725 Szeged, Szabadkai út 18., e-mail address: info@bonitasit.hu; website: https://bonitasit.hu/) as the infrastructure operator responsible for server operation.
  2. Invitech ICT Services Ltd. (mailing address: 2040 Budaörs, Edison utca 4.; e-mail address:
    fazekasb@invitech.hu; website: www.invitech.hu; phone number: 1444) as a business entity providing hosting services.
  3. Be Social Commercial Ltd. (mailing address: 1037 Budapest, Seregély utca 3-5.; e-mailing address:
    info@besocial.hu; website: www.besocial.hu; phone number: +36 70 411 2343) as the business entity responsible for the operation of the website.



5. COMMENTS AND COMPLAINTS

Visitors  to the https://pick.hu/en website have the opportunity to submit their comments/complaints or any problems they may have regarding the Products of the Data Controller to the Data Controller electronically through the  form on the https://pick.hu/en/complaints sub-page.

Complaints communicated by telephone or using electronic communications services qualify as oral complaints (hereinafter referred to as oral complaint) pursuant to Section 17/A (4) of Act CLV of 1997 on Consumer Protection (hereinafter referred to as Fgy.tv.).


5.1. Purpose of data processing

The purpose of data processing is to  inform the visitors of the https://pick.hu/en website by sending an electronic message, to contact them, to take their comments into account, to solve any problems that may arise, to coordinate them more effectively, to serve their needs to the maximum and to increase their satisfaction.


5.2. Legal basis for data processing

According to Article 6(1)(a) of the Regulation, the voluntary consent of the data subject.

Visitors  to the https://pick.hu/en website can submit their comments/complaints or any problems that may arise to the Data Controller by accepting the Privacy Policy by ticking the box and by clicking on the send message button.

If the message is sent successfully, the visitor will receive a confirmation of this fact.

If the consumer – in the case of an oral complaint – does not agree with the handling of the complaint, or the immediate investigation of the complaint is not possible, the Data Controller is obliged to take a record of the complaint and its position in relation to it and  to  carry out data processing in accordance with Article 6 (1) c) of the Regulation for the purpose of fulfilling a legal obligation to which the Data Controller is subject,  in accordance with Section 17/A (3) of the Fgy.tv.

If the Data Controller is a member of the Fgy. Pursuant to Section 17/B (3) of the Consumer Protection Act, the customer service is obliged to record all oral complaints made by phone and the telephone communication between the customer service and the consumer with audio recordings, in which case  it performs  data processing for the purpose of fulfilling a legal obligation to which the data controller is subject pursuant to Article 6(1)(c) of the Regulation.


5.3. Scope of data subjects

The data subjects include visitors who fill in the form and send comments.


5.4. Scope of processed personal data

The form is filled in by providing the following personal data:

Name
Email address
Phone number 

If the Data Controller is obliged to record the oral complaint pursuant to Section 17/A (3) of the Fgy.tv., the mandatory content elements of the report shall be determined by Section 17/A (5) of the Fgy.tv. as follows:

  1. the name and address of the consumer;
  2. the place, time and method of filing the complaint;
  3. a detailed description of the consumer's complaint, a list of documents, documents and other evidence presented by the consumer;
  4. a statement by the undertaking on its position on the consumer's complaint, if the immediate investigation of the complaint is possible;
  5. the signature of the person who took the minutes and, with the exception of verbal complaints communicated by telephone or other electronic communication service of the consumer;
  6. the place and time of recording the minutes;
  7. in the case of an oral complaint communicated by telephone or other electronic communication service, the unique identification number of the complaint;
  8. warning regarding the provisions of Section 17/A(5a) of the Fgy.tv.

(5a) If the consumer fails to provide the data specified in subsection (5) (a) and (c) during the recording of the report, or refuses to sign the report in accordance with subsection (5) e), the undertaking shall disapply the provisions of subsection (6) in the course of the settlement of the oral complaint.

(6) Unless otherwise provided for in a directly applicable legal act of the European Union, the undertaking shall reply to a written complaint in a verifiable manner within thirty days of receipt and shall take measures to communicate it. A shorter deadline may be set by law, and a longer deadline may be set by law. The company is obliged to justify its position rejecting the complaint.

If the Data Controller is obliged to make an audio recording pursuant to Section 17/B (3) of the Fgy.tv., then the Data Controller shall also process the voice of the data subject as personal data.

The visitor providing the data is responsible for the accuracy of the personal data supplied.


5.5. Duration of data processing

If the Data Controller is not obliged to keep a record of the verbal complaint, because the immediate investigation of the complaint is possible and the data subject agrees with the handling of the complaint, then in  accordance with Section 17/A (3) of the Fgy.tv. - the personal data voluntarily provided by the data subject will be processed until consent is withdrawn. The Data Controller keeps a consent log documenting consent events related to message submission. If the data subject withdraws his/her consent to the processing of personal data, the Data Controller will delete the personal data of the data subject from his/her register and any existing database.

If the Data Controller  is obliged to record the oral complaint  in accordance with Section 17/A (3) of Fgy.tv., together with the personal data specified in Section 17/A (5) of Fgy.tv., then the minutes of the oral complaint and the copy of the response recorded by the Data Controller  shall be kept for 3 (three) years in accordance with Section 17/A (7) of the Fgy.tv. If the Data Controller is obliged to make an audio recording pursuant to Section 17/B (3) of Fgy.tv., then the audio recording together with its unique complaint identifier, shall be retained for 5 (five) years in accordance with Section 17/B (3) of Fgy.tv.


5.6. Recipients of personal data, categories of recipients

Persons authorised to process personal data on behalf of the Controller and Processors.  


5.7. The Data Controller

A business entity as defined in Section 1 of this Privacy Policy.


5.8. Processor(s)

  1. Café Communications Ltd. (mailing address: 1037 Budapest, Seregély utca 3-5., e-mail address: info@cafecommunications.hu; website: https://cafecommunications.hu/) as the business entity responsible for the operation of the website.
  2. Be Social Commercial Ltd. (mailing address: 1037 Budapest, Seregély utca 3-5., e-mail address: info@besocial.hu; website: http://besocial.hu) as the data processor providing website development and maintenance services.
  3. BONITÁS IT Ltd. (mailing address: 6725 Szeged, Szabadkai út 18., e-mail address: info@bonitasit.hu; website:
    https://bonitasit.hu/) as the infrastructure operator responsible for server operation.
  4. Invitel Telecommunications Ltd. (mailing address: 2040 Budaörs, Puskás Tivadar u. 8-10., e-mail address: help@invitel.co.hu; website: https://invitel.hu) as the hosting service provider.


6. SECURITY OF DATA PROCESSING

The Controller processes and stores personal data in electronic form.

Taking into account the state of science and technology and the costs of implementation, as well as the nature, scope, circumstances and purposes of data processing, as well as the varying the likelihood and severity of the risk to the rights and freedoms of natural persons. Data Controller and the Data Processor(s) shall implement technical and organisational measures to guarantee a level of data security for the data subjects appropriate to the degree of risk.

When determining the appropriate level of security, the Data Controller shall expressly take into account the risks arising from data processing, which arise in particular from the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.

The Controller and the Processor(s) shall take measures to ensure that the Controller or natural persons acting under the direction of the Controller(s) and having access to the personal data may only be processed by the Processor or by persons acting under the authority of the Controller or Processor, in accordance with the Controller’s instructions, unless they are obliged to derogate from this under Union or Member State law.

The personal data affected by data processing are stored on servers within the BONITÁS IT Ltd.'s controlled IT infrastructure. The operation is carried out by the IT organization of BONITÁS IT Ltd., within the framework of a managed service agreement concluded with the subsidiaries. The regulations including the organizational and technical measures related to the operation are contained in the organization's Information Security Policy (ISP).


Accordingly, the Data Controller/Data Processor shall ensure:

  1. physical security, which includes the physical protection of all elements of the entire IT infrastructure that are involved in the service of the given service, as well as the guarding of the objects hosting these systems, the full supervision and control of access to these rooms;
  2. logical security, which includes the allocation of rights based on the principle of least privilege, its full supervision and control, which ensures the confidentiality and integrity of the stored data;
  3. system availability and service continuity in accordance with the applicable SLA (Service Level Agreement);
  4. to carry out risk analysis in which it identifies potential internal and external risks arising in connection with data management and processing, such as the risk of unauthorised access;
  5. the successful backup execution, which ensure regular and successful execution of system backups;
  6. patch management to keep systems up to date and minimize exposure to security vulnerabilities;
  7. perform vulnerability scans periodically, in accordance with security best practices;
  8. incident escalation procedures ensuring timely incident resolution.



7. EXERCISE OF RIGHTS AND REMEDIES

The data subject may exercise the following rights under the Regulation below, taking into account the above nature of certain legal bases of data processing.

7.1. Rights of the data subject

7.1.1. Transparent information

The Data Controller shall provide all the information required by the Regulation in a concise, transparent, understandable and easily accessible form, in a clear and comprehensible manner, in particular in the case of any information addressed to children. The Data Controller shall provide the information in writing or in another way - electronically - but may also provide oral information at the request of the data subject, provided that the identity of the data subject has been verified in another way.

7.1.2. Right of access to your personal data

At the request of the data subject, the Data Controller shall provide feedback on whether the processing of the data subject's personal data is in progress. If it is established that the personal data of the data subject is being processed, the data subject may request access to the personal data and to the following information:

  1. the purpose of the processing;
  2. the categories of personal data concerned;
  3. the recipients or categories of recipients to whom the Controller has disclosed or will disclose the personal data, in particular recipients in third countries or international organisations;
  4. the duration of storage of personal data or, if this is not possible, the criteria for determining this period;
  5. the data subject's right to request the Data Controller to rectify, delete or restrict the processing of his or her personal data, or to object to the processing of his or her personal data;
  6. the data subject's right to lodge a complaint with the Supervisory Authority;
  7. if the Data Controller did not collect the personal data directly from the data subject, the source of these personal data;
  8. whether automated decision-making and profiling have been carried out on the basis of the personal data and, if so, comprehensible information about the logic used and the significance of such processing and the likely consequences for the data subject;
  9. if the Data Controller transfers the personal data of the data subject to a country outside the EU or to an international organization, the data subject has the right to be informed of the appropriate safeguards relating to the transfer (Article 46 of the Regulation).

7.1.3. Right to rectification of inaccurate personal data

If the Data Controller processes inaccurate or incomplete personal data about the data subject, it shall rectify them without undue delay after receiving the data subject's request. The data subject may also request the completion of incomplete personal data, including by providing a supplementary statement

7.1.4. Right to erasure (to be forgotten)

The data subject has the right to delete his or her personal data and to request the Data Controller to comply with this request without undue delay if one of the following reasons applies:

  1. the personal data of the data subject are no longer necessary in connection with the original purpose of the data processing;
  2. the data subject withdraws his/her consent to data processing and there is no other legal basis for data processing;
  3. the lawfulness of data processing is based on the legitimate interest of the Data Controller, against which the data subject objects, and there is no overriding legitimate reason for data processing;
  4. the personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time;
  5. the personal data have been unlawfully processed;
  6. the personal data of the data subject must be erased in order to comply with a legal obligation imposed on the Controller by EU or Member State law;
  7. the lawfulness of the processing of personal data by the Data Controller is based on the consent given by a child's guardian, and or ga) the person concerned is the child's guardian and the child concerned has not yet reached the age of 16 required for consent;

    gb) the person concerned is a child who has already reached the age of 16 required for consent.

The Data Controller may not delete personal data if the data processing is necessary for the following reasons:

  1. for the purpose of exercising the right to freedom of expression and information;
  2. for the performance of a task which is subject to a legal obligation requiring the processing of personal data, or for the performance of a task carried out in the public interest or in the exercise of official authority;
  3. for preventive health or occupational health purposes, necessary under Union or Member State law or under a contract with a healthcare professional, for the assessment of a worker's ability to work, for the provision of medical or social care or treatment, or for the management of health or social systems and services;
  4. the processing is necessary for reasons of public interest in the area of public health, such as protection against serious cross-border threats to health or ensuring a high standard and safety of healthcare, medicinal products and medical devices, and is carried out on the basis of Union or Member State law which provides for appropriate and specific measures to safeguard the rights and freedoms of the data subject; and in particular professional secrecy;
  5. for archiving purposes in the public interest, for scientific and historical research purposes or for statistical purposes, where the data subject's right to erasure would be likely to render such processing impossible or seriously jeopardise it;
  6. for the establishment, exercise or defence of legal claims.

7.1.5. Right to restriction of processing

At the request of the data subject, the Data Controller shall restrict the processing of personal data if one of the following is met:

  1. the data subject contests the accuracy of the personal data;
  2. the processing is unlawful and the data subject opposes the erasure of the data and instead requests the restriction of its use;
  3. the Data Controller no longer needs the personal data for the purpose of data processing, but the data subject requires them for the establishment, exercise or defence of legal claims;
  4. the data subject objects to the data processing carried out where the processing is based on legitimate interests, the data subject has the right to object at any time.


If data processing is subject to restriction - based on the request of the data subject - such personal data will only be subject to storage exceptions

  1. with the consent of the data subject, or
  2. to establish, exercise or defend legal claims, or
  3. to protect the rights of another natural or legal person, or
  4. for reasons of important public interest of the Union or of a Member State. can be treated.


The Data Controller shall inform the data subject in advance of the lifting of the restriction of data processing.

7.1.6. Right to data portability

The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to the Data Controller, in a structured, commonly used, machine-readable format, and have the right to transmit those data to another controller if:

  1. the processing is based on consent or a contract; and
  2. The processing is carried out by automated means.

The data subject also has the right to request the direct transfer of personal data between controllers.

7.1.7. Right to object

The data subject has the right to object to the processing of his or her personal data if:

  1. the processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
  2. the processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party, including profiling;
  3. The processing is carried out for the purpose of direct marketing, including profiling where it is related to direct marketing.

In the case of data processing based on legitimate interest as defined in point b) above, the data subject may not object to the data processing if the Data Controller proves that:

  1. the processing is justified by compelling legitimate grounds which override the interests, rights and freedoms of the data subject, or
  2. for the establishment, exercise or defence of legal claims.

If the data subject objects to the processing of personal data for the purpose of direct marketing, the Data Controller will no longer process the personal data for this purpose.

7.1.8. Automated decision-making in individual cases, including profiling

The data subject has the right which produces legal effects concerning him or her or similarly significantly affects him or her.

The data subject may not exercise the above right if the decision

  1. necessary for the conclusion or performance of a contract between the data subject and the Data Controller;
  2. is made possible by Union or Member State law applicable to the Controller, which also lays down appropriate measures for the protection of the rights and freedoms and legitimate interests of the data subject;
  3. based on the explicit consent of the data subject.

In the cases referred to in points (a) and (c) above, the data subject may request human intervention, express his or her position and object to the decision.

7.1.9. Withdrawal of consent

The data subject is only entitled to withdraw his consent at any time in data processing cases based on his or her consent. The withdrawal of consent does not affect the lawfulness of the processing based on consent before its withdrawal.

The Controller shall inform the data subject prior to obtaining consent.

The declaration of the data subject withdrawing his or her consent is valid with the clear indication of the data processing in question.


7.2. Enforcement, complaint, remedy

7.2.1. Enforcement

The data subject may exercise the data processing rights listed above in an e-mail sent to the Data Controller's e-mail address or registered office address from the data subject's identifiable e-mail address, or by post in a letter signed by the data subject. The data subject’s declaration is valid with a clear indication of the specific processing operation The Data Controller provides the response by electronic means unless the data subject requests otherwise.

7.2.2. Complaints

If the data subject considers that the processing of personal data concerning him or her violates the provisions of the Regulation, the data subject has the right to lodge a complaint with the relevant Supervisory Authority, in particular in the Member State of his habitual residence, place of work or place of the alleged infringement.

Complaints may be lodged with the competent Supervisory Authority, National Authority for Data Protection and Freedom of Information (hereinafter referred to as the NAIH) as the Supervisory Authority in the territory of Hungary. Contact details of the NAIH:

E-mail: ugyfelszolgalat@naih.hu  
Address: 1055 Budapest, Falk Miksa utca 9-11.
Postal address: 1363 Budapest, Pf. 9.
Phone: +36 (1) 391-1400
Website: www.naih.hu  

The list of EU Supervisory Authorities is available on the website of the European Data Protection Board (EDPB), at the following link:

http://ec.europa.eu/justice/data-protection/article-29/structure/data-protection-authorities/index_en.htm  

7.2.3. Judicial remedies

a. Judicial remedy against the Supervisory Authority

All data subjects are entitled to an effective judicial remedy:

aa) against a legally binding decision (not including opinions or non-binding guidance) of the supervisory authority, or

ab) if the competent Supervisory Authority does not deal with the complaint or does not inform the data subject within three months of the procedural developments or the outcome of the complaint submitted.

Without prejudice to any other administrative or non‑judicial remedy, each data subject shall have the right to an effective judicial remedy against a legally binding decision of a supervisory authority.

b. Judicial remedy against the Data Controller or Data Processor

The data subject may turn to court against the Data Controller or the Data Processor if he or she considers that the Data Controller or the Data Processor commissioned by the Data Controller or acting on the basis of the Data Processor processes his or her personal data in violation of the provisions on the processing of personal data specified in the law or in a binding legal act of the European Union.

The procedure shall be initiated before the courts of the Member State in which the Controller or the Processor is established. Such proceedings may also be initiated before the courts of the Member State of the data subject's habitual residence, unless the Controller or the Data Processor is a public authority of a Member State acting in its capacity as a public authority.

In Hungary, the person concerned may also initiate the lawsuit before the court of his or her habitual residence.