The purpose of the data management information
Trapp Martin EV (Reg.: 55363929-1-22, 7625 Pécs, Losonc utca 6., hereinafter referred to as service provider, data manager) as a data manager, recognizes the content of this legal notice as binding on itself. It undertakes to ensure that all data processing related to its activities meets the requirements set out in these regulations and in the applicable national legislation, as well as in the legal acts of the European Union.
The data protection guidelines arising in connection with the data management of the Data Controller are continuously available at https://thermalpad.hu/adatkezelesi-tajekoztato.
The Data Controller reserves the right to change this information at any time. Of course, you will notify your audience of any changes in good time.
If you have any questions related to this announcement, please write to us and our colleague will answer your question.
The Data Controller is committed to protecting the personal data of its customers and partners, and considers it of utmost importance to respect its customers’ right to informational self-determination. The Data Controller treats personal data confidentially and takes all security, technical and organizational measures that guarantee data security.
The Data Controller describes its data management practices below.
Data of the data controller
The Data Controller deletes all e-mails received and orders placed on the website, together with other stored personal data, no later than 10 years after the date of data communication.
Name: Trapp Martin EV.
Address: 7625 Pécs, Losonc utca 6.
Individual entrepreneur registration number: 54028852
Name of registering authority: Ministry of the Interior Deputy State Secretary Responsible for Keeping Records Department for Document Supervision
Tax number: 55363929-1-22
Data Protection Officer
Name: Trapp Martin
Scope of processed personal data
Personal data to be provided during registration
Password (naturally encrypted and stored in so-called hashed form)
Users’ data is stored in a secure so-called They can be sent to our web servers via an SSL connection.
The Data Controller selects and operates the IT tools used for the management of personal data during the provision of the service in such a way that the managed data:
- accessible to those authorized to do so (availability);
- its authenticity and authentication are ensured (authenticity of data management);
- its immutability can be verified (data integrity);
- be protected against unauthorized access (data confidentiality).
The Data Controller uses appropriate measures to protect the data against unauthorized access, alteration, transmission, disclosure, deletion or destruction, as well as against accidental destruction.
The Data Controller ensures the protection of the security of data management with technical, organizational and organizational measures that provide a level of protection corresponding to the risks associated with data management.
The Data Controller keeps it during data management
- confidentiality: protects the information so that only those authorized to do so can access it;
- integrity: protects the accuracy and completeness of the information and the method of processing;
- availability: it ensures that when the authorized user needs it, he can really access the desired information and that the related tools are available.
It’s the job of cookies
- collect information about visitors and their devices;
- they note the individual settings of the visitors, which will be used, e.g. when using online transactions, so you don’t have to type them in again;
- facilitate the use of the website;
- they provide a quality user experience.
In order to provide customized service, a small data package, so-called it places a cookie and reads it back during the next visit. If the browser returns a previously saved cookie, the cookie management service provider has the opportunity to connect the user’s current visit with previous ones, but only with regard to its own content.
Duration of data management
The data storage period of the given cookie, more information is available here:
Google’s general cookie information: https://www.google.com/policies/technologies/types/
Google Analytics information: https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage?hl=hu
Facebook information: https://www.facebook.com/ads/preferences/?entry_product=ad_settings_screen
Legal background and legal basis of cookies:
The legal basis for data management is your consent based on Article 6 (1) point a) of the Regulation.
The main characteristics of the cookies used by the website:
Cookies strictly necessary for operation: These cookies are essential for the use of the website and enable the use of the basic functions of the website. In the absence of these, many functions of the site will not be available to you. The lifetime of these types of cookies is limited to the duration of the session.
Cookies to improve the user experience: These cookies collect information about the user’s use of the website, for example, which pages are visited most often or what error message is received from the website. These cookies do not collect information that identifies the visitor, that is, they work with completely general, anonymous information. We use the data obtained from these to improve the performance of the website. The lifetime of these types of cookies is limited to the duration of the session.
Cookies placed by third parties (analytics)
Remarketing cookies: May be displayed to previous visitors or users when they browse other websites in the Google Display Network and search for terms related to your products or services
Session cookie: These cookies store the location of the visitor, the language of the browser, the currency of the payment, and their lifetime is until the browser is closed, or a maximum of 2 hours.
Mobile version, design cookie: Detects the device used by the visitor and switches to full view on mobile. Its lifespan is 365 days.
Cookie acceptance cookie: When you arrive at the page, you accept the statement on the storage of cookies in the warning window. Its lifespan is 365 days.
Facebook pixel (Facebook cookie) The Facebook pixel is a code with the help of which a report on conversions is prepared on the website, target audiences can be compiled, and the owner of the page receives detailed analysis data about the visitors’ use of the website. With the help of the Facebook pixel, you can display personalized offers and advertisements to website visitors on the Facebook interface. You can read Facebook’s data management policy here: https://www.facebook.com/privacy/explanation
- Internet Explorer: http://windows.microsoft.com/en-us/internet-explorer/delete-manage-cookies#ie=ie-11
- Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer
- Mozilla: https://support.mozilla.org/hu/kb/weboldalak-altal-elhelyezett-sutik-torlese-szamito
- Safari: https://support.apple.com/kb/ph21411?locale=en_US
- Chrome: https://support.google.com/chrome/answer/95647
Data related to online ordering
For invoicing and delivery, we request the following data separately from our customers:
Name / Company name
Address (Zip code, City, Street, House number)
Tax number (in the case of a taxpayer)
Data related to online administration
Name / Company name
Address (Zip code, City, Street, House number)
Tax number (in the case of a taxpayer)
Data related to the newsletter
Purpose, method and legal basis of data management
General data management guidelines
The data management of the Data Controller’s activities is based on voluntary consent and legal authorization. In the case of data processing based on voluntary consent, the data subjects may withdraw their consent at any stage of the data processing.
In some cases, the management, storage, and transmission of a range of the provided data is made mandatory by law, of which we notify our customers separately.
We draw the attention of informants to the Data Controller that if they do not provide their own personal data, the informant is obliged to obtain the consent of the data subject.
Its basic data management principles are in line with the applicable legislation on data protection, and in particular with the following:
- year CXII. Act – on the right to self-determination of information and freedom of information (Infotv.);
- Regulation (EU) 2016/679 of the European Parliament and of the Council (April 27, 2016) – on the protection of natural persons with regard to the processing of personal data and on the free flow of such data, and on the repeal of Regulation 95/46/EC ( general data protection regulation, GDPR);
- Act V – on the Civil Code (Ptk.);
- Act C – on accounting (Accounting Act);
- year LIII. Act – on the prevention and prevention of money laundering and terrorist financing (Pmt.);
- year CCXXXVII. Act – on credit institutions and financial enterprises (Hpt.).Az adatok fizikai tárolási helyei
Your personal data (that is, the data that can be linked to your person) can be processed by us in the following way: on the one hand, in connection with maintaining the Internet connection, technical data related to the computer you use, browser program, Internet address, and visited pages are automatically generated in our computer system, on the other hand, you can also provide your name, contact information or other data if you wish to contact us personally when using the website.
Technically recorded data during the operation of the system: the data of the computer of the concerned entrant, which are generated during the voting and which are recorded by the Amazon AWS system as an automatic result of the technical processes. The data that is recorded automatically is automatically logged by the system upon entry and exit without a separate statement or action by the person concerned. This data cannot be combined with other personal user data, except in cases made mandatory by law. Only the data controller has access to the data.
Data transmission, data processing, the circle of those familiar with the data
Invoicing-related data processing
Name of the data processor: Billingo.hu
The seat of the data processor is Octonull Kft.
Contact details of the data processor: https://www.billingo.hu/kapcsolat
E-mail address of the data processor:
Based on the contract concluded with the Data Controller, the Data Processor participates in the registration of accounting documents. In doing so, the Data Processor will provide the name and address of the data subject to the extent necessary for accounting records, Sztv. It is processed for a period corresponding to paragraph (2) of § 169, after which it is deleted.
Data processing activity related to the delivery of goods
(1) Magyar Posta Zrt.
Name of the data processor: Magyar Posta Zrt.
The headquarters of the data processor: Budapest, Dunavirág utca 2-6.
The phone number of the data processor is +36-1-767-8200
E-mail address of the data processor:
(2) Packeta Hungary Kft.
Name of the data processor: Packeta Hungary Kft.
The seat of the data processor is: 1044 Budapest, Ezred u. 1-3 B2/11
Contact details of the data processor: https://www.packeta.hu/kapcsolat
(3) UPS Hungary Ltd.
Name of the data processor: UPS Magyarország Kft.
The seat of the data processor is: 2220 Vecsés, Lőrinci utca 154.
Contact details of the data processor: https://www.ups.com/hu/hu/help-center/contact.page?
The Data Processor participates in the delivery of the ordered goods based on the contract concluded with the Data Controller. In doing so, the Data Processor may process the customer’s name, address and telephone number until the end of the calendar year following the mailing of the postal item, after which it shall be deleted immediately.
Data processing related to online payment
Name of the data processor: Barion Payment Zrt.
The seat of the data processor is: 1117 Budapest, Infopark sétány 1. Building I. 5th floor 5.
The phone number of the data processor is +36-1-464-7099
E-mail address of the data processor: https://www.barion.com/hu/ugyfelszolgalat/
Based on the contract with the Data Controller, the Data Processor participates in the implementation of the Online payment. In doing so, the Data Processor processes the billing name, name and address, order number and date of the affected person within the civil law limitation period.
Data processing activity related to sending newsletters
Name of the company operating the newsletter sending system: mailchimp.com
Headquarters of the company operating the newsletter system: 675 Ponce de Leon Ave NE, Suite 5000 Atlanta, GA 30308 USA
Phone number of the company operating the newsletter system: none
Email address of the company operating the newsletter system:
The Data Processor participates in the sending of newsletters based on the contract concluded with the Data Controller. In doing so, the Data Processor processes the data subject’s name and e-mail address to the extent necessary for the newsletter, and deletes it immediately upon the data subject’s request.
Your rights and remedies
Within the period of data management, you are entitled to the following rights according to the provisions of the Regulation:
- the right to withdraw consent
- access to personal data and information about data management
- right to rectification
- restriction of data management,
- right to erasure
- right to protest
- right to portability.
If you wish to exercise your rights, it involves your identification, and the Data Controller must communicate with you as necessary. Therefore, for the purpose of identification, it will be necessary to provide personal data (but the identification can only be based on data that the Data Controller manages about you anyway), and your complaint about data management will be available in the Data Controller’s email account within the period specified in this information regarding complaints. If you were a customer of ours and would like to identify yourself in order to handle complaints or warranty, please enter your order ID for identification. Using this, we can also identify you as a customer.
The Data Controller will respond to complaints related to data management within 30 days at the latest.
Right to information
The Data Controller takes appropriate measures in order to provide the data subjects with all information regarding the processing of personal data referred to in Articles 13 and 14 of the GDPR and Articles 15-22. and provide each piece of information according to Article 34 in a concise, transparent, comprehensible and easily accessible form, clearly and comprehensibly worded.
The data subject’s right of access
You are entitled to receive feedback from the Data Controller as to whether your personal data is being processed, and if it is being processed, you are entitled to:
- get access to the processed personal data and inform the Data Controller of the following information:
- the purposes of data management;
- categories of personal data processed about you;
- information about the recipients or categories of recipients to whom the personal data has been or will be disclosed by the Data Controller;
- the planned period of storage of personal data or, if this is not possible, the criteria for determining this period;
- your right to request from the Data Controller the correction, deletion or restriction of processing of your personal data and, in the case of data processing based on legitimate interests, to object to the processing of such personal data;
- the right to submit a complaint to the supervisory authority;
- if the data was not collected from you, any available information about its source;
- about the fact of automated decision-making (if such a procedure is used), including profiling, as well as, at least in these cases, comprehensible information about the logic used and the significance of such data management and the expected consequences for you.
The purpose of exercising the right may be aimed at establishing and checking the legality of data management, therefore, in the event of multiple requests for information, the Data Controller may charge a fair fee in exchange for providing the information.
Access to personal data is ensured by the Data Controller by sending the processed personal data and information to you by email after your identification. If you have registered, we provide access so that you can view and check your personal data by logging into your user account.
Please indicate in your request that you are requesting access to personal data or information related to data management.
Right to rectification
You have the right to request that the Data Controller correct inaccurate personal data concerning you without delay.
Right to erasure
If one of the following reasons exists, the data subject has the right to request that the Data Controller delete his/her personal data without undue delay:
- personal data are no longer needed for the purpose for which they were collected or otherwise processed;
- the data subject withdraws the consent that forms the basis of the data management, and there is no other legal basis for the data management;
- the data subject objects to data processing and there is no overriding legal reason for data processing;
- personal data has been processed unlawfully;
- the personal data must be deleted in order to fulfill the legal obligation prescribed by the EU or Member State law applicable to the data controller;
- the collection of personal data took place in connection with the offering of services related to the information society.
Data deletion cannot be initiated if data management is necessary: for the purpose of exercising the right to freedom of expression and information; for the purpose of fulfilling the obligation under the EU or Member State law applicable to the data controller requiring the processing of personal data, or for the execution of a task carried out in the public interest or in the context of the exercise of public authority conferred on the data controller; affecting the field of public health, or for archival, scientific and historical research purposes or for statistical purposes, on the basis of public interest; or to submit, assert or defend legal claims.
The right to restrict data processing
At the request of the data subject, the Data Controller restricts data processing if one of the following conditions is met:
- the data subject disputes the accuracy of the personal data, in this case the limitation is for that period of time
applies, which allows checking the accuracy of personal data;
- the data processing is illegal and the data subject opposes the deletion of the data and instead requests the restriction of its use;
- the data controller no longer needs the personal data for the purpose of data management, but the data subject requires them to present, enforce or defend legal claims; obsession
- the data subject objected to data processing; in this case, the restriction applies to the period until it is determined whether the legitimate reasons of the data controller take precedence over the legitimate reasons of the data subject.
If data management is subject to restrictions, personal data may only be processed with the consent of the data subject, with the exception of storage, or to submit, enforce or defend legal claims, or to protect the rights of another natural or legal person, or in the important public interest of the Union or a member state.
Right to data portability
If the data management is carried out in an automated way, or if the data management is based on your voluntary consent, you have the right to ask the Data Controller to receive the data you have provided to the Data Controller, which the Data Controller sends in xml, JSON or csv format to your at your disposal, if this is technically feasible, you can request that the Data Controller forward the data in this form to another data controller.
Right to protest
The data subject has the right to object at any time, for reasons related to his own situation, to the processing of his personal data necessary for the execution of a task carried out in the public interest or within the framework of the exercise of public authority conferred on the data controller, or the processing necessary to assert the legitimate interests of the data controller or a third party, including profiling based on the aforementioned provisions too. In the event of a protest, the data controller may no longer process the personal data, unless it is justified by compelling legitimate reasons that take precedence over the interests, rights and freedoms of the data subject, or that are related to the submission, enforcement or defense of legal claims.
Automated decision-making in individual cases, including profiling
The data subject has the right not to be covered by the scope of a decision based solely on automated data management, including profiling, which would have legal effects on him or affect him to a similar extent.
Right of withdrawal
The data subject has the right to withdraw his consent at any time.
Right to go to court
In the event of a violation of their rights, the data subject may apply to the court against the data controller. The court acts out of sequence in the case.
Data protection official procedure
You can file a complaint with the National Data Protection and Freedom of Information Authority:
- Name: Nemzeti Adatvédelmi és Információszabadság Hatóság
- Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/C. Levelezési cím: 1530 Budapest, Pf.: 5.
- Telephone number: 0613911400
- Fax: 0613911410
- E-mail: Website: http://www.naih.hu
We provide information on data management not listed in this information when the data is collected.
We inform our customers that the court, the prosecutor, the investigative authority, the infringement authority, the public administrative authority, the National Data Protection and Freedom of Information Authority, the Hungarian National Bank, or other bodies based on the authorization of the law, provide information, communicate data, transfer documents, or they can contact the data controller to make it available.
If the authority has specified the exact purpose and the scope of the data, the Data Controller will release personal data to the authorities only to the extent and to the extent that is absolutely necessary to fulfill the purpose of the request.
This document contains all relevant data management information regarding the operation of the webshop in accordance with the European Union’s General Data Protection Regulation No. 2016/679 (hereinafter: Regulation. GDPR) and CXII of 2011. TV. (hereinafter: Infotv.) based on