PRIVACY NOTICE

MOKKATÁRSAK Kereskedelmi Korlátolt Felelősségű Társaság (registered seat: 1056 Budapest, Szarka u. 1.; company registration number: 01-09-963179; tax number: 23386567-2-41; electronic contact: ; phone number: +36 70 626 9919; website: http://habajuicebar.hu/ (hereinafter: the “Website”); hereinafter: the “Data Controller”) hereby informs the users of its services about the data processing carried out by it, in accordance with the applicable statutory provisions governing the protection of personal data.¹

Presentation of the Data Processing

The Data Controller pays special attention to the protection of personal data and always ensures fair and transparent data processing, a fundamental requirement of which is the provision of appropriate information about the processing of data. This Privacy Notice provides, among other things, information about the Data Controller’s data processing in the course of providing its services: the sources and scope of the data processed, the legal basis, purpose and duration of the processing, the rights of data subjects concerning their personal data and the choices available to them, as well as the contact details through which the Data Subject can receive answers to questions regarding the Data Controller’s data protection processes.

The Data Controller provides services related to organizing events and restaurant catering, and sells products on the Website. The Data Controller’s data processing activities are as follows: processing related to fulfilling orders for services connected with organizing events and restaurant catering; processing related to table reservations for restaurant catering services; sending newsletters to Data Subjects; processing related to product orders; processing for maintaining contact between the Data Controller and the Data Subject; processing related to handling consumer complaints submitted to the Data Controller; and, within the scope of the Data Controller’s legal obligations, fulfilling the obligation to retain accounting documents.

In order to make it easier to review the Data Controller’s data processing, summary tables of the individual data processing activities are published below. Detailed information is provided to the data subject in the full Privacy Notice.

Summary of the processing related to fulfilling orders for services connected with organizing events and restaurant catering
Purpose of processingFulfilment of orders for services related to organizing events and restaurant catering
Legal basis of processingPerformance of the contract between the Data Controller and the Data Subject [GDPR Art. 6(1)(b)]
Scope of data processedData Subject’s surname; first name; e-mail address; phone number
Duration of processingThe entire duration of the performance of the service, and thereafter the period during which consumer protection and general civil law claims may be enforced (five years)
Data processorsNEOSOFT Kft. (registered seat: 8000 Székesfehérvár, Távirda u. 2.); purpose of processing: providing IT infrastructure
Summary of the processing related to table reservations
Purpose of processingFulfilment of orders for services related to restaurant catering
Legal basis of processingPerformance of the contract between the Data Controller and the Data Subject [GDPR Art. 6(1)(b)]
Scope of data processedData Subject’s surname; first name; e-mail address; phone number; the date and time of the table reservation; number of guests
Duration of processingUntil the reservation is fully performed; if the reservation is not fulfilled, until the reservation time elapses; if the reservation is cancelled, until the time of cancellation
Data processorsNeosoft Kft. (registered seat: 8000 Székesfehérvár, Távirda u. 2.); purpose of processing: providing IT infrastructure
Summary of the processing related to ordering the Data Controller’s products
Purpose of processingFulfilment of the Data Subject’s order of the Data Controller’s products: – ordering the product on the Website; – sending confirmation to the Data Subject by e-mail regarding the product; – telephone coordination of questions related to the order, in particular delivery; – payment of the purchase price; – delivery of the product or arranging the product’s collection point; – enforcement of the Data Subject’s consumer claims.
Legal basis of processingPerformance of the contract between the Data Controller and the Data Subject [GDPR Art. 6(1)(b)]
Scope of data processedData processed during order fulfilment: Data Subject’s name, e-mail address, phone number; billing data (address, request for parcel delivery or indication of personal collection, payment method); in case of transfer, the bank and bank account number of the Data Subject; in case of card payment, the required card data; delivery data (if different from billing data); order ID; any comment attached to the order. Data processed in case of enforcement of consumer rights: content, place, time and manner of submission of withdrawal, warranty claim or termination; list of documents/evidence submitted; content of minutes taken; response given; essential data of the product (size, item number, price, name, quantity); Data Subject’s name, address, phone number, bank account number; delivery note number; order ID.
Duration of processingFive years following the termination of the service provided to the Data Subject (until claims related to the service become time-barred)
Data processorsNeosoft Kft. (registered seat: 8000 Székesfehérvár, Távirda u. 2.); purpose of processing: providing IT infrastructure
Summary of the processing related to sending the Data Controller’s newsletters
Purpose of processingSending a newsletter to inform recipients about the Data Controller’s promotions, offers, the availability of new products and new services, and to promote the Data Controller’s activities.
Legal basis of processingData Subject’s consent [GDPR Art. 6(1)(a) and Section 6(1) of Act XLVIII of 2008 on the Basic Conditions and Certain Limitations of Commercial Advertising Activity]; consent may be withdrawn at any time
Scope of data processedData Subject’s name; e-mail address
Duration of processingUntil withdrawal of the Data Subject’s consent
Data processorsNEOSOFT Kft. (registered seat: 8000 Székesfehérvár, Távirda u. 2.); purpose of processing: providing IT infrastructure
Summary of the Data Controller’s processing regarding cookies
Purpose of processingCollecting and storing information about the Data Subject’s browsing preferences, personal settings and identification on the Website, in order to tailor the Data Controller’s services to the Data Subject’s needs
Legal basis of processingCookies requiring consent: the Data Subject’s consent [GDPR Art. 6(1)(a)]; consent may be withdrawn at any time. Cookies not requiring consent: the Data Controller’s legitimate interest [GDPR Art. 6(1)(f)]
Scope of data processedAs set out in point 7 of this Privacy Notice
Duration of processingWhere the Data Subject has consented, until withdrawal of that consent
Processing related to contact
Purpose of processingTo allow the Data Subject to ask the Data Controller, in writing or electronically, questions related to the Data Controller’s activities or for other reasons that do not qualify as complaints, and for the Data Controller to answer them.
Legal basis of processingData Subject’s consent [GDPR Art. 6(1)(a)]; consent may be withdrawn at any time
Scope of data processedPersonal data provided by the Data Subject in their message, where applicable the Data Subject’s name, e-mail address, phone number
Duration of processingUntil withdrawal of the Data Subject’s consent, or, absent withdrawal, for five years following the provision of the Data Controller’s service, based on the general limitation period for civil law claims
Summary of the Data Controller’s processing for complaint-handling purposes
Purpose of processingInvestigation of complaints submitted by the Data Subject and providing written information to the Data Subject
Legal basis of processingCompliance with a legal obligation applicable to the Data Controller [GDPR Art. 6(1)(c)]
Scope of data processedAccounting documents supporting the bookkeeping records
Duration of processingThe Data Controller processes the data for five years [Section 17/A(7) of the Consumer Protection Act]
Summary of the Data Controller’s processing for the purpose of fulfilling its document retention obligation
Purpose of processingFulfilment of the Data Controller’s document retention obligation
Legal basis of processingCompliance with a legal obligation applicable to the Data Controller [GDPR Art. 6(1)(c)]
Scope of data processedData Subject’s name, address; the complaint’s unique ID number; the place, time and manner of submitting the complaint; the detailed description of the complaint; list of documents/evidence submitted; content, place and time of the minutes taken; the response given to the complaint; essential data of the product; Data Subject’s e-mail address, phone number, signature.
Duration of processingIn close connection with the sale of the Data Controller’s products, the accounting documents directly and indirectly supporting the bookkeeping records — i.e., the personal data related to fulfilment of the document retention obligation — must be retained for eight years [Section 169(2) of the Accounting Act]

1. Data Subject

The following belong among those affected by the Data Controller’s processes relating to the handling of personal data:

  • natural persons using the Data Controller’s services related to organizing events and restaurant catering;
  • natural persons making a table reservation for the Data Controller’s restaurant catering services;
  • persons ordering the Data Controller’s products;
  • persons subscribing to the newsletter;
  • recipients of the cookies applied by the Data Controller;
  • persons maintaining contact with the Data Controller;
  • persons submitting a complaint to the Data Controller

(hereinafter jointly: the “Data Subject”).

2. Sources from Which the Data Controller Obtains Personal Data

The Data Controller receives the Data Subject’s personal data from the Data Subject in the course of:

  • ordering the service, or concluding the contract for the service;
  • the online or telephone table reservation;
  • ordering the product;
  • subscribing to the newsletter;
  • accepting the use of cookies;
  • a request aimed at maintaining contact;
  • submitting a complaint.

3. Legal Basis, Purpose, Scope of the Data Processed and Duration of Processing

3.1 Data processed for the purposes of the Data Controller’s services related to organizing events and restaurant catering, legal basis and duration of processing

3.1.1. The legal basis of the Data Controller’s processing carried out for the purpose of fulfilling the services used by the Data Subject is the performance of the contract between the Data Controller and the Data Subject [GDPR Art. 6(1)(b)].

3.1.2. For the purpose of fulfilling the services, the Data Controller processes the Data Subject’s surname, first name, e-mail address and phone number.

3.1.3. The Data Controller processes the data processed for this purpose for the entire duration of the service provided to the Data Subject, and thereafter for five years, with regard to the period during which consumer protection and general civil law claims may be enforced.

3.2 Data processed by the Data Controller in connection with table reservations, legal basis and duration of processing

3.2.1. The legal basis of the Data Controller’s processing carried out for the purpose of fulfilling the Data Subject’s table reservation is the performance of the contract between the Data Controller and the Data Subject [GDPR Art. 6(1)(b)].

3.2.2. For the purpose of fulfilling the services, the Data Controller processes the Data Subject’s surname, first name, e-mail address, phone number, the date and time of the table reservation, and the number of guests.

3.2.3. The Data Controller processes the data processed for this purpose until the reservation is fully performed; if the reservation is not fulfilled, until the reservation time elapses; if the reservation is cancelled, until the time of cancellation.

3.3 Data processed for the purpose of ordering the Data Controller’s products, legal basis and duration of processing

3.3.1. The legal basis of the Data Controller’s processing carried out for the purpose of fulfilling the Data Subject’s order of the Data Controller’s products is the performance of the contract between the Data Controller and the Data Subject [GDPR Art. 6(1)(b)]. Fulfilment of the Data Subject’s order of the Data Controller’s products includes the following purposes:

  • ordering the product on the Website;
  • sending a confirmation regarding the product to the Data Subject by e-mail;
  • telephone coordination of questions related to the order of the product, in particular delivery;
  • payment of the purchase price;
  • delivery of the product or arranging the product’s collection point;
  • enforcement of the Data Subject’s consumer claims.

3.3.2. For the purpose of fulfilling orders of its products, the Data Controller processes the following data:

Data processed during the fulfilment of the order:

  • Data Subject’s name, e-mail address, phone number;
  • Data Subject’s billing data: address, request for parcel delivery or indication of personal collection, payment method (cash on delivery, bank transfer, or card payment); in case of transfer, the bank providing financial services to the Data Subject and the Data Subject’s bank account number; in case of card payment, the card data required for the payment;
  • delivery data (if different from the billing data): name, address;
  • order ID;
  • any comment the Data Subject may attach to the order.

Data processed in the event the Data Subject enforces consumer rights:

  • the content of the withdrawal, warranty claim or termination (reason for return), and the place, time and manner of submission;
  • the list of documents, papers and other evidence submitted by the Data Subject;
  • the content of the minutes taken regarding the enforcement of the consumer right;
  • the response given to the withdrawal, warranty claim or termination;
  • essential data of the product (size, item number, price, name, quantity);
  • the Data Subject’s name, address, phone number, bank account number; delivery note number; order ID.

3.3.3. The Data Controller processes the data processed for this purpose for the entire duration of the service provided to the Data Subject, and thereafter for five years, with regard to the period during which consumer protection and general civil law claims may be enforced.

3.4 Data processed for the purpose of sending the Data Controller’s newsletters, legal basis and duration of processing

3.4.1. The Data Controller sends newsletters to inform recipients about personalized promotions, offers, the availability of new products and new services, and to promote the Data Controller’s activities. The legal basis for this processing is the Data Subject’s consent [GDPR Art. 6(1)(a); also Section 6(1) of Act XLVIII of 2008 on the Basic Conditions and Certain Limitations of Commercial Advertising Activity]. Consent may be withdrawn at any time.

3.4.2. Within the framework of this processing, the Data Controller processes the following data: the Data Subject’s name and e-mail address.

3.4.3. The Data Controller processes the data until the Data Subject’s consent is withdrawn, after which it deletes the data. Consent may be withdrawn free of charge at any time; the Data Subject may unsubscribe from the newsletter at any time, and the Data Controller provides separate information about this in every newsletter.

3.5 Data processed for the purpose of contact, legal basis and duration of processing

3.5.1. The legal basis of the processing carried out for the purpose of contact between the Data Controller and the Data Subject — within which framework the Data Subject is given the opportunity to ask, in writing or electronically, questions related to the Data Controller’s activities or for other reasons that do not qualify as a complaint, and to receive an answer from the Data Controller — is the Data Subject’s consent [GDPR Art. 6(1)(a)]. Consent may be withdrawn at any time.

3.5.2. Within this framework, the Data Controller processes the following data:

  • the personal data provided by the Data Subject in their message, where applicable the Data Subject’s name, e-mail address and phone number.

3.5.3. The Data Controller processes the data processed until withdrawal of the Data Subject’s consent, or, absent withdrawal of consent, following the provision of the Data Controller’s service, for five years, based on the general limitation period for civil law claims.

3.6 Data processed for complaint-handling purposes, legal basis and duration of processing

3.6.1. The legal basis of the Data Controller’s processing carried out for the purpose of investigating complaints submitted by the Data Subject and providing written information to the Data Subject is compliance with a legal obligation applicable to the Data Controller [GDPR Art. 6(1)(c)].

3.6.2. For this purpose, the Data Controller processes the following data:

  • the Data Subject’s name and address; the complaint’s unique ID number; the place, time and manner of submitting the complaint; the detailed description of the Data Subject’s complaint; the list of documents, papers and other evidence submitted by the Data Subject; the content, place and time of taking the minutes; the response given to the complaint; essential data of the product; the Data Subject’s e-mail address, phone number and signature.

3.6.3. In the course of the processing carried out for the purpose of investigating a complaint submitted by the Data Subject, the Data Controller processes the minutes taken of the complaint and the copy of the response for five years, pursuant to Section 17/A(7) of Act CLV of 1997 on Consumer Protection.

3.7 Data processed for the purpose of fulfilling the Data Controller’s document retention obligation, legal basis and duration of processing

3.7.1. The legal basis of the Data Controller’s processing carried out for the purpose of fulfilling its document retention obligation is compliance with a legal obligation applicable to the Data Controller [GDPR Art. 6(1)(c); Section 169 of Act C of 2000 on Accounting (hereinafter: the “Accounting Act”)].

3.7.2. Within this framework, the Data Controller processes the following data:

  • accounting documents directly and indirectly supporting the bookkeeping records closely connected with the sale of its products.

3.7.3. In the course of the processing carried out for this purpose, the Data Controller is obliged, pursuant to Section 169(2) of the Accounting Act, to retain for eight years the accounting documents directly and indirectly supporting the bookkeeping records closely connected with the sale of its products.

4. Data Processing (Data Processors)

Among the Data Controller’s contracted partners engaged as necessary for the performance of the services, the following are the data processors through whom the Data Subject’s data are processed:

  • The Rocket Science Group LLC d/b/a MailChimp (registered seat: 675 Ponce De Leon Ave NE, Suite 5000, Atlanta, Georgia 30308, USA)

The Rocket Science Group LLC d/b/a MailChimp provides appropriate safeguards for the transfer of personal data by applying standard contractual clauses pursuant to GDPR Art. 46(2)(c).

Purpose of processing: advertising-related data processing – sending newsletters

  • Neosoft Kft. (registered seat: 8000 Székesfehérvár, Távirda u. 2.)

Purpose of processing: providing IT infrastructure

  • Mokkatársak Kft. (registered seat: 1056 Budapest, Szarka u. 1.; company registration number: 01-09-963179; tax number: 23386567-2-41)

Purpose of processing: collecting guests’ data

5. Data Security, Persons Entitled to Access the Data

5.1. Upon expiry of the data processing period, the Data Controller deletes the Data Subject’s data.

5.2. The Data Controller ensures the security of the data it processes and takes every measure to protect the Data Subject’s privacy and to prevent unauthorized access, alteration, transmission, disclosure, deletion or destruction, as well as accidental destruction and damage, and inaccessibility resulting from a change in the technology applied — that is, to ensure that Data Subjects’ personal data receive protection in accordance with applicable law.

5.3. Among the measures necessary to maintain the requirements of data security, the Data Controller processes the Data Subject’s data in a computer database, both automatically and manually, and has arranged for the Data Subject’s data to be processed in a closed system, always protected by password and saved to a hard drive, and for these systems to be used only in connection with, and to the extent strictly necessary for, the provision of the service, by those entitled to access the data.

5.4. The computer systems are protected by a firewall and appropriate virus protection.

5.5. The Data Controller carries out technical inspection of the system and takes action if an error is detected or reported.

5.6. The Data Controller ensures that those entitled to access the data receive comprehensive information about data protection rules. As a data security safeguard, the Data Controller’s executive officers and employees are subject to confidentiality obligations and legal liability regarding the personal data they become aware of in the course of their activities.

5.7. Information and network identifiers (IP address) that become accessible to the Data Controller through visitors’ use of the Website, and through the Data Subject’s use of their computer, are logged for the purpose of generating website visitor statistics and detecting any errors and attempted attacks that may arise. The Data Controller does not link the network identifiers to any other data that would allow the identification of the website visitor or the Data Subject. Beyond what is set out in this Privacy Notice, no other cookies or web bugs are downloaded in connection with visiting the Website.

5.8. The persons entitled to access the data processed by the Data Controller are limited to the circle strictly necessary to achieve the given processing purpose, and only those who need such access to perform their job duties have access rights.

6. Data Subject Rights, Remedies

6.1. The Data Subject may exercise the rights set out in this section electronically, at the e-mail address rosenstein@rosenstein.hu, or by post, in a letter addressed to the Data Controller at its registered seat.

6.2. At the Data Subject’s request, the Data Controller provides information in writing or electronically [GDPR Art. 15(1); right to information]:

  • about what data it processes concerning the Data Subject;
  • about the purposes of the processing;
  • about the categories of recipients to whom it may transfer the personal data;
  • about the duration of the processing;
  • about the Data Subject’s rights and remedies.

6.3. Before initiating the procedures regulated in this section, the Data Subject is entitled to turn to the Data Controller with a complaint — which may also be submitted electronically — in order to remedy any concerns regarding the processing and to restore lawful conditions. The Data Controller investigates the complaint within one month, takes minutes about it, decides on its merits, and informs the Data Subject of its decision in writing, electronically. If the Data Controller establishes that the Data Subject’s complaint is well-founded, it restores the lawful state of the processing, or terminates the processing — including any further collection and transfer of data. In such a case, the Data Controller may no longer process the Data Subject’s data, unless it proves that the processing is justified by compelling legitimate grounds which override the Data Subject’s interests, rights and freedoms, or which relate to the establishment, exercise or defence of legal claims. The Data Controller notifies those to whom it transferred the data concerned by the complaint about the complaint and any measures taken based on it. The complaint procedure regulated in this section serves to remedy concerns regarding data processing within the framework of maintaining contact with the Data Subject and does not apply to legal declarations made in connection with enforcing consumer rights related to on-site purchases of the Data Controller’s products.

6.4. At the Data Subject’s request, the Data Controller provides a copy of the personal data in a commonly used electronic format, or in another format chosen by the Data Subject [GDPR Art. 15(3); right of access, right to receive a copy].

6.5. The Data Controller modifies or corrects (rectifies) the Data Subject’s personal data in accordance with the Data Subject’s request [GDPR Art. 16; right to rectification].

6.6. At the Data Subject’s request, the Data Controller deletes the Data Subject’s personal data. The Data Controller may refuse to comply with the request for the reasons set out in GDPR Art. 17(3), for example if the personal data are necessary for the establishment or enforcement of a legal claim, or for compliance with a legal obligation under EU or Member State law applicable to the Data Controller, or for reasons of public interest, or for exercising the right to freedom of expression and information [GDPR Art. 17; right to erasure].

6.7. The Data Subject may withdraw, at any time, without restriction or justification, their consent given to the processing of their personal data for the purposes of sending advertising newsletters, filling labour shortages, applying cookies requiring consent, and for the purpose of contact, and may also give notice objecting to the sending of advertising. In such a case, the Data Controller immediately deletes all of the Data Subject’s personal data from its records and will no longer send newsletters to the Data Subject [right to withdraw consent]. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.

6.8. The Data Subject is entitled to request the restriction (blocking) of the processing of personal data:

  • if the Data Subject contests the accuracy of the personal data, for a period enabling the Data Controller to verify the accuracy of the personal data;
  • if the processing is unlawful and the Data Subject opposes the erasure of the personal data and requests the restriction of their use instead;
  • if the Data Controller no longer needs the personal data, but the Data Subject requests the restriction of the data for the establishment, exercise or defence of legal claims [GDPR Art. 18; right to restriction of processing (blocking)].

The Data Controller complies with a restriction request by storing the personal data separately from all other personal data. For example, in the case of electronic data files, it exports them to an external storage device, or, in the case of data stored on paper, moves them to a separate folder. With the exception of storage, the Data Controller processes such data only with the Data Subject’s consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or a Member State. We will inform the Data Subject in advance about the lifting of this restriction on processing.

6.9. The Data Subject is entitled to receive their personal data in a structured, commonly used, machine-readable format, and is entitled to transmit those data to another controller. In addition, the Data Controller ensures that, upon the Data Subject’s explicit request, it transmits the Data Subject’s data directly to another controller designated by the Data Subject [GDPR Art. 20(1) and (2); right to data portability].

6.10. The Data Controller informs the Data Subject of the measures taken within one month of receiving the Data Subject’s request. If the request is refused, the Data Controller informs the Data Subject, within one month of receipt of the request, of the reasons for the refusal, as well as of the fact that the Data Subject may lodge a complaint with the Authority and may exercise their right to judicial remedy.

6.11. Exercising these rights is free of charge. In certain cases, the Data Controller may charge a fee based on administrative costs, or may refuse to act on the request, if the Data Subject requests a copy of their data, or if the Data Subject’s request is manifestly unfounded or — in particular because of its repetitive nature — excessive.

6.12. The Data Controller reserves the right, if it has reasonable doubts concerning the identity of the person submitting the request, to request the provision of information necessary to confirm the Data Subject’s identity. This applies in particular where the Data Subject exercises their right to request a copy, in which case it is justified for the Data Controller to satisfy itself that the request originates from the entitled person.

6.13. If, in the Data Subject’s assessment, the Data Controller has infringed their right to the protection of personal data, or the Data Controller carries out unlawful data processing, the Data Subject may initiate proceedings before the Authority. Contact details of the Authority: postal address: 1530 Budapest, Pf.: 5.; e-mail: ugyfelszolgalat@naih.hu; phone: +36 (1) 391-1400; website: www.naih.hu.

6.14. If, in the Data Subject’s assessment, the Data Controller has infringed their right to the protection of personal data, the Data Subject may also initiate court proceedings and may claim compensation for damages caused by the unlawful processing of their data or by a breach of data security, and, in the case of infringement of personality rights, may claim compensation for the injury suffered. In the case of judicial enforcement, the Data Subject may also bring the action before the regional court (törvényszék) having jurisdiction over their place of residence or stay.

7. Cookies

7.1. When the Data Subject visits the Website, their computer stores cookies. Cookies are small text files that the browser stores on the Data Subject’s device in order to save certain information. When the Data Subject visits the Website again using the same device, the information saved in the cookies is transmitted either back to the Website (a “first-party cookie”) or to another website to which the cookie belongs (a “third-party cookie”).

7.2. Through the saved and returned information, the Website recognizes that the Data Subject has previously logged in and visited it using the browser used on that device. The Data Controller uses this information to design and display the Website optimally, in line with the Data Subject’s preferences. In this respect, only the cookie itself is identified on the Data Subject’s device. Beyond this extent, the Data Controller only stores the Data Subject’s personal data with the Data Subject’s express consent, or where it is strictly necessary for the use of the service offered to and used by the Data Subject.

7.3. The legal basis of the Data Controller’s processing carried out through the use of cookies — that is, tailoring the services provided on the Website to the Data Subject’s needs — is the Data Subject’s consent [GDPR Art. 6(1)(a)]. The cookies requiring the Data Subject’s consent are the Advertising cookies.

7.4. The Data Subject may give consent to the use of cookies by clicking the relevant checkbox for the given cookie on the Website. The Data Controller provides information below about the cookies that do not require the Data Subject’s consent.

7.5. The Website uses the following types of cookies, an explanation of whose scope and function is set out below:

  • Strictly necessary cookies
  • Function and Performance cookies
  • Consent-based cookies

7.6. The Website uses the following cookies:

Cookie nameCookie typeCookie providerData processed by cookiePurpose of cookieCookie lifetime
EssentialGeneral analyticsGoogleBrowserIdentifying customer interestDuration of browsing session
Stat cookieStatisticalGoogle AnalyticsProfileIdentifying customer interestUntil cache is cleared
Targeting cookieMarketingGoogle Analytics, FB, Google AdsClicksIdentifying customer interestUntil cache is cleared

7.7 Strictly necessary cookies

7.7.1. Strictly necessary cookies provide functions without which the Website cannot be used as intended. These cookies are used exclusively by the Data Controller, and are therefore first-party cookies. This means that all information stored in the cookies is returned to the Website.

7.7.2. Strictly necessary cookies serve, for example, to keep the Data Subject, as a registered user, logged in while navigating the Website’s various subpages, so that they do not have to re-enter their login credentials each time they access a new page.

7.7.3. The use of strictly necessary cookies on the Website is possible without the Data Subject’s consent. Strictly necessary cookies therefore cannot be individually activated or deactivated. However, the Data Subject may switch off cookies at any time in their browser.

7.7.4. Legal basis: GDPR Art. 6(1)(b).

7.8 Function and Performance cookies

7.8.1. Function cookies allow the Website to store data already provided (such as the registered name or language selection) and, based on this data, to offer improved and more personalized functions. These cookies only collect and store anonymous data, so that they cannot track the Data Subject’s movements on other websites.

7.8.2. Performance cookies collect data about how the Website is used, in order for the Data Controller to improve the Website’s attractiveness, content and functions. These cookies help, for example, to determine whether the Website’s subpages are visited, and which subpages are visited, as well as which content is of particular interest to users. Performance cookies also serve to:

  • record, in particular, the number of visits to a page, the number of visits to subpages, the time spent on the Website, the order of pages visited, which search terms led the Data Subject to the Data Controller, the country, region and, where applicable, the city from which the Data Subject accesses the Website, as well as the proportion of mobile devices accessing the Website;
  • record the movement of the computer mouse, as well as clicks and scrolling performed with the mouse, so that the Data Controller can understand which areas of the Website are of particular interest to users.

7.8.3. The Data Controller does not use this data in connection with the Data Subject’s name or user profile, but processes it as part of statistical reports. As a result, it can adapt the Website’s content to users’ needs and optimize its offering. The Data Subject’s IP address, transmitted for technical reasons, is automatically anonymized and does not allow conclusions to be drawn about the individual user.

7.8.4. Legal basis: GDPR Art. 6(1)(f).

7.9 Consent-based cookies

7.9.1. The Data Controller uses cookies that are not strictly necessary and are not function or performance cookies — such as advertising/marketing cookies — only with the Data Subject’s express consent.

7.9.2. The Data Controller further reserves the right to use the data obtained through cookies from the anonymous analysis of website visitors’ habits in order to display certain advertisements for its products on the Website. This is to the Data Subject’s benefit, because the Data Controller thereby displays advertising or content that, based on the Data Subject’s browsing habits, it considers likely to be of interest to the Data Subject, resulting in the Data Subject seeing fewer randomly displayed advertisements or content that is less aligned with the Data Subject’s needs.

7.9.3. Marketing cookies come from external advertising companies (third-party cookies) and collect information about websites visited by the Data Subject in order to create targeted advertising for the Data Subject.

7.9.4. Legal basis: GDPR Art. 6(1)(a).

7.9.5. The Data Subject may disable cookies used for online advertising through tools created by self-regulatory programs in numerous countries, which ensure that the Data Subject’s choices are respected — such as the American https://www.aboutads.info/choices/ or the European http://www.youronlinechoices.com/hu/. Cookie settings options can be found depending on the browser used (Internet Explorer, Google Chrome, Mozilla Firefox, Safari — see each browser’s help pages). Through these settings, the Data Subject can determine which tracking functions to allow or disallow on their computer. The Data Subject may withdraw their consent to the use of consent-based cookies individually, for the future, at any time, by adjusting the cookie settings accordingly.

7.9.6. Data Subjects who do not want Google Analytics to report on their visit may install the Google Analytics opt-out browser add-on. This add-on instructs the Google Analytics JavaScript scripts (ga.js, analytics.js and dc.js) not to send visit information to Google. In addition, Data Subjects who have installed the opt-out browser add-on will also not participate in content experiments. A Data Subject who wishes to opt out of Analytics’ web-activity tracking may visit the Google Analytics opt-out page (http://tools.google.com/dlpage/gaoptout) and install the add-on for their browser. For further information about installing and removing the add-on, please see the help section of the relevant browser.

7.10 Managing and deleting cookies

The Data Subject can set their browser (Internet Explorer, Google Chrome, Mozilla Firefox, Safari) so that, as a general rule, it does not allow the saving of cookies, and/or so that the browser asks each time whether the Data Subject agrees to enable cookies. The Data Subject may delete, at any time, any cookies they have re-enabled. Detailed information on how this works can be obtained by using the browser’s help function. Generally disabling the use of cookies may restrict the operation of certain functions of the Website.

7.11 Google Analytics

7.11.1. The Website uses Google Analytics, the web analytics service of Google Inc. (“Google”). In doing so, Google Analytics uses a specific form of cookie, which is stored on the Data Subject’s computer and which enables analysis of the Data Subject’s use of the Website. The information generated by the cookie about the Data Subject’s use of the Website is generally transmitted to and stored on a Google server located in the United States.

7.11.2. The Data Subject can prevent the storage of cookies by applying the appropriate settings in their browser software. In addition, the Data Subject can prevent Google from recording and processing the data generated by the cookie relating to the Data Subject’s use of the Website (including their IP address) by downloading and installing the browser plug-in available at https://tools.google.com/dlpage/gaoptout?hl=en.

7.11.3. The Website also uses Google Analytics for device-independent analysis of visitor flow through a user ID. The Data Subject can disable cross-device tracking of their use in their Google account, under “My Info” / “Personal info.”

7.11.4. Legal basis: GDPR Art. 6(1)(f).

7.12 Display of the Data Controller’s advertisements by external providers

7.12.1. The Data Controller’s advertisements are displayed by external providers — including Google — on various websites. The Data Controller and external providers, such as Google, jointly use their own cookies (such as Google Analytics cookies) and third-party cookies (such as DoubleClick cookies) to inform themselves based on users’ previous visits to the website, and to optimize and display advertisements.

7.12.2. Legal basis: GDPR Art. 6(1)(f).

7.13 Social Plug-ins

7.13.1. On the Website, the Data Controller uses social network plug-ins (“Social plug-ins”), in particular Facebook’s “Share” or “Share with friends” button. Facebook’s website, https://www.facebook.com/, is operated by Facebook Inc. (1601 S. California Ave, Palo Alto, CA 94304, USA), for which Facebook Ireland Limited (Hanover Reach, 5-7 Hanover Quay, Dublin 2, Ireland) is responsible in Europe. The plug-ins are generally marked with the Facebook logo.

7.13.2. By clicking the relevant button (e.g., “Share” or “Share with friends”), the Data Subject consents to their browser establishing a connection with the servers of the relevant social network, and to usage data being transmitted between the Data Subject and the relevant operator of the social network. The Data Controller has no influence over what kind and extent of data the social networks subsequently collect. The social network provider stores the data collected about the Data Subject as a user profile and uses it for advertising, market research and/or demand-oriented design of the Website. Such evaluation takes place, in particular, in order to develop demand-oriented advertising activity (also for users who are not logged in), and also to inform other users of the social network about the Data Subject’s activities on our Website. The Data Subject is entitled to object to the creation of such user profiles, in which case, to exercise this right, they must contact the provider of the relevant plug-in. Through the plug-ins, the Data Controller provides the Data Subject with the opportunity to establish contact with social networks and other users, so that the Data Controller can develop its offering and make it more interesting for the Data Subject as a user.

7.13.3. The data is transmitted regardless of whether the Data Subject has an account with the plug-in provider and whether they are logged in. If the Data Subject is logged in to the plug-in provider, the data collected by the Data Controller is directly assigned to their existing account with the plug-in provider. If the Data Subject clicks the “Activate” button and, for example, connects to the page, the plug-in provider also stores the information in the user’s account and shares it publicly with the Data Subject’s friends. The Data Controller recommends that the Data Subject log out of the social network regularly after use, especially before activating the button, in order to avoid being assigned to their existing profile with the plug-in provider.

7.13.4. For further information regarding the purpose and scope of data collection, and the processing carried out by the plug-in provider, the Data Subject may review the privacy statements of the relevant provider indicated below, which provide further information about their rights in this area, as well as about the settings available to protect their data.

Facebook Inc. (1601 S California Ave, Palo Alto, California 94304, USA); http://www.facebook.com/policy.php; further information on data collection: http://www.facebook.com/help/186325668085084, http://www.facebook.com/about/privacy/your-info-on-other#applications, as well as http://www.facebook.com/about/privacy/your-info#everyoneinfo. Facebook previously self-certified under the EU-US Privacy Shield (https://www.privacyshield.gov/EU-US-Framework); however, Facebook Ireland Limited (Hanover Reach, 5-7 Hanover Quay, Dublin 2, Ireland) is responsible for the data-processing operations of the Facebook website.

8. Other Provisions

8.1. If the Data Controller amends this Privacy Notice, it will publish a notice about this on the Website, and will also send the amended notice to the e-mail address provided by the Data Subject, so that the Data Subject can become aware of it.

8.2. The Data Controller provides information about any data processing not listed in this Privacy Notice at the time the data is collected. Courts, the prosecution service, other investigating authorities, misdemeanour authorities, administrative authorities, the National Authority for Data Protection and Freedom of Information, and, under statutory authorization, other bodies, may approach the Data Controller for the purpose of providing information, disclosing or transferring data, or making documents available. The Data Controller discloses personal data to such authorities — provided that the authority has indicated the exact purpose and scope of the data requested — only to the extent and degree strictly necessary to achieve the purpose of the request.

8.3. If the Data Controller intends to further process the personal data for a purpose other than that for which they were collected, it will inform the Data Subject, prior to such further processing, of that other purpose and of all relevant additional information.

8.4. If the Data Controller also discloses the data to another recipient, it will inform the Data Subject about this at the latest when the personal data are first disclosed.

¹ Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, GDPR). The text of the GDPR is available in all official languages of the European Union at eur-lex.europa.eu.

 

Data Transfer Statement

I acknowledge that the following personal data stored in the user account of the data controller MOKKATÁRSAK Korlátolt Felelősségű Társaság (1056 Budapest, Szarka u. 1., Hungary) in the user database of www.habajuicebar.com will be handed over to SimplePay Plc. and is trusted as data processor. The data transferred by the data controller are the following: name, e-mail address, phone number, and billing address details (country, postal code, city, address); where the customer checks out as a company (“company” customer type), the company name and tax number as well.

The nature and purpose of the data processing activity performed by the data processor can be found in the SimplePay Privacy Policy at the following link: https://simplepay.hu/adatkezelesi-tajekoztatok/