Privacy notice

1. Introduction

bioholisticcosmetic.hu (hereinafter bioholisticcosmetic.hu, service provider, data controller, Company), as data controller, acknowledges the content of this legal notice as binding upon itself. 
The Company undertakes that all data processing related to its activities complies with the requirements set out in this policy and in the applicable legislation. 
bioholisticcosmetic.hu is the operator of the bioholisticcosmetic.hu website.

bioholisticcosmetic.hu reserves the right to change this notice at any time. It will of course notify its audience of any changes in good time.

bioholisticcosmetic.hu is committed to protecting the personal data of its customers and partners, and considers respect for its customers' right to informational self-determination to be of paramount importance. The Data Controller treats personal data confidentially and takes all security, technical and organisational measures that guarantee the security of the data.

bioholisticcosmetic.hu sets out its data processing principles below and presents the expectations it has formulated for itself as data controller and complies with. Its data processing principles are in line with the applicable data protection legislation, in particular the following:

  • Act CXII of 2011 on the right to informational self-determination and freedom of information;
  • Act V of 2013 on the Civil Code (Ptk.);
  • Act XLVIII of 2008 on the basic conditions and certain restrictions of commercial advertising activity (Grt.);
  • Act CVIII of 2001 (Ekertv.) on certain issues of electronic commerce services and information society services;
  • Regulation (EU) 2016/679 of the European Parliament and of the Council (27 April 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: “GDPR”).

2. Definitions

  • data subject: any specific natural person identified or identifiable, directly or indirectly, on the basis of personal data;
  • personal data: data that can be associated with the data subject, in particular the data subject's name, identification mark, and one or more pieces of information characteristic of their physical, physiological, mental, economic, cultural or social identity, as well as any conclusion regarding the data subject that can be drawn from it;
  • consent: the voluntary and definite expression of the data subject's wishes, based on adequate information, by which they give their unambiguous agreement to the processing, in full or covering certain operations, of personal data relating to them;
  • data controller: the natural or legal person or organisation without legal personality who or which, alone or jointly with others, determines the purpose of the processing of data, makes and implements the decisions concerning data processing (including the means used), or has them implemented by the data processor;
  • data processing: any operation or set of operations performed on data, irrespective of the procedure applied, in particular collecting, recording, registering, organising, storing, altering, using, retrieving, transmitting, disclosing, aligning or combining, blocking, erasing and destroying, as well as preventing further use of the data, taking photographs, sound or video recordings, and recording physical characteristics suitable for identifying a person (e.g. finger or palm prints, DNA samples, iris images);
  • data transfer: making data available to a specific third party;
  • disclosure: making data available to anyone;
  • data erasure: rendering data unrecognisable in such a way that its restoration is no longer possible;
  • data processing (technical): performing technical tasks related to data processing operations, irrespective of the method and means used to perform the operations and the place of application, provided that the technical task is performed on the data;
  • data processor: the natural or legal person or organisation without legal personality who or which performs the processing of data on the basis of a contract, including a contract concluded pursuant to a provision of law. 

3. Company details

Our company's details and contact information are as follows:

  • Name: bioholisticcosmetic.hu
  • Postal address: Székesfehérvár
  • Company registration number: 42002727
  • Tax number: 66989486-2-27
  • Telephone: +36 30 298 0111
  • E-mail:  info@bioholisticcosmetic.hu
  • Representative of the data controller: %%vezeto%%

4. Scope of personal data, purpose, legal basis and duration of data processing

We draw the attention of those providing data to bioholisticcosmetic.hu that if they do not provide their own personal data, it is the data provider's obligation to obtain the data subject's consent. The data controller is not obliged to verify the existence of such consent. The data controller draws the partner's attention to the fact that if they fail to fulfil this obligation and the data subject therefore asserts a claim against the data controller, the data controller may pass on the asserted claim and the amount of the related damage to the partner.

We provide the following information regarding our individual data processing activities. 

4.1. Request for quotation, enquiry by direct contact

Interested parties have the opportunity to contact our Company directly by electronic mail sent to the Company's address or by telephone.

  • Purpose of data processing: keeping contact, promoting communication between the data subject and our Company, and in the interest of ever closer and more effective cooperation.
  • Legal basis of data processing: legitimate interest – Article 6(1)(f) GDPR
  • Scope of personal data processed: name of the requester/contact person; e-mail address, telephone number and other information provided by the data subject,
  • Duration of data processing: for 3 years after the validity period of the offer, or until the data subject objects
  • Recipients of personal data: the data controller does not transfer the data obtained to third parties, with the exception of the data processor(s) indicated in section 7. The recorded data may be accessed only by the Data Controller's employees and the designated colleagues of the data processor(s).
  • Designation of the legitimate interest: our Company's legitimate interest in processing the data subject's data – direct marketing
  • Persons concerned by the data processing: partners and data subjects enquiring directly (e.g. by e-mail, telephone) about the Company's services. 

4.2. Request for quotation, enquiry via the website (bioholisticcosmetic.hu)

Our company gives data subjects the opportunity to request a quotation electronically.

  • Purpose of data processing: keeping contact, promoting communication between the data subject and our Company, and in the interest of ever closer and more effective cooperation.
  • Legal basis of data processing: the data subject's voluntary consent – Article 6(1)(a) GDPR.
  • Scope of personal data processed: the enquirer's name (first name, surname); e-mail address, telephone number, company name and other information provided by the data subject.
  • Duration of data processing: for 3 years after the validity period of the offer, or until the consent is withdrawn.
  • Recipients of personal data: the data controller does not transfer the data obtained to third parties, with the exception of the data processor(s) indicated in section 7. The recorded data may be accessed only by the Data Controller's employees and the designated colleagues of the data processor(s).
  • Persons concerned by the data processing: partners and data subjects enquiring via the website about the Company's services and products.

4.3. Data processing related to the follow-up of requests for quotation

  • Purpose of data processing: the data controller's legitimate interest in keeping records of the data subject's data beyond the validity period of the offer for direct marketing purposes
  • Legal basis of data processing: the data controller's legitimate interest, Article 6(1)(f) GDPR,
  • Scope of personal data processed: contact person's surname and first name; telephone number; e-mail address
  • Recipients of personal data: the data controller does not transfer the data obtained to third parties, with the exception of the data processor(s) indicated in section 7. The recorded data may be accessed only by the Data Controller's employees and the designated colleagues of the data processor(s).
  • Duration of data processing: until the data subject objects
  • Designation of the legitimate interest: establishing business relations with partners and requesters, accurate information for data subjects. Our Company's legitimate interest in processing the data subject's data – direct marketing
  • Persons concerned by the data processing: the addressees of offers previously issued by the Company and the contact person(s) named in them.

4.4. Newsletter registration

  • Purpose of data processing: sending e-mail newsletters, also containing commercial advertising, to interested parties, informing them of current information
  • Legal basis of data processing: the data subject's prior, voluntary consent, Article 6(1)(a) GDPR,
  • Scope of personal data processed: name, e-mail address
  • Duration of data processing: until the voluntary consent is withdrawn, until unsubscribing from the newsletter. Our Company processes the data provided by the data subject until the consent is withdrawn. Based on the withdrawal of consent, we delete the processed data from our newsletter database within 7 days at the latest, and thereafter we do not send you newsletters.
  • Recipients of personal data: the data controller does not transfer the data obtained to third parties, with the exception of the data processor(s) indicated in section 7. The recorded data may be accessed only by the Data Controller's employees and the designated colleagues of the data processor(s). You may unsubscribe from the newsletter at any time by sending a letter to our Company at info@bioholisticcosmetic.hu, or by clicking the unsubscribe icon in the newsletter. 
  • Persons concerned by the data processing: partners and data subjects subscribing to the Company's electronic newsletter.

4.5. Newsletter data (for newsletters registered before 25 May 2018)

  • Purpose of data processing: sending e-mail newsletters, also containing commercial advertising, to interested parties, informing them of current information
  • Legal basis of data processing: the data controller's legitimate interest, Article 6(1)(f) GDPR,
  • Scope of personal data processed: name, e-mail address
  • Duration of data processing: until the data subject objects
  • Designation of the legitimate interest: information for data subjects who subscribed to the newsletter, also containing commercial advertising and business offers. Our Company's legitimate interest in processing the data subject's data, direct marketing.
  • Recipients of personal data: the data controller does not transfer the data obtained to third parties, with the exception of the data processor(s) indicated in section 7. The recorded data may be accessed only by the Data Controller's employees and the designated colleagues of the data processor(s). You may unsubscribe from the newsletter at any time by sending a letter to our Company at info@bioholisticcosmetic.hu, or by clicking the unsubscribe icon in the newsletter. 
  • Persons concerned by the data processing: partners and data subjects who subscribed to the Company's electronic newsletter before 25 May 2018.

4.6. Camera system

Cameras operate on the premises operated by the data controller for the personal and property security of data subjects and for other purposes. Information signs draw data subjects' attention to their operation. The activities related to the operation of the camera system have been defined in the premises' “Property protection camera data processing notice”, which is available on the premises.

4.7. Data processing related to ensuring the operation of the information technology service

  • Purpose of data processing: the bioholisticcosmetic.hu websites may use so-called “cookies” (temporary markers), which enable faster access to them. By “cookies” we mean a piece of information data that is active only for the duration of the individual customer session and is placed from the website on the Customer's computer for faster identification. The Customer may at any time request that cookies be switched off by changing the browser settings; however, switching them off may slow down or prevent access to some parts of the site or the use of certain functions. 
    The session cookies used avoid resorting to other IT tools that are potentially harmful to the confidentiality of customers' navigation and do not allow the acquisition of identifying personal data.
    The user can delete the cookie from their own computer, or disable the use of cookies in their browser. Cookies can generally be managed in the Tools/Settings menu of browsers under Privacy settings, under the name cookie.
  • Legal basis of data processing: the data subject's (User's) voluntary consent, Article 6(1)(a) GDPR.
    The User gives their voluntary consent to the data processing by accepting the pop-up notice and declaration when starting to browse the website, or by continuing to browse.
    Scope of personal data processed: the information technology data processing concerns the scope of data necessary for the operation of the “cookies” used to operate the website and for the use of the log files applied by the web hosting provider.
  • Duration of data processing: until the session is closed
  • Recipients of personal data: the data controller does not transfer the data obtained to third parties, with the exception of the data processor(s) indicated in section 7. The recorded data may be accessed only by the Data Controller's employees and the designated colleagues of the data processor(s).
  • Persons concerned by the data processing: every User visiting the website, regardless of the use of the services available on the website.

5. Other data processing

We provide information on data processing not listed in this notice when the data is collected. We inform our customers that certain authorities, bodies performing public tasks and courts may contact our company for the purpose of disclosing personal data. Our company discloses personal data to these bodies, provided that the body concerned has indicated the precise purpose and the scope of the data, only to the extent strictly necessary to achieve the purpose of the request, and if compliance with the request is prescribed by law. 

6. Transfer of personal data to a third country or international organisation

Our Company does not transfer your above personal data to a third country or to an international organisation.

7. Information on the use of data processors

In the course of data processing, the data controller transfers the data to the data processor(s) contracted with it for the performance of the contract.
Categories of recipients: system administration service provider, accounting and payroll service provider, server hosting, web hosting provider

8. Children

Our services are not intended for persons under 16 years of age, and we ask that persons under 16 do not provide Personal Data to the Data Controller. 
If we become aware that we have collected personal data from a child under 16, with the exception of the processing of data required by law, we take the steps necessary to delete the data as soon as possible.

9. Automated decision-making

Our Company does not apply automated decision-making in its data processing procedures and data collection.

10. Method of storing personal data, security of data processing

Our company's IT systems and other data storage locations are located at the registered office and on the servers provided by the data processor. Our company selects and operates the IT tools used to process personal data in the course of providing the service in such a way that the processed data:

  1. is accessible to those authorised (availability);
  2. its authenticity and authentication are ensured (authenticity of data processing);
  3. its unchanged state can be verified (data integrity);
  4. is protected against unauthorised access (data confidentiality).

We pay particular attention to the security of data, and we also take the technical and organisational measures and establish the procedural rules necessary to enforce the guarantees under the GDPR. We protect the data with appropriate measures, in particular against unauthorised access, alteration, transfer, disclosure, erasure or destruction, as well as against accidental destruction and damage, and against becoming inaccessible due to changes in the technology used.

The IT systems and networks of our company and our partners are protected against computer-assisted fraud, computer viruses, computer break-ins and denial-of-service attacks alike. The operator ensures security with server-level and application-level protection procedures. Daily backup of the data is in place. In order to avoid data protection incidents, our company takes every possible measure; should such an incident occur, we act without delay, in accordance with our incident management policy, to minimise the risks and remedy the damage.

11. Rights of data subjects, remedies

The data subject may request information on the processing of their personal data, and may request the rectification of their personal data or, with the exception of mandatory data processing, its erasure or withdrawal, and may exercise their right to data portability and to object in the manner indicated when the data was collected, or at the above contact details of the data controller.

The rights and remedies of data subjects have been defined and communicated to data subjects below on the basis of Act CXII of 2011 and Regulation (EU) 2016/679. 

The right to information, also known as the data subject's “right of access”: pursuant to Act CXII of 2011 and Article 15 of Regulation (EU) 2016/679, at the data subject's request the Data Controller provides information on 

  • the data it processes and the categories of personal data,
  • the purpose of the data processing,
  • the legal basis of the data processing,
  • the duration of the data processing,
  • where applicable, the period for which the data will be stored or, if this is not possible, the criteria used to determine that period,
  • where applicable, if the data were not collected from the data subject, any available information as to their source,
  • where applicable, the existence of automated decision-making, including profiling, and meaningful information about the logic involved, as well as the significance of such processing, and
  • the envisaged consequences for the data subject,
  • the details of the data processor, if a data processor was used, i. the circumstances and effects of the data protection incident and the measures taken to remedy it, and
  • in the case of transfer of the data subject's personal data, the legal basis, purpose and recipient of the data transfer.

The information is free of charge if the person requesting it has not yet submitted a request for information to the Data Controller concerning the same scope of data in the current year. In other cases a reimbursement of costs may be established. Reimbursement of costs already paid must be refunded if the data were processed unlawfully or the request for information led to rectification.

The Data Controller draws the attention of data subjects to the fact that, pursuant to Act CXII of 2011, information must be refused

  1. if, pursuant to a provision of an act, an international treaty or a binding legal act of the European Union, the Data Controller receives personal data in such a way that the transferring data controller indicates, simultaneously with the transfer, the restriction of the rights guaranteed by the said act to the data subject of the personal data, or another restriction of its processing;
  2. in the interest of the external and internal security of the state, thus national defence, national security, the prevention or prosecution of criminal offences, the security of the enforcement of sentences, furthermore in the economic or financial interest of the state or local governments, in the significant economic or financial interest of the European Union, and for the purpose of preventing and detecting disciplinary and ethical offences related to the practice of professions and breaches of labour law and occupational safety obligations, including in every case control and supervision, and furthermore in order to protect the rights of the data subject or others.

The Data Controller is obliged to notify the National Authority for Data Protection and Freedom of Information of rejected requests for information annually, by 31 January of the year following the reference year.

The right to rectification: the data subject has the right to obtain from the Data Controller, without undue delay, the rectification of inaccurate personal data concerning them. Taking into account the purpose of the processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement. At the same time, if the personal data does not correspond to reality and the personal data corresponding to reality is available to the Data Controller, the Data Controller rectifies the personal data as a matter of obligation, even without the data subject's request.

The right to erasure, also known as the “right to be forgotten”: the data subject has the right to obtain from the Data Controller the erasure of personal data concerning them without undue delay, and the Data Controller is obliged to erase personal data concerning the data subject without undue delay, unless mandatory data processing precludes this.

Apart from the above case, the Data Controller is obliged to erase the data pursuant to Act CXII of 2011 and Regulation (EU) 2016/679 of the European Parliament and of the Council if

  • the processing of the data is unlawful;
  • the data is incomplete or incorrect, and this state cannot be lawfully remedied, provided that erasure is not precluded by law;
  • the purpose of the data processing has ceased, or the statutory time limit for storing the data has expired;
  • it has been ordered by a court or the Authority;
  • the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
  • the data subject objects to the processing and there are no overriding legitimate grounds for the processing;
  • the personal data have to be erased for compliance with a legal obligation under the law applicable to the Data Controller;
  • the personal data were collected in relation to the offer of information society services referred to in Article 8(1) of Regulation (EU) 2016/679, offered directly to children.

Where the Data Controller has for any reason made the personal data public and is obliged to erase it pursuant to the above, the Data Controller, taking account of available technology and the cost of implementation, takes reasonable steps, including technical measures, to inform other data controllers processing the data that the data subject has requested the erasure of any links to, or copies or replications of, those personal data.

The Data Controller draws the attention of data subjects to the limits of the right to erasure or the “right to be forgotten” arising from the EU regulation, which are as follows:

  1. exercising the right of freedom of expression and information;
  2. compliance with a legal obligation which requires processing by Union or Member State law to which the data controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller;
  3. reasons of public interest in the area of public health;
  4. archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) of Regulation (EU) 2016/679, in so far as the right to erasure is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
  5. the establishment, exercise or defence of legal claims.

The right to restriction of processing, also known as the right to blocking: the data subject has the right to obtain from the Data Controller restriction of processing.
If, on the basis of the information available, it can be assumed that erasure would harm the legitimate interests of the data subject, the data must be blocked. Personal data blocked in this way may be processed only as long as the data processing purpose that precluded the erasure of the personal data exists.

If the data subject contests the accuracy or correctness of the personal data, but the incorrectness or inaccuracy of the contested personal data cannot be clearly established, the data is blocked. In this case the restriction applies to a period enabling the Data Controller to verify the accuracy of the personal data.

Pursuant to the EU regulation, data must be blocked if

  1. the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead;
  2. the Data Controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims; or
  3. the data subject has objected to processing; in this case the restriction applies to the period pending the verification whether the legitimate grounds of the Data Controller override those of the data subject.

Where processing has been restricted (blocked), such personal data may, with the exception of storage, only be processed with the data subject's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.

The Data Controller hereby specifically draws the attention of data subjects to the fact that the data subject's right to rectification, erasure and blocking may be restricted by law in the interest of the external and internal security of the state, thus national defence, national security, the prevention or prosecution of criminal offences, the security of the enforcement of sentences, furthermore in the economic or financial interest of the state or local governments, in the significant economic or financial interest of the European Union, and for the purpose of preventing and detecting disciplinary and ethical offences related to the practice of professions and breaches of labour law and occupational safety obligations, including in every case control and supervision, and furthermore in order to protect the rights of the data subject or others.
The Data Controller informs the data subject of the matters specified in their request without undue delay, within a maximum of 30 days of receipt of the request, and/or rectifies the data, and/or erases and/or restricts (blocks) the data, or takes other steps in accordance with the request, if there is no ground precluding this.

The Data Controller notifies the data subject in writing of the rectification, the erasure and the restriction of processing, as well as all those to whom the data was previously transferred or handed over for the purpose of data processing. At the data subject's request, the Data Controller informs them of these recipients. The notification may be omitted if, having regard to the purpose of the data processing, it does not harm the legitimate interest of the data subject, or if the information proves impossible or would involve a disproportionate effort. The Data Controller is also obliged to notify the data subject in writing if the exercise of the data subject's right cannot take place for any reason, and is obliged to indicate precisely the factual and legal grounds and the remedies available to the data subject: the possibility of applying to a court and to the National Authority for Data Protection and Freedom of Information.

The “right to data portability”: the data subject has the right

  1. to receive the personal data concerning them, which they have provided to the Data Controller, in a structured, commonly used and machine-readable format, and has the right
  2. to transmit those data to another data controller without hindrance from the data controller to which the personal data have been provided, where:
  3. the processing is based on consent; and
  4. the processing is carried out by automated means.

In exercising the right to data portability, the data subject has the right to have the personal data transmitted directly from one data controller to another, where technically feasible.
Having regard to the data processing carried out by the Data Controller, the conditions for exercising the right to data portability are not met (there is no automated data processing), therefore the data subject cannot exercise this right.

The right to object: the data subject may object to the processing of their personal data, including profiling, if

  • the processing (transfer) of the personal data is necessary solely for the enforcement of the right or legitimate interest of the Data Controller or the data recipient, except in the case of mandatory data processing;
  • the personal data is used or transferred for the purpose of direct marketing, public opinion polling or scientific research;
  • the exercise of the right to object is otherwise permitted by law.

The data subject may also object, pursuant to Article 21(3) of Regulation (EU) 2016/679, to the processing of personal data for direct marketing purposes, in which case the personal data may no longer be processed for that purpose.

Where personal data are processed for scientific or historical research purposes or statistical purposes, the data subject, on grounds relating to their particular situation, has the right to object to the processing of personal data concerning them, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
The Data Controller, simultaneously suspending the data processing, examines the objection within the shortest possible time from the submission of the request, but no later than 30 days, and informs the applicant of the result in writing. If the applicant's objection is well-founded, the Data Controller terminates the data processing, including further data collection and data transfer, and blocks the data, and notifies of the objection and of the measures taken on its basis all those to whom it previously transferred the personal data concerned by the objection and who are obliged to take measures to enforce the right to object.

If the data subject does not agree with the Data Controller's decision, or if the Data Controller misses the time limit referred to, the data subject is entitled to apply to a court within 30 days of its communication.
The data subject has the right to object in connection with automated decision-making.

Judicial enforcement: the data subject may apply to a court in the event of a violation of their rights. The court acts out of turn in the matter. The Data Controller must prove that the data processing complies with the provisions of the law.

In the event of a violation of your right to informational self-determination, you may file a report or complaint with:

National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság)
Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
Telephone: +36 (1) 391-1400, Fax: +36 (1) 391-1410
www: http://www.naih.hu
e-mail: ugyfelszolgalat@naih.hu