Privacy Policy

Date of adoption: 21/09/2020

 

contents

 

Data controller data

  • Name: Taphouse (Csapház)

  • Company name: BeerTapHouse Kft.

  • Headquarters: 1112 Budapest, Zsázsa utca 6.

  • Mailing address, complaint handling: 1112 Budapest, Zsázsa utca 6.

  • E-mail: info@csaphaz.hu

  • Phone number: +36 30 545 2620; +36 30 193 8831

  • Website: http://www.csaphaz.hu

  • Data Protection Officer

    • Name: Szabina Román-Ruszinkó

    • Mailing address: 612 Budapest, Zsázsa utca 6.

    • E-mail address: info@csaphaz.hu

  • Hosting provider

    • Name: Integrity Kft.

    • Mailing address: 1132 Budapest, Victor Hugo utca 18-22,

    • E-mail address: office@integrity.hu

    • Phone number: +36 1 450 2660

Description of the data management performed during the operation of the webshop

Information on the use of cookies

What is a cookie?
The Data Controller uses so-called cookies when visiting the website. The information package consisting of cookie letters and numbers that our website sends to your browser in order to save certain of your settings, facilitate the use of our website and contribute to the collection of some relevant, statistical information about our visitors. Some cookies do not contain personal information and are not suitable for identifying an individual user, but some contain a unique identifier - a secret, randomly generated series of numbers - that your device stores, thus ensuring your identity. The period of operation of each cookie (cookie) is described in the relevant description of each cookie (cookie).

Legal background and legal basis for cookies: The legal basis for data processing is your consent pursuant to Article 6 (1) (a) of the Regulation.

The main features of the cookies used by the website are:

Google Adwords cookie When someone visits our site, the visitor's cookie ID is added to the remarketing list. Google uses cookies, such as NID and SID cookies, to customize the ads that appear in Google products, such as Google Search. For example, you use such cookies to remember your recent searches, past interactions with individual advertisers 'ads or search results, and visits to advertisers' websites. AdWords Conversion Tracking uses cookies. It tracks cookies on a user's computer to track sales and other conversions resulting from an ad when that person clicks on an ad. Here are some common ways to use cookies: selecting ads based on what's relevant to that user, improving campaign performance reports, and avoiding ads that the user has already viewed.

Google Analytics cookie: Google Analytics is Google’s analytics tool that helps website and application owners gain a more accurate picture of their visitors ’activities. The Service may use cookies to collect information and report statistics about website usage without personally identifying visitors to Google. The main cookie used by Google Analytics is the "__ga" cookie. In addition to reporting from site usage statistics, Google Analytics, along with some of the advertising cookies described above, can also be used to show more relevant ads on Google products (such as Google Search) and across the web.

Cookies strictly necessary for operation: These cookies are essential for the use of the website and allow you to use the basic functions of the website. Without these, many features of the site will not be available to you. The lifespan of these types of cookies is limited to the duration of the session only.

Session cookie: These cookies store the visitor's location, browser language, payment currency, lifetime when the browser is closed, or up to 2 hours.

Referer cookies: Record what external page the visitor came to the site from. Their lifespan lasts until the browser is closed.

Cookie acceptance cookie: Upon arrival at the site, you accept the cookie storage statement in the warning window. Shelf life 365 days.

Basket Cookie: Records the products placed in the basket. Shelf life 365 days.

Facebook pixel A Facebook pixel is a code that is used to report conversions on a website, compile target audiences, and provide the site owner with detailed analytics about visitors ’use of the website. With the help of the Facebook pixel, you can display personalized offers and advertisements to the visitors of the website on the Facebook interface. You can read Facebook's privacy policy here: https://www.facebook.com/privacy/explanation

If you do not accept the use of cookies, certain features will not be available to you. You can find more information about deleting cookies at the following links:

Data processed for contracting and performance purposes

Several data management cases may be implemented for the conclusion and performance of the contract. We would like to inform you that data processing related to complaint handling will only take place if you contact us with a complaint.

If you do not make a purchase through the webshop, you are only a visitor to the webshop, then what is written in the management of data for marketing purposes may apply to you, if you give us consent for marketing purposes.

Data processing for the conclusion and performance of contracts in more detail:

 

1.Contact

For example, if you contact us by e-mail, contact form, or phone with a question about a beer or service.

Pre-contact is not obligatory, you can order it from the webshop at any time, omitting it.

Data handled: data you provide during contact.

Duration of data processing: the data will be deleted at the request of the data subject.

Legal basis for data management: your voluntary consent, which you give to the Data Controller by contacting us. [Data processing pursuant to Article 6 (1) (a) of the Regulation]

2.Order processing

During the processing of orders, data management activities are required in order to fulfill the contract.

Managed data: during data management, the Data Controller manages your name, address, telephone number, e-mail address, the name and quantity of the ordered product, the order number and the date of purchase.

If you have placed an order in the webshop, data management and the provision of data is essential for the fulfillment of the contract.

Duration of data processing: data are processed for 5 years according to the civil law limitation period.

Legal basis for data management: performance of the contract. [Data processing pursuant to Article 6 (1) (b) of the Regulation]

 

3. Issuance of the invoice

The data management process takes place in order to issue an invoice in accordance with the law and to fulfill the obligation to keep accounting documents. The Stv. Pursuant to Section 169 (1) - (2), companies must keep the accounting document directly and indirectly supporting the accounting records.

Managed data: name, address, ordered items.

Duration of data management: the issued invoices are issued in accordance with the Act. Pursuant to Section 169 (2), it must be retained for 8 years from the date of issue of the invoice.

Legal basis of data management: Act CXXVII of 2007 on Value Added Tax. Pursuant to Section 159 (1), the issue of an invoice is mandatory and must be kept for 8 years pursuant to Section 169 (2) of Act C of 2000 on Accounting [Data Management pursuant to Article 6 (1) (c) of the Decree].

4.Data management related to freight transport

The data management process takes place in order to deliver the ordered product.

Data handled: name, address, e-mail address, telephone number, personal note addressed to the courier service (eg doorbell).

Duration of data management: the Data Controller manages the data for the duration of the delivery of the ordered goods.
Legal basis for data processing: performance of contract [data processing pursuant to Article 6 (1) (b) of the Regulation].

 

5. Complaint handling

The data management process is in place to handle consumer complaints. If you have made a complaint to us, data management and the provision of data is essential.

Data processed: customer's name, telephone number, email address, content of the complaint.

Duration of data processing: warranty complaints are kept for 5 years in accordance with the Consumer Protection Act.

The legal basis for data management is whether you have a complaint about your voluntary decision, but if you do contact us, you are covered by the 1997 CLV on Consumer Protection. Act 17 / A. § (7), we are obliged to keep the complaint for 5 years [data processing according to Article 6 (1) c) of the Decree].

6.Data handled in relation to the verifiability of consent

During registration, ordering, subscribing to the newsletter, the IT system stores the IT data related to the consent for later proof.

Data managed: date of consent and IP address of the data subject.

Duration of data processing: due to legal requirements, the consent must be able to be verified later, therefore the duration of data storage will be stored for the limitation period after the termination of data processing.

Legal basis for data processing: Article 7 (1) of the Regulation provides for this obligation. [Data processing pursuant to Article 6 (1) (c) of the Regulation]

Data management for marketing purposes

 

1. Data management related to newsletter sending

Data managed:

Data handled in all cases: Name (Surname and First Name) and e-mail address as basic conditions for subscribing to the newsletter. The date of subscription and the IP address at that time, which is one of the technical conditions for sending a newsletter. When subscribing to the newsletter, please be sure to provide only your own personal information! The Data Controller shall not be liable for any problems arising from incorrect or incorrect data. Subscribing to the newsletter is voluntary, with the consent of the Subscriber.

Duration of data processing: until the data subject's consent is withdrawn. The data subject may withdraw the consent in several ways. 1. using the "Unsubscribe" function at the bottom of each newsletter; 2. by e-mail to info@csaphaz.hu requesting the deletion of your data.

Legal basis for data processing: your voluntary consent to the Data Controller by subscribing to the newsletter [Data processing under Article 6 (1) (a) of the Regulation]

2.Data management related to the sending and display of personalized advertisements

Managed data: when subscribing to the newsletter, in addition to the mandatory information (name, e-mail address), the date of birth and gender can be specified, which can help to send even more useful newsletters to the subscriber. In addition, using data (purchases) voluntarily provided during the visit and use of the webshop, we also compile personalized newsletters (based on individual promotions, offers, previously purchased products or other data provided during the purchase) for the best possible user experience and to let everyone know only the necessary and important information.

Duration of data processing: until the data subject's consent is withdrawn. The data subject may withdraw the consent in several ways. 1. using the "Unsubscribe" function at the bottom of each newsletter; 2. by e-mail to info@csaphaz.hu requesting the deletion of your data.


Legal basis for data processing: your voluntary, specific consent, which you give to the Data Controller during the data collection [Data processing pursuant to Article 6 (1) (a) of the Regulation]

3.Remarketing

Data management as a remarketing activity is implemented with the help of cookies.

Data handled: data handled by cookies specified in the cookie information.

Duration of data management: the data storage period of the given cookie, more information is available here:

Legal basis for data processing: your voluntary consent, which you give to the Data Controller using the website [Data processing pursuant to Article 6 (1) (a) of the Regulation].

4. Prize draw

The data management process takes place in order to conduct the sweepstakes.

Data managed: name, email address, telephone number.

Duration of data management: the data will be deleted after the closing of the prize draw, except for the data of the winner, which the Data Controller is obliged to keep for 8 years according to the Accounting Act.

Legal basis for data management: your voluntary consent, which you give to the Data Controller by using the website. [Data processing pursuant to Article 6 (1) (a) of the Regulation]

Manage data provided during the ordering process

The scope of the managed data: name, e-mail address, telephone number, cart contents.

Duration of data processing: until the data subject's consent is withdrawn. The data subject may withdraw the consent in several ways. 1. using the "Unsubscribe" function at the bottom of each newsletter; 2. by e-mail to info@csaphaz.hu requesting the deletion of your data.

Legal basis for data management: by accepting the data protection statement, you consent to us contacting you at the contact details provided during the ordering process (telephone number, e-mail address) for information or assistance, order matching or sales.

 

Additional data management

If the Data Controller wishes to perform further data processing, he / she shall provide preliminary information on the essential circumstances of the data management (legal background and legal basis of data management, purpose of data management, scope of data processed, duration of data management).

We would like to inform you that the Data Controller must comply with the written data requests of the authorities based on legal authorization. The Data Controller shall inform Infotv. In accordance with Section 15, Paragraphs (2) - (3), he keeps records (to which authority, what personal data, on what legal basis, when was transmitted by the Data Controller), the content of which the Data Controller provides information on request, unless its exclusion is excluded by law.

1.Data processing activities related to the transport of goods

Name of the data processor: Travel Trans Union Bt.

The registered office of the data processor: 1101. Budapest, Hungária krt. 5-7.

Telephone number of the data processor: 06 / 1-431-9094

E-mail address of the data processor: traveltrans@traveltrans.hu

The Data Processor participates in the delivery of the ordered goods on the basis of the contract concluded with the Data Controller. In doing so, the Data Processor may manage the name, address and telephone number of the customer until the end of the calendar year following the delivery of the product, after which it shall be deleted immediately.

2. Accounting data management

Name of the data processor: Nominal Classic Kft.

The registered office of the data processor: 13216, Fehérvári út 132-144 Budapest.

Telephone number of the data processor: 06 1 206 2370

The Data Processor participates in the accounting of accounting documents on the basis of a written contract concluded with the Data Controller. In doing so, the Data Processor shall provide the name and address of the data subject to the extent necessary for the accounting records, in accordance with the provisions of the Act. It shall be managed for a period in accordance with Section 169 (2), after which it shall be canceled immediately.

3. Invoicing data processing

Name of the data processor: KBOSS.hu Kft. (Szamlazz.hu)

The registered office of the data processor: 1031 Budapest, Záhony utca 7 / C.

Telephone number of the data processor: 06 30 354 4789

The e-mail address of the data processor: info@szamlazz.hu

The Data Processor participates in the registration of accounting documents on the basis of a contract concluded with the Data Controller. In doing so, the Data Processor shall provide the name and address of the data subject to the extent necessary for the accounting records, in accordance with the provisions of the Act. It shall be managed for a period in accordance with Section 169 (2), after which it shall be canceled.

4. Data processing related to online payment

Name of the data processor: UniCredit Bank Hungary Zrt.

The registered office of the data processor: Szabadság tér 5-6, 1054 Budapest.

Telephone number of the data processor: 06 1 325 3200

The Data Processor participates in the execution of the Online Payment on the basis of the contract concluded with the Data Controller. In doing so, the Data Processor handles the billing name and address of the data subject, the number and date of the order within the civil law limitation period.

5.Data processing related to other marketing activities:

The Data Controller transmits data to the following data processors in order to compile statistics for its own use and to specialize its marketing activities in the most informative and personal way possible for the user:

Facebook Ireland Ltd.

4 Grand Canal Square, Grand Canal Harbor, Dublin 2 Ireland

The data controller forwards to Facebook the data of the events related to the visit to www.csaphaz.hu (clicks; page downloads; date of purchase, purchased items and their prices), as well as the e-mail address of the data subject. These data are used to improve the user experience of www.netamin.hu, to prepare analyzes for internal use, and in the personalized marketing campaigns of the data controller.

Google LLC
Address: 1600 Amphitheater Parkway, Mountain View, CA 94043

Email: data-protection-office@google.com
Phone: +1 650-253-0000

The data controller provides Google with data on events related to the visit to www.csaphaz.hu (clicks; page downloads; date of purchase, purchased items and their prices). These data are used to improve the user experience of www.netamin.hu, to prepare analyzes for internal use, and in the personalized marketing campaigns of the data controller.

The data processor indicated above is located outside the territory of the European Union and processes the data outside the territory of the European Union. The data processor is a party to the Privacy Shild List, ie it ensures that the processing of the data is carried out with the guarantees provided in the European Union. More information is available at www.privacyshild.gov



Your rights during data management

 

Within the period of data processing, you have the following rights in accordance with the provisions of the Regulation:

  • the right to withdraw consent

  • access to personal data and data management information

  • right of rectification

  • data management restrictions

  • right of cancellation

  • the right to protest

  • the right to portability

If you wish to exercise your rights, this will involve your identification and the Data Controller must communicate with you. Therefore, in order to be identified, you will be required to provide personal data (but the identification may only be based on data that the Data Controller handles about you anyway) and your data processing complaints will be available in the Data Controller's e-mail account within the timeframe specified in this information. . If you have been our customer and would like to identify yourself for complaint handling, please also provide your order ID for identification. Using this, we can also identify you as a customer.

Complaints related to data management will be answered by the Data Controller within 30 days at the latest.

Right to withdraw consent

You have the right to withdraw your consent to data management at any time, in which case the data provided will be deleted from our systems. Please note, however, that in the case of an order that has not yet been fulfilled, cancellation may result in us not being able to deliver to you. In addition, if the purchase has already been made, we will not be able to delete your billing information from our systems in accordance with the accounting rules, and if you owe us, we may process your information in the event of withdrawal of consent based on a legitimate interest in recovering the claim.

Access to personal data

You have the right to receive feedback from the Data Controller as to whether your personal data is being processed and, if data is being processed, you have the right to:

  • have access to the personal data processed and

  • inform the Data Controller of the following information:

    • the purposes of data management;

    • categories of personal data processed about you;

    • information on the recipients or categories of recipients with whom or with whom the Personal Data has been or will be communicated by the Data Controller;

    • the intended period for which the personal data will be stored or, if that is not possible, the criteria for determining that period;

    • your right to request the Data Controller to rectify, delete or restrict the processing of personal data concerning you and to object to the processing of such personal data in the event of data processing based on a legitimate interest;

    • the right to lodge a complaint with the supervisory authority;

    • if the data was not collected from you, all available information about their source;

    • the fact of automated decision-making (if such a procedure has been used), including profiling, and, at least in these cases, understandable information about the logic used and the significance of such data processing and the expected consequences for you.

The purpose of exercising the right may be to establish and verify the lawfulness of the data processing, therefore in case of multiple requests for information, the Data Controller may charge a fair fee for the provision of the information.

Access to personal data is ensured by the Data Controller by sending you the processed personal data and information by e-mail after your identification. If you have a registration, we will provide access so that you can view and verify the personal information we manage about you by logging into your user account.

Please indicate in your request whether you are requesting access to personal data or requesting data management information.

Right to rectification

You have the right, at the request of the Data Controller, to correct inaccurate personal data concerning you without delay.

Right to restrict data management

You have the right, at the request of the Data Controller, to restrict data processing if any of the following is met:

  • You dispute the accuracy of the personal data, in which case the restriction applies to the period of time that allows the Data Controller to check the accuracy of the personal data, if the exact data can be established immediately, the restriction will not take place;

  • the data processing is illegal, but you object to the deletion of the data for any reason (for example, because the data is important to you in order to enforce a legal claim), so you do not request the deletion of the data, but instead request a restriction on its use;

  • the Data Controller no longer needs the personal data for the purpose of the designated data processing, but you request it in order to submit, enforce or protect legal claims; obsession

  • You have objected to the data processing, but the data controller's legitimate interest may also justify the data processing, in which case, until it is determined whether the Data Controller's legitimate reasons take precedence over your legitimate reasons, the data processing must be restricted.

Where processing is restricted, such personal data may be processed, with the exception of storage, only with the consent of the data subject or for the purpose of bringing, enforcing or protecting legal claims or protecting the rights of another natural or legal person or in the important public interest of the Union or a Member State.

The data controller will inform you in advance (at least 3 working days before the lifting of the restriction) about the lifting of the restriction of data management.

Right to delete - right to forget

You have the right to have the Data Controller delete your personal data without undue delay if any of the following reasons exist:

  • personal data are no longer required for the purpose for which they were collected or otherwise processed by the Data Controller;

  • You withdraw your consent and there is no other legal basis for the processing;

  • You object to the processing based on a legitimate interest and there is no overriding legitimate reason (ie a legitimate interest) in the processing,

  • the personal data was processed unlawfully by the Data Controller and this was established on the basis of the complaint,

  • personal data must be deleted in order to fulfill a legal obligation under Union or Member State law applicable to the Data Controller.

If, for any lawful reason, the Data Controller has disclosed personal data processed about you and is obliged to delete it for any of the reasons set out above, it shall take reasonable steps, including technical measures, to inform the data, taking into account available technology and implementation costs. other data controllers that you have requested the deletion of the links to the personal data in question or of a copy or duplicate of this personal data.

Deletion does not apply if data processing is required:

  • for the purpose of exercising the right to freedom of expression and information;

  • to fulfill an obligation under EU or Member State law to process personal data (such as data processing in the context of invoicing, as the retention of the account is required by law) or in the public interest or in the exercise of a public authority conferred on the data controller;

  • to submit, enforce or defend legal claims (eg: if the Data Controller has a claim against you and has not yet fulfilled it, or a consumer or data processing complaint is being processed).

Right to protest

You have the right to object at any time for reasons related to your situation to the processing of your personal data on the basis of a legitimate interest. In this case, the Data Controller may not further process the personal data, unless it proves that the data processing is justified by compelling legitimate reasons which take precedence over your interests, rights and freedoms, or which are related to the submission, enforcement or protection of legal claims.

If personal data is processed for the purpose of direct business acquisition, you have the right to object at any time to the processing of personal data concerning you for this purpose, including profiling, insofar as it relates to direct business acquisition. If you object to the processing of personal data for the purpose of direct business acquisition, the personal data may no longer be processed for this purpose.

Right to portability

If the data processing is carried out automatically or if the data processing is based on your voluntary consent, you have the right to ask the Data Controller to receive the data provided by you to the Data Controller, which the Data Controller provides to you in xml, JSON or csv format. if this is technically feasible, it may request that the Data Controller transfer the data in this form to another data controller.

Automated decision making

You have the right not to be covered by a decision (including profiling) based solely on automated data processing that would have legal effect on you or affect you to a similar extent. In such cases, the Data Controller shall take appropriate measures to protect the rights, freedoms and legitimate interests of the data subject, including at least the right of the data subject to request human intervention on the data subject, to express his or her views and to object to the decision.

The above does not apply if the decision:

  • Necessary for the conclusion or performance of a contract between you and the data controller;

  • EU or Member State law applicable to the controller, which also lays down appropriate measures to protect your rights and freedoms and legitimate interests; obsession

  • based on your express consent.

Login to the privacy register

Infotv. Pursuant to the provisions of the Act, the Data Controller had to notify certain data processing operations to the data protection register. This notification obligation ceased on 25 May 2018.

Data security measures

The Data Controller declares that it has taken appropriate security measures to protect personal data against unauthorized access, alteration, transmission, disclosure, deletion or destruction, as well as accidental destruction and damage, and becoming inaccessible due to changes in the technology used.

The Data Controller makes every effort to ensure that its data processors also take appropriate data security measures when working with your personal data.

Remedies

If, in your opinion, the Data Controller has violated any legal provision on data processing or has not complied with any of its requests, the National Data Protection and Freedom of Information Authority may initiate an investigation procedure to terminate the alleged unlawful data processing (mailing address: 1530 Budapest, Pf .: 5., e- mail: ugyfelszolgalat@naih.hu).

We would also like to inform you that in case of violation of the legal provisions on data processing, or if the Data Controller has not complied with any of his / her requests, he / she may file a civil lawsuit against the Data Controller in court.

Modification of data management information

The Data Controller reserves the right to amend this data management information in a manner that does not affect the purpose and legal basis of the data management. By using the website after the change takes effect, you accept the amended data management information.

If the Data Controller wishes to perform further data processing in connection with the collected data for a purpose other than the purpose of their collection, it shall inform you about the purpose of the data processing and the following information prior to the further data processing:

  • the duration of the storage of personal data or, if that is not possible, the criteria for determining the duration;

  • the right to request the Data Controller to access, rectify, delete or restrict the processing of personal data concerning you and to object to the processing of personal data in the case of data processing based on a legitimate interest and to request data portability in the case of data processing based on consent or contractual relationship the right to justice;

  • in the case of data processing based on consent, that you may withdraw your consent at any time,

  • the right to lodge a complaint with the supervisory authority;

  • whether the provision of personal data is based on a law or a contractual obligation or a precondition for concluding a contract, and whether you are obliged to provide personal data, and what the possible consequences of non-disclosure may be;

  • the fact of automated decision-making (if such a procedure has been used), including profiling, and, at least in these cases, understandable information about the logic used and the significance of such data processing and the expected consequences for you.

The data processing can only start after that, if the legal basis of the data processing is consent, ie in addition to the information, you must also consent to the data processing.

This document contains all relevant data management information related to the operation of the webshop in accordance with the General Data Protection Regulation 2016/679 of the European Union (hereinafter: Regulation GDPR) and the 2011 CXII. TV. (hereinafter: Infotv.).