Privacy Policy
1. Introduction
The purpose of this notice is to provide the following information regarding
Name: Angéla Manufaktúra Kft.
Registered office: 2030 Érd, Felső utca 106.
Company registration number: 13-09-238007
Tax ID: 32720893-1-13
Representative: Tóth-Csikász Angéla
Email: angelamanufaktura@gmail.com
Website: https://angelamanufaktura.com/
hereinafter referred to as the “Data Controller” or HABIT SOLUTIONS Kft.
the data protection and data processing policies applied in the course of its operations and economic activities, and to ensure that data subjects receive adequate information regarding the processing of their personal data. The Data Controller is committed to fully complying with the provisions of the laws and regulations governing the processing of personal data, as described below, in the course of its activities.
In drafting these rules, the Data Controller took particular account of
the Fundamental Law;
Act CVIII of 2001 on Certain Issues Concerning Electronic Commerce Services and Services Related to the Information Society;
Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information (hereinafter: Info Act);
Act V of 2013 on the Civil Code (hereinafter: Civil Code);
Act VI of 1998 on the promulgation of the Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data, signed in Strasbourg on January 28, 1981;
Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR);
The Data Controller hereby states that, in the course of its operations, it obtains only and exclusively such personal data as is voluntarily provided by the data subject or to the extent that the data subject consents to the collection, processing, and use of such data.
By accepting this Privacy Policy, the Data Subjects, as data subjects, declare that they have read and accepted the provisions and information contained therein and give their consent to the processing of their data.
2. Terms Used in This Brochure
Data Processing: performing technical tasks related to data processing operations;
Data Processing: any operation or set of operations performed on the data, regardless of the procedure used, including, in particular, the collection, recording, storage, organization, alteration, use, retrieval, disclosure, transmission, publication, alignment, or combination, blocking, erasure, and destruction of data, as well as the prevention of further use of the data, and the taking of photographs, audio recordings, or video recordings;
Data Controller: a natural or legal person, or a company with legal personality, who or which, either independently or jointly with others, determines the purposes of data processing, makes and implements decisions regarding data processing (including the means used), or has such decisions implemented by a data processor it has commissioned;
Data Transfer: making the data available to a specific third party;
Data Deletion: making the data unrecognizable in such a way that it cannot be recovered;
Data Breach: a security breach that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data that is transmitted, stored, or otherwise processed;
Affected: a natural person whose personal data is subject to processing;
Third Party: a natural or legal person, or any other entity, other than the data subject, the data controller, the data processor, or those persons who have been authorized to process personal data under the direct supervision of the data controller or data processor;
Consent: a voluntary and unequivocal expression of the Data Subject’s will, based on adequate information, by which the Data Subject gives his or her unambiguous consent to the processing of personal data concerning him or her—whether in full or in relation to specific operations;
Client: refers to natural persons, legal entities, or unincorporated associations that use, access, or subscribe to the Data Controller’s services.
Personal information: data that can be linked to a specific natural person—in particular, the person’s name, identification number, and one or more factors specific to the person’s physical, physiological, mental, economic, cultural, or social identity—as well as any conclusions drawn from such data regarding the Data Subject that do not constitute data of public interest or data made public in the public interest. Personal data includes, among other things, a person’s name, address, phone number, and email address;
Protest: a statement by the data subject objecting to the processing of his or her personal data and requesting that the processing be discontinued or that the processed data be deleted.
Website: refers to the website https://angelamanufaktura.com/
3. Data Processing Principles
The data processing carried out by the Data Controller complies with the data processing principles set forth in the GDPR and the Information Act, which are as follows:
Principles of Lawfulness, Fairness, and Transparency: The processing of personal data must be carried out lawfully, fairly, and in a manner that is transparent to the Data Subject.
Principle of Purpose Limitation: Personal data may be collected only for specified, explicit, and legitimate purposes and must not be processed in a manner incompatible with those purposes.
Principle of Data Minimization: Personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes of the processing.
Principle of Accuracy: Personal data must be accurate and, where necessary, kept up to date; all reasonable measures must be taken to ensure that personal data that is inaccurate in light of the purposes of the processing is erased or rectified without delay.
Principle of Limited Storage: Personal data must be stored in a form that allows for the identification of data subjects only for as long as is necessary to achieve the purposes of the processing.
Principle of Integrity and Confidentiality: Personal data must be processed in such a way that appropriate technical or organizational measures ensure the adequate security of the personal data, including protection against unauthorized or unlawful processing, accidental loss, destruction, or damage.
Principle of Accountability: The Data Controller is responsible for compliance with these principles and must be able to demonstrate such compliance.
In addition to the principles of data processing, the requirement to provide adequate information can be identified as a common requirement, since Data Controllers must inform Data Subjects about the data processing in any case where there is a legal basis for data processing.
4. The scope of the data processed, the purpose of data processing, its legal basis, and its duration
4.1 Data processing activities related to the Data Controller’s scope of services
The Data Controller collects and processes personal data provided by Data Subjects when they use the services listed on the website.
| Scope of Data Subject to Processing | **** |
| Purpose of Data Processing | **** |
| Legal Basis for Data Processing | **** |
| Duration of Data Processing | until the Data Subject requests the deletion of the data, or for a maximum of 5 years from the performance or termination of the contract for the provision of the service, that is, until the general statute of limitations under the Civil Code expires |
4.2 Newsletter Subscription
Data Subjects may subscribe to the Data Controller’s newsletter through the Website operated by the Data Controller or other online platforms:
| Scope of Data Subject to Processing | Name/Email Address of the Data Subject |
| Purpose of Data Processing | Through the newsletter, the Data Subject may be informed about current promotions, special offers, and content relevant to the Data Controller’s services |
| Legal Basis for Data Processing | the voluntary consent of the data subject |
| Duration of Data Processing | until the Data Subject requests deletion or unsubscribes from the newsletter. |
4.3 Cookie-k
A cookie (süti) egy olyan kisméretű szövegfájl, amely az Érintett számítógépe vagy a mobil eszköze merevlemezén tárolódik a cookie-ban beállított lejárati ideig, és a későbbi látogatásokkor újra aktiválódik. Célja, hogy rögzítse a látogatással kapcsolatos információkat, illetve a személyes beállításokat, ezek azonban a látogató személyével kapcsolatba nem hozható adatok. Segít a felhasználóbarát weboldal kialakításában, valamint az Érintett online élményének fokozása érdekében. Ha az Érintett nem egyezik bele, hogy az Adatkezelő cookie-kat használjon, amikor az Érintett a weboldalon böngészik, előfordulhat, hogy weboldal nem fog teljes körűen működni. Az Érintettek a Cookie Tájékoztató útján bővebb tájékoztatást nyerhetnek az Adatkezelő által használt Cookiek-ról.
| Scope of Data Subject to Processing | The Data Controller stores all analytical information without including the Data Subject's name or any other personal data |
| Purpose of Data Processing | Storing the Data Subject's personal settings |
| Legal Basis for Data Processing | the voluntary consent of the data subject |
| Duration of Data Processing | The Data Subject may delete cookies stored on their computer or mobile phone at any time through their browser settings |
4.4 Entering into Contracts with Partners
If a contract is entered into between the Data Controller and a partner, the parties shall specify in the contract the personal data of the contact person that is essential for maintaining the communication necessary to fulfill the terms of the contract.
| Scope of Data Subject to Processing | the Data Subject's name/phone number/job title/email address |
| Purpose of Data Processing | maintaining communication between businesses, ensuring compliance with the terms of contracts |
| Legal Basis for Data Processing | Data processing is necessary for the performance of contractual obligations |
| Duration of Data Processing | until the termination of the contractual relationship or until the expiration of the general statute of limitations as provided for in the applicable laws |
4.5 Contacting Us via the Website and Customer Service Data Processing
Data Subjects may contact the Data Controller directly through the “Contact Us” feature on the Website, or they may contact a member of the Data Controller’s customer service team by phone.
| Scope of Data Subject to Processing | the Data Subject’s name, company name (optional), email address, phone number, and other personal data voluntarily provided during the phone conversation and in the message |
| Purpose of Data Processing | Communication between the Data Subject and the Data Controller, quality assurance, customer service, and problem resolution |
| Legal Basis for Data Processing | the voluntary consent of the data subject |
| Duration of Data Processing | The Data Controller will store the personal data obtained in this manner for a maximum of 5 years |
5. Data Processors
5.1 The following data processors may access certain categories of personal data as necessary, in accordance with the applicable data protection principles.
| Data Processors | Contact Information | Activities |
| **** | **** | bookkeeping, payroll |
| **** | **** | marketing activities, ad management, PR |
| Billingo Technologies Zrt. | Website: https://www.billingo.hu/ | website development |
| Magic Qube Kft. | Headquarters: 7081 Simontornya, Gyár Street 13; Tax ID: 32800555-2-17; Email: office@magicqube.com | Website development as a subcontractor |
| Versanus Kft. | Phone: 06 30 951 3744 Address: 1138 Budapest, Mura Street 4, 9th floor, apt. 7 | Website domain provider |
| Tárhely.Eu Szolgáltató Kft. | Website: https://tarhely.eu/ | online hosting service |
In addition to the Data Processors listed above, individuals who are in an employment or contractual relationship with the Data Controller are authorized to access and process specific personal data. The individuals named in this section shall treat the data as confidential, given that, pursuant to their contracts with the Data Controller, the Data Controller’s employees and contractual partners providing services to the Data Controller are bound by a duty of confidentiality, under which they may not process the data they have access to for purposes other than those related to their legal relationship, nor may they disclose such data to third parties. The Data Controller regulates the duties, access rights, and obligations of persons involved in data processing in its internal policies and data processing agreements. Employees are liable under labor law, while contractual partners are liable under civil law for compliance with these provisions.
5.2 Other data processing activities involving the use of cookies.
A) Google Analytics and Tag Manager Integration
We collect technical data about visits to the website and the use of the service using Google Analytics. The data collected by Analytics (e.g., device type, browser type, language settings, referring website URL, device IP address, and other geographic data) is stored anonymously, separate from personal data, and is used for statistical analysis to optimize the system’s usability and marketing.
Google Tag Manager (GTM) is a tool that allows for the simple and centralized management of tags used on your website or in your app without having to directly modify the code on the page.
B) Pixel (META)
It is used to track visitor activity on the website (page views, adding items to the cart, purchases) and helps with remarketing for META ads.
C) Instagram Pixel (META)
It collects conversion and activity data on visitor behavior for Instagram ads.
D) LinkedIn Pixel (LinkedIn Insight Tag)
Tracking activities related to LinkedIn ads on the website, and measuring conversions and interest data.
E) TikTok Pixel
Tracking events and conversions related to TikTok ads on the website to measure and optimize campaign performance.
6. Data Transfer
As a general rule, the Data Controller does not disclose the data it processes to third parties. Data may be disclosed only if the Data Subject has given explicit and prior consent, or if required by law, or if requested by an authority with the authority of law.
7. Data Security
The primary platform for recording data is the Data Controller’s IT system.
The Data Controller stores the personal data specified above at the premises of the company’s IT data processor.
The Data Controller undertakes to ensure the security of the data in accordance with the provisions of the GDPR and the Information Act.
During the operation of the IT systems, the necessary access control, internal organizational, and technical measures ensure that your data cannot fall into the hands of unauthorized persons, and that unauthorized persons cannot delete, export, or modify the data from the system. The data controller also enforces data protection and data security requirements with respect to data processors.
The data controller maintains a record of any data protection incidents and, if necessary, notifies the Data Subject of such incidents, as well as the National Authority for Data Protection and Freedom of Information (NAIH) when required.
Access to personal data is granted to those persons acting within the Data Controller’s sphere of interest—in particular, agents and employees—who require such access to perform their duties and who are aware of and understand the obligations related to data processing.
The Data Controller pays particular attention to ensuring that all its agents and employees are familiar with its internal data protection protocol and process personal data in accordance with its provisions.
The Data Controller undertakes to ensure the security of the data using state-of-the-art and appropriate equipment and security measures, with particular regard to preventing unauthorized access to the data and ensuring that the data is not unlawfully disclosed, deleted, or destroyed. It will do everything in its power to ensure that data is not accidentally damaged or destroyed. The Data Controller also requires its employees involved in data processing activities to comply with the above commitment.
Under no circumstances does the Data Controller collect special categories of data, i.e., data relating to racial origin, membership in a national or ethnic minority, political opinions or party affiliation, religious or other philosophical beliefs, membership in interest groups, health status, pathological addictions, sexual life, or criminal history.
8. The Data Subject's Rights During Data Processing
During the period of data processing, Data Subjects have the following rights:
Right to Information
The Data Controller is required to provide information—in an appropriate manner, using simple and accessible language, and in a form that is easily accessible (online or offline)—regarding the essential aspects of data processing. At the time of collection of personal data, or if the Data Subject subsequently requests information, the Data Controller must make the Privacy Policy available to the Data Subject and have the Data Subject sign a statement confirming that they have read, understood, and accepted its contents.
The Data Subject is entitled at any time to request information regarding the personal data concerning him or her that is processed by the Data Controller. Such information may be requested via the email address specified in the privacy notice for the relevant data processing, by mail, or by telephone. The Data Controller is required to provide the requested information within 30 days of receiving the request.
Right to Erasure
The data subject has the right to request that the Data Controller erase personal data concerning him or her without undue delay, and the Data Controller is obligated to erase personal data concerning the data subject without undue delay. If the Data Controller has granted third parties access to the data requested for erasure, it must inform all those to whom it has disclosed the data of the data subject to delete any references to such data and any personal data stored by them. The purpose of this is to ensure that—unless there are legal or reasonable obstacles—the data in question “disappears” from searchable databases.
The erasure does not have to be carried out if the data processing
- is necessary for the exercise of the right to freedom of expression or the right to information;
- is necessary for the establishment, exercise, or defense of legal claims;
- is necessary to comply with a legal obligation;
- is necessary for archiving in the public interest, scientific or historical research, or statistical purposes, and erasure would render the fulfillment of the purpose of data processing impossible or would seriously jeopardize it.
Furthermore, the Data Controller shall erase personal data contained in its records pertaining to the data subject if the purpose for which the personal data was processed no longer exists.
In the case of paper-based records, their destruction must be documented in a written record so that the fact of their destruction can be proven to the competent authority at a later date.
The right to rectification of data:
The Data Subject may indicate that the processed data is inaccurate and may request that it be replaced with other information. The Data Controller is responsible for the accuracy of the data; therefore, it is necessary to verify its accuracy from time to time.
The right to restrict data processing:
The Data Subject may request that the Data Controller restrict the processing of their personal data, for example, in a situation that is unclear or subject to legal dispute. If the processing is restricted, such personal data may be processed—with the exception of storage—only with the Data Subject’s consent, or for the purpose of asserting, exercising, or defending legal claims, or to protect the rights of another natural or legal person, or for reasons of substantial public interest of the Union or of a Member State.
Right to data portability:
The Data Subject may request to receive the data processed about him or her in a structured, commonly used, machine-readable format (e.g., .doc, .pdf, etc.), and is entitled to transmit this data to another data controller without being prevented from doing so by the original data controller. This makes it easier for the data subject to transfer their personal data from one data controller to another.
The right to protest:
The Data Subject has the right, if he or she has not given consent to the processing of the data, to object at any time to the processing of his or her personal data for a specific reason.
If the Data Subject wishes to exercise his or her rights, this requires identification, and the Data Subject must necessarily communicate with the Data Controller; therefore, providing personal data will be necessary for identification purposes (but identification may only be based on data that we already process about you), and your complaints regarding data processing will be available in our email account within the timeframe specified in this notice regarding complaints.
The Data Controller will respond to complaints regarding data processing without delay, but no later than within 30 days.
9. legal remedies
The Data Subject has the right to file a complaint with the NAIH (1055 Budapest, Falk Miksa u. 9-11; www.naih.hu, Phone: +36 (1) 391-1400, Fax: +36 (1) 391-1410, E-mail: ugyfelszolgalat@naih.hu) or to enforce their rights regarding the processing of personal data before a court with jurisdiction and competence pursuant to Act CXXX of 2016 on the Code of Civil Procedure.
10. Final Provisions
If the Data Controller intends to process personal data for a purpose other than that set forth in this notice, it shall inform the Data Subject of the new purpose of the data processing prior to such further processing. Data processing for the new purpose may only begin thereafter—if the legal basis for data processing is consent—provided that, in addition to the notification, the Data Subject also consents to the data processing.
This Privacy Policy remains in effect until revoked; its scope of application extends to all organizational units of the Data Controller, its data processors, employees, officers, and those with whom it has a contractual relationship.
This Privacy Policy must be reviewed annually or whenever there are changes to EU or domestic legislation.
The Data Controller reserves the right to amend this policy or to make appropriate modifications to it in the event of changes to European Union or Hungarian laws.