Privacy Policy
1. Introduction
1.1. Purpose of the Privacy Policy
The purpose of this Privacy Policy (hereinafter: “Policy”) is to present in a transparent and detailed manner how personal data is handled during the activities of János Lajos Bokor Sole Proprietor (hereinafter: “Data Controller”), and to provide information on data subject rights and the means of exercising them.
1.2. Legal Compliance (GDPR, Act CXII of 2011)
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR): establishes uniform EU rules on the protection of personal data.
- Act CXII of 2011 (Infotv.): the foundational act of Hungarian data protection regulation, on the Right of Informational Self-Determination and on Freedom of Information.
This Policy aims to comply with the requirements set forth in the above legislation.
2. Data Controller Details
2.1. Name and Contact Details of the Data Controller
- Name: János Lajos Bokor Sole Proprietor (Ev.)
- Headquarters: 6 Mogyoróssy Street, 5700 Gyula, Hungary
- Registration / ÖVTJ Code: 552014
- Tax Number: 59792523-1-24
- Representative: János Lajos Bokor
- E-mail: rozmaringapartman@gmail.com
- Phone: +36 30 381 1144
2.2. Availability of the Privacy Policy
This Policy is available electronically at www.rozmaringapartman.hu/ and can also be viewed in printed form upon request at our customer reception office.
3. Definitions
3.1. GDPR Core Concepts
- Personal Data: any information relating to an identified or identifiable natural person (“data subject”).
- Data Controller: the natural or legal person which determines the purposes and means of the processing of personal data.
- Data Processor: a natural or legal person which processes personal data on behalf of the Data Controller.
- Consent: any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which they signify agreement to the processing of personal data relating to them.
- Data Subject: any identified or identifiable natural person to whom the personal data relates.
3.2. Definition of a Data Protection Incident (Personal Data Breach)
A data protection incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
4. Data Processing Principles
4.1. Legal Bases and Core Principles
- Lawfulness, fairness, and transparency: We process data only for specified and lawful purposes.
- Purpose limitation: Only for predetermined purposes, to the extent necessary to achieve the purpose.
- Data minimisation: We collect and process only personal data that is strictly necessary for the purpose.
- Accuracy: We ensure that the processed personal data is accurate and, where necessary, kept up to date.
- Storage limitation: Personal data is stored only for as long as necessary to achieve the purpose.
- Integrity and confidentiality: We apply appropriate technical and organizational measures to protect personal data.
4.2. Data Accuracy and Security
- Both the Data Controller and the data subject are responsible for regularly updating data; the latter is obliged to report any changes in their personal data.
- The Data Controller makes every effort to ensure that recorded data is accurate and protects it from unauthorized access with appropriate security measures.
5. Purposes and Legal Bases of Data Processing
5.1. Website Registration
- Purpose: Creating a user account and providing related services.
- Legal Basis:
- Consent (GDPR Art. 6(1)(a)) if registration is voluntary and requested by the data subject.
- Performance of a contract (GDPR Art. 6(1)(b)) if registration is a prerequisite for providing the service.
- Scope of Processed Data: Name, e-mail address, password (encrypted), registration date, IP address.
5.2. Order Management
- Purpose: Processing orders, fulfilling contracts, invoicing, and delivery.
- Legal Basis: Performance of a contract (GDPR Art. 6(1)(b)).
- Scope of Processed Data: Name, shipping and billing address, contact details (phone number, e-mail), order details.
5.3. Invoicing
- Purpose: Compliance with effective accounting legislation (e.g., Act C of 2000).
- Legal Basis: Compliance with a legal obligation (GDPR Art. 6(1)(c)).
- Scope of Processed Data: Name/company name, address, tax number (for legal entities), other data necessary for invoicing.
5.4. Newsletter Sending
- Purpose: Marketing communications, information about new products and promotions.
- Legal Basis: Consent (GDPR Art. 6(1)(a)).
- Scope of Processed Data: Name, e-mail address.
- Note: You can unsubscribe from the newsletter at any time by clicking the link at the bottom of the newsletter or by notifying the Data Controller directly.
5.5. Use of Cookies
- Purpose: Ensuring the proper functioning of the website, improving user experience, analyzing visitor data, marketing purposes.
- Legal Basis:
- Consent (GDPR Art. 6(1)(a)) – for all cookies that are not essential for the operation of the website.
- Legitimate interest or performance of a contract (GDPR Art. 6(1)(f) or (b)) – for technical cookies essential for operation.
- Further Details: See the “Use of Cookies” section (Section 11) of this Policy.
Cloudflare Turnstile and Cloudflare Cookies
To prevent unauthorized, automated use of contact and other forms, as well as to filter out unsolicited messages and malicious bot traffic, our website uses the Cloudflare Turnstile service.
During the operation of the service, certain technical data of the website visitor may be transmitted to Cloudflare, Inc. The transmitted and processed data may include in particular:
- the user’s IP address,
- browser and device technical data, such as User-Agent information,
- certain technical characteristics of the network connection,
- traffic and request data related to website use,
- and other technical information necessary for recognizing bot traffic.
The purpose of data processing is to determine whether the website or its forms are being used by a real user or an automated system, thereby ensuring the secure operation of the website and preventing abuse.
In providing the service, Cloudflare may use technical cookies or similar technologies necessary for operation and security checks. Depending on the applied Cloudflare configuration, an example is the cf_clearance cookie, which may serve to store the result of a successfully completed security check. The purpose of these technologies is to maintain website security, detect automated and malicious traffic, and handle repeated security checks.
Further information on data processing by Cloudflare Turnstile can be found in the following documents:
Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/
Cloudflare Turnstile Privacy Policy: https://www.cloudflare.com/turnstile-privacy-policy/
5.6. Social Media Data Processing
- Purpose: Communication, sharing information (Facebook, Instagram, etc.).
- Legal Basis: Voluntary decision, consent (GDPR Art. 6(1)(a)).
- Note: The data processing practices of social platforms must be viewed in the privacy policy of the respective platform.
6. Scope of Processed Data
6.1. Types of Personal Data
- Identification data: name, username, password (encrypted).
- Contact data: e-mail address, phone number, address.
- Technical data: IP address, browser type, cookies, login timestamp.
- Billing data: billing name, address, tax number (for companies).
6.2. Method and Duration of Data Storage
- Electronically: on protected servers, equipped with password and other security solutions.
- Paper-based (if any): at the headquarters or premises, in a locked location.
- Storage Period: until legal obligations are fulfilled and the purpose of data processing is achieved, or until consent is withdrawn. Afterwards, data is deleted or anonymized.
7. Rights of Data Subjects
7.1. Right to Information
The data subject is entitled to request information about the purposes, legal bases, sources, and duration of processing their personal data, as well as who has access to it.
7.2. Right to Rectification
If the data subject believes that their processed personal data is inaccurate or incomplete, they may request its rectification or completion.
7.3. Right to Erasure (“Right to be Forgotten”)
The data subject may request the erasure of their personal data if the data is no longer needed for its original purpose, or if the data subject withdraws their consent and there is no other legal basis for processing.
7.4. Right to Data Portability
The data subject is entitled to receive the personal data they provided in a structured, commonly used, and machine-readable format, and may request its transmission to another data controller.
7.5. Right to Object
- The data subject may object at any time to the processing of their personal data if the legal basis for processing is the legitimate interest of the Data Controller.
- The data subject has the specific right to object to the processing of their personal data for direct marketing purposes.
8. Data Security
8.1. Protection of Electronic Data
- Multi-level permission system.
- Regular backups.
- Antivirus protection and firewall usage.
8.2. Technical and Organizational Measures
- Use of a closed office network and secure Wi-Fi.
- Storing paper-based documents in a locked cabinet.
- Regular data protection training for employees and data processors.
9. Management of Data Protection Incidents
9.1. Reporting Incidents to Authorities (72-hour rule)
In the event of a data protection incident, the Data Controller shall report it without undue delay and, where feasible, not later than 72 hours after having become aware of it, to the National Authority for Data Protection and Freedom of Information (NAIH), unless the incident is unlikely to result in a risk to the rights and freedoms of natural persons.
9.2. Informing Data Subjects in Case of High Risk
If the incident is likely to result in a high risk to the rights and freedoms of natural persons, the Data Controller shall inform the data subjects without undue delay, describing the nature of the incident and the measures taken.
10. Data Processors and Third Parties
10.1. Hosting Provider
- Name: Vitarex Stúdió Kft.
- Headquarters: 1016 Budapest, Aladár u. 17. Ground floor 1.
- Contact: +36 1 385 1949 | vitarex@vitarex.hu
- Data Processing Activity: operating the web server, technical maintenance. Handles personal data only based on the instructions of the Data Controller.
10.2. Accountant and Other Partners
The Data Controller may use an accountant, courier service, marketing agency, and other partners for processing personal data.
- Accountant: [Name / Company of accountant], activity: accounting, payroll, tax-related tasks.
- Courier Service: [Name of courier service], activity: delivery of ordered products.
- Marketing Agency: [Name of agency], activity: planning and executing marketing campaigns.
The Data Controller always concludes written agreements with these partners (data processors) in accordance with GDPR requirements. The agreements stipulate that partners may process data solely on the instructions of the Data Controller, for the specified purpose, and for the necessary duration.
11. Use of Cookies
11.1. Purpose and Types of Cookies
- Session Cookies: essential for the functioning of the website, deleted when the browser is closed.
- Functional Cookies: enhance user comfort, for example by remembering login details or the selected language.
- Analytical Cookies (e.g., Google Analytics): serve statistical purposes, help understand user behavior, and improve website functionality.
- Marketing Cookies: support displaying relevant advertisements and measuring ad effectiveness.
11.2. Managing User Settings
- Users can control cookie handling in their browser settings, disabling or deleting them.
- Modifying cookie settings may cause certain website functions to not work properly.
- When visiting the website for the first time, an option is provided to enable or reject non-essential (e.g., marketing) cookies via a pop-up window.
12. Data Protection Officer (DPO)
12.1. Conditions for Designation and Duties
Pursuant to Article 37 of the GDPR, the Data Controller is obliged to designate a Data Protection Officer (DPO) if its core activities:
- consist of processing operations which require regular and systematic monitoring of data subjects on a large scale, or
- consist of processing on a large scale of sensitive data.
The duties of the officer include:
- continuously monitoring compliance with the GDPR,
- providing advice to the Data Controller and employees,
- acting as the contact point for the supervisory authority (NAIH) and data subjects.
12.2. Legal Status and Contact Details
The Data Protection Officer reports directly to senior management and cannot be instructed regarding their duties as DPO.
- Name: Andrea Bokorné Sarkadi
- Contact: rozmaringapartman@gmail.hu | +36 30 381 1144
If designating a DPO is not mandatory for the Data Controller, but it nevertheless appoints one, it will adequately inform data subjects in this Policy.
13. Enforcement Options for Data Subjects
13.1. Lodging a Complaint with the National Authority for Data Protection and Freedom of Information (NAIH)
If the data subject believes that the processing of their personal data violates effective legislation, they may lodge a complaint with the National Authority for Data Protection and Freedom of Information:
- Address: 1055 Budapest, Falk Miksa utca 9-11.
- Phone: +36 (1) 391-1400
- E-mail: ugyfelszolgalat@naih.hu
13.2. Right to Judicial Remedy
In case of infringement of their rights, the data subject may turn to court. The lawsuit may be initiated—at the choice of the data subject—before the regional court of their place of residence or stay.
14. Applicable Legislation Underlying Data Processing
14.1. GDPR (Regulation (EU) 2016/679)
Regulation (EU) 2016/679 of the European Parliament and of the Council, aimed at protecting natural persons with regard to the processing of personal data and ensuring the free movement of data within the EU.
14.2. Act CXII of 2011 on the Right of Informational Self-Determination
The Hungarian data protection act regulating the national core principles and limitations of personal data processing.
14.3. Other Relevant Hungarian Legislation
- Act C of 2000 on Accounting.
- Act V of 2013 on the Civil Code (Ptk.).
- Act XLVIII of 2008 on the Essential Conditions and Certain Limitations of Business Advertising Activity.
15. Final Provisions
15.1. Scope of the Privacy Policy and Possible Amendments
- This Policy is effective from August 2, 2026 (2026.08.02.).
- The Data Controller reserves the right to unilaterally amend this Policy, especially to reflect legislative changes, the introduction of new data processing activities, or recommendations of the supervisory authority.
- Amendments will be published on the website, and upon taking effect, data subjects accept the new rules by continuing to use the services.
Dated: Gyula, August 2, 2026
János Lajos Bokor
Owner