Privacy Policy

The purpose of this Privacy Policy (hereinafter: “Policy”) is to present in a transparent and detailed manner how personal data is handled during the activities of János Lajos Bokor Sole Proprietor (hereinafter: “Data Controller”), and to provide information on data subject rights and the means of exercising them.

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR): establishes uniform EU rules on the protection of personal data.
  • Act CXII of 2011 (Infotv.): the foundational act of Hungarian data protection regulation, on the Right of Informational Self-Determination and on Freedom of Information.

This Policy aims to comply with the requirements set forth in the above legislation.


  • Name: János Lajos Bokor Sole Proprietor (Ev.)
  • Headquarters: 6 Mogyoróssy Street, 5700 Gyula, Hungary
  • Registration / ÖVTJ Code: 552014
  • Tax Number: 59792523-1-24
  • Representative: János Lajos Bokor
  • E-mail: rozmaringapartman@gmail.com
  • Phone: +36 30 381 1144

This Policy is available electronically at www.rozmaringapartman.hu/ and can also be viewed in printed form upon request at our customer reception office.


  • Personal Data: any information relating to an identified or identifiable natural person (“data subject”).
  • Data Controller: the natural or legal person which determines the purposes and means of the processing of personal data.
  • Data Processor: a natural or legal person which processes personal data on behalf of the Data Controller.
  • Consent: any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which they signify agreement to the processing of personal data relating to them.
  • Data Subject: any identified or identifiable natural person to whom the personal data relates.

A data protection incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.


  • Lawfulness, fairness, and transparency: We process data only for specified and lawful purposes.
  • Purpose limitation: Only for predetermined purposes, to the extent necessary to achieve the purpose.
  • Data minimisation: We collect and process only personal data that is strictly necessary for the purpose.
  • Accuracy: We ensure that the processed personal data is accurate and, where necessary, kept up to date.
  • Storage limitation: Personal data is stored only for as long as necessary to achieve the purpose.
  • Integrity and confidentiality: We apply appropriate technical and organizational measures to protect personal data.
  • Both the Data Controller and the data subject are responsible for regularly updating data; the latter is obliged to report any changes in their personal data.
  • The Data Controller makes every effort to ensure that recorded data is accurate and protects it from unauthorized access with appropriate security measures.

  • Purpose: Creating a user account and providing related services.
  • Legal Basis:
    • Consent (GDPR Art. 6(1)(a)) if registration is voluntary and requested by the data subject.
    • Performance of a contract (GDPR Art. 6(1)(b)) if registration is a prerequisite for providing the service.
  • Scope of Processed Data: Name, e-mail address, password (encrypted), registration date, IP address.
  • Purpose: Processing orders, fulfilling contracts, invoicing, and delivery.
  • Legal Basis: Performance of a contract (GDPR Art. 6(1)(b)).
  • Scope of Processed Data: Name, shipping and billing address, contact details (phone number, e-mail), order details.
  • Purpose: Compliance with effective accounting legislation (e.g., Act C of 2000).
  • Legal Basis: Compliance with a legal obligation (GDPR Art. 6(1)(c)).
  • Scope of Processed Data: Name/company name, address, tax number (for legal entities), other data necessary for invoicing.
  • Purpose: Marketing communications, information about new products and promotions.
  • Legal Basis: Consent (GDPR Art. 6(1)(a)).
  • Scope of Processed Data: Name, e-mail address.
  • Note: You can unsubscribe from the newsletter at any time by clicking the link at the bottom of the newsletter or by notifying the Data Controller directly.
  • Purpose: Ensuring the proper functioning of the website, improving user experience, analyzing visitor data, marketing purposes.
  • Legal Basis:
    • Consent (GDPR Art. 6(1)(a)) – for all cookies that are not essential for the operation of the website.
    • Legitimate interest or performance of a contract (GDPR Art. 6(1)(f) or (b)) – for technical cookies essential for operation.
  • Further Details: See the “Use of Cookies” section (Section 11) of this Policy.

Cloudflare Turnstile and Cloudflare Cookies

To prevent unauthorized, automated use of contact and other forms, as well as to filter out unsolicited messages and malicious bot traffic, our website uses the Cloudflare Turnstile service.

During the operation of the service, certain technical data of the website visitor may be transmitted to Cloudflare, Inc. The transmitted and processed data may include in particular:

  • the user’s IP address,
  • browser and device technical data, such as User-Agent information,
  • certain technical characteristics of the network connection,
  • traffic and request data related to website use,
  • and other technical information necessary for recognizing bot traffic.

The purpose of data processing is to determine whether the website or its forms are being used by a real user or an automated system, thereby ensuring the secure operation of the website and preventing abuse.

In providing the service, Cloudflare may use technical cookies or similar technologies necessary for operation and security checks. Depending on the applied Cloudflare configuration, an example is the cf_clearance cookie, which may serve to store the result of a successfully completed security check. The purpose of these technologies is to maintain website security, detect automated and malicious traffic, and handle repeated security checks.

Further information on data processing by Cloudflare Turnstile can be found in the following documents:

Cloudflare Privacy Policy: https://www.cloudflare.com/privacypolicy/

Cloudflare Turnstile Privacy Policy: https://www.cloudflare.com/turnstile-privacy-policy/

  • Purpose: Communication, sharing information (Facebook, Instagram, etc.).
  • Legal Basis: Voluntary decision, consent (GDPR Art. 6(1)(a)).
  • Note: The data processing practices of social platforms must be viewed in the privacy policy of the respective platform.

  • Identification data: name, username, password (encrypted).
  • Contact data: e-mail address, phone number, address.
  • Technical data: IP address, browser type, cookies, login timestamp.
  • Billing data: billing name, address, tax number (for companies).
  • Electronically: on protected servers, equipped with password and other security solutions.
  • Paper-based (if any): at the headquarters or premises, in a locked location.
  • Storage Period: until legal obligations are fulfilled and the purpose of data processing is achieved, or until consent is withdrawn. Afterwards, data is deleted or anonymized.

The data subject is entitled to request information about the purposes, legal bases, sources, and duration of processing their personal data, as well as who has access to it.

If the data subject believes that their processed personal data is inaccurate or incomplete, they may request its rectification or completion.

The data subject may request the erasure of their personal data if the data is no longer needed for its original purpose, or if the data subject withdraws their consent and there is no other legal basis for processing.

The data subject is entitled to receive the personal data they provided in a structured, commonly used, and machine-readable format, and may request its transmission to another data controller.

  • The data subject may object at any time to the processing of their personal data if the legal basis for processing is the legitimate interest of the Data Controller.
  • The data subject has the specific right to object to the processing of their personal data for direct marketing purposes.

  • Multi-level permission system.
  • Regular backups.
  • Antivirus protection and firewall usage.
  • Use of a closed office network and secure Wi-Fi.
  • Storing paper-based documents in a locked cabinet.
  • Regular data protection training for employees and data processors.

In the event of a data protection incident, the Data Controller shall report it without undue delay and, where feasible, not later than 72 hours after having become aware of it, to the National Authority for Data Protection and Freedom of Information (NAIH), unless the incident is unlikely to result in a risk to the rights and freedoms of natural persons.

If the incident is likely to result in a high risk to the rights and freedoms of natural persons, the Data Controller shall inform the data subjects without undue delay, describing the nature of the incident and the measures taken.


  • Name: Vitarex Stúdió Kft.
  • Headquarters: 1016 Budapest, Aladár u. 17. Ground floor 1.
  • Contact: +36 1 385 1949 | vitarex@vitarex.hu
  • Data Processing Activity: operating the web server, technical maintenance. Handles personal data only based on the instructions of the Data Controller.

The Data Controller may use an accountant, courier service, marketing agency, and other partners for processing personal data.

  • Accountant: [Name / Company of accountant], activity: accounting, payroll, tax-related tasks.
  • Courier Service: [Name of courier service], activity: delivery of ordered products.
  • Marketing Agency: [Name of agency], activity: planning and executing marketing campaigns.

The Data Controller always concludes written agreements with these partners (data processors) in accordance with GDPR requirements. The agreements stipulate that partners may process data solely on the instructions of the Data Controller, for the specified purpose, and for the necessary duration.


  • Session Cookies: essential for the functioning of the website, deleted when the browser is closed.
  • Functional Cookies: enhance user comfort, for example by remembering login details or the selected language.
  • Analytical Cookies (e.g., Google Analytics): serve statistical purposes, help understand user behavior, and improve website functionality.
  • Marketing Cookies: support displaying relevant advertisements and measuring ad effectiveness.
  • Users can control cookie handling in their browser settings, disabling or deleting them.
  • Modifying cookie settings may cause certain website functions to not work properly.
  • When visiting the website for the first time, an option is provided to enable or reject non-essential (e.g., marketing) cookies via a pop-up window.

Pursuant to Article 37 of the GDPR, the Data Controller is obliged to designate a Data Protection Officer (DPO) if its core activities:

  • consist of processing operations which require regular and systematic monitoring of data subjects on a large scale, or
  • consist of processing on a large scale of sensitive data.

The duties of the officer include:

  • continuously monitoring compliance with the GDPR,
  • providing advice to the Data Controller and employees,
  • acting as the contact point for the supervisory authority (NAIH) and data subjects.

The Data Protection Officer reports directly to senior management and cannot be instructed regarding their duties as DPO.

  • Name: Andrea Bokorné Sarkadi
  • Contact: rozmaringapartman@gmail.hu | +36 30 381 1144

If designating a DPO is not mandatory for the Data Controller, but it nevertheless appoints one, it will adequately inform data subjects in this Policy.


If the data subject believes that the processing of their personal data violates effective legislation, they may lodge a complaint with the National Authority for Data Protection and Freedom of Information:

  • Address: 1055 Budapest, Falk Miksa utca 9-11.
  • Phone: +36 (1) 391-1400
  • E-mail: ugyfelszolgalat@naih.hu

In case of infringement of their rights, the data subject may turn to court. The lawsuit may be initiated—at the choice of the data subject—before the regional court of their place of residence or stay.


Regulation (EU) 2016/679 of the European Parliament and of the Council, aimed at protecting natural persons with regard to the processing of personal data and ensuring the free movement of data within the EU.

The Hungarian data protection act regulating the national core principles and limitations of personal data processing.

  • Act C of 2000 on Accounting.
  • Act V of 2013 on the Civil Code (Ptk.).
  • Act XLVIII of 2008 on the Essential Conditions and Certain Limitations of Business Advertising Activity.

  • This Policy is effective from August 2, 2026 (2026.08.02.).
  • The Data Controller reserves the right to unilaterally amend this Policy, especially to reflect legislative changes, the introduction of new data processing activities, or recommendations of the supervisory authority.
  • Amendments will be published on the website, and upon taking effect, data subjects accept the new rules by continuing to use the services.

Dated: Gyula, August 2, 2026

János Lajos Bokor
Owner