Privacy Policy
### 1. Introduction
Emesetar.com (1062 Budapest, Aradi u. 16. II/2., hereinafter: Service Provider, Data Controller), as a data controller, recognizes the contents of this legal notice as binding. It undertakes to ensure that all data processing related to its activities meets the requirements set out in this policy and the applicable legislation.
The privacy guidelines regarding the data processing of the service available at Emesetar.com are continuously available at: [https://emesetar.com/hu/adatvedelem/](https://emesetar.com/hu/adatvedelem/)
Emesetar.com reserves the right to change this information at any time. Naturally, it will notify its audience of any changes in due time. If our users have any questions that are not clear based on this announcement, please write to us, and our colleague will answer the question.
Emesetar.com is committed to protecting the personal data of its users and partners and considers it of paramount importance to respect its customers’ right to informational self-determination. Emesetar.com treats personal data confidentially and takes all security, technical, and organizational measures that guarantee the security of the data.
Emesetar.com describes its data management principles below and presents the expectations it has formulated and complies with as a data controller. Its data management principles are in accordance with the current legislation on data protection, in particular the following:
* Act LXIII of 1992 – on the Protection of Personal Data and the Publicity of Data of Public Interest (hereinafter: Avtv., Data Protection Act);
* Act CXIX of 1995 – on the Management of Name and Address Data for the Purpose of Research and Direct Marketing (Katv.);
* Act C of 2000 – on Accounting (Számv. tv.);
* Act CVIII of 2001 – on certain issues of electronic commerce services and information society services (Eker. tv.);
* Act XLVIII of 2008 – on the basic conditions and certain limitations of economic advertising activity (Grt.);
* Act CXII of 2011 – on the Right to Informational Self-Determination and Freedom of Information (Infotv.).
—
### 2. Definitions
**2.0. Data subject:** any specific natural person identified or – directly or indirectly – identifiable on the basis of personal data;
**2.1. Personal data:** data that can be associated with the data subject – especially the name, identification mark, and knowledge characteristic of one or more physical, physiological, mental, economic, cultural or social identities of the data subject – as well as the conclusion regarding the data subject that can be drawn from the data;
**2.2. Consent:** a voluntary and firm expression of the data subject’s will, based on adequate information, with which they give their unmistakable consent to the processing of personal data concerning them – in full or covering specific operations;
**2.3. Objection:** a statement by the data subject objecting to the processing of their personal data and requesting the termination of data processing or the deletion of the processed data;
**2.4. Data controller:** the natural or legal person or organization without legal personality who or which determines the purpose of the data processing, makes and implements decisions regarding the data processing (including the means used), or has them implemented by a data processor commissioned by them;
**2.5. Data processing (Data management):** regardless of the procedure used, any operation or set of operations performed on data, such as collection, recording, systematic organization, storage, alteration, use, transmission, disclosure, coordination or connection, blocking, deletion and destruction, as well as prevention of further use of the data;
**2.6. Data transfer:** if the data is made accessible to a specific third party;
**2.7. Disclosure:** if the data is made accessible to anyone;
**2.8. Data deletion:** making data unrecognizable in such a way that its recovery is no longer possible;
**2.9. Data blocking:** making the transmission, access, disclosure, transformation, alteration, destruction, deletion, connection or coordination and use of data impossible permanently or for a definite period;
**2.10. Data destruction:** complete physical destruction of the data or the data carrier containing them;
**2.11. Technical Data processing:** performing technical tasks related to data management operations, regardless of the method and tool used to perform the operations and the place of application;
**2.12. Data processor:** a natural or legal person or organization without legal personality who, based on a contract – including a contract concluded on the basis of law – processes data;
**2.13. Third person:** a natural or legal person or organization without legal personality who is not identical to the data subject, the data controller, or the data processor;
**2.14. Third country:** any state that is not an EEA state.
—
### 3. Principles of Data Management at Emesetar.com
Personal data may be processed if:
a) the data subject consents to it, or
b) it is ordered by law or – based on the authorization of a law, in the range specified therein – by a local government decree for a purpose based on public interest (hereinafter: mandatory data processing).
For the declaration of an incapacitated minor or a minor with limited capacity, the consent of their legal representative is required, except for those parts of the service where the declaration aims at registration occurring en masse in everyday life and does not require special consideration.
Personal data may only be processed for a specific purpose, in order to exercise a right and fulfill an obligation. At every stage, data processing must comply with this purpose.
Only personal data that is essential for the realization of the purpose of data management and suitable for achieving the purpose may be processed, only to the extent and for the time necessary for the realization of the purpose. Personal data may only be processed with consent based on adequate information.
The data subject must be informed – clearly, intelligibly, and in detail – of all facts related to the processing of their data, in particular the purpose and legal basis of the data processing, the person entitled to data processing and data processing, the duration of the data processing, and who may know the data. The information must also cover the data subject’s rights and legal remedies related to data processing.
The processed personal data must meet the following requirements:
a) their collection and processing are fair and lawful;
b) they are accurate, complete and, if necessary, timely;
c) the method of their storage is suitable for identifying the data subject only for the time necessary for the purpose of storage.
The use of a general and uniform personal identification mark that can be used without restriction is prohibited.
—
### 4. Scope of Personal Data, Purpose, Legal Basis, and Duration of Processing
The data processing of Emesetar.com’s activities is based on voluntary consent. In certain cases, however, the management, storage, and transmission of a set of the provided data is made mandatory by law, about which we notify our audience separately.
We draw the attention of data providers to Emesetar.com that if they do not provide their own personal data, it is the data provider’s duty to obtain the consent of the data subject.
#### 4.1. Data of Visitors to the Emesetar.com Website
* **Purpose:** To provide the service, check its operation, and prevent abuse during visits.
* **Legal Basis:** Consent of the data subject and Section 13/A (3) of Act CVIII of 2001.
* **Scope of Data:** Date and time of visit, IP address, browser type, viewed and previous URL.
* **Duration:** 3650 days from viewing the website.
**Cookies and Analytics:**
The website uses **Google Analytics** for web analytics. Users can manage or delete cookies in their browser settings. Emesetar.com also uses **Google Adwords Remarketing** codes. Visitors can opt-out of personalized ads through the Google Ad Settings manager.
—
### 5. Storage and Security of Personal Data
The IT systems of Cégnév Kft. (Company Name Ltd.) are located at its headquarters, its data processors, and on servers operated by **Cloudways Ltd** and **Mailchimp Ltd**.
We ensure:
a) **Availability:** Accessible to authorized persons.
b) **Authenticity:** Verification of data processing.
c) **Integrity:** Protection against unauthorized modification.
d) **Confidentiality:** Protection against unauthorized access.
—
### 6. Data Controller Information
* **Name:** Emesetar.com
* **Email:** info@emesetar.com
### 7. Data Processor Information
* **Name:** European Data Protection Office (EDPO)
* **Headquarters:** Avenue Huart Hamoir 71, 1030 Brussels, Belgium
—
### 8. Legal Remedies
The data subject may request information about the management of their personal data, request the correction of their personal data, or – with the exception of data management ordered by law – its deletion.
The data controller shall provide information in writing within a maximum of **30 days**.
**Right to Object:**
The data subject may object to the processing of their personal data if:
a) Processing is solely for the interest of the controller or a third party.
b) Use is for direct marketing, public opinion polling, or scientific research.
c) The law otherwise allows the exercise of the right to object.
Emesetar.com will examine the objection within **15 days**. If the data subject disagrees with the decision, they may turn to a **court** within 30 days of notification.
**Authority for complaints:**
**National Authority for Data Protection and Freedom of Information (NAIH)**
* Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
* Postal address: 1530 Budapest, Pf.: 5.
* Phone: +36 (1) 391-1400
* URL: [http://naih.hu](http://naih.hu)
* Email: ugyfelszolgalat@naih.hu