Privacy Policy
GDPR · Infotv. notice
Privacy Policy
This notice describes the processing of personal data carried out by the ladymhungary.hu webshop, in accordance with the General Data Protection Regulation of the European Union (GDPR, Regulation (EU) 2016/679) and Act CXII of 2011 on the right of informational self-determination and freedom of information (Infotv.).
1. Data controller
- Name: Tünde Menyhárt, Sole Trader
- Registered seat: 9082 Nyúl, Tavasz utca 14., Hungary
- Tax number: 67603538-1-28
- E-mail: info@ladymhungary.com
- Phone: +36 70 397 9879
The Data Controller has not appointed a separate data protection officer — there is no obligation to do so under Article 37 of the GDPR, given the size of the business and the nature of the data processing.
2. Scope of data processed
The Data Controller processes the following personal data:
- Data provided during purchase: name, e-mail address, postal address, phone number, billing details.
- Data related to account registration (optional): username, password (hashed), order history.
- Technical data: IP address, browser identifier, cookies (see point 8), time of visit.
- Processing of payment data: the Data Controller does not store card data; it is handled directly by the payment service provider (see point 5).
- Correspondence: the content of contact e-mails (until the matter is closed + the GDPR limitation period).
3. Purpose and legal basis of the data processing
| Purpose | Legal basis (GDPR) | Data processed |
|---|---|---|
| Fulfilment of the order, conclusion of contract, shipping | Article 6 (1) b) — performance of a contract | Name, address, e-mail, phone, order details |
| Invoicing, retention of accounting documents | Article 6 (1) c) — legal obligation (Accounting Act, Section 169) | Billing name, address, tax number (if any) |
| Contact, customer management | Article 6 (1) b) and f) — contract, legitimate interest | Name, e-mail, message content |
| Marketing (newsletter, discounts) | Article 6 (1) a) — consent | Name, e-mail |
| Statistical and marketing cookies | Article 6 (1) a) — consent (cookie banner) | See point 8 |
4. Duration of the data processing
- Order and billing data: 8 years (the retention obligation under Section 169 (2) of the Accounting Act).
- Customer account data: for the duration of the account’s activity, or until a request to delete the account.
- Marketing data: until the consent is withdrawn.
- Contact e-mails: 5 years from the closing of the matter (the general limitation period under the Civil Code).
- Cookie data: according to the validity period set out in the cookie policy (see point 8).
5. Data processors
For processing orders and operating the webshop, the Data Controller uses the following data processors:
- Hosting provider: Rackhost Zrt. (6722 Szeged, Tisza Lajos krt. 41., Hungary) — server operation, backups, EU jurisdiction.
- CDN and security service: Cloudflare, Inc. (San Francisco, CA, USA) — request forwarding, DDoS protection. Cloudflare distributes traffic among EU servers; any transfer to a third country (USA) is based on Cloudflare’s standard contractual clauses (SCC).
- E-mail sending (transactional): Zoho Corporation / Zoho Mail (EU data centre) — sending confirmation and notification e-mails.
- Business correspondence: Zoho Mail (Zoho Corporation, EU region) — info@ladymhungary.com.
- Payment service provider (future): SimplePay (OTP Mobil Kft., 1143 Budapest, Hungária krt. 17-19.) or Barion (Barion Payment Zrt., 1117 Budapest). Card data is handled directly by the payment service provider, not by the Data Controller.
- Courier service: Magyar Posta Zrt. (MPL) and GLS General Logistics Systems Hungary Kft. — handover of the shipping name, address and phone number.
- Online card payment: Stripe Payments Europe, Ltd. (1 Grand Canal Street Lower, Dublin, Ireland) — the customer’s name, e-mail address and the payment amount for processing the payment. Card data is sent directly to Stripe and does not touch the webshop’s server.
6. Data transfer to a third country
In connection with the Cloudflare service, data may also be transferred to servers located in the United States. Cloudflare provides appropriate safeguards under Article 46 of the GDPR (Standard Contractual Clauses, SCC). No other transfers to third countries take place.
7. Rights of the data subject
Under the GDPR, the data subject (the Customer or the visitor) may exercise the following rights:
- Right of access: may request information about the data processed about them (GDPR Article 15).
- Right to rectification: may request the correction of their data (Article 16).
- Right to erasure (“right to be forgotten”): may request the erasure of their data if the legal basis for processing has ceased (Article 17).
- Right to restriction: may request the temporary restriction of the processing (Article 18).
- Right to data portability: may request their data to be provided in a machine-readable format (Article 20).
- Right to object: may object to processing carried out on the basis of legitimate interest (Article 21).
- Withdrawal of consent: may withdraw consent-based processing at any time, without affecting the lawfulness of processing before the withdrawal (Article 7 (3)).
To exercise these rights, the request must be sent to info@ladymhungary.com. The Data Controller responds within 1 month.
8. Cookies
The webshop uses the following cookie categories:
- Necessary (always active): cookies essential to the operation of the webshop (cart contents, login, security tokens). Legal basis: GDPR Article 6 (1) f) legitimate interest and the electronic communications exception under the Electronic Communications Act.
- Statistics (opt-in): anonymous measurement of visitor behaviour (page views, browsing path). Legal basis: consent.
- Marketing (opt-in): remarketing and social-media pixels (e.g. Meta Pixel, Pinterest). Legal basis: consent.
Cookie settings can be changed at any time using the cookie banner. The detailed cookie list is available on the “Cookie settings” page linked to the cookie banner.
9. Data security
The Data Controller applies appropriate technical and organisational measures according to the state of science and technology to protect the data (HTTPS, password hashing, permission levels, regular backups, logging). In the event of a data protection incident, it fulfils its obligations under Articles 33–34 of the GDPR (notification to the NAIH within 72 hours, notification of data subjects as necessary).
10. Complaint
You may submit a data protection complaint to the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):
- Address: 1055 Budapest, Falk Miksa utca 9-11.
- Postal address: 1363 Budapest, Pf. 9.
- Phone: +36 1 391 1400
- E-mail: ugyfelszolgalat@naih.hu
- Website: naih.hu
Judicial remedy: the regional court of your place of residence or of the Data Controller’s seat.
In effect: 18 June 2026