Privacy Policy
1. Controller
[⚠ CÉGADAT — kitöltendő cégalapításkor: cégnév] [⚠ CÉGADAT — kitöltendő cégalapításkor: székhely címe] Email: [⚠ CÉGADAT — kitöltendő cégalapításkor: ügyfélszolgálati e-mail cím] Phone: [⚠ CÉGADAT — kitöltendő cégalapításkor: ügyfélszolgálati telefonszám]
is the controller responsible for the processing of personal data described on this page, within the meaning of the General Data Protection Regulation (GDPR).
2. What we process, and why
| Data | Purpose | Legal basis |
|---|---|---|
| Order data (name, delivery address, email, phone, order/payment details) | To perform the purchase contract (process, ship and account for the order) | Art. 6(1)(b) GDPR — performance of a contract |
| Customer account data (email, saved addresses, order history) | To provide the optional customer account | Art. 6(1)(b) GDPR — performance of a contract (at the customer's request) |
| Transactional emails (order confirmation, shipment notice, password reset) | To send the emails a purchase or account action requires | Art. 6(1)(b) GDPR — performance of a contract |
| Server/technical logs (IP address, request metadata) | Security, abuse prevention, and keeping the Shop running | Art. 6(1)(f) GDPR — legitimate interest in a secure, working service |
3. Cookies
The Shop sets exactly two cookies, both strictly functional and both httpOnly (not readable by page scripts):
_wsp_cart_id— identifies your shopping cart._wsp_customer_token— keeps you signed in to your customer account, if you have one.
We do not use analytics, advertising, or tracking cookies of any kind. Because both cookies are strictly necessary for the Shop to function (cart and login), no cookie-consent banner is shown — this is consistent with the ePrivacy exemption for cookies that are strictly necessary to provide a service the visitor explicitly requested.
4. Recipients / processors
Personal data is shared, to the extent necessary for the purposes above, with:
- Hetzner Online GmbH (hosting, within the EU) — hosts the Shop's servers and database.
- Stripe (payment processing) — processes card payments; card details are entered directly into Stripe's own secure form and never reach our servers.
- Resend (transactional email delivery) — sends order-confirmation, shipment, and account emails on our behalf.
- [⚠ CÉGADAT — kitöltendő cégalapításkor: beszállítói (dropship) partner cégneve] (order fulfilment) — receives the order and delivery-address data necessary to ship your order, as our dropshipping fulfilment partner.
[⚠ DECISION NEEDED: confirm, for each processor above, whether any transfer of personal data outside the EU/EEA occurs and, if so, on what Art. 44 ff. GDPR safeguard (e.g. Standard Contractual Clauses) it relies — to be completed once each processor's data-processing agreement is reviewed.]
5. Retention
Order and invoicing data is kept for as long as required by applicable tax and bookkeeping law (in Hungary, currently 8 years). Customer-account data is kept for as long as the account exists, plus the time needed to comply with the retention duty above. Server logs are kept only for a short, limited period needed for security purposes.
6. Your rights
Subject to the conditions set out in the GDPR, you have the right to request access to, correction of, or erasure of your personal data, to restrict or object to its processing, and to data portability. To exercise any of these rights, contact us at [⚠ CÉGADAT — kitöltendő cégalapításkor: ügyfélszolgálati e-mail cím].
You also have the right to lodge a complaint with a data-protection supervisory authority — in Hungary, the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), or the supervisory authority of your own EU country of residence, which will cooperate with the lead authority where applicable.
7. Automated decision-making
We do not use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
This page is a compliance DRAFT pending review by a qualified lawyer/data-protection advisor before launch. Values shown as {{…}} are filled in automatically from configuration once the company exists; a bracketed [⚠ …] note means the underlying policy has not been decided yet.