Privacy Statement

Name of Data Controller: Küber bútor Kft.
Registered office: 2096 Üröm, Tücsök utca 13 a
Company registration number: 13 09 189086
Tax number: 26123431-2-13
Representative: Eszter Kótai
Contact: info@wollerkonyha.hu, 36-40 Jász utca, Budapest, 1135.

(hereinafter referred to as the “Data Controller”)

1. Storage of personal data processed by the Data Controller

The Data Controller stores the personal data processed by it on the servers of the following hosting providers:

Hosting provider: Tárhelypark Kft.

Address of the hosting provider:, 18-22 Victor Hugo utca, Budapest 1132.

The email address of the hosting provider is: info@tarhelypark.hu

When drafting the provisions of the Privacy Statement, Küber bútor Kft. has taken into particular consideration the provisions of Regulation 2016/679 of the European Parliament and of the European Council (“General Data Protection Regulation” or “GDPR”), Act CXII of 2011 on the Right ofInformational Self-Determination and Freedom of Information. Küber bútor Kft. respects the privacy rights of visitors to its website. Küber bútor Kft. only records personal data that you voluntarily provide. The data will not be disclosed to third parties and will only be stored and used for the purpose of contacting you.

2. Definitions:

Personal data: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Data processing: any operation or set of operations which is performed upon personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, useage, disclosure by transmission, dissemination or making available otherwise, alignment or combination, restriction, erasure or destruction.

Data Controller: the natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of the processing are determined by European Union or Member State law. The data controller or the specific criteria for the designation of the data controller may also be determined by European Union or Member State law;

Data Processor: a natural or legal person, public authority, agency or any other body which processes personal data on behalf of the data controller;

Privacy Statement: this Privacy Statement of the Data Controller.

Data Transfer: where the data is made available to a specified third party;

Disclosure: where the data are made available to any person;

Data Erasure: the rendering of data unrecognisable in such a way that their recovery is not possible;

Data Destruction: the total physical destruction of a data carrier containing data;

Third country: any state that is not an EEA state;

Data Subject: any specified natural person who is identified or can be identified, directly or indirectly, on the basis of personal data;

Website: the website under the domain name www.wollerkonyha.hu

User: users of the Website.

3. Amendments to the Privacy Statement

The Data Controller reserves the right to unilaterally decide to modify or withdraw this Privacy Statement at any time and to inform the Data Subjects at the same time. The information shall be provided by publication on the Website or, depending on the nature of the change, by direct notification to the Data Subjects. If the user concerned continues to use the services of the Data Controller after the notification, this shall be deemed to constitute acceptance of the amended provisions of the Notice.

4. Scope, purpose, legal basis, storage period, access rights of the personal data processed

4.1. When the User visits the Website, the IP address of the User is automatically recorded by the Data Controller’s system.

The Data Controller places a small data package (so-called “cookie”) on the User’s computer in order to provide a personalized service. The purpose of the cookie is to ensure the highest possible quality of the operation of the site, to provide personalized services and to enhance the user experience. The User can delete the cookie from their computer or their browser to disable the use of cookies. By disabling the use of cookies, the User acknowledges that without a cookie, the functionality of the site is not fully functional.

Purpose of data processing: these data recorded in the log file are used for statistical purposes and cannot be linked to other personal data of the users.

Legal basis for processing: legitimate interest of the Data Controller in the operation of the Website (Article 6(1)(f) GDPR)

Duration of processing: for the period necessary for the proper functioning of the Website.

Persons entitled to access the Personal Data: Eszter Kótai (Küber bútor Kft.)

4.2. Data provided on the Website

Data processed: name, e-mail address, telephone number

Purpose of data processing: registration of customers, distinguishing customers from each other, fulfilling orders, customer contact, information about current information, offers.

Legal basis for processing: voluntary, specific and informed consent of the data subject (Article 6(1)(a) GDPR), or the performance of a contract or the legitimate interests of the Controller (Article 6(1)(b) and (f) GDPR).

Duration of processing: until 30 days after the withdrawal of consent or, failing that, until 5 years after the termination of the cooperation.

Persons entitled to access the Personal Data: Eszter Kótai (Küber bútor Kft.)

5. Method of data processing, data transfer
  • The Data Controller shall process Personal Data in accordance with the principles of good faith and fairness and transparency, as well as in accordance with the applicable laws and the provisions of this Statement.
  • The Data Controller shall use Personal Data necessary for the use of the Services on the basis of the consent of the User concerned and only for the purposes for which they are collected.
  • Unless otherwise stated by law, the disclosure of Personal Data to third parties or public authorities is only possible on the basis of a decision by a public authority or with the prior express consent of the User.
  • The Data Controller shall process Personal Data only for the purposes set out in this Statement and in the applicable legislation. The scope of the Personal Data processed shall be proportionate to the purpose of the Data Processing and shall not go beyond that purpose.
  • In all cases where the Data Controller intends to use the Personal Data for a purpose other than that for which it was originally collected, the Data Controller shall inform the User thereof and obtain his or her prior explicit consent or provide the User with the opportunity to object to such use.
  • The Controller does not verify the Personal Data provided. The person providing the Personal Data is solely responsible for the correctness of the Personal Data provided.

Processing of data received from third parties:

Any User who provides their e-mail address and Personal Data during the registration process also agrees that

  • (1) the data and consents provided by them being their own and accurate,
  • (2) they are the sole user of the service using the data provided.

With regard to this assumption of responsibility, any and all liability in connection with accessing the Service using an e-mail address and/or data provided shall be borne solely by the User who registered the e-mail address and provided the data. If the User has provided third party data during registration for the use of the service, the User shall be liable and the Data Controller shall be entitled to claim damages from the User. In such a case, the Data Controller shall provide all reasonable assistance to the competent authorities in order to establish the identity of the offending person.

The Personal Data of a person under the age of 16 may be processed only with the consent of the person who has parental authority over them. The Data Controller is not in a position to verify the eligibility of the person giving consent or the content of their declaration, so the User or the person having parental authority over them guarantees that the consent is in accordance with the law. In the absence of a declaration of consent, the Data Controller shall not process or collect Personal Data relating to a Data Subject under the age of 16, with the exception of the IP address used when using the Website, which is automatically recorded due to the nature of the Internet services.

6. Analytical Services:

The Data Controller uses Google Analytics to track site statistics and user demographics, interests and behaviour on websites. The Data Controller also uses Google Search Console for site search engine optimization and to measure user satisfaction. Google provides the option to limit the use of analytics services. Visit Google’s website to opt-out of the use of your data by Google Analytics. https://tools.google.com/dlpage/gaoptout

Data transfers to third countries or international organisations:

  • The Data Controller will not transfer the Data Subject’s personal data and records to a third country or international organisation outside the European Economic Area.
  • The Data Controller may, in certain cases – a formal judicial or police request, legal proceedings concerning copyright, property or other infringements or reasonable suspicion of such infringements – make available to third parties the Personal Data of the User concerned that are accessible to the Data Subject. The Data Controller shall not be held liable for such transfers and the consequences thereof. The processing of the transferred data shall be governed by the third party’s data processing provisions.
  • The Data Controller shall keep a record of the data transfers for the purpose of verifying the lawfulness of the data transfers and providing information to the User.

7. Information on data security measures

The Data Controller shall ensure that data protection is provided by default and by design. To this end, the Data Controller shall apply appropriate technical and organisational measures in order to:

  • precisely control access to the data;
  • allow access only to those persons who need the data to perform the task for which it is collected, and then only to the minimum necessary for the performance of that task;
  • carefully select the data processors it engages and ensure the security of the data through appropriate data processing contracts;
  • ensure the integrity (data integrity), authenticity and protection of the data processed.

The Data Controller shall implement reasonable physical, technical and organisational security measures to protect Personal Data, in particular against accidental, unauthorised or unlawful destruction, loss, alteration, disclosure, use, access or processing. The Data Controller shall immediately notify the Data Subject of any known unauthorised access to or use of Personal Data which is known to be of high risk to the Data Subject.

The Data Controller shall, where it is necessary to transfer Data Subject data, ensure adequate protection of the data transferred, for example by encrypting the data file. The Controller shall be fully responsible for the processing of the Data Subject’s data carried out by third parties.

The Data Controller shall also ensure that the Data Subject’s data are protected against destruction or loss by appropriate and regular backups.

8. Rights of Data Subjects

The User may request information about the processing of Personal Data at any time in writing, by registered or certified mail sent to the address of the Data Controller or by e-mail sent to their e-mail address.

The request for information may cover the data of the User processed by the Controller, their source, the purposes, legal basis and duration of the processing, the names and addresses of any Data Processors, the activities related to the processing and, in case of transfer of Personal Data, who has received or is receiving the User’s data and for what purposes.

The User may request the rectification or modification of his Personal Data processed by the Controller. Taking into account the purpose of the Processing, the User may request the completion of incomplete Personal Data.

The User may request the erasure of his Personal Data processed by the Controller.

Deletion may be refused (1) based on the right to freedom of expression and information.