Information

on data management

Information on data management

I. Name of data controller

Company name: Radics Barista Korlátolt Felelősségű Társaság

Headquarters:  1164 Budapest, Vágás utca 45. földszint 2.

Company register number: 01 09 173494

Tax number: 24360865242

 

II. Legislation underlying data management

The following legislation applies to data management: Regulation (Eu) 2016/679 of the European Parliament and of the Council (April 27, 2016) on the protection of natural persons with regard to the management of personal data and on the free flow of such data, and on the repeal of Regulation 95/46/EC, effective text: https://eurlex.europa.eu/legal-content/HU/TXT/PDF/?uri=CELEX:32016R0679&from=HU on the right to information self-determination and freedom of information CXII of 2011 Act (hereinafter: Info TV.), effective text: https://net.jogtar.hu/jogszabaly?docid=A1100112.TV XLVIII of 2008 on the basic conditions and certain limitations of economic advertising activities. law, effective text: https://net.jogtar.hu/jogszabaly?docid=A1100112.TV CLV of 1997 on consumer protection. law, effective text: https://net.jogtar.hu/jogszabaly?docid=99700155.TV

III. Information on managed data Scope of data managed by the Data Controller:

Online identifier of the data subject. Legal basis for data management: Consent of the data subject Duration of data management: Until withdrawal of consent IV. About cookies in general

(1) Cookies are short data files placed on the user's computer by the visited website. The purpose of the cookie is to make the given information communication and Internet service easier and more convenient. There are many types, but they can generally be classified into two large groups. One is the temporary cookie, which the website places on the user's device only during a specific session (e.g. during the security identification of internet banking), the other type is the permanent cookie (e.g. the language setting of a website), which remains until then on the computer until the user deletes it. Based on the guidelines of the European Commission, cookies [unless they are absolutely necessary for the use of the given service] can only be placed on the user's device with the user's permission.

(2) In the case of cookies that do not require the user's consent, information must be provided during the first visit to the website. It is not necessary for the full text of the information about cookies to appear on the website, it is sufficient if the website operators briefly summarize the essence of the information and refer to the availability of the full information via a link.

(3) In the case of cookies that require consent, the information may also be linked to the first visit to the website, in the event that the data management associated with the use of cookies already begins with the visit to the website. If the cookie is used in connection with the use of a function specifically requested by the user, the information may also appear in connection with the use of this function. In this case, it is not necessary for the full text of the information about cookies to appear on the website, a short summary of the essence of the information and a link to the availability of the full information is sufficient.

(4) The visitor must be informed about the use of cookies on the website in the data management information sheet according to the annex to these regulations. With this information, the Data Controller ensures that the visitor can learn, before using the information society-related services of the website and at any time during the use, for which data management purposes the Data Controller manages which types of data, including the management of data that cannot be directly linked to the user.

V. Used cookies

The Data Controller informs its Users that it uses Google Analytics, Google Remarketing, AdWords Conversion Tracking, and Facebook Remarketing programs to measure the number of visitors to its Website and its subpages and to monitor the behavior of its visitors, to compile statistics and to measure the effectiveness of its advertisements. The referred programs on the user's computer are so-called cookies are placed that collect user data. Website visitors (Data Subjects) authorize the Data Controller to use the Google Analytics, Google Remarketing, AdWords Conversion Tracking and Facebook Remarketing programs. At the same time, they consent to the monitoring and tracking of their user behavior and the use of all services provided by the programs for the Data Controller. In addition to all this, the user has the option to disable the data recording and data storage of cookies for the future at any time as described below. We inform our users that the settings and use of the Google Analytics, Google Remarketing, AdWords Conversion Tracking, and Facebook Remarketing programs fully comply with the requirements of the data protection authority. According to Google, Google Analytics mainly uses first-party cookies to report visitor interactions on its website. These cookies only record non-personally identifiable information. Browsers do not share their own cookies between domains.


More information about the cookie can be found in the Google Advertising and Privacy FAQ. 1. Google Analytics: The Data Controller uses the Google Analytics program primarily to generate statistics, including measuring the effectiveness of its campaigns. By using the program, the Data Controller mainly obtains information about how many visitors visited its Website and how much time the visitors spent on the Website. The program recognizes the visitor's IP address, so it can track whether the visitor is a returning or a new visitor, and it can also be tracked how the visitor traveled on the Website and where they entered. 1. Google Remarketing: Using the Google Remarketing program, the Data Controller collects the data of the DoubleClick cookie in addition to the usual data of Google Analytics. The remarketing service can be used through the DoubleClick cookie, which primarily ensures that visitors to the Website will later come across the Data Controller's ad on free Google advertising platforms. The Data Controller uses the Google Remarketing program for its online advertisements. The Data Controller's advertisements are also displayed on Internet websites by external service providers, such as Google. The Data Controller and third-party service providers, such as Google, use their own cookies (such as Google Analytics cookies) and third-party cookies (such as the DoubleClick cookie) to collect information based on users' previous visits to the Website. for orientation and to optimize and display advertisements. 1. Google AdWords conversion tracking: The purpose of Google AdWords conversion tracking is to enable the Data Controller to measure the effectiveness of AdWords ads. It does this with the help of cookies placed on the User's computer, which exist for 30 days and do not collect personal data. 2. Facebook Remarketing The Data Controller uses the Facebook remarketing pixel to increase the effectiveness of Facebook ads, so-called for the purpose of building a remarketing list. Thus, after visiting the Website, an external service provider - such as Facebook - may display advertisements on Internet websites. Remarketing lists are not suitable for personal identification. They do not contain the visitor's personal data, they only identify the browser software. 3. Disable cookies If you want to manage cookie settings or disable the function, you can do so from your own user's computer in your browser. Depending on the browser's toolbar, this option can be found in the cookies/cookies/tracking functions placements menu item, but usually in Tools > Settings > Under Privacy settings, you can set which tracking functions you enable/disable on your computer. Users who do not want Google Analytics to create a report on their visit can install the Google Analytics blocking browser extension. If you wish to opt-out of Analytics web activity, visit the Google Analytics opt-out page and install the add-on for your browser. For more information on installing and uninstalling the extension, see the help for your browser.

VI. Access to data and data security measures

1. Access to data and data transmission Personal data provided by you may be accessed by the employees of the Data Controller in order to perform their duties. The data manager forwards the processed personal data to its subcontractors as specified in the annex to these regulations. Only in exceptional cases does the Data Controller hand over your personal data to other - not listed in the annex - Data Controllers and public bodies. Thus, for example, if court proceedings are initiated in a case concerning you and the court in charge needs to hand over documents containing your personal data, the police will contact the Data Controller and request the transmission of documents containing your personal data for the investigation. 2. Data security measures The Data Controller stores the personal data provided by you on the Data Controller's servers or, where applicable, in its paper-based archives. The Data Controller does not use the services of other companies to store personal data. The data controller takes appropriate measures to protect personal data, among other things, against unauthorized access or unauthorized changes. For example, access to personal data stored on the server is logged by the Data Controller, which means that it is always possible to check who, when and what personal data was accessed.



VII. The data subject's rights related to data management

1. Your access rights As the authorized person, you can access your personal data. If you request that the Data Controller provide feedback on whether it handles your personal data, the Data Controller is obliged to provide information regarding the following: a. what personal data, b. on what legal basis, c. for what data management purpose, d. from what source, e. how long you treat it. Your right to receive feedback on whether the Data Controller is (or is not) handling your personal data, a. covers personal data about you; b. does not cover anonymous data; c. does not cover personal data that does not relate to you; and d. includes pseudonymized data that can be clearly linked to you. Upon your request, the Data Controller provides access and a copy of your personal data. If you request an additional/repeated copy of your personal data, the Data Controller may charge a reasonable fee to pay the administrative costs incurred in connection with the fulfillment of the request, which fee you will bear. 2. Your right to correction You have the right to correct your personal data. This right a. does not cover anonymous data; b. covers personal data about you; c. does not cover personal data that does not relate to you; and d. includes pseudonymized data that can be clearly linked to you. Based on your request, the Data Controller will properly correct or supplement your personal data. The Data Controller will inform the recipients of your personal data (if any) about the correction of your personal data. However, the Data Controller will not inform the recipients of the correction of personal data if informing the recipients proves to be impossible or would require a disproportionately large effort. 3. Right to deletion Under certain conditions, you have the right to delete your personal data. The Data Controller is obliged to delete your personal data without undue delay if a. the Data Controller manages these personal data, and b. You request the deletion of your personal data, and c. the personal data are not necessary for the purposes for which the Data Controller processes the personal data. The Data Controller is obliged to delete your personal data without undue delay if a. the Data Controller manages your personal data, and b. You request the deletion of your personal data, and c. You withdraw your consent on which the processing of your data is based, and d. there is no other legal basis for further processing of your data. The Data Controller is obliged to delete your personal data without undue delay if a. the data management is necessary to enforce the legitimate interests of the Data Controller or a third party, and b. You object to the Data Controller handling your personal data, and c. the legitimate reason for the processing of such personal data does not take precedence over your objection. The Data Controller is obliged to delete your personal data without undue delay if a. You request the deletion of your personal data, and b. the processing of such data by the Data Controller is not illegal, or c. deletion is mandatory under applicable laws, or d. your data is collected in relation to services related to the information society. The Data Controller will inform the recipients of your personal data (if any) about the deletion of your personal data. However, the Data Controller will not inform the recipients of the deletion of personal data if informing the recipients is impossible or would require a disproportionately large effort. 4. Your right to restrict the processing of your personal data You may request the restriction of the processing of your personal data. Your right to request the restriction of the processing of your personal data (a) does not extend to anonymous data; (b) covers personal data relating to him; (c) does not cover personal information that does not relate to you; and (d) includes pseudonymized data that can be clearly linked to you. The Data Controller limits the processing of your personal data to the period during which it checks the accuracy of such data, if you request the restriction of the processing of your personal data and you dispute the accuracy of such data. The Data Controller restricts the processing of your personal data if you request the restriction of the processing of data whose processing is illegal and you oppose the deletion of such data. The Data Controller restricts the processing of your personal data if (a) you request the restriction of the processing of your personal data, and (b) the Data Controller no longer needs this data for the purposes of its data processing, and (c) you use your data to present, assert or enforce a legal claim or required for protection. The Data Controller restricts the processing of your personal data if a. You object to the processing of your personal data that is necessary for the legitimate interests of the Data Controller, and b. You are waiting for confirmation that there is a legitimate reason for the processing of your personal data by the Data Controller, which does not take precedence over your objection. The Data Controller informs the recipients of such personal data (if any) about the restriction of the processing of your personal data. However, the Data Controller will not inform the recipients of such a restriction if informing the recipients would be impossible or would require a disproportionately large effort. If the Data Controller restricts the processing of your personal data, it may (a) store such personal data, (b) process such personal data based on your consent, (c) process personal data to assert, assert or defend a legal claim or a person to protect your rights. 5. Your right to data portability You have the right to receive your personal data provided by you to a data controller in a segmented, widely used, machine-readable format, and you are also entitled to have this data transmitted to another data controller without hindrance (where technically possible) the data manager to whom you provided the personal data, if the data management is based on consent or is necessary for the performance of a contract and the data management is automated. Your right to data portability (a) does not extend to anonymous data; (b) covers personal data about you; (c) does not cover personal information that does not relate to you; and (d) does not cover clearly pseudonymized data. 6. The deadline for processing your request as a data subject The Data Controller shall respond to requests for the rights you are entitled to according to the above without undue delay, but within one month at the latest. 7. Right to file a complaint If you believe that your rights have been violated, the Data Controller recommends that you initiate a consultation with the Data Controller by contacting the Data Controller directly. If such consultation does not lead to results or if you do not wish to participate in such activities, you can turn to the court or the NAIH. In the event of initiation of court proceedings, you may decide to initiate the proceedings before the competent court according to your address or place of residence. NAIH's contact details are as follows: 1125 Budapest, Szilágyi Erzsébet fasor 22/C.; telephone: +36 1 391 1400; fax: +36 1 391 1410; e-mail: ugyfelszolgalat@naih.hu; website: www.naih.hu 8. Amendments to this information


The Data Controller reserves the right to amend this information at any time. The Data Controller informs customers of such modifications by letter or e-mail, as appropriate, and in all cases in accordance with the relevant legislation.