I. General. Besides other general information, this chapter contains the data of the Controller and some processors.
II. Ways of processing. In this chapter you may find specific information (the purpose, grounds and period of processing, the scope of data subjects and the data processed) per each purpose of the processing:
II/1. Registration, login
II/5. Prize games
II/7. Personal data of partners
III. The rights of the users as data subjects. Here you may find a detailed description of your rights regarding the processing and the related procedure.
IV. Remedies. In this chapter you may find the detailed description of the remedies you can have if our rights related to your personal data are violated.
registering on the website, and the visitor of the website shall be considered data subjects. The Controller:
Company name/ Name: S.P.O. Marketing Kereskedelmi és Szolgáltató Korlátolt Felelosségu Társaság
Registered and postal address: 1064 Budapest, Podmaniczky utca 57. 2. em. 14.
E-mail: [email protected]
Tax No: 23502431-2-42
Registration No: 01-09-294355
‘Controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
2. It is
the Controller’s intention to ensure the protection of the personal data of the
persons providing such on the Website at www.visitme.hu to the extent possible. This Privacy
Policy shall be applicable in respect of the Website only and no other websites of any third parties, even if such are accessible from the Website.
which it shall inform the users by email.
4. The Controller provides its services protecting the personality rights of the visitors of the
Website and its clients, in accordance with the law, especially:
- REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF
THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, GDPR);
- the Hungarian Civil Code;
- Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom
of Information (hereinafter: the Data Protection Act)
5. Please note that it is voluntary to provide personal data on the Website and upon the
6. The Controller may forward personal data to pursue its activities, to the extent required thereto, to data processors as recipients. ‘Processor’ means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
6.1. The accountant of the Controller is considered a data processor:
Company name/ Name: BONUK Kft.
Registered and postal address: 1015 Budapest, Donáti utca 38. A. lház. fszt.
E-mail: [email protected]
Activities: accountancy, in case no data is provided, the Controller cannot fulfill its activities.
Forwarded personal data: personal data required for invoices, name and address.
6.2. The personal data processed by us are stored at our storage provider as a data processor:
Forwarded data: data collected upon registration.
Marketing data (name and email address) are also stored at the storage provider below: Name: RACKFOREST Kft.
Registered seat: 1132 Budapest, Victor Hugo u. 18-22.
E-mail address: [email protected]
Phone: +36 70 362 4785
6.3. We use a service provider for the payment systems:
Name: Barion Payment Zrt.
Activities: payment services, in case no data is provided, the Controller cannot fulfill its activities.
Forwarded data: data requested and provided upon payment.
7. Upon placing an order, the personal data will be forwarded to the restaurant concerned.
II. Ways of processing:
II/1. Registration, login:
8. For using the services on the Website and entering into an agreement, a registration and
login is necessary. Without a registration, no contract is made between the Parties and the Controller cannot provide its services. The data provided upon registration shall be processed by the Controller fit to the purpose, as and to the extent required to provide the services and keep contact with the clients as provided for by law. The data subject may add new data with changing his or her profile and upon placing the order the data subject may use a new delivery address. With your account you can record your former orders and the state of V coins. In case of registration or logging in with Facebook or Google+, the personal data will be forwarded to us by and collected from them.
9. The ground for processing is the voluntary consent of the data subject in accordance with point (a) of subparagraph 1 of Article 6 of the GDPR. By providing their personal data, the with accepting the users give their consent to the use of their personal data by the Controller for providing its services. The Controller will only use the personal data only for the purpose known by the data subject at the provision, and shall not forward them or grant access to them to any third parties without any authorization and keep them separately and encrypted. The employees or subcontractors of the Controller shall have access to the personal data.
10. The purpose of processing is to ensure that the Controller fulfill the orders of the
customers as data subjects.
11. If the user buys a coupon in the coupon shop, his or her name will be forwarded to the
printing location of the user’s choice to identify the user as the person entitled to claim the coupon.
12. Personal data processed:
· name (surname and first name),
· email address,
· home address, billing address (postcode, municipality, street, house No.), delivery
· phone number,
· Facebook or Google+ profile picture.
Period of processing: until the data subject requests its profile to be deleted, in respect of
invoice data for the duration required by law (8 years).
11. The User may subscribe to the newsletter upon registration and without a registration with
its expressed, voluntary and active declaration.
12. The purpose of processing is informing the data subjects on the services, products, news
and events of the Controller and any changes thereto.
13. The ground for processing is the voluntary consent of the data subject in accordance
with point (a) of
subparagraph 1 of Article 6 of the GDPR.
Processed personal data:
· name (surname and first name)
· email address
14. Period of processing: lasts until the data subject requests to unsubscribe from the
15. Upon the placement of the order, for fulfilling it, the Controller processes personal
16. The purpose of processing is the provision of the services.
17. The ground for processing is the performance of the contract. [point (b) of
subparagraph 1 of Article 6 of the GDPR].
18. Period of processing: the civil law expiry period of 5 years.
19. Processed personal data: home address, phone number, e-mail address, the number and
date of placing the order.
20. The personal data in the order will be forwarded to the respective restaurant. In case
no data is provided, the
Controller cannot provide the service of home delivery.
20. The Controller stores, i.e. processes the personal data on the invoices.
21. The purpose of processing is issuing invoices, compliance with the laws for
22. The ground for processing is compliance with a legal obligation, in accordance with
paragraph (1) of Article 159 of Act CXXVII of 2007, and paragraph (2) of Article 169 of Act C of 2000 [point (c) of subparagraph 1 of Article 6 of the GDPR].
23. Processed personal data: name, address, e-mail address, phone number.
24. The data subjects are the natural persons on the invoices.
25. Period of processing: 8 years.
26. The data in the invoices will be forwarded to the company providing the invoice
II/5. Prize games
27. The Controller processes the personal data of the participants as data subjects to
organize the prize game.
28. The purpose of processing is the organization of the prize
29. The ground for processing is the voluntary consent of the data subject [point (a) of
subparagraph 1 of Article 6 of the GDPR].
30. Processed personal data: name, address, e-mail address, phone number.
31. Period of processing: until the closure of the prize game, in respect of the winners for
32. The processing shall be made for the purpose of complaint-handling, the Contractor is
obligated to keep the complaint.
33. The data subject is the person making a complaint.
34. The ground for processing is compliance with a legal obligation, in accordance with paragraph (7) of Article 17/A of Act CLV of 1997, and paragraph (2) of Article 169 of Act C of 2000 [point (c) of subparagraph 1 of Article 6 of the GDPR].
35. Processed personal data: name, address, e-mail address, phone
36. Period of processing: 3 years, as provided for by law.
II/7. Personal data of partners
37. In respect of the Controller’s contractual partners (especially restaurants) which are
not its clients, the Controller processed the personal data of natural person partners and the natural person contact persons of the partners not being natural persons (names, home addresses, email addresses, phone numbers of partners and names, phone numbers, email addresses, titles, position the contact persons).
38. The ground for processing is the performance of the contract [point (b) of subparagraph 1 of Article 6 of the GDPR] in case of natural person partners. In respect of natural person contact persons of the partners not being natural persons, the ground for processing is the legitimate interests of the Controller and the partner that their agreement be fulfilled [point (f) of subparagraph 1 of Article 6 of the GDPR].
39. Period of processing:
the civil law expiry period of 5 year.
order to monitor the Website, the Controller uses an analytical tool (cookie) which prepares a data string and tracks how the visitors use the
internet pages. When a page is viewed, the
system generates a cookie in order to record the information related to the visit (pages visited, time spent on the Controller’s
pages, browsing data, exits, etc) and installs
it on the computer of the visitor but these data cannot be linked to the
visitor's person. This tool is instrumental in
improving the ergonomic design of
improving a user-friendly website, enhancing the online experience
for visitors and preventing data loss. Cookies recognize the computer of
the visitor and manage its IP address. Most internet browsers accept cookies,
but visitors have the option of deleting or automatically
rejecting or allowing them. The visitor has the option to decline the installation of cookies.
Since all browsers are
can set their cookie preferences individually with the help of
the browser toolbar. Users might not be able
to use certain features on the Website if they decide
not to accept cookies. Using cookies, the websites seen by the visitor and the
internet use customs of the visitor
may be monitored. Only
upon revisiting the Website and exclusively the respective service provider
can link such
data to the person of the visitor. The duration of the storing of such
data depends on the type of the cookies.
Session cookies erase the data upon closing the Website, Flash-cookies, however may store the data up to one year of inactivity.
41. The ground for processing is the voluntary consent of the data subject (the visitor) in
accordance with point (a) of subparagraph 1 of Article 6 of the GDPR.
42. Processed data: browser history, identification No, date, time of visit.
43. The purpose of processing: improvement of the user experience, storing of the data of
the respective session, prevention of data loss, identification and tracking of the data subjects, web analytics .
44. In the Menu of most of the browsers, there is a “Help” function providing information
for the data subject, in his or her browser
- where to disable cookies,
- how to accept new cookies,
to instruct the browser to set new cookies or
- turn off other cookies.
45. Outer servers help the impartial measuring and auditing of the visitor and other web analytics data (Google Analytics and Facebook). The service providers can provide detailed information for the data subject.
Further information on the cookies used by Google may be found via this link: http://www.google.com/policies/technologies/ads/.
Description of the Analytics cookies: https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie- usage#analyticsjs
Information regarding the analytics cookies of Facebook: https://www.facebook.com/policies/cookies/ https://developers.facebook.com/docs/mediaguide/pixel-and-analytics/
46. The Controller uses the following cookies with the expiration of 1 year:
• Name : „s”
stores the work session of the visitor; functional; obligatory;
• Name : „address”
In some cities an address needs to be provided to set the terms of food delivery. It is obligatory where it is used. This also helps to narrow the restaurant search results. This data is only stored in the moment of placing the order.
• Name : „p”
A cookie used for some of the promotion and pop-up (city choosing) windows. It is obligatory, for ignoring it results that the website cannot be used.
III. The rights of the users as data subjects
47. The data subject may exercise his or her following rights via the contacts of the
Controller listed above:
- right to request information on the processing of the personal data and the right
- right to rectification,
to request erasure except the cases of obligatory processing,
- right to withdraw the cosent,
- right to data portability,
- Right to objection;
- right to object against automated individual decision-making.
III/1. Right for information and access:
48. The Controller shall take appropriate measures to provide any information referred to
in Articles 13 and 14 relating to processing to the data subject in a concise, transparent, intelligible and easily accessible form, using clear and plain language.
49. Information may be requested in writing through the contact data of the Controller specified above. When requested by the data subject, the information may be provided orally, provided that the identity of the data subject is proven by other means.
50. The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information: the purposes of the processing; the categories of personal data concerned; the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations; the envisaged period for which the personal data will be stored; the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing; the right to lodge a complaint with a supervisory authority; the existence of automated decision-making, including profiling and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject. Where personal data are transferred to a third country or to an international organisation, the data subject shall have the right to be informed of the appropriate safeguards relating to the transfer.
51. The controller shall provide a copy of the personal data undergoing processing. For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs. Where the data subject makes the request by electronic means, and unless otherwise requested by the data subject, the information shall be provided in a commonly used electronic form.
52. The Controller shall be obliged to respond to requests from the data subject at the
latest within one month.
III/2. Right to rectification:
53. The data subject shall have the right to obtain from the Controller without undue delay
the rectification of inaccurate personal data and the completion of incomplete personal data concerning him or her.
III/3. Right to erasure (‘right to be forgotten’):
54. The data subject shall have the right to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have
the obligation to erase personal data without undue delay where one of the following grounds applies:
- the personal data are no longer necessary in relation to the
purposes for which they were collected or otherwise processed;
- the data subject withdraws consent on which the processing is based, and where there is no other legal ground for the processing;
- the data subject objects to the processing and there are no overriding legitimate grounds for the processing,;
- the personal data have been unlawfully processed;
- the personal data have to be erased for compliance with a legal obligation in Union
or Member State law to which the controller is subject;
- the personal data have been collected in relation to the offer of information society services.
55. Erasure may not be requested to the extent that processing is necessary: for exercising the right of freedom of expression and information; for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; for reasons of public interest in the area of public health; for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes; or for the establishment, exercise or defence of legal claims.
III/4. Right to restriction of processing:
56. The data subject shall have the right to obtain from the controller restriction of
processing where one of the following applies:
- the accuracy of the personal data is contested by the data subject, for a period enabling the controller to verify the accuracy of the personal data;
- the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;
- the controller no longer needs the personal data for the purposes of the processing, but they are required by the data subject for the establishment, exercise or defence of legal claims;
- the data subject has objected to processing pending the verification whether the legitimate grounds of the controller override those of the data subject.
57. Where processing has been restricted, such personal data shall, with the exception of storage, only be processed with the data subject's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the European Union or of a Member State.
58. A data subject who has obtained restriction of processing shall be informed by the
controller before the
restriction of processing is lifted.
III/5. Right to data portability:
59. The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided.
III/6. Right to object:
60. The data subject shall have the right to object, on grounds relating to his or her
particular situation, at
any time to processing of personal data concerning him or her
which is necessary for the performance of a task
carried out in the public interest or in the
exercise of official authority vested in the controller or processing is
the purposes of the legitimate interests pursued by the controller or by a third party, including profiling based on those provisions. The Controller shall no longer process the personal data unless the Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.
61. Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing. Where the data subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.
III/7. Right to object against automated individual decision-making:
62. The data subject shall have the right not to be subject to a decision based solely on
automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her. This right may not be exercised if the processing is necessary for entering into, or performance of, a contract between the data subject and a data controller; is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard the data subject's rights and freedoms and legitimate interests; or is based on the data subject's explicit consent.
III/8. Right of withdrawal:
63. The data subject shall have the right to withdraw his or her consent anytime. The
withdraw of the consent shall not affect affecting the lawfulness of processing based on consent before its withdrawal.
III/9. Rules on the procedure of the enforcement of rights:
64. Deadline: The Controller shall provide information on actions taken on a request
under Chapter III hereof to the data subject without undue delay and in any event within one month of receipt of the request. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. The Controller shall inform the data subject of any such extension within one month of receipt of the request, together with the reasons for the delay. Where the data subject makes the request by electronic form means, the information shall be provided by electronic means where possible, unless otherwise requested by the data subject.
65. If the controller does not take action on the request of the data subject, the controller shall inform the data subject without delay and at the latest within one month of receipt of the request of the reasons for not taking action and on the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.
66. Information shall be provided free of charge. Where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the controller may either charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; or refuse to act on the request.
67. The Controller shall communicate any rectification or erasure of personal data or restriction of processing to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort.
68. Any person shall have the right to notify the Hungarian National Authority for Data Protection and Freedom of Information (in Hungarian: Nemzeti Adatvédelmi és Információszabadság Hatóság; http://www.naih.hu/; székhely: 1055 Budapest, Falk Miksa utca 9-11., Postacím: 1363 Budapest, Pf.: 9., Telefon: +36 (1) 391-1400) and request an investigation alleging an infringement relating to his or her personal data or concerning the exercise of the rights of access to public information or information of public interest, or if there is imminent danger of such infringement. The Authority shall carry out the investigation free of charge; the costs thereof shall be advanced and borne by the Authority.
69. In the event of any infringement of his rights, the data subject may turn to court action against the controller. The court shall hear such cases in priority proceedings. The action shall be heard by the competent tribunal. If so requested by the data subject, the action may be brought before the tribunal in whose jurisdiction the data subject’s home address or temporary residence is located. Data controllers shall be liable for any damage caused to a data subject as a result of unlawful processing or by any breach of data security requirements. The data controller shall also be liable for any damage caused by data processors acting on its behalf. The data controller may be exempted from liability if it proves that the damage was caused by reasons beyond his control. No compensation shall be paid where the damage was caused by intentional or serious negligent conduct on the part of the aggrieved party. Should the data controller infringe the personality rights of the data subject with the illegal control of the data subject’s data or with the breach of data security requirements, the data subject may claim restitution from the data controller.