Privacy Policy

PRIVACY POLICY

Effective as of: 2026. 06. 24.

The purpose of this Privacy Policy is to outline the data protection and data management principles applied by Attila Varjas e.v. in operating the online store, which the Data Controller recognizes as binding upon themselves. This notice complies with the European Union General Data Protection Regulation (GDPR) and the relevant Hungarian data protection laws (Infotv.).

1. DETAILS OF THE DATA CONTROLLER
Name: Attila Varjas e.v.
Registered Seat: 2120 Dunakeszi Határ street 29.
Registration Number: 61684083
Tax Number: 91672511-1-33
E-mail: attila.varjas@gmail.com
Hereinafter referred to as: "Data Controller".

2. SCOPE, PURPOSE, LEGAL BASIS, AND DURATION OF DATA PROCESSING

2.1. E-commerce Order Processing and Fulfillment
- Scope of data processed: Name, billing address, shipping address, e-mail address, phone number, purchased product details, timestamp of purchase.
- Purpose of data processing: Processing orders, delivering products, communicating with the Buyer, and fulfilling the contractual agreement.
- Legal basis for data processing: GDPR Article 6(1)(b) – necessary for the performance of a contract.
- Data retention period: 5 years from the fulfillment of the contract (in accordance with the civil law statute of limitations in Hungary).

2.2. Compliance with Legal Obligations (Invoicing)
- Scope of data processed: Name, billing address, tax number (in case of corporate buyers).
- Purpose of data processing: Issuing legally compliant accounting documents (invoices).
- Legal basis for data processing: GDPR Article 6(1)(c) – compliance with a legal obligation, with regard to the Hungarian Act C of 2000 on Accounting.
- Data retention period: At least 8 years as mandated by Section 169 (2) of the Hungarian Accounting Act.

2.3. Newsletter and Marketing E-mails (Shopify Email)
- Scope of data processed: Name, e-mail address.
- Purpose of data processing: Sending updates, promotional offers, and marketing materials regarding new products.
- Legal basis for data processing: GDPR Article 6(1)(a) – the voluntary and explicit consent of the data subject.
- Data retention period: Until consent is withdrawn (unsubscribing), which can be done at any time by clicking the unsubscribe link at the bottom of any newsletter.

2.4. Website Analytics and Statistics (Google Analytics)
- Scope of data processed: IP address (in anonymized form), approximate geographic location, browsing behavior, device information.
- Purpose of data processing: Measuring website traffic statistics and improving user experience.
- Legal basis for data processing: GDPR Article 6(1)(a) – consent granted via the website's cookie consent banner.
- Data retention period: Until the expiration of the respective cookies, or until consent is revoked (maximum 14 months).

3. COMPANION MOBILE APPLICATION (ANDROID APP) PRIVACY
The free Android companion mobile application associated with the flashcard packs operates entirely offline, does not require user registration, and **does not collect, store, track, or transmit any personal data, device identifiers, or user information** to the Data Controller or any third parties.

4. DATA PROCESSORS (THIRD PARTIES ENGAGED IN PROCESSING DATA)
To provide services seamlessly, the Data Controller engages the following external data processors, who handle data under strict data protection compliance agreements:

- E-commerce Platform: Shopify International Limited (The Sidings, 4th Floor, Grand Canal Quay, Dublin 2, D02 E7K8, Ireland) – Provides the webstore infrastructure and technical data storage.
- Online Payment Gateway: Stripe Payments Europe Ltd. (The One Building, 1 Grand Canal Street Lower, Dublin 2, Ireland) – Processes secure credit card transactions.
- Online Invoicing: Billingo Technologies Zrt. (1133 Budapest, Árbóc utca 6., Hungary) – Automates and generates electronic invoices.
- Logistics / Shipping: The actual courier service or parcel delivery partner assigned to ship the order (e.g., GLS Hungary Kft. or other contracted courier/delivery partners) – Manages delivery details (name, address, phone number, email) to execute physical delivery.
- Analytics Provider: Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) – Collects aggregated website traffic statistics.

5. RIGHTS OF DATA SUBJECTS (BUYERS)
You have the right to:
- Request access to and information about your personal data stored by us.
- Request the rectification or completion of inaccurate data.
- Request the erasure of your data ("right to be forgotten"), provided the legal basis for processing no longer exists (e.g., unsubscribing from newsletters).
- Request the restriction of data processing.
- Object to the processing of your personal data.
- Exercise your right to data portability.

You can submit any requests regarding the exercise of these rights to the attila.varjas@gmail.com e-mail address.

6. LEGAL REMEDIES AND ENFORCEMENT
If you believe that the Data Controller has violated your privacy rights, please contact us directly at attila.varjas@gmail.com so we can swiftly resolve the issue.

You are also entitled to lodge a complaint directly with the competent supervisory authority or take legal action before a court:
National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
Postal Address: 1363 Budapest, Pf.: 9., Hungary
E-mail: ugyfelszolgalat@naih.hu
Website: www.naih.hu
You may also initiate a lawsuit before the regional Court (Törvényszék) competent based on your place of residence.