PUBLIC NOTICE FOR THE PROCESSING OF PERSONAL DATA FOR MARKETING PURPOSES
The data controller and, where applicable, the data processor performing any data processing operations:
Data Controller: Hennel Mariann EV (hereinafter: EV), 2141 Csömör, Csalogány u. 31.
Data Processors:
MailerLite Limited, an Irish registered company at Ground Floor, 71 Lower Baggot Street, Dublin 2, D02 P593, Ireland
The https://photom.hu website does not store personal data; it automatically forwards data to Mailerlite and via email to Hennel Mariann EV.
Name and contact details of the data protection officer:
The Info Act Section 25/L and Article 37 of the GDPR do not apply to EV, so it is not required to appoint a data protection officer and notify the Authority. Data protection responsibility: Hennel Mariann EV, 2141 Csömör, Csalogány u. 31.
Scope of data subjects:
Any natural person who visits the https://photom.hu website and provides personal data with their consent.
Purpose and legal basis of the planned data processing:
The data controller collects the following personal data on the https://photom.hu website after obtaining consent:
| Data Collection Source | Collected Personal Data | Legal Basis for Data Processing | Purpose of Data Processing | Data Retention Period |
|---|---|---|---|---|
| https://photom.hu– Message sending | Name, Email address, Message | Based on consent | Marketing and sales activities | Until data deletion (e.g., upon withdrawal of consent) |
| https://photom.hu– Appointment booking | Name, Phone number, Email address, Message | Based on consent | Marketing and sales activities – appointment scheduling, newsletter | Until data deletion (e.g., upon withdrawal of consent, unsubscribing) |
| https://photom.hu– Blog subscription | Email address | Based on consent | Marketing and sales activities – new blog post publication | Until data deletion (e.g., upon withdrawal of consent, unsubscribing) |
| https://photom.hu– Other | Name, Photo, Video | Based on consent | Marketing activities, social media platforms: Facebook, Instagram, Pinterest, TikTok, non-commercial purposes: contests, exhibitions, business cards, publications, references | Upon withdrawal of consent |
| https://photom.hu– Other | Name + Review | Based on consent | Marketing activities / social media platforms: website, Facebook, Instagram | Upon withdrawal of consent |
The provision of personal data in the above cases is not mandatory; it is voluntary. The data controller may only process the provided data with the data subject’s consent and with their unambiguous agreement.
The rights of the data subject according to the Info Act and GDPR and how to exercise these rights:
(1) The rights of the data subject are regulated by Section II/a of the Info Act and Articles 13-21 of the GDPR.
(2) Section 2:43(e) of the Civil Code stipulates that a violation of the right to personal data protection constitutes an infringement of personal rights.
(3) The data subject is entitled to:
- Receive information about the facts related to the data processing before the processing begins (hereinafter: right to prior information),
- Upon request, the data controller shall provide personal data and information related to its processing (hereinafter: right of access),
- Upon request, and in other cases defined in this section, the data controller shall rectify or supplement personal data (hereinafter: right to rectification),
- Upon request, and in other cases defined in this section, the data controller shall restrict the processing of personal data (hereinafter: right to restriction of processing),
- Upon request, and in other cases defined in this section, the data controller shall delete personal data (hereinafter: right to erasure).
Furthermore, the GDPR guarantees the right to data portability and the right to object.
The data controller’s data processing operations regarding the data subject’s personal data comply with the Info Act, the General Data Protection Regulation, and the data controller’s “Privacy Policy”.
The data controller’s notifications comply with the Info Act, the General Data Protection Regulation, and the data controller’s “Privacy Policy”, and the information and consent forms are annexes to the data controller’s “Privacy Policy”.
In order to ensure the right of access, the data subject may request information about their personal data and its processing from the data controller. Requests can be sent via post (2141 Csömör, Csalogány u. 31.) or electronically (info@photom.hu). In case of an electronic request, the data subject should indicate their preferred method of receiving the response (by post or electronically). The data controller will respond to the request within 25 days of receipt.
To ensure the right of rectification, the data subject may request that the data controller correct the personal data it processes. Requests can be sent via post (2141 Csömör, Csalogány u. 31.) or electronically (info@photom.hu). In case of an electronic request, the data subject should indicate their preferred method of receiving the response (by post or electronically). The data controller will respond to the request within 25 days of receipt.
To ensure the right to restrict processing, the data controller will examine the request regarding data processing restrictions. Requests can be sent via post (2141 Csömör, Csalogány u. 31.) or electronically (mariann@photom.hu). In case of an electronic request, the data subject should indicate their preferred method of receiving the response (by post or electronically). Data processing restrictions may occur in the following cases:
- If the data subject disputes the accuracy, correctness, or completeness of the personal data processed by the data controller or by the data processor acting on its behalf or instruction, or if the accuracy is in doubt, during the period needed to resolve the doubt,
- If, according to applicable law, the data should be deleted, but the data subject reasonably assumes that deleting the data would violate their legitimate interests,
- If, according to applicable law, the data should be deleted, but the data controller or other public authority must retain the data for legal proceedings (e.g., criminal investigation) until the completion of the investigation or procedure.
The data controller will notify the data subject of any restrictions on data processing. The data controller will respond to the request within 25 days of receipt.
To ensure the right to erasure, the data controller will examine requests related to the deletion of personal data. Requests can be sent via post (2141 Csömör, Csalogány u. 31.) or electronically (info@photom.hu). In case of an electronic request, the data subject should indicate their preferred method of receiving the response (by post or electronically). Personal data may be deleted in the following cases:
Info Act:
- If the data processing is unlawful,
- If the data subject withdraws consent for data processing or requests deletion of personal data, except where data processing is required by law.
GDPR:
- If the personal data is no longer necessary for the purpose it was collected or processed,
- If the data subject withdraws consent for processing based on Article 6(1)(a) or Article 9(2)(a), and no other legal basis exists for processing.
The withdrawal of consent may be done through unsubscribing. After examining the request, the data controller will delete the data. If the request for correction, deletion, or restriction of personal data is rejected by the data controller or the data processor, the data subject will be informed about their right to contact the supervisory authority.
The data controller will also inform third-party controllers and processors about the correction, deletion, or restriction of data processing.
For the right to data portability, the data subject will receive their personal data in an Excel file. Requests can be made electronically (info@photom.hu), and the data controller will respond within 25 days of receipt.
The right to object is not applicable in this case, as the data processing does not concern public interest or the legitimate interests of the data controller or a third party.
Data Security Measures:
The data controller protects personal data in accordance with the Info Act and GDPR as defined in the “Privacy Policy”.
Data Transfer or Intended Transfer:
EV is required to provide data upon authority and national security requests according to applicable laws and the Data Protection Policy. No other data transfers are carried out. No data is transferred to third-country recipients or international organizations.
Automated Decision-Making, Information Society Services for Children, Special Data:
EV does not use automated decision-making, including profiling, in its data processing.
EV does not provide information society services to children, so personal data provided under this notice can only be provided by persons over the age of 16.
EV does not process special data.
Authority Complaints, Remedies:
The detailed rules are found in Section 22 of the Info Act.
Supervisory Authority:
National Authority for Data Protection and Freedom of Information
Address: 1055 Budapest, Falk Miksa u. 9-11.
Postal address: 1374 Budapest, P.O. Box 603.
Email: ugyfelszolgalat@naih.hu
Phone: +36 (1) 391-1400
Fax: +36 (1) 391-1410
Website: https://naih.hu
Definitions:
Data Subject: Any natural person who can be identified or identifiable based on any information.
Identifiable Natural Person: A natural person who can be identified directly or indirectly, in particular by means of an identifier such as a name, identification number, location data, online identifier, or factors related to the natural person’s physical, physiological, genetic, mental, economic, cultural, or social identity.
Personal Data: Any information related to the data subject.
Data Controller: A natural or legal person, or a non-legal entity who alone or jointly determines the purposes and means of data processing, decides and carries out the data processing, or has it carried out by a data processor.
Data Processor: A natural or legal person, or non-legal entity who processes personal data on behalf of the data controller.
Recipient: A natural or legal person, or non-legal entity to whom personal data is disclosed by the data controller or the data processor (Info Act). Any natural or legal person, public authority, agency, or any other body that the data is disclosed to, regardless of whether they are a third party. Public authorities with access to personal data within the scope of specific investigations under EU or national law are not considered recipients.
The website uses cookies. You can view the list of cookies here.