1.1 Preamble
The scope of the Data Privacy Statement (notice) extends to the system accessible at the domain addresses listed in the footer, as well as the applications and networks connected to it. This current Document is placed in the footer of the website, available in multiple languages, effective from the given date and valid until revoked. By using the Website, and especially when placing an order, and by explicitly indicating this in the respective field, the User accepts that all regulations related to the use of the Website automatically apply to them.
If the User accesses the Website operated by the Company, or uses a related application, reads its content in any way, they acknowledge the provisions of the Document as binding. The Operator is entitled to unilaterally modify the content of the Document, which will not be retroactive.
1.2 Data Controllers, Operators
1.2.1 Hungarian Toll Stickers
The sale of road toll entitlements (toll stickers) for the toll road networks located in Hungary is carried out in this system by Enternova Kft. (Company). Consequently, everything related to the sale of toll stickers for the Hungarian road network should be associated with the responsibility and authority of Enternova Kft. as outlined in the relevant points of this document (General Terms and Conditions, Business Regulations). The usage fees for the Hungarian road network should be managed distinctly from services related to non-Hungarian toll road networks, regardless of whether these separate services are available through the same system here.
- Enternova Kft. cannot be held responsible in the event of a legal dispute arising from the sale of non-Hungarian toll stickers.
- Enternova Kft. disclaims any liability arising from the sale of non-Hungarian toll stickers.
The details of Enternova Kft.:
- 2116 Zsámbok Hunyadi utca 1.
- Tax number: 24892955-2-13
- Company registration number: 13 09 186967
Enternova Kft. can be contacted through the support ticket system available from the contact menu and the footer. When a given support ticket is opened, if its content falls within the competence of Enternova Kft., it will be automatically directed for processing.
1.2.2 Non-Hungarian Toll Stickers
The sale of road toll entitlements (toll stickers) for the toll road networks not located in Hungary is carried out in this system by Network Line Ltd. (Company). Consequently, everything related to the sale of toll stickers for non-Hungarian road networks should be associated with the responsibility and authority of Network Line Ltd. as outlined in the relevant points of this document (General Terms and Conditions, Business Regulations). Usage fees for non-Hungarian road networks should be managed distinctly from services related to the Hungarian toll road network, regardless of whether these separate services are available through the same system here.
- Network Line Ltd. cannot be held responsible in the event of a legal dispute arising from the sale of Hungarian toll stickers.
- Network Line Ltd. disclaims any liability arising from the sale of Hungarian toll stickers.
The details of Network Line Ltd.:
- Hova Villas 1
- BN3 3DH
- Brighton & Hove
- Tax number: 22013 28802
Network Line Ltd. can be contacted through the support ticket system available from the contact menu and the footer. When a given support ticket is opened, if its content falls within the competence of Network Line Ltd., it will be automatically directed for processing.
1.2.4 Additional Data Controllers
Stripe Payment Processor
Cloudflare CDN Network
Kboss.hu Billing
SMS Processor
Google
APP Store IOS
1.3 Definitions
- Website: the system accessible at the domain addresses placed in the footer and through associated applications.
- GDPR (General Data Protection Regulation): the new Data Protection Regulation of the European Union.
- Data Processing: any operation or set of operations performed on personal data or on sets of data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- Data Controller, Processor: the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller and determines the purposes and means of the processing of personal data, either independently or together with others. Where the purposes and means of processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be determined by Union or Member State law.
- Operators, Companies: the operators, owners of the Website.
- Personal Data: any information relating to an identified or identifiable natural person (data subject). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- Consent of the data subject: any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
- Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
- Third Party: a natural or legal person, public authority, agency, or body other than the data subject, controller, processor, and persons who, under the direct authority of the controller or processor, are authorized to process personal data.
- User: visitors, users, customers (data subjects) of the Website.
1.4 Principles of Data Processing and Handling
The Data Controller declares that it processes personal data in accordance with this privacy notice and complies with legal requirements, particularly regarding the following:
- Personal data must be processed lawfully, fairly, and in a transparent manner in relation to the data subject User.
- The collection of personal data must be for specified, explicit, and legitimate purposes.
- The purpose of processing personal data must be adequate, relevant, and limited to what is necessary.
- Personal data must be accurate and up to date. Inaccurate personal data must be erased promptly.
- Personal data should be stored in a way that allows identification of the data subjects only as long as necessary. Longer storage of personal data is only permissible if done for public interest archiving or statistical purposes.
- Personal data must be processed in such a way that ensures appropriate security, including protection against unauthorized or unlawful processing, accidental loss, destruction, or damage by applying appropriate technical or organizational measures.
- The principles of data protection must be applied to all information relating to an identified or identifiable natural person.
1.5 Processed Data and Their Legal Basis
The legal basis for data processing is the consent of the data subject and is also based on the following legal regulation.
EU regulations on certain aspects of electronic commerce services and services related to the information society provide further information.
During the visit of the Website, certain parameters of visitors are automatically recorded.
These logging parameters may include the following for a particular User, depending on what the Website's code can identify:
- The entry time of visits, the time spent on the website, the activities performed during the time, and the exit time.
- Type of the visitor's browser, resolution, language, operating system, type of computer device.
- Visitor's IP address.
The purpose of processing these data is quality assurance as well as website statistics. The duration of this data processing is 5 years unless the User specifies otherwise.
1.6 Processed Data on the Website
The scope of processed data includes the name given by the User, email address, phone number, billing name, billing address, tax number, vehicle registration number, country of origin (nationality). In the case of insurance matters, any additional personal data indispensable for the conclusion of the particular insurance. These processed data are processed based on the Privacy Policy of the given (Third Party) insurance companies.
The purpose of data processing is for the full use of the Website, to create a sales-directed contract, define its content, monitor its performance, invoice fees arising from it, and enforce claims related to it.
With the specific consent of the User, the Website may process certain personal data for purposes such as newsletters or other direct marketing communications.
1.6.1 Duration of Data Processing, Deadline for Data Erasure
Upon request from the data subject, the processed data should be deleted within 48 hours based on point 1.7, otherwise point 1.5 applies. In the case of accounting documents, they must be retained according to the provisions of the accounting law, which also qualifies as the mandatory retention period for the data contained therein.
1.7 Important Data Processing Information, Request for Data Deletion
The duration of data processing always depends on the specific User purpose. The User, as the data subject, can object to the processing of their personal data. The User can also request deletion of data earlier if they can prove entitlement to such deletion. Submission of a request for data deletion may be done in writing through the Website's support ticket system. The Data Controller may request additional identifying data if it is unclear that the person requesting data deletion is indeed entitled to do so.
1.8 Newsletter, DM Activities
The Operator declares that they fully comply with the relevant legal provisions based on the published information and descriptions. According to the law on fundamental conditions and certain limitations of economic advertising activities, the User can give prior and express consent for the Operator to contact them with advertising offers or other communications based on the provided contact details and handle their personal data for the purpose of sending advertising offers. The scope of processed data: personal name, email address, phone number, date.
The legal basis for data processing: The User can unsubscribe from receiving offers without restriction or justification. Unsubscription from the newsletter can be done via the "unsubscribe" link placed at the bottom of the sent newsletters, which can last until a subsequent subscription.
The advertiser, advertising service provider, or the party disseminating the advertisement keeps records of the personal data of individuals who have provided their consent within the scope specified in the consent declaration. The data recorded in this register pertaining to the recipient of the advertisement may only be processed in accordance with the contents of the consent declaration until withdrawal.
1.9 Rights Related to Data Processing
The data subject can request information from the data controller about the processing of their personal data, request the correction, deletion, or blocking of their personal data. If the User has any questions regarding the data processed, or requests information about their data, they can do so through the Website's support ticket system. The legal basis for data transfer is the User's consent, as well as the regulations of the European Union regarding certain aspects of electronic commerce services and services related to the information society.
The data controller is obligated to design and execute data processing operations in a way that ensures the protection of the privacy of the data subjects. The data controller, or within its scope of activity, the processor, is obligated to ensure data security and take technical and organizational measures, and establish procedural rules necessary to enforce the relevant regulations and other data and privacy protection rules.
Data must be protected by appropriate measures against unauthorized access, modification, transmission, public disclosure, deletion, or destruction, as well as accidental destruction or damage, and against becoming inaccessible due to changes in the applied technology. To ensure the protection of data managed electronically within various records, appropriate technical solutions must be applied to ensure that the data stored in the records are not directly linkable and attributable to the data subject unless otherwise prescribed by law.
During the automated processing of personal data, the data controller and processor ensure with further measures:
- Prevention of unauthorized data input.
- Prevention of use of automated data processing systems by unauthorized persons with the aid of data transmission equipment.
- Monitorability and determinability of to which bodies personal data were or may be transmitted by means of data transmission equipment.
- Monitorability and determinability of what personal data were entered, when, and by whom into the automated data processing systems.
- Restorability of installed systems in case of malfunction and that reports are made of errors occurring during automated processing.
When determining and applying measures serving the security of data, the data controller and processor must consider the level of technical development. Among possible data processing solutions, the one ensuring a higher level of protection of personal data must be chosen unless it would result in disproportionate hardship for the data controller.
The data controller maintains several automatic log records to check the legality of data transfers and to inform the data subject, which collectively contain and make tracable the time of transmission of personal data processed by it, the legal basis and recipient of the data transfer, as well as the scope of personal data transmitted, furthermore any other data specified by law prescribing data processing.
If the data controller does not comply with the data subject's request for rectification, blocking, or deletion, it will inform the data subject in writing of the factual or legal reasons for the refusal of the request within 30 days from receipt of the request. In case of refusal of a request for rectification, deletion, or blocking, the data controller informs the data subject about the possibilities for legal remedy.
The data subject is entitled to receive the personal data concerning them, provided by them to the data controller. The data subject is entitled not to be subjected to a decision which is based solely on automated processing, including profiling, which produces legal effects concerning them or significantly affects them in a similar way, except if it is necessary for the conclusion or performance of a contract between the data subject and the data controller, or Union law permits its making, with necessary safeguards in place, or the data subject has given explicit consent.
2.1 Final Provisions
Data provided by the User are stored on servers. Only staff members of the operator have access to the data, and they are all responsible for handling the data securely.
If you discover any errors or omissions in this information, please notify us of this immediately. Our staff will do everything they can to handle even the smallest User or visitor conflict, and if necessary, supplement or modify the current Data Privacy Statement.
2.2 Rights Related to Data Processing
- Right to request information:
You can request information from us through the support ticket system about which data we process, on what legal basis, for what data processing purposes, from what sources, and for how long. Upon your request, we will send you information within a maximum of 30 days, to the email address provided in the request. - Right to rectification:
You can request us through the support ticket system to modify any of your data. We will act on your request and send you information within a maximum of 30 days to the email address provided in the request. - Right to erasure:
You can request the deletion of your data from us through the support ticket system. We will proceed with this upon your request within a maximum of 30 days, and we will send you confirmation to the email address provided in the request. - Right to restriction:
You can request the restriction of processing of your data from us through the support ticket system. Restriction will last as long as the reason specified by you necessitates the storage of the data. We will proceed with this upon your request within a maximum of 30 days, and we will send you confirmation to the email address provided in the request. - Right to object:
You can object to data processing through the support ticket system. We will examine the objection within a maximum of 15 days from submission of the request, make a decision on its merit, and we will inform you about the decision by email. - Possibility for enforcement of data processing rights:
If you experience unlawful data processing, notify us through the support ticket system so we have the opportunity to restore lawful conditions in a short time. In your interest, we will do everything to resolve the problem.
If in your opinion lawful conditions cannot be restored or the restoration does not meet your expectations, you can seek legal remedy for your complaint through the following link:
Legal regulations underlying data processing:
- Regulation (EU) 2016/679 of the European Parliament and of the Council (April 27, 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
- Act CXII of 2011 on the Right to Informational Self-Determination and on Freedom of Information.
- Act LXVI of 1995 on the Protection of Public Documents, Public Archives, and Private Archival Materials.
- Decree 335/2005 (XII. 29.) of the Government on General Requirements for Document Management by Public Bodies.
- Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Services Related to the Information Society.
- Act C of 2003 on Electronic Communications.
- The service provider aims to fully comply with legal requirements for the processing of personal data, especially the regulations outlined in Regulation (EU) 2016/679 of the European Parliament and of the Council.
This Data Privacy Statement is prepared based on Regulation (EU) 2016/679 of the European Parliament and of the Council regarding the protection of natural persons with regard to the processing of personal data and on the free movement of such data, observing Act CXII of 2011, which addresses the right to informational self-determination and freedom of information.
Data protection issues, submissions of requests can occur through the support ticket system found in the website's contact menu and footer.
evignet24.com I evignet24.eu
12/12/2024