PRIVACY NOTICE
Introduction
Kinoki Kft. (registered office: 1141 Budapest, Tihamér utca 38-40. Fsz. 6.; Company Registration Number: 01-09-419826), as data controller (the "Company" or "Data Controller"), in the course of its operations, provides services to the persons ordering such services, and processes the personal data of the data subjects involved in the provision of the services in accordance with this Privacy Notice.
The Company intends to fully comply with the statutory requirements governing the processing of personal data, in particular the provisions of Act CXII of 2011 on Informational Self-Determination and Freedom of Information (the "Info Act") and Regulation (EU) 2016/679 of the European Parliament and of the Council (the "Regulation" or "GDPR"), and therefore wishes to ensure the exercise of the right to transparent information as required by Article 12 of the GDPR by means of this Notice.
This Privacy Notice has been prepared on the basis of the Regulation and with regard to the Info Act.
Name and contact details of the Data Controller:
Name: KINOKI KFT.
Registered office: 1141 Budapest, Tihamér utca 38-40. Fsz. 6. ajtó
Company Registration Number: 01-09-419826
Tax number: 32355756-2-42
Service website: www.justalayout.com
Mailing address: 1141 Budapest, Tihamér utca 38-40. Fsz. 6. ajtó
E-mail: info@justalayout.com
Represented by: Radnóthy Szabolcs, sole managing director
1. Definitions
GDPR: (see above)
data processing: any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
data processor: a service provider engaged by the Company, being a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
personal data: any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
controller: a natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
data transfer: making data accessible to a third party as defined in this Notice;
data subject's consent: any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
data subject: a natural person whose personal data are processed;
personal data breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;
recipient: a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. Public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;
third party: a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data;
erasure of data: rendering data unrecognisable in such a manner that its restoration is no longer possible;
restriction of processing: the marking of stored personal data with the aim of limiting their processing in the future, either permanently or for a defined period;
flagging of data: marking data with an identifier for the purpose of distinguishing it;
destruction of data: the complete physical destruction of the data carrier containing the data.
2. General Principles of Data Processing
The Data Controller declares that it processes personal data in accordance with the provisions of this Privacy Notice and complies with the requirements of the GDPR, the Info Act and all other applicable legislation, with particular attention to the content of this section:
Personal data must be processed lawfully, fairly and in a transparent manner in relation to the data subject.
Personal data may only be collected for specified, explicit and legitimate purposes that have been communicated in advance.
The purpose of processing personal data shall be adequate and relevant, and processing may only take place to the extent necessary.
Personal data must be accurate and kept up to date. Inaccurate personal data must be erased without delay.
Personal data must be stored in a manner that permits identification of data subjects only for as long as is necessary for the purpose of the data processing.
Further processing of personal data beyond the purposes set out in this Notice shall be lawful where the processing is necessary for compliance with a legal obligation, for purposes in the public interest, for scientific research or statistical purposes, or for the establishment, exercise or defence of legal claims.
Personal data must be processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures.
The principles of data protection shall apply to any information concerning an identified or identifiable natural person.
3. Key Information on Data Processing
Personal data shall be processed exclusively for the purpose of exercising a right or fulfilling an obligation under the GDPR and the Info Act, in compliance with the principle of purpose limitation, for a predetermined purpose, to the extent and for the duration necessary to achieve that purpose. Processing must comply with its purpose at every stage — and where the purpose of processing has ceased or the processing is otherwise unlawful, the data shall be erased by the Company.
Prior to the commencement of processing, the Company shall inform the data subject of the purposes, legal basis, categories of data processed and any other relevant information through this Notice.
The purposes, legal bases, data subjects and retention periods for each of the Company's processing activities are set out separately under each activity. The rights of data subjects are detailed in Section 11 below, as they are identical for all processing activities.
Where processing is based on the data subject's consent, the data subject may withdraw their previously given consent in writing at any time — including by sending an e-mail to the contact address provided. Upon withdrawal of consent, the data processed on that basis shall be erased.
The persons authorised to access data are the Data Controller and its data processors and their employees.
The data subject ordering the service may request information from the Data Controller about the processing of their personal data, and may request access to, rectification of, or — where processing is based on consent — erasure or restriction of their personal data, may object to the processing of such data, and may exercise the right to data portability.
The data subject may withdraw their consent to data processing at any time; however, this shall not affect the lawfulness of processing carried out on the basis of consent prior to its withdrawal.
Where processing is based on consent, the data subject is entitled to request that the Data Controller erase inaccurate personal data relating to them without undue delay; and the Data Controller is obliged to erase personal data relating to the data subject without undue delay where the legal basis for processing has ceased.
Modification or erasure of personal data may be initiated and effectively carried out only in writing. Written declarations may be made in traditional paper-based form or via the e-mail address indicated in Section 1 of this Notice.
It is important to note that the withdrawal of consent-based processing authorisation by the data subject does not terminate the data subject's contract with the Company, and therefore the withdrawal does not affect the data subject's payment obligations towards the Company. Non-payment in itself constitutes a ground for processing the data subject's data, as it occurs in connection with payment arrears owed to the Company. The commencement of processing is conditional upon the placement of an order.
4. Service Orders
Persons ordering services from the Company may place orders online through the service website, without prior registration. The performance of the service commences on the basis of a contract concluded electronically between the Company and the data subject.
The Data Controller processes the following data of data subjects as set out below:
Purpose: Provision of services by the Company, exercise of rights and fulfilment of obligations arising from or under the contract, enforcement of the Company's legitimate interests, prevention, investigation and disclosure of abuse
Categories of data processed: Name, e-mail address, phone number, home address, billing data
Legal basis: Article 6(1)(a) and (b) GDPR — consent of the data subject and performance of a contract to which the data subject is party
Data subjects: Data subjects in a contractual relationship
Retention period: 5 years from the fulfilment of the order
Data Controller: The Company
Data transfer: To data processors in a contractual relationship with the Company and to persons entitled to independent processing pursuant to applicable law
Persons authorised to access data: The Data Controller and its employees or agents; the data processor and its employees
Method of storage: Electronic
Profiling: None
Automated decision-making: None
Any data and content made available by the data subject in connection with the performance of the service shall be stored on a server operated by the Company for a period of 5 years following the final performance of the service.
5. Personal Contact
The Data Controller processes the following data of persons who have placed orders for the purpose of maintaining personal contact:
Purpose: Identification, contact.
Categories of data processed: Name, phone number, e-mail address, home address
Legal basis: Article 6(1)(a) and (b) GDPR — consent of the data subject and performance of a contract to which the data subject is party, as well as compliance with the obligation to provide information to the data subject
Data subjects: Data subjects in a contractual relationship
Data Controller: The Company
Persons authorised to access data: The Data Controller and its employees or agents; the data processor and its employees
Retention period: Until the end of the service
Method of storage: Electronic
Profiling: None
Automated decision-making: None
Any data and content made available by the data subject in connection with the performance of the service shall be stored on a server operated by the Company for a period of 5 years following the performance of the contract.
6. Invoicing and Accounting
The Data Controller is obliged to issue invoices to service recipients in connection with the services it provides, and is therefore required to engage the cooperation of the National Tax and Customs Administration (NAV) (registered office: 1054 Budapest, Széchenyi u. 2.), which operates the invoicing software, Gestio Bt. (registered office: 1033 Budapest, Miklós utca 13. II. em. 7.), which handles the Company's accounting, and OTP Bank Nyrt., which manages banking transactions, all of which qualify as independent data controllers in their own right.
Method of storage of billing data: Electronic
The Data Controller processes the following personal data of the data subject for invoicing purposes:
-
name;
-
home address;
-
amount of receivables;
-
consideration for the service.
Purpose: Fulfilment of the statutory condition for enforcing claims arising from the contract
Categories of data processed: Name, home address
Legal basis: Article 6(1)(c) GDPR — compliance with a legal obligation incumbent on the controller, and Article 6(1)(f) GDPR — purposes of the legitimate interests pursued by the controller
Data subjects: Data subjects in a contractual relationship
Retention period: Until the end of the 8th year following the date of issue of the invoice
Data Controller: The Company
Data processors: OTP Bank Nyrt.
Data transfer: To OTP Bank Nyrt.
Persons authorised to access data: The Data Controller and its employees or agents
Method of storage: Paper-based and electronic
Profiling: None
Automated decision-making: None
In the event of non-performance of the contract, any data and content made available by the data subject in connection with the performance of the service shall be stored on a server operated by the Company for a period of 60 months from the termination of the contract, for the purpose of enforcing claims arising from the contract.
7. Social Media
A social media platform is a media tool through which messages are disseminated via community users. Social media uses the internet and online publishing opportunities to transform users from content consumers into content editors. Social media is a type of internet application containing user-generated content, such as Facebook, Google+, Twitter, etc. Forms of social media presence may include public speeches, presentations, demonstrations, and descriptions of products or services.
The categories of personal data appearing on social media are as follows:
-
forums,
-
blog posts,
-
images, videos and audio content,
-
message walls,
-
e-mail messages,
-
the user's public profile picture.
Purpose: Promotion of the Company and its operated website
Legal basis: Voluntary consent of the data subject ordering the service
Data subjects: Data subjects who specifically follow the relevant social media page
Retention period: In accordance with the rules applicable on the relevant social media platform
Information regarding erasure: Following a request for erasure or withdrawal of consent, the Company shall remove the relevant data to the extent possible.
Data Controller: The Company
Persons authorised to access data: In accordance with the rules applicable on the relevant social media platform
Method of storage: Electronic
Data transfer: To the company operating the relevant social media platform
Profiling: None
Automated decision-making: None
It is important to note that when a user uploads or submits personal data, they grant the operator of the social media platform a worldwide licence to store and use such content. It is therefore very important to ensure that the user has full authority to disclose the information published.
8. Cookies
8.1. General Information on Cookies
Cookies are small text files placed on the user’s device by the website during a visit. They improve the user experience by saving browsing data, allowing the website to remember settings and offer locally relevant content.
Cookies used on our website fall into two main categories: (1) technically necessary cookies, which are essential for the operation of the website, and (2) non-essential (analytical, marketing) cookies, the use of which requires the prior, informed and unambiguous consent of the data subject under the GDPR and Act C of 2003 on Electronic Communications (the “Eht.”).
8.2. Categories of Cookies Used
a) Technically Necessary Cookies
These cookies are essential for the basic functioning of the website (e.g. session management, security features, storage of cookie consent decisions). They do not require the prior consent of the data subject, pursuant to Section 155(4) of the Eht.
b) Analytical Cookies (Google Analytics)
Our website uses Google Analytics, a service provided by Google LLC (“Google”), which collects data on website usage via cookies. Analytical cookies are not necessary for the operation of the website; therefore, their placement requires the prior consent of the data subject pursuant to Article 6(1)(a) GDPR.
The principal cookies used by Google Analytics:
– _ga: used to distinguish users; expiry: 2 years
– _gid: used to distinguish users; expiry: 24 hours
– _gat: used to throttle request rate; expiry: 1 minute
Details of data processing in connection with analytical cookies:
Purpose: Collection of statistical data on the behaviour of website visitors for the purpose of improving the website
Legal basis: Article 6(1)(a) GDPR – consent of the data subject
Data subjects: Visitors to the website
Categories of data processed: IP address (anonymised), browsing behaviour, session data, device type
Retention period: Until withdrawal of consent, but no longer than 2 years
Data Controllers: The Company and Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA), each acting as independent data controllers
Transfer to third country: Data are transferred to Google LLC’s servers in the United States. The legal basis for this transfer is the Standard Contractual Clauses (SCCs) pursuant to Article 46(2)(c) GDPR. Google’s privacy framework notice is available at: https://policies.google.com/privacy
Profiling: None
Automated decision-making: None
8.3. Consent and Withdrawal
Non-essential cookies are only placed on the basis of the data subject’s prior, unambiguous and informed consent. Consent is obtained via a cookie banner displayed on the first visit to the website, where the data subject may accept or reject each category of cookies separately. The consent decision is recorded at storage level.
The data subject may withdraw their consent at any time by: (i) deleting and/or blocking cookies in their browser settings; (ii) installing the Google Analytics Opt-out Browser Add-on (available at: https://tools.google.com/dlpage/gaoptout); or (iii) modifying the cookie settings on the website. Withdrawal does not affect the lawfulness of processing carried out on the basis of consent prior to withdrawal.
9. Data Processors
Payment service providers:
Company name: OTP Bank Nyrt.
Registered office: 1055 Budapest, Bajcsy-Zsilinszky út 74
Phone: +36 1 366 6666
E-mail: informacio@otpbank.hu
Payment transactions carried out by the data subject are processed through payment systems provided by the payment service providers listed in this section, in relation to the Company's payment accounts. Data may only be accessed by employees of the Data Controller and — in accordance with their own privacy notices — by employees of the payment service providers, all of whom are responsible for the secure handling of data.
Purpose: Provision of financial transaction services for the Data Controller's operations
Legal basis: Article 6(1)(c) GDPR — compliance with a legal obligation
Data subjects: Data subjects in a contractual relationship
Categories of data: The data subject's name, account-keeping bank, bank account number and the amount paid
Data Controller: The Company
Persons authorised to access data: The Company and its employees or agents, and the payment service provider and its employees
Retention period and erasure: Until the end of the Company's operations. Data are erased by the payment service provider after 10 years.
Method of storage: Electronic
Data transfer: None
Profiling: None
Automated decision-making: None
Invoicing:
Company name: KBOSS.hu Kft.
Registered office: 1031 Budapest, Záhony utca 7.
Phone: +36 30 35 44 789
E-mail: info@szamlazz.hu
The data subject is able to fulfil their payment obligation to the Company on the basis of the accounting document issued by the invoicing service provider. Data may only be accessed by employees of the Data Controller and — in accordance with their own privacy notices — by employees of the service provider, all of whom are responsible for the secure handling of data.
Purpose: Compliance with accounting regulations and fulfilment of tax obligations
Legal basis: Article 6(1)(c) GDPR — compliance with a legal obligation
Data subjects: Data subjects in a contractual relationship
Categories of data: The data subject's name, home address and the amount payable
Data Controller: The Company
Data transfer: None
Persons authorised to access data: The Company and its employees or agents
Retention period and erasure: Data are erased by the invoicing service provider after 8 years.
Method of storage: Electronic
Profiling: None
Automated decision-making: None
Accounting:
Company name: Kilenced Könyvelő Kft.
Registered office: 1033 Budapest, Miklós utca 13. II. em. 7.
Phone: +36 30 962 3389
E-mail: lenger.csaba@gestio.axelero.net
The Company fulfils its filing and tax payment obligations in respect of accounting documents completed by the data subject by submitting the returns prepared by the accounting service provider to the tax authority and meeting its tax payment obligations on the basis of such returns. Data may only be accessed by employees of the Data Controller and — in accordance with their own privacy notices — by employees of the service provider, all of whom are responsible for the secure handling of data.
Purpose: Compliance with accounting regulations and fulfilment of tax obligations
Legal basis: Compliance with a statutory obligation
Data subjects: Data subjects in a contractual relationship
Categories of data: The data subject's name, home address, amount payable, account-keeping bank and bank account number
Data Controller: The Company
Data transfer: None
Persons authorised to access data: The Company and its employees or agents
Retention period and erasure: Data are erased by the accounting service provider after 8 years.
Method of storage: Electronic
Profiling: None
Automated decision-making: None
10. Rights in Connection with Data Processing
Right to Information
The data subject may request information from the Data Controller through the contact details provided, regarding the data processed by the Data Controller or by a data processor acting on its behalf, including what data are processed, on what legal basis, for what purpose, from what source, for how long, as well as the name and address of the data processor and its activities related to processing, the circumstances and effects of any personal data breach and the measures taken to remedy it, and — in the case of data transfer — the legal basis for and recipient of the transfer. Upon the data subject's request, the Data Controller shall provide information without undue delay, and in any event within 30 days, to the e-mail address provided by the data subject.
Information is provided free of charge once per calendar year; for additional requests, a fee may be charged. Any fee already paid shall be refunded if the processing is found to be unlawful or if the data need to be rectified due to a fault attributable to the Data Controller.
Right to Rectification
The data subject may request through the contact details provided that the Data Controller modify any of their data. The Data Controller shall act on such a request without undue delay, and in any event within 30 days, and shall send a notification to the e-mail address provided by the data subject.
Right to Erasure
The data subject may request through the contact details provided that the Company erase their data. The Company shall comply with such a request without undue delay, and in any event within 30 days, and shall send a notification to the e-mail address provided by the data subject.
Personal data may be erased if:
-
the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
-
the data subject withdraws consent on which the processing is based and there is no other legal ground for the processing;
-
the data subject objects to the processing and there are no overriding legitimate grounds for the processing;
-
the personal data have been unlawfully processed;
-
the personal data must be erased for compliance with a legal obligation under Union or Member State law to which the controller is subject;
-
the personal data were collected in relation to the offer of information society services to children under the age of 16;
-
where the controller has made personal data public and they are no longer necessary for the purposes for which they were collected, the controller shall erase them and, taking account of available technology and the cost of implementation, shall take reasonable steps — including technical measures — to inform controllers which are processing the personal data that the data subject has requested the erasure of any links to, or copies or replications of, those personal data.
Right to Restriction of Processing
The data subject may request through the contact details provided that the Company restrict the processing of their data. Restriction shall remain in place for as long as the reason indicated by the data subject necessitates the retention of the data. The Company shall comply with such a request without undue delay, and in any event within 30 days, and shall send a notification to the e-mail address provided by the data subject.
Right to Object
The data subject may object to the processing through the contact details provided. The Company shall examine the objection within the shortest possible time from the date of submission, and in any event within 15 days, shall make a decision on its merits, and shall notify the data subject of its decision by e-mail.
An objection to personal data processing may be raised where:
the processing or transfer of personal data is carried out solely for the purpose of fulfilling a legal obligation applicable to the Data Controller, or for the purposes of the legitimate interests pursued by the Data Controller, the data recipient or a third party, unless the processing is mandatory;
the use or transfer of personal data is for the purpose of direct marketing, public opinion polling or scientific research; and
in other cases provided for by law.
If the objection is found to be well-founded, the Data Controller shall cease the processing and restrict the data, and shall notify all those to whom the personal data subject to the objection were previously transferred, who are also obliged to take measures to enforce the right to object.
Legal Remedies and Complaints Regarding Data Processing
In the event of unlawful data processing detected by the data subject, please notify the Company so that the lawful situation may be restored within a short period of time. The Company shall do everything in its power to resolve the issue in the interest of the data subject.
If the data subject considers that the lawful situation cannot be restored, they may notify the competent authority at the following contact details:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Postal address: 1530 Budapest, Pf.: 5.
Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
Phone: +36 (1) 391-1400
Fax: +36 (1) 391-1410
E-mail: ugyfelszolgalat@naih.hu
URL: https://naih.hu
11. Legal Basis for Data Processing
-
REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
-
Act CXII of 2011 on Informational Self-Determination and Freedom of Information
-
Act LXVI of 1995 on Public Records, Public Archives and the Protection of Private Archival Material
-
Government Decree No. 335/2005 (XII. 29.) on the General Requirements for the Records Management of Bodies Performing Public Duties
-
Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services
-
Act C of 2003 on Electronic Communications
12. Miscellaneous Provisions
With regard to the data transferred within the scope defined in this Privacy Notice, data processors shall be independently liable for personal data processing carried out by them on behalf of the Company.
This Privacy Notice is effective from 1 June 2026 until revoked.
The Data Controller reserves the right to amend this Privacy Notice unilaterally at any time, with prior notice to data subjects. Data subjects shall be informed through a notice published on the website at least eight calendar days prior to any amendment.