data protection manual
INTRODUCTION
Ördögbot Bt. (founded 2004, Represents: János Batinkov) issues the following
manual.
According to the European Union and the European Councildirective 2016/679 directive
(27April 2016), concerning the protection and free movement of natural persons as well
as the repealed directive 95/46/EK, the following is disclosed.
This data handling manual regulates the following sites:
The manual is available on the following link: link
The modifications of the manual will take effect on publication of the site under the link
above.
DATA CONTROLLER AND CONTACT DETAILS:
Name: Ördögbot Bt..
Place of business:Hungary,6500 Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
Tax Number:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-113401
RESPONSIBLE FOR DATA CONTROLLING :
Name: Ördögbot Bt..
Place of business:Hungary,6500 Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
Tax Number:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-113401
3 | P a ge
Name: Ördögbot Bt..
Place of business:Hungary,6500 Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
Tax Number:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-1134013
DEFINITIONS
1. “personal data” shall mean any information relating to an identified or identifiable
natural person (“data subject”); an identifiable person is one who can be identified,
directly or indirectly, in particular by reference to an identification number or to one
or more factors specific to his physical, physiological, mental, economic, cultural or
social identity;
2. “processing of personal data” (“processing”) shall mean any operation or set of
operations which is performed upon personal data, whether or not by automatic
means, such as collection, recording, organization, storage, adaptation or alteration,
retrieval, consultation, use, disclosure by transmission, dissemination or otherwise
making available, alignment or combination, blocking, erasure or destruction;
3. “controller” shall mean the natural or legal person, public authority, agency or any
other body which alone or jointly with others determines the purposes and means of
the processing of personal data; where the purposes and means of processing are
determined by national or Community laws or regulations, the controller or the
specific criteria forhisnominationmaybedesignatedbynationalorCommunitylaw;
4. “processor” shallmeananaturalor legalperson,publicauthority,agencyoranyother
body which processes personal data on behalf of the controller;
5. “recipient” shall mean anatural or legal person, public authority, agency or any other
body to whom data are disclosed, whether a third party or not; however, authorities
which may receive data in the framework of a particular inquiry shall not be regarded
as recipients;
6. “the data subject’s consent” shall mean any freely given specific and informed
indication of his wishes by which the data subject signifies his agreement to personal
data relating to him beingprocessed;
7. „personal data breach”: a breach of security leading to the accidental or unlawful
destruction, loss, alteration, unauthorised. disclosure of, or access to, personal
data transmitted, stored or otherwiseprocessed.
Name: Ördögbot Bt..
Place of business:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
Tax Number:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-1134014
PRINCIPLES REGARDING DATA PROCESSING
Personal data shall be:
a) processed lawfully, fairly and in a transparent manner in relation to the data
subject (‘lawfulness, fairness andtransparency’);
b) collectedfor specified, explicit andlegitimatepurposes andnotfurtherprocessed
in a manner that is incompatible with those purposes; further processing for
archivingpurposes inthepublicinterest, scientificorhistorical researchpurposes
or statisticalpurposes shall,inaccordancewithArticle89(1),not be consideredto
be incompatible with the initial purposes (‘purpose limitation’);
c) adequate, relevant and limited to what is necessary in relation to the purposes for
which they are processed (‘dataminimisation’);
d) accurateand,wherenecessary,keptuptodate;every reasonablestepmustbe
taken to ensure that personal data that are inaccurate, having regard to the
purposes for which they are processed, are erased or rectified without delay
(‘accuracy’);
e) kept in a form which permits identification of data subjects for no longer than is
necessary for the purposes for which the personal data are processed; personal
data may be stored for longer periods insofar as the personal data will be
processed solely for archiving purposes in the public interest, scientific or
historical research purposes or statistical purposes in accordance with Article
89(1) subject to implementation of the appropriate technical and organisational
measures required by this Regulation in order to safeguard the rights and
freedoms of the data subject (‘storagelimitation’);
f) processed in a manner that ensures appropriate security of the personal data,
including protection against unauthorised or unlawful processing and against
accidental loss, destruction or damage, using appropriate technical or
organisational measures (‘integrity andconfidentiality’).
The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1
(‘accountability’).
Name: Ördögbot Bt..
Place of business:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
Tax Number:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-1134015
DATA PROCESSING
DATA PROCESSING FOR WEB STORE1. Purpose of data controlling:
Personal data Data processing
Username Identfication, enabling registration.
Password Secure entry to user profile.
Surname and first name Contact, purchase and making a regular
invoice.
E-mail Contact.
Telephone number Contact, more efficient data exchange in
connection with invoicing and delivery.
Invoice name and address Creating regular invoices, and creating
contracts, defining and modifying their
contents, tracking their execution and
invoicing expenses incurring.
Delivery name and address Enabling delivery.
Date and time of purchase/order Executing technical procedure.
IP address at purchase Executing technical procedure.
Username or email address do not need to contain personal data.
2. Data subjects: All data subjects shopping in the web store.
3. Periodofdataprocessing:Immediatelyafter registration.AccordingtoGDPRArt. 19,
the data controller informs the data subject about the erasure of the data,
electronically on any of the contacts having been given by the data subject. If the
erasure apples to email address, it will also be erased.
Name: Ördögbot Bt..
Placeofbusiness:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
TaxNumber:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-1134016
4. Potentialpersons eligible foraccessingdataandtheir addressees:Personal
data can be controlled by sales and marketing employees, respecting the above
principles.
5. Informationconcerning thedata subjects’dataprotection:
Datasubjectanrequirethedatacontrollertobegivenaccesstotheirpersonaldata,
their correction, deletion or limitation of their control, and
can object to controlling such data, as well as
has the right to free movement of data, and to repeal their consent at any time.
6. The data subject can require access, correction, deletion or limitation of their
control, their free movement, repeal against data controlling in the following
way:
Place of business: Hungary, 6500 Baja, Bartsch S. u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
7. Legal base:
7.1. GDPR Art. 6 (1)b),
7.2.In case of regular invoicing Art. 6. (1) c).
8. Informationconcerning thedata subjects’dataprotection:
Datasubjectanrequirethedatacontrollertobegivenaccesstotheirpersonaldata,
their correction, deletion or limitation of their control, and
can object to controlling such data, as well as
has the right to free movement of data, and to repeal their consent at any time.
9. We inform you that data control is subject to yourconsent.
you must give us your personal data if you require a newsletter from us.
failing to provide data might incur us not being able to send you our newsletters.
Name: Ördögbot Bt..
Placeofbusiness:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
TaxNumber:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-1134017
DATA CONTROLLERS:
Delivery
1. Activity executed by data controller: Delivering and transporting goods
2. Name and contact details of data controller:
• Name: Magyar Posta Zrt. Ügyfélszolgálati Igazgatóság
Place of business: 3512 Miskolc
E-mail: idopontegyeztetes@posta.hu
Telephone: 06-46-503-868
3. Data controlled: Addressee’s name, Delivery address, telephone number, e-mail
address.
4. Data subjects: All data subjects requesting home delivery.
5. Purpose of data controlling: Delivering goods ordered.
6. Period of data controlling, deadline of deletion of data: Until delivery has been
executed.
7. Legal basis of data controlling: Art. 6, (1) b).
8 | P a ge
Name: Ördögbot Bt..
Placeofbusiness:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
TaxNumber:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-1134018
Online payment
1. Activity executed by data controller: Online payment
2. Name and contact details of data controller:
Barion Payment Inc.
Budapest
Infopark sétány 1.
H-1117
General support
• +3614647099
Fax
+36 1 464 70 80
E-mail
hello@barion.com
Web
https://www.barion.com/en
3. Data controlled: Addressee’s name, Delivery address, e-mail address.
8. Data subjects: All data subjects using online shopping.
4. Purpose of data controlling: Conducting online payments, acknowledgementof
online payment, fraud-monitoring for the interest of user protection.
5. Periodof data controlling,deadline of deletion of data:Untiltheexecutionofonline
payment.
9. Legal basis of data controlling: Art. 6, (1) c).
9 | P a ge
Name: Ördögbot Bt..
Place of business:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
TaxNumber:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-1134019
Web hosting service provider
1. Activity executed by data controller: Hosting Service
2. Nameandcontactdetailsofdatacontroller:
Siteground
Web: https://siteground.com
Email: info@siteground.com
3. Data controlled: All personal data provided by the data subject.
4. Data subjects: All users using this website.
5. Purpose of data controlling:Publication and appropriate maintenance of website.
6. Periodofdatacontrolling,deadlineofdeletionofdata:Untiltheterminationofthe
agreement between the data controller and the web hosting service provider, or
until the data controller’s cancellation request towards the web hosting service
provider.
10. Legal basis of data controlling: Art. 6, (1) c) and f).
10 | P a ge
Name: Ördögbot Bt..
Placeofbusiness:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
TaxNumber:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-11340110
CONTROLLING COOKIES
1. Cookies of web stores, such as password-protected cookies, cookies needed for
basket and security cookies, which do not necessitate prior consent from the data
subjects.
2. Data controlled:Individual identification number, data, time stamps
3. Data subjects: All data subjects visiting the website.
4. Purpose of data controlling: identification of buyers, register of basket, tracking
visitors,
5. Duration of data handling, deadline for deleting data:
Type of cookie Legal basis Time Data controlled
Session cookies
Until expiration
of the visiting
session.
connect.sid
6. Potential data controllers eligible for access of cookiedata:personal data shallnot be
controlled from data collected bycookies.
7. Informing data subjects about their rights of deleting data: Data subjects have the
possibility of deleting cookies from their browser menu under the settings of Data
control.
8. Legal basis: Consentfrom data subjects is not required provided the only purpose of
the use of cookies is communication or in case the user has specifically requested so.
Name: Ördögbot Bt..
Placeofbusiness:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
TaxNumber:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-11340111
Name: Ördögbot Bt..
Placeofbusiness:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
TaxNumber:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-11340112
GOOGLE ADWORDS CONVERSION TRACKING
1. Data controller uses online advertisement programme called „Google AdWords”
along with its conversion tracking service, Google’s conversion tracker service is a
serviceofGoogleInc.(1600AmphitheatreParkway,MountainView,CA94043,USA;
„Google“).
2. When the User accesses a website via Google advertisement, a cookie is created on
their computer.The validity ofthese cookies is limited,they cannot contain personal
data, based on which the user cannot be identified.
3. When the User browses the various pages of the website and the validity of the
cookies has not expired, Google and the data controller can track that the user has
clicked on then advertisement.
4. Every Google AdWords client receives different cookies so that they cannot be
tracked on the websites of Adwordsclients.
5. The data obtained by the conversion tracker cookies servers the purpose of creating
conversionstatistics for thoseoptingforAdWords conversiontracking.Thisway,the
clients are informed about the number of users having clicked on their
advertisements suppled by conversion tracking. The clients do access information
that they can use to identify any user.
6. If you do not want to participate in the conversion tracking, they can refuse this
servicebyblocking the installationof cookies in theirbrowser.After this, youwillnot
figure in the conversion trackingstatistics.
7. FurtherinformationalongwithGoogle’sdatacontrollingdeclarationcanbeaccessed
on the following link: www.google.de/policies/privacy/
Name: Ördögbot Bt..
Place of business:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
TaxNumber:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-11340113
Name: Ördögbot Bt..
Placeofbusiness:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
TaxNumber:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-11340114
APPLICATION OF GOOGLE ANALYTICS
1. This website uses Google Analytics, which is Google Inc.’s (“Google”) web analytics
service. Google Analytics uses so-called cookies, text files, which are saved onto
computers, thus assisting the analysis of the use of the visited website “cookies”
2. The information createdby the cookies belonging to thewebsiteused by theUser are
usually savedand storedonto one of Google’s servers in theUnitedStates ofAmerica
(USA) By activating IP anonymity Google shortens the User’s IP address within the
member states of the European Union or other countries part of then agreement of
then European EconomicArea.
3. Only in exceptional cases are fullIP addresses forwarded and shortened on Google’s
serversintheUSA.Assignedbythiswebsite,Googlewillusethisinformationtocreate
reports to the owner of the website regarding the activity on the website or to assist
further services in connection with website or internet use.
4. Within Google Analytics the User’s browser does not connect the IP address with
other Google data. The user can block the storage of cookies by setting their browser
appropriately, although we would like to advise you that in that case some functions
of this website may be unavailable. The User can also block Google from collecting
and processing website use data through cooked if then following browser plugin is
downloaded and installed: https://tools.google.com/dlpage/gaoptout?hl=hu
15 | P a ge
Name: Ördögbot Bt..
Place of business:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
TaxNumber:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-11340115
NEWSLETTER, DM ACTIVITY
10. The Client can consent to their data required for sending commercial offers being
controlled, using the principles of the following guide.
11. Theserviceprovidedwillnot sendunsolicitedadvertisementmessages, andtheUser
canunsubscribefrombeingsentofferswithoutlimitationorjustification.Inthiscase,
the service provider deletes all personal data from its register and will not approach
the User with commercial offers. There is a link provided n the message where the
User can unsubscribe fromadvertisements.
12. Purpose of datacontrolling:
Personal Data Purpose of data controlling
Name, email address Identification, enabling subscription to
newsletter.
Date of subscription Executing technical procedure.
IP address at subscription Executing technical procedure.
5. Data subjects: All data subjects subscribed to the newsletter.
6. The purpose of data controlling: sending electronic messages containing
advertisement (e-mail, text message, push message) to data subjects, giving
information about current news, goods, discounts, new functions, etc.
7. Period of data controlling, deadline of deletion of data:the repeal of the declaration
of consent, until unsubscription.
8. Registration number: in progress…
16 | P a ge
Name: Ördögbot Bt..
Placeofbusiness:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
TaxNumber:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-11340116
9. Potential persons eligible for accessing data and their addressees:Personal data can
be controlled by sales and marketing employees, respecting the above principles.
10. Informationconcerning thedata subjects’dataprotection:
• Datasubjectanrequirethedatacontrollertobegivenaccesstotheirpersonaldata,
their correction, deletion or limitation of their control, and
• can object to controlling such data, as well as
• has the right to free movement of data, and to repeal their consent at any time.
11. Thedatasubjectcanrequireaccess, correction,deletionorlimitationoftheircontrol,
their free movement, repeal against data controlling in the following way:
– Place of business: Hungary, 6500 Baja, Bartsch S. u.4
– E-mail: hello@xtremestix.com
– Telephone: +36-20-940-9872 .
12. Data subject can unsubscribe from the newsletter at any time.
13. Legal base: Art. 6 (1) a) and f)
14. We inform you that
• data control is subject to yourconsent.
• you must give us your personal data if you require a newsletter from us.
• failing to provide data might incur us not being able to send you our newsletters.
17 | P a ge
Name: Ördögbot Bt..
Placeofbusiness:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
TaxNumber:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-11340117
COMPLAINS
1. Reasons and purpose of datacollection:
Personal data The purpose of data management
Surname and first name Identification, contact
E-mail Contact.
Telephone number Contact.
Invoicing name and address Identification, handling quality complaints,
questionsandqueriesconcerningthegoods
ordered.
2. Data subjects:All data subjects shopping on the web store and making a complaint.
3. Period of data controlling, deadline of deletion of data: The minutes including the
received complaint, its transcript and the response to it shall be kept
4. Potential persons eligible for accessing data and their addressees: Personal data
canbe controlledby sales andmarketing employees, respecting the aboveprinciples.
5. Informationconcerning thedata subjects’dataprotection:
• Datasubjectanrequirethedatacontrollertobegivenaccesstotheirpersonaldata,
their correction, deletion or limitation of their control, and
• can object to controlling such data, as well as
• has the right to free movement of data, and to repeal their consent at any time.
6. The data subject can require access, correction, deletion or limitation of their
control, their free movement, repeal against data controlling in the following
way:
– bypostonthefollowingaddress: ,
– viae-mailat ,
– by phone on
7. Legal base: Art. 6 (1)c
18 | P a ge
Name: Ördögbot Bt..
Placeofbusiness:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
TaxNumber:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-11340118
5. We inform you that
• provision of personal data is subject to contact obligations
• personal data controlling is a prerequisite of executing a contract
• you must give your personal details so that we can handle your complaint(s)
• failure to comply may resultin us not being able to handle your complaint(s)to
the company
SOCIAL WEBSITES
1. Collection of data: name and profile picture of those registered on
Facebook/Google+/Twitter/Pinterest/Youtube/Instagram
2. Data subjects: All data subject who registered and “liked” websites such as
Facebook/Google+/Twitter/Pinterest/Youtube/Instagram etc.
3. Purpose of data collection: sharing the certain elements of the website, its products,
discounts and the website itself, as well as making it more popular by promoting
“likes”.
4. Period of data controlling, deadline of deletion of data; Potential persons eligible for
accessing data and their addressees;Information concerning the data subjects’ data
protection: The data subject can be informed about the source of data, their
controlling and their handover on the social media websites. Data controlling is
executed on the social website, so the period of data is subject to the social website’s
own regulations.
5. Legal base:the data subject’s voluntary consent to their data being controlled by the
social website.
19 | P a ge
Name: Ördögbot Bt..
Placeofbusiness:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
TaxNumber:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-11340119
CLIENT CONTACTS AND OTHER ISSUES
1. Provided there are questions when using any of our data controlling services, in case
ofproblems,thedatasubject cangetincontactwiththedatacontrolleronthecontact
details (telephone, email, social media) published on the website.
2. At least two 2 years after receiving the data, the data controller deletes all emails,
messages, telephones, data given on Facebook with the user’s name and email
address, along with personal data voluntarily provided.
3. Information is given on data controlling of data not listed in this manual.
4. Upon exceptional request from the authorities, or mandated by legislation, upon
request from other parties, the provider is obliged to provide information,
communicate and hand over the data and make documents available.
5. In this case, the provider will only disclose personal data, in case the client has
specified its exact purpose and type of data, that is essential for the purpose of the
inquiry.
DATA SUBJECTS’ RIGHTS
1. Right of access
The data subject shall are eligible for receiving feedback from the data controller
concerning if the data controlling is still in progress, and if such data controlling is in
progress, the data subject is eligible for gaining access to the personal data and
information listed in the legislation.
2. Right to rectification
The data subject shall have the right that upon request the data controller will rectify the
inexact personal data with regard to your data without delay. Taking the purpose of data
controllingintoconsideration,youhavetherighttorequestamendingyourpersonaldata,
among others, through amendingdeclaration.
3. Right to erasure
The data subject shall have the right that upon request the data controller will erase the
personal data with regard to your data without delay, and the data controller is obliged
to erase the data, without unjustified delay in case of particular conditions.
4. Right to beforgotten
20 | P a ge
Name: Ördögbot Bt..
Placeofbusiness:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
TaxNumber:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-11340120
If the data controller has published the personal data, and they are obliged to erase it,
takingintoaccountthe availabletechnologyandcostsofitsexecution,thedata controller
will take the necessary steps, including technical measures in order to inform the data
controllers in possession of the data that you have requested the aforementioned
personal data or copy or second copy of these personal data to be erased.
5. Right to restriction of processing
The data subject shallhave the right, upon request,to restrictthe processing of data,if one
of the following conditions applies:
• Youcontesttheprecisionofpersonaldata, inthis case the restrictionapplies to the
period of time that allows the data controller to check the precision of data;
• dataprocessingis illegal,andyouobjecttodatabeingerased,instead, requestthat
they be restricted;
• thedatacontrollerdoesnotneedpersonaldatafor thepurposeofdatacontrolling,
however, you request those in order to propose, validate and protect legal
requests;
• youobjectagainstdataprocessing,inthis case,therestrictionapplies totheperiod
oftime untilithasbeenconfirmedthatthe justificationofthedata controllerhave
priorities over your legaljustifications.
6. Right to dataportability
The data subject shall have the right to receive personal data in an articulated, widely
used, computer-readable format, you have further right to forward this data to another
data controller without the original data controller being able to impede it.
7. Right to object
The data subject shall have the right to object to the use of personal data at any time due
to your personal situation, including the rightto objetto a profile being created based on
the aforementioned regulations.
8. Objectioninthe interest of seeking direct business
If the personal data processing takes place in order to have direct business, the data
subject shall have the right to object to your relevant personal data being used for this
purpose, including profiling, provided this is closely related to seeking direct business.If
you object to your personal data being used for the purpose of seeking direct business,
your personal data cannot be processed for this purpose.
9. Automatizedindividualdecision-making,includingprofiling
21 | P a ge
Name: Ördögbot Bt..
Placeofbusiness:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
TaxNumber:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-11340121
The data subject shall have the right not to be subject to a decision based solely on
automated processing, including profiling, which produces legal effects concerning him
or her or similarly significantly affects him or her.
Paragraph 1 shall not apply if the decision:
• is necessary for entering into, or performance of, a contract between the data
subject and a data controller;
• is authorised by Union or Member State law to which the controller is subject and
which also lays down suitable measures to safeguard the data subject’s rights and
freedoms and legitimate interests;or
• is based on the data subject’s explicit consent.
DEALINE OF TAKING ACTION
The data controller informs you about the measures taken based on the above requests
without delay, within one month after the request has been received.
In case of emergency this period can be extended to 2 months. The data controller will
inform you about the extension of the deadline within one month after receipt of the
request.
Ifthedatacontrollerdoesnot acts inyour request, youwillbe informedaboutthe reasons
for failing to take action within a month after submitting your request, including
informationinconnectionwithwhichauthoritiesyoucansubmit your requestandfilefor
redress.
SECURITY OF DATA CONTROLLING
The data controller and the data processor shall take appropriate technical and
organizational measures to take into accountthe current state of science and technology
and the costs ofimplementation,thenature, scope, circumstances and objectives of data
controlling and the risk of varying probability and severity of individuals’ rights and
freedoms to guarantee an adequate level of data security, including, inter alia, where
appropriate::
22 | P a ge
Name: Ördögbot Bt..
Placeofbusiness:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
TaxNumber:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-11340122
a) encrypting personal data;
b) the ensuring, integrity, availability and resistance of systems and services used to
conduct secret handling of personaldata
c) incase of physical or technicalincidentits ability to reset access and availability of
personal data in time;
d) procedure to test, assess and evaluate the technical and organizational measures
taken in order to guarantee the security of data controlling.
Ifthedatabreachincurspotentialhighrisksconcerningindividuals’ rightsandfreedoms,
the data collector informs the data subject about data breach without delay.
Thetypeofdatabreachmustbereportedtothedatasubjectina clearandunderstandable
way, as well,they must be providedwith thename and contact ofthe responsible for data
controlling;thedatasubjectmustbeinformedabouttheexpectedconsequencesresulting
from a data breach, the measures taken by the data controller to rule out data breach,
including measures taken in order to mitigate potentially harmful consequences.
The data subject does not need informing if any of the following conditions
• the data controller has taken appropriate technical and organisational
measures,whichhavebeenappliedtothoseinvolvedindatabreach,particularly
those measures, for instance, application of encryption, which render the data
unintelligible to those not eligible for accessing them.
• thedata controllerhas takenfurthermeasures followingdatabreachthat
ensurethathighriskstothedatasubject’srightsandfreedomdonotoccur
• information would necessitate disproportionate effort. In such cases, the data
subjects shall be informed based on published instructions, or similar measures
must be taken that ensure informing data subjects alike.
If the data controller has not informed the authorities about the data breach, the
responsible authority, after considering whether the data breach incurs with a high risk,
can order to have the data subject be informed.
REPORTING DATA BREACH TO THE AUTHHORITIES
The data controller reports data breach to the authorities defined in Art. 55 without
unjustifieddelayand,ifpossible,within72hoursofbeinginformedofdatabreach,except
when there is no risk regarding the rights and freedom of individuals.If the report is not
made within 72 hours, reasons for delay shall be attached to justify the delay.
23 | P a ge
Name: Ördögbot Bt..
Placeofbusiness:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
TaxNumber:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-11340123
COMPLAINTS CAN BE MADE TO
Complaints may be sent to Information Commissioner’s Office:
Information Commissioner’s Office
Wycliffe House
Water Lane
Wilmslow
Cheshire
SK9 5AF
Tel: 0303 123 1113 (local rate) or 01625 545 745 if you prefer to use a national rate
number
24 | P a ge
Name: Ördögbot Bt..
Place of business:Hungary,6500Baja,BartschS.u.4
E-mail: hello@xtremestix.com
Telephone: +36-20-940-9872
TaxNumber:21980141-1-03,EU-Taxnumber:HU21980141
Company Registration Number: 03-06-11340124
CLOSURE
Throughout the manual the following regulations were considered:
– EuropeanUnionandEuropeanCouncil’s95/46/EC(27April2016)Directiveonthe
protection of individuals with regartd to the processing of personal data and on the
free movement of such data
– EuropoeanUnionandEuropoeanCouncil’sdirective2016/679abouttheprotection
of individuals with regard to the processing of personal data and on the free
movement of such data, and the repeal of directive 95/46/EC.