Privacy Notice regarding newsletter distribution
The Data Controller Decoration & Design Kft. (registered office: 2310 Szigetszentmiklós, Kántor u. 5., represented by: Barna Ferenc and Boris Malovík, managing directors, e-mail: info@decorand.com) hereby informs you about the processing of data provided in connection with newsletter sending:
The data subject may subscribe to the Data Controller's newsletter service with the data specified below.
| Name of data processing: |
Newsletter subscription and sending |
|
|
|
| What is the purpose of data processing? |
The main purpose of processing data related to newsletter sending is the regular informing of the recipient (subscribed data subject) about the latest promotions, events and news of the Data Controller (and its Partners), essentially regular advertising. |
|
|
|
| Who are the data subjects? |
Every natural person who wishes to be regularly informed about the Data Controller's news, promotions and discounts, and therefore subscribes to the newsletter service by providing their personal data. |
|
|
|
| Who/what is the source of the data? |
Data subjects |
|
|
|
| What are the categories and scope of processed data? |
What is the purpose of each data category and scope? |
What is the legal basis for data processing? |
|
|
| name of contact person |
identification |
Voluntary consent (GDPR Article 6(1)(a) and Section 6(1) of Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions of Commercial Advertising Activities) |
|
|
| name of the company on behalf of which the contact person acts |
identification |
|
|
|
| e-mail address |
identification and sending of newsletter |
|
|
|
| technical data: date of subscription and unsubscription |
future evidentiary purposes |
|
|
|
| How long does data processing last? |
Data processing lasts until deletion at the request of the data subject (unsubscription), or until deletion due to the e-mail address becoming unreachable.
The Data Controller processes (solely stores) the date of subscription and unsubscription for 5 years following unsubscription from the newsletter, for the purpose of being able to prove the lawfulness of newsletter sending. |
|
|
|
| Is data disclosed (access granted, transferred, transmitted) to third parties? |
Data may be transferred to authorities, courts, legal representatives, data protection officers, or persons or bodies conducting due diligence on the Data Controller.
Data is transferred to the data processor. |
|
|
|
| Is there a data processor engaged? |
Company name |
Registered office |
Place of service provision |
Service |
| |
The Rocket Sience Group, LLC |
675 Ponce de Leon Ave NE, Suite 5000 Atlanta, GA 30308 USA |
e-mail sending service |
|
| Is there automated decision-making? |
Does not occur. |
|
|
|
| Is there profiling? |
Does not occur. |
|
|
|
| What data security measures does the Data Controller implement? |
The Data Controller ensures in particular:
-
that access to equipment used for data processing (hereinafter: the data processing system) is denied to unauthorised persons,
-
the prevention of unauthorised reading, copying, modification or removal of data carriers,
-
the prevention of unauthorised entry of personal data into the data processing system, and the prevention of unauthorised access to, modification of or deletion of personal data stored therein,
-
the prevention of unauthorised use of data processing systems via data transmission equipment,
-
that persons authorised to use the data processing system can only access personal data specified in their access authorisation,
-
that it can be verified and established to which recipients personal data has been or may be transmitted, or made or may be made available, via data transmission equipment,
-
that it can subsequently be verified and established which personal data was entered into the data processing system, at what time, and by whom,
-
the prevention of unauthorised access to, copying, modification or deletion of personal data during their transmission or during the transport of data carriers,
-
that the data processing system can be restored in the event of a malfunction.
-
that the data processing system remains operational, that errors occurring during its operation are reported, and that stored personal data cannot be altered even through faulty operation of the system. |
|
|
|
| What rights does the data subject have and how can they be exercised? |
The following table shows the relationship between the rights of the data subject and the legal basis/bases specified above in connection with data processing, so that it is clear to the data subject which rights are available under the applicable legal basis. Following the table, the data subject receives an explanation of the content of the rights and how to exercise them. |
|
|
|
| |
Right to prior information |
Right of access |
Right to rectification |
Right to erasure |
Restriction |
Data portability |
Objection |
Withdrawal of consent |
| Consent |
YES |
YES |
YES |
YES |
YES |
YES |
NO |
YES |
| Contract |
YES |
YES |
YES |
YES |
YES |
YES |
NO |
NO |
| Legal obligation |
YES |
YES |
YES |
NO |
YES |
NO |
NO |
NO |
| Vital interests |
YES |
YES |
YES |
YES |
YES |
NO |
NO |
NO |
| Public task, public authority. |
YES |
YES |
YES |
NO |
YES |
NO |
YES |
NO |
| Legitimate interest |
YES |
YES |
YES |
YES |
YES |
NO |
YES |
NO |
Right to information (GDPR Articles 13 and 14)
Where the Data Controller processes personal data relating to the data subject, the Data Controller is obliged to provide the data subject – even without a request to that effect – with information on the most important characteristics of the processing, including its purpose, legal basis, duration, the identity and contact details of the Data Controller and its representative, the contact details of the data protection officer, the recipients of personal data, in the case of processing based on legitimate interest the legitimate interest of the Data Controller and/or a third party, and the rights of the data subject and remedies available (including the right to lodge a complaint with a supervisory authority); and, if the data subject is not the source of the data, the source of personal data and the categories of personal data concerned, to the extent the data subject does not already have this information. The Data Controller provides this information by making this notice available to the data subject.
Right of access (GDPR Article 15)
The data subject has the right to obtain confirmation from the Data Controller as to whether or not personal data concerning them is being processed, and, where that is the case, the right to access the personal data and information relating to the circumstances of the processing. Where personal data is transferred to a third country or an international organisation, the data subject is entitled to be informed of the appropriate safeguards pursuant to Article 46 relating to the transfer. The Data Controller shall provide a copy of the personal data undergoing processing to the data subject upon request.
Right to withdraw consent (GDPR Article 7)
The data subject has the right to withdraw their consent at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.
Right to rectification (GDPR Article 16)
The data subject has the right to obtain from the Data Controller without undue delay the rectification of inaccurate personal data concerning them.
Right to object (GDPR Article 21)
The data subject has the right to object, on grounds relating to their particular situation, at any time to processing of personal data concerning them which is based on GDPR Article 6(1)(e) or (f).
In such a case, the Data Controller shall no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject.
Right to restriction of processing (GDPR Article 18)
The data subject has the right to obtain from the Data Controller restriction of processing upon request where one of the conditions set out in the GDPR applies, in which case the Data Controller shall not carry out any operation on the data other than storage.
Where the data subject has objected to processing, the restriction shall apply for the period pending the verification of whether the legitimate grounds of the Data Controller override those of the data subject.
Right to erasure ('right to be forgotten') (GDPR Article 17)
The data subject has the right to obtain from the Data Controller the erasure of personal data concerning them without undue delay where the processing has no purpose, where consent has been withdrawn and there is no other legal basis, where there is no overriding legitimate reason for processing in the case of an objection, or where the data was processed unlawfully from the outset, or where the data must be erased to comply with a legal obligation. Where the Data Controller has made the personal data public and is obliged to erase it, the Data Controller shall, taking into account available technology and the cost of implementation, take reasonable steps – including technical measures – to inform controllers processing the personal data that the data subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data.
Right to data portability (GDPR Article 20)
The data subject has the right to receive the personal data concerning them, which they have provided to a Data Controller, in a structured, commonly used and machine-readable format, and has the right to transmit those data to another controller without hindrance from the Data Controller to which the personal data have been provided, where the statutory conditions apply (automated processing and consent or contract as legal basis).
Where and how can the data subject request detailed information about data processing and transfers, and where and how can they exercise their rights?
The Data Controller draws the attention of data subjects that they may submit requests for information, exercise their right of access, and exercise other rights by sending a declaration to the Data Controller's postal address (8000 Székesfehérvár, Berényi út 72-100.) or e-mail address (info@pannonjob.hu). The Data Controller shall examine and respond to the declaration within the shortest possible time from receipt, and shall take the necessary steps in accordance with the declaration, the Internal Data Protection Policy, and applicable legislation.
Contact details of the supervisory authority for complaints (GDPR Article 77):
National Authority for Data Protection and Freedom of Information
Address: 1055 Budapest, Falk Miksa utca 9-11.
Postal address: 1363 Budapest, Pf. 9.
Phone: +36 (1) 391-1400
Fax: +36 (1) 391-1410
www: http://www.naih.hu
e-mail: ugyfelszolgalat@naih.hu
For further information about your rights and the details of lodging a complaint with the authority, please visit: http://naih.hu/panaszuegyintezes-rendje.html.
In the event of an infringement of their rights, the data subject may also turn to the court competent for their place of residence and may claim damages, among other remedies.
You can find the court competent for your place of residence here: https://birosag.hu/birosag-kereso
Other
The data subject may unsubscribe from the newsletter at any time via the link at the bottom of e-mails, or by sending a request to info@decorand.com .
You may also unsubscribe from the newsletter by post to the following address:
Decoration & Design Kft., 2310 Szigetszentmiklós, Kántor u. 5.
The Data Controller reviews the newsletter list every three years and requests a confirmatory consent for newsletter sending after three years. The data of any data subject who does not provide confirmatory consent will be deleted by the Data Controller from the active newsletter mailing list.
The Data Controller keeps statistics on the readership of sent newsletters by tracking clicks on links contained in the newsletters.
The Data Controller informs data subjects that in the course of newsletter sending, the Data Controller is entitled to forward not only its own offers but also, directly and indirectly, the offers of its contracted Partners to data subjects.
Closed: 11 April 2026.
Version: 1.0. Barna Ferenc and Boris Malovík, Managing Directors, Decoration & Design Kft.