Privacy Policy

in which I inform you, as a visitor to my website and user of my services, about my data processing and data protection rules.

1. What principles do I follow when processing data?

I follow the following core principles during data processing:

  • I process personal data lawfully, fairly, and in a transparent manner in relation to you.
  • I collect personal data only for specified, explicit, and legitimate purposes and do not process it in a manner incompatible with those purposes.
  • The personal data I collect and process is adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.
  • I take every reasonable step to ensure that the data I process is accurate and, where necessary, kept up to date; I will promptly erase or rectify inaccurate personal data.
  • I store personal data in a form that permits your identification for no longer than is necessary for the purposes for which the personal data are processed.
  • I ensure appropriate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures.

  • I process (i.e., collect, record, organize, store, and use) your personal data based on your prior, informed, and voluntary consent, and only to the necessary extent and always for a specific purpose.

  • In some cases, the processing of your data is based on legal requirements and is mandatory, in which case I will specifically draw your attention to this fact.
  • In certain cases, I, or a third party, have a legitimate interest in processing your personal data, for example, for the operation, development, and security of my website.

2. Who am I?

Individual Entrepreneur: Katalin Duchenka
Registered Office: 3421 Mezőnyárád, Szent István király út 44.
Website: https://naturedesign.hu/
Email Address: info@naturedesign.hu
Tax ID: 48984203-1-25

In accordance with Article 37 of the GDPR, I am not obliged to appoint a Data Protection Officer.

Website Hosting Provider:

Name of Hosting Provider: Rackhost Zrt.

Registered Office of Hosting Provider: 6722 Szeged, Tisza Lajos körút 41.

Website of Hosting Provider: https://rackhost.hu/

Email Address of Hosting Provider: info@rackhost.hu

To ensure the high-quality service of my clients, I use the following Data Processor during data handling:

Data Controller: Katalin Duchenka

Address: 3421 Mezőnyárád, Szent István út 44.

Should I modify the scope of my Data Processors, I will update the changes in this Notice.

Data I process:

I only request personal data from my website visitors if they wish to register, log in, or participate in a prize draw.

I do not connect the personal data provided in connection with registration or my marketing services, and it is fundamentally not my goal to identify my visitors.

You can request further information regarding data processing at the email address info@naturedesign.hu or my registered office address. I will send my response to the contact information you provided within 15 days (but no later than 1 month).

3. What are cookies and how do I manage them?

Cookies are small data files (hereinafter: cookies) that are placed on your computer via the website through its use, saved, and stored by your internet browser. Most frequently used internet browsers (Chrome, Firefox, etc.) accept and allow the download and use of cookies as a default setting. However, you can refuse or disable them by modifying your browser settings, and you can also delete cookies already stored on your computer. The ‘Help’ section of each browser provides more detailed information on the use of cookies.

There are some cookies that do not require your prior consent. My website provides brief information about these when your first visit begins, such as session cookies that assist with authentication, media playback, load balancing, user interface customization, and user-centric security cookies.

I will inform you about cookies that require consent—if data processing begins immediately upon visiting the page—at the start of your first visit and ask for your consent.

I do not use or allow cookies that permit third parties to collect data without your consent.

Accepting cookies is not mandatory; however, I assume no responsibility if my website does not function as expected due to the lack of cookie authorization.

Cookie settings can be accessed by clicking the black icon in the bottom-left corner of the website.

What cookies do I use?

Name: _ga
Provider: naturedesign.hu
Purpose: Registers a unique ID that generates statistical data on how the visitor uses the website.
Expiry: 2 years
Type: HTTP

Name: _gat
Provider: naturedesign.hu
Purpose: Stores the throttle request rate used by Google Analytics.
Expiry: Session
Type: HTTP

Name: _gid
Provider: naturedesign.hu
Purpose: Registers a unique ID that generates statistical data on how the visitor uses the website.
Expiry: Session
Type: HTTP

Name: _fbp
Provider: naturedesign.hu
Purpose: Used by Facebook to provide a series of advertising products for a third party (e.g., real-time bidding ads).
Expiry: 3 months
Type: HTTP

Name: fr
Provider: facebook.com
Purpose: Facebook uses this cookie to offer a series of advertising products (such as real-time bidding from third-party advertisers).
Expiry: 3 months
Type: HTTP

Detailed information on third-party cookies can be found on this page.

4. What else should you know about data processing related to my website?

You provide your personal data to me voluntarily during registration or contact. Therefore, I ask you to pay careful attention to the truthfulness, correctness, and accuracy of your data when disclosing it, as you are responsible for this. Incorrect, inaccurate, or incomplete data may prevent you from using my services.

If you provide personal data of a person other than yourself, I assume that you have the necessary authorization to do so.

You may withdraw your consent to data processing at any time free of charge by:

  • Deleting your registration,
  • Withdrawing your consent to data processing, or
  • Withdrawing your consent to the processing or use of any data required for registration or requesting its blocking.

I undertake to register the withdrawal of consent within a 30-day deadline for technical reasons. However, I draw your attention to the fact that I may still process certain data after the withdrawal of consent for the purpose of fulfilling my legal obligations or asserting my legitimate interests.

In case of misleading use of personal data, or if one of our visitors commits a crime or attacks my system, I will immediately delete their data simultaneous with the termination of their registration, and—if necessary—I will keep the data for the duration of civil liability assessment or criminal proceedings.

5. What should you know about data processing for direct marketing and newsletters?

By the statement made during registration or by modifying your personal data stored on the newsletter and/or direct marketing registration interface later (i.e., by clearly expressing your intention to consent), you can consent to the use of your personal data for marketing purposes. In this case—until the withdrawal of consent—I will also process your data for the purpose of sending direct marketing and/or newsletters, and I will send you advertising and other mailings, as well as information and offers, and/or forward newsletters (Section 6 of the Grtv).

You may give or withdraw your consent regarding direct marketing and the newsletter either jointly or separately, free of charge and at any time.

The cancellation of registration is always considered a withdrawal of consent. Withdrawing consent to direct marketing and/or newsletter data processing is not interpreted as a simultaneous withdrawal of consent to data processing related to my website.

I undertake to register the withdrawal or cancellation of individual consents within a 15-day deadline for technical reasons.

6. What should you know about prize draws?

I may organize prize draws on a campaign basis, the specific conditions of which are detailed in a separate policy. The policy of the current promotion can always be found on the homepage of my website via a centrally placed link.

7. Other data processing questions

I may only transfer your data within the framework defined by law. In the case of my data processors, I ensure through contractual conditions that they may not use your personal data for purposes contrary to your consent. Further information can be found in Section 2.

I do not transfer data abroad.

The court, the prosecutor’s office, and other authorities (e.g., police, tax office, National Authority for Data Protection and Freedom of Information) may contact me for the provision of information, disclosure of data, or making documents available. In these cases, I must fulfill my obligation to provide data, but only to the extent strictly necessary to achieve the purpose of the request.

My collaborators and employees involved in data processing and/or data processing are entitled to access your personal data to a predetermined extent, subject to a confidentiality obligation.

I protect your personal data with appropriate technical and other measures, and I ensure the security and availability of the data, as well as protect it against unauthorized access, alteration, damage, disclosure, and any other unauthorized use.

As part of organizational measures, I control physical access to my premises, continuously train myself, and keep paper-based documents locked away with appropriate protection. As part of technical measures, I use encryption, password protection, and anti-virus software. However, I draw your attention to the fact that data transmission over the internet cannot be considered completely secure. I do everything possible to make the processes as secure as possible, but I cannot take full responsibility for data transmission via my website. However, I adhere to strict regulations regarding the data received by me to ensure the security of your data and prevent unauthorized access.

Regarding security issues, I ask for your help in carefully safeguarding your access password to my website and not sharing this password with anyone!

8. What are your rights and remedies?

You may:

  • Request information about data processing.
  • Request the rectification, modification, or completion of your personal data processed by me.
  • Object to the data processing and request the erasure or restriction (blocking) of your data (except for mandatory data processing).
  • Seek legal remedy before a court.
  • Lodge a complaint with the supervisory authority or initiate proceedings (https://www.naih.hu/panasz-vagy-kozerdeku-bejelentes-a-panasztorveny-szerint).

Supervisory Authority: National Authority for Data Protection and Freedom of Information (NAIH)

  • Registered Office: 1055 Budapest,
    Falk Miksa utca 9-11.
  • Mailing Address: 1363 Budapest, Pf.: 9.
  • Telephone: +36 (1) 391-1400
  • Fax: +36 (1) 391-1410
  • E-mail: ugyfelszolgalat@naih.hu
  • Website: https://naih.hu/

Upon your request, I will provide information on your data processed by me (or by my appointed data processor), including:

  • The data itself.
  • The source of the data.
  • The purpose and legal basis of the data processing.
  • The duration of the processing (or the criteria for determining this duration if not possible).
  • The name, address of my data processors, and their activities related to data processing.
  • The circumstances and effects of data protection incidents, and the measures taken to remedy and prevent them.
  • The legal basis and recipient of any data transfer of your personal data.

I will provide the information within 15 days (but no later than 1 month) from the submission of the request. The information is free of charge, except if you have already submitted an information request concerning the same scope of data in the current year. I will refund the cost already paid by you if the data has been processed unlawfully, or if the request for information has led to rectification. I can only refuse to provide information in cases specified by law, by indicating the legal provision and informing you about the possibility of judicial remedy or turning to the Authority.

I will notify you and all those to whom the data was previously disclosed for data processing purposes of the rectification, restriction, designation, and erasure of personal data, unless the failure to notify does not infringe your legitimate interests.

If I do not comply with your request for rectification, restriction, or erasure, I will inform you of the reasons for the refusal in writing or electronically (with your consent) within 15 days (but no later than 1 month) of receiving the request, and inform you of the possibility of judicial remedy and turning to the Authority.

If you object to the processing of your personal data, I will examine the objection within 15 days (but no later than 1 month) of receiving the request and inform you of my decision in writing. If I decide that your objection is justified, I will cease data processing—including further data collection and transfer—and restrict the data. I will also notify all those to whom the personal data affected by the objection was previously transferred, and who are obliged to take action to enforce the right to object.

I will refuse to comply with the request if I can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims. If you do not agree with my decision, or if I miss the deadline, you may appeal to the court within 30 days of the communication of the decision or the last day of the deadline.

Data protection cases fall within the jurisdiction of the Regional Court (Törvényszék), and the lawsuit may also be initiated before the court of the data subject’s place of residence or domicile, at the data subject’s choice. A foreign citizen may also lodge a complaint with the supervisory authority competent for their place of residence.

I kindly ask you, before turning to the supervisory authority or the court with your complaint, to contact me for a consultation and the fastest possible resolution of the problem.

9. What are the main guiding laws for my activities?

  • Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data (GDPR)
  • Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (Info tv.)
  • Act V of 2013 on the Civil Code (Ptk.)
  • Act CVIII of 2001 on certain issues of electronic commerce services and information society services (Eker tv.)

  • Act C of 2003 on Electronic Communications (Ehtv)
  • Act CLV of 1997 on Consumer Protection (Fogyv tv.)
  • Act CLXV of 2013 on complaints and public interest disclosures (Pktv.)
  • Act XLVIII of 2008 on the basic conditions and certain restrictions of commercial advertising activity (Grtv.)

10. Modification of the Privacy Policy

I reserve the right to modify this Privacy Policy, of which I will inform the data subjects appropriately. Information regarding data processing will be published on the website www.naturedesign.hu.

Budapest, 2025.03.26.