Privacy Policy
Introduction
Palatinusné Eizrich Zsuzsanna, sole proprietor (Registered office: 5008 Szolnok, Fazekas Mihály u. 51., Hungary; Tax number: 46722472-2-36) (hereinafter referred to as the Service Provider or Data Controller) processes personal data in accordance with this Privacy Policy.
The current Privacy Policy is continuously available on the following website: www.seaberry.hu. Any amendments to this Privacy Policy become effective upon publication at the above address.
The Data Controller processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), Act CXII of 2011 on Informational Self-Determination and Freedom of Information, and other applicable Hungarian and European Union legislation.
I. Data processing related to purchases made through the website
The legal basis for processing depends on the purpose of the processing.
Personal data necessary for entering into and performing a purchase contract is processed pursuant to Article 6(1)(b) of the GDPR.
Personal data required for invoicing, accounting and compliance with statutory obligations is processed pursuant to Article 6(1)(c) of the GDPR.
Where processing is necessary for the establishment, exercise or defence of legal claims or for the legitimate operation and security of the webshop, processing may be based on the legitimate interests of the Data Controller pursuant to Article 6(1)(f) of the GDPR.
Where processing is based on consent, the legal basis is Article 6(1)(a) of the GDPR.
The categories of data subjects concerned include all users placing an order, creating an account or otherwise using the webshop operated by the Service Provider.
The categories of personal data processed may include the password provided by the customer in encrypted form, first and last name, e-mail address, telephone number, shipping name and address, billing name and address, company name and tax number where applicable, selected payment method, order information, customer notes and the date of registration.
The purpose of processing is to provide full functionality of the website, including entering into, administering and performing purchase contracts, processing orders, communicating with customers, arranging delivery, processing payments, issuing invoices, handling complaints and returns, monitoring contractual performance and enforcing claims arising from the contractual relationship.
Personal data is retained only for as long as necessary for the purpose for which it was collected or for the period required by applicable law.
The Service Provider informs users that pursuant to Section 169(2) of Act C of 2000 on Accounting, accounting documents must be retained for at least 8 years. This retention requirement also applies to the personal data contained in such documents.
The Service Provider may retain personal data for longer where required by applicable legislation or where necessary for the establishment, exercise or defence of legal claims.
Personal data may be accessed by the Data Controller, authorised persons acting on behalf of the Data Controller, and data processors engaged by the Data Controller, subject to applicable data protection legislation.
Personal data may be corrected or deleted upon request, except where the continued processing or retention of such data is required by law.
Requests relating to personal data may be submitted:
by post to Palatinusné Eizrich Zsuzsanna, 5008 Szolnok, Fazekas Mihály u. 51., Hungary
or by e-mail to info@seaberry.hu.
The following principles also apply to the operation of the webshop:
The Service Provider may process personal data that is technically necessary for providing the requested services. When selecting and operating the technical means used for providing information society services, the Service Provider shall ensure that personal data is processed only where and to the extent necessary for providing the service or fulfilling another lawful purpose.
The Service Provider may process personal identification data, address details and information relating to the use of services where this is necessary for entering into and performing a contract, processing orders, invoicing or fulfilling legal obligations.
Personal data may be processed for additional purposes only where a valid legal basis exists under applicable data protection legislation.
Personal data shall be deleted when the purpose of processing ceases to exist, unless continued retention is required by law or is necessary for the establishment, exercise or defence of legal claims.
The Service Provider ensures that users can obtain information about the categories of personal data processed, the purposes of processing, the applicable legal bases and the relevant retention periods.
II. Cookies
The webshop uses cookies and similar technologies required for the operation of the website. These may include session cookies, shopping cart cookies, security cookies and other cookies strictly necessary for providing services explicitly requested by the user.
Prior consent is not required for cookies where their sole purpose is to enable communication over an electronic communications network or where they are strictly necessary to provide a service explicitly requested by the user.
Optional analytics and other non-essential cookies are used only after the user has provided the required consent.
The data processed through cookies may include unique identifiers, information relating to the use of the website, dates and times of visits, browser and device information and website interaction data.
The categories of data subjects concerned include all visitors to the website.
The purpose of essential cookies is to ensure the operation of the website, maintain user sessions, manage the shopping cart, provide security functions and remember user selections.
The duration of processing depends on the type of cookie used. Session cookies generally expire when the browsing session ends, while other cookies may remain on the user’s device for a predefined period.
Personal data generated through cookies may be accessible to the Data Controller and, where applicable, service providers engaged by the Data Controller.
Users may delete or block cookies through their browser settings and may modify or withdraw consent for optional cookies through the cookie settings available on the website.
Blocking essential cookies may affect certain functions of the webshop.
The Service Provider may use Google Analytics to measure and analyse website traffic.
Google Analytics is activated in accordance with the user’s cookie preferences and applicable consent requirements.
During the use of Google Analytics, information relating to website usage, browser and device characteristics, pages visited and website interactions may be processed.
Further information about Google’s privacy practices is available at: https://policies.google.com/privacy
III. Data transfers and data processors
Personal data may be transferred to service providers where this is necessary for the operation of the webshop, fulfilment of orders, delivery, payment processing, invoicing or other lawful business purposes.
Only personal data necessary for the relevant service is transferred.
Hosting and e-mail service provider:
Name: Sybell Informatika Kft.
Registered office: 1158 Budapest, Késmárk u. 7/B, 2nd floor, 206., Hungary
Telephone: +36 (1) 707 6726
E-mail: info@sybell.hu
Website: sybell.hu
Privacy Policy: https://sybell.hu/adatvedelmi-tajekoztato/
Fulfilment and delivery:
Order fulfilment and delivery coordination is carried out by inLOG&CO Kft., either directly or through contracted courier and delivery service providers.
Name: inLOG&CO Kft.
Registered office: 2049 Diósd, Homokbánya út 77., Hungary
Telephone: +36 70 984 2828, +36 30 159 4490
E-mail: inlog@inlog.hu
Website: inlog.hu
Privacy Policy: https://inlog.hu/adatkezelesi-tajekoztato/
For the purpose of order fulfilment and delivery, the following information may be transferred where necessary: recipient name, delivery address, telephone number, e-mail address and information necessary for fulfilling and delivering the order.
inLOG&CO Kft. may arrange delivery through courier service providers including GLS, DPD, MPL and other contracted logistics providers where applicable.
Online payment processing:
Online card payments are processed through Stripe.
Depending on the payment service used, personal data may be processed by Stripe Payments Europe, Limited, Stripe Technology Europe, Limited and other relevant Stripe entities.
The data transferred for payment processing may include customer identification and contact details, billing information, transaction details and information necessary for payment authentication and fraud prevention.
The Data Controller does not receive or store the customer’s complete payment card details.
Further information is available at: https://stripe.com/privacy
Electronic invoicing:
Electronic invoicing is provided through Számlázz.hu.
Service provider:
KBOSS.hu Kft.
Registered office: 1031 Budapest, Záhony utca 7., Hungary
Website: www.szamlazz.hu
The information necessary for issuing invoices may be transferred to the invoicing service provider, including the customer’s name, billing address, company information and tax number where applicable, as well as information relating to the order.
Personal data may also be disclosed to courts, authorities or other public bodies where disclosure is required by law or is necessary for the establishment, exercise or defence of legal claims.
The Data Controller does not sell personal data.
IV. Data security
The Data Controller shall design and implement data processing operations in a manner that protects the privacy and personal data of data subjects.
The Data Controller and the data processors acting on its behalf shall take appropriate technical and organisational measures to ensure the security of personal data.
Personal data shall in particular be protected against unauthorised access, alteration, disclosure, transmission, deletion, destruction, accidental loss or damage.
When determining the appropriate security measures, the Data Controller takes into account the state of the art, the nature and scope of the processing, and the risks associated with processing.
Access to personal data is restricted to authorised persons and service providers who require access for legitimate operational or legal purposes.
Rights of data subjects
Data subjects may exercise the following rights in relation to their personal data, subject to the conditions set out in the GDPR:
- right of access;
- right to rectification;
- right to erasure;
- right to restriction of processing;
- right to data portability;
- right to object;
- right to withdraw consent where processing is based on consent;
- rights relating to automated decision-making and profiling.
The data subject may request confirmation as to whether personal data concerning them is being processed and, where applicable, obtain access to such data and information concerning the processing.
The data subject may request the correction of inaccurate personal data or the completion of incomplete data.
The data subject may request deletion of personal data where the conditions set out in the GDPR are met.
The right to deletion does not apply where continued processing is necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims.
The data subject may request restriction of processing in the circumstances specified by the GDPR.
Where processing is based on consent or a contract and is carried out by automated means, the data subject may request personal data provided by them in a structured, commonly used and machine-readable format and may request its transmission to another controller where technically feasible.
Where processing is based on legitimate interests, the data subject may object to the processing on grounds relating to their particular situation.
Where processing is based on consent, consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, where such decision produces legal effects concerning them or similarly significantly affects them, except in cases permitted under the GDPR.
The webshop does not use solely automated decision-making producing such effects as part of its ordinary purchasing process.
Requests concerning personal data may be submitted by e-mail to info@seaberry.hu or by post to the registered office of the Data Controller.
The Data Controller shall respond to requests without undue delay and, as a general rule, within one month of receipt of the request.
Where justified by the complexity or number of requests, this period may be extended by up to two additional months in accordance with the GDPR. The data subject shall be informed of any extension and the reasons for it.
The Data Controller may request additional information where reasonably necessary to verify the identity of the person making the request.
Legal remedies
If a data subject considers that the processing of their personal data infringes applicable data protection legislation, they may lodge a complaint with the competent supervisory authority.
Nemzeti Adatvédelmi és Információszabadság Hatóság
Hungarian National Authority for Data Protection and Freedom of Information
Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary
Postal address: 1363 Budapest, Pf. 9., Hungary
Telephone: +36 (1) 391 1400
E-mail: ugyfelszolgalat@naih.hu
Website: www.naih.hu
Data subjects are also entitled to seek judicial remedy in accordance with applicable legislation.
Judicial remedies
The Data Controller is responsible for demonstrating that personal data is processed in accordance with applicable legislation.
Legal proceedings relating to data protection may be brought before the competent Hungarian court in accordance with applicable procedural rules.
Where permitted by applicable law, proceedings may also be initiated before the court having jurisdiction according to the data subject’s place of residence or habitual residence.
Compensation
Any person who has suffered material or non-material damage as a result of an infringement of applicable data protection legislation may be entitled to compensation in accordance with the GDPR and applicable Hungarian law.
Applicable legislation
The principal legislation applicable to the processing of personal data includes:
- Regulation (EU) 2016/679 of the European Parliament and of the Council – General Data Protection Regulation (GDPR)
- Act CXII of 2011 on Informational Self-Determination and Freedom of Information
- Act CVIII of 2001 on Electronic Commerce and Information Society Services
- Act C of 2000 on Accounting
- Act V of 2013 on the Civil Code
- Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities
- Act C of 2003 on Electronic Communications
Effective from: 23 September 2026.