General Terms and Conditions
This Agreement enters into force upon signature by the PARTIES. Either party is entitled to unilaterally withdraw from the Agreement, without giving reasons, within 3 days from the date of signature, by means of a written declaration sent by registered mail with return receipt. Beyond this period, amendments to the Agreement are likewise only possible in written form via registered mail with return receipt, within the deadline indicated in the Agreement.
It is the client's responsibility to submit the material to be edited, no later than the indicated deadline. Should no information or data be received from the client, the editorial office is entitled to prepare the publication from the materials available to it.
The CLIENT shall pay the service fee by the payment deadline specified on the invoice issued by the SERVICE PROVIDER. In the event of late payment of the service fee, the CLIENT shall pay default interest to the SERVICE PROVIDER in accordance with the provisions of the Hungarian Civil Code in force from time to time.
If the CLIENT withdraws from the Agreement beyond the three-day period, the CLIENT shall pay a frustration penalty (kötbér). The amount of the penalty is 50% of the list price of the service fee, which the CLIENT shall pay to the SERVICE PROVIDER against an invoice within 15 days of the withdrawal, and shall at the same time repay any discounts already received on the services already in operation.The SERVICE PROVIDER does not accept and does not publish any material or information that violates any applicable law, public morals, or the good reputation or personal rights of any natural or legal person.
The CLIENT consents to the SERVICE PROVIDER being entitled to hand over the prepared publication materials to third parties. The SERVICE PROVIDER is obliged to perform the tasks undertaken in the Agreement by the deadlines undertaken therein.
The CLIENT assumes responsibility for the authenticity and accuracy of the data contained in the material to be published, and for the fact that the CLIENT is entitled to publish or produce the publication in the form and content submitted. In the event that the publication material or text is submitted in an incomplete, inaccurate, or grammatically/orthographically incorrect form, the publication fee is non-refundable, and the SERVICE PROVIDER excludes any liability arising therefrom.
The SERVICE PROVIDER assumes liability up to a maximum of the amount of the service fee, for damage claims arising from erroneous or inaccurate publication, in the event of a justified complaint raised at the time of publication.
In matters not regulated in the Agreement concluded between the PARTIES, Hungarian law shall apply, in particular the provisions of the Civil Code. Data processing shall take place in accordance with the data protection legislation in force from time to time. The PARTIES declare that the content and conditions of the Agreement constitute a business secret.
PRIVACY POLICY
1. INTRODUCTION
Hello Tourist (hereinafter: the Data Controller) pays particular attention to the protection of personal data, compliance with mandatory legal provisions, and secure and fair data processing in the course of its activities.
Data Controller details:
Hello Tourist Kft.
Balogh Ferenc utca 5.
2890 Tata
The Data Controller manages the personal data made available to it in all cases in compliance with the applicable Hungarian and European legislation and ethical expectations, and in all cases takes the technical and organisational measures necessary for appropriate and secure data processing.
This policy was prepared in consideration of the following applicable legislation:
-
Act XLVIII of 2008 on the basic conditions and certain restrictions of commercial advertising activity
-
Act CXII of 2011 on the right of informational self-determination and on freedom of information
The Data Controller undertakes to unilaterally comply with this policy and requests – in a notice available on its website – that its clients also accept the provisions of this policy. The Data Controller reserves the right to amend its privacy policy. In the event of any amendment, the updated text shall be made publicly available.
2. DEFINITIONS
In our policy, data protection terms have the following meanings:
-
data file: the totality of data managed in a single register;
-
data processor: the natural or legal person, or organisation without legal personality, who or which processes data on the basis of a contract – including a contract concluded pursuant to a statutory provision;
-
data controller (data responsible body): the body performing a public task that produced the public-interest data subject to mandatory electronic publication, or in the course of whose operation such data was generated;
-
data processing (kezelés): regardless of the procedure applied, any operation or set of operations performed on data, in particular collection, recording, registration, classification, storage, alteration, use, querying, transmission, disclosure, harmonisation or linking, blocking, deletion, and destruction, as well as the prevention of further use of the data, the taking of photographs, sound or video recordings, and the recording of physical characteristics suitable for personal identification (e.g. fingerprints, palm prints, DNA samples, iris images);
-
data controller (adatkezelő): the natural or legal person, or organisation without legal personality, who or which, alone or jointly with others, determines the purpose of data processing, makes and implements decisions regarding such processing (including the means used), or has them implemented by the data processor;
-
data publisher: the body performing a public task which – where the data responsible body does not publish the data itself – publishes on its website the data transmitted to it by the data responsible body;
-
data marking: the labelling of data with an identifier for the purpose of distinguishing it;
-
data transmission: making data accessible to a specified third party;
-
data deletion: rendering data unrecognisable in such a way that it can no longer be restored;
-
data protection incident: unlawful processing or handling of personal data, in particular unauthorised access, alteration, transmission, disclosure, deletion or destruction, as well as accidental destruction and damage;
-
data blocking: marking data with an identifier for the purpose of permanently or temporarily restricting its further processing;
-
criminal personal data: personal data generated during or prior to criminal proceedings, in connection with the criminal act or proceedings, at the bodies authorised to conduct criminal proceedings or to detect crimes, as well as at the penitentiary organisation, which can be linked to the data subject, including data on prior convictions;
-
EEA state: a Member State of the European Union and any other state that is a party to the Agreement on the European Economic Area, as well as any state whose nationals enjoy a legal status equivalent to that of nationals of states party to the EEA Agreement under an international treaty between the EU and its Member States and a non-EEA state;
-
data subject: any specified natural person identified or – directly or indirectly – identifiable on the basis of personal data;
-
third country: any state that is not an EEA state;
-
third party: a natural or legal person, or organisation without legal personality, who or which is not identical to the data subject, the data controller or the data processor;
-
consent: the voluntary and definite expression of the data subject's will, based on adequate information, by which they give their unambiguous consent to the processing of their personal data – either fully or in respect of specific operations;
-
binding corporate rules: an internal data protection policy adopted by a data controller or group of data controllers operating in several countries, including at least one EEA state, and approved by the National Authority for Data Protection and Freedom of Information (the Authority), which is binding on the data controller or group of data controllers, and which – in the case of transfers to third countries – ensures the protection of personal data through the unilateral commitment of the data controller or group of data controllers;
-
data of public interest by virtue of public interest: any data that does not fall within the concept of public-interest data but whose disclosure, knowability or accessibility is ordered by law in the public interest;
-
special category data: personal data revealing racial origin, national affiliation, political opinion or party affiliation, religious or other ideological belief, membership in an interest-representation organisation, sexual life; personal data concerning health status or pathological addiction; as well as criminal personal data;
-
disclosure: making the data accessible to anyone;
-
personal data: any data relating to the data subject – in particular the data subject's name, identification mark, and one or more characteristics specific to their physical, physiological, mental, economic, cultural or social identity – as well as any conclusion concerning the data subject drawn from the data;
-
objection: a statement by the data subject by which they object to the processing of their personal data and request the discontinuation of the processing or the deletion of the processed data;
-
data handling (processing as technical operations): the performance of technical tasks related to data processing operations, regardless of the method and means used to carry out the operations and the place of their application, provided that the technical task is performed on the data;
-
data destruction: the complete physical destruction of the data carrier containing the data;
-
public-interest data: any information or knowledge held by a body or person performing a state or local government task or other statutorily defined public task that relates to its activities or arose in connection with the performance of its public task, that does not fall under the concept of personal data, and that is recorded in any manner or form – regardless of the method of its processing, its individual or collective nature – in particular data concerning powers, competence, organisational structure, professional activity, evaluation of its effectiveness, types of data held, legal regulations governing operation, financial management, and concluded contracts.
3. PRINCIPLES OF DATA PROCESSING
Personal data may be processed exclusively for a specified purpose, in order to exercise a right or fulfil an obligation. At every stage of the data processing, the processing must comply with this purpose, and the collection and processing of the data must be fair and lawful.
Only personal data that is indispensable for the achievement of the purpose of the data processing, and suitable for achieving that purpose, may be processed. Personal data may be processed only to the extent and for the duration necessary to achieve the purpose.
Personal data retains this status throughout the processing for as long as its link with the data subject can be restored. The link with the data subject can be restored if the data controller has the technical means necessary for restoration.
During the processing, the accuracy, completeness and – where necessary in view of the purpose of the processing – up-to-date status of the data must be ensured, and the data subject must be identifiable only for the duration necessary for the purpose of the processing.
The processing of personal data shall be considered fair and lawful if, with a view to ensuring the data subject's freedom of expression, a person wishing to obtain the data subject's opinion visits them at their place of residence or stay, provided that the data subject's personal data are processed in accordance with the provisions of the relevant Act and the personal approach is not for commercial purposes. Personal approaches may not take place on public holidays as defined by the Labour Code.
Personal data may be processed if the data subject consents to such processing, or if it is ordered by an Act of Parliament or – on the basis of authorisation in an Act and within the scope defined therein – by a decree of a local government for a purpose based on public interest (mandatory data processing).
Personal data may be processed only for a specified purpose, in order to exercise a right or fulfil an obligation. At every stage of the processing, the data processing must comply with this purpose.
Only personal data that is indispensable for, and suitable for, achieving the purpose of the data processing may be processed, and only to the extent and for the duration necessary to achieve the purpose.
Personal data may be transmitted, and different data processing operations may be linked, where the data subject has given consent, or where permitted by an Act, and where the conditions of data processing are met for each individual item of personal data.
Personal data may be transmitted from the country – regardless of the medium or method of transmission – to a data controller or processor located in a third country only if the data subject has expressly consented, or if permitted by an Act, and provided that an adequate level of protection of personal data is ensured during the processing or handling of the transmitted data in the third country.
In the case of mandatory data processing, the purpose and conditions of the processing, the scope and accessibility of the data to be processed, the duration of the processing, and the identity of the data controller shall be determined by the Act or local government decree ordering the processing.
An Act may order the disclosure of personal data in the public interest, with explicit specification of the scope of the data. In all other cases, disclosure requires the consent of the data subject, and in the case of special category data, written consent. In case of doubt, it shall be presumed that the data subject has not given consent.
The consent of the data subject shall be deemed to have been given in respect of data communicated by them in the course of their public appearances, or transmitted by them for the purpose of disclosure.
In proceedings initiated at the request of the data subject, consent to the processing of their necessary data shall be presumed. The data subject's attention must be drawn to this fact.
The data subject may also give consent within the framework of a written contract concluded with the Data Controller, for the purpose of fulfilling the provisions of the contract. In this case, the contract must contain all the information that the data subject must know with regard to the processing of their personal data, in particular the definition of the data to be processed, the duration of the processing, the purpose of use, the transmission of the data, and the use of a data processor.
The contract must unambiguously state that the data subject, by signing, consents to the processing of their data as specified in the contract.
The right to the protection of personal data and the personality rights of the data subject – unless otherwise provided by law – may not be infringed by other interests related to data processing, including the public nature of public-interest data.
4. BASIS OF DATA PROCESSING
In the course of its activities, the Data Controller bases the processing of personal data in every case on a statutory provision or on voluntary consent. In certain cases, in the absence of consent, the processing is based on another legal basis or on Section 6 of Act CXII of 2011.
Data of website visitors
The Data Controller does not record either the user's IP address or any other personal data when its operated websites are visited.
The HTML code of the websites operated by the Data Controller may, for the purpose of web analytics measurements, contain references coming from and pointing to independent external servers. The measurement also covers conversion tracking. The web analytics service provider does not process personal data, but only browsing-related data that is not suitable for identifying individuals.
Web analytics services are currently provided by GOOGLE within the framework of the Analytics service (for example).
Description of the technical solution for data protection (for example): the Data Controller runs so-called remarketing advertisements through the advertising systems of Facebook and Google AdWords. These service providers may collect or receive data from the Data Controller's website and other internet locations using cookies, web beacons and similar technologies. Using these data, they provide measurement services and target advertisements: these may appear on additional websites in the partner networks of Facebook and Google. Remarketing lists do not contain personal data of the visitor and are not suitable for personal identification.
The user can delete cookies from their own computer or prohibit their use in their browser in advance. These options are available, depending on the browser, typically in the Settings / Privacy menu.
Further information on the privacy policies of Google and Facebook can be read at the following addresses:
google.com/privacy.html and facebook.com/about/privacy
Newsletter
The Data Controller delivers online newsletters and direct marketing messages by electronic means containing news, updates and business offers to subscribers of newsletters of the websites it operates (also known as VIP members), generally on a monthly basis, but at most twice a week. Subscription to the newsletter requires the provision of a name and e-mail address, which is essential for the delivery of the messages.
The data are processed until the data subject requests their deletion. The option to unsubscribe is provided by a direct link in every newsletter. The user is responsible for the authenticity of the personal data provided.
Quiz game
The Data Controller may announce quiz games on the websites it operates. A person may participate in a given quiz game only once. To verify this, the Data Controller requests the player's name, e-mail address and telephone number. The Data Controller notifies all players, including those who do not receive a prize, by e-mail about the prizes and the identity of the winners. The Data Controller notifies the winner via the telephone number provided, and through that channel requests the further data of the winner that are necessary for delivering any physical prize.
The data of quiz game players are retained until the last day of the current year.
5. SECURITY OF DATA PROCESSING
Website operator:
Yettel Magyarország Zrt.
Pannon út 1.
Hungary, Törökbálint
The Data Controller protects the data in particular against unauthorised access, alteration, transmission, disclosure, deletion or destruction, as well as against accidental destruction and damage. The Data Controller, together with the server operators, ensures the security of the data by means of technical, organisational and structural measures that provide a level of protection commensurate with the risks arising in connection with the data processing.
6. RIGHTS OF DATA SUBJECTS
The data subject may request information about the processing of their personal data, and may request the rectification of their personal data, and – with the exception of data processing prescribed by law – the blocking or deletion of their personal data, via the link in the footer of the newsletters or at any of the contact details of the Data Controller.
At the data subject's request, the Data Controller shall provide information about the data subject's data that it processes or that are processed by a data processor commissioned by the Data Controller or on its instructions, the source of these data, the purpose, legal basis and duration of the processing, the name and address of the data processor and its activities related to the data processing, the circumstances and effects of any data protection incident and the measures taken to remedy it, and – in the case of transmission of the data subject's personal data – the legal basis and recipient of the data transmission.
The Data Controller shall delete personal data if its processing is unlawful, if the data subject requests it, if the data are incomplete or inaccurate and this situation cannot be lawfully corrected – provided that deletion is not precluded by law – if the purpose of processing has ceased, the statutory period for storing the data has expired, or if a court or the data protection commissioner has so ordered.
The data subject may object to the processing of their personal data if the processing (transmission) of their personal data is necessary solely for the enforcement of the right or legitimate interest of the data controller or data recipient, except where the processing is ordered by law; if the use or transmission of the personal data is for the purpose of direct marketing, opinion polling or scientific research; or where the exercise of the right of objection is otherwise permitted by law.
The Data Controller is obliged – with simultaneous suspension of the processing – to examine the objection within the shortest possible time from the submission of the request, but no later than 15 days, and to inform the requester in writing of the outcome. Where the objection is justified, the data controller is obliged to discontinue the processing – including any further collection and transmission of data – and to block the data.