Privacy Policy

1. INTRODUCTION

SunZone Ltd. (4220 Hajdúböszörmény, 86 Arad Street, hereinafter referred to as the “Company” or “Data Controller”), as the data controller, acknowledges the content of this legal notice as binding on itself. It undertakes that all data processing related to its activities complies with the provisions of this policy and the applicable national laws, as well as the legal acts of the European Union.

SunZone Ltd. reserves the right to modify this notice at any time. Any changes will, of course, be communicated to the public in a timely manner.

SunZone Ltd. is committed to protecting the personal data of its clients and partners and considers it a priority to respect clients’ right to informational self-determination. Personal data are treated confidentially, and all security, technical, and organizational measures are taken to ensure data protection.

The issuer of this notice, and simultaneously the Data Controller (hereinafter: the “Company”), is:

  • Company Name: Sun Zone Limited Liability Company
  • Registered Office: 4220 Hajdúböszörmény, 86 Arad Street
  • Company Registration Number: 09-09-028863
  • Tax Number: 25966969-2-09
  • Representative: Dr. Rita Szabadosné Nagy
  • Website: www.sinol.hu

The data processing practices are as follows:


2. SCOPE OF PERSONAL DATA, PURPOSE, LEGAL BASIS, AND DURATION OF PROCESSING

SunZone Ltd.’s data processing activities are based on either voluntary consent or legal authorization. In cases of data processing based on voluntary consent, data subjects may withdraw their consent at any stage of the data processing. However, in certain cases, processing, storing, or transferring specific data is mandatory under law.

Data providers are reminded that if they submit personal data that is not their own, it is their responsibility to obtain the consent of the data subject.

SunZone Ltd.’s principles of data management comply with applicable data protection laws, in particular:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (April 27, 2016) – on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, GDPR)
  • Act CXII of 2011 – on informational self-determination and freedom of information
  • Act V of 2013 – Civil Code
  • Act C of 2000 – on accounting
  • Act CVIII of 2001 – on electronic commerce services and certain issues related to information society services
  • Act C of 2003 – on electronic communications
  • Act XLVIII of 2008 – on the basic conditions and certain limitations of economic advertising activities
  • Act I of 2012 – Labor Code

2.1. SERVER LOGGING OF WWW.SINOL.HU

When visiting the www.sinol.hu website, the web server automatically logs the user’s activity. The purpose of processing: during website visits, the service provider records visitor data to monitor the operation of the service, provide personalized service, and prevent abuse.

Legal basis for processing: Article 6(1)(f) of the GDPR, as SunZone Ltd. has a legitimate interest in the secure operation of its website, and Section 13/A(3) of Act CVIII of 2001.

Types of personal data processed: date, time, user computer IP address, information related to the user’s browser and operating system, and the URL of the visited page.

Duration of processing: 30 days from the date of website visit.

Data controller: the Company

Data processor: UNAS Online Ltd.

  • Registered Office: H-9400 Sopron, 14 Kőszegi Street
  • Processor task: provision of online hosting

SunZone Ltd. does not link the data obtained from log analysis with other information and does not attempt to identify the user.

An IP address is a numeric series that uniquely identifies the computers accessing the Internet. Using IP addresses, visitors can even be geographically located. The visited page URLs, along with date and time data, cannot identify the data subject on their own but may allow inferences about the user if combined with other data (e.g., provided during registration).

Data processing by external service providers regarding logging: The portal’s HTML code contains links to and from external servers, independent of SunZone Ltd. These external servers communicate directly with the user’s computer. Visitors should note that these links’ providers can collect user data (e.g., IP address, browser, operating system, mouse movements, visited page URLs, and visit time) due to direct connection and communication with the user’s browser. Any potentially personalized content is served by the external provider’s server. Detailed information on data processing by these external providers can be obtained from the data controllers listed below. The independent measurement and auditing of www.sinol.hu’s website traffic and other web analytics data are facilitated by the Google Analytics server as an external service provider. Information on data handling can be found at http://www.google.com/intl/hu/policies/.

2.2. COOKIE MANAGEMENT ON WWW.SINOL.HU

To provide a personalized experience, the service provider places a small data file, called a cookie, on the user’s computer and reads it during subsequent visits. If the browser returns a previously stored cookie, the service provider handling the cookie can link the user’s current visit with previous ones, but only with respect to its own content.

Types of cookies used:

  1. Essential Cookies
  • Purpose of processing: Essential cookies help make our website usable by enabling basic functions such as navigation and access to secure areas of the website. Without these cookies, the website cannot function properly.
  • Legal basis for processing: legitimate interest of the data controller, GDPR Article 6(1)(f)
  • Types of personal data processed: ID number, date, time
  • Duration of processing: until the end of the session
  1. Preference Cookies
  • Purpose of processing: Preference cookies allow us to remember information that changes the website’s behavior or appearance, such as your preferred language or region.
  • Legal basis for processing: consent of the data subject, GDPR Article 6(1)(a)
  • Types of personal data processed: ID number, IP address, date, time
  • Duration of processing: until the end of the session
  1. Statistical Cookies
  • Purpose of processing: By collecting and reporting data in an anonymous form, statistical cookies help the website owner understand how visitors interact with the website.
  • Legal basis for processing: consent of the data subject, GDPR Article 6(1)(a)
  • Types of personal data processed: ID number, IP address, date, time
  • Duration of processing: until the end of the session
  1. Marketing Cookies
  • Purpose of processing: Marketing cookies are used to track visitors’ website activity. The goal is to display relevant advertisements to individual users and encourage engagement, making our website more valuable to content publishers and third-party advertisers.
  • Legal basis for processing: consent of the data subject, GDPR Article 6(1)(a)
  • Types of personal data processed: ID number, IP address, date, time
  • Duration of processing: until the end of the session
  1. Unclassified Cookies
  • Purpose of processing: Unclassified cookies are those that are still being classified together with individual cookie providers. They may be used for identifying users, distinguishing between users, identifying the user’s current session, storing data provided during the session, preventing data loss, tracking users, and web analytics measurements.
  • Legal basis for processing: consent of the data subject, GDPR Article 6(1)(a)
  • Types of personal data processed: ID number, IP address, date, time
  • Duration of processing: until the end of the session
  1. Information on cookie settings for popular browsers:

Please note that certain website functions or services may not work properly without cookies.

2.3. WEB STORE

2.3.1. SCOPE OF PERSONAL DATA, PURPOSE, LEGAL BASIS, AND DURATION OF PROCESSING

Data processing activities in the web store are based on either voluntary consent or legal authorization. In cases of data processing based on voluntary consent, data subjects may withdraw their consent at any stage. However, in certain cases, the processing, storing, or transferring of specific data is mandatory under law, about which we notify our audience separately.

Data providers are again reminded that if they submit personal data that is not their own, it is their responsibility to obtain the consent of the data subject.


2.3.2. WEB STORE REGISTRATION

Purchases in the web store can be made either as a registered user or without registration.

  • Purpose of processing: managing purchases in the web store, issuing invoices, maintaining customer records, distinguishing between customers, fulfilling orders, documenting purchases and payments, complying with accounting obligations, customer communication, analyzing purchasing habits, providing personalized service, sending email newsletters (including commercial content) to interested parties, providing information on current offers and promotions, conducting direct marketing, creating personalized offers, and maintaining communication.
  • Legal basis for processing: voluntary consent of the data subject, [Act CVIII of 2001, Section 13/A], [Act XLVIII of 2008, Section 6(5)], [Accounting Act C of 2000, Section 169(2)], and 41/2007 (IX.19.) Ministry of Health Decree, Section 19.
  • Types of personal data processed: order ID, customer name, phone number, email address, password, billing name and address, payment and delivery method, delivery address, browsing data (IP address, recently viewed products), order history, details of individual purchases (contents of the order, time, serial number), product value, product storage conditions, pharmacy issuer name and ID code (for pharmaceutical products), consent for direct marketing.
  • Duration of processing:
    • personal data provided are retained for 24 months from the last login or purchase,
    • purchase-related data are retained for 8 years in accordance with [Accounting Act C of 2000, Section 169(2)].
  • Card payments: bank card and transaction data are handled by the financial service provider partner.
    • Data processing subject: SimplePay payment
    • Duration: 6 months
    • Nature and purpose: execution of SimplePay service
    • Data processed: name, address, phone number, email address
    • More details: available in the SimplePay Privacy Policy: http://simplepay.hu/vasarlo-aff
  • Parcel delivery: recipient and delivery data are disclosed only to Magyar Posta Zrt. (1138 Budapest, Dunavirág u. 2–6), DHL Express Hungary Ltd. (1185 Budapest, BUD International Airport, Terminal 302), and other courier partners solely for delivery purposes.
  • Data transfers:
    • payment transaction data (payer ID, transaction amount, date, time) to the financial service provider;
    • for parcel delivery, to Magyar Posta Zrt. MPL Logistics and DHL Hungary Ltd. and other courier partners.
  • Legal basis for data transfer: consent of the data subject; GDPR Article 6(1)(b).
  • Data processors:
    • Name: Unas Online Ltd., Registered Office: H-9400 Sopron, 14 Kőszegi Street
      Task: technical operation of the webshop
    • Name: Sun Zone Ltd., Registered Office: 4220 Hajdúböszörmény & 1138 Budapest, 182 Váci Street
      Task: invoicing and order forwarding

The web store deletes incoming emails with the sender’s name, email address, and any other personal data contained in the message within a maximum of 5 years from submission.


2.3.3. CART ABANDONMENT

If a visitor leaves the web store without purchasing items in their cart, the system may optionally send a reminder email within 48 hours, provided the user has previously consented.

  • Purpose of processing: reminding users of products left in the cart, customer communication, analyzing purchasing habits, providing targeted service, direct marketing, and providing information.
  • Legal basis for processing: GDPR Article 6(1)(a), voluntary consent of the data subject.
  • Types of personal data processed: ID number, date, time, name, email address, products left in the cart, their prices, total value of products, consent for direct marketing.
  • Duration of processing: until withdrawal of consent for direct marketing.

2.3.4. PRODUCT RECOMMENDATIONS BASED ON RETARGETING

The web store may record and evaluate information necessary to optimize ad display using cookies. This information includes which products the visitor has previously viewed in the web store. Recording and evaluation are carried out in an anonymized manner and do not allow identification of the visitor. Importantly, this information is not combined with other personal data of the visitor.

Using this information, personalized product recommendations can be shown to the visitor that may match their interests. Retargeting also allows targeted online ads to be shown on our partners’ websites to users who previously showed interest in our web store or its products.

  • Legal basis for processing: GDPR Article 6(1)(a), your consent.
  • Purpose of processing: providing product recommendations tailored to the user’s interests.
  • Data subjects: visitors to the web store.
  • Types of data processed: IP address, cookies (advertising identifiers).
  • Duration of processing: until withdrawal of consent.

Visitors who no longer wish to receive personalized recommendations can modify cookie settings in their browser.

Retargeting banners can also be disabled by clicking the “X” in the top-right corner of the banner and selecting the opt-out option.

3. INFORMATION ON THE RIGHTS OF THE DATA SUBJECT

3.1. SUMMARY OF THE DATA SUBJECT’S RIGHTS

  1. Transparent information, communication, and facilitation of the exercise of the data subject’s rights
  2. Right to prior information – when personal data are collected from the data subject
  3. Information to be provided if personal data are not obtained from the data subject
  4. Right of access
  5. Right to rectification
  6. Right to erasure (“right to be forgotten”)
  7. Right to restriction of processing
  8. Notification obligation regarding rectification, erasure, or restriction of processing
  9. Right to data portability
  10. Right to object
  11. Automated decision-making in individual cases, including profiling
  12. Limitations
  13. Notification of a personal data breach
  14. Right to lodge a complaint with a supervisory authority
  15. Right to an effective judicial remedy against a supervisory authority
  16. Right to an effective judicial remedy against the data controller or data processor

3.2. DETAILED DESCRIPTION OF THE DATA SUBJECT’S RIGHTS

1. Transparent information, communication, and facilitation of the exercise of the data subject’s rights

1.1. The data controller must provide all information and explanations related to the processing of personal data to the data subject in a concise, transparent, intelligible, and easily accessible form, expressed clearly and understandably, especially when information is addressed to children. Information can be provided in writing or by other means, including electronically. Upon request, verbal information may also be provided, provided the identity of the data subject is verified.

1.2. The data controller must facilitate the exercise of the data subject’s rights.

1.3. The data controller must inform the data subject without undue delay, but at the latest within one month of receiving the request, about the measures taken in response to a request to exercise their rights. This period may be extended by up to two additional months under the conditions specified in the Regulation, with notification to the data subject.

1.4. If no action is taken in response to a request, the data controller must inform the data subject without delay, but at the latest within one month of receiving the request, about the reasons for inaction and about the right to lodge a complaint with a supervisory authority and the right to judicial remedy.

1.5. The data controller provides information and guidance on the data subject’s rights free of charge, except in cases where the Regulation allows a fee. Detailed rules are set out in Article 12 of the Regulation.


2. Right to prior information – if personal data are collected from the data subject

2.1. The data subject has the right to receive information about facts and circumstances concerning data processing before processing begins. This includes being informed about:

a) the identity and contact details of the data controller and its representative;
b) contact details of the data protection officer (if applicable);
c) the purpose of intended processing and the legal basis for processing;
d) in the case of processing based on legitimate interest, the legitimate interests of the controller or a third party;
e) the recipients or categories of recipients of the personal data;
f) if applicable, whether the controller intends to transfer personal data to a third country or international organization.

2.2. To ensure fair and transparent processing, the controller must also inform the data subject about:

a) the period for which personal data will be stored, or, if that is not possible, the criteria used to determine that period;
b) the data subject’s right to request access, rectification, erasure, or restriction of processing, to object to processing, and the right to data portability;
c) in cases of processing based on consent, the right to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal;
d) the right to lodge a complaint with a supervisory authority;
e) whether providing personal data is required by law, contract, or a contractual prerequisite, and the possible consequences of not providing data;
f) the existence of automated decision-making, including profiling, and meaningful information about the logic involved and the significance and expected consequences for the data subject.

2.3. If the data controller intends to process personal data for a purpose other than that for which they were collected, the data subject must be informed beforehand about the new purpose and all relevant information.

Detailed rules for the right to prior information are set out in Article 13 of the Regulation.


3. Information to be provided if personal data are not obtained from the data subject

3.1. If personal data are not obtained from the data subject, the controller must provide the information described above no later than one month after obtaining the data; if the data are used for communication with the data subject, at the time of first contact; or, if data are likely to be disclosed to another recipient, at the latest at the time of first disclosure of the data. This includes information about the categories of personal data and the source, including whether they come from publicly accessible sources.

3.2. Other rules as specified in section 2 (Right to prior information) also apply.

Detailed rules for this obligation are set out in Article 14 of the Regulation.


4. Right of access

4.1. The data subject has the right to obtain confirmation from the data controller as to whether personal data concerning them are being processed, and if so, to access the personal data and related information described in sections 2–3 (Regulation Article 15).

4.2. If personal data are transferred to a third country or international organization, the data subject has the right to be informed of the safeguards under Article 46 of the Regulation.

4.3. The data controller must provide a copy of the personal data being processed. Additional copies may be subject to a reasonable fee based on administrative costs.

Detailed rules on the right of access are set out in Article 15 of the Regulation.


5. Right to rectification

5.1. The data subject has the right to request the controller to correct inaccurate personal data concerning them without undue delay.

5.2. Considering the purpose of processing, the data subject has the right to request completion of incomplete personal data, including by providing a supplementary statement.

These rules are set out in Article 16 of the Regulation.


6. Right to erasure (“right to be forgotten”)

6.1. The data subject has the right to request that the controller delete personal data concerning them without undue delay, and the controller is obliged to do so…