Privacy policy

1. Introduction

Kisanyám Dizájn (hereinafter: Kisanyám Dizájn, service provider, data controller, the Company), as data controller, acknowledges the content of this legal notice as binding on itself. 
The Company undertakes to ensure that all data processing related to its activities complies with the requirements set out in this policy and in the applicable legislation. 
Kisanyám Dizájn is the operator of the kisanyamdizajn.hu website.

Kisanyám Dizájn reserves the right to change this notice at any time. Naturally, it will inform its audience of any changes in due time.

Kisanyám Dizájn is committed to protecting the personal data of its customers and partners, and considers it particularly important to respect its customers' right to informational self-determination. The Data Controller treats personal data confidentially and takes all security, technical and organizational measures that guarantee the security of the data.

Below, Kisanyám Dizájn describes its data processing principles and presents the requirements it has set for itself as data controller and complies with. Its data processing principles are in line with the applicable data protection legislation, in particular the following:

  • Act CXII of 2011 on the right to informational self-determination and freedom of information;
  • Act V of 2013 on the Civil Code (Ptk.);
  • Act XLVIII of 2008 on the basic conditions and certain restrictions of commercial advertising activities (Grt.).
  • Act CVIII of 2001 (Ekertv.) on certain issues of electronic commerce services and information society services;
  • Regulation (EU) 2016/679 of the European Parliament and of the Council (27 April 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: "GDPR")

2. Definitions

  • data subject: any natural person who is identified, or who can be identified directly or indirectly, on the basis of specific personal data;
  • personal data: data that can be associated with the data subject, in particular the name and identification mark of the data subject and knowledge of one or more physical, physiological, mental, economic, cultural or social characteristics, as well as any conclusion concerning the data subject that can be drawn from it;
  • consent: a voluntary and explicit expression of the data subject's wishes, based on appropriate information, by which they give their unambiguous consent to the processing of personal data concerning them, either in full or for specific operations;
  • data controller: the natural or legal person or organization without legal personality which, alone or jointly with others, determines the purpose of the processing of data, makes and implements decisions regarding data processing (including the means used), or has them implemented by the data processor;
  • data processing: any operation or set of operations performed on data, regardless of the procedure used, in particular collection, recording, organization, storage, alteration, use, retrieval, transfer, disclosure, alignment or combination, blocking, erasure and destruction, as well as preventing further use of the data, taking photographs, sound or video recordings, and recording physical characteristics suitable for identifying a person (e.g. fingerprints or palm prints, DNA samples, iris images);
  • data transfer: making data available to a specific third party;
  • disclosure: making data available to anyone;
  • data erasure: making data unrecognizable in such a way that it can no longer be restored;
  • data processing (technical): performing technical tasks related to data processing operations, regardless of the method and means used to carry out the operations and the place of application, provided that the technical task is performed on the data;
  • data processor: the natural or legal person or organization without legal personality that processes data on the basis of a contract, including a contract concluded on the basis of a legal provision. 

3. Company details

Our company's details and contact information are as follows:

  • Name: Kisanyám Dizájn
  • Mailing address: 3 Mikszáth Kálmán utca, 2459 Rácalmás, Hungary
  • Company registration number: 58993240
  • Tax number: 49310795-1-27
  • Phone number: +36 30 738 9020
  • E-mail:  info@kisanyamdizajn.hu
  • Representative of the data controller: Vilmos Tóth Kardos, sole proprietor, owner

4. Scope of personal data, purpose, legal basis and duration of data processing

We draw the attention of those providing data to Kisanyám Dizájn to the fact that if they do not provide their own personal data, it is the data provider's obligation to obtain the consent of the data subject. The data controller is not obliged to verify this. The data controller draws the partner's attention to the fact that if they fail to fulfill this obligation and the data subject therefore enforces a claim against the data controller, the data controller may pass on the enforced claim or the amount of the related damage to the partner.

We provide the following information regarding our individual data processing activities. 

4.1. Requests for quotes and inquiries by direct contact

Interested parties may contact our Company directly by e-mail sent to the Company's address or by phone.

  • Purpose of data processing: keeping in contact, promoting communication between the data subject and our Company, and ensuring the closest and most effective cooperation possible.
  • Legal basis of data processing: legitimate interest, Article 6(1)(f) GDPR
  • Scope of personal data processed: name, e-mail address and phone number of the person requesting a quote / contact person, and other information provided by the data subject,
  • Duration of data processing: for 3 years after the validity period of the quote, or until the data subject objects
  • Recipients of personal data: The data controller does not transfer the data it obtains to third parties, with the exception of the data processor(s) specified in section 7. The recorded data may only be accessed by the Data Controller's employees and the designated colleagues of the data processor(s).
  • Legitimate interest: our Company's legitimate interest in processing the data subject's data is direct marketing
  • Data subjects concerned: partners and data subjects inquiring directly (e.g. by e-mail or phone) about the Company's services. 

4.2. Requests for quotes and inquiries through the website (kisanyamdizajn.hu)

Our company allows data subjects to request quotes electronically.

  • Purpose of data processing: keeping in contact, promoting communication between the data subject and our Company, and ensuring the closest and most effective cooperation possible.
  • Legal basis of data processing: the voluntary consent of the data subject, Article 6(1)(a) GDPR.
  • Scope of personal data processed: name of the interested person (first name, last name), e-mail address, phone number, company name, and other information provided by the data subject.
  • Duration of data processing: for 3 years after the validity period of the quote, or until consent is withdrawn.
  • Recipients of personal data: The data controller does not transfer the data it obtains to third parties, with the exception of the data processor(s) specified in section 7. The recorded data may only be accessed by the Data Controller's employees and the designated colleagues of the data processor(s).
  • Data subjects concerned: partners and data subjects inquiring through the website about the Company's services and products.

4.3. Data processing related to the follow-up of quote requests

  • Purpose of data processing: the data controller's legitimate interest in keeping records of the data subject's data beyond the validity period of the quote for the purpose of direct marketing
  • Legal basis of data processing: legitimate interest of the data controller, Article 6(1)(f) GDPR,
  • Scope of personal data processed: contact person's last name and first name; phone number; e-mail address
  • Recipients of personal data: The data controller does not transfer the data it obtains to third parties, with the exception of the data processor(s) specified in section 7. The recorded data may only be accessed by the Data Controller's employees and the designated colleagues of the data processor(s).
  • Duration of data processing: until the data subject objects
  • Legitimate interest: building business relationships with partners and those requesting quotes, providing accurate information to data subjects. Our Company's legitimate interest in processing the data subject's data is direct marketing
  • Data subjects concerned: the recipients of quotes previously issued by the Company and the contact person(s) named in them.

4.4. Newsletter registration

  • Purpose of data processing: sending e-mail newsletters, which may also contain commercial advertising, to interested parties, and informing them about current news
  • Legal basis of data processing: the prior, voluntary consent of the data subject, Article 6(1)(a) GDPR,
  • Scope of personal data processed: name, e-mail address
  • Duration of data processing: until voluntary consent is withdrawn or the data subject unsubscribes from the newsletter. Our Company processes the data provided by the data subject until consent is withdrawn. Upon withdrawal of consent, we delete the processed data from our newsletter database within 7 days at the latest, and we will no longer send you newsletters.
  • Recipients of personal data: The data controller does not transfer the data it obtains to third parties, with the exception of the data processor(s) specified in section 7. The recorded data may only be accessed by the Data Controller's employees and the designated colleagues of the data processor(s). You can unsubscribe from the newsletter at any time by sending a letter to our Company at info@kisanyamdizajn.hu, or by clicking the unsubscribe icon in the newsletter. 
  • Data subjects concerned: partners and data subjects subscribing to the Company's electronic newsletter.

4.5. Newsletter data (for newsletter registrations before 25 May 2018)

  • Purpose of data processing: sending e-mail newsletters, which may also contain commercial advertising, to interested parties, and informing them about current news
  • Legal basis of data processing: legitimate interest of the data controller, Article 6(1)(f) GDPR,
  • Scope of personal data processed: name, e-mail address
  • Duration of data processing: until the data subject objects
  • Legitimate interest: providing information, including commercial advertising and business offers, to data subjects who have subscribed to the newsletter. Our Company's legitimate interest in processing the data subject's data is direct marketing.
  • Recipients of personal data: the data controller does not transfer the data it obtains to third parties, with the exception of the data processor(s) specified in section 7. The recorded data may only be accessed by the Data Controller's employees and the designated colleagues of the data processor(s). You can unsubscribe from the newsletter at any time by sending a letter to our Company at info@kisanyamdizajn.hu, or by clicking the unsubscribe icon in the newsletter. 
  • Data subjects concerned: partners and data subjects who subscribed to the Company's electronic newsletter before 25 May 2018.

4.6. Camera system

Cameras operate on the premises operated by the data controller for the personal and property security of data subjects and for other purposes. Information signs draw data subjects' attention to their operation. The activities related to the operation of the camera system are set out in the premises' "Security camera data processing notice", which is available on site.

4.7. Data processing related to ensuring the operation of information technology services

  • Purpose of data processing: Kisanyám Dizájn may use so-called "cookies" (temporary markers) on its websites, which allow faster access to them. "Cookies" are pieces of information that are only active during a given customer session and are placed on the Customer's computer by the website for faster identification. The Customer can always request that cookies be disabled by changing the browser settings; however, disabling them may slow down or prevent access to some parts of the site and the use of certain functions. 
    The session cookies used avoid the need to resort to other IT tools that are potentially harmful to the confidentiality of customers' navigation and do not allow identifying personal data to be obtained.
    Users can delete cookies from their own computer, or disable the use of cookies in their browser. Cookies can usually be managed in the Tools/Settings menu of browsers, under the Privacy settings, under the name cookie.
  • Legal basis of data processing: the voluntary consent of the data subject (User), Article 6(1)(a) GDPR.
    The User gives their voluntary consent to the data processing by accepting the information notice and declaration that pops up when they start browsing the website, or by continuing to browse.
    Scope of personal data processed: IT data processing concerns the data required for the operation of the "cookies" used to run the website and for the use of the log files applied by the web hosting provider.
  • Duration of data processing: until the end of the session
  • Recipients of personal data: The data controller does not transfer the data it obtains to third parties, with the exception of the data processor(s) specified in section 7. The recorded data may only be accessed by the Data Controller's employees and the designated colleagues of the data processor(s).
  • Data subjects concerned: All Users visiting the website, regardless of whether they use the services available on the website.

5. Other data processing

We provide information about data processing not listed in this notice when the data is collected. We inform our customers that certain authorities, bodies performing public duties and courts may contact our company for the purpose of disclosing personal data. Our company provides personal data to these bodies, provided that the body concerned has specified the exact purpose and scope of the data, only to the extent that is absolutely necessary to achieve the purpose of the request, and if the fulfillment of the request is required by law. 

6. Transfer of personal data to a third country or international organization

Our Company does not transfer your above personal data to a third country or to an international organization.

7. Information on the use of data processors

In the course of data processing, the data controller transfers the data to the data processor(s) contracted with it for the performance of the contract.
Categories of recipients: system administration service provider, accounting and payroll service provider, server hosting, web hosting provider

8. Children

Our services are not intended for persons under the age of 16, and we ask that persons under the age of 16 do not provide Personal Data to the Data Controller. 
If we become aware that we have collected personal data from a child under the age of 16 (with the exception of data processed in accordance with legal requirements), we will take the necessary steps to delete the data as soon as possible.

9. Automated decision-making

Our Company does not use automated decision-making in its data processing procedures or data collection.

10. Method of storing personal data, security of data processing

Our company's IT systems and other data storage locations are located at the registered office and on servers provided by the data processor. Our company selects and operates the IT tools used to process personal data in the course of providing the service in such a way that the processed data:

  1. is accessible to those authorized to access it (availability);
  2. its authenticity and authentication are ensured (authenticity of data processing);
  3. its integrity can be verified (data integrity);
  4. is protected against unauthorized access (data confidentiality).

We pay particular attention to the security of data, and we take the technical and organizational measures and establish the procedural rules necessary to enforce the guarantees under the GDPR. We protect the data with appropriate measures, in particular against unauthorized access, alteration, transfer, disclosure, erasure or destruction, as well as accidental destruction, damage, and becoming inaccessible due to changes in the technology used.

The IT systems and networks of our company and our partners are protected against computer-assisted fraud, computer viruses, computer intrusions and denial-of-service attacks. The operator ensures security with both server-level and application-level protection procedures. Daily backups of the data are in place. To avoid data breaches, our company takes all possible measures; in the event of such an incident, in accordance with our incident management policy, we act immediately to minimize the risks and prevent damage.

11. Rights of data subjects, legal remedies

The data subject may request information about the processing of their personal data, and may request the rectification of their personal data or, with the exception of mandatory data processing, its erasure or withdrawal, and may exercise their right to data portability and to object in the manner indicated when the data was collected, or at the data controller's contact details above.

The rights and legal remedies of the data subject under Act CXII of 2011 and Regulation (EU) 2016/679 are set out below and communicated to data subjects. 

The right to information, also known as the data subject's "right of access": Under Act CXII of 2011 and Article 15 of Regulation (EU) 2016/679, at the request of the data subject, the Data Controller provides information 

  • about the data it processes and the categories of personal data,
  • about the purpose of data processing,
  • about the legal basis of data processing,
  • about the duration of data processing,
  • where applicable, about the period for which the data will be stored or, if this is not possible, the criteria used to determine that period,
  • where applicable, if the data was not collected from the data subject, any available information about its source,
  • where applicable, about automated decision-making, including profiling, as well as meaningful information about the logic involved and the significance of such processing, and
  • its expected consequences for the data subject,
  • about the details of the data processor, if a data processor was used, about the circumstances and effects of a data breach and the measures taken to remedy it, and
  • in the case of transfer of the data subject's personal data, about the legal basis, purpose and recipient of the data transfer.

The information is free of charge if the person requesting it has not yet submitted a request for information to the Data Controller concerning the same set of data in the current year. In other cases, a fee may be charged. Any fee already paid must be refunded if the data was processed unlawfully or the request for information led to rectification.

The Data Controller draws data subjects' attention to the fact that, under Act CXII of 2011, information must be refused

  1. if, on the basis of a law, an international treaty or a binding legal act of the European Union, the Data Controller receives personal data in such a way that the transferring data controller indicates, at the time of the transfer, a restriction of the rights of the data subject provided for in the said Act, or another restriction of its processing.
  2. in the interest of the external and internal security of the state, such as national defense, national security, the prevention or prosecution of criminal offenses, and the security of the execution of sentences, as well as for state or local government economic or financial interests, significant economic or financial interests of the European Union, and for the purpose of preventing and uncovering disciplinary and ethical offenses related to the practice of professions and breaches of labor law and occupational safety obligations (including, in all cases, inspection and supervision), and to protect the rights of the data subject or others.

The Data Controller is obliged to notify the National Authority for Data Protection and Freedom of Information of rejected requests for information annually, by 31 January of the year following the year in question.

The right to rectification: The data subject has the right to have the Data Controller rectify inaccurate personal data concerning them without undue delay at their request. Taking into account the purpose of the data processing, the data subject has the right to request that incomplete personal data be completed, including by means of a supplementary statement. However, if the personal data does not correspond to reality and the personal data corresponding to reality is available to the Data Controller, the Data Controller will rectify the personal data as a matter of course, even without the data subject's request.

The right to erasure, also known as the "right to be forgotten": The data subject has the right to have the Data Controller erase personal data concerning them without undue delay at their request, and the Data Controller is obliged to erase personal data concerning the data subject without undue delay if this is not precluded by mandatory data processing.

In addition to the above case, the Data Controller is obliged to erase the data under Act CXII of 2011 and Regulation (EU) 2016/679 of the European Parliament and of the Council if

  • the processing of the data is unlawful;
  • the data is incomplete or incorrect, and this cannot be lawfully remedied, provided that erasure is not precluded by law;
  • the purpose of the data processing has ceased, or the statutory deadline for storing the data has expired;
  • it has been ordered by a court or the Authority.
  • the personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
  • the data subject objects to the processing and there are no overriding legitimate grounds for the processing;
  • the personal data must be erased to comply with a legal obligation under the law applicable to the Data Controller;
  • the personal data was collected in connection with the offer of information society services offered directly to children, as referred to in Article 8(1) of Regulation (EU) 2016/679.

If the Data Controller has made the personal data public for any reason and is obliged to erase it as described above, taking into account the available technology and the cost of implementation, it will take reasonable steps, including technical measures, to inform other data controllers processing the data that the data subject has requested the erasure of links to, or copies or replications of, the personal data in question.

The Data Controller draws data subjects' attention to the following limitations of the right to erasure or "right to be forgotten" arising from the EU regulation:

  1. exercising the right to freedom of expression and information;
  2. compliance with an obligation under Union or Member State law applicable to the data controller that requires the processing of personal data, or the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller;
  3. public interest in the area of public health;
  4. archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) of Regulation (EU) 2016/679, insofar as the right to erasure is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
  5. the establishment, exercise or defense of legal claims.

The right to restriction of processing, also known as the right to blocking: The data subject has the right to have the Data Controller restrict processing at their request.
If, on the basis of the information available, it can be assumed that erasure would harm the legitimate interests of the data subject, the data must be blocked. Personal data blocked in this way may only be processed for as long as the purpose of processing that precluded the erasure of the personal data persists.

If the data subject contests the accuracy or correctness of the personal data, but the incorrectness or inaccuracy of the contested personal data cannot be clearly established, the data will be blocked. In this case, the restriction applies for a period enabling the Data Controller to verify the accuracy of the personal data.

Under the EU regulation, the data must be blocked if

  1. the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead;
  2. the Data Controller no longer needs the personal data for the purposes of processing, but the data subject requires them for the establishment, exercise or defense of legal claims; or
  3. the data subject has objected to the processing; in this case, the restriction applies until it is established whether the legitimate grounds of the Data Controller override those of the data subject.

If processing is subject to restriction (blocking), such personal data may, with the exception of storage, only be processed with the data subject's consent, or for the establishment, exercise or defense of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State.

The Data Controller hereby expressly draws data subjects' attention to the fact that the data subject's right to rectification, erasure and blocking may be restricted by law in the interest of the external and internal security of the state, such as national defense, national security, the prevention or prosecution of criminal offenses, and the security of the execution of sentences, as well as for state or local government economic or financial interests, significant economic or financial interests of the European Union, and for the purpose of preventing and uncovering disciplinary and ethical offenses related to the practice of professions and breaches of labor law and occupational safety obligations (including, in all cases, inspection and supervision), and to protect the rights of the data subject or others.
The Data Controller will, without undue delay and at the latest within 30 days of receipt of the request, inform the data subject about what they requested, and/or rectify the data, and/or erase and/or restrict (block) the data, or take other steps in accordance with the request, if there are no grounds precluding it.

The Data Controller notifies the data subject in writing of the rectification, erasure or restriction of processing, as well as everyone to whom the data was previously transferred or handed over for the purpose of processing. At the data subject's request, the Data Controller informs them of these recipients. Notification may be omitted if, in view of the purpose of the processing, this does not harm the legitimate interests of the data subject, or if providing the information proves impossible or requires disproportionate effort. The Data Controller is also obliged to notify the data subject in writing if the data subject's exercise of their rights cannot be fulfilled for any reason, and must specify the factual and legal reasons as well as the legal remedies available to the data subject: the possibility of turning to a court or to the National Authority for Data Protection and Freedom of Information.

The "right to data portability": The data subject has the right to

  1. receive the personal data concerning them, which they have provided to the Data Controller, in a structured, commonly used and machine-readable format, and has the right to
  2. transmit those data to another data controller without hindrance from the data controller to which the personal data have been provided, where:
  3. the processing is based on consent; and
  4. the processing is carried out by automated means.

In exercising the right to data portability, the data subject has the right to request, where technically feasible, the direct transfer of personal data between data controllers.
In view of the data processing carried out by the Data Controller, the conditions for exercising the right to data portability are not met (there is no automated data processing), so the data subject cannot exercise this right.

The right to object: The data subject may object to the processing of their personal data, including profiling, if

  • the processing (transfer) of personal data is necessary solely for the enforcement of the rights or legitimate interests of the Data Controller or the data recipient, except in the case of mandatory data processing;
  • the personal data is used or transferred for the purposes of direct marketing, public opinion polling or scientific research;
  • the exercise of the right to object is otherwise permitted by law.

The data subject may also object, under Article 21(3) of Regulation (EU) 2016/679, to the processing of personal data for direct marketing purposes, in which case the personal data may no longer be processed for this purpose.

Where personal data is processed for scientific or historical research purposes or statistical purposes, the data subject has the right to object, on grounds relating to their particular situation, to the processing of personal data concerning them, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
The Data Controller, while simultaneously suspending the processing, examines the objection within the shortest possible time, but no later than 30 days from the submission of the request, and informs the applicant of the result in writing. If the applicant's objection is well-founded, the Data Controller terminates the processing, including further data collection and transfer, blocks the data, and notifies everyone to whom it previously transferred the personal data affected by the objection, and who are obliged to take action to enforce the right to object, of the objection and the measures taken on its basis.

If the data subject does not agree with the Data Controller's decision, or the Data Controller misses the deadline referred to, the data subject is entitled to turn to a court within 30 days of its communication.
The data subject has the right to object to automated decision-making.

Enforcement in court: The data subject may turn to a court if their rights are violated. The court acts in the case as a matter of priority. The Data Controller is obliged to prove that the data processing complies with the provisions of the law.

If your right to informational self-determination is violated, you may file a report or complaint with:

National Authority for Data Protection and Freedom of Information (NAIH)
Address: 22/c Szilágyi Erzsébet fasor, 1125 Budapest, Hungary
Phone: +36 (1) 391-1400, Fax: +36 (1) 391-1410
Web: http://www.naih.hu
E-mail: ugyfelszolgalat@naih.hu

Customer reviews

What our customers say

They answered all my questions quickly, and the milestone set arrived in time for the baby shower.

Szabó Réka Animal milestone set

The padlock ceremony sign was one of the most beautiful props at our wedding, and it has hung in our living room ever since.

Eszter and Máté Nagy Padlock ceremony sign

The name sign turned out exactly as I imagined. It has become the favorite piece in my little girl's room.

Kovács Anita Two-layer name sign

Can't find what you're looking for?

Tell us what you have in mind: size, color, lettering. We'll check whether it can be made, and give you a price too.