Privacy policy of Fallost escape room

 

Data Controller: eBusiness Experts Kft.

Address: 1036 Budapest, Bécsi Street 85, ground floor 5.

Company registration number: 01 09 295679

 

 

The main purpose of this privacy notice is to gather all the reasons and ways of collecting, using, processing, and storing the personal data of users – Data Subjects. The owner of www.fallost.hu wishes to ensure all the users about the safety of their personal data.

 

1. Used definitions

 

  • Personal data: Personal data is any information that relates to an identified or identifiable living individual. Different pieces of information, which are collected together can lead to the identification of a particular person and also constitute personal data.
  • Data processing: The carrying out of operations on data, especially by a computer, to retrieve, transform, or classify information.
  • Data Controller: A data controller is a person, company, or other body that determines the purpose and means of personal data processing (this can be determined alone, or jointly with another person/company/body).
  • Data subject: Data subject refers to any person who can be identified, directly or indirectly, via an identifier such as a name, an ID number, location data, or via factors specific to the person's physical, physiological, genetic, mental, economic, cultural or social identity.
  • Data processor: Processor means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.
  • Data processing: The carrying out of operations on data, especially by a computer, to retrieve, transform, or classify information.
  • Third-party: A third party is someone who is not one of the main people involved in the data processing, but who is involved in it in a minor role.
  • Personal data breach: 'personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.

 

2. Data protection acts

 

  • A fogyasztóvédelemről szóló 1997. évi CLV. törvény
  • 2001. évi CVIII. törvény
  • 2008. évi XLVIII. törvény
  • 2011. évi CXII. törvény
  • 2013. évi V. törvény a Polgári Törvénykönyvről.
  • Az Európai Parlament és a Tanács (EU) 2016/679 rendelete (2016. április 27.) a természetes személyeknek a személyes adatok kezelése tekintetében történő védelméről és az ilyen adatok szabad áramlásáról, and the 95/46/EK rendelet hatályon kívül helyezéséről.

 

3. About the Data Controller

 

  • Name: eBusiness Experts Kft.
  • Address: 1036 Budapest, Bécsi Street 85, ground floor 5.
  • Phone number: 0630 680 6902
  • E-mail: hello@fallost.hu
  • Web: www.fallost.hu
  • Legal representative: Forgács Balázs
  • Data Protection Officer: Forgács Balázs
  • Data Protection Officer’s e-mail address: hello@fallost.hu

 

4. Where do we store your data?

 

  • We store the data requested from you within the territory of the European Economic Area ("EEA").

 

5. Who has access to your data?

 

  • We will not pass on, sell or trade your Data to third parties for marketing purposes. We use the data transmitted to third parties only to enable the service provided to you. If we provide data to third parties, you can find it below in any case.

 

6. What is the legal basis for the processing?

 

  • When processing your personal data, we always inform you that it is necessary for invoicing, for the use of services, or for the purpose of providing marketing services.

 

7. The Data Subject's rights

 

  • Data subjects have the right to request information about the personal data the company stores about them.
  • Data Subjects have the right to request the restriction of the usage of their data.
  • Data subjects have the right to request rectification of their personal data if the information is incorrect, including the right to have incomplete personal data completed.
  • Data subjects have the right to get a copy of their data transferred to them or another party whenever the company processes their personal data.
  • Data Subjects have the right to request the deletion of their personal data.

 

8. How can you exercise your rights?

 

 

9. Online Appointment

 

- Why do we use your personal data?

 

  • The Service Provider uses your personal data to process and manage your online appointment booking and to send notifications about it. We use your personal data to manage payments, handle complaints and administer the service.

 

- What types of personal data are processed?

 

  • Contact information: name, address, e-mail address, phone number
  • Payment information

 

- What is the legal basis for processing your personal data?

 

  • In order for the use of the service and the reservation of the desired date to be smooth, it is necessary for the Service Provider to process your personal data.

 

- How long do we save your data?

 

  • We keep your data for 30 days.

 

10. When paying for service

 

- Why do we use your personal data?

 

  • We use your Personal Data when making the payment, which can be done by bank transfer or in person on-site. After the payment, we also fill out a form with the person paying the amount, in which he accepts the rules and regulations.

 

- What types of personal data are processed during payment?

 

  • Name
  • Email address
  • Mobile number

 

- What types of personal data are processed when filling out the form?

 

  • Name
  • Address
  • ID Card Number

 

- What is the legal basis for processing your personal data?

 

  • These data are necessary for the service provider to successfully process the payment of the service and for the items specified in the policy.

 

11. Storage Provider

 

- Why do we use your personal data?

 

  • tarhely.eu is the provider of the hosting space and makes regular backups of the files, data, and settings on its servers as part of an additional service. We do our best to protect this data. The service provider stores data backups made from the storage space for 28 days, and data backups made from incoming correspondence stored on the server for 14 days. The data processor undertakes to store its database on a system that requires unique identification of users and ensures that only authorized persons can access the data contained therein.

 

- About tarhely.eu

 

  • Name: Tárhely.Eu Kft.
  • Address: 1144 Budapest, Ormánság Street 4. X. floor 241.
  • Phone number: +36 1 789 2 789
  • Web: www.tarhely.eu

 

 

12. Direct Marketing

 

- Why do we use your personal data?

 

  • We use your personal data to send marketing offers in the form of e-mail messages.
  • In relation to www.fallost.hu, we send relevant information and offers to optimize your experience.

 

- What types of personal data do we process?

 

  • Name
  • E-mail address

 

- Who can access your personal data?

 

  • The data serve the sole purpose of enabling the Service Provider to fulfill its service obligations towards you.
  • Direct marketing letters are sent from the Mailchimp Newsletter system.

 

- Data of Mailchimp Newsletter System

 

  • Name: Mailchimp –  The Rocket Science Group LLC
  • Address: The Rocket Science Group, LLC , 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308 USA
  • Web: www.mailchimp.com

 

- What is the legal basis for processing your personal data?

 

The processing of your personal data is based on your consent when you consent to direct marketing.

 

  • Right to withdraw consent:

 

You have the right to withdraw your consent to the processing of your personal data at any time, or to object to direct marketing. If you do so, the Service Provider will not send you any further direct marketing emails related to the www.fallost.hu online store.

 

  • You can opt out of direct marketing in the following ways:

 

Follow the instructions for this in the marketing email.

 

  • The right to object to the processing of your personal data:

 

You have the right to object to the processing of your personal data. You can do this at hello@fallost.hu. In this case, your account will be deleted.

 

13. Compliance with legal obligations

 

- Why do we use your personal data?

 

  • We use your personal data to comply with legal requirements, court orders and decisions of the authorities.
  • This includes the collection and verification of your personal data in accounting in order to comply with accounting laws.

 

- What types of personal data do we process?

 

  • Name
  • Address
  • Transaction amount
  • Transaction date

 

- Who can access your personal data?

 

  • Your personal data can be seen by the Service Provider and its employees and the accounting company. At the moment, accounting is done manually, no other invoicing programs are included in the processes.

 

- Accounting firm

 

  • Based on the concluded contract, he contributes to the accounting of invoicing documents. In doing so, the Data Processor will provide the name and address of the data subject to the extent necessary for accounting records, Sztv. Pursuant to § 169, paragraph (2), it shall be kept for 8 years from the date of issue of the invoice. If the data subject withdraws his consent to the issuance of the invoice, the Data Controller is Infotv. Based on point a) of § 6, paragraph (5), you are entitled to keep your personal data obtained during the issuance of the invoice for 8 years.

 

- Data

 

  • Name: Hollandimpex Financial Kft.
  • Address: 1181 Budapest, Üllői út 505

 

- What is the legal basis for processing your personal data?

 

  • The processing of personal data is necessary in order for the Service Provider to fulfill its legal obligations.

 

- How long do we store your data?

 

  • We store your data in accordance with the accounting rules in force in your country.

14. Billing

 

- Why do we use your personal data?

 

  • Issuing the invoice is our legally required obligation, for which we use the following personal data: billing name, billing address, e-mail address. 

 

- Who can access your personal data?

 

  • Name: KBOSS.hu Kft.
  • Address: 1031 Budapest, Záhony utca 7.
  • Company registration number: 01 09 303201

15. Cookies

 

- Why do we use your personal data?

 

  • Cookies are short text files that are stored on the hard drive of the computer or mobile device and are activated on subsequent visits. When you use our services, we assume that you consent to the use of such cookies.

 

- How do we use cookies?

 

  • We use persistent cookies to remember your chosen home page and store your data if you select the "Remember me" option when logging in.
  • Some cookies from third parties are set by them themselves and we have no control over them. These are social media providers such as Facebook, Instagram regarding how users share content on this site. This also applies to their icons, which indicate this. Google Analytics is a service of Google Inc. The data collected from the cookies is used to evaluate how the interested party/buyer used the website, and also to prepare reports related to website activity to the website operator in order to perform additional services related to website and Internet use.

 

- What types of personal data do we process?

 

  • We will only associate your cookie ID with the information provided or collected in connection with your account if you are logged into your account.

 

- Who can access your personal data?

 

  • The data provided to the third party is solely for the purpose of enabling the company to fulfill its service obligations to you; we use the analytics tool to collect statistics to optimize the page and present relevant material.

 

- How long do we save your data?

 

  • You can easily delete cookies from your computer or mobile device using your browser. You can find everything about managing and deleting cookies in the "Help" menu.

 

16. Asset Protection System

 

The service provider operates an electronic monitoring system in the area of ​​the Fallost escape room.

 

- What is the purpose of data controlling?

 

  • When using the service, to follow the game progress in the given locations, and also to provide assistance to the game master, to protect human life, physical integrity, and property, prevent and detect violations of law, and bring the perpetrator to justice.

 

- What is the legal basis for processing your personal data?

 

  • The consent of the data subject by entering the gaming area of ​​the service provider, SzVMt. Based on § 30.
  • Surveillance cameras do not record images, so players' personal data and facial images are not stored and processed.

 

17. Rules of procedure

 

  • If a request is received by the DATA Controller, the Data Controller shall inform the data subject in writing as quickly as possible, but no later than within 30 days, of the measures taken based on the request.

 

  • If the complexity of the request or other objective circumstances justify it, the above deadline can be extended once, for a maximum of 60 days. The Data Controller shall notify the data subject in writing of the extension of the deadline, together with the appropriate justification for the extension.

 

  • The data controller provides the information free of charge, unless:
  • the data subject requests information/measures for essentially unchanged content;
  • the request is clearly unfounded;
  • the request is excessive.

 

  • The applicant requests the transfer of the data on paper or on an electronic data carrier (CD or DVD), in which case the Data Controller will transfer a copy of the relevant data free of charge as requested (unless the chosen platform would be technically disproportionately difficult). An administration fee of HUF 500 per page/data carrier is requested for each additional requested copy.

 

  • The data controller notifies all persons to whom the relevant data were previously disclosed of the correction, deletion, or restriction it has implemented, unless the disclosure is impossible or requires a disproportionately large effort.

 

  • If requested by the data subject, the Data Controller will provide information to which persons their data has been forwarded.

 

  • The data controller shall respond to the request in electronic form, unless:
  • The Data Controller does not know the electronic contact information of the data subject
  • the data subject specifically requests the answer in a different way, and it does not cause unreasonably high additional expenses for the Data Controller;

 

18. Compensation

 

  • Any person concerned is entitled to demand compensation from the Data Controller and/or the Data Processor in the event of material or non-material damage as a result of the violation of data protection laws. If the Data Controller and data processor(s) are also involved in the infringement, they are jointly and severally liable for the resulting damage.

 

  • The Data Controller and any data processors are only liable if they cannot prove that they are not responsible for the event that caused the damage.

 

  • The Data Processor is only responsible for the damages incurred if it has violated the provisions of the relevant data protection legislation specifically formulated for Data Processors, or if the damage occurred due to disregarding the instructions of the Data Controller.

 

19. Legal Remedy

 

  • If you have objections or problems with the Data Controller's data management, please feel free to contact the Data Controller's data protection officer Balázs Forgács

 

  • If, in his opinion, his rights have been violated by the Data Controller and/or the data processors, he is entitled to Pp. to apply to a court with jurisdiction and authority. The court acts out of sequence in the case.

 

  • If you wish to file a complaint regarding data management, you can do so at the National Authority for Data Protection and Freedom of Information, at the following contact details: headquarters: 1125 Budapest, Szilágyi Erzsébet fasor 22/C.; mailing address: 1530 Budapest, Pf.: 5. Phone: 06-1/391-1400; fax: 06-1/391-1410; e-mail address: ugyfelszolgalat@naih.hu; website: www.naih.hu.

 

 

20. Authority cooperation

 

  • The Data Controller will only hand over data that is absolutely necessary to achieve the goal specified by the requesting authority, and if the Data Controller receives an official request from the authorized authorities, it will obligatorily hand over the specified personal data.

 

2023.04.03.

Link