Data management policy

Please read the Data Processing Policy carefully before using the Webshop, and only use our services if you agree with all of its points.

1. Introduction

The purpose of this Data Management Policy (hereinafter: Policy) is to set out the data management principles applied by the MATOS.HU webshop (hereinafter: Webshop) and the Webshop’s data protection policy, which the operator of the Webshop, Good Biom Dental Kft, tax number: 32471410-2-41, company registration number: 01-09-425903, as the data controller, recognizes as binding upon itself.

2. Legal basis for data processing

When processing data, the Webshop complies with the provisions of the following laws:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR)
  • Act CXII of 2011 on the right to self-determination in information and freedom of information (Infotv.)

3. Purpose and legal basis of data processing

3.1. Purpose of data processing:

  • Management of customer registrations
  • Fulfillment and delivery of orders
  • Invoicing and payment processing
  • Customer contact and customer service
  • Marketing activities and sending newsletters (based on the customer’s consent)

3.2. Legal basis for data processing:

  • The customer’s consent to data processing (GDPR Article 6(1)(a))
  • Performance of a contract (GDPR Article 6(1)(b))
  • Compliance with a legal obligation (GDPR Article 6(1)(c))
  • Legitimate interests (GDPR Article 6(1)(f))

4. Scope of data processed

4.1. Data provided during customer registration:

  • Name
  • Email address
  • Password (stored in encrypted form)
  • Phone number
  • Billing and shipping address

4.2. Data provided during order fulfillment:

  • List of products ordered
  • Payment details (credit card details are not stored by the Webshop; payment is made via the K&H banking interface)

4.3. Data provided for marketing purposes:

  • Name
  • Email address
  • Consent to marketing communications

5. Data retention period

5.1. The Webshop retains the data provided during customer registration for the duration of the registration. After the data processing authorization expires, the data controller will use an IT program to make the registered personal data unrecognizable in a way that can’t be reversed. After that, the data can’t be restored.

5.2. We keep the data needed to fulfill orders for 8 years, based on the relevant accounting laws. The data controller shall render the recorded personal data unrecognizable in a manner that cannot be restored using an IT program after the termination of the data processing authorization. After that, the data cannot be restored.

5.3. In the case of data processing for marketing purposes, we retain the data until the consent is withdrawn.

6. Access to data and data security

6.1. The data is processed by the Webshop staff and the data processors commissioned by them (hereinafter referred to as data controllers), who are obliged to treat the data confidentially and comply with data protection regulations.

6.2. In order to ensure data security, we use appropriate technical and organizational measures to protect data from unauthorized access, modification, disclosure, and destruction.

6.3 When processing personal data, the Company uses the following data processors exclusively for technical tasks:

name of data processor: Sybell Informatika Kft.

address: 1158 Budapest, Késmárk u. 7/B 2. em. 206.

company registration number: 01-09-293034

purpose of data processing: hosting service provider

name of data processor: SW-Logic Kft.

address: 1095 Budapest, Soroksári út 48.

company registration number: 01-09-331260

purpose of data processing: website operator

name of data controller: KBOSS.hu Kft. (szamlazz.hu)

address: 1031 Budapest, Záhony utca 7.

company registration number: 01-09-303201

Purpose of data processing: billing information service

7. Rights of data subjects

7.1. Right of access: The customer has the right to request information about their personal data processed by us and the manner of its processing.

7.2. Right to rectification: The customer has the right to request the rectification of inaccurate or incomplete data.

7.3. Right to erasure: The customer has the right to request the erasure of their data if there is no legal obligation to retain the data.

7.4. Right to restriction of processing: The customer may request the restriction of processing in certain cases, for example if they dispute the accuracy of the data.

7.5. Right to data portability: The customer has the right to request that the data they have provided be made available to them in a machine-readable format or transferred to another data controller.

7.6. Right to object: The customer may object to data processing at any time if the data processing is based on legitimate interests.

8. Remedies

If the customer feels that the Webshop has violated their rights, they may contact the following remedies:

  • National Authority for Data Protection and Freedom of Information (NAIH)
  • Initiation of court proceedings

9. Final provisions

9.1. The Webshop reserves the right to amend the Data Processing Policy and will notify users of any changes in an appropriate manner.9.2. The current version of the Data Processing Policy is available on the Matos.hu website.