PRIVACY POLICY
www.miastudio.hu
Privacy Policy
-
The purpose of this privacy notice (hereinafter referred to as “Notice“) is to set out the information collected by Khaloo Bagheri Mahshid E.V. (hereinafter referred to as “Controller“) through the website www.miastudio.hu, and to ensure that the constitutional principles of data protection, the right of informational self-determination and the requirements of data security are met, and that, within the framework of the law, everyone has access to his/her personal data, can understand the circumstances of their processing, and prevent unauthorized access, alteration and unauthorized disclosure of data. In addition, this Notice is intended to provide information to data subjects on the Controller’s data management practices.
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Regulation (EC) No 95/46/EC (General Data Protection Regulation; hereinafter “GDPR“)
- Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (hereinafter referred to as “Infotv.“)
- Act V of 2013 on the Civil Code (hereinafter “Civil Code”)
- Act CXXX of 2016 on the Code of Civil Procedure (hereinafter referred to as the “Code”)
- Act CVIII of 2001 on certain aspects of electronic commerce services and information society services (hereinafter referred to as “E-commerce Act“)
The current data of the Controller are the following:
- Name: Khaloo Bagheri Mahshid E.V.
- Seat: 1085 Budapest, József körút 69. fsz. 10105 Oktyabr kör körút, Győr boulevard 69, Budapest, office 1. door 1.
- Registration number: 59950873
- Tax number: 90649257-1-42
- Registering authority: Hungarian Central Office for Administrative and Electronic Public Services
- Phone number: +36305252943
- E-mail address: contact@miastudio.hu
-
Data subjects are obliged to provide all the information to the best of their knowledge and accurately.
-
If the data subject does not provide his or her own personal data, the data subject is obliged to obtain the consent of the data subject.
-
If the Controller transfers the data to processors or other third parties, the Controller shall keep a record of these. The record of the data transfer shall include the recipient of the data transfer, the method and time of the transfer and the scope of the data transferred.
-
Data processing related to certain activities of the Controller:
-
-
Shopping in the webshop
-
Legal basis for processing: performance of a contract
Data processed: name, address, delivery address, chosen delivery option and payment method
Purpose of data processing: sale and delivery of the products offered on the website
Deadline for deleting data: 9 years after the order is placed
Possible consequences of failure to communicate the data: the impossibility to conclude or perform the contract
-
-
Billing
-
Legal basis for processing: compliance with a legal obligation
Data processed: name; address
Purpose of processing: to comply with a legal obligation
Purpose of the transfer: to fulfil a legal obligation
Deadline for deletion: 9 years after the invoice is issued
Possible consequences of non-disclosure: there is no legal obligation to withhold data
-
- Cookie management of the Controller’s website
-
-
To facilitate navigation and thus the use of the website by recording the visitor’s preferences and usage habits,
-
improve the user experience by collecting information about how visitors use the website, which sub-pages they visit or use most often. This will help us to know how to provide an even better user experience when they visit our site again,
-
collecting statistics and analysing them to understand how visitors use other online services in addition to the website, which we can then improve,
-
further development and transparency of the website to meet the needs of visitors
-
where appropriate, targeted advertising to show the most relevant offers to the visitor.
-
“Session cookies” are necessary for browsing the website, for using certain basic functions, including the ability to record the actions taken by the visitor on a particular page, function or service. Without the use of “session cookies”, a smooth use of the website cannot be guaranteed. They are valid for the duration of the visit and are automatically deleted at the end of the session or when the browser is closed.
The proper functioning of the website is ensured in accordance with the legislation in force.
The “session cookies” used by the website are:
|
Cookie name |
Purpose of the cookie |
Storage time |
|
wp-wpml_current_language |
WordPress multilingual plugin sets this cookie to store the current language/language settings. |
At the end of a session or by closing the browser. |
-
-
“Cookies for statistics”
-
We try to fill the website with the content that visitors prefer, and to do this we need to collect statistics on visitor habits.
The website uses the cookies necessary to produce the following statistics:
|
Cookie name |
Purpose of the cookie |
Storage time |
|
sbjs_migrations
|
Sourcebuster sets this cookie to identify the source of the visit and stores information about user actions in the cookies. This analytical and behavioural cookie is used to improve the visitor experience on the website. |
At the end of a session or by closing the browser.
|
|
sbjs_current_add
|
Sourcebuster sets this cookie to identify the source of the visit and stores information about user actions in the cookie. This analytical and behavioural cookie is used to improve the visitor experience on the website. |
At the end of a session or by closing the browser.
|
|
sbjs_current
|
Sourcebuster sets this cookie to identify the source of the visit and stores information about user actions in the cookie. This analytical and behavioural cookie is used to improve the visitor experience on the website. |
At the end of a session or by closing the browser. |
|
sbjs_first
|
Sourcebuster sets this cookie to identify the source of the visit and stores information about user actions in the cookie. This analytical and behavioural cookie is used to improve the visitor experience on the website. |
At the end of a session or by closing the browser. |
|
sbjs_udata
|
Sourcebuster sets this cookie to identify the source of the visit and stores information about user actions in the cookie. This analytical and behavioural cookie is used to improve the visitor experience on the website. |
At the end of a session or by closing the browser. |
|
sbjs_session
|
Sourcebuster sets this cookie to identify the source of the visit and stores information about user actions in the cookie. This analytical and behavioural cookie is used to improve the visitor experience on the website. |
1 hour |
|
woosw_key |
7 days |
|
|
wc_cart_hash_48822a8341b3c3e2468e487372488cb9-en |
Until deleted |
Modern browsers allow you to change the “cookie settings”. Some browsers automatically accept “cookies” by default, but this setting can be changed to prevent automatic acceptance in the future. If you change this setting, the browser will offer you the option to “set cookies” each time you visit.
The Controller will not remember any identifier or password even if “cookies” are enabled. The visitor can use the services in complete safety even if he accepts “cookies”.
Please note that since the purpose of “cookies” is to support and facilitate the usability and processes of the website, we cannot guarantee that a visitor will be able to use all the functions of the website to their full extent if “cookies” are disabled. The website may then function differently than intended in the browser.
Google Chrome
Microsoft Internet Explorer 11
Microsoft Internet Explorer 10
-
Data subjects may at any time request information in writing from the Controller about the processing of their personal data processed by the Controller, request erasure or modification, and withdraw their consent previously given, using the contact details provided in point 3.
-
The data subject may not exercise his or her right to erasure in the case of processing required by law.
-
Content of the right to information: at the request of the data subject, the Controller shall provide the data subject with the information listed in Articles 13 and 14 of the GDPR and the information referred to in Articles 15 to 22 and 34 of the GDPR in a concise and plain language.
-
Content of the right of access: upon request of the data subject, the Controller shall provide information on whether or not data processing concerning him or her is in progress at the Controller. If the Controller is processing data relating to the applicant, the data subject shall have the right of access to the following information:
-
-
Personal data relating to him or her;
-
the purpose(s) of the processing;
-
the categories of personal data concerned;
-
the persons to whom the data subject’s data have been or will be disclosed;
-
the duration of data storage;
-
the right to rectification, erasure and restriction of processing;
-
the right to apply to a court or supervisory authority;
-
the source of the data processed;
-
profiling and/or automated decision-making, and the details and practical implications of their use;
-
the transfer of processed data to a third country or international organisation.
-
-
In the event of a request for data as described above, the Controller shall provide the data subject with a copy of the data processed by the Controller in accordance with the request. Upon specific request, it is possible to request the Controller to deliver the data by electronic means.
-
The Controller charges an administration fee of HUF 1000,- per page for each additional copy.
-
The deadline for the release of the requested data is 30 days from the date of receipt of the request.
-
The right to rectification: the data subject may request the rectification of inaccurate data relating to him or her processed by the Controller.
-
Right to erasure: If any of the following grounds apply, the Controller shall, at the data subject’s request, erase the data concerning the data subject as soon as possible and in any event within 5 working days:
-
-
The data was processed unlawfully (without legal authorisation or personal consent);
-
the processing is unnecessary for the achievement of the original purpose;
-
the data subject withdraws consent to the processing and the Controller has no other legal basis for the processing;
-
the data in question were collected in connection with the provision of information society services;
-
the personal data must be erased in order to comply with the legal obligations applicable to the Controller.
-
-
The erasure of data will not be possible if the processing is still necessary for any of the following:
-
-
Further processing is necessary to comply with the legal requirements applicable to the Controller;
-
necessary for the exercise of the right to freedom of expression and information;
-
in the public interest;
-
for archiving, scientific, research or statistical purposes;
-
to assert or defend legal claims.
-
-
Right to restriction of processing: if any of the following grounds apply, the Controller shall restrict processing at the request of the data subject:
-
-
If the data subject contests the accuracy of the data relating to him or her, the restriction shall apply for the period of time until the accuracy or correctness of the data in question can be verified to the satisfaction of the data subject;
-
the data processing is unlawful, but the data subject requests that it not be erased, but only that the processing be restricted;
-
the data are no longer necessary for the purposes of processing, but the data subject requests their retention for the purpose of exercising or defending legal claims;
-
-
Where the Controller imposes a restriction on any data processed, it shall process the data concerned during the period of the restriction only if and to the extent that:
-
-
The data subject consents to this;
-
necessary to assert or defend legal claims;
-
necessary to assert or defend the rights of another person;
-
necessary for the protection of the public interest.
-
-
Right of withdrawal: the data subject has the right to withdraw his or her consent given to the Controller at any time, in writing. In the event of such a request, the Controller shall immediately and permanently delete all data which it has processed in relation to the data subject and the further storage of which is not required by law or is not necessary for the exercise or defence of legitimate interests. The lawfulness of the processing carried out until the withdrawal of consent shall not be affected by such withdrawal.
-
The right to data portability: the data subject has the right to request the transfer of data relating to him or her by the Controller to another controller in a commonly used format readable by computer software. The Controller shall comply with the request as soon as possible and in any event within 30 days.
-
Automated decision making and profiling: the data subject has the right not to be subject to a decision based solely on automated processing (such as profiling) which would have legal effects concerning him or her or otherwise adversely affect him or her. This right shall not apply if:
-
-
the processing is necessary for the conclusion or performance of a contract between the data subject and the controller;
-
the data subject explicitly consents to the use of such a procedure;
-
is authorised by law;
-
necessary to assert or defend legal claims.
-
The e-mails received during the contact with the Controller and their contents (in particular the name and address of the sender, the date, attachments) will be stored by the Controller for 5 years and then deleted. If, in the unilateral opinion of the Controller, the message is not relevant, it will be deleted within 30 days.
-
The Controller shall keep the data it processes, both in paper and electronic form, at its headquarters. The hosting provider also has access to the data stored in electronic form, but only for the purpose of providing IT support. The name of the hosting provider is Websupport Hungary Ltd., with seat at H-1119 Budapest, Fehérvári út 97-99., telephone number: +36 1 700 2323, e-mail: info@mhosting.hu
-
Exceptions to point (1) are data stored by the Controller’s processors, which are kept at the data processors’ headquarters.
-
The Controller uses an IT system for its operations that ensures that the data:
-
be verifiable (data integrity);
-
the authenticity of the data (authenticity of processing);
-
be accessible to those who are entitled to them (availability);
-
and to be protected against unauthorised access (data confidentiality).
-
-
Data protection covers in particular:
-
-
unauthorised access;
-
to change;
-
for transmission;
-
for deletion;
-
for disclosure;
-
accidental damage;
-
accidental destruction;
-
and inaccessibility due to changes in the technology used.
-
-
The Controller shall use state-of-the-art solutions providing an adequate level of security to protect the electronically processed data. In assessing adequacy, particular emphasis shall be placed on the level of risk posed by the processing of the data by the Controller. IT security shall ensure that the data stored cannot be directly attributed or linked to data subjects (unless permitted by law).
-
The Controller shall ensure in the course of its processing that:
-
-
the authorised person can access the data when he or she needs it;
-
only those who are authorised to access the information;
-
the accuracy and completeness of the information and the processing method are protected.
-
-
The Controller and any data processors it may use shall at all times protect its information systems against fraud, espionage, viruses, intrusions, damage and natural disasters. The Controller (or its processor) shall apply server-level and application-level security procedures.
-
Messages transmitted to the Controller via the Internet, in whatever form, are at increased risk of network threats that could lead to modification of information, access by unauthorized persons, or other illegal activity. However, the Controller will do everything reasonably practicable and reasonable in the state of the art to prevent such threats. To this end, the systems in place are monitored to record security anomalies, to obtain evidence of a security incident and to verify the effectiveness of the precautions taken.
-
If the Controller receives a request pursuant to Articles 15-22 of the GDPR, the Controller shall inform the data subject in writing of the action taken on the request as soon as possible and in any event within 30 days.
-
Where justified by the complexity of the request or other objective circumstances, the above deadline may be extended once, up to a maximum of 60 days. The Controller shall notify the data subject in writing of any extension of the time limit, together with the reasons for the extension.
-
The controller shall provide the information free of charge unless:
-
-
the data subject repeatedly requests information/action on substantially unchanged content;
-
the application is manifestly unfounded;
-
the request is excessive.
-
-
In cases under point (3), the Controller is entitled to:
-
-
refuse the request;
-
to make the execution of the request subject to the payment of a reasonable fee.
-
-
If the applicant requests the data to be provided on paper or on an electronic storage medium (CD or DVD), the Controller will provide one copy of the data concerned free of charge in the requested format (unless the chosen platform would present a disproportionate technical difficulty). For each additional copy requested, an administration fee of HUF 1000 per page/CD-DVD will be charged.
-
The Controller shall notify any rectification, erasure or restriction carried out by it to all persons to whom the data concerned were previously disclosed, unless such notification is impossible or involves a disproportionate effort.
-
If the data subject so requests, the Controller shall inform him/her of the persons to whom his/her data have been disclosed.
-
The controller shall provide its response to the request in electronic form, unless:
-
-
the data subject explicitly requests a different response and this does not result in an unreasonably high additional cost for the Controller;
-
the Controller does not know the electronic contact details of the data subject.
-
-
If any data subject suffers pecuniary or non-pecuniary damage as a result of a breach of the data protection legislation, he or she has the right to claim compensation from the Controller and/or the Data Processor. Where both the Controller and the processor(s) are involved in the infringement, they shall be jointly and severally liable for the damage suffered.
-
The data processor shall be liable for the damage suffered only if it has breached the provisions of the applicable data protection legislation specifically applicable to data processors or if the damage has occurred as a result of its failure to comply with the instructions of the Controller.
-
The Controller or any data processor shall be liable only if they cannot prove that they are not responsible for the event or circumstance giving rise to the damage.
-
If the data subject considers that his or her rights have been infringed by the Controller and/or the processors, he or she has the right to apply to the competent court under the Civil Code. The court shall rule on the matter out of turn.
-
If the data subject wishes to lodge a complaint about the processing of personal data, he or she may do so at the National Authority for Data Protection and Freedom of Information, at the following contact details: headquarters: 1055 Budapest, Falk Miksa utca 9-11; postal address: 1363 Budapest, Pf.: 9. Phone: 06-1/391-1400; fax: 06-1/391-1410; e-mail:ugyfelszolgalat@naih.hu ; website: www.naih.hu.
-
The Controller shall, where it receives a formal request from the competent authorities, provide the personal data concerned on a mandatory basis.
-
The Controller shall only disclose data in the cases referred to in point (1) which are strictly necessary for the purpose of achieving the aim stated by the requesting authority.
Budapest, 17 June 2025.