1) Purpose of this Notice
The purpose of this Privacy Notice is to define the data protection and data processing principles applied by Charis Foundation (registered office: 9172 Győrzámoly, dr. Pécsi Gyula u. 31., hereinafter referred to as the “Service Provider”), as well as to outline its data protection policy and ensure that the rights of data subjects are respected during the processing of their personal data.
The Service Provider operates a webshop at www.awme.hu (hereinafter referred to as the “Webshop”), where it processes the personal data of visitors, registered users, customers, and newsletter subscribers.
2) Data Controller
The data controller is the Service Provider:
- Name: Charis Foundation
- Registered office: 9172 Győrzámoly, dr. Pécsi Gyula u. 31.
- Mailing address: 9172 Győrzámoly, dr. Pécsi Gyula u. 31.
- Phone: +36 96 604 112, +36 30 474 9631
- Email: awme@awme.hu
3) Categories of Personal Data Processed
3.1) Registration
To make purchases in the Webshop and to access certain wholesale or professional pricing, users are required to create an account (registration). Registration is necessary for placing orders and constitutes a precondition for entering into a contract.
- Purpose of processing: identification of customers, facilitating purchases, sending personalized newsletters
- Legal basis: consent of the data subject (Article 6(1)(a) GDPR)
- Data processed: username, email address, name, billing address (name, address), shipping address (name, address), phone number
- Retention period: until the withdrawal of consent (deletion of the user account)
3.2) Newsletter Subscription
Visitors may subscribe to the newsletter on the website.
- Legal basis: consent of the data subject (Article 6(1)(a) GDPR)
- Data processed: name, email address
- Retention period: until the withdrawal of consent (unsubscribe)
3.3) Cookies
The Webshop uses cookies during its operation. Some cookies are essential for the proper functioning of the Webshop and for ensuring user convenience. Other cookies (e.g. those provided by third parties) are used for statistical analysis (such as Google Analytics).
Google Analytics is used to collect information about how visitors use the website. These cookies do not identify users personally (even IP addresses are only partially recorded). They collect information such as:
- pages visited
- clicks within the website
- number of pages viewed
- session duration
- error messages encountered
This information is used to improve the website and enhance the user experience.
3.4) Order Processing
The Webshop allows users to place orders for products offered by the Service Provider. Orders and invoices are stored in the Webshop system and related administrative systems.
- Legal basis: consent of the data subject (Article 6(1)(a) GDPR) and legal obligation under accounting laws
- Data processed: name, shipping address, billing address, email address, phone number, date
- Retention period:
- orders: up to 2 years (or as specified by the user)
- invoices: 8 years (in accordance with applicable accounting laws)
3.5) Technical Data
The web server operating the Webshop logs technical data for security and development purposes, including:
- visited URLs
- IP address
- browser information
These data are automatically deleted after 60 days.
4) Access to Data, Data Transfers, Data Processing
- Personal data is primarily accessed only by employees of the Service Provider
- Data is not disclosed or made available to third parties, except when required by law
- External data processors may be engaged for operating the Webshop and fulfilling orders (e.g. accountants, delivery services, IT providers, financial service providers)
Data Processors:
- Website management: Kálmán Mónika, 2310 Szigetszentmiklós, Irtás u. 9.
- Courier service: GLS Hungary, 2351 Alsónémedi, GLS Európa u. 2.
- Web hosting: ICON MÉDIA Kft., 6000 Kecskemét, Csóka u. 26.
5) Data Storage and Security
Personal data is stored electronically on servers operated by ICON MÉDIA Kft. and, in the case of orders and related documentation, also in the Service Provider’s administrative systems.
The Service Provider takes all reasonable technical and organizational measures to ensure the secure operation of its systems and the protection of personal data.
6) Handling of Data Breaches
The Service Provider shall report any personal data breach to the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of individuals.
If the breach is likely to result in a high risk, the affected individuals will be informed without undue delay. The notification will include a clear description of the nature of the breach and the information required under Article 34(2) of the GDPR.
7) Rights of Data Subjects
Data subjects have the right to:
- request information about their personal data
- request correction, modification, or deletion of their data
- request restriction of processing
- object to the processing of their personal data
Requests can be submitted via email at: awme@awme.hu
8) Legal Remedies
Data subjects may contact the Service Provider regarding their requests at awme@awme.hu or by post at the address provided above.
If a request is rejected or not fulfilled, the data subject may lodge a complaint with the competent supervisory authority or seek legal remedy before a court in accordance with the GDPR.
In Hungary, the competent authority is:
National Authority for Data Protection and Freedom of Information (NAIH)
Data subjects are entitled to all rights and remedies provided under Articles 77–82 of the GDPR.