STRAMM-AIR Ipari és Szolgáltató Kft. (TAX NUMBER: 12815526-2-08, COMPANY REGISTRATION NUMBER: 08-09-010266, Address: 9012 Győr, Sokorópátkai u. 93., Hungary) (hereinafter: Data Controller), during the operation of the www.stramm-air.hu website (hereinafter: Website), processes the data of visitors, users of the Website, and users of services available on the Website (hereinafter collectively: Data Subject).
In connection with data processing, the Data Controller hereby informs Data Subjects about personal data processed on the Website, its principles and practices followed in processing personal data, as well as the means and options available to Data Subjects for exercising their rights.
By using the Website, the Data Subject accepts the contents of this Privacy Policy and consents to the processing of data specified below.
- Definitions
- Data Subject: any specified natural person identified or—directly or indirectly—identifiable on the basis of personal data;
- Personal Data: data that can be associated with the data subject—in particular the name, identification mark, and knowledge characteristic of one or more physical, physiological, mental, economic, cultural, or social identities of the data subject—as well as conclusions regarding the data subject that can be drawn from the data;
- Consent: a voluntary and explicit expression of the data subject’s will, based on adequate information, by which they give their unambiguous agreement to the processing of personal data concerning them—either fully or extending to specific operations;
- Objection: a statement by the data subject objecting to the processing of their personal data and requesting the termination of data processing or the erasure of processed data;
- Data Controller: the natural or legal person or organization without legal personality who or which independently or jointly with others determines the purpose of data processing, makes and executes decisions regarding data processing (including instruments used), or has them executed by a commissioned data processor;
- Data Processing: regardless of the procedure used, any operation or set of operations performed on data, in particular collection, recording, registration, organization, storage, alteration, use, retrieval, transfer, disclosure, alignment or combination, blocking, erasure, and destruction, as well as preventing further use of the data;
- Data Processing Activity (Data Processor Operations): technical tasks related to data processing operations, regardless of the method and instrument used to carry out operations and the location of application, provided that the technical task is performed on the data;
- Data Processor: the natural or legal person or organization without legal personality who or which processes data on the basis of a contract concluded with the Data Controller—including contracts concluded pursuant to statutory provisions;
- Data Transfer: making data accessible to a specified third party;
- Disclosure: making data accessible to anyone;
- Data Erasure: making data unrecognizable in such a manner that its recovery is no longer possible;
- Data Blocking: providing data with an identifying mark to restrict its further processing permanently or for a specified period;
- Data Destruction: total physical destruction of the data carrier containing the data;
- Third Party: any natural or legal person or organization without legal personality who or which is not identical to the data subject, the data controller, or the data processor.
- Purpose of Data Processing
The Data Controller stores and processes data provided by the Data Subject during contact strictly for specific purposes, solely to provide services available on the Website (quotation requests, professional inquiries), maintain contact, and identify the user. Automatically recorded data serves purpose-bound statistical generation and technical development of the IT system. The Data Controller does not and shall not use personal data provided for purposes other than those defined above.
The release of personal data to third parties or authorities—unless required by law with binding force—is only possible with the prior, explicit consent of the Data Subject. In any case where the Data Controller intends to use provided data for a purpose other than the original purpose of data collection, it shall inform the Data Subject, obtain their prior, explicit consent, or provide them with the opportunity to prohibit such use.
- Legal Basis for Data Processing
Data processing carried out by the Data Controller takes place based on the voluntary consent of the Data Subject pursuant to Section 5 (1) a) of Act CXII of 2011 on Informational Self-Determination and Freedom of Information (hereinafter: Info Act), as well as Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services.
The Data Controller does not verify the accuracy or truthfulness of personal data provided to it. The person/Data Subject providing the data is solely responsible for its correctness. Upon specifying an email address, any Data Subject assumes responsibility that services from that email address will be used exclusively by them. In light of this responsibility, all liability associated with inquiries made from a given email address rests solely on the Data Subject who provided that email address.
- Details of the Data Controller
- Company Name: STRAMM-AIR Ipari és Szolgáltató Kft.
- Tax Number: 12815526-2-08
- Company Registration Number: 08-09-010266
- Address: 9012 Győr, Sokorópátkai u. 93., Hungary
- Email: info@stramm-air.hu
- Duration of Data Processing
5.1. Data provided via electronic contact form and email Processing of personal data provided when sending the contact form or via direct email inquiries lasts until the Data Subject requests the deletion of data provided in this manner. Data deletion may take place at any time following the submission of a request for deletion (by mail or email). In this case, the deadline for deleting data is 5 business days following receipt of the request. The obligation to erase does not apply to mandatory data retention required by law (e.g., accounting regulations).
5.2. Registration data Processing of personal data required during registration lasts until the Data Subject requests the deletion of their registration. Deletion of registration may take place at any time following the submission of a request for deletion (by mail or email). In this case, the deadline for deleting data is 5 business days following receipt of the request.
5.3. Technical data Logged data is stored by the system for 2 years from the date of logging—with the exception of the date of the last visit, which is automatically overwritten.
- Scope of Processed Personal Data
6.1. Data provided during contact To make contact and request a quote via the Website, the Data Subject may provide the following data: Name, Phone Number, Email Address, Company Name, Message Text.
6.2. Data required during registration To use services on the Website, the Data Subject must provide the following data: Name, Phone Number, Email, Company Name, Billing Address, Shipping Address.
6.3. Technical data Data of the Data Subject’s connecting computer generated during the use of the service and recorded by the Data Controller’s system as an automatic result of technical processes. These include, in particular, the date and time of the visit, the IP address of the Data Subject’s computer, browser type, and the address of the viewed and previously visited website.
Data recorded automatically is logged by the system without any special statement or action by the Data Subject upon entry or exit. This data cannot be linked to other personal user data—except in cases mandated by law. Only the Data Controller and the Hosting Provider have access to this data.
The Data Controller may collect data on Data Subject activity, which cannot be combined with other data provided by the Data Subject, nor with data generated when using other websites or services.
The HTML code of the Website may contain links coming from and pointing to external servers independent of the Data Controller. The providers of these links are capable of collecting user data due to direct connection to their servers.
External servers assist in independent measurement and auditing of Website traffic and other web analytics data (Google Analytics). The data controllers can provide detailed information regarding the management of measurement data to the Data Subject (Contact: Google Analytics). If the Data Subject does not wish Google Analytics to measure the above data in the described manner and purpose, they can install the browser add-on blocking this.
6.4. Cookies To provide customized service, the Data Controller and designated external service providers place and read back a small data packet, a so-called cookie, on the Data Subject’s computer. If the browser sends back a previously saved cookie, the service provider managing the cookie has the opportunity to connect the Data Subject’s data saved during current visits with previous ones, but exclusively regarding its own content.
The Data Controller uses the following cookies:
- Session cookie: Session cookies are automatically deleted after the Data Subject’s visit. These cookies serve to allow the Data Controller’s Website to operate more efficiently and securely, making them essential for certain website functions to work properly.
- Persistent cookie: The Data Controller also uses persistent cookies for a better user experience (e.g., providing optimized navigation). These cookies are stored for a longer period in the browser’s cookie file. The duration depends on the settings applied by the Data Subject in their web browser.
- Cookie used for password-protected sessions.
- Security cookie.
The “Help” function in the menu bar of most browsers provides information on how the Data Subject can disable cookies, accept new cookies, or turn off other cookies in their browser.
The Website uses Google AdWords remarketing tracking codes. This allows visitors to the site to be reached later with remarketing ads on websites within the Google Display Network. The remarketing code uses cookies to tag visitors. Website Users can disable these cookies by visiting Google’s Ad Settings manager and following the instructions provided there. Following this, personalized offers from the Service Provider will not appear for them.
More information about cookies: https://silktide.com/tools/cookie-consent/docs/
More information about Google Analytics: https://www.google.hu/intl/hu/analytics/
- Entities Authorized to Access Data, Data Transfer, Data Processing
Primarily, the Data Controller and internal staff of the Data Controller are entitled to access the data; however, they shall not publish or transfer it to third party/parties.
In addition to the above, transfer of personal data concerning the User may only take place in cases mandatory under law or based on the User’s consent.
Details of the Hosting Provider (Data Processor):
- Name: Tárhely.Eu Szolgáltató Kft.
- Headquarters: 1144 Budapest, Ormánság utca 4. X. em. 241., Hungary
- Company Registration Number: 01-09-904961
- Tax Number: 14457814-2-42
- Email address: support@tarhely.eu
- User Rights and Enforcement Options
8.1. Right to information The Data Subject is entitled to request information at any time regarding personal data concerning them processed by the Data Controller.
Upon request of the Data Subject, the Data Controller provides information regarding data processed concerning them, the purpose, legal basis, and duration of processing, as well as who receives or received their data and for what purpose. The Data Controller shall provide the requested information in writing within a maximum of 30 days from the submission of the request.
The Data Subject may turn to the Data Controller’s staff with any question or comment related to data processing via the info@stramm-air.hu email address.
8.2. Data Subject may request erasure, rectification, or blocking of data The Data Subject is entitled at any time to request the correction of incorrectly recorded data or their erasure via the Data Controller’s contact details. The Data Controller shall erase the data within 5 business days of receiving the request; in this case, data cannot be recovered. Erasure does not apply to data processing necessary under law (e.g., accounting regulations), which the Data Controller shall retain for the required period.
Furthermore, the Data Subject may request the blocking of their data. The Data Controller blocks personal data if requested by the data subject or if, based on available information, it can be assumed that erasure would violate the Data Subject’s legitimate interests. Personal data blocked in this way may only be processed for as long as the purpose of data processing that excluded the erasure of personal data exists.
The Data Subject and all those to whom the data was previously transferred for data processing purposes must be notified of rectification, blocking, and erasure. Notification may be omitted if this does not violate the User’s legitimate interest considering the purpose of data processing.
If the data controller does not comply with the data subject’s request for rectification, blocking, or erasure, it shall communicate the factual and legal reasons for refusing the request in writing within 30 days of receiving the request.
8.3. Data Subject may object to the processing of personal data The Data Subject may object to the processing of their personal data. The Data Controller shall examine the objection within the shortest possible time from the submission of the request, but within a maximum of 15 days, make a decision on its merit, and inform the applicant in writing of its decision.
8.4. Legal Remedies Under the Info Act and the Civil Code (Act V of 2013), the Data Subject may:
- Turn to the National Authority for Data Protection and Freedom of Information (1055 Budapest, Falk Miksa utca 9-11., www.naih.hu), or
- Enforce their rights before a court.
If the Data Subject provided third-party data to utilize the service or caused damage in any way during the use of the Website, the Data Controller is entitled to enforce damages against the Data Subject. In such cases, the Data Controller shall provide all reasonable assistance to investigating authorities to establish the identity of the infringing person.
- Use of Email Addresses
The Data Controller pays special attention to the lawfulness of using electronic mail addresses it manages, thus using them to send emails only in specified ways. The management of email addresses primarily serves to identify the Data Subject and maintain contact during inquiries and price quotations.
- Data Security
The Data Controller undertakes to ensure data security and take technical measures to ensure that recorded, stored, and processed data is protected, doing everything possible to prevent its destruction, unauthorized use, and unauthorized alteration. It also undertakes to call upon any third parties to whom data may be transferred or handed over to fulfill their obligations in this regard.
- Other Provisions
The Data Controller reserves the right to unilaterally modify this Privacy Policy upon prior notice to Data Subjects—notified via the Website interface. Following the entry into force of the modification, the Data Subject accepts the provisions contained in the modified Privacy Policy by implied conduct through the use of the Website.