(You can read our General Terms and Conditions here.)
This Privacy Notice explains clearly and in detail, before processing begins, how Server Line Kft. (the “Controller”) handles the personal data of website visitors, registered users, enquirers and customers (“Data Subjects”), their rights and available remedies. It also applies where services are requested by telephone, email or in person at 1087 Budapest, Asztalos Sándor út 3.
It contains the Controller’s internal data-protection rules and measures and is published on the website. A copy may be requested from customer service. It also covers the other websites operated by the Controller listed in the governing Hungarian notice. This English page is a translation for information; if interpretations differ, the Hungarian version governs.
Definitions
“Personal data” means any information relating to an identified or identifiable natural person, including identification by name, number, location data, online identifier or factors specific to physical, physiological, genetic, mental, economic, cultural or social identity.
“Processing” means any operation performed on personal data, whether automated or not, including collection, recording, organisation, structuring, storage, alteration, retrieval, consultation, use, disclosure, transmission, combination, restriction, erasure or destruction.
“Controller” means the person or body that determines the purposes and means of processing, alone or jointly. “Processor” means a person or body that processes personal data on the Controller’s behalf.
1. Controller details
Server Line Szolgáltató Kft.
Registered office: 2340 Kiskunlacháza, Sellő u. 140., Hungary
Branch: 1087 Budapest, Asztalos Sándor út 3., Hungary
Company registration number: 13-09-154514
Tax number: 23829808-2-13
Represented by: Zsolt Gerlich, Managing Director
Telephone: +36 1 210 7260
Email: info@serverline.hu
2. Processors and recipients
Hosting provider: Tárhely.Eu Szolgáltató Kft., +36 1 789 2789, support@tarhely.eu, 1538 Budapest, PO Box 510.
Courier for delivery: GLS General Logistics Systems Hungary Csomag-Logisztikai Kft., 2351 Alsónémedi, GLS Európa u. 2., info@gls-hungary.com.
Online card-payment provider: OTP Mobil Szolgáltató Kft., 1093 Budapest, Közraktár u. 30–32., ugyfelszolgalat@simple.hu, +36 1/20/30/70 3-666-611. Card details are entered on OTP Mobil’s secure interface and are not disclosed to the Controller. The Controller sends only the amount and transaction identifier.
Accountant acting as an independent controller for accounting documents: KKp Bt., 2340 Kiskunlacháza, Munkácsy M. utca 27., kkpbt@vnet.hu.
Customer and order data are recorded in the Controller’s internally developed CRM running on the hosting provider’s servers. Contracted system administrators may access systems where necessary for installation and maintenance.
3. Principal legislation
Regulation (EU) 2016/679 (“GDPR”); Hungarian Act CXII of 2011 on informational self-determination and freedom of information; and Hungarian Act CVIII of 2001 on electronic commerce and information-society services.
4. Data-processing principles
4.1 Fairness, lawfulness and transparency. Processing is carried out fairly, lawfully and transparently.
4.2 Purpose limitation. Personal data are collected and used only for the purposes stated in this Notice and disclosed only to persons involved in those purposes.
4.3 Data minimisation. Only data that are adequate, relevant and necessary for the service are requested.
4.4 Accuracy. Data Subjects must provide accurate, current data and obtain consent before supplying another person’s data. Incorrect data are corrected or erased promptly when reported.
4.5 Storage limitation. Identifiable data are kept only as long as required for the processing purpose or by law.
4.6 Security. The Controller uses organisational and technical measures, including malware and firewall protection and physical safeguards, to protect data from unauthorised access, disclosure, alteration, loss or destruction. Employees and processors are subject to equivalent duties. Registered users remain responsible for protecting their account and password.
5. Purposes, legal bases, data and retention
Registration and creation of a customer account. Legal basis: consent, GDPR Article 6(1)(a). Data Subjects: registering customers. Data: email address and password. Access: management. Retention: until consent is withdrawn. Recipients: hosting provider and system administrator. Without the data, registration is not possible.
Issuing accounting documents. Legal basis: legal obligation, GDPR Article 6(1)(c). Data: billing name and address, payment method, issue/performance/payment dates, products and net/gross prices and order total. Access: management and customer service. Retention: eight years under Hungarian accounting law. Recipients: accountant and hosting provider. Without the data, an addressed invoice cannot be issued.
Order performance and delivery. Legal basis: performance of a contract, GDPR Article 6(1)(b). Data: customer name, delivery address, email, telephone, order notes, payment and collection method. Access: management, customer service, production and sales. Retention: five years after performance. Recipients: hosting provider and courier. Without the data, an order cannot be placed or delivered.
Contact concerning order performance. Legal basis: performance of a contract. Data: contact name, email and telephone. Access: management and customer service. Retention: erased after performance unless separate consent or another legal basis applies. Recipient: hosting provider.
Newsletter. Legal basis: consent. Data: name and email. Access: management and marketing. Retention: until consent is withdrawn. Recipient: hosting provider. Without the data, newsletters and information about promotions and products cannot be sent.
Complaints and warranty claims. Legal basis: legal obligation. Data may include the claim identifier, name, address, place, time and method of complaint, submitted evidence, description, record details and returned-product information. Access: management and customer service. Complaint records and replies are retained for five years; entries in the customers’ book for two years. No routine external transfer occurs. Without the data, consumer rights cannot be administered.
Answering enquiries. Legal basis: consent. Data: name, email and message. Access: management and customer service. Messages are erased within thirty days after communication ends unless another purpose applies. No routine external transfer occurs.
Where consent is the legal basis, it may be provided by the relevant checkbox online or by a separate email or paper statement. Sending an initial enquiry by email gives consent to processing the personal data in that message for responding. Consent can be withdrawn at any time, without affecting prior lawful processing. Statutory processing and data required for a contract or legitimate legal claims may continue after withdrawal.
6. Cookies and external content
A cookie is a small data file stored by the browser. The website may also use other local browser storage. Strictly necessary cookies operate without consent; optional external content, marketing and conversion measurement remain blocked by default.
6.1 Strictly necessary cookies
PHPSESSID — Set by Server Line Kft. Purpose: secure session identification and operation of sign-in, accounts, forms and essential functions. Lifetime: browsing session. Legal basis: providing the website and user-requested service; prior consent is not required.
site_language — Set by Server Line Kft. Purpose: remember the selected website language. Lifetime: up to one year. Legal basis: storing a user preference and providing the selected language; prior consent is not required.
sl_cookie_consent — Set by Server Line Kft. Purpose: record whether external content, marketing and conversion services were allowed or rejected, together with the settings version and time. Lifetime: up to 180 days. Legal basis: retaining the visitor’s privacy choice; prior consent is not required.
6.2 External content loaded with consent
The following services do not load on a first visit. A connection is created only after consent through “Accept all”, detailed settings or the enable button beside the content. Legal basis: consent under GDPR Article 6(1)(a).
Trustindex customer reviews. Provider: Trustindex Ltd. Purpose: display Google reviews and the aggregate rating for Server Line Kft. Possible data include IP address, browser/device data, viewing time and cookie or local-storage identifiers. Cookie names and lifetimes depend on the provider. Provider privacy notice.
Google Maps. Provider: Google. Purpose: display the Server Line premises on an interactive map. Possible data include IP address, browser/device data, approximate location, usage information and cookie or local-storage identifiers. Processing may also depend on the visitor’s Google account and privacy settings. Google Privacy Policy.
6.3 Marketing and conversion measurement
These technologies load only after prior consent. Selecting “Necessary only” prevents them from starting.
Google Ads and Google tag. Provider: Google. Purpose: measure advertising performance and conversions, compile campaign statistics and, where enabled, create remarketing audiences. Possible data include page title and URL, visit/conversion time, ad-click identifiers, IP address, browser/device data, online identifiers and conversion value/currency. Google may use first- and third-party cookies. Google Privacy Policy.
Meta Pixel (Facebook Pixel). Provider: Meta Platforms Ireland Limited. Purpose: measure Facebook and Instagram advertising, conversions, campaign statistics and create audiences and remarketing audiences. Possible data include the visited page and actions, visit/conversion time, ad-click identifiers, IP address, browser/device data and online identifiers. Meta Privacy Policy.
6.4 Changing or withdrawing consent
Consent can be changed or withdrawn by category at any time through “Cookie settings” in the footer. After withdrawal, affected services do not load on later page views. Cookies previously placed by an external provider can be removed through browser settings. Completely blocking cookies in the browser may restrict essential website functions.
7. Rights of Data Subjects
7.1 Access. You may request information about processing purposes, legal bases, data, processors and complaint rights and receive a copy free of charge. A reasonable fee may be charged for manifestly unfounded or excessive requests (paper copies: HUF 10 per page). The Controller responds in an intelligible form as soon as possible and within the period stated in the governing notice.
7.2 Rectification. You may request correction of inaccurate data and completion of incomplete data. Registered users may update account details online; other requests use the contact method in section 9. A refusal is explained in writing with available remedies.
7.3 Erasure. Data are erased where processing is unlawful, consent is withdrawn and no other basis exists, inaccurate data cannot lawfully be corrected, the purpose has ended, or a court or the Hungarian data-protection authority orders erasure. Erasure on request does not cover data retained under a legal obligation or required for contract performance or legal claims.
7.4 Restriction. You may request restriction while accuracy is verified; where processing is unlawful but erasure is opposed; where the Controller no longer needs the data but they are required for legal claims; or while an objection is assessed.
7.5 Portability. Where processing is based on consent or contract, you may receive data you provided in a machine-readable form or ask for direct transfer to another controller where technically feasible.
7.6 Objection. You may object to processing based on legitimate interests. If the objection prevails, the Controller stops the processing unless compelling lawful grounds or legal claims require it.
8. Remedies
For unlawful processing or refusal of a request, you may contact the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9–11.; postal address 1363 Budapest, PO Box 9; ugyfelszolgalat@naih.hu, or the court competent for your residence or place of stay.
9. Submitting a request
Send requests and withdrawal of consent in writing to info@serverline.hu or Server Line Kft., 1087 Budapest, Asztalos Sándor út 3., Hungary. The Controller investigates without delay and answers within the applicable statutory period. Email requests are considered authentic when sent from an address already recorded for the Data Subject. Additional identification may be requested where identity is uncertain.
10. Personal-data breaches
A breach is accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to personal data. Report a suspected breach immediately using section 9. The Controller notifies NAIH without undue delay and, where feasible, within 72 hours unless the breach is unlikely to risk rights and freedoms, and takes steps to remedy it.
11. Acceptance and amendment
By using the website, Data Subjects acknowledge this Notice. The Controller may amend it unilaterally; the updated version is published on the website.
12. Job applicants
Purpose: selecting a future employee and arranging an interview. Legal basis: consent, GDPR Article 6(1)(a), given separately when submitting a CV. Without consent the application cannot be considered and the CV is erased immediately. Data Subjects: applicants. Data may include name, birth name, place/date of birth, mother’s name, address, contact data, photograph, qualifications and experience. Access: Managing Director. No transfer to third parties. Retention: until the recruitment process ends. Without the data, an application cannot be made.
Effective from: 25 May 2018.
DESIGN AND PRINT – high quality, delivered fast.
Our modern production department, experienced designers and helpful Budapest customer service team are ready to assist you.