Privacy policy

PRIVACY STATEMENT OF VOLTIE KFT.


REGARDING ITS WEBSITE’S, WEBSHOP’S AND MOBILE APPLICATION’S DATA PROCESSING OPERATIONS RELATED TO THE DATA SUBJECT


The present Privacy Statement (hereinafter referred to as: ‘Privacy Statement or Statement’) contains all

information about the data processing operations of Voltie Kft. (hereinafter referred to as: ‘Service

Provider/data controller’) regarding its website’s, the webshop’s and mobile application’s data processing

operations related to the data subjects, in accordance with Regulation (EU) 2016/679 of the European

Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the

processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC

(hereinafter referred to as: General Data Protection Regulation/GDPR) and with the Hungarian Act

CXII of 2011 on the Right to Informational Self-Determination and on Freedom of Information

(hereinafter referred to as ‘Privacy Act’) and other relevant legislation on ensuring the protection of

personal data.


To maintain the security of your personal data, we will take the necessary and appropriate measures to

ensure that while using:


a) on the one hand our website www.voltie.eu for gathering information and purchase on

shop.voltie.eu, and


b) on the other hand our mobile application “Voltie” our users, partners as data subjects shall be provided

with information on the processing of their personal data in a consistent, transparent, comprehensible and

easily accessible way and to facilitate the exercise of your rights as a data subject.


In the present Privacy Statement we describe the online data processing operations related only to the usage

of our website, webshop and our mobile application, as well as we inform you about data processing

regarding the Service Provider's presence in social media.


The use or copying of the whole text or the contents of the present Privacy Statement by any third party

without the consent of the lawyer who drafted the Statement is prohibited. Service Provider may change

the text of the present Statement in accordance with its data management practices.


Please read the contents of this statement carefully and feel confident to contact us with your questions.



CHAPTER I

DESCRIPTION OF DATA CONTROLLER AND DATA PROCESSORS


Data Controller


The publisher of the present Privacy Statement as the data controller/Service Provider:

Voltie Korlátolt Felelősségű Társaság

Registered seat: 1 Tarjáni Street, Tatabánya, 2800, Hungary

Company registration number.: 11-09-030332

Tax Number: 27997695-2-11

Represented by: Ádám Szücs and Tamás Binder solely

Email address: info@voltie.eu

Website: https://www.voltie.eu/


Data Processors


Voltie Kft. as Service Provider is considered to be the data controller when managing the personal

data of the ones concerned as data subjects. We also use data processors to maintain our website and

mobile application and to provide our services and perform our activities. Data processors are bound by

the obligation of confidentiality with regard to the data obtained. Data processor treats personal data in

accordance with the agreement between them and Service Provider to the extent of performing their duties.


Please be advised that, with respect to the data provided through our website and our mobile application,

only the following data processor partners listed may see and manage any data provided by the data subject.


Based on the applicable regulations, in order to entrust a data processor, Service Provider does not need to

ask for the prior consent of the person concerned (data subject), but you need to be informed about

the process. Accordingly, we inform the ones concerned about the contact details of the data

processors, who may handle the given data strictly for the purpose specified by us for the safety of our

users and for faster and more convenient administration during our services.


1. Web hosting partner


We contract with an external partner for web hosting services, who may only have the ability to access and

see – but not to further process – the personal data of the natural persons concerned as follows:


Name of the data processor: Framer B.V.

Registered seat: Rozengracht 207B, 1016 LZ Amsterdam, Netherlands

Website: https://www.framer.com/

For more information on our data processor’s privacy policy: https://www.framer.com/legal/dataprocessing-

addendum/


Purpose of data processing: proper operation of the website, providing the user the opportunity to

contact us.


Legal basis for the data processing: consent of the data subject.


Time of data processing: until termination of the contract between the data controller and the processor

or until the data subject’s withdrawal of consent, with regard to the fact that the personal data provided

while making contact may only be viewed by the hosting provider, but that data is not stored on the server,

it is received directly into the Service Provider's closed system.

Scope of the data processed: our partner does not actually manage data, but may have access to the data

received through the contact form.


2. Partner facilitating online shopping


Name of data processor: ShopRenter.hu Kft.

Registered seat: 129 Kassai Street, Debrecen 4028

Website: www.shoprenter.hu

Email: info@shoprenter.hu


The data is transferred to ShopRenter.hu Kft. after the registration in the webshop and these data are

processed on the online interface of ShopRenter.hu Kft.

Purpose of data processing: proper performance of the webshop registration and the provision of

services.


Legal basis for the data processing: consent of the data subject during the registration

Time of data processing: until termination of the contract between the data controller and the processor

or until the data subject’s withdrawal of consent.

Scope of the data processed: data provided during registration.


3. The data processing partner operating the newsletter service


3.1 Name of the data processor: The Rocket Science Group LLC Mailchimp

Registered seat: 675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308 USA

Website: www.mailchimp.com

For more information on our data processor’s privacy policy:

https://mailchimp.com/legal/


3.2 Name of data processor: MiniCRM Zrt.

Registered seat: 13-14 Madách Imre Str. Budapest 1075.

Company registration nr.: 01-10-047449

TAX ID: 23982273-2-42

Telephone nr.: +36 (1) 999 - 0402

Email: help@minicrm.hu

Website: https://www.minicrm.hu/

For more information on our data processor’s privacy policy visit:

https://www.minicrm.hu/adatvedelem/


Purpose of data processing: briefings, offers and information provided to the data subject.

Legal basis for the data processing: consent of the data subject.

Recipients of personal data: The Service Provider and its data processing partner operating the newsletter

service.

Time of data processing: until the termination of the contract between the controller and the processor

or until the withdrawal of the consent of the data subject.

Scope of the data processed: name and email address of the data subject.


4. Other data processing partners who facilitate and support the process of the service


4.1 Name of data processor: Formspark - Trampoline Software SRL

Email: support@formspark.io

Website: https://formspark.io/

You can find more information about our partner's data management activities here:

https://formspark.io/legal/privacy-policy/


The purpose of data management: Facilitating the filling out of forms provided by the Service Provider,

enhancing the user experience and organizing the provided data for the Service Provider.

The legal basis for data management is the consent of the data subject.

Recipients of personal data: Service Provider.

The period of storage of personal data lasts until the existence of the user account or the contract, in the

case of contact, until the retention period specified therein or until the consent of the person concerned is

withdrawn (deletion request).

Scope of the data processed: data of the data subject provided on the forms.


4.2 Name of data processor: MiniCRM Zrt.

Registered seat: 1075 Budapest, Madách Imre út 13-14.

Company registration number: 01-10-047449

Tax number: 23982273-2-42

Phone number: +36 (1) 999 - 0402

Email: help@minicrm.hu

Website: https://www.minicrm.hu/

For more information on our data processor’s privacy policy visit:

https://www.minicrm.hu/adatvedelem/


Purpose of data management: Coordination and systematization of sales, task management within the

Service Provider's activities, customer service, partnerships, and the Service Provider's entire internal

processes related to its services.

The legal basis for data management is the consent of the data subject.

Recipients of personal data: Service Provider and the data processing partner operating the CRM system.

The period of storage of personal data lasts until the existence of the service or until the consent of the

data subject is withdrawn (deletion request).

Scope of the data processed: personal data entered in the form when registering the user account, personal

data entered during registration via Facebook campaigns, personal data entered during webshop registration

and purchase, personal data entered during application registration and use.


4.3 Adatfeldolgozó megnevezése: Google Ireland Limited


Registered seat: Gordon House, Barrow Street, Dublin 4, Ireland

For more information on our data processor’s privacy policy visit:

https://policies.google.com/privacy?hl=hu#intro


Purpose of data management: Sales, task management within the Service Provider's activities, customer

service, partnerships, and the coordination and systematization of the Service Provider's entire servicerelated

internal processes, in particular the transmission of the data of the stakeholders who establish contact

through Facebook campaigns via Google Sheets to the CRM system, as well as to the stakeholders who use

the application the data provided during registration in the application are recorded through the Google Cloud system.


The legal basis for data management is the consent of the data subject.

Recipients of personal data: Service provider and data controller partner.

The period of storage of personal data asts until the existence of the service or until the consent of the

data subject is withdrawn (deletion request).

Scope of the data processed: personal data provided during registration via Facebook campaigns, personal

data provided during registration in the application.


5. The data processing partner promoting online payment services in the webshop


Name of the data processor: Simple Pay – OTP Mobil Szolgáltató Kft.

Registered seat: 17-19. Hungária krt., Budapest, 1143 Hungary

Email address: dpo@otpmobil.com

For more information on our data processor’s privacy policy:

https://simplepay.hu/adatkezelesi-tajekoztatok/


Purpose of data processing: to ensure the operation of the online purchase service and in-app purchase,

and secure purchase of the desired product via secure electronic payment.

Legal basis for the data processing: consent of the data subject, fulfillment of legal obligations.

Time of data processing: The data processor manages the data for the purpose of providing the service,

so until such time, the data processor manages the data entrusted to them until the end of the contract

period between them and Service Provider. It differs from this only if it is necessary for other purposes to

further process the data, such as: Fulfillment of legal obligation: Billing, accounting (8 years after the

termination of the contract); Customer Complaint (5 years) Management; Prevention of money laundering

and terrorist financing (8 years after the termination of the contract). In these cases, you can find out the

exact time of data processing from our data processing partner's privacy policy, or by contacting them at

the given contact or email address.


Scope of the data processed: Data they receive from a data controller as a Service Provider in order to

complete your payment and give you the information related to it: Purchase data (purchase amount, detailed

cart content). Information (name, e-mail) required for making a wire transfer payment. Data generated by

credit card and wire payment transactions: Transaction data (payment transaction identifiers, date, content).


6. The data processing partner providing billing services


Name of the data processor: Számlázz.hu – KBOSS.hu Kft.

Registered seat: 7/D Záhony Str. Budapest 1031

Email: info@szamlazz.hu

For more information on our data processor’s privacy policy visit:

https://www.szamlazz.hu/adatvedelem/


Purpose of data processing: Számlázz.hu is provided with the data required for the invoice to be issued

to the data subject, which is stored by the data processor in an online system and issues an invoice on behalf

of the data controller with the parameters specified by the data controller.

Legal basis for the data processing: with the use of the service, the data subject gives his or her consent

to process the transmitted data to the extent and for the time necessary for the performance of the service.

Time of data processing: until termination of the contract between the data controller and the data

processor or until the withdrawal of the consent of the data subject.

Scope of the data processed: the name, address, billing data of the data subject and items of the bill.ű


7. Data processing partner delivering orders


7.1 Name of data processor: GLS General Logistics Systems Hungary Kft.

Registered seat: 2 Európa Str. Alsónémedi 2351

Email: adatvedelem@gls-hungary.com

For more information on our data processor’s privacy policy visit:

https://gls-group.eu/EN/en/privacy-policy


7.2. Name of data processor: Magyar Posta Kft.

Registered seat: 2-6 Dunavirág Str. Budapest 1138 Budapest

Contact of DPO: adatvedelem@posta.hu

For more information on our data processor’s privacy policy visit:

https://www.posta.hu/adatkezelesi_tajekoztato


7.3. Name of data processor: DPD Hungary Zrt.

Registered seat: Floor 2, 33 Váci Str. Budapest 1134 Budapest

Contact of DPO: dpd@dpd.hu

https://www.dpd.com/hu/hu/adatvedelem/


The purpose of data management: delivery of the Service Provider's packages.

Legal basis for data processing: consent of the data subject.

Duration of data processing: lasts until the termination of the contract between the data controller and

the data processor or the withdrawal of the data subject's consent.

Scope of data processed: name, e-mail address, telephone number and exact address of the data subject.

Our data processing partner does not receive information about the exact content of the package.


8. Data processing partner providing accounting services


Purpose of data management: In order to fulfill its tax and accounting obligations, the Service Provider

contracts with an external accounting service provider, who also manages the personal data of natural

persons related to the contract, in order to fulfill the tax and accounting legal obligations of the Service

Provider. Name and contact information of this data processor:


Name of data processor: Aurum Accounting Kft.

Registered seat: 3 fszt. 40/A Tahi Street, Budapest 1139

Company registry nr.: 01-09-953857


Legal basis for data processing: fulfilment of legal obligations.

Duration of data processing: the time specified in the legislation in force at all times, or, in the absence

thereof, or accordingly, 8 years after the termination of the legal relationship giving the legal basis for data

processing.

Scope of data processed: name, address, billing address of the data subject and invoice data.


9. Data processing partner supporting marketing activities


Name of data processor: 2100 International Digital Agency Kft.

Registered seat: 1 floor I. 25 Lehel Str. Budapest, 1134

Email cím: 2100@2100labs.com


Purpose of data management: creating a relationship between the Service Provider and the person

concerned, facilitating the provision of services and advertisement.

Legal basis for data processing: consent of the data subject;

Duration of data processing: until contacting the Service Provider and concluding a possible contract,

during the existence of the service or until the consent of the data subject is withdrawn (deletion request).

Scope of data processed: name, email address, phone nr. of the data subject.




CHAPTER II


DEFINITIONS


For the purposes of the present Privacy Statement, in accordance with Article 4 of the GDPR Regulation:


1. ‘personal data’ means any information relating to an identified or identifiable natural person (‘data subject’);

an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference

to an identifier such as a name, an identification number, location data, an online identifier or to one or

more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of

that natural person;


2. ‘processing’ means any operation or set of operations which is performed on personal data or on sets of

personal data, whether or not by automated means, such as collection, recording, organisation, structuring,

storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or

otherwise making available, alignment or combination, restriction, erasure or destruction;


3.‘restriction of processing’ means the marking of stored personal data with the aim of limiting their processing

in the future;


4. ‘profiling’ means any form of automated processing of personal data consisting of the use of personal data

to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects

concerning that natural person's performance at work, economic situation, health, personal preferences,

interests, reliability, behaviour, location or movements;


5. ‘pseudonymisation’ means the processing of personal data in such a manner that the personal data can no

longer be attributed to a specific data subject without the use of additional information, provided that such

additional information is kept separately and is subject to technical and organisational measures to ensure

that the personal data are not attributed to an identified or identifiable natural person;


6. ‘controller’ means the natural or legal person, public authority, agency or other body which, alone or jointly

with others, determines the purposes and means of the processing of personal data; where the purposes and

means of such processing are determined by Union or Member State law, the controller or the specific

criteria for its nomination may be provided for by Union or Member State law;


7. ‘processor’ means a natural or legal person, public authority, agency or other body which processes personal

data on behalf of the controller;


8. ‘recipient’ means a natural or legal person, public authority, agency or another body, to which the personal

data are disclosed, whether a third party or not. However, public authorities which may receive personal

data in the framework of a particular inquiry in accordance with Union or Member State law shall not be

regarded as recipients; the processing of those data by those public authorities shall be in compliance with

the applicable data protection rules according to the purposes of the processing;


9. ‘third party’ means a natural or legal person, public authority, agency or body other than the data subject,

controller, processor and persons who, under the direct authority of the controller or processor, are

authorised to process personal data;


10. ‘consent of the data subject’ means any freely given, specific, informed and unambiguous indication of the

data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement

to the processing of personal data relating to him or her;


11. ‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss,

alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;


12. 'consent' means a voluntary and explicit expression of the wish of a data subject, based on appropriate

information, and giving his or her unambiguous consent to the processing of personal data concerning him

or her, either wholly or in part;


13. ’protest’: a statement by the data subject that he or she objects to the processing of his personal data and

requests the termination of the data processing or the deletion of the data processed.


14. ’data processing’ means performing technical tasks related to the data processing operations, irrespective

of the method or device used to perform the operations and wherever they are carried out, provided that

the technical task is performed on the data.


15. ’transfer of data’ means forwarding the data to a specific third party.


16. ’disclosure’: making available the data to the public.


17. ’deletion of data’ means the process of rendering data unrecognizable in such a way that it is no longer

possible to recover it.


18. ’sets of personal data’ means the total amount of data processed in a register.




CHAPTER III


PRINCIPLES


We handle the processing of personal data of those concerned, in accordance with Article 5 of the GDPR

Regulation, taking into account the following principles:


1. Principle of legality, fairness and transparency: we process personal data in a lawful, fair and

transparent manner in relation to the data subject;


2. Principle of purpose limitation: personal data is collected for a specific, explicit and legitimate purpose

and is not further processed in a manner that is incompatible with those purposes; further processing for

archiving purposes in the public interest, scientific or historical research purposes or statistical purposes

shall not be considered to be incompatible with the initial purposes;


3. Principle of data minimization: personal data shall be adequate, relevant and limited to what is

necessary in relation to the purposes for which they are processed; Regarding this principle, we do not ask

for personal data, that is not necessary for proceeding our services.


4. Principle of accuracy: personal data must be accurate and, where necessary, kept up to date; We make

every reasonable step to ensure that personal data that are inaccurate, having regard to the purposes for

which they are processed, are erased or rectified without delay. If you as a data subject consider, that one or

more personal data of yours was given or was indicated by us inaccurately, we would kindly like to ask you

to let us know through an e-mail sent to info@voltie.eu, so that we can correct it.


5. Principle of storage limitation: personal data shall be kept in a form which permits identification of

data subjects for no longer than it is necessary for the purposes for which the personal data are processed;

personal data may be stored for longer periods insofar as the personal data will be processed solely for

archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in

accordance with Article 89 (1) of the GDPR Regulation subject to implementation of the appropriate

technical and organizational measures required by the GDPR Regulation in order to safeguard the rights

and freedoms of the data subject. To this end, we take into account that personal data provided by the data

subject will be stored only for the time necessary, depending on the time of provision of the service, on

legal requirements and on the data subject's consent, meaning that different time periods may be required

for each of our data management activities.


6. Principle of integrity and confidentiality: we process personal data

in a manner that ensures appropriate security of the personal data, including protection against unauthorized

or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or

organizational measures.


7. Principle of accountability: As a liable data controller, Service Provider is responsible for acting upon

principles listed in 1-6. and is prepared to demonstrate compliance.




CHAPTER IV


LAWFUL TREATMENT OF THE DATA SUBJECT’S PERSONAL DATA


1. [Data process operation with the consent of the data subject]


(1) On our website and when purchasing through our webshop and using our mobile application, during

registration, purchases and the use of the application the personal data described in Chapter V of the present

Statement will be processed based on the consent of the data subject. In case of data processing based on

consent, the consent of the data subject to the processing of personal data shall be requested by us prior to

the start of data processing. If data processing serves multiple purposes at the same time, the consent must

be given for all data processing purposes. These objectives are set out in Chapter V of the present Statement.

By accessing the present Privacy Statement if you use the website or the mobile application, you consent to

the use of this Privacy Statement by ticking the appropriate box.


(2) We would like to inform you about our obligation, that where the consent of the data subject is given

by means of a written declaration covering other matters as well, the request for consent shall be clearly

distinguished from those other matters in a clear and easily accessible form, in a simple language, and shall

not contain unfair terms. Any part of the statement containing the consent of the data subject that does not

meet the requirements of the law is not binding.


(3) We would also like to inform you, that in order for the data subject's consent to be based on the

information given by us, the data subject must at least be aware of the identity of the controller (Service

Provider) and the purpose of the processing of personal data. Giving consent is not considered to be

voluntary if the person concerned does not have a real or free choice and is unable to deny or withdraw

consent without it causing any damage to him or her. The data of the Service Provider can be found in

Chapter I of the present Statement, while the purpose of data process is stated in Chapter V.


(4) Data process is considered to be lawful if it is required in the context of a contract or at an intention to

conclude a contract. Service Provider shall not set up a condition for entering into a contract by requesting

personal data that is not necessary for the performance of the contract. If we enter into a service contract

with you, we may need to request additional personal data in order to prepare the contract, which will be

the subject of separate communication. If the contract is not concluded, the data provided through that

separate communication will be deleted from our system.


(5) The possibility of withdrawing consent shall be made available to the data subject in an

understandable, easily accessible form, in a clear and simple manner and shall not contain unfair terms.

Please be advised that if you wish to withdraw your consent, you may do so by sending an email to

info@voltie.eu. In case of withdrawal, we will immediately delete the data and inform the data subject in a

reply email. If the fulfillment of our legal obligation or contractual obligation (eg. provision of a service,

invoice, fulfillment of accounting obligation) requires further processing of certain data, we will inform you

in a reply email.


(6) If personal data has been given with the consent of the data subject, we may process the given data

without further specific consent and after the withdrawal of the consent of the data subject for the

fulfillment of our legal obligation unless otherwise provided by law.


(7) The consent should be voluntary, meaning it is free from all external influences and can possibly serve

as a legal basis if there is a real choice for You, as the data subject and there is no risk of deception,

intimidation, coercion or other significant negative consequences in the event of denial of consent. In the

absence of a voluntary decision, we would not have the appropriate legal basis for data processing. Without

question, we always base your consent on your voluntary decision regarding our consent-based data

processing activities, providing you with an uninfluenced choice.


(8) Given that there is a rare possibility that a minor under the age of 16 may inquire to contact us through

the website, makes purchases in the webshop or uses our mobile app, we consider it important to note the

following: one specific matter of the legal basis for consent is Article 8 of the GDPR Regulation, which

requires the consent of the parent for the lawfulness of data processing involving minors under 16 years of

age. In the case of a child under the age of 16, the processing of children's personal data is only lawful if

and to the extent that the consent has been given or authorized by the parent exercising parental authority

over the child. Parental guardians are kindly requested to inform us immediately if they become aware that

they have not given their consent or authorization to the processing of personal data of a child under the

age of 16, being under parental supervision. By informing us, we can take the necessary steps to delete the

personal data provided.


2. [Our obligation on providing information]

We keep the present Privacy Statement available to those concerned in an easily accessible way on

our website and at our seat. The Statement informs the data subject in a publicly accessible manner,

before and during the processing of the data, of all facts related to the management of their data, including

the purpose and legal basis of the data process, the person entitled to data processing, the duration of the

data process, about the fact if the personal data of the data subject is processed according to the data

subject’s consent (Section 5 Article 6 of the Privacy Act) and regarding who is entitled to know the data.

Our provision of information also covers the rights and remedies of the data subject concerned,

that you may find in Chapter IX., X. and XI. of the present Statement.


3. [Data process operation based on the fulfillment of a legal obligation]

Data process operation based on the fulfillment of a legal obligation is independent from the consent of the

data subject. Before starting the data process we must inform the data subject, that the process of data is

based on a legal obligation. In such case we inform the data subject in a clear and detailed way before the

beginning of the data process operation about all facts related to the process of his or her data, especially

the purpose and legal basis of the data process, the person entitled to data processing, the duration of the

data process, about the fact that the personal data is processed according to a legal obligation and regarding

who is entitled to know the data. The information provided by us also covers the rights and remedies of the

data subject concerned. In case of mandatory data process, the information may also be given by disclosing

a reference to the provisions of the legal obligation that contains the necessary information covered by this

paragraph.


4. [Data process operation based on a legitimate interest]

Personal data may be processed if the data processing is necessary for the purpose of enforcing the legitimate

interest of the Service Provider, exceptionally a third party, unless the right to the protection of the personal

data of the data subject and the respect of his or her privacy represents a higher value than that legitimate

interest. Such legitimate interest may make the data processing lawful, regardless of the consent of the data

subject if the legitimate interest only restricts the right and privacy of the data subject to the extent necessary

and proportionate. In the case of such interest-based data process, the principle of graduality and, if possible,

the presence of the data subject shall be ensured. As data controller, we must conduct a written legitimate

interest test for the lawfulness of data processing based on our legitimate interest and inform those

concerned in an easily accessible way. Currently, as a Service Provider, our only legitimate interest-based

data management is the operation of our security camera system, for which Service Provider retains the

legitimate interest test performed at Service Provider's headquarters. In the event of further interest-based

data processing, we will supplement the present Statement with this information.




CHAPTER V


DATA PROCESS OPERATIONS ON OUR WEBSITE, IN OUR MOBILE APPLICATION,

DURING ONLINE PURCHASES AND ON SOCIAL MEDIA PLATFORMS


1. Contacting us

(1) A natural person initiating contact by email or telephone request may voluntarily provide the Service

Provider with the following information when contacting the Service Provider. Service Provider stores it

only with the express request and consent of the data subject:

1. name (surname, first name);

2. email address;

3. any other personal data provided by the data subject voluntarily as a content of his or her message.


(2) The purpose of processing the personal data: providing information about our services, establishing

contact between the natural person and us as Service Provider. Providing personalized client service and

offer if required.


(3) The legal basis for data process is the consent of the data subject. In the case of telephone or e-mail

communications, you may give your consent to the management of your personal information when

communicating with Service Provider. If you wish to withdraw your consent, you can do so by sending us

an email with your request to info@voltie.eu. If there is no obligation to further process the data due to our

legal obligation or our contractual data management activities under Section (5), we will promptly delete the

data and will inform you in a reply email.


(4) The recipient of the personal data described in Section (2) is solely Service Provider. When a person

contacts the Service Provider, the data transmitted is not visible to the data processor or other third party

and the data is not stored in the storage space. The data is sent directly to info@voltie.eu email account

managed exclusively by the Service Provider. In the case of communication by telephone or direct personal

inquiry, if data are required, the Service Provider shall enter them into its own closed system.


(5) The duration of personal data storage shall last until 5 years after contacting us, but the latest until

the consent of the data subject is withdrawn (until a request on deleting the data is submitted by the data

subject). If the data subject concludes a contract with the Service Provider after the hereby described way

of contacting us, then further data management is governed by our contractual data management terms.


2. Information on the cookie policy of our website


Our website may use cookies to improve the user experience. In this case, the user will be notified of the

use of cookies in a pop-up window during the first visit. A cookie is a small text file that is stored on the

hard drive of the computer or mobile device for the duration set in the cookie and is activated (reports back

to the web server) on subsequent visits. The websites use cookies with the purpose of recording information

related to the visit (pages visited, time spent on the pages, browsing data, exits, etc.), as well as personal

settings, but these data cannot be linked to the person of the visitor. This tool helps you create a userfriendly

website to enhance your online experience. Cookies are not suitable for identifying the person

concerned. The purpose of cookies is to make the given information communication and internet service

easier and more convenient. The user has the option to delete or reject them. Since every browser is

different, you can set your cookie preferences individually using your browser's toolbar. If you do not want

to allow any cookies, you can change your web browser settings so that you are notified when cookies are

sent, or you can simply reject all cookies. However, you can also delete the cookies stored on your computer

or mobile device at any time. See your browser's help for more information about settings.

Cookies that collect statistical data: These cookies only collect statistical data, so they do not process

personal data. During their operation, they monitor how you use the website, which topics you view, what

you click on, how you scroll the website, which pages you visit. However, it only collects information

anonymously. This way we can find out, for example, how many visitors the page has per month. These

statistical data also help to adapt our site to user needs.


3. Personal information provided during registration and the usage of the mobile application


(1) With the consent of the data subject, we manage the

a) email address and

b) nickname

of the registered users of the mobile application for the purpose of registering and managing the user

account for the provision of the service.


In addition to the above, the data subject can provide data on the charging of the vehicle and its conditions

within the application.


(2) Purpose of the processing of personal data: To facilitate and secure the usage of the application.

Ensuring full use of the features of the mobile application Facilitating and ensuring the use of all features

of the mobile application. The entry of Voltie users into the system and the creation of charging history and

statistics for the user based on the user’s settings.


(3) The legal basis of the processing of the data shall be the consent of the data subject. The data subject

may indicate his or her consent to the processing of his or her personal data by ticking the appropriate box.

The present Statement is accessible via a link posted there when downloading the mobile application. The

application requires you to read and accept the present Statement. If you wish to withdraw your consent

and thus wish to cancel your registration, you can do so by sending an email to info@voltie.eu and you also

need to delete your account in the mobile application. We inform the data subject in a reply email on deleting

the data. If due to the fulfillment of our legal obligation or contractual obligation (eg fulfillment of an order

(purchase, issuing of an invoice) further processing of certain data is necessary, we will inform you in a reply

email.


(4) The personal data referred to in paragraph (1) is addressed to the Service Provider.


(5) The period of storage of personal data is valid until the registration, but not later than the mandatory

retention period prescribed by law or the withdrawal of the consent of the data subject (request for deletion).

Please note that if you made a purchase, the period of data storage for the purpose of providing the service

will be as set out in section 4 below.


4. Personal data provided during the purchase


(1) During the purchase, the data subject establishes a contractual relationship with Voltie Kft. as the data

controller. The purpose and legal basis of this data management is: by obtaining the consent of the

person concerned, as well as due to the legal performance of the contract, for the purpose of concluding,

fulfilling, terminating the contract necessary for the purchase, and issuing an invoice, we process the

following data of the natural person who contracted as a customer (scope of processed data:)

1. surname and first name,

2. e-mail address,

3. billing address;

4. shipping address.


(2) This data management is considered lawful even if the data management is necessary to take steps at the

request of the data subject prior to the conclusion of the contract. The recipients of the personal data

are the Service Provider as a data processor, our employees and our data processing partners who carry out

invoicing and possible delivery. The duration of the storage of personal data is the time specified in the

current applicable legislation, or, in the absence thereof, or accordingly 5 years after the termination of the

contract, after that the data will be deleted.


5. Personal information provided when purchasing online


(1) Purpose of data management: based on the consent of the data subject and the conclusion of a

contract, in case to conclude, perform, terminate a contract, to grant discount, to issue invoice we process

the following personal data required for the online service from our registered and non-registered users who

contracted us for the purpose of purchase (scope of data processed:)

1. surname and first name,

2. telephone number,

3. email address,

4. billing address,

5. payment data,

6. shipping address.


(2) Such data processing shall also be considered lawful where it is necessary to take steps at the request of

the data subject prior to the conclusion of the contract. The personal data will be addressed to the

Service Provider, our employees and our data processing partners for online shopping, billing and delivery.

With the exception of the payment data contained in paragraph (3), the period of storage of personal data

shall be the period specified in the prevailing applicable law, in the absence thereof, and accordingly 5 years

after the termination of the contract and thereafter shall be deleted.


(3) Payment data processing: For the purpose of concluding, executing, terminating, providing a contract,

granting discount, and issuing an invoice for the purpose of performing a contract, we will process the

payment data necessary (payment method, cardholder name, credit card details) of the individual. Such data

processing shall be considered lawful even if such processing is necessary to take action at the request of

the data subject prior to the conclusion of the contract.


The scope of the data processed: payment method, cardholder name (card name), card number,

expiration date.


Legal basis for data management: based on the legal title of the contract. The information may also be

provided in the contract. The provision of the data is a condition for the provision of the contracted service.

Recipient of the data: The recipient of the personal data is the data processing partner of the Service

Provider that makes and facilitates online shopping, billing and shipping procedures. The data subject may

pay the fee for the service by credit card or bank transfer. The recipient of the payment data being the data

processor contracted with the Service Provider for the execution of payment services. The Service Provider

does not see payment data, we only receive a code that is linked to the payment through the data processor

but is not traceable to the natural person. The payment processor shall have the necessary security and IT

measures and systems in place to ensure the secure handling of payment data. If required in the event of a

temporary disruption or other failure of the payment service system, - if online payment can be secured -

the Service Provider shall keep the payment data encrypted.


Duration of data storage: Credit card data will be encrypted and disclosed only for the purpose of the

transaction and only by authorized persons. Once the service has been completed, the data will no longer

be disclosed or accessed. Data will be deleted after 8 years.


6. Data process operation on our social media platforms


(1) We would like to inform You, that we maintain the ‘voltie.eu’ Facebook, the ‘@voltie.eu’ Instagram,

the „@voltieeu” TikTok and the ‘Voltie’ LinkedIn account (hereinafter collectively referred to as:

social media platforms).


(2) Complaints submitted to Service Provider through our social media platforms are not considered to be

formally submitted.


(3) Personal data published by visitors on the social media platforms of ours are not processed by us.


(4) Visitors are subject to the Privacy and Service Terms of the social media platforms.


(5) In case of an unlawful or offensive content posted on our social media platforms, we may exclude the

person from the site without notice and may delete his or her comment.


(6) We are not responsible for any unlawful data content or comments published by our social media

platform users. We are not responsible for any problems that may result from malfunctioning of the social

media platforms, causing a breach in personal data protection.


(7) Service provider shall be entitled to publish images or videos on the social media platforms of the data

subject solely with the given consent of the data subject, excluding the category of mass recordings.


(8) The provisions in this section also apply to any of our future social media platforms of ours.


7. Data management related to the newsletter service, advertising and marketing inquiries


(1) On the Service Provider's website and mobile application, natural persons registering for the newsletter

service may give their consent to the processing of their personal data by checking the relevant box. The

Service Provider does not check the box in advance. When signing up, we make this data management

information available via a link. The person concerned can unsubscribe from the newsletter at any time by

using the "Unsubscribe" button of the newsletter received by e-mail or by making a statement in e-mail,

which means withdrawal of consent. In such a case, all data concerning the newsletter service of the data

subject will be deleted immediately.


(2) The scope of personal data that can be processed is the natural person:

1. name (surname, first name);

2. email address.


(3) The purpose of processing personal data: sending newsletters and advertising material regarding the

Service Provider's products and services.


(4) The legal basis for data management is the consent of the data subject.


(5) Recipients of personal data: Service Provider and its data processing partner providing newsletter

services.


(6) The period of storage of personal data lasts until the existence of the newsletter service or until the

consent of the data subject is withdrawn (deletion request).


(7) A natural person who consents to the Service Provider's advertising and marketing inquiries may give

his/her consent to the processing of his/her personal data for advertising and marketing purposes by

checking the relevant box online or by signing a document confirming his/her consent. The Service

Provider does not pre-check the box. Before giving consent, we provide the present Privacy Statement

available via a link or we present it to the data subject before personally giving consent. The data subject

may withdraw his/her consent to marketing inquiries at any time by making a statement in person, by

telephone or by e-mail. In such a case, we will immediately delete all data of the data subject stored for this

purpose.


(8) The scope of personal data that can be processed is the natural person's:

1. name (surname, first name);

2. e-mail address;

3. telephone number.


(9) The purpose of the processing of personal data: sending advertising material and marketing inquiries

regarding the Service Provider's products and services.


(10) The legal basis for data processing is the consent of the data subject.


(11) Recipients of personal data: Service Provider and its data processing partner operating the CRM

system.


(12) The storage period of personal data lasts until the service is provided or until the data subject

withdraws his consent (deletion request).




CHAPTER VI


INFORMATION ON THE RIGHTS AND OBLIGATIONS BETWEEN THE DATA CONTROLLER AND THE DATA PROCESSOR


(1) Data processors listed in the registry of data processing activities shall comply with the technical and

organizational measures, including data security, to ensure compliance with the requirements of the GDPR

Regulation, in particular in terms of expertise, reliability and resources.


(2) Data processors shall be bound by the obligation of confidentiality with regard to data made available

to them by the Service Provider.


(3) In the course of its activities, the data processor shall ensure that persons authorized to have access to

the personal data concerned, unless they are already under the obligation of confidentiality by an appropriate

legal obligation, undertake to observe confidentiality with regard to the personal data which they become

aware of.


(4) The data processor must have appropriate hardware and software tools and must implement technical

and organizational measures suitable for ensuring the lawfulness of data processing and the protection of

the rights of data subjects.


(5) The Service Provider as a data controller shall enter into a written contract with the data processor for

the data processing activity, which shall include the data processing rights and obligations.


(6) The Service Provider, as a data controller, has the right to monitor the data processor's performance of

the contract referred to in paragraph (5).




CHAPTER VII


DATA SECURITY MEASURES


1. [Data security measures]

(1) For the purposes of personal data security, we are obliged to take all technical and organizational

measures and establish the procedural rules necessary to ensure data protection regarding any of our data

management activities.


(2) We protect the data by appropriate measures against accidental or unlawful destruction, loss, alteration,

injury, unauthorized disclosure or unauthorized access to it.


(3) We classify and manage personal data as confidential.


(4) With regard to the data arriving through our website, electronic data processing and record keeping is

carried out by means of a computerized information system that meets the requirements of data security.


(5) If the data of the natural persons concerned are handled by a paper-based document suitable for our

data processing operations, they must be managed and kept at the premises of our seat and office, in

accordance with the provisions of the Regulations and the present Privacy Statement (legal basis, scope of

processed data, retention period).


(6) We ensure the control of incoming and outgoing electronic communications for the protection of

personal data.


(7) Only we have access to documents that are in progress and undergoing data processing, and those are

kept securely closed.


(8) We ensure appropriate physical protection of the data and the means and documents carrying them.




CHAPTER VIII


MANAGEMENT OF PERSONAL DATA BREACH


1. [Concept of personal data breach]


(1) A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss,

alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed.

(Article 4 of GDPR Regulation 12)


(2) The most common reported breaches may include: loss of laptop or mobile phone, unsafe storage of

personal data; unsafe transfer of data, unauthorized copying, forwarding of clients, guest, customer, partner

lists, attacks against the server, breaking the website.


2. [Managing and remedy of personal data breach]


(1) Prevention, management of personal data breach, compliance with applicable legal requirements is our

responsibility as Service Provider.


(2) If we notice a breach we shall observe the personal data breach immediately. Access and access attempts

must be registered in the IT systems and analyzed continuously.


(3) Personal data breaches can be reported at our central e-mail address (info@voltie.eu), telephone number,

so clients, contractors, partners and others considered can report the underlying signs or events and security

weaknesses.


(4) In the event of a personal data breach being reported, we will immediately examine the notification,

identify the breach and decide whether it is a real breach or a false call. The following should be examined

and established:

a) the date and place of the event (breach);

b) description, circumstances and effects of the event (breach),

c) the range and number of data compromised during the breach;

d) the scope of persons affected by the compromised data;

e) the description of the measures taken to prevent the breach;

f) the description of the measures taken to prevent, remedy and reduce the damage.


(5) In the event of a personal data breach, the affected systems, persons, data must be delimited and

separated, and the evidence supporting the incident must be collected and preserved. It is then possible to

start repairing the damage and restoring the lawful operation.


3. [Register of personal data breach]


1. A record of personal data breach shall be kept, including:

a) the scope of the personal data concerned;

b) the scope and number of data subjects affected by the personal data breach;

c) the date of the personal data breach;

d) the circumstances and effects of the personal data breach;

e) the steps taken to remedy the personal data breach;

f) other data specified in the law regarding the relevant data processing operation.


(2) We retain data relating to personal data breach in the register for 5 years.


4. [Reporting personal data breach to the authority]

Data breaches that are likely to endanger the rights and freedoms of natural persons shall be reported by us

to the competent supervisory authority, the National Data Protection and Freedom of Information

Authority (NAIH) pursuant to Article 33 (1) of the GDPR. The GDPR requires the controller to notify the

NAIH of the incident without undue delay and, if possible, no later than 72 hours after becoming aware of

the breach. Our notification shall be made electronically or on paper through the NAIH Data Breach

Reporting System. (https://www.naih.hu/adatvedelmi-incidensbejelent--rendszer.html)




CHAPTER IX


RIGHTS, LEGAL REMEDIES OF THE RELATED PERSON


Below, we inform the data subject about the rights and remedies available to the natural person concerned

with regard to the protection of personal data. The submission and processing of the request of the

data subject are governed by the provisions of Chapter XI.


1. [The right to preliminary information and the right of access by the data subject]

The data subject is entitled to be informed of facts and information related to data process operations prior

to the commencement of these operations. Please contact info@voltie.eu for information. If requested, we

will provide you with the requested information without undue delay, but no more than one month, stating

whether your personal data are being processed and, if so, you have the right to know what personal data

are being processed, on what legal basis, for what purpose, for what period of time; and to whom, when,

under what law and which personal data of yours we provide access to; to whom we transmit your personal

data; the source of our access to your data; whether we use automated decision-making and, if so, its logic,

and in the case of pursuing profiling, we also inform you.

You may request a copy of your personal data, which will be provided for the first time free of charge, after

which you may be charged a reasonable fee based on administrative costs. Please note that in order to meet

our data security requirements, we have the right to verify your identity when requesting and making copies.

The data subject has the right to receive feedback from the data controller on whether personal data are

being processed and, if such processing is in progress, the data subject shall have access to personal data

and related information as defined in the GDPR Regulation. (Article 15 of GDPR Regulation).


2. [The right to rectification]

Upon request, the data subject shall have the right to obtain from the controller without undue delay the

rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the

processing, the data subject shall have the right to have incomplete personal data completed, including by

means of providing a supplementary statement. If the data subject credibly verifies the accuracy of the

corrected data, we will comply with the request within a maximum of one month and will inform the data

subject accordingly.


3. [The right to erasure (‘the right to be forgotten’)]

Upon request, the data subject shall have the right to obtain from the controller the erasure of personal data

concerning him or her without undue delay and the controller shall have the obligation to erase personal

data without undue delay if one of the grounds set out in the GDPR Regulation applies. (Article 17 of

GDPR Regulation) Where the data processed are necessary for law enforcement purposes or, for example,

for settlement with a public authority, the data processing may be carried out on the basis of a legal

obligation or a legitimate interest. Upon deletion, the data controller shall also notify the data processors

involved of the deletion obligation.



The data controller shall delete the personal data relating to the data subject without undue delay if any of

the following grounds applies:

a) personal data are no longer required for the purpose for which they were collected or otherwise processed;

b) the storage period set by the controller has expired;

c) the data subject has withdrawn his or her consent as the basis for the processing and there is no other

legal basis for the processing;

d) the data subject objects to the processing and there is no legitimate reason for the processing;

e) the personal data have been unlawfully processed;

f) personal data must be deleted in order to comply with a legal obligation under Union or national law

applicable to the data controller;

g) personal data have been collected in connection with the provision of information society services.


4. [Right to restriction of processing]

Upon request, the data subject shall have the right to obtain from the controller – through our contact

information described in point 1. – the restriction of processing if the following conditions specified in the

GDPR Regulation are met:

a) contest the accuracy of your personal information (limited to the time of our review);

b) the processing is unlawful and the data subject opposes the erasure of the data and instead requests that

their use be restricted;

c) the data controller no longer needs personal data for the purpose of processing, but the data subject

requires them to assert or defend a legal claim; or

d) the data subject has objected to the data processing (we restricted to the time during which the legitimate

interest of the data controller is established).


5. [Notification obligation regarding rectification or erasure of personal data or restriction of

processing]

We shall communicate and inform upon any rectification or erasure of personal data or restriction of

processing carried out all recipient to whom or with whom the personal data have been disclosed, unless

this proves impossible or requires a disproportionate effort. At the request of the data subject, the we shall

inform the data subject about those recipients. (Article 19 of GDPR Regulation)


6. [The right to data portability]

By applying the conditions set out in the GDPR Regulation, data subject shall have the right to receive the

personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly

used and machine-readable format and have the right to transmit those data to another controller without

hindrance from the controller to which the personal data have been provided. (Article 20 of GDPR

Regulation)


7. [The right to object]

The data subject shall have the right to object, on grounds relating to his or her particular situation, at any

time to processing of personal data concerning him or her which is based on point (e) or (f) of Article 6 (1)

(data processing necessary for the performance of a task carried out in the public interest or in the exercise

of official authority vested in the controller; the legitimate interests of the controller or by a third party, with

exceptions) (Article 21 of GDPR Regulation) In the event of an objection, the data controller may not

further process the personal data except for a legitimate reason which prevails over the interests of the data

subject or is necessary for the establishment, exercise or defense of legal claims.


8. [Automated individual decision-making, including profiling]

We do not use or perform profiling, automated decision making or automated mechanisms. We do not

allow our data processors to make automated decision making or profiling, except with the express written

consent of the data subject. The data subject shall have the right not to be subject to a decision based solely

on automated processing, including profiling, which produces legal effects concerning him or her or

similarly significantly affects him or her. (Article 22 of GDPR Regulation)


9. [Restrictions]

Union or Member State law to which the data controller or processor is subject may restrict by way of a

legislative measure the scope of the obligations and rights provided for in Articles 12 to 22 and Article 34,

as well as Article 5 in so far as its provisions correspond to the rights and obligations provided for in

Articles 12 to 22. (Article 23 of GDPR Regulation) In the event of a restriction, personal data may only be

stored. Further data processing may only be conducted with the data subject’s consent, for the purposes of

legal proceedings or the public interest.


10. [Informing the data subject of a personal data breach]

When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons,

we shall communicate the personal data breach to the data subject without undue delay. (Article 34 of GDPR Regulation)




CHAPTER X


THE DATA SUBJECT’S RIGHT OF APPEAL


1. [Right to lodge a complaint with the supervisory authority]

The data subject has the right to lodge a complaint to the supervisory authority if the data subject considers

that the processing of personal data concerning him or her violates the GDPR Regulation. (Article 77 of

GDPR Regulation)


2. [Right to an effective judicial remedy against the supervisory authority]

Each natural or legal person shall have the right to an effective judicial remedy against a legally binding

decision of the supervisory authority concerning them, or if the supervisory authority does not handle the

complaint or does not inform the person concerned of the progress or the outcome of the complaint within

three months. (Article 78 of GDPR Regulation)


3. [Right to an effective judicial remedy against the controller or the processor]

Each data subject shall have the right to an effective judicial remedy if he or she considers that his or her

rights under the GDPR Regulation have been infringed as a result of the processing of his or her personal

data in non-compliance with the GDPR Regulation. (Article 79 of GDPR Regulation) If you believe that

your personal data has been processed in violation of applicable data protection requirements, you may

lodge a complaint with the supervisory authority – see section Chapter X Point 2 for contact details. You

also have the right to initiate court procedure, that shall proceed out of turn. In this second case, you are

free to choose whether to file your claim with the competent regional court of your place of residence

(domicile) or place of temporary residence (temporary address) or of the Service Provider’s seat. You can

search for the regional court of your place of residence at https://birosag.hu/birosag-kereso. According to

the Service Provider's seat, the Budapest-Capital Regional Court has jurisdiction.




CHAPTER XI


SUBMISSION OF THE DATA SUBJECT’S APPLICATION OF REQUEST AND THE MEASURES TAKEN BY US AS DATA CONTROLLER


1. [Measures based on the request of the data subject]

(1) In the cases covered by the present Privacy Statement, the data subject may primarily submit his or her

request by email to info@voltie.eu. As data controller we shall inform the data subject of the measures taken

on his or her request for the exercise of his or her rights without undue delay, but no later than one month

after application of the request. If for any reason we are unaware of the submission of the request, we are

obliged to act promptly and without any delay along with informing the data subject.


(2) Where necessary, taking into account the complexity of the application and the number of applications,

this deadline may be extended by a further two months. We shall inform the data subject of the extension

of the deadline by indicating the reasons for the delay within one month of receiving the application of

request.


(3) If the data subject submitted the application by electronic means, the information shall, as far as possible,

be provided by electronic means, unless otherwise requested by the data subject.


(4) If we do not take any measures following the request by the data subject, we must inform the data subject

without any delay, but at the latest within one month from receiving the application of the request, of the

reasons for the non-execution of the measure and also about the data subject’s right to lodge a complaint

with the supervisory authority and his or her right to appeal at court.


(5) We provide the information set out in Articles 13 and 14 of the GDPR Regulation and the information

on the rights of the data subject (Articles 15 to 22 and 34 of the GDPR Regulation) free of charge. If the

data subject's application of request is unfounded without any doubt or is highly exaggerative, in particular

because of its repetitive nature, we may charge fee calculated based on the administrative costs of providing

for the requested information or refuse to take measures. It is us who bear the burden of proving that the

application of request is unfounded highly exaggerative.


(6) If we have reasonable doubts as to the identity of the natural person submitting the request, we may

request further information necessary to confirm the identity of the person concerned.


2. Contact details of the supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information

http://naih.hu

Address: 9-11. Falk Miksa Street Budapest, 1530

Postal address: 1363 Budapest, Pf .: 9.

Email: ugyfelszolgalat@naih.hu

Phone number: +36 (1) 391-1400