Privacy Policy

Introduction

Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the “GDPR” or the “Regulation”), requires the data controller to take appropriate measures to provide the data subject with all information relating to the processing of their personal data in a concise, transparent, intelligible and easily accessible form, using clear and plain language, and to facilitate the exercise of the data subject’s rights. This obligation is also required under Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information. We comply with this legal obligation through the information set out below, which is published on the Company’s website and made available to data subjects upon request.

1. Identification of the Data Controller

The publisher of this notice, acting as Data Controller, is:

  • Company name: Westerlike Ltd.
  • Registered office: 6723 Szeged, Molnár utca 6., Hungary
  • Contact e-mail: info@westerlike.com

(hereinafter: “the Company”)

2. Data Processors

A data processor is a natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller (Article 4(8) GDPR).

Engaging a data processor does not require the data subject’s prior consent; however, the data subject must be informed. Accordingly, the following information is provided.

2.1 IT Service Provider

For the operation and maintenance of its website, the Company engages an IT service provider (primarily for hosting services), which processes personal data submitted via the website for the duration of the applicable service agreement:

  • Company name: Rackhost Zrt.
  • Registered office: 6722 Szeged, Tisza Lajos körút 41., Hungary

2.2 Postal and Delivery Services

Where applicable, the Company shares the personal data necessary for delivery of ordered products (name, address and telephone number of the data subject) with delivery/postal service providers, solely for the purpose of completing delivery.

2.3 Other Service Providers

The Company also shares personal data with the following processors:

  • Mail server provider: Rackhost Zrt.
  • Virtual server provider: Rackhost Zrt.

(including related accounting and system administration services)

3. Legal Basis for Data Processing

3.1 Consent of the Data Subject

  1. Where the Company relies on consent as the legal basis for processing, consent must be obtained using the content and information requirements set out in the Company’s internal data management policy.
  2. Consent may also be given by ticking a relevant box on the Company’s website, through the data subject’s relevant technical settings when using information-society services, or through any other clear affirmative statement or action indicating agreement to the processing of their personal data. Silence, pre-ticked boxes, or inactivity do not constitute consent.
  3. Consent covers all processing activities carried out for the same purpose(s). Where processing serves multiple purposes, separate consent must be obtained for each purpose.
  4. Where consent is requested as part of a written declaration that also concerns other matters (e.g., the conclusion of a sales or service contract), the request for consent must be presented in a manner clearly distinguishable from those other matters, in an intelligible and easily accessible form, using clear and plain language. Any part of such a declaration that infringes the Regulation shall not be binding.
  5. The Company may not make the conclusion or performance of a contract conditional upon consent to processing of personal data that is not necessary for the performance of that contract.
  6. It must be as easy to withdraw consent as it is to give it.
  7. Where personal data were recorded on the basis of the data subject’s consent, the Company may, unless otherwise provided by law, continue to process the data as necessary to comply with an applicable legal obligation, and may also process such data lawfully after consent has been withdrawn, to the extent permitted by law.

3.2 Compliance with a Legal Obligation

  1. Where processing is based on a legal obligation, the scope of data processed, the purpose of processing, the retention period, and the recipients of the data are determined by the applicable legislation.
  2. Processing on this legal basis does not depend on the data subject’s consent, since the processing is mandated by law. Before processing begins, the data subject must nevertheless be informed that the processing is mandatory, together with all relevant details — in particular the purpose and legal basis of the processing, the identity of the controller and any processors, the retention period, and who may access the data. The data subject must also be informed of their rights and available remedies. Where processing is mandatory, this information may be provided by reference to the relevant legislation.

3.3 Legitimate Interest

A legitimate interest of the Company or a third party may serve as the legal basis for processing, provided that this interest does not override the fundamental rights, freedoms and interests of the data subject. The data subject’s reasonable expectations, based on their relationship with the Company, must be taken into account; processing personal data for contact purposes — including direct marketing — may be based on legitimate interest under these conditions.

3.4 Performance of a Contract

Processing may also be based on the necessity of performing a contract to which the data subject is a party, or of taking steps at the data subject’s request prior to entering into a contract.

3.5 Vital Interests

Protection of the vital interests of the data subject or of another natural person may also constitute a legal basis for processing — for example, where a natural person receives healthcare services, or where processing is necessary to help contain the spread of an epidemic.

3.6 Facilitating the Data Subject’s Rights

In connection with all processing activities, the Company is obliged to ensure that data subjects can exercise their rights.

4. Processing of Website Visitors’ Data – Use of Cookies

4.1 General Cookie Information

Website visitors must be informed about the Company’s use of cookies and, except for strictly necessary session cookies, must give their consent.

A cookie is a small piece of data that a visited website sends to the visitor’s browser (as a name/value pair) so that it can be stored and later retrieved by the same website. Cookies may be temporary (deleted when the browser closes) or persistent (retained for a defined period). The browser subsequently transmits this data back to the server with each HTTP(S) request, which involves storing information on the user’s device.

Modern websites rely on cookies to recognise a visitor (for example, to remember that they are logged in) and to respond accordingly, including recognising a returning visitor. The associated risk is that users are not always aware of this and may be tracked by the website operator or by third-party services embedded in the page (e.g., Facebook, Google Analytics), which may build a profile of the user — in which case the cookie data may constitute personal data.

4.2 Categories of Cookies

  • Strictly necessary session cookies: essential for the website to function — for example, to identify the user (e.g., to remember that they are logged in or what is in their shopping basket). These typically store a session ID, with the remaining data held securely on the server. If the session ID is not generated securely, the site is exposed to session-hijacking; secure generation of these values is therefore essential. (Some terminologies instead classify any cookie deleted at browser close as a “session cookie”, meaning a browsing session from start to close.)
  • Functional cookies: remember a visitor’s preferences — for example, the display format the user prefers. These cookies essentially store the user’s chosen settings.
  • Performance cookies: collect information about a visitor’s behaviour on the website, such as time spent and clicks. These are typically served by third-party tools (e.g., Google Analytics, Google Ads, Yandex) and can be used to build a profile of the visitor.

Further information on Google Analytics cookies: https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage

Further information on Google Ads cookies: https://support.google.com/adwords/answer/2407785?hl=en

4.3 Managing Cookie Consent

Accepting cookies is not mandatory. Browser settings can be configured to reject all cookies or to prompt the user before a cookie is stored. Most browsers accept cookies by default, but this behaviour can typically be changed.

Cookie settings for popular browsers can be found at:

  • Google Chrome: https://support.google.com/accounts/answer/61416?hl=en
  • Firefox: https://support.mozilla.org/hu/kb/sutik-engedelizeze-es-tiltasa-amit-weboldak-haszn
  • Microsoft Edge: https://windows.microsoft.com/hu-hu/windows-10/edge-privacy-faq
  • Safari: https://support.apple.com/hu-hu/HT201265

Please note that certain website functions or services may not operate correctly without cookies.

4.4 Data Collected During a Website Visit

During use of the website, the following information about the visitor and their device may be recorded:

  • the visitor’s IP address
  • browser type
  • characteristics of the device’s operating system (including language settings)
  • date of the visit
  • the page, function or service accessed
  • click activity

This data is retained for a maximum of 90 days and is used primarily for the investigation of security incidents.

4.5 Legal Basis and Purpose by Cookie Category

Strictly necessary session cookies – Purpose: to ensure the proper functioning of the website, allowing visitors to browse and use its features and services smoothly, including identifying logged-in users during a visit. These cookies apply only to the current visit and are automatically deleted when the session ends or the browser is closed. Legal basis: Section 13/A(3) of Act CVIII of 2001 on Certain Aspects of Electronic Commerce Services and Information Society Services, under which a service provider may process personal data that is strictly necessary for the technical provision of the service, and only to the extent and for the duration necessary.

Functional cookies – Purpose: to improve the efficiency of the service, enhance the user experience, and make the website more convenient to use. Legal basis: the visitor’s consent. This data is typically stored on the user’s device and allows the website to recognise the visitor.

Performance cookies – Purpose: to analyse website usage and to support the delivery of advertising offers. Legal basis: the data subject’s consent.

5. Rights of the Data Subject – Overview

  1. Transparent information, communication, and facilitation of the exercise of data subject rights
  2. Right to be informed in advance, where personal data are collected from the data subject
  3. Right to be informed, where personal data were not obtained from the data subject
  4. Right of access
  5. Right to rectification
  6. Right to erasure (“right to be forgotten”)
  7. Right to restriction of processing
  8. Notification obligation regarding rectification, erasure, or restriction of processing
  9. Right to data portability
  10. Right to object
  11. Rights relating to automated individual decision-making, including profiling
  12. Restrictions
  13. Notification of a personal data breach
  14. Right to lodge a complaint with a supervisory authority
  15. Right to an effective judicial remedy against a supervisory authority
  16. Right to an effective judicial remedy against a controller or processor

6. Rights of the Data Subject – Detailed Provisions

6.1 Transparent Information, Communication and Facilitation of Rights

  1. The Company must provide the data subject with all information concerning the processing of their personal data in a concise, transparent, intelligible and easily accessible form, using clear and plain language — with particular care where the information is addressed to children. Information must be provided in writing, or by other means including, where appropriate, electronically. Information may be given orally at the data subject’s request, provided their identity has been verified by other means.
  2. The Company must facilitate the exercise of the data subject’s rights.
  3. The Company shall inform the data subject of any action taken in response to a request without undue delay, and in any event within one month of receiving the request. This period may be extended by a further two months where necessary, provided the data subject is informed of the extension and the reasons for it.
  4. If the Company does not take action on a data subject’s request, it shall inform the data subject without delay, and at the latest within one month of receiving the request, of the reasons for not taking action, and of the data subject’s right to lodge a complaint with a supervisory authority and to seek a judicial remedy.
  5. Information, communications and actions taken under this section are provided free of charge; however, a fee may be charged in the cases specified in the Regulation.

Detailed rules are set out in Article 12 of the GDPR.

6.2 Right to Prior Information (Where Data Are Collected from the Data Subject)

The data subject has the right to be informed, before processing begins, of:

  • the identity and contact details of the Company and its representative, if any;
  • the contact details of the Data Protection Officer, if any;
  • the purpose of the intended processing and its legal basis;
  • where processing is based on legitimate interest, the nature of that legitimate interest;
  • the recipients or categories of recipients of the personal data, if any;
  • where applicable, the Company’s intention to transfer personal data to a third country or international organisation.

To ensure fair and transparent processing, the data subject must also be informed of:

  • the retention period, or the criteria used to determine it;
  • the right to request access to, rectification or erasure of, or restriction of processing of, their personal data, the right to object to processing, and the right to data portability;
  • where processing is based on consent, the right to withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
  • the right to lodge a complaint with a supervisory authority;
  • whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract, whether the data subject is obliged to provide the data, and the possible consequences of failing to do so;
  • the existence of automated decision-making, including profiling, and, at least in such cases, meaningful information about the logic involved and the significance and envisaged consequences of such processing for the data subject.

Where the Company intends to process personal data for a purpose other than that for which it was collected, it must inform the data subject of that new purpose, together with all other relevant information, before carrying out the further processing.

Detailed rules are set out in Article 13 of the GDPR.

6.3 Information Where Data Were Not Collected from the Data Subject

Where the Company did not obtain personal data directly from the data subject, it must provide the information described in Section 6.2 above, together with the categories of personal data concerned and the source of the data (including, where applicable, whether it originates from publicly available sources), within a reasonable period after obtaining the data and no later than one month; or, if the data are used for contacting the data subject, at the latest at the time of first contact; or, if disclosure to another recipient is envisaged, at the latest when the data are first disclosed.

Detailed rules are set out in Article 14 of the GDPR.

6.4 Right of Access

  1. The data subject has the right to obtain confirmation from the Company as to whether personal data concerning them are being processed and, if so, to access that data together with the related information described in Sections 6.2–6.3 above (Article 15 GDPR).
  2. Where personal data are transferred to a third country or an international organisation, the data subject is entitled to be informed of the appropriate safeguards applied under Article 46 GDPR.
  3. The Company must provide the data subject with a copy of the personal data undergoing processing. For any additional copies requested, the Company may charge a reasonable fee based on administrative costs.

Detailed rules are set out in Article 15 of the GDPR.

6.5 Right to Rectification

  1. The data subject is entitled to obtain, without undue delay, the rectification of inaccurate personal data concerning them.
  2. Taking into account the purpose of the processing, the data subject is entitled to have incomplete personal data completed, including by means of a supplementary statement.

These rules are set out in Article 16 of the GDPR.

6.6 Right to Erasure (“Right to be Forgotten”)

The data subject has the right to request the erasure of personal data concerning them without undue delay, and the Company is obliged to comply where any of the following applies:

  • the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
  • the data subject withdraws consent on which the processing was based, and there is no other legal ground for the processing;
  • the data subject objects to the processing and there are no overriding legitimate grounds for it;
  • the personal data have been unlawfully processed;
  • erasure is required to comply with a legal obligation under EU or Member State law applicable to the Company;
  • the personal data were collected in connection with the offer of information-society services directly to a child.

The right to erasure does not apply where processing is necessary:

  • for exercising the right of freedom of expression and information;
  • for compliance with a legal obligation under EU or Member State law, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Company;
  • for reasons of public interest in the area of public health;
  • for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes, where erasure would be likely to render impossible or seriously impair the achievement of those purposes;
  • for the establishment, exercise or defence of legal claims.

Detailed rules are set out in Article 17 of the GDPR.

6.7 Right to Restriction of Processing

  1. Where processing is restricted, the relevant personal data may, with the exception of storage, only be processed with the data subject’s consent, or for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the EU or a Member State.
  2. The data subject has the right to request restriction of processing where any of the following applies: (a) the accuracy of the personal data is contested, for the period necessary to allow the Company to verify accuracy; (b) the processing is unlawful and the data subject opposes erasure, requesting restriction of use instead; (c) the Company no longer needs the data for the purposes of processing, but the data subject requires them for the establishment, exercise or defence of legal claims; or (d) the data subject has objected to processing, pending verification of whether the Company’s legitimate grounds override those of the data subject.
  3. The data subject must be informed before any restriction on processing is lifted.

Detailed rules are set out in Article 18 of the GDPR.

6.8 Notification Obligation Regarding Rectification, Erasure or Restriction

The Company must notify each recipient to whom personal data have been disclosed of any rectification, erasure, or restriction of processing, unless this proves impossible or involves disproportionate effort. The Company shall inform the data subject about those recipients upon request.

Detailed rules are set out in Article 19 of the GDPR.

6.9 Right to Data Portability

  1. Where processing is based on consent or on a contract, and is carried out by automated means, the data subject has the right to receive personal data concerning them, which they provided to the Company, in a structured, commonly used and machine-readable format, and has the right to transmit that data to another controller without hindrance from the Company.
  2. The data subject may also request that personal data be transmitted directly from the Company to another controller, where technically feasible.
  3. Exercise of the right to data portability is without prejudice to the right to erasure under Article 17 GDPR, and does not apply where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Company. This right shall not adversely affect the rights and freedoms of others.

Detailed rules are set out in Article 20 of the GDPR.

6.10 Right to Object

  1. The data subject has the right, on grounds relating to their particular situation, to object at any time to the processing of their personal data based on the performance of a task carried out in the public interest, or on the Company’s legitimate interest (including profiling based on those grounds). In such cases, the Company may no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or where the processing is necessary for the establishment, exercise or defence of legal claims.
  2. Where personal data are processed for direct marketing purposes, the data subject has the right to object at any time to such processing, including profiling to the extent it relates to direct marketing. Where an objection is made, the personal data may no longer be processed for that purpose.
  3. This right must be explicitly brought to the data subject’s attention at the latest at the time of first communication, and must be presented clearly and separately from other information.
  4. The data subject may also exercise the right to object by automated means, using technical specifications.
  5. Where personal data are processed for scientific or historical research purposes, or for statistical purposes, the data subject has the right to object, on grounds relating to their particular situation, unless the processing is necessary for the performance of a task carried out for reasons of public interest.

Detailed rules are set out in Article 21 of the GDPR.

6.11 Automated Individual Decision-Making, Including Profiling

  1. The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
  2. This right does not apply where the decision: (a) is necessary for entering into, or the performance of, a contract between the data subject and the Company; (b) is authorised by EU or Member State law applicable to the Company, which also lays down suitable measures to safeguard the data subject’s rights, freedoms and legitimate interests; or (c) is based on the data subject’s explicit consent.
  3. In the cases referred to in points (a) and (c) above, the Company must implement suitable measures to safeguard the data subject’s rights, freedoms and legitimate interests, including at least the right to obtain human intervention, to express their point of view, and to contest the decision.

Detailed rules are set out in Article 22 of the GDPR.

6.12 Restrictions

EU or Member State law applicable to the Company or its processors may restrict the scope of the rights and obligations set out in Articles 12–22 and Article 34, as well as Article 5 of the Regulation, through legislative measures, provided such restriction respects the essence of fundamental rights and freedoms.

The conditions for such restrictions are set out in Article 23 of the GDPR.

6.13 Notification of a Personal Data Breach

  1. Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the Company must notify the data subject of the breach without undue delay, describing its nature in clear and plain language and disclosing at least: (a) the name and contact details of the Data Protection Officer or other contact point for further information; (b) the likely consequences of the breach; and (c) the measures taken or proposed by the Company to address the breach, including, where appropriate, measures to mitigate its possible adverse effects.
  2. Notification to the data subject is not required where any of the following applies: (a) the Company has implemented appropriate technical and organisational protection measures, applied to the affected data, that render the data unintelligible to unauthorised persons (e.g., through encryption); (b) the Company has taken subsequent measures ensuring that the high risk to the rights and freedoms of data subjects is no longer likely to materialise; or (c) notification would involve disproportionate effort, in which case the Company shall instead issue a public communication or take similarly effective measures to inform data subjects.

Detailed rules are set out in Article 34 of the GDPR.

6.14 Right to Lodge a Complaint with a Supervisory Authority

The data subject has the right to lodge a complaint with a supervisory authority — in particular in the Member State of their habitual residence, place of work, or the place of the alleged infringement — if they consider that the processing of their personal data infringes the Regulation. The competent supervisory authority must inform the complainant of the progress and outcome of the complaint, including the possibility of a judicial remedy.

These rules are set out in Article 77 of the GDPR.

Supervisory authority:

  • National Authority for Data Protection and Freedom of Information (NAIH)
  • Registered office: 1125 Budapest, Szilágyi Erzsébet fasor 22/c, Hungary
  • Postal address: 1530 Budapest, Pf.: 5, Hungary
  • Telephone: +36 (1) 391-1400
  • E-mail: ugyfelszolgalat@naih.hu

6.15 Right to an Effective Judicial Remedy Against a Supervisory Authority

  1. Without prejudice to other available administrative or non-judicial remedies, every natural and legal person has the right to an effective judicial remedy against a legally binding decision of a supervisory authority concerning them.
  2. Without prejudice to other available administrative or non-judicial remedies, every data subject has the right to an effective judicial remedy where the competent supervisory authority fails to handle a complaint, or fails to inform the data subject of the progress or outcome of a lodged complaint within three months.
  3. Proceedings against a supervisory authority must be brought before the courts of the Member State in which the authority is established.
  4. Where proceedings are brought against a decision of a supervisory authority in respect of which the European Data Protection Board has previously issued an opinion or decision under the consistency mechanism, the supervisory authority must forward that opinion or decision to the court.

These rules are set out in Article 78 of the GDPR.

6.16 Right to an Effective Judicial Remedy Against a Controller or Processor

  1. Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority, every data subject has the right to an effective judicial remedy where they consider that their rights under the Regulation have been infringed as a result of unlawful processing of their personal data.
  2. Proceedings against the Company (as controller) or a processor must be brought before the courts of the Member State in which the Company or processor is established. Such proceedings may also be brought before the courts of the Member State of the data subject’s habitual residence, unless the Company or processor is a public authority of a Member State acting in the exercise of its public powers.

These rules are set out in Article 79 of the GDPR.

Szeged, 1 June 2026

WESTERLIKE Ltd.