Privacy Policy

PANNONARIS

Data Processing Notice

For customers and visitors of the Pannonaris webshop

  • Data Controller: Énekesné Partos Viktória, individual entrepreneur
  • Brand name: Pannonaris
  • Effective: 2026.09.11.

1. Data Controller’s Details

NameÉnekesné Partos Viktória, individual entrepreneur
Trade namePannonaris
Registered office1039 Budapest, Hadrianus u. 7., Hungary
Registration number54894046
Tax number56258433-2-41
E-mailinfo@pannonaris.com
Phone+36 20 331 4810
WebshopPannonaris.com

The Data Controller is currently not obliged to appoint a data protection officer. Data protection queries or requests from data subjects may be submitted to the e-mail address given above.

2. Purpose and Principles of the Notice

This Notice sets out which personal data the Data Controller processes in connection with operating the Pannonaris webshop, fulfilling orders, invoicing, shipping, communication, withdrawal and complaint handling, for what purpose, on what legal basis and for how long, as well as who may receive the data and what rights are afforded to data subjects.

The Data Controller processes personal data lawfully, fairly and in a transparent manner, for specified purposes, limited to what is necessary, accurately and with appropriate security. The provision of special categories of personal data is not required to use the webshop; customers should not submit such data.

3. Data Subjects and the Main Scope of Data Processed

  • visitors to and persons interested in the Webshop;
  • private individuals placing orders without registration;
  • the natural-person contact persons and representatives of corporate customers;
  • persons exercising a right of withdrawal, a warranty claim or a complaint;
  • subscribers to the newsletter, should Pannonaris launch a newsletter in the future.

The data processed in connection with an order are: name, billing and shipping address, e-mail address, phone number, order details, the shipping method chosen, payment status, and the data required to identify the transfer. In the case of a corporate purchase, the company name, registered office, tax number and the contact person’s data may also be processed.

4. The Individual Data Processing Activities

4.1. Order, Conclusion of Contract and Performance

DataPurposeLegal BasisRetention
name; addresses; e-mail; phone; order content; identifier; shipping and payment datareceiving and confirming the order, performance of the contract, communicationGDPR Article 6(1)(b) - performance of a contract or steps prior to entering into a contract5 years from performance of the contract; a separate rule applies to billing documents

Providing the data is necessary for the performance of the order. Without the mandatory data, the Data Controller is unable to accept or fulfil the order.

4.2. Unsuccessful or Unpaid Order

DataPurposeLegal BasisRetention
order and contact datahandling and deletion of an order not paid within 3 business days, and prevention of abuse and repeated disputesGDPR Article 6(1)(b), or, where justified, Article 6(1)(f) - legitimate interesta maximum of 30 days from deletion of the order; in the event of a dispute, until the claim is closed

4.3. Invoicing and Accounting Retention

DataPurposeLegal BasisRetention
name/company name; billing address; tax number; order and financial data; invoice dataissuing and sending the electronic invoice, bookkeeping, tax and accounting obligationsGDPR Article 6(1)(c) - legal obligationaccounting records for at least 8 years

The electronic invoice is issued through the Billingo system. Pursuant to legal requirements, invoice data may be transferred to the National Tax and Customs Administration.

4.4. Bank Transfer

DataPurposeLegal BasisRetention
name of the payer; bank account number; payment reference; amount; date; transaction identifieridentifying the purchase price, financial settlement and refundGDPR Article 6(1)(b) and (c)at least 8 years, together with the related accounting records

4.5. Shipping

DataPurposeLegal BasisRetention
name of the recipient; shipping address; e-mail; phone number; shipment identifier; where necessary, the data required for customs clearancedelivery, notification, tracking, and handling of damage or loss claimsGDPR Article 6(1)(b)until delivery and any complaint are closed; for evidentiary purposes, a maximum of 5 years

For the purpose of delivery, the data may be transferred to Magyar Posta Zrt. (MPL) or another carrier indicated later in the Webshop. The carrier’s own data processing terms may also apply.

4.6. Contact and Inquiries

DataPurposeLegal BasisRetention
name; e-mail; phone number, if provided; message and attachmentsanswering the inquiry, sending further images or product informationGDPR Article 6(1)(f) - legitimate interest in responding to the inquiry; for pre-contractual questions, Article 6(1)(b)a maximum of 1 year from closure of the matter; in the case of a contract or dispute, for the duration pertaining thereto

4.7. Withdrawal, Warranty Claims and Complaint Handling

DataPurposeLegal BasisRetention
identification and contact data; order; content of the complaint or claim; photographs; report/minutes; response; refund dataensuring consumer rights, investigating the complaint, handling legal claimsGDPR Article 6(1)(c), and, for legal claims, Article 6(1)(f)the consumer protection complaint and response for 3 years; in the event of a dispute, until the final closure of the claim

4.8. Newsletter and Direct Marketing

At the launch of Pannonaris, no newsletter is planned. If a newsletter is launched later, this may only take place on the basis of separate, voluntary and revocable consent. Acceptance of the General Terms and Conditions or making a purchase does not constitute consent to the newsletter. Consent may be withdrawn at any time; withdrawal does not affect the lawfulness of processing carried out before its withdrawal.

4.9. Operation of the Website, Log Data and Cookies

In the course of the technical operation of the Webshop, the IP address, the time of the visit, the page viewed, browser and device information, error codes, and the data of security and session cookies may be processed. Strictly necessary cookies may be used on the basis of the legitimate interest in the operation and security of the Webshop, or on the basis of providing the electronic service expressly requested.

Analytical, personalisation or marketing cookies may only be placed with prior, voluntary consent. The name, provider, purpose and lifetime of the actual cookies used are set out in the separate Cookie Notice.

5. Data Processors and Recipients

Service ProviderTaskData Transferred
Billingo Technologies Zrt.
1133 Budapest, Árbóc utca 6. I. emelet
hello@billingo.hu
electronic invoicing and sending invoicesbilling, order and contact data
Magyar Posta Zrt. (MPL)parcel delivery and delivery notificationsrecipient’s name, address, e-mail, phone number, shipment data
MBH Bank Nyrt. 1056 Budapest, Váci ú. 38.receiving EUR transfers and refundspayment and account identification data
NeoSoft Informatikai Szolgáltató Kft., 8000 Székesfehérvár, Távírda u. 2/A. Torony Irodaház II. emelet 1.hosting, logging, backupsdata processed in the Webshop and technically stored
NeoSoft Informatikai Szolgáltató Kft., 8000 Székesfehérvár, Távírda u. 2/A. Torony Irodaház II. emelet 1.operation of the webshop and technical supportthe data processed in the system, to the extent of access
Google Ireland Limited
Gordon House, Barrow Street, Dublin 4, Ireland
Gmail-based electronic correspondencename, e-mail, messages and attachments

The Data Controller discloses only the data necessary for the performance of the given task. Certain recipients - in particular the bank, the carrier and the NAV (National Tax and Customs Administration) - may also act as independent data controllers within the scope of their own statutory obligations. The final list is to be updated once the technical service providers have been selected.

6. Data Transfers Outside the European Economic Area

The Data Controller primarily uses service providers operating within the European Economic Area. However, the services of certain technology providers may also result in access to, or transfer of, data outside the EEA. In such cases, the transfer of data may only take place subject to appropriate safeguards under Chapter V of the GDPR - such as an adequacy decision or standard contractual clauses. This section is to be refined once the actual technical services have been selected.

7. Automated Decision-Making and Profiling

In its currently planned operations, Pannonaris does not apply any solely automated decision-making or profiling that would produce legal effects concerning the data subject or similarly significantly affect them. Should this change in the future, the Data Controller will amend this Notice in advance.

8. Data Security

The Data Controller applies technical and organisational measures appropriate to the risks of the processing, in particular access control, strong and unique passwords, multi-factor authentication where available, encrypted data transmission, regular updates, backups, and the restriction of service providers’ access rights. Paper-based documents are stored securely, inaccessible to unauthorised persons.

In the event of a personal data breach, the Data Controller assesses its risk, documents the incident, and, where necessary, notifies the NAIH within the statutory deadline, and, in the case of high risk, the data subjects as well.

9. Rights of Data Subjects

  • may request information about, and access to, the personal data processed concerning them;
  • may request the rectification of their inaccurate data;
  • where the statutory conditions are met, may request the erasure of their data or the restriction of its processing;
  • may object to processing based on legitimate interest;
  • may request their automatically processed data based on a contract or consent in a machine-readable format, and may request that such data be transferred;
  • may withdraw their consent at any time;
  • may lodge a complaint with the supervisory authority and may bring the matter before a court.

Requests may be sent to the e-mail address info@pannonaris.com or to the postal address 1039 Budapest, Hadrianus u. 7. The Data Controller will respond without undue delay, as a general rule within one month. Where necessary, it may request confirmation of identity. Fulfilling the request is, as a general rule, free of charge.

The right to erasure does not apply to data which the Data Controller is obliged or entitled to retain due to a legal obligation, or for the establishment, exercise or defence of legal claims.

10. Legal Remedies

National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9-11.
Postal address: 1363 Budapest, Pf. 9.
E-mail: ugyfelszolgalat@naih.hu
Website: https://www.naih.hu/
Phone: +36 1 391 1400

The data subject may also enforce their rights before the regional court (törvényszék) having jurisdiction over their place of residence or habitual abode, or before the court having jurisdiction over the Data Controller’s registered office, in accordance with the applicable legislation.

11. Data of Children

The Webshop is not specifically directed at children. Making a purchase requires the capacity to conclude a contract. If the Data Controller becomes aware that personal data has been provided by a child without an appropriate legal basis, it will delete the data following the necessary investigation.

12. Amendment of the Notice

The Data Controller may amend this Notice in the event of changes to its operations, the technologies applied, or the applicable legislation. The version in effect is available on the Webshop in a downloadable and saveable format. Data subjects will be informed of any material change in a manner appropriate to the circumstances of the given processing activity.