Privacy policy

COCCINELLE PILATES Kft. DATA PROCESSING NOTICE

This document provides information about the data processing carried out by Coccinelle Pilates Kft. as the data controller in relation to reformer pilates fitness services.

Please read the following information carefully!

  1. Purpose of this document
    This document provides information on the processing of personal data collected from participants who register and make appointments via the coccinellepilates.hu website (hereinafter referred to as the “Website”) in relation to the reformer pilates fitness service provided by Coccinelle Pilates Kft. as the data controller, in accordance with the Act CXII of 2011 on informational self-determination and freedom of information (hereinafter referred to as the “Infotv.”) and the European Parliament and Council Regulation (EU) 2016/679 of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (repealing Directive 95/46/EC) (hereinafter referred to as the “Regulation”, GDPR).

Through this document, the data controller informs about the personal data processed in relation to the reformer pilates fitness service, the purpose of the data processing, the retention period, the methods of storage and transfer, the principles and practices followed in the processing of personal data, as well as the ways and opportunities for the data subjects to exercise their rights.

Coccinelle Pilates Kft. reserves the right to unilaterally modify this document at any time.

  1. The Data Controller
    The data controller in relation to the reformer pilates fitness service is Coccinelle Pilates Kft. (hereinafter referred to as “Coccinelle Pilates” or “Data Controller”).

Registered office of Coccinelle Pilates Kft.: 1171 Budapest, Réti csík utca 22, földszint 5.

Registering Court: Fővárosi Törvényszék Cégbírósága

Company Registration Number: 01-09-427707

Tax Number: 32505061-2-42

Email: bstampfer@gmail.com

Phone Number: +36 70 2262959

  1. Data Processing Activities Related to the Reformer Pilates Fitness Service
    A customer (hereinafter referred to as the “Guest”) wishing to use the reformer pilates fitness service may only provide their own personal data. These data are necessary to register for classes through the appointment booking system. By providing these data, the Guest expressly accepts and guarantees that, if the provided personal data infringes upon the rights of third parties, they shall bear full responsibility for any potential damages, fines, or liabilities arising from such violations, as well as any associated costs and fees that may arise in connection with these.

Purpose of the Data Processing:
The identification of individuals making appointments for reformer pilates fitness services through the appointment booking system.

Legal basis for the data processing:
The data subject’s voluntary, informed, and explicit consent, which is provided by the Guest through a checkbox on the designated platform. The Guest provides consent by ticking the “I accept the privacy terms, the booking regulations, and I explicitly consent to the processing of my data by Coccinelle Pilates for its own purposes and that its employees may contact me at the provided contact details” checkbox. This consent is given based on the information provided in this document (Article 5(1)(a) of the Infotv. and Article 6(1)(a) of the GDPR).

Scope of the processed data:
During appointment booking: last name, first name, email address, phone number.

Data retention period:
Until consent is withdrawn.

Data processing location:
On the data controller’s premises and on IT equipment located at the Coccinelle Pilates Studio.

Data storage method:
Electronic.

Data transfer:
No data transfer takes place.

Data processors:
No data processors are involved.

Consequences of failure to provide data:
If the required data is not provided or is incomplete during the appointment booking process, the prospective Guest will not be able to participate in the prize draw.

 

  1. Data Security
    Coccinelle Pilates Kft. respects the regulations concerning the security of personal data. Therefore, both Coccinelle Pilates Kft. and any authorized data processors take all necessary technical and organizational measures and establish the procedures required to ensure compliance with the confidentiality and data security provisions of the Infotv. and the GDPR.

Coccinelle Pilates Kft. protects the personal data it processes with appropriate measures against unauthorized access, alteration, transfer, disclosure, deletion, or destruction, as well as accidental destruction or damage.

In the course of its data processing, Coccinelle Pilates Kft. ensures the following principles:

  1. a) Confidentiality: It ensures that the information is protected and accessible only to those who are authorized to access it;
    b) Integrity: It ensures the accuracy and completeness of the information and the processing method;
    c) Availability: It ensures that the information is available to the authorized user when needed, along with the tools required to access it.
  2. Rights of Data Subjects and Legal Enforcement
    All personal information provided by the data subject to Coccinelle Pilates Kft. must be accurate, complete, and up to date.

The data subject may request information regarding the processing of their personal data, as well as request the correction of their personal data, or, with the exception of mandatory data processing, request its deletion, withdrawal, and exercise their right to data portability and objection in the manner indicated at the time of data collection, or through the contact details provided by the data controller.

Right to Information:
Coccinelle Pilates Kft. takes appropriate measures to provide all the information referred to in Articles 13 and 14 of the GDPR, as well as the information required under Articles 15–22 and 34 of the GDPR, to data subjects in a concise, transparent, intelligible, and easily accessible form, using clear and plain language.

The right to information can be exercised in writing through the contact details indicated in section 2 of this notice. Upon request, the data subject can also receive verbal information after verifying their identity.

Right of Access:
The data subject is entitled to request information from the data controller about whether their personal data is being processed, and if such processing is ongoing, they are entitled to access the personal data and the following information:

  • The purposes of the data processing;
  • The categories of the personal data concerned;
  • The recipients or categories of recipients with whom or to whom the personal data has been or will be disclosed, including specifically third-country recipients and international organizations;
  • The intended duration of the storage of personal data;
  • The right to rectify, erase, or restrict processing and the right to object;
  • The right to lodge a complaint with the supervisory authority;
  • Information about the sources of the data;
  • The existence of automated decision-making, including profiling, and meaningful information about the logic involved, as well as the significance and expected consequences of such processing for the data subject.

If personal data is transferred to a third country or an international organization, the data subject is entitled to receive information on the appropriate safeguards in place for the transfer.

Coccinelle Pilates Kft. will provide a copy of the personal data that is the subject of processing to the data subject. For any additional copies requested by the data subject, the data controller may charge a reasonable fee based on administrative costs. The information will be provided electronically by Coccinelle Pilates Kft. upon request.

The data controller will provide the requested information within a maximum of one month from the submission of the request.

Right to Rectification:
The data subject may request the correction of inaccurate personal data or the completion of incomplete data processed by Coccinelle Pilates Kft.

Right to Erasure:
The data subject is entitled to request the erasure of their personal data without undue delay under any of the following circumstances:

  • The personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
  • The data subject withdraws the consent on which the processing is based, and there is no other legal ground for the processing;
  • The data subject objects to the processing, and there are no overriding legitimate grounds for the processing;
  • The personal data has been unlawfully processed;
  • The personal data must be erased in order to comply with a legal obligation under Union or Member State law applicable to the data controller;
  • The personal data has been collected in relation to the offering of information society services.

Erasure of data may not be requested if the processing is necessary for:

  • The exercise of freedom of expression and information;
  • Compliance with a legal obligation to which the data controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  • Reasons of public health, or for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes in accordance with the public interest;
  • The establishment, exercise, or defense of legal claims.

Right to Restriction of Processing:
The data subject is entitled to request the restriction of processing under any of the following conditions:

  • The data subject contests the accuracy of the personal data, in which case the restriction applies for a period enabling the data controller to verify the accuracy of the personal data;
  • The processing is unlawful, and the data subject opposes the erasure of the data and requests the restriction of its use instead;
  • The data controller no longer needs the personal data for the purposes of processing, but the data subject requires the data for the establishment, exercise, or defense of legal claims; or
  • The data subject has objected to the processing; in this case, the restriction applies for the period required to determine whether the legitimate grounds of the data controller override those of the data subject.

If the processing is restricted, personal data will only be processed, other than for storage, with the consent of the data subject, or for the establishment, exercise, or defense of legal claims, or to protect the rights of another natural or legal person, or for reasons of important public interest in the Union or a Member State.

Coccinelle Pilates Kft. will inform the data subject in advance if the restriction of processing is lifted.

Right to Data Portability:
The data subject is entitled to receive the personal data concerning them, which they have provided to the data controller, in a structured, commonly used, and machine-readable format, and is entitled to transmit those data to another data controller.

Right to Object:
The data subject is entitled to object at any time, on grounds relating to their particular situation, to the processing of their personal data, which is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller, or to the processing necessary for the purposes of the legitimate interests pursued by the data controller or by a third party, including profiling based on these provisions. In case of objection, the data controller may no longer process the personal data unless compelling legitimate grounds for the processing override the interests, rights, and freedoms of the data subject, or the processing is necessary for the establishment, exercise, or defense of legal claims.

If the processing of personal data is carried out for direct marketing purposes, the data subject has the right to object at any time to the processing of their personal data for such marketing purposes, including profiling to the extent that it is related to direct marketing.

In the case of an objection to the processing of personal data for direct marketing, the data may no longer be processed for such purposes.

Automated Decision-Making in Individual Cases, Including Profiling:
The data subject is entitled not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.

This right does not apply if the processing is:

  • Necessary for the performance of a contract between the data subject and the data controller;
  • Authorized by Union or Member State law applicable to the data controller, which also establishes suitable measures to protect the data subject’s rights and freedoms, and legitimate interests; or
  • Based on the explicit consent of the data subject.

Right to Withdraw Consent:
The data subject is entitled to withdraw their consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

Procedural Rules:
The data controller will provide the data subject with information about the actions taken in response to a request under Articles 15-22 of the GDPR without undue delay, and in any case within one month of receiving the request. If necessary, considering the complexity of the request and the number of requests, this deadline may be extended by a further two months.

The data controller will inform the data subject of the extension of the deadline, specifying the reasons for the delay, within one month of receiving the request. If the request was submitted electronically, the information will be provided electronically, unless the data subject requests otherwise.

If the data controller does not take action in response to the data subject’s request, they will inform the data subject without undue delay, and in any case, within one month of receiving the request, about the reasons for not taking action and the possibility to lodge a complaint with a supervisory authority and seek judicial remedy.

Coccinelle Pilates Kft. will provide the requested information and notifications free of charge. If the request is clearly unfounded or excessive, particularly due to its repetitive nature, the data controller may charge a reasonable fee based on the administrative costs involved in providing the requested information or taking the requested action, or refuse to act on the request.

The data controller will inform all recipients of any rectification, erasure, or restriction of processing carried out, except where this is impossible or would involve disproportionate effort. The data subject may request information about these recipients.

The data controller will provide the data subject with a copy of the personal data being processed. For additional copies requested by the data subject, the data controller may charge a reasonable fee based on administrative costs. If the request was submitted electronically, the information will be provided electronically, unless the data subject requests otherwise.

Compensation and Damages for Non-Material Loss:

Anyone who has suffered material or non-material damage as a result of a breach of the Regulation is entitled to compensation from the data controller or the data processor for the damage suffered. The data processor is only liable for damages caused by data processing if it has not complied with the legal obligations specifically imposed on data processors, or if it has disregarded or acted contrary to the lawful instructions of the data controller.

If multiple data controllers or data processors, or both the data controller and the data processor, are involved in the same data processing and are responsible for the damages caused by the processing, each data controller or data processor is jointly and severally liable for the entire damage.

The data controller or data processor is exempt from liability if it proves that it is not responsible for the event that caused the damage.

Data Protection Authority Procedures:

The data subject has the right to file a complaint with the National Authority for Data Protection and Freedom of Information regarding the processing of their personal data.

  • Name: Nemzeti Adatvédelmi és Információszabadság Hatóság
  • Headquarters: 1055 Budapest, Falk Miksa Street 9-11
  • Mailing address: 1363 Budapest, P.O. Box 9
  • Phone: +36 1 391 1400
  • Fax: +36 1 391 1410
  • Email: ugyfelszolgalat@naih.hu
  • Website: http://www.naih.hu

Right to judicial remedy:

In the event of a violation of their rights, the data subject may bring a case before a court against the data controller, regardless of whether a complaint has been submitted. The court shall deal with the matter on an expedited basis.

  1. Contact

If the user wishes to contact Coccinelle Pilates, they may do so through the contact details provided in point 2 of the information notice, which contains the details of the data controller.