Privacy Notice
1. Introduction
1.1. The purpose of this data protection notice
The purpose of this Privacy Notice (hereinafter: „the Notice”) is to set out, in a transparent and detailed manner, how we process personal data in the Rita Zsova, sole trader (hereinafter referred to as the „Data Controller”) in the course of its activities, and to provide information on the rights of data subjects and how to exercise them.
1.2. Regulatory compliance (GDPR, Act CXII of 2011)
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR): lays down uniform EU rules on the protection of personal data.
- Act CXII of 2011 (Infotv.): the Act forming the basis of Hungarian data protection legislation, which deals with the right to informational self-determination and freedom of information.
This Prospectus is intended to comply with the requirements set out in the above legislation.
2. Details of the data controller
2.1. Name and contact details of the data controller
- Name: Rita Zsova
- Registered office: 28 Deák Ferenc Street, 3300 Eger.
- Sole trader registration number: 56600483
- Tax number: 66192994-1-30
- Member of Parliament: Rita Zsova
- Email: zsovarita@gmail.com
- Telephone number:+36202513886
2.2. Availability of the privacy notice
This Prospectus is available in electronic form at www.ritazsova.com It is available on our website and, upon request, in printed form at our customer service office.
3. Definitions
3.1. Basic concepts of the GDPR
- Personal data: any information relating to an identified or identifiable natural person („data subject”).
- Data Controller: a natural or legal person who determines the purposes and means of the processing of personal data.
- Data processor: a natural or legal person who processes personal data on behalf of the Data Controller.
- Consent: a voluntary and explicit expression of the data subject’s will, by which they give their consent to the processing of their personal data.
- Affected: any identified or identifiable natural person to whom the personal data relates.
3.2. Definition of a data breach
A data breach is defined as any incident resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data that has been transmitted, stored or otherwise processed.
4. Data processing guidelines
4.1. Legal bases and fundamental principles
- Legality, due process and transparency: We process data only for specific and lawful purposes.
- Purpose-driven: Only for a pre-determined purpose, and to the extent necessary to achieve that purpose.
- Data efficiency: We collect and process only the personal data that is essential for achieving the purpose.
- Accuracy: We ensure that the personal data we process is accurate and, where necessary, kept up to date.
- Limited shelf life: We only retain personal data for as long as is necessary to fulfil the purpose for which it was collected.
- Integrity and confidentiality: We implement appropriate technical and organisational measures to protect personal data.
4.2. Accuracy and security of data
- Both the Data Controller and the data subject are responsible for ensuring that the data is updated regularly; the data subject is obliged to notify the Data Controller of any changes to their personal data.
- The Data Controller shall do everything in its power to ensure that the data on file is accurate and to protect it from unauthorised access by means of appropriate security measures.
5. Purposes and legal bases for data processing
5.1. Registering on the website and managing your user account
- Objective: To create a user account, enable users to log in, and allow them to save their favourite works.
- Legal basis:
- Consent (Article 6(1)(a) of the GDPR), as registration is voluntary and is initiated by the data subject.
- Scope of data processed: Name, email address, password (in encrypted form), date of registration, IP address, and details of the user’s saved favourites.
5.2. Managing purchase intent and enquiries
- Objective: Receiving expressions of interest in purchasing the works selected on the website, and agreeing the terms and details of the purchase with the prospective buyer.
- Legal basis: Taking steps at the data subject’s request prior to entering into a contract (Article 6(1)(b) of the GDPR).
- Scope of data processed: Name, email address, telephone number (if provided), details of the selected works, and any other information provided when contacting us.
- Note: The shopping basket on the website is intended for collecting the selected items. The purchase is not finalised via online payment, but following consultation with the Data Controller by email.
5.3. Invoicing
- Objective: Compliance with current accounting legislation (e.g. Act C of 2000).
- Legal basis: Compliance with a legal obligation (Article 6(1)(c) of the GDPR).
- Scope of data processed: Name/company name, address, tax registration number (in the case of a legal entity), and any other information required for invoicing.
5.4. Sending newsletters
- Objective: Information on new works, the availability of reproductions, art news and related information.
- Legal basis: Consent (Article 6(1)(a) of the GDPR).
- Scope of data processed: Name, email address.
- Note: You can unsubscribe from the newsletter at any time by clicking on the link at the bottom of the newsletter or by contacting the Data Controller directly.
5.5. Use of cookies
- Objective: To ensure the website functions properly, to improve the user experience, to analyse visitor data, and for marketing purposes.
- Legal basis:
- Consent (Article 6(1)(a) of the GDPR) – for all cookies that are not essential to the functioning of the website.
- Legitimate interest or performance of a contract (Article 6(1)(f) or (b) of the GDPR) – in the case of technical cookies that are essential for the website to function.
- Further details: See the section entitled „Use of cookies” in this Notice (point 11).
Cloudflare Turnstile and Cloudflare cookies
To prevent unauthorised, automated use of our contact and other forms, and to filter out unsolicited messages and malicious bot traffic, our website uses the Cloudflare Turnstile uses the service.
During the operation of the service, certain technical data relating to visitors to the website may be transmitted to the Cloudflare, Inc. to them. The data transferred and processed may include, in particular:
- the user’s IP address,
- technical details of the browser and the device, such as User-Agent information,
- certain technical characteristics of the network connection,
- traffic and request data relating to the use of the website,
- as well as other technical information required for the detection of bot traffic.
The purpose of data processing is to determine whether the website and its forms are being used by a genuine user or an automated system, thereby ensuring the secure operation of the website and preventing misuse.
In the course of providing the service, Cloudflare collects the data necessary for operations and security checks may use technical cookies and similar technologies. Depending on the Cloudflare configuration used, this could, for example, be the cf_clearance cookie, which may be used to store the result of a successfully completed security check. The purpose of these technologies is to maintain website security, detect automated and malicious traffic, and manage repeated security checks.
Further information on data processing carried out by Cloudflare Turnstile can be found in the following documents:
Cloudflare Privacy Policy:
https://www.cloudflare.com/privacypolicy/
Cloudflare Turnstile Privacy Notice:
https://www.cloudflare.com/turnstile-privacy-policy/
5.6. Data processing on social media platforms
- Objective: Keeping in touch, sharing information (Facebook, Instagram, etc.).
- Legal basis: Voluntary decision, consent (Article 6(1)(a) of the GDPR).
- Note: The data processing practices of social media platforms can be found in each platform’s privacy policy.
6. Scope of data processed
6.1. Types of personal data
- Identification details: name, username, password (encrypted).
- Contact details: email address, telephone number, address.
- Technical specifications: IP address, browser type, cookies, time of login.
- Billing details: billing name, address, tax registration number (for companies).
6.2. Method and duration of data storage
- Stored electronically on secure servers, protected by passwords and other security measures.
- In paper form (if available) at the registered office or place of business, in a secure location.
- Retention period: until the statutory obligations have been fulfilled and the purpose of data processing has been achieved, or until consent is withdrawn. Thereafter, the data will be erased or anonymised.
7. The rights of data subjects
7.1. The right to information
The data subject is entitled to request information on the purposes for which their personal data is processed, the legal basis for such processing, the sources of the data, the duration of the processing, and who has access to it.
7.2. Right to rectification
If the data subject considers that their personal data being processed is inaccurate or incomplete, they may request that it be rectified or supplemented.
7.3. The right to erasure („the right to be forgotten”)
The data subject may request the erasure of their personal data if the data are no longer necessary for the purposes for which they were originally collected, or if the data subject withdraws their consent and there is no other legal basis for the processing.
7.4. Right to data portability
The data subject is entitled to receive the data they have provided in a widely used, machine-readable format, or to request that such data be transferred to another data controller.
7.5. The right to protest
- The data subject may object at any time to the processing of their personal data where the legal basis for the processing is the Data Controller’s legitimate interests.
- The data subject has the specific right to object to the processing of their personal data for the purposes of direct marketing.
8. Data security
8.1. Protection of electronic data
- Regular backups.
- Virus protection and the use of firewalls.
8.2. Technical and organisational measures
- Storage of paper-based documents in a locked cupboard.
9. Handling data protection incidents
9.1. Reporting incidents to the authorities (72-hour rule)
In the event of a data breach, the Data Controller shall report it to the National Authority for Data Protection and Freedom of Information (NAIH) without undue delay and, where possible, within 72 hours at the latest, unless it is likely that there is no risk to the rights and freedoms of data subjects.
9.2. Informing data subjects in the event of a high risk
If the incident is likely to pose a high risk to the rights and freedoms of data subjects, the Data Controller shall inform the data subjects without delay, setting out the nature of the incident and the measures taken.
10. Data processors and third parties
10.1. Hosting provider
Company name: Vitarex Stúdió Kft.
Address: Budapest, 17 Aladár Street, Ground Floor 1, 1016
Telephone number: +36 1 385 1949
Email: vitarex@vitarex.hu
Data processing activities: operation of the web server, technical maintenance. It processes personal data solely in accordance with the Data Controller’s instructions.
10.2. Accountants and other partners
In the course of its activities, the Data Controller may engage data processors who assist in the processing of personal data.
- Accountant: Edit Szalay, Data-Agora Ltd., activities: carrying out bookkeeping, tax and accounting tasks.
Other data processors: The Data Controller may engage additional partners necessary for the operation of the website and its services; where necessary, this Notice will be updated to reflect such changes. Data processors may process personal data solely on the instructions of the Data Controller and in accordance with the provisions of the GDPR.
11. Use of cookies
11.1. The purpose and types of cookies
- Session cookies: these are essential for the website to function and are deleted when you close your browser.
- Functional cookies: they enhance the user’s convenience, for example by remembering login details or the selected language.
- Analytical cookies (e.g. Google Analytics): these are used for statistical purposes, to help us understand user behaviour and improve the website’s performance.
- Marketing cookies: they help to display relevant adverts and measure the effectiveness of those adverts.
11.2. Managing user settings
- Users can control how cookies are handled in their browser settings, allowing them to disable or delete them.
- If you change your cookie settings, some features of the website may not work properly.
- When you visit the website for the first time, you will be given the option to accept or reject non-essential (e.g. marketing) cookies via a pop-up window.
12. Data Protection Officer
12.1. Conditions and duties relating to appointment
Under Article 37 of the GDPR, the Data Controller is required to appoint a Data Protection Officer (DPO) if its core business is:
- involves data processing operations which, by their nature or scope, require regular and systematic monitoring, or
- are based largely on the handling of highly sensitive data.
The official’s duties include:
- ongoing monitoring of compliance with the GDPR,
- advice for the Data Controller and employees,
- maintaining contact with the supervisory authority (NAIH) and data subjects.
12.2. Legal status and contact details
The Data Controller is not obliged to appoint a data protection officer under Article 37 of the GDPR and therefore does not appoint a separate data protection officer.
13. Remedies available to data subjects
13.1. Lodging a complaint with the National Authority for Data Protection and Freedom of Information (NAIH)
If the data subject considers that the processing of their personal data infringes the applicable legislation, they may lodge a complaint with the National Authority for Data Protection and Freedom of Information:
- Title: 1055 Budapest, 9–11 Falk Miksa Street.
- Telephone: +36 (1) 391-1400
- Email: ugyfelszolgalat@naih.hu
13.2. The possibility of judicial redress
In the event of a breach of the data subject’s rights, they may bring a claim before a court. They may also bring the claim – at their discretion – before the court with jurisdiction over their place of residence or place of stay.
14. The legislation forming the basis for data processing
14.1. GDPR (Regulation (EU) 2016/679)
Regulation (EU) 2016/679 of the European Parliament and of the Council, the purpose of which is to protect natural persons in relation to the processing of personal data and to ensure the free flow of data within the EU.
14.2. Act CXII of 2011 on the right to informational self-determination
The Hungarian Data Protection Act, which sets out the fundamental principles and restrictions governing the processing of personal data in Hungary.
14.3. Other relevant Hungarian legislation
- Act C of 2000 on Accounting.
- Act V of 2013 on the Civil Code (Ptk.).
- Act XLVIII of 2008 on the fundamental conditions governing commercial advertising activities.
15. Final provisions
15.1. Scope of the Privacy Notice and how it may be amended
- This Prospectus shall take effect on 3 August 2026.
- The Data Controller is entitled to amend this Policy unilaterally, in particular in order to take account of changes in legislation, the introduction of new data processing activities, or the recommendations of the supervisory authority.
- Any amendments will be published on the website, and once they come into force, data subjects will be deemed to have accepted the new rules by continuing to use the services.
Dated: Eger, 25 July 2026.
Rita Zsova, sole trader
Data Controller