Privacy Policy

This Privacy Notice describes how we process your personal data when you use Pure & Calm’s cosmetic services and website. We take great care to the protection of your personal data and comply with the EU General Data Protection Regulation (GDPR).

  1. Who is the data controller?
  • Name of Data Controller: Dorottya Ajtay E.V.
  • Headquarters: Budapest 1195 Zrínyi utca 51.
  • Contact: ajtay dot dori at gmail dot com
  1. What data do we process and for what purpose?

We process your personal data only for specific purposes, which may include:

  • Contact and appointments: Your name, email address, phone number in order to schedule appointments for the services, which are handled through Calendly and Gmail.
  • Invoicing: We use the Számlázz.hu system to manage the mandatory data (name, address) required for invoicing.
  • Social media: Photos on our Instagram page are published only with the prior consent of the data subject.
  • Website visit: There is no login option on the website; only links, photos and information can be found. The website and domain are provided by Rackhost.
  1. Legal basis for data processing

Legal basis of data processing:

  • Appointment booking and contact: Your consent, legitimate interest of the data controller.
  • Invoicing: Fulfilment of a legal obligation.
  • Social media content: Prior consent of the data subject.
  1. Data retention periods

We will only keep your personal data for as long as necessary, as follows:

Purpose of data processing

Data Processed

Retention period

Contact and book an appointment

Name, e-mail address, phone number

Until the performance of the service, up to 1 year

Invoicing

Name, address, billing information

According to the law, for 8 years

Social media content

Photos and videos with the prior consent of the data subject

At the request of the data subject, we will delete it

Website Data Backup

Data on the website

Until deletion or regular updates

  1. Service providers, legal bases and processed data

The table below summarises the different data processing services, the legal basis of data processing and the scope of data processed:

Provider

Purpose

Service location

Legal basis

Data Processed

Justification of legitimate interest

Számlázz.hu

Invoicing

Hungary

Legal obligation

Name, address, billing information

Rackhost

Website hosting service

Hungary

Legitimate interest

Information and photos on the website

Ensuring the operation of the website

Calendly

Appointment booking

EU

Consent

Name, e-mail address, phone number

Gmail

Correspondence, appointment booking, backup

EU

Consent, legitimate interest (in case of backup)

Name, e-mail address, phone number, website data

Appointments, backup to protect your data

Instagram

Social media presence

EU

Consent

Photos and videos with the  explicit consent of the data subject

  1. Security measures

We take your privacy to the utmost importance and do everything we can to keep it safe. To this end, we apply the following technical and organizational measures:

  • Encrypted data transmission: Data is transmitted over an encrypted channel in all cases to prevent unauthorized access to the data.
  • Access restriction: Access to data is restricted to employees who need to process data in order to perform their work, thus ensuring the protection of personal data.
  • Data backup and recovery: The website and important data are backed up at regular intervals and can be restored if necessary.
  • Regular audits: We regularly review our privacy processes and ensure that our data practices are compliant with the latest regulatory requirements.
  1. Your rights

You have the following rights under the GDPR:

  1. Information: You may request information about the scope of the data we process and your processing process.
  2. Access: You can request a copy of the data we process (once a year free of charge upon request)
  3. Correction: You can request clarification of the data.
  4. Deletion: You can request that your data be deleted when it is no longer needed.
  5. Restriction: You can request the restriction of processing, for example if you contest the accuracy of your data or if the processing is unlawful.
  6. Objection: You may object to the processing of your data if the processing is based on a legitimate interest or for the purpose of direct marketing.

You can exercise your rights related to data processing through ajtay dot dori at gmail dot com address. For identification, please provide your name and the requested data processing operation.

  1. Contact

If you have any questions about data protection, you can contact us at the following contact details:

  • E-mail: ajtay dot dori at gmail dot com
  • Address: 1195 Budapest Zrínyi utca 51.
  1. Right to lodge a complaint

If you feel that your data protection rights have been violated, you can file a complaint with the National Authority for Data Protection and Freedom of Information (NAIH).

https://www.naih.hu/adatkezeles-erintettjekent-fordulok-a-hatosaghoz