GDPR
For Physical Well-Being Services
Please read this Information Notice carefully in order to understand how I handle your personal data in connection with the European Union General Data Protection Regulation (GDPR) and applicable laws, and to be informed about your rights regarding data management.
My business reserves the right to amend this notice at any time, should there be any changes in regulations, laws, or the company's details. If the change involves information that I am legally required to notify you about, I will do so without delay. If you have submitted a question regarding this notice by post, I will respond immediately, but no later than within one month in writing.
Your personal data (i.e., data that can be linked to you as an individual) may come into my possession if you provide it through the following channels: Facebook, Viber, the company's website, email systems, by telephone, or in person.
Please be informed that courts, prosecutors, investigative authorities, misdemeanor authorities, administrative authorities, the National Authority for Data Protection and Freedom of Information, the Hungarian National Bank, or other bodies authorized by law may request information, data, or documents from my business as the data controller. My business will provide such authorities with personal data only to the extent strictly necessary to achieve the purpose of their request, provided that the authority specifies the purpose and scope of the requested data.
As a sole proprietor, Ács-Ady Zsuzsanna, acting as the data controller, I treat all personal data entrusted to me confidentially and recognize this legal statement as binding.
No one other than myself, as the service provider, has access to the personal data you provide; the accounting company may only access invoicing data.
My data processing activities are based on voluntary consent or statutory authorization. In cases where processing is based on voluntary consent, data subjects may withdraw their consent at any stage of processing. In certain cases, the handling, storage, and transfer of specific data categories are required by law, in which case clients will be separately informed.
This data management notice is continuously available on my website / Facebook page / in my studio.
Pursuant to Article 13 of the General Data Protection Regulation of the European Union (Regulation No. 679/2016, hereinafter: GDPR), I provide the following mandatory information:
Company name: ÁCS-ADY ZSUZSANNA Sole Proprietor, Data Controller
Tax number: 56524361-1-34
Registered address: 7530 Kadarkút, Hősök tere 1/a, Relaxéria
Website: www.relaxeria.hu
Contact: Tel.: +36 20 232 5582 ; www.facebook.com/Relaxéria ; E-mail: relaxeriakadarkut@gmail.com
Data Protection Officer: Not required under Article 37 of the GDPR
Data Protection Requests: Any requests or questions concerning data processing may be sent by post to the above address and name. Responses will be provided without undue delay, but no later than 30 days to the address you specify.
Data transfer abroad: No data is transferred outside Hungary.
Recording of images/audio in the premises or waiting area: does/does not take place.
Purposes of Data Processing
In connection with massage and physical well-being services, I process clients' personal data to fulfill legal obligations and to maintain client relationships.
When processing the personal data of minors under the age of 16, I require written authorization from a parent or legal guardian at the first appointment.
Legal Bases for Using Your Personal Data
The processing of your personal data is based on the following legal grounds:
-
Issuing invoices in compliance with accounting regulations. Legal basis: GDPR Article 6 (1)(c).
-
Your phone number and first name are required solely for appointment scheduling. Legal basis: GDPR Article 6 (1)(a).
-
In some cases, you may share health-related information for massage or physical well-being services. A treatment record is only created and stored with your explicit consent. Legal basis: GDPR Article 9 (2)(a).
-
You provide consent by giving your phone number and first name (by filling out and signing the treatment record). Without these, the service cannot be provided.
Method and Duration of Data Processing
-
Data is stored on paper.
-
Invoices are kept for at least 5 years due to legal requirements.
Rights of Data Subjects
You have the following rights under applicable law with regard to your personal data. If you wish to obtain further information or exercise any of these rights, you may contact me at any time.
-
Right of access to your personal data processed by me; right to data portability.
-
Rectification of outdated or inaccurate data.
-
Erasure of your personal data (applies only to contact details).
-
Restriction of processing.
-
Prohibition of the use of your personal data for direct marketing.
-
Transfer of your personal data to a third-party provider, or prohibition thereof.
-
Right to receive a copy of your personal data processed by me.
-
Right to object to the processing of your personal data.
Remedies
In Hungary, the supervisory authority for data protection is:
National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9-11
Mailing address: 1363 Budapest, P.O. Box 9
Tel: +36 (1) 391 1400
Fax: +36 (1) 391 1410
E-mail: ugyfelszolgalat@naih.hu
Website: https://www.naih.hu
