Privacy Policy

1. Introduction

Premier Ink. Tattoo (hereinafter Premier Ink. Tattoo, the service provider, the data controller, the Company), as data controller, acknowledges the content of this legal notice as binding upon itself. 
The Company undertakes to ensure that all data processing related to its activities complies with the requirements set out in this policy and in the applicable legislation. 
Premier Ink. Tattoo is the operator of the premierinktattoo.hu website.

Premier Ink. Tattoo reserves the right to amend this notice at any time. It will of course inform its audience of any changes in good time.

Premier Ink. Tattoo is committed to protecting the personal data of its clients and partners and considers it of paramount importance to respect its clients' right to informational self-determination. The Data Controller treats personal data confidentially and takes all security, technical and organizational measures that guarantee the security of the data.

Below, Premier Ink. Tattoo sets out its data processing principles and presents the expectations it has formulated for itself as a data controller and which it observes. Its data processing principles are in line with the applicable data protection legislation, in particular the following:

  • Act CXII of 2011 on the Right to Informational Self-Determination and on Freedom of Information;
  • Act V of 2013 on the Civil Code (Civil Code);
  • Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activity.
  • Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services;
  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: „GDPR”)

2. Definitions

  • data subject: any specified natural person identified on the basis of personal data or – directly or indirectly – identifiable;
  • personal data: data that can be associated with the data subject – in particular the data subject's name, identification mark and information characteristic of one or more of their physical, physiological, mental, economic, cultural or social identity – as well as any conclusion regarding the data subject that can be drawn from it;
  • consent: the voluntary and definite expression of the data subject's wishes, based on adequate information, by which they give their unambiguous agreement to the processing – in full or in respect of individual operations – of personal data relating to them;
  • data controller: the natural or legal person, or organization without legal personality, who or which, alone or jointly with others, determines the purpose of the processing of the data, takes and implements decisions regarding the processing (including the means used), or has them implemented by a data processor;
  • data processing: irrespective of the procedure applied, any operation or set of operations performed on the data, in particular collecting, recording, registering, organizing, storing, altering, using, querying, transmitting, disclosing, aligning or combining, blocking, erasing and destroying the data, as well as preventing further use of the data, taking photographs, audio or video recordings, and recording physical characteristics suitable for identifying a person (e.g. fingerprints or palm prints, DNA samples, iris images);
  • data transfer: making the data accessible to a specified third party;
  • disclosure: making the data accessible to anyone;
  • data erasure: rendering the data unrecognizable in such a way that their restoration is no longer possible;
  • data handling: the performance of technical tasks related to data processing operations, irrespective of the method and means used to carry out the operations and the place of application, provided that the technical task is performed on the data;
  • data processor: the natural or legal person, or organization without legal personality, who or which processes the data on the basis of a contract – including a contract concluded pursuant to a provision of law. 

3. Company details

Our company's details and contact information are as follows:

  • Name: Premier Ink. Tattoo
  • Mailing address: 8200 Veszprém, Móricz Zsigmond utca 15., Hungary
  • Company registration number: 56345861
  • Tax number: 57695808-1-39
  • Phone: +36 70 637 0408
  • E-mail:  info@premierinktattoo.hu
  • Representative of the data controller: Noé Pálma, sole trader, owner

4. The scope of personal data, the purpose, legal basis and duration of processing

We draw the attention of those providing data to Premier Ink. Tattoo that if they do not provide their own personal data, it is the obligation of the person providing the data to obtain the data subject's consent. The data controller is not obliged to verify that such consent exists. The data controller draws the partner's attention to the fact that if the partner fails to fulfil this obligation and the data subject therefore asserts a claim against the data controller, the data controller may pass on the asserted claim or the amount of the related damage to the partner.

We provide the following information in relation to each of our processing activities. 

4.1. Requests for quotes and enquiries by direct contact

Prospective clients have the opportunity to contact our Company directly by electronic mail sent to the Company's address or by telephone.

  • Purpose of processing: keeping in touch, in order to facilitate communication between the data subject and our Company and to ensure the closest and most effective cooperation possible.
  • Legal basis for processing: legitimate interest – GDPR Article 6(1)(f)
  • Scope of personal data processed: name of the person requesting the quote / contact person; e-mail address, phone number, and any other information provided by the data subject,
  • Duration of processing: for 3 years following the expiry of the validity period of the quote, or until the data subject objects
  • Recipients of personal data: the data controller does not pass on the data obtained to third parties, with the exception of the data processor(s) specified in section 7. The recorded data may only be accessed by the employees of the Data Controller and the designated colleagues of the data processor(s).
  • Statement of the legitimate interest: it is our Company's legitimate interest to process the data subject's data – direct marketing
  • Scope of data subjects: partners and data subjects making direct enquiries (e.g. by e-mail or telephone) regarding the Company's services. 

4.2. Requests for quotes and enquiries via the website (premierinktattoo.hu)

Our company provides the opportunity for data subjects to request a quote electronically.

  • Purpose of processing: keeping in touch, in order to facilitate communication between the data subject and our Company and to ensure the closest and most effective cooperation possible.
  • Legal basis for processing: the data subject's voluntary consent – GDPR Article 6(1)(a).
  • Scope of personal data processed: name of the enquirer (first name, surname); e-mail address, phone number, company name, and any other information provided by the data subject.
  • Duration of processing: for 3 years following the expiry of the validity period of the quote, or until consent is withdrawn.
  • Recipients of personal data: the data controller does not pass on the data obtained to third parties, with the exception of the data processor(s) specified in section 7. The recorded data may only be accessed by the employees of the Data Controller and the designated colleagues of the data processor(s).
  • Scope of data subjects: partners and data subjects enquiring via the website about the Company's services and products.

4.3. Processing related to the follow-up of quote requests

  • Purpose of processing: it is the data controller's legitimate interest to keep a record of the data subject's data beyond the validity period of the quote for the purposes of direct marketing
  • Legal basis for processing: the data controller's legitimate interest, GDPR Article 6(1)(f),
  • Scope of personal data processed: contact person's surname and first name; phone number; e-mail address
  • Recipients of personal data: the data controller does not pass on the data obtained to third parties, with the exception of the data processor(s) specified in section 7. The recorded data may only be accessed by the employees of the Data Controller and the designated colleagues of the data processor(s).
  • Duration of processing: until the data subject objects
  • Statement of the legitimate interest: establishing business relationships with partners and those requesting quotes, and providing accurate information to data subjects. It is our Company's legitimate interest to process the data subject's data – direct marketing
  • Scope of data subjects: the addressees of quotes previously issued by the Company and the contact person(s) named in them.

4.4. Newsletter registration

  • Purpose of processing: sending e-mail newsletters that also contain commercial advertising to interested parties, and providing information about current matters
  • Legal basis for processing: the data subject's prior, voluntary consent, GDPR Article 6(1)(a),
  • Scope of personal data processed: name, e-mail address
  • Duration of processing: until voluntary consent is withdrawn or the newsletter is unsubscribed from. Our Company processes the data provided by the data subject until consent is withdrawn. Following the withdrawal of consent, we delete the processed data from our newsletter database within 7 days at the latest, after which we will no longer send you newsletters.
  • Recipients of personal data: the data controller does not pass on the data obtained to third parties, with the exception of the data processor(s) specified in section 7. The recorded data may only be accessed by the employees of the Data Controller and the designated colleagues of the data processor(s). You may unsubscribe from the newsletter at any time by sending a message to our Company at info@premierinktattoo.hu, or by clicking the unsubscribe icon in the newsletter. 
  • Scope of data subjects: partners and data subjects who have subscribed to the Company's electronic newsletter.

4.5. Newsletter data (for newsletter registrations made before 25 May 2018)

  • Purpose of processing: sending e-mail newsletters that also contain commercial advertising to interested parties, and providing information about current matters
  • Legal basis for processing: the data controller's legitimate interest, GDPR Article 6(1)(f),
  • Scope of personal data processed: name, e-mail address
  • Duration of processing: until the data subject objects
  • Statement of the legitimate interest: providing information containing commercial advertising and business offers to data subjects who have subscribed to the newsletter. It is our Company's legitimate interest to process the data subject's data, direct marketing.
  • Recipients of personal data: the data controller does not pass on the data obtained to third parties, with the exception of the data processor(s) specified in section 7. The recorded data may only be accessed by the employees of the Data Controller and the designated colleagues of the data processor(s). You may unsubscribe from the newsletter at any time by sending a message to our Company at info@premierinktattoo.hu, or by clicking the unsubscribe icon in the newsletter. 
  • Scope of data subjects: partners and data subjects who subscribed to the Company's electronic newsletter before 25 May 2018.

4.6. Camera system

Cameras operate on the premises operated by the data controller in the interest of the personal and property security of data subjects and for other purposes. Information signs draw the attention of data subjects to their operation. The activities related to the operation of the camera system are set out in the premises' „Property protection camera data processing notice”, which is available on site.

4.7. Processing related to ensuring the operation of the information technology service

  • Purpose of processing: the Premier Ink. Tattoo websites may use so-called "cookies" (temporary markers) which enable faster access to them. By "cookies" we mean an item of information that is active only for the duration of an individual client session and which is transferred from the website to the Client's computer for the purpose of faster identification. The Client may at any time request that cookies be disabled by changing their browser settings; however, disabling them may slow down or prevent access to some parts of the site and the use of certain functions. 
    The session cookies used avoid the need to resort to other IT tools that are potentially harmful to the confidentiality of clients' navigation and do not make it possible to obtain identifying personal data.
    The user is able to delete cookies from their own computer or to disable the use of cookies in their browser. Cookies can generally be managed in the Tools/Settings menu of browsers under the Privacy settings, named cookies.
  • Legal basis for processing: the data subject's (User's) voluntary consent, GDPR Article 6(1)(a).
    The User gives their voluntary consent to the processing by accepting the pop-up notice and declaration when they begin browsing the website, or by continuing to browse.
    Scope of personal data processed: the information technology processing concerns the range of data necessary for the operation of the "cookies" used to run the website and for the use of the log files applied by the web hosting provider.
  • Duration of processing: until the session is closed
  • Recipients of personal data: the data controller does not pass on the data obtained to third parties, with the exception of the data processor(s) specified in section 7. The recorded data may only be accessed by the employees of the Data Controller and the designated colleagues of the data processor(s).
  • Scope of data subjects: every User visiting the website, irrespective of whether they use the services available on the website.

5. Other processing

We provide information about processing activities not listed in this notice at the time the data is collected. We inform our clients that certain authorities, bodies performing public duties and courts may contact our company for the purpose of disclosing personal data. Our company discloses personal data to these bodies – provided that the body concerned has specified the exact purpose and the scope of the data – only to the extent strictly necessary to achieve the purpose of the request, and only where the fulfilment of the request is prescribed by law. 

6. Transfer of personal data to a third country or an international organization

Our Company does not transfer your above personal data either to a third country or to an international organization.

7. Information on the use of data processors

During the processing, the data controller transfers the data to the data processor(s) contracted by it for the performance of the contract.
Categories of recipients: system administration service provider, accounting and payroll service provider, server hosting, web hosting provider

8. Children

Our services are not intended for persons under the age of 16, and we ask that persons under the age of 16 do not provide Personal data to the Data Controller. 
If it comes to our attention that we have collected personal data from a child under the age of 16 – with the exception of the processing of data required by law – we will take the steps necessary to delete the data as soon as possible.

9. Automated decision-making

Our Company does not apply automated decision-making in its data processing procedures or data collection.

10. The manner of storing personal data, the security of processing

Our company's IT systems and other data retention locations are situated at its registered office and on the servers provided by the data processor. Our company selects and operates the IT tools used for the processing of personal data in the course of providing the service in such a way that the processed data is:

  1. accessible to those authorized to access it (availability);
  2. authentic and its authentication is ensured (authenticity of processing);
  3. verifiable as unchanged (data integrity);
  4. protected against unauthorized access (confidentiality of data).

We pay particular attention to the security of the data, and we furthermore take those technical and organizational measures and establish those procedural rules that are necessary to give effect to the guarantees under the GDPR. We protect the data with appropriate measures, in particular against unauthorized access, alteration, transfer, disclosure, erasure or destruction, as well as against accidental destruction or damage and inaccessibility arising from changes in the technology applied.

The IT systems and networks of our company and our partners are equally protected against computer-assisted fraud, computer viruses, computer intrusions and denial-of-service attacks. The operator also ensures security through server-level and application-level protection procedures. Daily backup of the data is in place. Our company takes every possible measure to avoid data protection incidents; should such an incident occur, we act without delay – in accordance with our incident management policy – to minimize the risks and remedy the damage.

11. Rights of data subjects, remedies

The data subject may request information about the processing of their personal data, and may request the rectification or – with the exception of mandatory processing – the erasure or withdrawal of their personal data, and may exercise their right to data portability and their right to object in the manner indicated at the time the data was collected, or via the data controller's contact details above.

The rights and remedies of data subjects are set out below and communicated to data subjects on the basis of Act CXII of 2011 and Regulation (EU) 2016/679. 

The right to information, otherwise known as the data subject's „right of access”: pursuant to Act CXII of 2011 and Article 15 of Regulation (EU) 2016/679, at the data subject's request the Data Controller provides information on 

  • the data and categories of personal data it processes,
  • the purpose of the processing,
  • the legal basis of the processing,
  • the duration of the processing,
  • where applicable, the period for which the data will be stored, or if this is not possible, the criteria used to determine that period,
  • where applicable, if the data was not collected from the data subject, all available information as to their source,
  • where applicable, automated decision-making, including profiling, and meaningful information about the logic involved, as well as the significance of such processing, and
  • the envisaged consequences of such processing for the data subject,
  • the details of the data processor, if a data processor has been used, and the circumstances and effects of the data protection incident and the measures taken to remedy it, and furthermore
  • in the case of a transfer of the data subject's personal data, the legal basis, purpose and recipient of the transfer.

The provision of information is free of charge if the person requesting the information has not yet submitted a request for information to the Data Controller in the current year concerning the same scope of data. In other cases, a fee may be charged. Any fee already paid must be refunded if the data was processed unlawfully or if the request for information led to a rectification.

The Data Controller draws the attention of data subjects to the fact that information must be refused pursuant to Act CXII of 2011,

  1. if, on the basis of a provision of law, an international treaty or a binding legal act of the European Union, the Data Controller receives personal data in such a way that the transferring data controller indicates, simultaneously with the transfer, a restriction of the rights guaranteed to the data subject of the personal data under the said act, or another restriction of its processing.
  2. in the interest of the external and internal security of the state, such as national defence, national security, the prevention or prosecution of criminal offences and the security of the enforcement of penalties, and furthermore for state or local government economic or financial reasons, for a significant economic or financial interest of the European Union, and for the purpose of preventing and detecting disciplinary and ethical breaches connected with the practice of professions and breaches of labour law and occupational safety obligations – including in every case inspection and supervision – and furthermore in the interest of protecting the rights of the data subject or of others.

The Data Controller is obliged to notify the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) annually, by 31 January of the year following the year in question, of requests for information that have been refused.

The right to rectification: the data subject has the right to obtain from the Data Controller, without undue delay, the rectification of inaccurate personal data concerning them. Taking into account the purposes of the processing, the data subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement. At the same time, if the personal data does not correspond to reality and the Data Controller has the personal data corresponding to reality at its disposal, the Data Controller shall rectify the personal data as a matter of obligation, even without a request from the data subject.

The right to erasure, otherwise known as the „right to be forgotten”: the data subject has the right to obtain from the Data Controller the erasure of personal data concerning them without undue delay, and the Data Controller is obliged to erase personal data concerning the data subject without undue delay, unless mandatory processing precludes this.

In addition to the above case, the Data Controller is obliged to erase the data pursuant to Act CXII of 2011 and Regulation (EU) 2016/679 of the European Parliament and of the Council if

  • the processing of the data is unlawful;
  • the data is incomplete or incorrect – and this state of affairs cannot lawfully be remedied – provided that erasure is not precluded by law;
  • the purpose of the processing has ceased, or the statutory time limit for storing the data has expired;
  • it has been ordered by a court or by the Authority.
  • the personal data is no longer necessary for the purpose for which it was collected or otherwise processed;
  • the data subject objects to the processing and there is no overriding legitimate ground for the processing;
  • the personal data must be erased in order to comply with a legal obligation under the law applicable to the Data Controller;
  • the personal data was collected in relation to the offer of information society services referred to in Article 8(1) of Regulation (EU) 2016/679 offered directly to children.

Where the Data Controller has for some reason made the personal data public and is obliged to erase it in accordance with the above, it shall, taking account of available technology and the cost of implementation, take reasonable steps – including technical measures – to inform other controllers processing the data that the data subject has requested the erasure of any links to, or copy or replication of, the personal data in question.

The Data Controller draws the attention of data subjects to the limits on the right to erasure or the „right to be forgotten” arising from the EU regulation, which are as follows:

  1. exercising the right to freedom of expression and information;
  2. compliance with an obligation under Union or Member State law applicable to the controller which requires the processing of personal data, or the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  3. public interest in the area of public health;
  4. archiving purposes in the public interest, scientific and historical research purposes or statistical purposes in accordance with Article 89(1) of Regulation (EU) 2016/679, in so far as the right to erasure is likely to render impossible or seriously impair the achievement of that processing; or
  5. the establishment, exercise or defence of legal claims.

The right to restriction of processing, otherwise known as the right to blocking: the data subject has the right to obtain from the Data Controller restriction of processing at their request.
If, on the basis of the information available to it, it may be assumed that erasure would harm the legitimate interests of the data subject, the data must be blocked. Personal data blocked in this way may be processed only for as long as the processing purpose that precluded the erasure of the personal data continues to exist.

If the data subject contests the accuracy or correctness of the personal data but the incorrectness or inaccuracy of the contested personal data cannot be unambiguously established, the data is blocked. In this case, the restriction applies to the period that enables the Data Controller to verify the accuracy of the personal data.

Pursuant to the EU regulation, the data must be blocked if

  1. the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of its use instead;
  2. the Data Controller no longer needs the personal data for the purposes of the processing, but the data subject requires it for the establishment, exercise or defence of legal claims; or
  3. the data subject has objected to the processing; in this case the restriction applies to the period until it is established whether the legitimate grounds of the Data Controller override those of the data subject.

Where processing is subject to restriction (blocking), such personal data may, with the exception of storage, be processed only with the data subject's consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State.

The Data Controller hereby expressly draws the attention of data subjects to the fact that the data subject's right to rectification, erasure and blocking may be restricted by law in the interest of the external and internal security of the state, such as national defence, national security, the prevention or prosecution of criminal offences and the security of the enforcement of penalties, and furthermore for state or local government economic or financial reasons, for a significant economic or financial interest of the European Union, and for the purpose of preventing and detecting disciplinary and ethical breaches connected with the practice of professions and breaches of labour law and occupational safety obligations – including in every case inspection and supervision – and furthermore in the interest of protecting the rights of the data subject or of others.
The Data Controller shall inform the data subject of the matters set out in their request without undue delay, and at the latest within 30 days of receipt of the request, and/or rectify the data, and/or erase and/or restrict (block) the data, or take other steps in accordance with the request, unless there is a ground precluding this.

The Data Controller shall notify the data subject in writing of the rectification, the erasure and the restriction of processing, and shall also notify all those to whom the data was previously transferred or handed over for the purposes of processing. At the data subject's request, the Data Controller shall inform them of these recipients. Notification may be omitted if, having regard to the purpose of the processing, this does not harm the legitimate interests of the data subject, or if providing the information proves impossible or would require a disproportionate effort. The Data Controller is also obliged to notify the data subject in writing if the exercise of the data subject's rights cannot be realized for some reason, and is obliged to specify precisely the factual and legal grounds, as well as the remedies available to the data subject: the possibility of turning to the courts and to the National Authority for Data Protection and Freedom of Information.

The „right to data portability”: the data subject has the right to

  1. receive the personal data concerning them, which they have provided to the Data Controller, in a structured, commonly used, machine-readable format, and furthermore has the right to
  2. transmit that data to another controller without hindrance from the controller to which the personal data was provided, where:
  3. the processing is based on consent; and
  4. the processing is carried out by automated means.

In exercising the right to data portability, the data subject has the right to request – where technically feasible – the direct transmission of the personal data between controllers.
Having regard to the processing activities carried out by the Data Controller, the conditions for exercising the right to data portability are not met (there is no automated processing), and therefore the data subject cannot exercise this right.

The right to object: the data subject may object to the processing of their personal data – including profiling – if

  • the processing (transfer) of the personal data is necessary solely for the enforcement of a right or legitimate interest of the Data Controller or the recipient of the data, except in the case of mandatory processing;
  • the personal data is used or transferred for the purposes of direct marketing, public opinion polling or scientific research;
  • the exercise of the right to object is otherwise permitted by law.

The data subject may also object, on the basis of Article 21(3) of Regulation (EU) 2016/679, to the processing of personal data for the purposes of direct marketing; in that case the personal data may no longer be processed for such purposes.

Where personal data is processed for scientific and historical research purposes or statistical purposes, the data subject has the right to object, on grounds relating to their particular situation, to the processing of personal data concerning them, unless the processing is necessary for the performance of a task carried out for reasons of public interest.
The Data Controller shall examine the objection – while simultaneously suspending the processing – within the shortest possible time from the submission of the request, but within 30 days at the latest, and shall inform the applicant of the outcome in writing. If the applicant's objection is well founded, the Data Controller shall terminate the processing – including any further data collection and data transfer – and shall block the data, and shall notify of the objection and of the measures taken on the basis of it all those to whom the personal data concerned by the objection was previously transferred and who are obliged to act in order to give effect to the right to object.

If the data subject does not agree with the Data Controller's decision, or if the Data Controller fails to observe the aforementioned time limit, the data subject is entitled – within 30 days of its communication – to turn to the courts.
The data subject has the right to object in relation to automated decision-making.

Judicial enforcement: in the event of a violation of their rights, the data subject may turn to the courts. The court shall deal with the case as a matter of priority. It is the Data Controller's obligation to prove that the processing complies with the provisions of the law.

In the event of a violation of your right to informational self-determination, you may submit a report or complaint to:

National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c, Hungary
Phone: +36 (1) 391-1400, Fax: +36 (1) 391-1410
www: http://www.naih.hu
e-mail: ugyfelszolgalat@naih.hu

Map