The “Sanya Dance Education” website, operated by Tóth Sándor Sole Proprietor (Registration No.: 53651727) at www.sanyatancoktatas.hu (hereinafter referred to as the “Website”), respects the personal data rights of all visitors. In accordance with applicable Hungarian legislation, by providing the information required for contacting us through the Website and registering for workshops or private lessons, you consent to Tóth Sándor Sole Proprietor using and processing your data as necessary, in compliance with the relevant legal requirements.
Please note that providing your data is voluntary. You have the right at any time to request information regarding data processing, as well as to request the correction or deletion of your data by contacting Tóth Sándor Sole Proprietor (1237 Budapest, Hrivnák Pál utca 61.) or by email at sanyatancoktatas@gmail.com. We assume no responsibility for the accuracy of the data provided by you.
1. Data Controller
This Privacy Policy and Data Processing Notice (hereinafter: “Privacy Notice”) sets out the data processing rules and privacy information applicable to users (hereinafter: “User”) of the Website www.sanyatancoktatas.hu, operated by:
Sanya Dance Education
Address: 1237 Budapest, Hrivnák Pál utca 61.
Representative: Tóth Sándor Sole Proprietor
Email: sanyatancoktatas@gmail.com
(hereinafter: “Data Controller”).
This Privacy Notice complies with:
- Act CXII of 2011 on Informational Self-Determination and Freedom of Information (“Info Act”);
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (“GDPR”).
2. Contacting Us Through the Website
Purpose of Data Processing
The Website operates a messaging system through which visitors may send messages to the Website operator without registration. Two-way communication requires the processing of the visitor’s contact information.
Categories of Personal Data Processed
When sending a message, the following data are stored:
- Public IP address
- Timestamp of submission
- Name
- Email address
- Message content
- Telephone number
Legal Basis
Voluntary consent of the data subject pursuant to Article 6(1)(a) GDPR.
Retention Period
Personal data provided during contact requests are processed from the time of contact and deleted after five years. Users may withdraw their consent and request deletion of their data at any time during this period.
This does not affect retention obligations required by law (e.g., tax legislation) or additional processing activities based on further consent given by the user.
3. Server Logging
Purpose of Data Processing
To ensure:
- IT system security and prevention of abuse;
- Uninterrupted operation of the Website;
- Optimization of Website performance.
Categories of Data Processed
When visiting the Website, the system automatically records data in log files, including:
- Date and time of access
- Name of the requested file
- Referring website URL
- IP address
- Amount of transferred data
- Operating system used
- Browser type and version
Legal Basis
Article 6(1)(f) GDPR (legitimate interest), as the Data Controller has a legitimate interest in ensuring the secure operation of the Website.
Retention Period
30 days.
4. Use of Cookies
Purpose
To provide personalized services and improve user experience.
Data Processed
The Data Controller places and reads small data files (“cookies”) on the user’s device. When a browser returns a previously stored cookie, the service provider can associate the current visit with previous visits relating to its own content.
Legal Basis
Consent of the data subject pursuant to Article 6(1)(a) GDPR. Consent may be withdrawn at any time. Users may delete cookies or disable their use through browser settings.
Retention Period
12 hours.
5. Data Stored When Registering for Workshops and Private Lessons
Purpose of Data Processing
The Website provides an online registration service through its “Registration” and “Contact” functions. This service enables two-way communication between the Data Controller and end users.
Legal Basis
Voluntary consent pursuant to Article 6(1)(a) GDPR.
Categories of Data Processed
Workshop registration:
- Name
- Email address
- Telephone number
- Address (optional)
Private lesson registration:
- Name
- Email address
- Telephone number
- Address
Retention Period
Until consent is withdrawn, but no later than one year after the user’s last activity if no services are used during that period.
6. General Rules of Data Processing
The Data Controller does not use personal data for purposes unrelated to its operations. Personal data are disclosed to third parties or authorities only with the user’s prior explicit consent unless otherwise required by law.
Users are solely responsible for the accuracy of the personal data they provide. By providing an email address, users acknowledge responsibility for all activity conducted through that address.
7. Persons Entitled to Access Data, Data Transfers, and Data Processors
Personal data are primarily accessible only to the Data Controller and are not published or transferred to third parties.
The Data Controller may engage external service providers for:
- IT system operation
- Order fulfillment
- Accounting and administration
The Data Controller ensures that such providers offer appropriate guarantees for GDPR compliance and the protection of data subjects’ rights.
Users are advised to provide only information strictly necessary for the purposes described above. Personal data are protected through appropriate technical, organizational, and security measures. However, internet-based data transmission cannot be considered completely secure.
Hosting Provider
Rackhost Zrt.
Address: 1132 Budapest, Victor Hugo utca 18–22.
Company Registration Number: 06-10-000489
Website: https://rackhost.hu/
8. User Rights and Remedies
Users have the right to:
- Request information regarding their personal data;
- Correct inaccurate data;
- Request deletion of their data;
- Withdraw consent at any time.
The Data Controller will provide requested information within 30 days of receiving a request. Correction or deletion requests must be fulfilled within three business days. Deleted data cannot be restored, except where retention is required by law.
Users may enforce their rights before a court or file a complaint with the:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH).
If false information is intentionally provided or damage is caused through use of the Website, the Data Controller reserves the right to seek compensation and cooperate with authorities to identify the responsible party.
9. Use of Email Addresses
The Data Controller pays particular attention to the lawful use of email addresses. Email addresses are primarily used for:
- User identification;
- Receiving user inquiries;
- Responding to user inquiries;
- Maintaining communication with users.
10. Miscellaneous Provisions
The Data Controller’s IT systems may collect activity-related information that cannot be linked to personal data provided during contact requests or data generated through other websites or services.
Where personal data are intended to be used for purposes different from the original purpose of collection, users will be informed and given the opportunity to exercise their rights, including granting or withholding consent.
The Data Controller undertakes to ensure data security and implement all necessary technical measures to protect collected and stored personal data against destruction, unauthorized access, unauthorized use, and unauthorized modification.
The Data Controller reserves the right to amend this Privacy Notice unilaterally with prior notice to users. Continued use of the Website after the amendments take effect constitutes acceptance of the updated Privacy Notice.