Data management and data protection information

Opening Provisions

The purpose of this Notice is to set out the data protection and data processing principles and policy applied by TRIUM-ITECH Zrt., and to fulfill the information obligations under Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: GDPR).

In the course of operating the website https://www.potapingpong.hu/ (hereinafter: the “Website“), TRIUM-ITECH Zrt. processes the data of visitors to the Website and of persons utilizing the services of the Data Controller that are available and purchasable via the Website (hereinafter: “Service” or “Services“) (hereinafter collectively: the “Data Subject“).

TRIUM-ITECH Zrt. acknowledges the content of this legal notice as binding upon itself. It undertakes to ensure that all data processing related to its activities complies with the requirements set forth in this policy, applicable national legislation, and the legal acts of the European Union.

TRIUM-ITECH Zrt. is committed to protecting the personal data of data subjects and attaches great importance to respecting their right to information self-determination (particularly that of users of the Service). TRIUM-ITECH Zrt. treats personal data confidentially and implements all security, technical, and organization-wide measures necessary to guarantee the security of data.

Concepts

The basic concepts of data processing are defined in detail by Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (hereinafter: Infotv.) and the GDPR. Key concepts for the interpretation of this notice: “personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, a number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person; “controller” means the natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of the processing are determined by Union or Member State law, the controller or the specific criteria for the designation of the controller may also be determined by Union or Member State law; “processing” means any operation or set of operations which is performed on personal data or on data sets, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction; “processor” means the natural or legal person, public authority, agency or any other body which processes personal data on behalf of the controller; “recipient” means the natural or legal person, public authority, agency or any other body to whom or to which personal data are disclosed, whether or not a third party. Public authorities which may have access to personal data in the context of a specific investigation in accordance with Union or Member State law shall not be considered recipients; the processing of such data by those public authorities must comply with the applicable data protection rules in accordance with the purposes of the processing; “restriction of processing”: the marking of stored personal data with a view to restricting their future processing; “filing system”: a file of personal data, whether centralised, decentralised or organised by function or geographical area, which is accessible on the basis of specific criteria; “third party”: a natural or legal person, public authority, agency or any other body other than the data subject, the controller, the processor or the persons who, under the direct authority of the controller or processor, are authorised to process personal data; “data subject’s consent”: any freely given, specific, adequately informed and unambiguous indication of the data subject’s wishes by which the data subject, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data concerning him or her; “data breach”: any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed;

Principles

Personal data:
  1. a) must be processed lawfully and fairly and in a manner that is transparent to the data subject (“lawfulness, fairness and transparency”);
  2. b) must be collected only for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes (“purpose limitation”);
  3. c) must be adequate and relevant in relation to the purposes for which the data are processed and limited to what is necessary (“data economy”);
  4. d) must be accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data which are inaccurate, having regard to the purposes of the processing, are erased or rectified without delay (“accuracy”);
  5. e) stored in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for a longer period only if the personal data are processed for archiving purposes in the public interest, scientific and historical research purposes or statistical purposes in accordance with Article 89(1), subject to the implementation of appropriate technical and organisational measures to protect the rights and freedoms of data subjects (‘storage limitation’);
  6. (f) processing shall be carried out in such a way that appropriate technical or organisational measures are applied to ensure the appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage (‘integrity and confidentiality).
The controller shall be responsible for compliance with the above principles and shall be able to demonstrate such compliance (‘accountability’).

I. Data of the data controller and data processor(s)

1.1. Data Controller: Data Controller Name: TRIUM-ITECH Zrt. Head Office: 1149 Budapest, Angol utca 34. E-mail: info@potapingpong.hu Website: www.potapingpong.hu 1.2. Data processor(s): The data controller uses the following data processors:
Reason for data processing: Name of data processor: Address and other contact details of data processor:
Hosting service, Mailing system operator Tárhely.Eu Szolgáltató Kft. 1097 Budapest, Könyves Kálmán körút 12-14. support@tarhely.eu
Accounting
Operator of electronic accounting system KBOSS.hu Kft. 1031 Budapest, Záhony utca 7. info@szamlazz.hu www.szamlazz.hu
Online payment service provider available on the website SimplePay Zrt. 1138 Budapest, Váci út 135-139. B. ép. 5. em. https://simplepay.hu/ ugyfelszolgalat@simple.hu +36 1 3-666-611 +36 20 3-666-611 +36 30 3-666-611 +36 70 3-666-611
1.3. Data Protection Officer The Data Controller has considered the possibility of appointing a Data Protection Officer based on Article 37 of the GDPR and has concluded that the data processing occurring during visits to the Website or purchases made on the Website does not justify the appointment of a Data Protection Officer.

II. Legal basis, purpose and method of data processing, as well as the scope of personal data processed and the duration of data processing

2.1. Data processing related to visiting the Website

The data processing carried out during the visit to the Website and the visitor’s stay on the Website is carried out in order to operate the site and ensure the user experience, including the use of cookies.

Processed data:

  • technical data

Which includes data generated during the use of the site, such as IP address, login information, browser data, time of visit to individual pages, page views and navigation paths, number and time of page visits, time zones, and data about the device with which you view the site.

The source of the data is our analytical software.

We process the above data in order to analyze the habits of the Data Subjects on the site, maintain the secure operation of our site, and understand the usefulness of our individual marketing decisions.

In the course of our activities, we do not collect personal data, nor sensitive data such as ethnicity, religious beliefs, sexual life and orientation, political opinions and trade union membership, or health background, and genetic or biometric information.

2.2. Data processing related to the use of the Website (registration)

The Services displayed on the Website are exclusively accessible and usable online through the Website.

The purpose of the Website is to provide users (data subjects) with assistance in compiling a project and its electrical equipment, which users can order from the Webshop, and to prepare a quote for their customers.

The electronic availability of the General Terms and Conditions (GTC) for the use of the services on the Website: https://potapingpong.hu/altalanos-szerzodesi-feltetelek/

 

You can only use the services of the Website by registering. In this context, we process your personal data as follows:

Scope of processed personal data: username, surname and first name, address/billing address, e-mail address, telephone number, and other personal data provided by you.

Purpose of data processing: to identify you, to ensure the use of the services of the Website, and to create and fulfill the contract between you and the Data Controller for the purchase of a Service.

Legal basis for data processing: necessary for the performance of a contract/to take steps prior to concluding a contract [GDPR Article 6 (1) (b)].

Duration of data processing: Duration of data processing: for the period necessary to fulfill the contract between you and the Data Controller for the purchase of the Service, up to the time limit for civil law claims (5 years).

The Data Controller does not verify the authenticity or correctness of the personal data provided by you (e.g. e-mail address, etc.). The person who provided them is solely responsible for the correctness of the data. The Data Controller excludes any liability arising from incorrect data.

2.3. Purchase on the Website

2.3.1. Personal data processed for the purpose of payment of the Service

You can pay for the Service – depending on the selected service – with the following payment methods: bank card payment via the SimplePay system.

Personal data processed: username, surname and first name, billing and shipping address, e-mail address, bank account number, value of the ordered service, transfer time, telephone number (optional).

Purpose of data processing: your identification, fulfillment of the contract between you and the Data Controller for the purchase (use) of the Service.

Legal basis for data processing: fulfillment of a contract (GDPR Article 6 (1) point b).

Duration of data processing: 8 years in order to fulfill the obligation to preserve accounting documents (Accounting Act Section 169 (2)).

We use the following external service providers to provide the Services:

  • Name of the data processor/independent data controller: SimplePay Zrt.
  • Headquarters: 1138 Budapest, Váci út 135-139. B. ép. 5th amendment.
  • Company registration number: 01-10-143303
  • Scope of data transferred: Username, surname, first name, country, telephone number, e-mail address, name of the purchased product/service, amount, order number.
  • Purpose of data transfer: Providing customer service assistance to the Data Subject, confirming transactions, filtering out abuses (fraud monitoring), and fraud profiling for the protection of Data Subjects.
  • Legal basis for data transfer: data processing is necessary for the performance of the contract [GDPR Article 6 (1) (b)].
  • Reference to the partner’s data processing information: SimplePa

III. Access to data, method of storing personal data, security measures

The data is only accessible to the data controller and its commissioned data processors (e.g. hosting service providers, payment service providers and online billing platforms) to the extent necessary. The Data Controller, taking into account the state of science and technology, implements appropriate technical, administrative and organizational measures to guarantee data security:
  • only our employees and partners who have been authorized to do so have access to personal data;
  • the Website receives data encrypted via a secure HTTPS protocol, so it is not possible for unauthorized persons to access personal data through any network device between the target server;
  • Our employees use operating systems and software with the latest security updates in the performance of their duties;
  • We encrypt our backups;
  • We delete personal data that is no longer required or anonymize it for statistical purposes.
  • Our hosting provider’s servers operate in a secure data center;
  • The Website stores personal data on its IT equipment located at its headquarters and on the hosting provider’s secure data center. stores it on its servers.
The Data Controller shall keep records of any data protection incidents, indicating the facts related to the data protection incident, its effects and the measures taken to remedy it. The Data Controller shall notify the National Data Protection and Freedom of Information Authority of any data protection incident without delay and, if possible, no later than 72 hours after it has become aware of the data protection incident, unless the data protection incident is unlikely to result in a risk to the rights and freedoms of natural persons. We regularly review our security measures, record the necessary actions in our internal Incident Management Policy and our employees always perform their duties in accordance with the current policy.

IV. Rights of data subjects and possibilities for enforcement

The Data Subject may at any time request information about the processing of his or her personal data processed by the Data Controller, and may request the correction of his or her personal data, or – with the exception of mandatory data processing – its deletion, withdrawal, and exercise his or her right to data portability and objection through the Data Controller’s contact details provided in point 1. The deletion does not apply to any data processing required by law (e.g. accounting regulations), which the Data Controller will retain for the necessary period. Right to information: The data subject has the right to contact the Data Controller in writing via the Data Controller’s contact details provided in point I. with a request for information regarding the processing of his or her personal data. The Data Controller shall inform the data subject without undue delay, but in any case within one month of receipt of the request, of the measures taken in response to the data subject’s request. If necessary, taking into account the complexity of the request and the number of requests, the 30-day deadline may be extended by another two months. The Data Controller shall inform the data subject of the extension of the deadline, indicating the reasons for the delay, within one month of receipt of the request. If the data subject submitted the request electronically, the Data Controller shall provide the information electronically, unless the data subject requests otherwise. The Data Controller shall provide the information and the action free of charge. If the data subject’s request is manifestly unfounded or, in particular, excessive due to its repetitive nature, the Data Controller may charge a reasonable fee, taking into account the administrative costs of providing the requested information or information or taking the requested action, or may refuse to take action on the basis of the request. Right of access: The data subject shall have the right to receive from the Data Controller feedback on whether personal data concerning him or her are being processed and, where such processing is being carried out, access to the personal data and the following information: the purposes of the processing; the categories of personal data concerned; the recipients or categories of recipients to whom the personal data have been or will be disclosed, including in particular recipients in third countries or international organisations; the planned period for which the personal data will be stored; the right to rectification, erasure or restriction of processing and to object; the right to lodge a complaint with a supervisory authority; information on the sources of the data; the fact of automated decision-making, including profiling, as well as intelligible information on the logic involved and the significance and foreseeable consequences of such processing for the data subject. The controller shall provide the data subject with a copy of the personal data subject to processing. For further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs. At the data subject’s request, the controller shall provide the information in electronic form. Right to rectification: The data subject may request the rectification of inaccurate personal data concerning him or her and the completion of incomplete data. Right to erasure: The data subject shall have the right to obtain from the Controller the erasure of personal data concerning him or her without undue delay where one of the following grounds applies:
  • the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
  • the data subject withdraws his or her consent to the processing and there is no other legal basis for the processing;
  • the data subject objects to the processing and there are no overriding legitimate grounds for the processing;
  • the personal data have been processed unlawfully;
  • the personal data must be erased for compliance with a legal obligation to which the controller is subject under Union or Member State law;
  • the personal data were collected in connection with the provision of information society services.
Erasing of data cannot be requested in the case of mandatory processing: Article 6 GDPR. in the case of a legal basis based on Article (1) point (c) of the GDPR. Right to restriction of processing: At the request of the data subject, the Controller shall restrict the processing of the data where one of the following conditions is met:
  • the data subject contests the accuracy of the personal data, in which case the restriction shall apply for a period enabling the accuracy of the personal data to be verified;
  • the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead;
  • the data controller no longer needs the personal data for the purposes of the processing, but the data subject requires them for the establishment, exercise or defence of legal claims

V. Automated decision-making

The Data Controller does not carry out automated decision-making and profiling with the Data Subject’s personal data.

VI. Managing Cookies

The website uses technical cookies for the operation of the website and for the best possible user experience. In addition, cookies for statistical and marketing purposes only work with the consent of the Data Subject. The Data Subject can modify or delete cookies in the browser settings at any time. Regarding cookie settings, we would like to point out that the use of cookies is permitted by default in browsers. The Data Subject can delete cookies from their computer or even set their browser to block their use. In the latter case, we would like to point out that the operation of the site will not be fully functional. By clicking the “I accept” button on the Website, the Data Subject consents to the use of cookies managed by our own or external service providers (“third parties”) necessary to record the data and information written in this notice. Such data is the data of the Data Subject’s computer that is generated when using our website or that is recorded as an automatic result of technical processes by the cookies used on our website. The automatically recorded data is automatically logged by the system – without the specific consent of the Data Subject – when visiting or leaving the website. We do not link this data with any other personal data and the Data Subject cannot be identified. Only we and the service provider managing the cookies have access to this data. More detailed information about cookie settings for the following browsers: https://support.google.com/accounts/answer/61416?hl=hu https://support.mozilla.org/hu/kb/sutik-informacio-amelyet-weboldalak-tarolnak-szami?redirectlocale=hu&redirectslug=S%C3%BCtik+kezel%C3%A9se https://support.microsoft.com/hu-hu/help/17442/windows-internet-explorer-delete-manage-cookies https://privacy.microsoft.com/en-us/windows-10-microsoft-edge-and-privacy

VII. Amendment of the data processing information

The Data Controller reserves the right to unilaterally modify or withdraw this data management information at any time, with prior notification to the Data Subjects on the Website. The information is published on the Website. By continuing to use the Website, the Data Subject accepts the modified terms and conditions.

VIII. Other provisions

This Privacy Policy is valid from 28 May 2026 until withdrawn The content of the Privacy Policy has been prepared in accordance with the provisions of the following legal acts: Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data Act CVIII of 2016 on certain aspects of electronic commerce services and information society services Act XLVIII of 2016 on the basic conditions and certain restrictions of economic advertising The court, the prosecutor, the investigating authority, the misdemeanour authority, the administrative authority, the National Data Protection and Freedom of Information Authority, the Hungarian National Bank, or other bodies authorized by law may contact the Data Controller to provide information, communicate, transfer data, or make documents available. The Data Controller shall only disclose personal data to the authorities – if the authority has specified the precise purpose and scope of the data – to the extent and insofar as this is absolutely necessary to achieve the purpose of the request. The Data Controller shall not be subject to the provisions of any code of conduct. Dated: Budapest, 28 May 2026.

SIMPLEPAY
Data transfer statement

I acknowledge that the following personal data stored in the user database of www.potapingpong.hu by the data controller TRIUM-ITECH Zrt. (1149 Budapest, Angol utca 34.) will be transferred to SimplePay Zrt. as the data processor. The scope of data transmitted by the data controller is as follows:
  • Surname, first name
  • Country
  • E-mail address
  • Amount and currency
  • Order number
The nature and purpose of the data processing activity carried out by the data processor can be viewed in the SimplePay Data Processing Information, at the following link: http://simplepay.hu/vasarlo-aff

Sikeres üzenetküldés

Válaszunkkal hamarosan jelentkezünk!

Feliratkozás

Értesülj eseményeinkről, versenyekről, akciókról első kézből.

Érdeklődöm

Írj nekünk, ha kérdésed van, vagy érdeklődsz a lehetőségeinkről