Anteus

Privacy Policy

Based on EU Regulation 2016/679 (GDPR) and the applicable Hungarian data protection legislation.

1. Introduction

It is important to us to comply with the applicable data protection rules. Below we describe what personal data Anteus Fejlesztő, Kereskedelmi és Szolgáltató Korlátolt Felelősségű Társaság (hereinafter: Data Controller) processes, for what purpose and on what legal basis, and what rights you have.

Contact details of the Data Controller:
Anteus Fejlesztő, Kereskedelmi és Szolgáltató Korlátolt Felelősségű Társaság
Mailing address: 1163 Budapest, Veres Péter út 48.
E-mail: info@anteus.hu
Phone: +36 1 9000 300

2. What personal data do we process, and for what purpose?

The webshop is a closed, business-to-business (B2B) system. The scope of data processed:

  • Communication data – messages sent to us (web messaging, e-mail). Purpose: answering enquiries, fulfilling orders, handling possible legal claims. Legal basis: legitimate interest (GDPR Article 6(1)(f)).
  • Registration and customer data – company name, tax number, contact person's name, e-mail address, phone number, billing and shipping address, data of ordered products. Purpose: creating and approving the company account, fulfilling orders, invoicing. Legal basis: performance of a contract (Article 6(1)(b)) and legal obligation (Article 6(1)(c) – accounting).
  • User data – data required for the technical operation and security of the account and the service. Legal basis: legitimate interest, performance of a contract.
  • Technical / visit data – the time and duration of the visit, pages and product range viewed, the referring source, session identifier. Source: the system's built-in, own visit-measurement solution. Purpose: developing the service and maintaining its secure operation. The data is stored in a manner unsuitable for direct identification (session-based). Legal basis: legitimate interest.
  • Marketing data – if you consent, partner contact data for newsletter/campaign purposes. Legal basis: consent (Article 6(1)(a)), or legitimate interest in the case of an existing partner relationship.

We do not collect special (sensitive) data, such as health, religious, political or biometric data.

3. How do we collect data?

We obtain personal data primarily directly from you (registration, order, message). Certain technical data is generated during the use of the Website by the system's own tools. By default the Website does not load external (third-party) advertising or analytics tracking code; the content security policy (CSP) restricts the execution of external scripts.

4. Data security measures

  • The entire Website is accessible over an encrypted (HTTPS) connection with a valid certificate.
  • Passwords are stored in an irreversible (hashed) form; the access keys of external systems are encrypted.
  • Role-based access control, activity logging and regular backups protect the data.
  • The details of the security measures are contained in the operator's IT security policy and disaster recovery plan.

5. Data processors and recipients

To maintain the business, we cooperate with the following data processors; the processing with them is governed by contract:

  • Hosting provider: Webinit – operation of the system and secure storage of the data. It does not carry out independent data processing. Legal basis: performance of a contract, legitimate interest (secure operation).
  • Courier services: the provider indicated in the ordering process (e.g. GLS, Englmyer). Data transferred: name, shipping address, e-mail, phone number, order identifier and delivery note. Purpose: organising delivery. Legal basis: performance of a contract.
  • Invoicing and data reporting: the Service Provider's own integrated invoicing module issues the invoice and fulfils the NAV Online Invoice data reporting. Data transferred: the company and item data required for the invoice. Legal basis: legal obligation (accounting, tax data reporting).
  • Expert partners (accountant, lawyer) and authorities – on the basis of a legal obligation or legitimate interest, to the extent necessary.

If the Service Provider introduces online card payment or an external analytics/advertising provider in the future, this will be indicated separately in this Policy and at checkout.

6. International data transfer

We process your data primarily within the European Economic Area (EEA). If any provider transfers data outside the EEA, we do so only with the appropriate safeguards under the GDPR (e.g. an adequacy decision of the European Commission or approved contractual clauses).

7. Duration of data processing

We store the data only for as long as necessary to achieve the purpose or to fulfil legal obligations. We retain invoicing and purchase data for at least 8 years under accounting rules. In anonymised form we may use the data for statistical purposes for an unlimited time.

8. Your rights

Under the GDPR you have the right to access (information and a copy of the data processed about you), rectification, erasure, restriction of processing, data portability and objection. You can submit your request to info@anteus.hu; we generally fulfil the request free of charge within 14 (and at most, as a legal maximum, 30) days. To prevent abuse, we may request verification of identity. Erasure may result in the termination of account-linked services; erasure does not affect data subject to a statutory retention obligation.

If you believe that the processing of your data is unlawful, you may lodge a complaint with the supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
1055 Budapest, Falk Miksa utca 9-11.
Mailing address: 1363 Budapest, Pf.: 9.
Phone: 06 (1) 391 1400
E-mail: ugyfelszolgalat@naih.hu
Website: naih.hu

9. Cookies

The Website uses cookies necessary for its operation (session and security cookies), which are required for logging in, keeping the cart and secure operation. By default the system does not load marketing or external analytics cookies. You can disable cookies in your browser at any time, but this may limit the operation of some functions.

10. Marketing communication

We send marketing messages only if you have consented to this, or an existing partner relationship exists. Consent can be withdrawn at any time, and we provide the option to unsubscribe in every newsletter. Even after unsubscribing, we may send non-marketing notifications related to the fulfilment of orders.

11. Amendment of the Policy

The Data Controller reserves the right to amend this Policy. We publish amendments on the Website; in the case of a material change we inform registered users.