Privacy policy

Last updated: June 17, 2026

 

Privacy Policy
 

1. Identification of the Data Controller
The online store available at https://www.voniastore.com/ is operated by:

Name: Vonia Global Trade Kft.
Company registration number: 07-09-037621

Tax number: 33061210-2-07
EU VAT number: HU33061210

Registered office: 2464 Gyúró, Bocskai út 16..
E-mail: info@voniastore.com

(hereinafter: the “Data Controller”).

The Data Controller processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR”), Act CXII of 2011 on Informational Self-Determination and Freedom of Information, Act V of 2013 on the Civil Code, Act C of 2000 on Accounting, Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities, and other applicable data protection and consumer protection legislation.

2. General principles of data processing

The Data Controller processes personal data lawfully, fairly and transparently. Personal data are collected only for specified, explicit and legitimate purposes and are not processed in a manner incompatible with those purposes. The Data Controller ensures that data processing is adequate, relevant and limited to what is necessary in relation to the purposes for which the data are processed. Personal data are accurate and, where necessary, kept up to date. Appropriate technical and organisational measures are implemented in order to protect personal data.

3. Data processing related to visiting the website

3.1. Data subjects concerned: users visiting the website.

3.2. Legal basis of processing: Article 6(1)(f) GDPR, i.e. the legitimate interest of the Data Controller in ensuring the secure operation, integrity and availability of the website, except where specific processing requires consent.

3.3. Scope of processed data: technical identifiers generated during browsing, including IP address, date and time of access, browser type, operating system, the pages visited, referral data and other technical log data that are necessary for operation, security and diagnostics.

3.4. Purpose of processing: ensuring the technical operation of the website, maintaining service quality, preventing abuse, ensuring IT security, generating statistics and diagnosing errors.

3.5. Duration of processing: for the period necessary to achieve the purpose of the relevant processing activity, or for the period required by applicable law or by legitimate security and audit requirements.

3.6. Method of storage: on the Data Controller’s IT systems and, where necessary, on the systems of contracted service providers used for hosting and website operation.

4. Data processing related to cookies

4.1. The website uses cookies and similar technologies. Necessary cookies are used on the basis of the Data Controller’s legitimate interest in providing the website and the webshop service. Statistical, analytical and marketing cookies are used on the basis of the user’s consent where required by law.

4.2. Detailed information about cookies, their categories, functions, legal basis, retention periods and settings options is available in the separate Cookie Information Notice published by the Data Controller.

5. Data processing related to receiving and replying to messages

5.1. Data subjects concerned: users who send a message to the Data Controller through the message interface available under the “Contact” menu of the website, or by using the e-mail address(es) displayed on the website.

5.2. Legal basis of processing: Article 6(1)(a) GDPR, i.e. the user’s consent, and where the communication relates to steps prior to entering into a contract or to an existing order, Article 6(1)(b) GDPR may also apply.

5.3. Categories of data processed: the sender’s name, e-mail address, telephone number if provided, message content, and any other personal data voluntarily included in the message.

5.4. Purpose of processing: enabling communication between the user and the Data Controller, responding to enquiries, handling requests and supporting the conclusion or performance of a contract.

5.5. Duration of processing: for the period necessary to reply to and document the communication, or longer where the content of the communication is relevant to the conclusion, performance or defence of legal claims relating to a contract.

5.6. Method of storage: on a separate data processing list within the Data Controller’s IT system and in the Data Controller’s mailbox system.

6. Data processing related to newsletters

6.1. Data subject concerned: a user who subscribes to the newsletter on the website by completing the relevant fields and ticking the consent checkbox.

6.2. Legal basis of processing: Article 6(1)(a) GDPR and Section 6(1)-(2) of Act XLVIII of 2008, i.e. the user’s consent. Consent is given voluntarily by reading this Privacy Policy, filling in the newsletter subscription fields and ticking the consent statement displayed there.

6.3. Categories of data processed: name and e-mail address of the subscriber, as well as technical data necessary to document subscription and unsubscription.

6.4. Purpose of processing: sending newsletters, offers, product information and marketing communications to the subscriber, and documenting the consent related to such communications.

6.5. Duration of processing: until the withdrawal of consent (unsubscription) or until deletion of the data at the user’s request.

6.6. Method of storage: on a separate data processing list within the Data Controller’s IT system and within the newsletter system used by the Data Controller.

7. Data processing related to registration

7.1. Data subjects concerned: users registering on the website.

7.2. Legal basis of processing: Article 6(1)(a) GDPR, i.e. the user’s consent given during registration by filling in the registration form, ticking the privacy statement and clicking the registration confirmation button.

7.3. Categories of data processed: the personal data and contact data indicated on the registration form, in particular surname, first name and e-mail address, and any additional data requested for the operation of the user account.

7.4. Duration of processing: until deletion initiated by the registered user, by the Data Controller upon the user’s request, or by the Data Controller in accordance with the applicable Terms of Service. The Data Controller executes a deletion request without undue delay, but no later than within 10 working days after receipt of the request.

7.5. Method of storage: on a separate data processing list within the Data Controller’s IT system.

8. Data processing related to orders

8.1. Data subjects concerned: users placing an order on the website.

8.2. Legal basis of processing: Article 6(1)(b) GDPR, since the processing is necessary for the performance of a contract to which the user is a party, as well as Article 6(1)(c) GDPR with regard to accounting, tax and other statutory retention obligations.

8.3. Categories of data processed: surname, first name, billing address, shipping address, e-mail address, telephone number, order details, selected payment and delivery method, invoice data, purchase date, purchase price, shipping fee and any other data required for contract performance.

8.4. Purpose of processing: conclusion and performance of the sales contract, processing the order, delivering the product, issuing invoices, handling returns and complaints, customer service administration, and compliance with legal obligations.

8.5. Duration of processing: data processed for order fulfilment are retained for the period necessary to comply with statutory document retention obligations under accounting legislation, which is at least 8 years from the issuance of the invoice, after which the data are deleted or anonymised unless a longer retention period is required by law or for the establishment, exercise or defence of legal claims.

8.6. Method of storage: on separate data processing lists within the Data Controller’s IT system, and on accounting records and documents where required by law.

9. Data transfers

9.1. Data subjects concerned: users who choose an online payment method during the ordering process on the website.

9.2. Recipients of data transfers relating to payment services may include:

Name of recipient: Stripe Payments Europe Ltd.
Website: https://stripe.com
Privacy notice: https://stripe.com/privacy

Name of recipient: PayPal (Europe) S.à r.l. et Cie, S.C.A.
Registered office: 22-24 Boulevard Royal, L-2449 Luxembourg
Website: https://www.paypal.com
Privacy notice: https://www.paypal.com/privacy

Name of recipient: Revolut Bank UAB
Registered office: Konstitucijos ave. 21B, LT-08130 Vilnius, Lithuania
Website: https://www.revolut.com

9.3. Legal basis of the transfer: Article 6(1)(b) GDPR, as the transfer is necessary for the performance of the payment transaction chosen by the user and therefore for the performance of the contract. Depending on the service, compliance obligations of the recipient may also be based on Article 6(1)(c) GDPR.

9.4. Categories of transferred data: identification and transaction data necessary for payment processing, such as the order identifier, amount, currency, payer name, e-mail address, billing data and technical transaction identifiers. The Data Controller does not receive or store the complete card data entered directly with the payment service provider.

9.5. Purpose of the transfer: enabling online payment processing, transaction confirmation, fraud prevention, accounting reconciliation and handling related customer service issues.

9.6. For detailed information about the processing carried out by the online payment service providers, including legal basis, purpose, scope of data, duration of processing and data subject rights, the user should consult the privacy notice of the relevant payment service provider.

9.7. The Data Controller does not transfer personal data to third parties for independent business or marketing purposes.

9.8. Outside the cases expressly described in this Policy, the Data Controller transfers personal data only where required by law or upon a lawful request from a competent authority, court or other public body.

9.9. Recipients and processors involved in product delivery may include the following courier and logistics partners:

GLS General Logistics Systems Hungary Csomag-Logisztikai Kft.
Registered office: 2351 Alsónémedi, GLS Európa u. 2.
Telephone: +36 29 886 700
E-mail: info@gls-hungary.com
Website: https://gls-group.eu/HU/hu/home

Delivery Solutions Zrt. (Sameday)
Registered office: 1097 Budapest, Könyves Kálmán körút 34.
Telephone: +36 1 374 3890
E-mail: info@sameday.hu

Magyar Posta Zrt.
Registered office: 1138 Budapest, Dunavirág utca 2-6.
Telephone: +36 1 767 8200
Website: https://posta.hu

DHL Express Magyarország Kft.
Telephone: +36 1 245 4545
E-mail: info.hu@dhl.com
Website: https://www.dhl.com/hu-hu/home.html

10. Data processors

10.1. Hosting and webshop system provider

10.1.1. Data subjects concerned: all users whose data are processed through the website and webshop.

10.1.2. The Data Controller uses the services of Shopify International Limited as data processor.
Website: https://www.shopify.com
Privacy notice: https://www.shopify.com/legal/privacy
(hereinafter: the “Processor”).

10.1.3. Scope of processing: all data specified in this Privacy Policy to the extent necessary for hosting and webshop operation.

10.1.4. Purpose of processing: ensuring the IT operation of the website, operation of the webshop system, provision of hosting services, and the technical administration of orders placed through the website.

10.1.5. Duration of processing: the same as the retention periods applicable to the relevant categories of data and processing purposes described in this Privacy Policy.

10.1.6. Processing is limited to the extent necessary for the IT operation of the website, the operation of the webshop system, hosting services and the technical administration of orders made through the website.

10.2. Processing related to newsletter delivery

10.2.1. Data subjects concerned: users subscribing to the newsletter on the website, regardless of whether they use any other services of the website.

10.2.2. The Data Controller uses Shopify International Limited as processor for the technical services necessary for newsletter delivery. The details of this Processor are set out in Section 10.1.2 above.

10.2.3. Scope of processing: the name and e-mail address of the newsletter subscriber.

10.2.4. Purpose of processing: operation of the system used by the Data Controller for newsletters, technical sending of newsletters and data processing operations necessary for the secure provision of the service.

10.2.5. Duration of processing: until withdrawal of the consent given for newsletter delivery (unsubscription), or until deletion of the data at the user’s request.

10.2.6. Processing is limited to the operations necessary for operating the newsletter system, sending newsletters technically and ensuring secure operation of the service.

10.3. Processing related to delivery of products

10.3.1. Data subjects concerned: users ordering products with delivery to the address specified by them.

10.3.2. The Data Controller uses the courier services and logistics partners listed in Section 9.9 of this Policy as processors for the data processing tasks related to delivery.

10.3.3. Scope of processing: for the performance of the contract arising from the user’s order, the following data may be processed: surname, first name, telephone number, e-mail address and shipping address.

10.3.4. Purpose of processing: delivery of the ordered product to the address specified by the user within the framework of performance of the contract, including, where necessary, telephone coordination regarding the place and time of delivery.

10.3.5. Duration of processing: for the period necessary to carry out delivery and handover.

10.3.6. Processing is limited to the data processing operations necessary to perform delivery and handover.

10.4. Processing related to issuing invoices

10.4.1. Data subjects concerned: users placing an order on the website, regardless of whether they use any other services of the website.

10.4.2. The Data Controller uses Billingo Technologies Zrt. as processor.
Company registration number: 01-10-140802
Tax number: 27926309-2-41
Registered office: 1133 Budapest, Árbóc utca 6. III. emelet
Website: https://www.billingo.hu
(hereinafter: the “Processor”).

10.4.3. Scope of processing: records containing the name and address of the user placing the order, e-mail address, designation of the ordered goods and/or services, date of purchase, purchase price, shipping fee and any other fees.

10.4.4. Purpose of processing: ensuring the operation of the invoicing system used by the Data Controller for generating, issuing, storing and recording invoices, and carrying out the technical and administrative operations required for this purpose.

10.4.5. Duration of processing: for the period necessary to comply with accounting document retention obligations, namely 8 years from the issuance of the invoice.

10.4.6. Processing is limited to the operations necessary for generating, issuing, storing, transmitting invoices and operating the invoicing system.

10.5. Processing related to bookkeeping services

10.5.1. Data subjects concerned: users placing an order.

10.5.2. The Data Controller uses BARTALIS ESZTER EV. as processor.
Registered office: 2360 Gyál, Radnóti utca 16.
Tax number: 57987486-1-33
(hereinafter: the “Processor”).

10.5.3. Scope of processing: data appearing on accounting documents relating to the user placing the order, including name, address, e-mail address, designation of ordered goods, date of purchase, purchase price, shipping fee and any other fees.

10.5.4. Purpose of processing: compliance with statutory accounting obligations relating to the economic activity of the Data Controller by using the services of the above Processor.

10.5.5. Duration of processing: at most until the expiry of the statutory accounting document retention period, i.e. deletion in the year following the 8th year after issuance of the invoice.

10.5.6. Processing is limited to the operations necessary for the fulfilment and review of accounting obligations.

10.6. Use of a logistics and administrative contributor

10.6.1. Data subjects concerned: users placing orders on the website.

10.6.2. The Data Controller uses Huszta András EV as processor.
Registered office: 2464 Gyúró, Bocskai út 16.
Registration number: 59521972
Tax number: 90338782-2-27
EU VAT number: HU90338782
(hereinafter: the “Processor”).

10.6.3. Scope of processing: data necessary for order fulfilment and related administration, in particular customer identification, order and delivery data.

10.6.4. Purpose of processing: coordination of logistics, administrative support and participation in the fulfilment of orders.

10.6.5. Duration of processing: for the period necessary to perform the relevant logistics and administrative tasks and to comply with any related legal obligations.

10.6.6. Processing is limited to operations connected with the fulfilment of orders, logistics coordination and the performance of related administrative tasks.

10.7. Processing related to fulfilment and logistics services

10.7.1. Data subjects concerned: users whose orders are handled through the fulfilment process.

10.7.2. The Data Controller uses Fuseler Kft. as processor.
Registered office: 1222 Budapest, Pehely utca 13.
Company registration number: 01-09-413808
Tax number: 32242599-2-43
EU VAT number: HU32242599
(hereinafter: the “Processor”).

10.7.3. Scope of processing: data necessary for warehousing, picking, packing, logistics preparation and fulfilment of orders.

10.7.4. Purpose of processing: carrying out the warehousing, picking, packing, logistics preparation and fulfilment tasks connected to orders.

10.7.5. Duration of processing: for the period necessary for fulfilment of the order and closure of the related logistics processes.

10.7.6. Processing is limited to logistics and fulfilment operations necessary to perform orders.

10.8. The Data Controller uses the processors specified in this Privacy Policy for the implementation of the respective processing purposes. The Data Controller reserves the right to engage additional processors, in which case this Privacy Policy will be amended accordingly and the changes will be published.

"

11. Rights of the User in relation to data processing
 
11.1. Right of access: upon the User’s request, the Data Controller shall provide information about the personal data processed by it or by a Processor engaged by it or on its instructions, the source of the data, the purpose, legal basis and duration of the processing, the name and address of the Processor and its activities related to the processing, the circumstances and effects of any data protection incident that may have occurred and the measures taken to remedy it, and, in the event of transfer of the User’s personal data, the legal basis and recipient of the transfer. The Data Controller shall provide the information without undue delay, but no later than within one month of receipt of the request.

11.2. Right to data portability: the User has the right to receive the personal data concerning him or her, which he or she has provided to the Data Controller, in a structured, commonly used and machine-readable format, and has the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, if the processing is based on consent or on a contract and is carried out by automated means.

11.3. Right to rectification: the User may request the rectification of his or her processed data, which the Data Controller shall carry out without undue delay, but no later than within one month of receipt of the request. Taking into account the purpose of the processing, the User also has the right to request completion of incomplete personal data, including by means of a supplementary statement.

11.4. Right to restriction of processing: the Data Controller shall mark personal data processed by it for the purpose of restricting processing. The User has the right to request that the Data Controller restrict processing where one of the following applies: the User contests the accuracy of the personal data, for a period enabling the Data Controller to verify the accuracy of the personal data; the processing is unlawful and the User opposes the erasure of the data and requests the restriction of their use instead; the Data Controller no longer needs the personal data for the purposes of processing, but the User requires them for the establishment, exercise or defence of legal claims; or the User has objected to processing based on the legitimate interests of the Data Controller, in which case the restriction applies for the period until it is determined whether the legitimate grounds of the Data Controller override those of the User.

11.5. Right to erasure: the Data Controller shall erase personal data if the data are no longer necessary for the purposes for which they were collected or otherwise processed; if the User withdraws consent and there is no other legal basis for processing; if the User objects to processing and there are no overriding legitimate grounds for processing; if the personal data have been unlawfully processed; if the personal data must be erased for compliance with a legal obligation under Union or Member State law applicable to the Data Controller; or if the data were collected in relation to the offer of information society services directly to a child where such rules apply.

11.6. Right to object: the User has the right to object at any time, on grounds relating to his or her particular situation, to the processing of his or her personal data based on the legitimate interests of the Data Controller. In such a case, the Data Controller may no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the User or which relate to the establishment, exercise or defence of legal claims.

12. Handling of User requests

12.1. The Data Controller provides the information and takes the measures described above free of charge. Where the User’s request is manifestly unfounded or excessive, in particular because of its repetitive character, the Data Controller, taking into account the administrative costs of providing the requested information or communication or taking the requested action, may charge a reasonable fee or refuse to act on the request.

12.2. The burden of demonstrating the manifestly unfounded or excessive character of the request lies with the Data Controller.

12.3. If the Data Controller does not take action on the User’s request, it shall inform the User without undue delay, but no later than within one month of receipt of the request, of the reasons for not taking action and of the possibility of lodging a complaint with the supervisory authority indicated below and seeking a judicial remedy.

12.4. The User may submit requests to the Data Controller in any manner that enables his or her identification. Identification of the requesting User is necessary because the Data Controller may only comply with requests submitted by persons entitled to do so. If the Data Controller has reasonable doubts concerning the identity of the natural person making the request, it may request additional information necessary to confirm the User’s identity.

12.5. The User may primarily submit requests electronically to the e-mail address info@voniastore.com. If the User wishes to submit the request by post, information about the mailing address may be requested by e-mail at info@voniastore.com. A request sent by e-mail is regarded as authentic by the Data Controller if it is sent from the e-mail address previously provided and registered by the User, however, the use of another e-mail address does not automatically result in refusal of the request. In the case of a request sent by e-mail, the time of receipt is the time when the e-mail reaches the Data Controller’s electronic mail system.

12.6. Enforcement of rights

Data subjects may enforce their rights before the courts and may also turn to the Hungarian National Authority for Data Protection and Freedom of Information:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Address: 1055 Budapest, Falk Miksa utca 9-11.
Mailing address: 1363 Budapest, Pf. 9.
Telephone: +36 1 391 1400
Website: https://www.naih.hu
E-mail: ugyfelszolgalat@naih.hu

13. Data protection and data security

13.1. Within the scope of its data processing and data processor management activities, the Data Controller ensures the security of the data and takes technical and organisational measures and internal procedural rules to enforce legal requirements and other data and confidentiality protection rules. In particular, it protects the processed data against unauthorised access, alteration, transmission, disclosure, deletion or destruction, accidental destruction or damage, and becoming inaccessible due to changes in the technology used.

13.2. Data serving as the basis for measuring website traffic and mapping usage habits are recorded by the Data Controller’s IT system in such a way that they cannot be directly linked to a specific person from the outset.

13.3. Data are processed only to the extent necessary and proportionate for the achievement of the lawful purposes defined in this Privacy Policy, on the basis of the applicable legislation and recommendations, and subject to appropriate security measures.

13.4. For this purpose, the Data Controller uses the HTTPS protocol to access the website, which encrypts and uniquely identifies web communication. In addition, as described above, the Data Controller stores the processed data in encrypted data files, in separate processing lists organised by processing purpose, to which only duly authorised staff members of the Data Controller and the processors indicated in this Privacy Policy may have access, to the extent necessary for the performance of their tasks.

14. Cookies

14.1. Information on the use of cookies

14.1.1. What is a cookie?

A cookie is a small data file that is placed on the user’s device by the website in order to recognise the browser, remember certain settings, enable the service and assist with analytics and marketing functions.

14.1.2. Legal background and legal basis of cookies

The legal basis for necessary cookies is the legitimate interest of the Data Controller in ensuring the proper operation of the website. The legal basis for non-essential statistical, analytical and marketing cookies is the User’s consent where required by applicable law.

14.2. Main characteristics of the cookies used by the website

14.2.1. Cookies necessary for operation

These cookies are required for the technical operation of the website and the webshop, including navigation, security, cart functions and checkout.

14.2.2. Statistical (analytical) cookies

Examples may include Google Analytics measurement cookies such as _ga_JTFSMHVVZX and _ga_WSJ3C5GB03.

14.2.3. Marketing cookies

Examples may include Shopify marketing and session tracking cookies such as _shopify_marketing and _shopify_s.

14.3. The exact list and lifetime of cookies may change from time to time as a result of modifications to the Shopify system and the integrated services.