Privacy policy
This policy explains how Humán Hygiene Kft (the "Controller", "we", "us") processes personal data about visitors and customers of Human Hygiene Kft. (the "Shop"). It is written to satisfy the information requirements of Articles 13 and 14 of the EU General Data Protection Regulation 2016/679 ("GDPR") and the corresponding rules of the ePrivacy Directive 2002/58/EC as transposed in your member state.
1. Data controller
Humán Hygiene Kft
Tavasz utca 3.
2142 Nagytarcsa
Hungary
Email: info@human-hygiene.hu
Phone: 06203892950
If our processing requires a Data Protection Officer (DPO) under Article 37 GDPR, the DPO is reachable at the address above; otherwise please use the channels above for any privacy enquiry.
2. Categories of personal data we process
- Account data: name, email address, password hash, language preference, marketing-consent state.
- Order data: shipping and billing address, telephone, the products ordered, order date, amount and payment method. We do NOT store full payment card numbers — see Section 4.
- Communication data: the contents of any email, contact-form message or chat conversation you send us, plus the time stamp.
- Technical / device data: IP address, browser user-agent, device type, pages viewed, referrer, time stamps. Collected by the web server's standard request log.
- Cookie data: see Section 6 and the cookie banner shown on first visit.
3. Purposes, legal bases, and retention
- Fulfilling your order (payment, delivery, invoicing) — Art. 6(1)(b) GDPR (contract performance). Retained for the duration of the contract; commercial / tax records per Section 7.
- Managing your account — Art. 6(1)(b). Retained until you delete the account; backups for up to 90 days.
- Responding to your messages — Art. 6(1)(f) (our legitimate interest in customer service). Retained 3 years from last contact.
- Fraud prevention and IT security — Art. 6(1)(f). Server logs keyed to IP: up to 30 days.
- Marketing emails — Art. 6(1)(a) (your consent), revocable at any time via the unsubscribe link in every email. Retained until you unsubscribe.
- Analytics / marketing cookies — Art. 6(1)(a) (your consent given in the cookie banner). See the banner for per-cookie lifetimes.
- Tax and accounting records — Art. 6(1)(c) (legal obligation). Retained per national law (commonly 6–10 years).
4. Payments
We do not process or store full payment-card details on our own systems. Payments are handled by our payment service providers (e.g. Stripe, PayPal, or those shown at checkout). Each is an independent controller for the payment data it processes; their privacy notices apply to their own processing. We receive only the minimum necessary (a payment success/failure status and a tokenised reference).
5. Recipients of personal data
We share your personal data only with carefully selected processors who help us run the Shop, each bound by a Data Processing Agreement under Article 28 GDPR:
- Hosting / infrastructure — runs the Shop and stores its data.
- Payment service providers — process your payment securely.
- Shipping carriers — recipient address and telephone needed to deliver physical goods.
- Email service providers — send transactional emails and, with your consent, marketing emails.
- Analytics / marketing providers (only with your consent) — measure usage and campaign effectiveness.
We do not sell or rent personal data.
6. Cookies and similar technologies
We use cookies that are strictly necessary for the Shop to function (cart, session, CSRF protection). These do not require your consent under Article 5(3) ePrivacy Directive. Other cookies — analytics, marketing, embedded content — are set only after you give consent through the cookie banner on your first visit. You can withdraw consent at any time via the cookie-settings link in the footer.
7. International transfers
Where any processor processes personal data outside the European Economic Area, we ensure an adequate level of protection by means of (i) an adequacy decision of the European Commission, (ii) the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), or (iii) another safeguard recognised under Chapter V GDPR. A copy of the relevant safeguard is available on request from info@human-hygiene.hu.
8. Your rights
Under Articles 15–22 GDPR you have the right, in the circumstances and on the conditions set out in the GDPR, to:
- Access a copy of the personal data we hold about you (Art. 15);
- Rectify inaccurate or incomplete data (Art. 16);
- Erase your data ("right to be forgotten") in certain circumstances (Art. 17);
- Restrict our processing in certain circumstances (Art. 18);
- Data portability — receive your data in a structured, machine-readable format (Art. 20);
- Object to processing based on legitimate interests, including direct marketing (Art. 21);
- Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal (Art. 7(3));
- Lodge a complaint with the supervisory authority of your EU member state of residence, work or alleged infringement (Art. 77).
To exercise any of these rights, contact us at info@human-hygiene.hu. We respond within one month, extendable by two further months in complex cases (Art. 12(3) GDPR).
9. Automated decision-making
We do not subject you to decisions based solely on automated processing — including profiling — that produce legal effects concerning you or significantly affect you. Fraud screening on payments may use automated checks by our payment providers; any block can be reviewed by a human on request.
10. Children
The Shop is not directed at children. If you are under the age at which a child can validly consent under the law of your country (between 13 and 16 across EU member states; Article 8 GDPR), you must obtain a parent's or guardian's consent before providing personal data.
11. Changes to this policy
We may update this policy to reflect changes in the law or our practices. The version in force is published on this page; material changes will be highlighted on the Shop or notified by email if we hold an active marketing-consent record for you.
Last updated: 2026-05-27