Cellashop

Privacy and Cookie Notice

Webshop
cellashop.hu
Controller
We Form IT
Effective
3 August 2026
Version
1.0 (2026-08-03)

This notice explains how personal data of visitors, buyers, contact persons and reviewers of cellashop.hu is processed, pursuant to Article 13 of the General Data Protection Regulation (GDPR).

1. Controller and contact

2. Principles

The Controller processes personal data only for specified, explicit and legitimate purposes, to the extent necessary; ensures accuracy; and retains data only as long as needed. Appropriate technical and organisational measures protect data against unauthorised access, alteration, disclosure, loss or destruction.

3. Data processed and purposes

3.1. Website delivery and security logs

Purpose: making the website available, troubleshooting, IT security, preventing abuse

Data: IP address, date and time, requested URL, HTTP status, referrer, basic browser and device data, technical event logs

Legal basis: GDPR Art. 6(1)(f) – the Controller’s legitimate interest in secure and demonstrable operation

Retention: [KITÖLTENDŐ: javasolt normál naplómegőrzés 30–90 nap]; for security incidents until the claim or procedure is closed

Recipients: hosting, CDN, development and IT security providers

Provision of data: Data are generated automatically; without them secure website delivery cannot be ensured. The legitimate-interest balancing must be documented.

3.2. Cart and language settings

Purpose: operating the cart, session, language and basic user settings

Data: session identifier, cart contents, language choice, necessary security tokens

Legal basis: GDPR Art. 6(1)(b) – steps taken at the user’s request prior to entering into a contract; and Art. 6(1)(f) – a functioning and secure interface

Retention: until the end of the session or until the actual cookie expiry: [KITÖLTENDŐ]

Recipients: hosting and webshop providers

Provision of data: Strictly necessary cookies do not require marketing consent, but transparent information is required.

3.3. Orders and contract performance

Purpose: receiving and confirming orders, concluding contracts, customer contact, performance and evidence

Data: name, email, phone number, billing and shipping address, company data, order ID, product, quantity, price, discount, payment and shipping method, messages, fulfilment status

Legal basis: GDPR Art. 6(1)(b) – performance of a contract or steps prior to entering into a contract

Retention: until the end of the general civil limitation period following termination or performance of the contract, as a rule 5 years; for pending claims until final closure

Recipients: webshop and hosting providers, internal customer service, legal counsel where necessary

Provision of data: Without the checkout fields marked as required, the order cannot be completed.

3.4. Invoicing and accounting retention

Purpose: issuing invoices, bookkeeping, fulfilling tax and accounting obligations

Data: name or company name, billing address, tax ID, order and invoice data, consideration, payment data

Legal basis: GDPR Art. 6(1)(c) – legal obligation, in particular under accounting and tax laws

Retention: accounting documents for at least 8 years; other tax data until the applicable limitation period

Recipients: [KITÖLTENDŐ: számlázó szolgáltató], [KITÖLTENDŐ: könyvelő], tax authority

Provision of data: Providing billing data is a statutory and contractual requirement.

3.5. Payment

Purpose: initiating, reconciling, refunding and fraud-preventing card, PayPal or cash-on-delivery payments

Data: order ID, amount, currency, payment status, transaction ID, payer name and related technical data; the Controller does not store full card data

Legal basis: GDPR Art. 6(1)(b) – contract performance; for fraud prevention Art. 6(1)(f) – legitimate interest; for accounting data Art. 6(1)(c)

Retention: 5 years for order data, 8 years for accounting documents; otherwise according to the payment provider’s own notice

Recipients: [KITÖLTENDŐ: bankkártyás fizetési szolgáltató], PayPal, cash-on-delivery carrier; some providers act as independent controllers

Provision of data: Without the data required for the chosen payment method, that method cannot be used.

3.6. Delivery and parcel collection

Purpose: addressing parcels, booking transport, tracking, delivery, dangerous goods requirements and delivery complaints

Data: recipient name, address or locker ID, email, phone, parcel ID, cash-on-delivery amount, data needed for dangerous-goods handling of the shipment, delivery status

Legal basis: GDPR Art. 6(1)(b) – contract performance; for certain dangerous-goods and documentary data Art. 6(1)(c)

Retention: 5 years in the Controller’s order records; otherwise according to the carrier’s own notice

Recipients: GLS, Foxpost, and [KITÖLTENDŐ: veszélyes visszafuvarozó]

Provision of data: Without shipping data, delivery cannot be performed.

3.7. Contact, complaints, warranty and guarantee

Purpose: answering questions, investigating complaints and defective performance claims, record-keeping, handling legal claims

Data: name, contact details, order data, description of complaint or defect, photo, minutes, claim and response, refund data where needed

Legal basis: for simple enquiries GDPR Art. 6(1)(f) – legitimate interest in responding; for contractual claims Art. 6(1)(b); for consumer complaints and minutes Art. 6(1)(c)

Retention: simple enquiry: [KITÖLTENDŐ: javasolt 1 év] or until the matter is closed; consumer complaint and warranty/guarantee minutes: 3 years; in case of dispute until final closure

Recipients: customer service, IT and email providers, manufacturer/distributor, expert, legal counsel, ADR body or authority where necessary

Provision of data: Without the requested data, the matter cannot always be investigated on the merits.

3.8. Withdrawal notice and online withdrawal function

Purpose: receiving withdrawal, proving its timing, automatic acknowledgment, arranging return and refund

Data: withdrawal decision, name, order or contract ID, acknowledgment email or other electronic contact, submission date and time, return and refund data

Legal basis: GDPR Art. 6(1)(c) – legal obligation regarding the consumer withdrawal function; Art. 6(1)(b) – performing termination of the contract

Retention: until the general civil limitation period for claims, as a rule 5 years; 8 years for accounting refund documents

Recipients: webshop and email providers, payment provider, return carrier, accountant

Provision of data: Without required fields the online function cannot identify the relevant contract; withdrawal may also be exercised by any other clear statement. The online withdrawal function is continuously available at /elallas.

3.9. Customer reviews

Purpose: publishing product experience, verifying review authenticity, moderation and aggregation

Data: displayed name or alias, score, opinion, date, product; non-publicly: email, order ID, verified-purchase status, moderation log

Legal basis: GDPR Art. 6(1)(a) – consent to publish the opinion and name; for authenticity and abuse prevention Art. 6(1)(f) – legitimate interest

Retention: until consent is withdrawn or the review is deleted; verification and moderation log [KITÖLTENDŐ: javasolt 3 év]

Recipients: webshop and hosting providers, persons performing moderation; website visitors if published publicly

Provision of data: Reviews are voluntary; consent may be withdrawn at any time, without affecting the lawfulness of prior processing.

3.10. Legal claims and abuse handling

Purpose: preventing, bringing and defending against fraud, payment disputes, dangerous-product incidents, legal claims or official proceedings

Data: order, payment, communication, log and evidential data needed for the matter

Legal basis: GDPR Art. 6(1)(f) – legitimate interest of the Controller and others in enforcement and security; for official requests Art. 6(1)(c)

Retention: until the claim can be enforced; for pending matters until final closure, then until the end of mandatory retention

Recipients: legal counsel, insurer, payment and transport providers, court, authority, ADR body

Provision of data: The legitimate-interest balancing must be documented; the data subject may object.

4. Processors and independent recipients

Before publication, the list below must be completed on the basis of actual contracts and processor agreements. Providers must be identified by full legal name, address, role and contact details — not by marketing name alone.

ServiceProviderTask / role
PayPalPayPal (Europe) S.à r.l. et Cie, S.C.A. [pontos adatokat a kereskedői szerződésből ellenőrizni]payment; typically an independent controller
GLSGLS General Logistics Systems Hungary Csomag-Logisztikai Kft. [aktuális szerződéses adatokkal ellenőrizni]home delivery
Foxpost[KITÖLTENDŐ: a hatályos szerződésben szereplő teljes jogi név]parcel lockers and possible returns

5. Transfers to third countries

The Controller primarily processes data within the European Economic Area. Corporate groups of certain payment, cloud, email or support providers may also access data from outside the EEA. Before publication, the place of transfer and safeguards must be established for each provider.

6. Automated decision-making and profiling

The Controller [KITÖLTENDŐ: nem végez / részletesen ismertet] solely automated decision-making that produces legal effects concerning the data subject or similarly significantly affects them. Information on the payment provider’s own fraud-prevention decisions is set out in that provider’s privacy notice.

7. Data security

The Controller applies measures proportionate to risk, including encrypted HTTPS connections, access control and two-factor authentication on admin interfaces, regular updates and backups, logging, access reviews, data minimisation, incident response procedures and contractual checks of providers. Full card data do not enter the Cellashop system.

8. Data subject rights

The data subject may request, at info@cellashop.hu or at the Controller’s postal address:

  • information and access to personal data processed, including a copy;
  • rectification of inaccurate data and completion of incomplete data;
  • erasure of data where there is no further legal basis or mandatory retention;
  • restriction of processing under the GDPR conditions;
  • receipt of data provided by them and processed by automated means on the basis of contract or consent, in a portable format, and — where technically feasible — transmission to another controller;
  • objection to processing based on legitimate interest; the Controller may then continue only for compelling legitimate grounds or legal claims;
  • withdrawal of consent at any time, without affecting the lawfulness of processing before withdrawal;
  • intervention regarding automated decision-making under the GDPR, if such a decision occurs.

The Controller responds without undue delay, as a rule within one month. For complex or numerous requests the period may be extended by a further two months, with notice within the first month. Where there is reasonable doubt, the Controller may request proportionate further information needed for identification.

9. Remedies

The data subject may first contact the Controller directly. They may also lodge a complaint with the supervisory authority or go to court.

Under the GDPR, court proceedings may also be brought in the Member State of the Controller’s establishment or of the data subject’s habitual residence.

10. Cookie notice

According to the website’s current information, the Webshop uses cookies for cart and language settings. Exact cookie names, domains and expiries cannot be determined without a live browser and network review, so the inventory below must be completed before publication.

Statistical, convenience or marketing cookies that are not necessary for the service may only be placed with prior, specific and withdrawable consent. “Accept all” and refusal must be equally easy; pre-ticked toggles and mere continued browsing are not valid consent. The user must later be able to change their choice just as easily.

Cookies can be deleted or blocked in the browser, but blocking strictly necessary cookies may prevent the cart or checkout from working.

11. Newsletter and marketing

At the time of publishing this version, no newsletter subscription was identifiable on the website. The Controller may not send electronic direct marketing without prior, explicit consent. Before introducing a newsletter, a separate subscription text, demonstrable consent, easy unsubscribe, a provider list and an updated privacy notice are required.

12. Changes to this notice

The Controller amends this notice when laws, providers or processing change, indicating the change and effective date, and archives prior versions. Before a new purpose or consent-based processing, appropriate prior information is given and, where needed, new consent is obtained.

Privacy and Cookie Notice | Cellashop