Privacy and Cookie Notice
- Webshop
- cellashop.hu
- Controller
- We Form IT
- Effective
- 3 August 2026
- Version
- 1.0 (2026-08-03)
This notice explains how personal data of visitors, buyers, contact persons and reviewers of cellashop.hu is processed, pursuant to Article 13 of the General Data Protection Regulation (GDPR).
1. Controller and contact
- Controller name: We Form IT
- Privacy email: info@cellashop.hu
2. Principles
The Controller processes personal data only for specified, explicit and legitimate purposes, to the extent necessary; ensures accuracy; and retains data only as long as needed. Appropriate technical and organisational measures protect data against unauthorised access, alteration, disclosure, loss or destruction.
3. Data processed and purposes
3.1. Website delivery and security logs
Purpose: making the website available, troubleshooting, IT security, preventing abuse
Data: IP address, date and time, requested URL, HTTP status, referrer, basic browser and device data, technical event logs
Legal basis: GDPR Art. 6(1)(f) – the Controller’s legitimate interest in secure and demonstrable operation
Retention: [KITÖLTENDŐ: javasolt normál naplómegőrzés 30–90 nap]; for security incidents until the claim or procedure is closed
Recipients: hosting, CDN, development and IT security providers
Provision of data: Data are generated automatically; without them secure website delivery cannot be ensured. The legitimate-interest balancing must be documented.
3.2. Cart and language settings
Purpose: operating the cart, session, language and basic user settings
Data: session identifier, cart contents, language choice, necessary security tokens
Legal basis: GDPR Art. 6(1)(b) – steps taken at the user’s request prior to entering into a contract; and Art. 6(1)(f) – a functioning and secure interface
Retention: until the end of the session or until the actual cookie expiry: [KITÖLTENDŐ]
Recipients: hosting and webshop providers
Provision of data: Strictly necessary cookies do not require marketing consent, but transparent information is required.
3.3. Orders and contract performance
Purpose: receiving and confirming orders, concluding contracts, customer contact, performance and evidence
Data: name, email, phone number, billing and shipping address, company data, order ID, product, quantity, price, discount, payment and shipping method, messages, fulfilment status
Legal basis: GDPR Art. 6(1)(b) – performance of a contract or steps prior to entering into a contract
Retention: until the end of the general civil limitation period following termination or performance of the contract, as a rule 5 years; for pending claims until final closure
Recipients: webshop and hosting providers, internal customer service, legal counsel where necessary
Provision of data: Without the checkout fields marked as required, the order cannot be completed.
3.4. Invoicing and accounting retention
Purpose: issuing invoices, bookkeeping, fulfilling tax and accounting obligations
Data: name or company name, billing address, tax ID, order and invoice data, consideration, payment data
Legal basis: GDPR Art. 6(1)(c) – legal obligation, in particular under accounting and tax laws
Retention: accounting documents for at least 8 years; other tax data until the applicable limitation period
Recipients: [KITÖLTENDŐ: számlázó szolgáltató], [KITÖLTENDŐ: könyvelő], tax authority
Provision of data: Providing billing data is a statutory and contractual requirement.
3.5. Payment
Purpose: initiating, reconciling, refunding and fraud-preventing card, PayPal or cash-on-delivery payments
Data: order ID, amount, currency, payment status, transaction ID, payer name and related technical data; the Controller does not store full card data
Legal basis: GDPR Art. 6(1)(b) – contract performance; for fraud prevention Art. 6(1)(f) – legitimate interest; for accounting data Art. 6(1)(c)
Retention: 5 years for order data, 8 years for accounting documents; otherwise according to the payment provider’s own notice
Recipients: [KITÖLTENDŐ: bankkártyás fizetési szolgáltató], PayPal, cash-on-delivery carrier; some providers act as independent controllers
Provision of data: Without the data required for the chosen payment method, that method cannot be used.
3.6. Delivery and parcel collection
Purpose: addressing parcels, booking transport, tracking, delivery, dangerous goods requirements and delivery complaints
Data: recipient name, address or locker ID, email, phone, parcel ID, cash-on-delivery amount, data needed for dangerous-goods handling of the shipment, delivery status
Legal basis: GDPR Art. 6(1)(b) – contract performance; for certain dangerous-goods and documentary data Art. 6(1)(c)
Retention: 5 years in the Controller’s order records; otherwise according to the carrier’s own notice
Recipients: GLS, Foxpost, and [KITÖLTENDŐ: veszélyes visszafuvarozó]
Provision of data: Without shipping data, delivery cannot be performed.
3.7. Contact, complaints, warranty and guarantee
Purpose: answering questions, investigating complaints and defective performance claims, record-keeping, handling legal claims
Data: name, contact details, order data, description of complaint or defect, photo, minutes, claim and response, refund data where needed
Legal basis: for simple enquiries GDPR Art. 6(1)(f) – legitimate interest in responding; for contractual claims Art. 6(1)(b); for consumer complaints and minutes Art. 6(1)(c)
Retention: simple enquiry: [KITÖLTENDŐ: javasolt 1 év] or until the matter is closed; consumer complaint and warranty/guarantee minutes: 3 years; in case of dispute until final closure
Recipients: customer service, IT and email providers, manufacturer/distributor, expert, legal counsel, ADR body or authority where necessary
Provision of data: Without the requested data, the matter cannot always be investigated on the merits.
3.8. Withdrawal notice and online withdrawal function
Purpose: receiving withdrawal, proving its timing, automatic acknowledgment, arranging return and refund
Data: withdrawal decision, name, order or contract ID, acknowledgment email or other electronic contact, submission date and time, return and refund data
Legal basis: GDPR Art. 6(1)(c) – legal obligation regarding the consumer withdrawal function; Art. 6(1)(b) – performing termination of the contract
Retention: until the general civil limitation period for claims, as a rule 5 years; 8 years for accounting refund documents
Recipients: webshop and email providers, payment provider, return carrier, accountant
Provision of data: Without required fields the online function cannot identify the relevant contract; withdrawal may also be exercised by any other clear statement. The online withdrawal function is continuously available at /elallas.
3.9. Customer reviews
Purpose: publishing product experience, verifying review authenticity, moderation and aggregation
Data: displayed name or alias, score, opinion, date, product; non-publicly: email, order ID, verified-purchase status, moderation log
Legal basis: GDPR Art. 6(1)(a) – consent to publish the opinion and name; for authenticity and abuse prevention Art. 6(1)(f) – legitimate interest
Retention: until consent is withdrawn or the review is deleted; verification and moderation log [KITÖLTENDŐ: javasolt 3 év]
Recipients: webshop and hosting providers, persons performing moderation; website visitors if published publicly
Provision of data: Reviews are voluntary; consent may be withdrawn at any time, without affecting the lawfulness of prior processing.
3.10. Legal claims and abuse handling
Purpose: preventing, bringing and defending against fraud, payment disputes, dangerous-product incidents, legal claims or official proceedings
Data: order, payment, communication, log and evidential data needed for the matter
Legal basis: GDPR Art. 6(1)(f) – legitimate interest of the Controller and others in enforcement and security; for official requests Art. 6(1)(c)
Retention: until the claim can be enforced; for pending matters until final closure, then until the end of mandatory retention
Recipients: legal counsel, insurer, payment and transport providers, court, authority, ADR body
Provision of data: The legitimate-interest balancing must be documented; the data subject may object.
4. Processors and independent recipients
Before publication, the list below must be completed on the basis of actual contracts and processor agreements. Providers must be identified by full legal name, address, role and contact details — not by marketing name alone.
| Service | Provider | Task / role |
|---|---|---|
| PayPal | PayPal (Europe) S.à r.l. et Cie, S.C.A. [pontos adatokat a kereskedői szerződésből ellenőrizni] | payment; typically an independent controller |
| GLS | GLS General Logistics Systems Hungary Csomag-Logisztikai Kft. [aktuális szerződéses adatokkal ellenőrizni] | home delivery |
| Foxpost | [KITÖLTENDŐ: a hatályos szerződésben szereplő teljes jogi név] | parcel lockers and possible returns |
5. Transfers to third countries
The Controller primarily processes data within the European Economic Area. Corporate groups of certain payment, cloud, email or support providers may also access data from outside the EEA. Before publication, the place of transfer and safeguards must be established for each provider.
6. Automated decision-making and profiling
The Controller [KITÖLTENDŐ: nem végez / részletesen ismertet] solely automated decision-making that produces legal effects concerning the data subject or similarly significantly affects them. Information on the payment provider’s own fraud-prevention decisions is set out in that provider’s privacy notice.
7. Data security
The Controller applies measures proportionate to risk, including encrypted HTTPS connections, access control and two-factor authentication on admin interfaces, regular updates and backups, logging, access reviews, data minimisation, incident response procedures and contractual checks of providers. Full card data do not enter the Cellashop system.
8. Data subject rights
The data subject may request, at info@cellashop.hu or at the Controller’s postal address:
- information and access to personal data processed, including a copy;
- rectification of inaccurate data and completion of incomplete data;
- erasure of data where there is no further legal basis or mandatory retention;
- restriction of processing under the GDPR conditions;
- receipt of data provided by them and processed by automated means on the basis of contract or consent, in a portable format, and — where technically feasible — transmission to another controller;
- objection to processing based on legitimate interest; the Controller may then continue only for compelling legitimate grounds or legal claims;
- withdrawal of consent at any time, without affecting the lawfulness of processing before withdrawal;
- intervention regarding automated decision-making under the GDPR, if such a decision occurs.
The Controller responds without undue delay, as a rule within one month. For complex or numerous requests the period may be extended by a further two months, with notice within the first month. Where there is reasonable doubt, the Controller may request proportionate further information needed for identification.
9. Remedies
The data subject may first contact the Controller directly. They may also lodge a complaint with the supervisory authority or go to court.
- Authority: Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
- Address: 1055 Budapest, Falk Miksa utca 9–11.
- Postal address: 1363 Budapest, Pf. 9.
- Email: ugyfelszolgalat@naih.hu
- Phone: +36 1 391 1400
- Website: https://www.naih.hu
Under the GDPR, court proceedings may also be brought in the Member State of the Controller’s establishment or of the data subject’s habitual residence.
10. Cookie notice
According to the website’s current information, the Webshop uses cookies for cart and language settings. Exact cookie names, domains and expiries cannot be determined without a live browser and network review, so the inventory below must be completed before publication.
Statistical, convenience or marketing cookies that are not necessary for the service may only be placed with prior, specific and withdrawable consent. “Accept all” and refusal must be equally easy; pre-ticked toggles and mere continued browsing are not valid consent. The user must later be able to change their choice just as easily.
Cookies can be deleted or blocked in the browser, but blocking strictly necessary cookies may prevent the cart or checkout from working.
11. Newsletter and marketing
At the time of publishing this version, no newsletter subscription was identifiable on the website. The Controller may not send electronic direct marketing without prior, explicit consent. Before introducing a newsletter, a separate subscription text, demonstrable consent, easy unsubscribe, a provider list and an updated privacy notice are required.
12. Changes to this notice
The Controller amends this notice when laws, providers or processing change, indicating the change and effective date, and archives prior versions. Before a new purpose or consent-based processing, appropriate prior information is given and, where needed, new consent is obtained.
