POLINVENT | USA

Privacy Policy

Effective: 29 April 2025

This policy provides an overview of what personal data we collect from users on our website https://www.polinvent.com/ (the "Website") and on our other interfaces (e.g. Facebook, Instagram), how we use and transfer this personal data, how data subjects can obtain information about the data provided, and what security measures we take to protect users' personal data.

POLINVENT Kft. cares about the protection of the personal data of its users, and therefore, in all operations (e.g. collection, processing and transmission), when processing personal data, it complies with the applicable EU and Hungarian legislation, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council - General Data Protection Regulation of the European Union (hereinafter: GDPR).

I.Operator of the website, data controller

Regarding the processing of personal data indicated in this information, the processing of personal data is carried out by POLINVENT KFT (registered office: 2360 Gyál, Bánki Donát utca 22., company registration number: 13-09-197070, authorised representative: Attila Áron Nagy, managing director, hereinafter referred to as POLINVENT). Users may send their requests and questions regarding the protection of personal data and the exercise of their data subject rights to one of the following contact details:

II.Personal data

Personal data is any information relating to an identified or identifiable natural person ("data subject"). An identifiable natural person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, telephone number, bank details, IP address.

III.Certain data processing, data processing purposes

(i) Data recorded in log files

When using our website, the following data is recorded as a log file on the website server:

  • information about the type of browser and the version of the browser you are using;
  • the resolution of your visit to the website;
  • the user's operating system and other information about the terminal equipment used;
  • User's IP address;
  • the duration of access;
  • the website from which the user's system accessed our website;
  • the websites visited by the user on our website.

The data collected in this way is used for internal, system operation and statistical purposes only. The data will not be stored together with other personal data of the user.

The data stored in the log files also ensure the functionality of the website. We use this data to optimise our website and to ensure the security of our IT systems. We do not use the data recorded in the log files for marketing purposes.

We process the log files for the purposes of data processing in accordance with Article 6(1)(f) of the GDPR to assert our legitimate interest in the proper functioning of the site and the collection of statistical data.

The data is deleted as soon as it is no longer necessary for the purpose for which it was collected:

  • the processing for the purposes of ensuring the functioning of the website ends when the session is closed;
  • data stored in log files will be deleted after a maximum of 7 days.

If user IP addresses recorded in log files are deleted or changed, they can no longer be assigned to the client browsing the website.

Given the fact that the processing and storage of the data is necessary for the functioning of the website, the data subject cannot object to this processing.

(ii) Contact form used on this website

On the website, the visitor can contact the data controller. The visitor can indicate his/her interest in the data controller's products by using the contact form. In the contact form, the name and e-mail address of the visitor must be provided. By filling in the form, the visitor as data subject declares that he/she has read the data controller's Privacy Notice. The personal data provided for this purpose will be processed by the data controller solely for the purpose of contacting you. After contacting the data subject, the data controller shall delete the personal data of the interested party without undue delay and at the latest within 3 working days. The processing is carried out for the purpose of establishing the contract on this legal basis.

On the website of the controller, the data subject declares that he or she is over 18 years of age in relation to the use of the customer contact form. A person under 18 years of age may not contact the controller via the customer contact form, given that, pursuant to Article 8(1) of the GDPR, the validity of his or her consent to processing requires the consent of his or her legal representative. The controller is not in a position to verify the age and entitlement of the person giving consent, so the data subject warrants that the data he or she has provided are accurate.

(iii) Registration

Users may register on our website in order to place an order. Registration is possible by providing the following data:

  • company name,
  • contact person name,
  • email address of the contact person,
  • phone number of the contact person,
  • password,
  • billing details (company name, company tax number, billing address, VAT ID),
  • shipping details (company name, shipping address, company phone number).

In addition to the above, the date and time of registration will also be saved. The above information is required for registration.

By registering, the user acknowledges the contents of this Privacy Policy and by clicking on the "Submit" button, the user expressly agrees that his/her data may be used for the following purposes after registration:

  • to fulfil orders,
  • website management.

The legal basis for the processing of personal data is the consent of the data subject, i.e. Article 6(1)(a) GDPR.

We delete the data as soon as it is no longer necessary for the purpose for which it was collected, so we process the data until the registration is cancelled or the consent is withdrawn.

Please note that if you withdraw your consent to data processing, your registration (account) will be deleted, but we will continue to process your data relating to your purchases.

(iv) Purchases

We process the following data when you make purchases through this website:

  • billing information (company name, company tax number, billing address),
  • delivery details (company name, delivery address, telephone number),
  • purchase details,
  • payment details.

If you are registered, we will automatically use your registration details for your purchase after you log in to the website.

The processing of data relating to purchases is necessary for the performance of contracts and to comply with applicable civil law, consumer protection, accounting, tax and related procedural legislation, and the legal basis for the processing of such data is Article 6(1)(b) and (c) of the GDPR.

If you are the beneficiary of a given purchase (the purchased product is delivered to you, but you did not order it), or a contact person of the legal person of the purchaser, we process your data based on our legitimate interest in the performance of the contract, in accordance with Article 6(1)(f) of the GDPR.

We will delete your purchase data as soon as it is no longer necessary to fulfil contracts and/or other legal obligations.

We inform the persons concerned by the processing of personal data in connection with purchases that we process their personal data until the end of the year following the expiry of the general limitation period (5 years) for the purposes of protecting our rights, internal records and controls, based on our legitimate interest.

In the event of legal, administrative or other proceedings, we will process them on the basis of our legitimate interest for the period necessary for the proceedings, even beyond the period indicated above.

(v) Payment data

Payment details are processed together with your purchase details. You can only pay online by credit card through Stripe.

Stripe is a technology company building the economic infrastructure for the internet. It enables businesses of all sizes - from start-ups to public companies - to accept payments and manage their businesses online.

Paying by credit card is a convenient and secure way to shop in our Webshop. After ordering the goods you have selected, you will be redirected to the Stripe interface, where you can pay with your credit card through the encrypted transaction currently considered the most secure by Stripe.

Security is based on the separation of data. The Webshop receives the order information from the customer, and Stripe receives only the card details required for the payment transaction on the TLS encrypted payment page.

The Webshop is not informed of the data content of the payment page, which can only be accessed by Stripe. The result of the transaction will be communicated to the Webshop page after payment. To pay by card, your Internet browser must support SSL encryption. The value of the goods/services purchased, the amount paid, will be blocked immediately on your card account.

All our customers must do is click on "Pay online by credit card" when selecting a payment method, and then enter the credit card number, expiry date, three-digit security code and the name on the credit card in the Stripe payment interface.

Stripe's online payment system allows you to pay with MasterCard; VISA; American Express; Apple Pay; Google Pay.

We can only accept cards issued for electronic use only if the bank issuing the card authorises its use! Please check with your bank whether your card can be used for online purchases.

Confirmation of all transactions (including unsuccessful ones) will be sent to the email address provided at the time of purchase.

We will not pass on any additional costs associated with the payment method to our customers, but your service provider (e.g. credit card issuer, PayPal) may deduct other costs beyond our control.

(vi) Contacting us

Users are entitled to contact us using the e-mail contact details on our website, where we process the following data:

  • name,
  • e-mail address,
  • Contents of your message.

The data generated during the contact process and any subsequent correspondence will be processed for the purposes of maintaining contact with you, responding to your inquiries, fulfilling your requests, and handling any complaints. Additionally, we process this data based on our legitimate interests for the protection of our rights, internal record-keeping, audits, and quality assurance, as well as to comply with our legal obligations. Therefore, the legal basis for processing this data is Article 6(1)(c) and (f) of the GDPR.

In accordance with the above, the data processed in connection with contacting us and maintaining communication will be retained until the end of the year following the general statute of limitations period (5 years). In the event of legal, official, or other proceedings, we may process this data beyond the aforementioned period based on our legitimate interests, for the duration necessary for such proceedings.

IV.Cookies, pixels, other technologies

We use various technologies on the Website that involve(s) the use of your personal data, details of which are available in our Cookie Notice.

V.Data transfer

The personal data you provide will be shared with and/or accessed by the following partners, who will further process your data as independent data controllers:

Partners for parcel delivery services

DHL Express Magyarország Kft.

Office: 1185 Budapest, BUD International Airport Terminal 1, DHL building 302.

Company registration number: 01-09-060665

Web: www.dhl.hu

Purpose of data processing: parcel delivery service

Data transferred: name, postcode and address of the User, billing name and address.

Further data transfer

  • Credit card payment platform operator: Stripe, Inc. (office: 185 Berry Street, Suite 550, San Francisco, CA 94107 USA, Web: www.stripe.com, Email: info@stripe.com)
  • Google Ads: Google Ireland Ltd. (office: Gordon House, Barrow Street, Dublin 4, Ireland) and Google LLC (office: 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States) Google Privacy Policy

Data processors

We use the following data processors for data processing:

  • Website hosting, operation, cloud services:
    • Cognityv Technologies Korlátolt Felelősségű Társaság (2360 Gyál, Bánki Donát utca 22., tax number: 25584280-2-13, web: https://cognityv.com/)
    • Amazon Web Services Inc. (office: 1 Burlington Rd, Dublin 4, Ireland, tax number: LU26888617, Web: https://aws.amazon.com/)
  • Operating analytical, analysis software: Google Analytics: Google Ireland Ltd. (office: Gordon House, Barrow Street, Dublin 4, Ireland) and Google LLC (office: 1600 Amphitheatre Parkway, Mountain View, CA 94043, United States) Google Privacy Policy

In addition to the above, we may transfer your data to third parties only to our legal, financial and claims management partners and to public authorities and courts, will inform you in advance or obtain your consent to transfer data to other third parties.

VI.Security measures

We undertake several security protocols to safeguard your personal data. The information we process is protected through physical and technological means to ensure access is restricted solely to duly authorized personnel.

Our information technology infrastructure is fortified by a dedicated hardware firewall to prevent unauthorized access from external networks. Access to personal data is limited to those employees within our organization who require such access to fulfill their designated responsibilities. These employees receive comprehensive training in security and data privacy practices. To secure the acquisition and transmission of personal information via our website, we employ standardized Secure Sockets Layer (SSL) encryption technology. During the order processing phase, personal information is transmitted through SSL-encrypted communication, indicated by the padlock symbol in the web browser and the "https://" prefix in the address bar.

You are advised to maintain the confidentiality of your password and refrain from disclosing it to third parties for website access. Furthermore, it is recommended that you periodically update your password. We strongly counsel against utilizing the same password for accessing our website as you employ for other password-protected online platforms, such as email accounts and online banking services.

Upon concluding your session on our website, it is prudent to log out of your account and close your browser to mitigate the risk of unauthorized access. Please be aware that we cannot provide an absolute guarantee of data security for communications conducted via electronic mail.

VII.Your Data Protection Rights

As a data subject under the GDPR, you possess the following rights concerning your personal data that we, as the data controller, process:

a) Right of Access

You have the right to inquire whether we are processing your personal data. If we are, you are entitled to access that data and receive pertinent details about the processing activities, including the reasons for processing and who the data may be shared with.

b) Right to Rectification

Should your personal data be inaccurate, you have the right to request that we rectify it promptly. Taking into account the reasons for processing, you may also request that incomplete data be completed, which can include providing additional information.

c) Right to Erasure ('right to be forgotten')

You have the right to have your data erased, without undue delay, by the data controller, if one of the following grounds applies:

  • Where your personal data are no longer necessary in relation to the purpose for which it was collected or processed.
  • Where you withdraw your consent to the processing and there is no other lawful basis for processing the data.
  • Where you object to the processing and there is no overriding legitimate grounds for continuing the processing.
  • Where you object to the processing and your personal data are being processed for direct marketing purposes.
  • Where your personal data have been unlawfully processed.
  • Where your personal data have to be erased in order to comply with a legal obligation.
  • Where your personal data have been collected in relation to the offer of information society services (e.g. social media) to a child.

The above does not apply in cases where the processing is necessary:

  • to exercise the right to freedom of expression and information;
  • to comply with an obligation under Union or Member State law that requires the processing of personal data that is applicable to Polinvent, or to carry out a task carried out in the public interest or in the exercise of official authority vested in us;
  • in the public interest in the field of public health;
  • for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, where a right of erasure would be likely to render such processing impossible or seriously jeopardise it; or
  • for the establishment, exercise or defence of legal claims.

d) Right to Restriction of Processing

You shall have the right to obtain from the controller restriction of processing where one of the following applies:

  • You contest the accuracy of the personal data; in which case the restriction applies for the period of time that allows the controller to verify the accuracy of the personal data;
  • the processing is unlawful, and you oppose the erasure of the data and instead request the restriction of their use;
  • we no longer need the personal data for the purposes of processing, but you require them for the establishment, exercise or defence of legal claims; or
  • you have objected to processing - in which case the restriction will apply for a period until it is determined whether our legitimate grounds for processing override your legitimate grounds.

Right to data portability

As a data subject, you have the right to receive the personal data concerning you that you have provided to us in a structured, commonly used, machine-readable format and the right to transmit such data to another controller without our hindrance, if:

  • processing is based on your consent or on a contract with us; and
  • the processing is carried out by automated means.

In exercising this right, you have the right to request, where technically feasible, the direct transfer of personal data between controllers.

The exercise of this right must not adversely affect the rights and freedoms of others.

e) Right to Object

You have the right to object at any time, on grounds relating to your particular situation, to the processing of your personal data based on Article 6(1)(e) or (f) of the GDPR (processing necessary for the performance of a task carried out in the exercise of official authority or processing carried out for the purposes of the legitimate interests pursued by the controller), including profiling based on those provisions. In this case, we may no longer process the personal data, unless we can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.

If your personal data are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such purposes, including profiling, if it is related to direct marketing. If you object to the processing of your personal data for direct marketing purposes, your personal data will no longer be processed for these purposes.

Contact Us

If you have any questions, comments or complaints about our processing or if you wish to exercise any of the rights set out above, please contact us using one of the contact details below:

In the event that you consider the processing of your personal data to be non-compliant with applicable regulations, or if you have incurred damages as a consequence of such processing, you are entitled to pursue the following remedies:

  • Judicial Remedy: You may bring your case before the competent court for judicial review (https://birosag.hu/birosag-kereso).
  • Official Complaint: You have the right to file a formal complaint with the National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság - NAIH), with its headquarters at 1055 Budapest, Falk Miksa utca 9-11., and accessible via their website at www.naih.hu.

VIII.Amendment of this policy

We reserve the right to unilaterally change this Privacy Notice and its annex without prior notice. Therefore, please check this website regularly for any changes to this Privacy Notice.