DATA PROTECTION DECLARATION
Stand: 02.FEB.2025
1. RESPONSIBLE PERSON & CONTACT
Responsible person:
CARBOFARM Kft.
1134 Budapest, Váci út 45, Building G, 7th Floor
Hungary
E-Mail: privacy@carbo.farm
2. BASICS & PURPOSES OF DATA PROCESSING
We process personal data based on the GDPR:
- Contract fulfilment (Art. 6 para. 1 lit. b): For orders, deliveries, invoices.
- Legal Obligations (Art. 6 para. 1 lit. c): Tax-related retention (§ 132 BAO), Reporting obligations.
- Legitimate interests (Art. 6 para. 1 lit. f): IT security, fraud prevention, marketing (unless there is an objection).
- Consent (Art. 6 para. 1 lit. a): E.g. for newsletters, analytical cookies (can be revoked at any time).
3. OPERATION OF OUR WEBSITE
Hosting: Odoo (Webshop) – Data Protection Policy.
Domain: GoDaddy – Data Protection Policy.
Collected Data:
- Technical: IP address, browser data, access time.
- Content-related: Information from contact forms, registrations.
Purpose: Operation of the website, contract processing, security.
Storage duration: Log data max. 12 months (except in case of investigations).
4. COOKIES
Basis:
- Essential Cookies: Art. 6 para. 1 lit. f GDPR (Functionality of the webshop).
- Analysis Cookies: Only with consent (Art. 6 para. 1 lit. a).
Details:
Cookies gemäß Cookie Policy.
Control:
- Browser settings (e.g. Chrome: Settings > Privacy and security > Cookies).
- Cookie banner in the webshop (if provided by Odoo).
5. WEBSHOP (Odoo)
Collected Data:
Category | Examples | Legal basis |
---|---|---|
Mandatory information | Name, Address, Payment data* | Art. 6 Abs. 1 lit. b, c |
Optional | Date of birth, Language preference | Art. 6 Abs. 1 lit. a, f |
Technical | IP-Address, Order history | Art. 6 Abs. 1 lit. f |
*Credit card data is processed directly by PCI-DSS certified partners (Stripe, PayPal).
Data transfer:
- Logistics partners: DHL, UPS (only necessary for delivery).
- Payment service provider: Stripe (Data protection), PayPal (Data protection).
- Tax authorities: In case of legal obligation.
Storage duration:
- Contract data: 7 years (according to § 132 BAO).
- Account data: Until the deletion of your account + 3 years (claims).
6. SOCIAL MEDIA
Used platforms:
- LinkedIn (Data protection)
- Facebook (Data protection)
- X (Twitter) (Data protection)
- Instagram (Data protection)
Notes:
- We have no control over the data processing by these providers.
- Interactions (e.g. "Share", "Like") are subject to their privacy policies.
- Direct messages on social media are in accordance with our general Verarbeitungsgrundsätzen behandelt (siehe Punkt 2).
7. YOUR RIGHTS
According to the GDPR, you can:
- Request information about stored data (Art. 15).
- Request correction of inaccurate data (Art. 16).
- Request deletion, provided that there is no retention obligation (Art. 17).
- Request restriction of processing (Art. 18).
- Receive data portability in a machine-readable format (Art. 20).
- Submit an objection to direct marketing (Art. 21).
Right of complaint:
If you have any data protection concerns, please contact us first.
Additionally, you can contact the Hungarian supervisory authority:
NAIH (Szilágyi Erzsébet fasor 22/C, H-1125 Budapest).
8. CHANGES
Current version at: www.carbo.farm/datenschutz.