This notice explains what personal data Triglav Modular collects, why, and what you can do about it. It covers the shop at triglavmodular.hu.
Who is responsible
The data controller is Márton Bertók (Triglav Modular), a sole trader in Budapest, Hungary. For anything in this notice, or to exercise any of the rights below, email [email protected]. The full trading address is on the Terms and conditions page.
What is collected, and why
Only what an order needs, plus what the law requires of a seller.
- Placing and delivering an order — your name, email, postal address, phone number and what you bought. Used to take payment, issue the invoice, and ship the goods. Legal basis: performance of the contract (GDPR Art. 6(1)(b)).
- Invoicing — your billing details appear on the invoice, which the law requires to be kept. Legal basis: legal obligation (Art. 6(1)(c)); Hungarian accounting law sets the retention period.
- An account, if you create one — your email, name and saved address, so you do not re-enter them. Legal basis: contract, and your consent for the account itself (Art. 6(1)(a)/(b)).
- Fraud prevention and site security — payment and bot-protection checks at the checkout process technical data such as your IP. Legal basis: legitimate interest in not being defrauded (Art. 6(1)(f)).
- Email you send — if you write in, that message and its address, to reply and keep a record. Legal basis: legitimate interest.
Who else handles it
Running a shop means a few specialist services process some of your data on the shop’s behalf or as their own controllers. Each has its own privacy notice.
- Stripe and PayPal — card and wallet payments. Card details are entered on their systems and never reach this site.
- Billingo — issues the invoices, in Hungary.
- The shipping carrier — receives the delivery address and a tracking record for your parcel.
- Google reCAPTCHA — bot protection on the checkout.
- Cloudflare — serves and protects the site, and sees request data such as your IP in doing so.
- The email/SMTP service — delivers the shop’s transactional email (order confirmations and the like).
Data is shared only as needed for these purposes, and never sold.
Sending data outside the EU
Some of those services (Stripe, PayPal, Google, Cloudflare) are based in or transfer data to the United States. Where they do, the transfer relies on the EU–US Data Privacy Framework or the European Commission’s Standard Contractual Clauses.
How long it is kept
Invoices and the order data on them are kept for the retention period Hungarian accounting law requires (eight years). Account data is kept until you delete the account or ask for it to be removed. Support email is kept only as long as it is useful. Cookies expire as set out below.
Cookies
The shop sets a small number of cookies. The functional ones are needed for it to work; the others are named so you know what they do.
- Cart and session (woocommerce_cart_hash, woocommerce_items_in_cart, wp_woocommerce_session_*) — remember what is in your cart. Strictly necessary; not optional.
- Payment and anti-fraud (Stripe’s __stripe_mid / __stripe_sid, PayPal’s, Google reCAPTCHA’s) — set once a purchase is under way, to take payment safely.
- Order source (sbjs_*) — record how you arrived, so an order can note where it came from.
Your rights
Under the GDPR you may ask to see the data held about you, to correct it, to have it deleted, to restrict or object to its use, and to receive it in a portable form; and you may withdraw any consent you gave. Some of these are limited by the invoice-retention obligation above. Email [email protected] to exercise any of them.
If you think your data has been handled wrongly, you may complain to the Hungarian supervisory authority, the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), naih.hu — though getting in touch first is usually quicker.
Changes
If this notice changes, the version here is always the current one.