GDPR
1. Introduction
1.1. The Purpose of the Privacy Notice
The purpose of this Privacy Notice (hereinafter: "Notice") is to explain, in a transparent and detailed manner, how we process personal data in the course of the activities of Landscape Studio Kft. (hereinafter: "Data Controller") in the course of its activities, as well as to provide information about the rights of data subjects and how to exercise those rights.
1.2. Legal Compliance (GDPR, Act CXII of 2011 - Hungary)
• Regulation (EU) 2016/679 of the
European Parliament and of the Council (GDPR): establishes uniform EU
rules on the protection of personal data.
• Act CXII of 2011 (Infotv.): the law that
forms the basis of Hungarian data protection regulations, which addresses the
right to informational self-determination and freedom of information.
This
Prospectus is intended to comply with the requirements set forth in the
above-mentioned laws.
2. Data Controller Information
2.1. Name and Contact Information of the Data Controller
• Name: Landscape Studio Kft.
• Registered office: H2800 Tatabánya,
Vértanúk sqr 2/a, Hungary
• Company registration number: 11-09-031231
• Tax ID number: 32649006-2-11
• Representative: István Jäger, Managing
Director
• Email: hub@veridian-hub.com
• Phone number: +36706348312
(Hungarian/English/German)
2.2. Availability of the Privacy Notice
This Prospectus is available in electronic form at https://www.veridian-hub.com/gdpr/ and can also be viewed in print form upon request at our customer service office.
3. Definitions
3.1. Basic GDPR Concepts
• Personal data: any information relating to
an identified or identifiable natural person ("data subject").
• Data controller: the natural or legal
person who determines the purposes and means of the processing of personal
data.
• Data processor: the natural or legal person
who processes personal data on behalf of the data controller.
• Consent: a voluntary and explicit
expression of the data subject's will, by which they give their consent to the
processing of personal data relating to them.
• Data subject: any identified or
identifiable natural person to whom the personal data relates.
3.2. Definition of a Data Breach
A data breach is defined as any incident that results in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to personal data that has been transferred, stored, or otherwise processed.
4. Data Processing Policy
4.1. Legal Bases and Principles
• Lawfulness, fair processing, and
transparency: We process data only for specific and lawful purposes.
• Purpose limitation: We process data only
for a predetermined purpose and to the extent necessary to achieve that
purpose.
• Data minimization: We collect and process
only the personal data that is essential to achieving the purpose.
• Accuracy: We ensure that the personal data
we process is accurate and, where necessary, up to date.
• Limited retention: We store personal data
only for as long as necessary to achieve the purpose.
• Integrity and confidentiality: We implement
appropriate technical and organizational measures to protect personal data.
4.2. Data Accuracy and Security
• Both the Data Controller and the data
subject are responsible for regularly updating the data; the data subject is
required to notify the Data Controller of any changes to their personal data.
• The Data Controller will take all necessary
measures to ensure that the recorded data is accurate and will protect it from
unauthorized access through appropriate security measures.
5. Purposes and Legal Bases for Data Processing
5.1. Registration on the Website
• Purpose: To create a user account, provide
related services, and establish contact.
• Legal basis:
o Consent (Article
6(1)(a) of the GDPR) if registration is voluntary and requested by the data
subject.
o Performance of a
contract (Article 6(1)(b) of the GDPR) if registration is a prerequisite for providing
the service or establishing contact.
• Scope of data processed: Name, email address, password (encrypted), registration date, IP address, phone number, company name.
5.2. Order Management (Partner Portal)
• Purpose: Processing orders, fulfilling the
contract, invoicing, and shipping.
• Legal basis: Performance of a contract
(GDPR Article 6(1)(b)).
• Scope of data processed: Name, shipping and
billing addresses, contact information (phone number, email), order details.
5.3. Invoicing (via the partner portal and based on individual contracts)
• Objective: To comply with applicable accounting laws and regulations (e.g., Act C of 2000).
• Legal basis: Compliance with a legal
obligation (GDPR Article 6(1)(c)).
• Scope of data processed: Name/company name,
address, tax ID number (for legal entities), and other data necessary for
invoicing.
5.4. Subscribe to the Newsletter
• Purpose: Marketing communications,
providing information about new products and promotions.
• Legal basis: Consent (GDPR Article
6(1)(a)).
• Scope of data processed: Name, email
address.
• Note: You may unsubscribe from the newsletter at any time by clicking the link at the bottom of the newsletter or by contacting the Data Controller directly.
5.5. Use of Cookies
• Purpose: To ensure the proper functioning
of the website, improve the user experience, analyze traffic data, and for
marketing purposes.
• Legal basis:
o Consent (GDPR
Article 6(1)(a)) – for all cookies that are not essential to the functioning of
the website.
o Legitimate
interest or performance of a contract (GDPR Article 6(1)(f) or (b)) – for
technical cookies that are essential for the website's operation.
• Further details: See the "Use of Cookies"
section (Section 11) of this Notice.
5.6. Data Processing on Social Media Platforms
• Purpose: Staying in touch, sharing
information (LinkedIn, Facebook, Instagram, etc.).
• Legal basis: Voluntary decision, consent
(GDPR Article 6(1)(a)).
• Note: Please refer to the privacy policy of
each social media platform for information on its data processing practices.
6. Scope of Processed Data
6.1. Types of Personal Data
• Identification data: name, username,
password (encrypted).
• Contact information: email address, phone
number, address.
• Technical data: IP address, browser type,
cookies, login time.
• Billing information: billing name, address,
tax ID number (for companies).
6.2. Method and Duration of Data Storage
• In electronic form on secure servers,
protected by passwords and other security measures.
• In paper form (if applicable) at the
headquarters or branch office, in a locked location.
• Retention period: until legal obligations
are fulfilled, the purpose of data processing is achieved, or consent is
withdrawn. Afterward, the data will be deleted or anonymized.
7. The Rights of Data Subjects
7.1. Right to Information
The data subject has the right to request information regarding the purposes for which we process their personal data, the legal basis for such processing, the sources of the data, the duration of the processing, and who has access to it.
7.2. Right to Correction
If the data subject believes that their personal data being processed is inaccurate or incomplete, they may request that it be corrected or supplemented.
7.3. Right to Erasure ("Right to Be Forgotten")
The data subject may request the erasure of their personal data if the data is no longer necessary for the original purpose, or if the data subject withdraws their consent and there is no other legal basis for the processing.
7.4. Right to data portability
The data subject has the right to receive the data he or she has provided in a widely used, machine-readable format, and may request that such data be transmitted to another data controller.
7.5. The Right to Protest
• The data subject may object at any time to
the processing of their personal data if the legal basis for the processing is
the Data Controller's legitimate interest.
• The data subject has the specific right to
object to the processing of their personal data for direct marketing purposes.
8. Data Security
8.1. Protection of Electronic Data
• Multi-level access control system.
• Regular backups.
• Virus protection and firewall.
8.2. Technical and Organizational Measures
• Use of a closed office network and secure
Wi-Fi.
• Storage of paper-based documents in a
locked cabinet.
• Regular data protection training for
employees and data processors.
9. Handling Data Breaches
9.1. Reporting an incident to the authorities (72-hour rule)
In the event of a data breach, the Data Controller shall report it to the National Authority for Data Protection and Freedom of Information (NAIH) without undue delay and, if possible, within 72 hours at the latest, unless it is unlikely to pose a risk to the rights and freedoms of the data subjects.
9.2. Informing Affected Parties in the Event of High Risk
If the incident is likely to pose a high risk to the rights and freedoms of the data subjects, the Data Controller shall inform the data subjects without delay, explaining the nature of the incident and the measures taken.
10. Data Processors and Third Parties
10.1. Web Hosting Provider
• Name: Webnode AG
• Registered office: Badenerstrasse 47, 8004
Zurich, Switzerland
• Contact information: webnode@webnode.com
• Data processor activities: web server
operation and technical maintenance. Processes personal data solely in
accordance with the Data Controller's instructions.
10.2. Accountant and Other Partners
The Data Controller may engage an accountant, a courier service, a marketing agency, and other partners to process personal data.
• Accountant: Gergely Papp, Mérlegkép.ES Team
Kft; services: accounting, payroll processing, and tax-related tasks.
• Courier service: GLS; activities: delivery
of ordered products.
• Marketing agency: CR3 Marketing Agency Kft.
– CR3Agency; activities: planning and execution of marketing campaigns.
The Data Controller always enters into a written contract with these partners (data processors) in accordance with the requirements of the GDPR. The contracts stipulate that the partners may process the data exclusively in accordance with the Data Controller's instructions, for the specified purpose, and for the necessary period of time.
11. Use of Cookies
11.1. The Purpose and Types of Cookies
• Session cookies: These are essential for
the website to function and are deleted when you close your browser.
• Functional cookies: These enhance user
convenience; for example, they remember your login credentials or your selected
language.
• Analytics cookies (e.g., Google Analytics):
used for statistical purposes; they help us understand user behavior and
improve the website's performance.
• Marketing cookies: used to display relevant
ads and measure the effectiveness of those ads.
11.2. Managing User Settings
• Users can control how cookies are handled
in their browser settings, allowing them to disable or delete them.
• If you change your cookie settings, some
features of the website may not function properly.
• When you visit the website for the first
time, you'll have the option to accept or reject non-essential cookies (e.g.,
marketing cookies) via a pop-up window.
12. Data Protection Officer
12.1. Criteria and Duties for Appointment
Under Article 37 of the GDPR,
the Data Controller is required to appoint a Data Protection Officer (DPO) if
its core activities:
• involve data processing operations that, by
virtue of their nature or scope, require regular and systematic monitoring, or
• are based to a significant extent on the processing
of highly sensitive data.
The DPO's responsibilities
include:
• continuously monitoring compliance with the
GDPR,
• providing advice to the Data Controller and
employees,
• maintaining contact with the supervisory
authority (NAIH) and data subjects.
12.2. Legal Status and Contact Information
The Data
Protection Officer reports directly to senior management and cannot be
instructed to act outside the scope of his or her duties.
• Name: István Jäger
• Contact information: hub@veridian-hub.com
If the Data
Controller is not required to appoint a DPO but nevertheless appoints one, it
will inform the data subjects accordingly in this Notice.
13. Remedies Available to Affected Parties
13.1. Filing a Complaint with the National Authority for Data Protection and Freedom of Information (NAIH)
If the data subject believes
that the processing of their personal data violates applicable laws, they may
file a complaint with the National Authority for Data Protection and Freedom of
Information:
• Address: 1055 Budapest, Falk Miksa Street
9-11.
• Phone: +36 (1) 391-1400
• Email: ugyfelszolgalat@naih.hu
13.2. Availability of Judicial Remedies
If the data subject's rights are violated, he or she may bring a lawsuit. The lawsuit may be filed—at the data subject's discretion—with the court having jurisdiction over his or her place of residence or place of stay.
14. Legal provisions governing data processing
14.1. GDPR (EU Regulation 2016/679)
Regulation (EU) 2016/679 of the European Parliament and of the Council, which aims to protect natural persons with regard to the processing of personal data and to ensure the free flow of such data within the EU.
14.2. Act CXII of 2011 on the Right to Informational Self-Determination
The Hungarian Data Protection Act, which governs the fundamental principles and limitations of personal data processing in Hungary.
14.3. Other Relevant Hungarian Laws
- Act C of 2000 on Accounting.
- Act V of 2013 on the Civil Code (Ptk.).
- Act XLVIII of 2008 on the Basic Conditions
for Commercial Advertising Activities.
15. Final Provisions
15.1. Scope of the Privacy Notice and Options for Amending It
• This Privacy Notice is effective as of
August 13, 2026.
• The Data Controller reserves the right to
unilaterally amend this Privacy Notice, particularly in response to changes in
legislation, the introduction of new data processing activities, or to comply
with the recommendations of the supervisory authority.
• Amendments will be published on the
website, and upon their entry into effect, data subjects accept the new rules
by continuing to use the services.
Dated: Tatabánya, August 13, 2026
Landscape
Studio Kft.
(István
Jäger, CEO)
