Skip to Content
  • English (US) Magyar
  • 30+ years of experience • Nationwide delivery • Professional support

  • 0
    My Cart
  • 0
    Wishlist
  • Sign in
  • Products

    Takeaway & packaging


    Takeaway & packaging Glassware & bar supplies Hygiene & cleaning Storage & logistics All products Offers & clearance

    Tableware & serving


    Tableware & serving Cutlery Shop equipment

    Kitchen & back-of-house


    Kitchen & preparation Pastry & bakery Hygiene & cleaning Storage & logistics Professional consultation

    Quick links


    All products Offers & clearance Delivery & payment Contact
  • Brands
  • Services
    • Appointment
    • Our services
  • About Us
  • Contact
Impex 2000 HoReCa Center Kft.
  • Contact us
Impex 2000 HoReCa Center Kft.
  • 0
  • 0
    • Products
    • Brands
    • Services
      • Appointment
      • Our services
    • About Us
    • Contact
  • 30+ years of experience • Nationwide delivery • Professional support

  • English (US) Magyar
  • Sign in
  • Contact us

Privacy Notice

1. The purpose of the regulation, the name of the data controller

This document provides information about the processing of your personal data and your related rights according to the European Union regulation (Regulation (EU) 2016/679 of the European Parliament and of the Council, hereinafter: GDPR) and the domestic legislation (Act CXII of 2011 on the right to informational self-determination and freedom of information, hereinafter: Info Act).

Name and contact details of the data controller:

The name of the data controller: Impex 2000 HoReCa Center Kft. (hereinafter: Company or Data Controller)

The mailing address of the data controller: H-1097 Budapest, Ecseri út 14–16., Building F, ground floor.

The email address of the data controller: iroda [at] horecacenter [dot] hu

The phone number of the data controller: +36 1 799 1191

2. Concepts and interpretations related to personal data

personal data: data that can be associated with the data subject – particularly the data subject's name, identification mark, as well as knowledge characteristic of one or more physical, physiological, mental, economic, cultural, or social identity – and any conclusion regarding the data subject that can be drawn from the data;

sensitive data: a) personal data related to race, ethnicity, political opinion or party affiliation, religious or other philosophical beliefs, membership in an interest representation organization, sexual life, b) personal data related to health status, pathological addiction, as well as criminal personal data;

data management: any operation performed on data, regardless of the applied procedure, or the totality of operations, particularly collection, recording, storage, alteration, use, querying, transmission, disclosure, coordination or combination, restriction, deletion, and destruction, as well as preventing further use of the data, taking photographs, sound or video recordings, and recording physical characteristics suitable for identifying the person (e.g., fingerprint or palm print, DNA sample, iris image);

data processing: performing technical tasks related to data management operations, regardless of the methods and tools used for executing the operations, as well as the location of the application, provided that the technical task is performed on the data;

data transfer: making data accessible to a specified third party;

disclosure: making data accessible to anyone;

data controller: the natural or legal person, or organization without legal personality, who or which independently or together with others determines the purpose of data processing, makes and executes decisions regarding data processing (including the tools used), or has it executed by the data processor;

data processor: the natural or legal person, or organization without legal personality, who or which processes data based on a contract – including a contract concluded under legal provisions;

data deletion: the rendering of data unrecognizable in such a way that their recovery is not possible.

3. Principles of data processing

Only personal data that is essential for the realization of the purpose of data processing can be processed, suitable for achieving the purpose. Personal data can only be processed to the extent and duration necessary for the realization of the purpose.

Personal data retains this quality during data processing as long as its relationship with the data subject can be restored. The relationship with the data subject can be restored if the data controller has the technical conditions necessary for recovery.

During data processing, the accuracy, completeness, and – if necessary considering the purpose of data processing – up-to-dateness of the data must be ensured, as well as that the data subject can only be identified for as long as necessary for the purpose of data processing.

Personal data may be processed if the data subject consents to it, or if it is ordered by law or – based on the authorization of law, within the scope defined therein – by a local government regulation for a purpose based on public interest (hereinafter: mandatory data processing).

Personal data may also be processed if the processing is necessary for the legitimate interests of the data controller, or the third party receiving the data, or parties, except if the interests of the data subject that are entitled to protection are of higher priority in terms of fundamental rights and freedoms (GDPR Article 6(1)(f)).

Personal data – in the absence of a legal provision – may only be processed with the consent of the visitor. The nature of the data provision – voluntary or mandatory – must be explained before the data collection. In the case of mandatory data provision, the legal regulation ordering the data processing must be indicated. During data processing, the data may only be used for the specified purpose.

In addition to the purpose of data processing, clear information must be published about who will handle and process the data.

The data controller is obliged to plan and execute the data processing operations in such a way as to ensure the protection of the data subjects' privacy during the application of the relevant laws.

The data controller, as well as the data processor in its area of activity, is obliged to ensure the security of the data, and is also required to take the necessary technical and organizational measures and establish the procedural rules necessary for the enforcement of the relevant data and confidentiality protection regulations.

The data must be protected with appropriate measures, especially against unauthorized access, alteration, transmission, disclosure, deletion, or destruction, as well as against accidental destruction and damage, and against becoming inaccessible due to changes in the applied technology.

The visitor may request information at any time during the data processing, and may check the content of their data, and may request corrections, modifications, changes, or deletions at any time as needed. The visitor may modify or withdraw their consent to data processing at any time.

Data processing generally occurs electronically. The deletion of data must be carried out in accordance with legal requirements simultaneously with the fulfillment of the purpose of data processing.

Data may be transmitted, and different data processing activities may be combined, if the visitor has consented to it, or if the law permits it, and if the conditions for data processing are met for each individual personal data.

4. The legal background, legal basis, purpose, and the processed personal data of the data processing carried out on the website.

4.1. The laws serving as the basis for data processing.

The Data Controller carries out the processing and protection of data in compliance with the following applicable laws:

– Regulation (EU) 2016/679 of the European Parliament and of the Council (April 27, 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (GDPR)

– Act CXII of 2011 on the right to informational self-determination and on freedom of information (Info Act)

– Act CVIII of 2001 on electronic commerce services and certain issues related to information society services (electronic commerce act)

– Act XLVIII of 2008 on the basic conditions and certain restrictions of economic advertising activities (economic advertising act)

4.2. General information about cookies

4.2.1. Visitors to the website must be informed about the use of cookies on the site, and their consent must be requested for this.

4.2.2. A cookie (in English, cookie) is a piece of data that the visited website sends to the visitor's browser (in name-value pair format) for it to store, so that the same website can load its content later. A cookie can have a validity period, which can be until the browser is closed, but it can also be valid indefinitely. In subsequent HTTP(S) requests, the browser sends this data to the server as well. This modifies the data on the user's machine.

4.2.3. The essence of a cookie is that, due to the nature of web services, it is necessary to identify a user (e.g., that they have logged into the site) and to manage them accordingly in the future. The danger lies in the fact that the user may not always be aware of this, and it may be suitable for the website operator or another provider, whose content is embedded in the site, to track the user, thereby creating a profile of them; in this case, the content of the cookie can be considered personal data.

4.3. Types of cookies

Technically essential session cookies: which without it the site simply would not functionally work; these are necessary for user identification (e.g., to manage whether they are logged in, what they added to the cart, etc.). This typically involves storing a session identifier, while the other data is stored on the server. These cookies are deleted when logging out of the browser.

Usage-enhancing cookies: these are the cookies that remember the user's choices, such as how the user wants to view the site. These types of cookies essentially represent the setting data stored in the cookie.

Performance-providing cookies: collect information about the user's behavior on the visited webpage, the time spent, and their clicks. These are typically third-party applications (e.g., Google Analytics). They are suitable for profiling the visitor.

You can find information about Google Analytics cookies here: https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage

Accepting and enabling the use of cookies is not mandatory. You can reset your browser settings to refuse all cookies or to indicate when a system is sending a cookie. Most browsers do automatically accept cookies by default, but these can usually be changed to prevent automatic acceptance, and the browser will offer the option to choose every time.

4.4. You can find information about cookie settings for the most popular browsers at the following links

Google Chrome: https://support.google.com/accounts/answer/61416?hl=en

Mozilla Firefox: https://support.mozilla.org/en/kb/allowing-and-blocking-cookies

Microsoft Edge: https://support.microsoft.com/en-us/microsoft-edge

Safari: https://support.apple.com/en-us/HT201265

Please note that certain website features or services may not function properly without cookies.

4.5. Information about the cookies used on the Company's website and the data generated during the visit

4.5.1. Data processed during the visit: Our company's website may record and process the following data about the visitor and the device used for browsing during the use of the website: the IP address used by the visitor, the type of browser, the characteristics of the operating system of the device used for browsing (set language), the date and time of the visit, the visited (sub)page, feature or service, click. We retain this data for a maximum of 90 days and may primarily use it for investigating security incidents.

4.5.2. Cookies used on the website:

Technically essential session cookies: The purpose of data management is to ensure the proper functioning of the website. These cookies are necessary for visitors to browse the website, to use its functions smoothly and comprehensively, particularly to remember the actions performed by the visitor on the respective pages (e.g., contents of the cart) or to identify the logged-in user during a visit. The duration of data management for these cookies only pertains to the visitor's current visit; upon the end of the session or closing the browser, this type of cookie is automatically deleted from their computer. The legal basis for this data management is Section 13/A. (3) of Act CVIII of 2001 on electronic commerce services.

Usage-enhancing cookies: These remember the user's choices, for example, how the user would like to see the page (e.g., selected language). The legal basis for data management is the visitor's consent. The purpose of data management is to increase the efficiency of the service, enhance the user experience, and make the use of the website more convenient.

Performance cookies: They collect information about users’ behaviour on the website they visit, the time spent there and their clicks. The legal basis for processing is the data subject’s consent. The purpose of processing is website analysis and sending advertising offers.

4.5.3. Links: The pages of the website contain references and jump points to pages maintained by other providers, over which the Company has no influence regarding the practice of personal data management. We would like to draw our visitors' attention to the fact that if they click on such jump points, they will be redirected to other providers' pages. In such cases, – if they feel the need – they should read the statements of the page providers regarding the protection of personal data.

4.6. Data management related to orders and billing

The legal background and basis for data processing: The background of data processing is provided by the GDPR, the Info Act, and the provisions of Act C of 2000 on accounting (Sztv.). The legal basis for data processing regarding the order is the performance of the contract (GDPR Article 6 (1) (b)), and regarding the issuance and retention of invoices, it is the fulfillment of the legal obligation imposed on the Data Controller as stated in the Sztv. (GDPR Article 6 (1) (c)).

The purpose of data processing: The purpose is to issue invoices in accordance with the laws and to fulfill the obligation to retain accounting documents. According to Section 169 (1)-(2) of the Sztv., economic companies must retain accounting documents that directly and indirectly support the bookkeeping.

The scope of processed data: For the order, name, phone number, address, and email address are required, and for the issuance of the invoice, name and address (in the case of a business, company name, registered office, and tax number).

The duration of data processing: The issued invoices must be retained for 8 years from the date of issuance, according to Section 169 (2) of the Sztv.

4.7. Data processing related to goods delivery

The legal background and basis for data processing: The background of data processing is provided by the GDPR and the provisions of the Info Act. The legal basis for data processing is the performance of the contract (GDPR Article 6 (1) (b)).

The purpose of data processing: In the case of goods delivery, the purpose of data processing is to deliver the ordered goods to you, adapting to your needs, using our own delivery capacity or with the assistance of our contractual partner.

The scope of processed data: The provision of name, delivery address, and phone number is required for data processing.

The duration of data processing: The Data Controller processes the data until the delivery of the ordered goods is completed.

4.8. Data processing related to newsletter sending

The legal background and basis of data processing: The background of data processing is provided by the GDPR, the Info Act, and the 2008 XLVIII. Act on the basic conditions and certain limitations of economic advertising activities (Grt.). The legal basis for data processing is your consent in accordance with Article 6 (1) a) of the GDPR and Sections 6 (1)-(2) of the Grt.

The purpose of data processing: The purpose of data processing is to inform you about the latest and best offers and promotions. We inform you that in the newsletter we may include advertisements from not only the Data Controller but also other economic entities; however, we do not transfer or forward your personal data to them.

The scope of processed data: Providing your name and email address is required for data processing.

The duration of data processing: Until you withdraw your consent.

4.9. Data processing related to sending and displaying personalized advertisements

The legal background and basis of data processing: The background of data processing is provided by the GDPR, the Info Act, and the Grt. The legal basis for data processing is your consent in accordance with Article 6 (1) a) of the GDPR and Sections 6 (1)-(2) of the Grt.

The purpose of data processing: The purpose of data processing is to deliver personalized offers that best match your needs and preferences.

The scope of processed data: During data processing, the Data Controller records, using cookies, which products you have previously visited.

The duration of data processing: Until you withdraw your consent.

4.10. Data processing related to contact

The legal background and basis of data processing: The background of data processing is provided by the GDPR and the provisions of the Info Act. The legal basis for data processing is your consent in accordance with Article 6 (1) a) of the GDPR.

The purpose of data processing: The purpose of data processing is to be able to answer your question.

The scope of processed data: It is necessary to provide your name and contact information (email address or phone number) when contacting.

The duration of data processing: We store messages sent during contact for a maximum of one month, but you can request the deletion of the personal data provided during contact at any time.

4.11. Data processing related to the enforcement of warranty claims

The designation of data processing: The Data Controller provides a 1-year warranty for certain products it sells. During this period, the Data Controller stores the data necessary for the enforcement of warranty claims and may use or transfer the data to the extent necessary for the enforcement of the claim.

The legal background and basis of data processing: The background of data processing is provided by the GDPR, the Info Act, and Act V of 2013 on the Civil Code (Ptk.). The legal basis for data processing is the fulfillment of a legal obligation and the fulfillment of a contract (GDPR Article 6 (1) b) and c) points).

The purpose of data processing: Enforcement of warranty claims.

The scope of processed data: During data processing, the Data Controller processes your name, address, the characteristics of the purchased product, and the date of purchase.

The duration of data processing: The data is processed by the Data Controller during the warranty period, for 1 year.

4.12. Data processing related to registration

The legal background and basis of data processing: The background of data processing is provided by the GDPR and the provisions of the Info Act. The legal basis for data processing is your consent in accordance with Article 6 (1) a) of the GDPR, as well as the performance of the contract (Article 6 (1) b) of the GDPR).

The purpose of data processing: The purpose of data processing is to identify the user and to maintain contact during the use of the service.

The scope of processed data: During registration, it is necessary to provide name, email address, password, in the case of a business, company name and tax number, as well as whether or not to request the newsletter service.

The duration of data processing: The data provided during registration is stored for five years, but you have the option to request the deletion of the provided personal data at any time.

4.13. Additional data processing

If the Data Controller wishes to carry out further data processing, it will provide prior information about the essential circumstances of the data processing (the legal background and basis of data processing, the purpose of data processing, the scope of processed data, the duration of data processing).

We inform you that the Data Controller must comply with written data requests from authorities based on legal authorization. The Data Controller keeps a record of data transfers in accordance with Section 15 (2)-(3) of the Info Act (which authority, what personal data, on what legal basis, when was transferred by the Data Controller), and will provide information about its content upon request, unless the law excludes such information.

4.14. Other provisions

The user is required to provide accurate and complete information in response to the questions on the registration form during registration, as well as to appropriately update the registration data in case of changes.

In the case of falsehood, incompleteness, or inaccuracy of the data provided by the user, Impex 2000 HoReCa Center Kft. has the right to partially or fully suspend or terminate the user's access.

Impex 2000 HoReCa Center Kft. reserves the right to immediately terminate the user's right to use and access the website at any time, at its own discretion, if the user violates the terms of the data processing information or any relevant legal provisions.

5. On the engagement of data processors and their activities related to data processing

Data processor: the natural or legal person, public authority, agency, or any other body that processes personal data on behalf of the data controller (GDPR Article 4, point 8). The engagement of the data processor does not require the prior consent of the data subject, but the data subject must be informed. Accordingly, we provide the following information:

5.1. Data processing related to accounting

The name of the data processor: Adónavigátor Tanácsadó Kft.

The mailing address of the data processor: 6000 Kecskemét, Mezei utca 9. fsz. 1.

The email address of the data processor: kriszti [at] adonavigator [dot] hu

The phone number of the data processor: +36 20 339 4268

The Data Processor collaborates with the Data Controller based on a written contract in the accounting of accounting documents. In this process, the Data Processor handles the name and address of the data subject to the extent necessary for the accounting records, for the duration specified in Section 169 (2) of the Accounting Act, and subsequently deletes it without delay.

5.2. Data processing activities related to the delivery of goods

The name of the data processor: GLS General Logistics Systems Hungary Kft.

The mailing address of the data processor: 2351 Alsónémedi, GLS Európa u. 2.

The email address of the data processor: info [at] gls-hungary [dot] hu

The phone number of the data processor: +36 29 88 66 70

The name of the data processor: Magyar Posta Zrt. (MPL courier service)

The registered office of the data processor: 1138 Budapest, Dunavirág utca 2-6.

The website of the data processor: https://www.posta.hu

The Data Processors collaborate with the Data Controller based on a written contract in the delivery of the ordered goods. In this process, the Data Processor may handle the name, address, and phone number of the customer until the delivery of the ordered goods, and subsequently deletes it without delay. In the case of delivery performed with its own delivery fleet, no data transfer to a third party will take place.

5.3. Data processing related to the operation of the online store and the storage of personal data

The name of the data processor: Odoo S.A.

The registered office of the data processor: Chaussée de Namur 40, 1367 Grand-Rosière, Belgium

The website of the data processor: https://www.odoo.com

The Data Processor provides the operation of the web store and the enterprise management system based on the contract with the Data Controller, as well as the storage of personal data on servers located in the European Union. The Data Processor is not authorized to access personal data. The newsletters are also sent through this system.

5.4. Data processing aimed at the storage of personal data

The name of the data processor: BITheory Kft.

The address of the data processor's headquarters: 1192 Budapest, Zalaegerszeg u. 33. I./5.

The phone number of the data processor: +36 20 529 8282

The contact details of the data processor: support [at] bitheory [dot] hu

The Data Processor performs the storage of personal data on its servers based on a written contract with the Data Controller. It is not authorized to access personal data.

6. Data security measures

The Data Controller declares that it has taken appropriate security measures to protect personal data against unauthorized access, alteration, transmission, disclosure, deletion or destruction, as well as against accidental destruction and damage, and against becoming inaccessible due to changes in the applied technology.

7. Your rights during data processing – rights of the data subject

7.1. You are entitled during the duration of data processing

1. Transparent information, communication, and facilitation of the exercise of rights of the data subject

2. Right to prior information – if personal data is collected from the data subject

3. Information to the data subject and the information to be provided if the personal data was not obtained from them by the data controller

4. The right of the data subject to access

5. The right to rectification

6. The right to erasure ("the right to be forgotten")

7. The right to restriction of processing

8. The obligation to notify related to the rectification or erasure of personal data, or the restriction of processing

9. The right to data portability

10. The right to object

11. Automated decision-making in individual cases, including profiling

12. Restrictions

13. Information to the data subject about the data breach

14. The right to lodge a complaint with a supervisory authority

15. The right to an effective judicial remedy against a supervisory authority

16. The right to an effective judicial remedy against the data controller or the data processor

1. Transparent information, communication, and facilitating the exercise of rights by the data subject

1.1. The data controller must provide the data subject with all information regarding the processing of personal data in a concise, transparent, understandable, and easily accessible form, clearly and in an easily comprehensible manner, especially in the case of any information addressed to children. The information must be provided in writing or by other means – including, where appropriate, electronically. Upon request of the data subject, oral information may also be provided, provided that the data subject's identity has been verified by other means.

1.2. The data controller must facilitate the exercise of the data subject's rights.

1.3. The data controller shall inform the data subject of the measures taken in response to a request for the exercise of their rights without undue delay, but in any case within one month of the receipt of the request. This deadline may be extended by a further two months under the conditions set out in the GDPR, of which the data subject must be informed.

1.4. If the data controller does not take action in response to the data subject's request, they shall inform the data subject without delay, but no later than one month from the receipt of the request, of the reasons for the lack of action, as well as that the data subject has the right to lodge a complaint with a supervisory authority and to exercise their right to judicial remedy.

1.5. The data controller provides the information and the notification regarding the data subject's rights and actions free of charge; however, a fee may be charged in the cases specified in the GDPR. The detailed rules can be found in Article 12 of the GDPR.

2. Right to prior information – if the personal data is collected from the data subject

2.1. The data subject is entitled to receive information about the facts and information related to data processing before the processing begins. In this context, the data subject must be informed: a) about the identity and contact details of the data controller and its representative, b) about the contact details of the data protection officer (if any), c) about the purpose of the intended processing of personal data, as well as the legal basis for the processing, d) in the case of processing based on legitimate interests, about the legitimate interests of the data controller or a third party, e) about the recipients of the personal data – with whom the personal data is shared – and the categories of recipients, if any, f) if applicable, about the fact that the data controller intends to transfer personal data to a third country or an international organization.

2.2. In order to ensure fair and transparent data processing, the data controller must inform the data subject of the following additional information: a) the duration of storage of personal data, or if this is not possible, the criteria for determining this duration; b) the data subject's right to request access to their personal data, its rectification, deletion, or restriction of processing, and to object to the processing of such personal data, as well as their right to data portability; c) in the case of data processing based on the data subject's consent, that the right to withdraw consent at any time does not affect the lawfulness of processing based on consent before its withdrawal; d) the right to lodge a complaint with a supervisory authority; e) whether the provision of personal data is based on a legal obligation or a contractual requirement, or if it is a prerequisite for entering into a contract, as well as whether the data subject is obliged to provide the personal data and what possible consequences may arise from the failure to provide such data; f) the fact of automated decision-making, including profiling, as well as at least in these cases, information about the logic involved and understandable information regarding the significance of such processing and the expected consequences for the data subject.

2.3. If the data controller intends to carry out further processing of personal data for purposes other than those for which the data was collected, they must inform the data subject of this different purpose and all relevant supplementary information before the further processing. The detailed rules regarding the right to prior information are contained in Article 13 of the GDPR.

3. Information to the data subject if the personal data was not obtained from them by the data controller.

3.1. If the data controller did not obtain the personal data from the data subject, they must inform the data subject no later than one month from the acquisition of the personal data; if the personal data is used for the purpose of contacting the data subject, at least at the time of the first contact with the data subject; or if the data is expected to be disclosed to other recipients, no later than at the time of the first disclosure of the personal data, they must inform them of the facts and information mentioned in the previous point 2, as well as the categories of the data subject's personal data, and the source of the personal data, and if applicable, whether the data originates from publicly accessible sources.

3.2. The further rules are governed by the provisions mentioned in the previous point 2. The detailed rules for this information are contained in Article 14 of the GDPR.

4. The data subject's right of access

4.1. The data subject has the right to receive feedback from the data controller regarding whether their personal data is being processed, and if such processing is ongoing, they have the right to access their personal data and related information (Article 15 of the GDPR).

4.2. If personal data is transferred to a third country or to an international organization, the data subject has the right to be informed about the appropriate safeguards in accordance with Article 46 of the GDPR.

4.3. The data controller must provide a copy of the personal data subject to processing to the data subject. For any additional copies requested by the data subject, the data controller may charge a reasonable fee based on administrative costs. Detailed rules regarding the data subject's right of access are contained in Article 15 of the GDPR.

5. The right to rectification

5.1. The data subject has the right to request the Data Controller to rectify inaccurate personal data concerning them without undue delay.

5.2. Taking into account the purpose of the processing, the data subject has the right to request the completion of incomplete personal data – including by means of a supplementary statement. These rules are contained in Article 16 of the GDPR.

6. The right to erasure ("the right to be forgotten")

6.1. The data subject has the right to request the data controller to delete personal data concerning them without undue delay, and the data controller is obliged to delete the personal data concerning the data subject without undue delay if a) the personal data is no longer necessary for the purposes for which it was collected or otherwise processed; b) the data subject withdraws the consent on which the processing is based, and there is no other legal basis for the processing; c) the data subject objects to the processing, and there are no overriding legitimate grounds for the processing; d) the personal data has been processed unlawfully; e) the personal data must be deleted to comply with a legal obligation to which the data controller is subject under Union or Member State law; f) the collection of personal data was related to the offering of information society services directly to children.

6.2. The right to deletion cannot be enforced if the processing is necessary a) for exercising the right to freedom of expression and information; b) for compliance with a legal obligation to which the data controller is subject under Union or Member State law, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the data controller; c) for reasons of public interest in the area of public health; d) for archiving purposes in the public interest, scientific and historical research purposes, or statistical purposes, insofar as the right to deletion is likely to make it impossible or seriously jeopardize the achievement of those purposes; or e) for the establishment, exercise, or defense of legal claims. Detailed rules regarding the right to deletion are provided in Article 17 of the GDPR.

7. The right to restriction of processing

7.1. In the case of restriction of processing, such personal data may be processed only with the consent of the data subject, or for the establishment, exercise or defense of legal claims, or for the protection of the rights of another natural or legal person, or for important public interest of the Union or a Member State, except for storage.

7.2. The data subject has the right to request the Data Controller to restrict processing if any of the following applies: a) the data subject contests the accuracy of the personal data – in this case, the restriction applies for the period that allows the Data Controller to verify the accuracy of the personal data; b) the processing is unlawful, and the data subject opposes the deletion of the data and requests instead the restriction of their use; c) the Data Controller no longer needs the personal data for processing purposes, but the data subject requires them for the establishment, exercise or defense of legal claims; or d) the data subject has objected to the processing – in this case, the restriction applies for the period until it is determined whether the legitimate grounds of the data controller override those of the data subject.

7.3. The data subject must be informed in advance about the lifting of the restriction of processing. The relevant rules are contained in Article 18 of the GDPR.

8. Notification obligation related to rectification, deletion, and restriction

The data controller informs all recipients of any corrections, deletions or restrictions on processing of personal data with whom the personal data has been shared, unless this proves impossible or requires disproportionate effort. At the request of the data subject, the data controller informs them of these recipients. These rules can be found under Article 19 of the GDPR.

9. The right to data portability

9.1. Under the conditions set out in the GDPR, the data subject has the right to receive the personal data concerning them, which they have provided to a data controller, in a structured, commonly used, machine-readable format, and they have the right to transmit those data to another data controller without hindrance from the data controller to whom the personal data was provided, if a) the processing is based on consent or a contract; and b) the processing is carried out by automated means.

9.2. The data subject may also request the direct transfer of personal data between data controllers.

9.3. The exercise of the right to data portability shall not adversely affect the rights and freedoms of others. Detailed rules are provided in Article 20 of the GDPR.

10. The right to object

10.1. The data subject has the right to object at any time to the processing of their personal data based on public interest, the performance of a task carried out in the public interest (GDPR Article 6(1)(e)) or legitimate interests (GDPR Article 6(1)(f)), including profiling based on those provisions. In this case, the data controller may not continue to process the personal data unless the data controller demonstrates that the processing is necessary for compelling legitimate grounds which override the interests, rights, and freedoms of the data subject, or is related to the establishment, exercise, or defense of legal claims.

10.2. If the processing of personal data is for the purpose of direct marketing, the data subject has the right to object at any time to the processing of their personal data for this purpose, including profiling, insofar as it is related to direct marketing. If the data subject objects to the processing of personal data for direct marketing purposes, the personal data may no longer be processed for this purpose.

10.3. These rights must be explicitly brought to the attention of the data subject at the latest during the first contact, and the information regarding these rights must be presented clearly and separately from all other information.

10.4. The data subject may also exercise the right to object using automated tools based on technical specifications.

10.5. If the processing of personal data is carried out for scientific and historical research purposes or for statistical purposes, the data subject has the right to object to the processing of personal data concerning them for reasons related to their own situation, unless the processing is necessary for the performance of a task carried out in the public interest. The relevant rules are contained in Article 21 of the GDPR.

11. Automated decision-making in individual cases, including profiling

11.1. The data subject has the right not to be subject to the scope of a decision based solely on automated data processing – including profiling – which would have legal effects on them or similarly significantly affect them.

11.2. This right shall not apply in cases where the decision: a) is necessary for the conclusion or performance of a contract between the data subject and the data controller; b) is based on Union or Member State law applicable to the data controller, which also establishes appropriate measures to protect the rights and freedoms of the data subject and their legitimate interests; or c) is based on the explicit consent of the data subject.

11.3. In the cases mentioned in points a) and c) above, the data controller is obliged to take appropriate measures to protect the rights, freedoms, and legitimate interests of the data subject, including at least the right of the data subject to request human intervention from the data controller, to express their point of view, and to contest the decision. Further rules are contained in Article 22 of the GDPR.

12. Restrictions

Union or member state law applicable to the data controller or data processor may limit the scope of rights and obligations (GDPR Articles 12-22, Article 34, Article 5) through legislative measures, provided that the limitation respects the essential content of fundamental rights and freedoms. The conditions for this limitation are set out in Article 23 of the GDPR.

13. Informing the data subject about the data breach

13.1. If the data breach is likely to result in a high risk to the rights and freedoms of natural persons, the data controller must inform the data subject of the data breach without undue delay. This information must clearly and understandably describe the nature of the data breach and at least include the following: a) the name and contact details of the data protection officer or other contact point for further information; b) the likely consequences of the data breach; c) the measures taken or planned by the data controller to address the data breach, including, where appropriate, measures to mitigate any adverse consequences of the data breach.

13.2. The data subject does not need to be informed if any of the following conditions are met: a) the data controller has implemented appropriate technical and organizational protective measures, and these measures have been applied to the data affected by the data protection incident, particularly those measures – such as the application of encryption – that make the data unintelligible to unauthorized persons who have access to personal data; b) the data controller has taken further measures following the data protection incident that ensure that the high risk to the rights and freedoms of the data subject is no longer likely to materialize; c) informing the data subject would require disproportionate effort. In such cases, the data subjects should be informed through publicly available information or similar measures that ensure equally effective communication to the data subjects. Further rules are contained in Article 34 of the GDPR.

14. The right to lodge a complaint with a supervisory authority

The data subject has the right to lodge a complaint with a supervisory authority – particularly in the member state of their habitual residence, workplace, or the place of the alleged infringement – if the data subject believes that the processing of their personal data infringes the GDPR. The supervisory authority to which the complaint is submitted is obliged to inform the complainant about the procedural developments regarding the complaint and its outcome, including whether the complainant is entitled to a judicial remedy. These rules are contained in Article 77 of the GDPR.

15. The right to an effective judicial remedy against a supervisory authority

15.1. Without prejudice to other administrative or non-judicial remedies, every natural and legal person is entitled to an effective judicial remedy against a legally binding decision of the supervisory authority concerning them.

15.2. Without prejudice to other administrative or non-judicial remedies, every affected person is entitled to an effective judicial remedy if the competent supervisory authority does not address the complaint, or does not inform the affected person of the procedural developments or the outcome of the submitted complaint within three months.

15.3. Proceedings against the supervisory authority must be initiated before the court of the member state where the supervisory authority is located.

15.4. If proceedings are initiated against a decision of the supervisory authority for which the Board has previously issued an opinion or made a decision within the framework of the consistency mechanism, the supervisory authority is obliged to send this opinion or decision to the court. These rules are contained in Article 78 of the GDPR.

16. Right to an effective judicial remedy against a controller or processor

16.1. Without prejudice to available administrative or non-judicial remedies – including the right to lodge a complaint with the supervisory authority – every affected person is entitled to an effective judicial remedy if they consider that their rights under the GDPR have been infringed as a result of the processing of their personal data not in compliance with the GDPR.

16.2. Proceedings against the data controller or the data processor must be initiated before the court of the member state where the data controller or the data processor has its place of activity. Such proceedings may also be initiated before the court of the member state where the data subject has their habitual residence, unless the data controller or the data processor is a public authority acting in the exercise of public authority of a member state. These rules are contained in Article 79 of the GDPR.

8. Remedies

If you believe that the Data Controller has violated any legal provision regarding data processing, or has not fulfilled any of your requests, you may initiate an investigation procedure with the National Data Protection and Freedom of Information Authority to terminate the presumed unlawful data processing.

You can file a complaint with the National Data Protection and Freedom of Information Authority:

Name: National Data Protection and Freedom of Information Authority

Headquarters: 1055 Budapest, Falk Miksa Street 9-11.

Mailing address: 1363 Budapest, P.O. Box 9.

Phone: +36 1 391 1400

Email: ugyfelszolgalat [at] naih [dot] hu

Website: https://www.naih.hu

9. Modification of the data processing information

The Data Controller reserves the right to modify this data processing information. By using the website after the modification comes into effect, the user accepts the modified data processing information. The Data Controller ensures that in case of modification, the previous text version is also available on the website.

Effective: from August 1, 2026

Family-owned since 1991.
Your hospitality supplier.

Contact & request a quoteOur servicesAbout us
+36 1 799 1191 iroda@horecacenter.hu

Products

Tableware & servingTakeaway & packagingGlassware & bar suppliesCutleryKitchen & preparationPastry & bakeryAll product categories →

Customer information

My account & ordersProfessional consultationDelivery, collection & paymentTerms and ConditionsPrivacy NoticeRight of withdrawalLegal notice

Showroom & goods collection

1097 Budapest, Ecseri út 14–16.
Building F, ground floor
Entrance: from Gyáli út 27.

Showroom: Mon–Fri 10:00–16:00
Goods collection: Mon–Fri 8:00–16:00

For collection in person, please report first to the ground floor of Building F. Our colleagues will direct you to the warehouse collection point in Building G.

Directions & contact →

Cookie Policy

© Impex 2000 HoReCa Center Kft.
English (US) | Magyar
Powered by Odoo - The #1 Open Source eCommerce

We use cookies to provide you a better user experience on this website. Cookie Policy

Only essentials I agree