By using our website, you accept the following terms and conditions, regardless of whether you have read them. Lack of knowledge of these terms of use does not exempt anyone from responsibility and may not serve as a basis for any claim.
The pharmapromo.hu website in its entirety is the intellectual property of the employees of Pharmapromo Kft. and is protected by copyright. Information and data available on the website may only be used with accurate attribution of the source and in their original context. Only Pharmapromo Kft., the operator of the portal, is entitled to use the pharmapromo.hu domain name.
Definitions:
- “personal data”: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
- “processing”: any operation or set of operations performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
- “restriction of processing”: the marking of stored personal data with the aim of limiting their processing in the future;
- “controller”: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
- “processor”: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
- “restriction of processing”: the marking of stored personal data with the aim of limiting their processing in the future;
- “profiling”: any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements;
- “pseudonymisation”: the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data are not attributed to an identified or identifiable natural person;
- “filing system”: any structured set of personal data which is accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis;
- “recipient”: a natural or legal person, public authority, agency or another body to which personal data are disclosed, whether or not a third party. Public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of such data by those public authorities shall comply with the applicable data protection rules according to the purposes of the processing;
- “third party”: a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data;
- “consent of the data subject”: any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
- “personal data breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
Name of the controller: Pharmapromo Tanácsadó és Szolgáltató Kft. (hereinafter: the Service Provider)
Address of the controller: 4026 Debrecen, Csemete u. 20., Hungary
Contact: pharmapromo@pharmapromo.hu
Name of the processing activity: visitor database of the pharmapromo.hu website; processing of the data of persons sending messages via the Contact page
Legal basis for processing: Article 6 of Regulation (EU) 2016/679 of the European Parliament and of the Council (27 April 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, repealing Directive 95/46/EC (General Data Protection Regulation, GDPR), and the data subject’s voluntary consent pursuant to Section 5 of Act CXII of 2011 on Informational Self-Determination and Freedom of Information. For users under the age of 16, the validity of consent to data processing requires the consent or subsequent approval of their legal representative.
Scope of data processed
Data that the user may provide on the Contact page: name, e-mail address, subject and message content. The system forwards the data provided on the Contact form to pharmapromo@pharmapromo.hu. The data are not stored in a database.
Data recorded or capable of being recorded in the case of all visitors:
- When the website is used, the IP address of the user’s computer is recorded. These data are logged automatically by the system; however, the Service Provider does not link the data contained in the log file with other personal data, and therefore they are not suitable for identifying the user for the Service Provider.
- During use of the website, the portal retrieves the time and location of the user’s visit and the technical parameters of browsing (browser, screen resolution and type of operating system). The system monitors these data automatically but does not log them or link them to other personal data. The data are used only for the duration of the visit in order to ensure optimal display.
- In order to provide customised services, a small data package known as a cookie is placed on the user’s computer and read during subsequent visits. Cookies make the website easier to use, provide a high-quality user experience, remember visitors’ individual settings and provide information about the visitor and their device. If the browser returns a previously stored cookie, the service provider managing the cookie may link the user’s current visit with previous visits, but only in relation to its own content. Visitors may disable cookies in their browser or delete cookies stored previously.
- Session cookies: The purpose of these cookies is to enable visitors to browse the PharmaPromo website fully and smoothly, use its functions and access the services available there. These cookies remain valid until the end of the session (browsing); when the browser is closed, they are automatically deleted from the computer or other device used for browsing.
- Data stored by third parties: In order to provide and improve the services of the website, the Service Provider also uses third-party services on its website. The operators of pharmapromo.hu do not have direct access to personal data collected through cookies in connection with the services below; the privacy policies of the respective service providers govern the processing of such data.
- By using Google Analytics for statistical purposes, the Service Provider collects information about how visitors use the website. The data collected are anonymous and are available in aggregated form for statistical purposes; the Service Provider cannot link them to personal data.
Any user may disable the acceptance of cookies in their browser settings and may delete previously received files at any time.
Purpose of data processing:
To respond to questions and enquiries submitted on the Contact page. Personal data are transferred to third parties only with the user’s prior and informed consent.
In the case of data recorded in log files while browsing the website, data storage serves exclusively technical and statistical purposes. The anonymous visitor identifier, as a character string (cookie), cannot in itself identify the customer, i.e. the visitor; it can only recognise the visitor’s device. Users may configure their browser so that it does not allow a unique identifier to be placed on their device, and they may also delete previously stored cookies. In this case, users can still use a substantial part of the service, although in certain cases (for example, customised solutions) some functions may not be available to their fullest extent.
Duration of data processing: The Service Provider is entitled to process the data provided by the user via the Contact form until the user submits a request for deletion. At the user’s voluntary request, the Service Provider will delete the data within 5 working days of receiving the request. If the user uses personal data unlawfully or deceptively, or commits a criminal offence, the Service Provider may, in accordance with the Terms of Use, delete all of the user’s personal data immediately upon becoming aware of the matter, simultaneously with deleting the registration.
Deletion of personal data: A request for deletion of the user’s data must be sent by e-mail to pharmapromo@pharmapromo.hu. The Service Provider will delete the data within 5 working days of receiving the request. Once deleted, the displayed data cannot be restored.
Data security measures: During processing, the data provided by the user on the Contact page may be accessed only by developers employed by the Service Provider who have individual, restricted (“admin”) access.
Controller and processors:
Pharmapromo Kft. (programming, controller); 4026 Debrecen, Csemete u. 20., Hungary
NOOP IT Services Kft. (system administration services); 4060 Balmazújváros, Oncsa u. 37., Hungary
Hetzner Online GmbH (server hosting); Industriestr. 25, 91710 Gunzenhausen, Germany
Technical information:
The Service Provider selects and operates the IT tools used for the operation of the portal and the processing of personal data in such a way that the processed data:
– are accessible to authorised persons (availability);
– have assured authenticity and authentication (authenticity of processing);
– have verifiable integrity (data integrity);
– are protected against unauthorised access (confidentiality of data).
The Service Provider protects the data by appropriate measures against unauthorised access, alteration, transmission, disclosure, deletion or destruction, as well as against accidental destruction.
The Service Provider ensures the security of processing through technical, organisational and administrative measures that provide a level of protection appropriate to the risks associated with the processing.
During processing, the Service Provider preserves:
- confidentiality: protecting information so that it can be accessed only by persons authorised to do so;
- integrity: protecting the accuracy and completeness of the information and the method of processing;
- availability: ensuring that authorised users can access the required information when needed and that the related tools are available.
Data transfer: The Service Provider informs the user and requests the user’s consent if the user’s data are transferred to a third party. The Service Provider keeps records of data transfers.
Rights of data subjects and means of enforcement
The data subject may request information about the processing of their personal data and may request the rectification of personal data or, except in cases of mandatory processing, their erasure or withdrawal. The data subject may also exercise the right to data portability and the right to object in the manner indicated when the data were collected or by using the controller’s contact details above.
- Right to information
The Service Provider shall take appropriate measures to provide the data subject with all information referred to in Articles 13 and 14 of the GDPR and all communications under Articles 15–22 and 34 relating to the processing of personal data in a concise, transparent, intelligible and easily accessible form, using clear and plain language.
- Right of access by the data subject
The data subject shall have the right to obtain from the controller confirmation as to whether or not personal data concerning them are being processed and, where that is the case, access to the personal data and the following information: the purposes of the processing; the categories of personal data concerned; the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations; the envisaged period for which the personal data will be stored; the right to request rectification or erasure of personal data or restriction of processing and to object to processing; the right to lodge a complaint with a supervisory authority; information as to the source of the data; the existence of automated decision-making, including profiling, and meaningful information about the logic involved, as well as the significance and envisaged consequences of such processing for the data subject. The controller shall provide the information no later than one (1) month after receipt of the request.
- Right to rectification
The data subject may request the rectification of inaccurate personal data concerning them processed by the Service Provider and the completion of incomplete data.
- Right to erasure (“right to be forgotten”)
The data subject shall have the right to obtain from the Service Provider the erasure of personal data concerning them without undue delay where one of the following grounds applies:
– the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
– the data subject withdraws consent on which the processing is based and there is no other legal ground for the processing;
– the data subject objects to the processing and there are no overriding legitimate grounds for the processing;
– the personal data have been unlawfully processed;
– the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the controller is subject;
– the personal data have been collected in relation to the offer of information society services.
Erasure may not be requested where processing is necessary:
- for exercising the right of freedom of expression and information;
- for compliance with a legal obligation which requires processing under Union or Member State law to which the controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- for reasons of public interest in the area of public health, or for archiving purposes, scientific or historical research purposes or statistical purposes in the public interest; or
- for the establishment, exercise or defence of legal claims.
- Right to restriction of processing
At the request of the data subject, the Service Provider shall restrict processing where one of the following conditions applies:
– the accuracy of the personal data is contested by the data subject, for a period enabling the accuracy of the personal data to be verified;
– the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;
– the controller no longer needs the personal data for the purposes of processing, but they are required by the data subject for the establishment, exercise or defence of legal claims; or
– the data subject has objected to processing, pending verification whether the legitimate grounds of the controller override those of the data subject.
Where processing has been restricted, such personal data shall, with the exception of storage, only be processed with the data subject’s consent or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or of a Member State.
- Right to data portability
The data subject shall have the right to receive the personal data concerning them, which they have provided to the controller, in a structured, commonly used and machine-readable format and to transmit those data to another controller.
- Right to object
The data subject shall have the right to object, on grounds relating to their particular situation, at any time to processing of personal data concerning them which is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, or for the purposes of the legitimate interests pursued by the controller or by a third party, including profiling based on those provisions. In the event of an objection, the controller shall no longer process the personal data unless the controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of legal claims.
- Automated individual decision-making, including profiling
The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
- Right to withdraw consent
The data subject shall have the right to withdraw their consent at any time without giving reasons.
- If the User considers that their rights have been infringed in the course of processing, the following remedies are available:
- the User may contact the Controller directly by post (PharmaPromo Kft., 4026 Debrecen, Csemete u. 20., Hungary) or by e-mail at: pharmapromo@pharmapromo.hu
- the User may bring proceedings before a court in the event of unlawful processing of their data or a breach of data security requirements. In accordance with applicable law, the User may be entitled to compensation and damages for non-material harm. Information on the jurisdiction and contact details of the courts is available at birosagok.hu
- the data subject may lodge a complaint with the supervisory authority, the Hungarian National Authority for Data Protection and Freedom of Information (NAIH). Contact details of NAIH: Registered office: H-1125 Budapest, Falk Miksa utca 9-11, Hungary. Telephone: +36 1 391 1400. E-mail: ugyfelszolgalat@naih.hu. Website: naih.hu
Amendment of the Privacy Policy: The Service Provider reserves the right to amend this Privacy Policy unilaterally, subject to prior notice to users. By using the service after an amendment enters into force, you accept the amended Privacy Policy.
(Last amended: 12 August 2026)