Privacy Policy
1. General guidelines
- We collect and process personal data only in accordance with applicable laws.
- We transfer personal data to third parties only with consent.
- We do not sell the personal data we process to third parties under any circumstances.
- We store data as securely as possible.
- We send newsletters only to those who have given their prior and explicit consent.
- Data subjects may request access to, modification or deletion of the data stored about them at any time.
2. Details and contact information of our company (data controller, Service Provider)
Name of the data controller: Magyar Labdarúgó Egylet KFT
Contact address of the data controller: 7900 Szigetvár, Széchenyi utca 99/2
Email: info@crusaders.shop
Website: crusaders.shop
Tax number: HU25919527
The service provider reserves the right to amend this Privacy Notice, about which the data subjects will be informed in an appropriate manner. Information related to data processing is published on the LINK GOES HERE website.
3. Definitions according to the GDPR (Regulation)
3.1. data subject/User:any natural person who is identified or can be identified, directly or indirectly, on the basis of specific personal data;
3.2. personal data: any data that can be associated with the data subject, in particular the data subject’s name, identification mark and one or more factors specific to their physical, physiological, mental, economic, cultural or social identity, as well as any conclusion drawn from such data relating to the data subject;
3.3. consent: the voluntary and explicit expression of the data subject’s wishes, based on appropriate information, by which the data subject gives their unambiguous consent to the processing of personal data relating to them, either in full or for certain operations;
3.4. data controller:the natural or legal person, or organisation without legal personality, who or which, alone or jointly with others, determines the purpose of data processing, makes and implements decisions concerning data processing, including the means used, or has them implemented by a data processor;
3.5. data processing: any operation or set of operations performed on data, regardless of the procedure applied, including in particular collection, recording, organisation, storage, alteration, use, retrieval, transmission, disclosure, alignment or combination, blocking, deletion and destruction, as well as prevention of further use of the data, taking photographs, audio or video recordings, and recording physical characteristics suitable for identifying a person, such as fingerprints, palm prints, DNA samples or iris images;
3.6. data transfer: making data accessible to a specified third party;
3.7. disclosure: making data accessible to anyone;
3.8. data deletion:making data unrecognisable in such a way that its restoration is no longer possible;
3.9. data processing activity: the performance of technical tasks related to data processing operations, regardless of the method and means used to perform the operations and the place of application, provided that the technical task is performed on the data;
3.10. data processor: the natural or legal person, or organisation without legal personality, who or which processes data on the basis of a contract, including a contract concluded pursuant to a statutory provision;
3.11. data protection incident: unlawful processing or handling of personal data, including in particular unauthorised access, alteration, transfer, disclosure, deletion or destruction, as well as accidental destruction and damage.
4. Scope of processed data, purpose and duration of data processing, and data processor
Type of processed data: Username
Purpose of data processing: Identification, registration.
Duration of data processing: Until withdrawal of consent.
Legal basis of data processing: Consent of the data subject.
Type of processed data: Password
Purpose of data processing: Secure login to the user account.
Duration of data processing: Until withdrawal of consent.
Legal basis of data processing: Consent of the data subject.
Type of processed data: Name
Purpose of data processing: Contact, coordination of arising questions.
Duration of data processing: Until withdrawal of consent.
Legal basis of data processing: Consent of the data subject.
Type of processed data: Email address
Purpose of data processing: Contact, coordination of arising questions.
Duration of data processing: Until withdrawal of consent.
Legal basis of data processing: Consent of the data subject.
Type of processed data: Phone number
Purpose of data processing: Contact, coordination of arising questions.
Duration of data processing: Until withdrawal of consent.
Legal basis of data processing: Consent of the data subject.
Type of processed data: Billing name and address
Purpose of data processing: Issuing a proper invoice, creating and then fulfilling the contract.
Duration of data processing: We process the data for 5 years according to the limitation period under civil law.
Legal basis of data processing: Issuing an invoice is mandatory pursuant to Section 159(1) of Act CXXVII of 2007 on Value Added Tax and pursuant to Section 169(2) of Act C of 2000 on Accounting.
Type of processed data: Shipping name and address
Purpose of data processing: Enabling home delivery.
Duration of data processing: Until delivery of the ordered goods.
Legal basis of data processing: Performance of a contract. Data processing under Article 6(1)(b) of the Regulation.
Type of processed data: Date of purchase/registration
Purpose of data processing: Proof of consent.
Duration of data processing: Until the limitation period following termination of data processing.
Legal basis of data processing: This obligation is prescribed by Article 7(1) of the Regulation. Data processing under Article 6(1)(c) of the Regulation.
Type of processed data: IP address at the time of purchase/registration
Purpose of data processing: Proof of consent.
Duration of data processing: Until the limitation period following termination of data processing.
Legal basis of data processing: This obligation is prescribed by Article 7(1) of the Regulation. Data processing under Article 6(1)(c) of the Regulation.
Scope of data subjects: all data subjects registered on or purchasing through the webshop website.
Personal data is shared only and exclusively with the third party indicated in the “processor of the given personal data” column, in order to fulfil contractual obligations.
Details and tasks of data processors used during data processing
Hosting provider
Name: InfoNetfort Kft.
Address: 7900 Szigetvár, Szent István ltp 17. IV/25.
Phone: +36-30/530-2953
Email: kapcsolat@netfort.hu
Website: www.netfort.hu
Tax number: 26648082-2-02
Company registration number: 02 09 084205
Accounting tasks
Courier service
Direct marketing, newsletter
Name:
Address:
4.1 Contact form:
Type of processed data: Name
Purpose of data processing: Contact.
Duration of data processing: For 90 days after the data subject’s last contact.
Legal basis of data processing: Consent of the data subject during contact.
Type of processed data: Email address
Purpose of data processing: Contact.
Duration of data processing: For 90 days after the data subject’s last contact.
Legal basis of data processing: Consent of the data subject during contact.
Type of processed data: Phone number
Purpose of data processing: Contact.
Duration of data processing: For 90 days after the data subject’s last contact.
Legal basis of data processing: Consent of the data subject during contact.
Type of processed data: Other personal data provided by the data subject during contact.
Duration of data processing: For 90 days after the data subject’s last contact.
Legal basis of data processing: Consent of the data subject during contact.
Scope of data subjects: persons contacting us by phone, email or through the contact form.
Personal data is not shared with third parties.
5. Newsletter, direct marketing activity
We send newsletters only to Users who have given their prior and explicit consent. Consent is given using the “Newsletter subscription” form.
Type of processed data: Name
Purpose of data processing: Sending newsletters.
Duration of data processing: Until withdrawal, meaning until unsubscription.
Legal basis of data processing: Consent of the data subject.
Type of processed data: Email address
Purpose of data processing: Sending newsletters.
Duration of data processing: Until withdrawal, meaning until unsubscription.
Legal basis of data processing: Consent of the data subject.
Type of processed data: Time of consent and IP address of the data subject.
Purpose of data processing: Verifiability of consent.
Duration of data processing: Until withdrawal, meaning until unsubscription.
Legal basis of data processing: This obligation is prescribed by Article 7(1) of the Regulation.
Scope of data subjects: all data subjects subscribed to the newsletter.
The operator of the newsletter sending system and the data processor of the data:
Name: Magyar Labdarúgó Egylet KFT
Address: 7900 Szigetvár, Széchenyi u. 99/2
5.1 Procedure for withdrawing consent, meaning unsubscribing
The data subject may unsubscribe from the newsletter at any time, free of charge. Unsubscription may be done using the link sent in the newsletters or by sending an email to the EMAIL ADDRESS GOES HERE email address.
6. Cookie management
6.1 What is a cookie?
During visits to the website, the Data Controller uses so-called cookies. A cookie is an information package consisting of letters and numbers, which our website sends to the data subject’s browser in order to save certain settings, make the use of our website easier and help us collect some relevant statistical information about our visitors. Cookies do not contain personal information and are not suitable for identifying individual users. Cookies often contain a unique identifier, a secret, randomly generated number sequence, which is stored on the data subject’s device.
Some cookies expire after the website is closed, while others are stored on the computer for a longer period.
6.2. Legal background and legal basis of cookie management
Cookies typically used by webshops include so-called “password-protected session cookies”, “shopping cart cookies” and “security cookies”, for which it is not necessary to request prior consent from data subjects.
Fact of data processing, scope of processed data: unique identification number, dates, times.
Scope of data subjects: all data subjects visiting the website.
Purpose of data processing: identification of users, tracking visitors.
Legal basis of data processing: consent of the data subject in accordance with Section 5(1)(a) of the Infotv.
6.3 Duration of data processing, deadline for deletion of data: the website uses the following cookies:
- Security cookies: __cfduid, _biz_flagsA, _biz_nA 3, _biz_pendingA, _biz_sid, _biz_uid
- Google Analytics cookies: _ga, _gid
- Cookies necessary for the proper use of the website:
Possible data controllers authorised to access the data: the data controller does not process personal data through the use of cookies.
Description of the data subjects’ rights related to data processing: Data subjects have the option to delete cookies in the Tools/Settings menu of their browser, generally under the Privacy settings.
If the data subject does not accept the use of cookies, certain functions will not be available to them. More information about deleting cookies can be found at the following links:
• Internet Explorer: http://windows.microsoft.com/en-us/internet-explorer/delete-managecookies#ie=ie-11
• Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-yourcomputer
• Chrome: https://support.google.com/chrome/answer/95647?hl=en
• Safari: https://support.apple.com/kb/ph21411?locale=en_US
7. Google Analytics
7.1. This website uses Google Analytics, a web analytics service provided by Google Inc. (“Google”). Google Analytics uses so-called cookies, text files that are saved on your computer and help analyse the use of the website visited by the User.
7.2. Information generated by cookies relating to the website used by the User is usually transferred to and stored on one of Google’s servers in the USA. By activating IP anonymisation on the website, Google will first shorten the User’s IP address within the member states of the European Union or in other states party to the Agreement on the European Economic Area.
7.3. The full IP address is transferred to a Google server in the USA and shortened there only in exceptional cases. On behalf of the operator of this website, Google will use this information to evaluate how the User used the website, to prepare reports for the website operator concerning website activity, and to provide further services related to website and internet use.
7.4. The IP address transmitted by the User’s browser within the framework of Google Analytics is not combined with other Google data. The User can prevent the storage of cookies by selecting the appropriate settings in their browser; however, please note that in this case not all functions of this website may be fully usable. The User may also prevent Google from collecting and processing data generated by cookies relating to the User’s website use, including the IP address, by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=hu
8. Google AdWords conversion tracking and remarketing
8.1. The data controller uses the online advertising programme called “Google AdWords” and also uses Google’s conversion tracking service within its framework. Google conversion tracking is an analytics service provided by Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”).
8.2. When a User accesses a website through a Google advertisement, a cookie required for conversion tracking is placed on their computer. These cookies have limited validity and do not contain any personal data, so the User cannot be identified through them.
8.3. When the User browses certain pages of the website and the cookie has not yet expired, both Google and the data controller can see that the User clicked on the advertisement.
8.4. Each Google AdWords customer receives a different cookie, so they cannot be tracked across the websites of AdWords customers.
8.5. The information obtained using conversion tracking cookies is used to prepare conversion statistics for customers who choose AdWords conversion tracking. Customers are thus informed about the number of users who clicked on their advertisement and were redirected to a page with a conversion tracking tag. However, they do not receive any information that could identify any individual user.
8.6. If you do not wish to participate in conversion tracking, you can refuse this by disabling the installation of cookies in your browser. After this, the data subject will not be included in the conversion tracking statistics.
8.7. Further information and Google’s privacy policy are available at: www.google.de/policies/privacy/
8.8. Google AdWords Remarketing
8.9. Data processing as a remarketing activity is carried out using cookies.
Processed data
The data processed by the cookies specified in the cookie notice.
Duration of data processing
The data storage period of the given cookie; more information is available here:
Google general cookie notice: https://www.google.com/policies/technologies/types/
Google Analytics notice:
https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage?hl=hu
Legal basis of data processing
The voluntary consent of the data subject, which the data subject gives to the service provider by using the website.
9. Rights of data subjects
9.1 Right to information
At the data subject’s request, the Service Provider, as data controller, provides information about the data processed by it or by a processor commissioned by it, the source of the data, the purpose, legal basis and duration of data processing, the name, address and data-processing-related activities of the data processor, the circumstances, effects and measures taken to remedy any data protection incident, and, in the case of data transfer, its legal basis and recipient. The data controller provides the information in an understandable form, in writing at the data subject’s request, as soon as possible after submission of the request, but no later than within 30 days. This information is free of charge if the person requesting information has not yet submitted a request for information concerning the same scope of data to the data controller in the current year. In other cases, the Service Provider may determine reimbursement of costs.
9.2 Right to rectification
The Service Provider rectifies personal data if it does not correspond to reality and the personal data corresponding to reality is available to it.
9.3 Right to blocking
The Service Provider blocks personal data if the data subject requests this, or if, based on the information available to it, it can be assumed that deletion would violate the legitimate interests of the data subject. Blocked personal data may only be processed for as long as the data processing purpose that excluded deletion of the personal data exists. The Service Provider marks the personal data processed by it if the data subject disputes its correctness or accuracy, but the incorrectness or inaccuracy of the disputed personal data cannot be clearly established.
9.4 Right to deletion
The Service Provider deletes personal data if its processing is unlawful, if the data subject requests it, if the processed data is incomplete or incorrect and this condition cannot lawfully be remedied, provided that deletion is not excluded by law, if the purpose of data processing has ceased, if the statutory storage deadline has expired, or if deletion has been ordered by a court or by the National Authority for Data Protection and Freedom of Information.
9.5 Procedural rules
The data controller has 30 days to delete, block or rectify personal data. If the data controller does not fulfil the data subject’s request for rectification, blocking or deletion, it shall communicate the reasons for refusal in writing or, with the data subject’s consent, electronically within 30 days. The Service Provider notifies the data subject and all those to whom the data was previously transferred for data processing purposes about the rectification, blocking, marking and deletion. Notification may be omitted if this does not violate the legitimate interests of the data subject with regard to the purpose of data processing.
9.6 Objection
The data subject may object to the processing of their personal data if
a) the processing or transfer of personal data is necessary solely for the fulfilment of a legal obligation concerning the data controller or for the enforcement of the legitimate interest of the data controller, data recipient or third party, except where the processing is required by law;
b) in other cases specified by law.
The Service Provider examines the objection as soon as possible after submission of the request, but no later than within 15 days, decides on whether it is justified, and informs the applicant of its decision in writing. If the data controller determines that the data subject’s objection is justified, it terminates the data processing, including further data collection and transfer, blocks the data, and notifies all those to whom the personal data affected by the objection was previously transferred and who are obliged to take action in order to enforce the right to object.
If the data subject does not agree with the decision made by the data controller, they may turn to court within 30 days of its notification.
The Service Provider may not delete the data subject’s data if data processing is required by law. However, the data may not be transferred to the data recipient if the data controller has agreed with the objection, or if the court has established that the objection is justified.
9.7. Right to data portability
If data processing is carried out by automated means, or if data processing is based on the voluntary consent of the data subject, the data subject has the right to request from the Data Controller the data they provided to the Data Controller, which the Data Controller shall provide to the data subject in XML, JSON or CSV format. If technically feasible, the data subject may request that the Data Controller transfer the data in this format to another data controller.
9.8 Compensation and non-material damages
The Service Provider compensates damage caused to others by unlawful processing of the data subject’s data or by breach of data security requirements. In the event of violation of the data subject’s personality rights, the data subject may claim non-material damages under Section 2:52 of the Civil Code. The data controller is also liable to the data subject for damage caused by the data processor. The data controller is exempt from liability if the damage was caused by an unavoidable cause outside the scope of data processing.
The data controller does not compensate damage and non-material damages may not be claimed to the extent that the damage or infringement of personality rights was caused by the intentional or grossly negligent conduct of the injured party or data subject.
9.9 Right to turn to court
In the event of violation of their rights, the data subject may turn to court against the data controller. The court shall act out of turn in the case.
9.10 Complaint
Complaints may be submitted to the National Authority for Data Protection and Freedom of Information:
Name: National Authority for Data Protection and Freedom of Information
Registered office: 1125 Budapest, Szilágyi Erzsébet fasor 22/C.
Postal address: 1530 Budapest, P.O. Box 5.
Phone: +361/391-1400
Fax: +361/391-1410
Email: ugyfelszolgalat@naih.hu
Website: http://www.naih.hu
10. Data security
The service provider designs and carries out data processing operations in a way that ensures protection of the privacy of data subjects.
The service provider, and within its scope of activity the data processor, ensures the security of the data, takes the technical and organisational measures and establishes the procedural rules necessary to enforce the Infotv. and other data and confidentiality protection rules.
The service provider protects the data with appropriate measures, in particular against unauthorised access, alteration, transfer, disclosure, deletion or destruction, as well as against accidental destruction and damage, and against becoming inaccessible due to changes in the technology used.
During data processing, the service provider preserves:
• confidentiality: protects information so that only those authorised can access it
• integrity: protects the accuracy and completeness of the information and the processing method
• availability: ensures that when the authorised user needs it, they can actually access the required information and the related tools are available.
The IT systems and networks of the service provider and its partners involved in data processing are protected against computer-aided fraud, espionage, sabotage, vandalism, fire and flood, as well as computer viruses, computer intrusions and denial-of-service attacks. The operator ensures security through server-level and application-level protection procedures.
11. Applicable laws used for this Privacy Notice
• Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Infotv.)
• Act V of 2013 on the Civil Code (Civil Code)
• Act CLV of 1997 on Consumer Protection
• Act XIX of 1998 on Criminal Procedure
• Act CVIII of 2001 on certain issues of electronic commerce services and information society services
• Act C of 2003 on Electronic Communications
• Act XLVIII of 2008 on the basic conditions and certain restrictions of economic advertising activity
• Recommendation of the National Authority for Data Protection and Freedom of Information on the data protection requirements of prior information
• GDPR, Regulation (EU) 2016/679 of the European Parliament and of the Council on the processing and protection of personal data of natural persons and on the free movement of such data
04.09.2026