Privacy Notice
Privacy Notice
DS-MEDICAL Ltd. – intactbody.com
This document is a draft; it is recommended that it be reviewed by a legal expert before finalisation. The information in square brackets [ ] is to be completed or verified.
Date of entry into force: [to be completed] Version number: 2.0 Last revised: [month] 2026
Table of Contents
- Introduction
- The data controller and their contact details
- Definitions
- Principles of data processing
- Data processing in connection with the operation of the online shop
- Management of cookies
- Analytics and advertising services
- Newsletters and direct marketing (DM) activities
- Complaints handling
- Data processors and other recipients
- Social media platforms
- Customer relations and other data processing activities
- Rights of data subjects
- Time limits for measures
- Security of data processing
- Handling of data protection incidents
- Review of mandatory data processing
- Complaints and remedies
- Legal framework
- Final provisions
1. Introduction
DS-MEDICAL Kft. (hereinafter: “Service Provider” or “Data Controller”) is committed to protecting the personal data of its customers and visitors to the Website (hereinafter: “Data Subject” or “User”).
The purpose of this Privacy Notice (hereinafter: “Notice”) is to provide transparent, easily understandable information on how the Data Controller operates the website https://intactbody.com (hereinafter: “Website”) and the online shop operated through it, as well as in the provision of related services; furthermore, it explains what rights the Data Subject may exercise in this context.
Through the Website, the Data Controller sells various products online as part of its online shop service (currently including, amongst others, Tenmag-branded dietary supplements and vitamin preparations, with further product categories to be added in the future).
This Notice relates to Regulation (EU) 2016/679 of the European Parliament and of the Council (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter: ‘GDPR’), as well as the relevant Hungarian legislation.
The current version of the Privacy Notice is available on the Website at [to be added: e.g. intactbody.com/adatvedelem]. Amendments to the Privacy Notice shall take effect upon publication on that page.
2. The data controller and its contact details
| Data | Value |
|---|---|
| Company name | DS-MEDICAL Kft. |
| Registered office | 4600 Kisvárda, Szent László u. 32. |
| Company registration number | [to be completed] |
| Tax number | HU-32017672 |
| info@dsmedical.hu | |
| Telephone | +36 30 257 4550 |
| Website | https://intactbody.com |
Should the Data Controller appoint a data protection officer or designate a data protection contact person, their contact details will be included in each updated version of this Notice.
3. Definitions
| Term | Definition |
|---|---|
| Personal data | Any information relating to an identified or identifiable natural person. |
| Data processing | Any operation carried out on personal data (collection, recording, storage, use, transmission, erasure, etc.). |
| Data controller | The party that determines the purposes and means of processing personal data – in this case, DS-MEDICAL Kft. |
| Data processor | A person who processes personal data on behalf of the Data Controller and in accordance with the Data Controller’s instructions. |
| Recipient | The person to whom personal data is disclosed, regardless of whether they are a third party. |
| Consent of the data subject | A voluntary, specific, informed and unambiguous expression of will. |
| Data breach | A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, the data being processed. |
| Profiling | The automated processing of personal data aimed at evaluating the personal characteristics of the data subject (e.g. preferences, behaviour). |
| Third party | A person other than the data subject, the data controller, the data processor or a person acting under their direct control. |
4. Principles of data processing
The Data Controller applies the following principles when processing personal data:
| Principle | Content |
|---|---|
| Lawfulness, fairness and transparency | Data processing shall be carried out lawfully, fairly and in a manner that is transparent to the Data Subject. |
| Purpose limitation | Data shall be collected only for specified, explicit and legitimate purposes. |
| Data minimisation | Only data that is necessary and relevant to achieving the purposes shall be processed. |
| Accuracy | The data processed shall be accurate and, where necessary, kept up to date. |
| Limited storage | Data is stored only for as long as is necessary. |
| Integrity and confidentiality | Appropriate technical and organisational measures ensure the security of the data. |
| Accountability | The Data Controller can demonstrate compliance with the above principles. |
5. Data processing in connection with the operation of the online shop
DS-MEDICAL Kft. provides an online shop service via the Website, through which it currently sells primarily Tenmag-branded dietary supplements and vitamin products; the product range may be expanded to include further categories in the future. The provisions of this section apply uniformly to all products and services sold via the Website, regardless of the specific product category.
5.1 Scope, purpose and legal basis of data processing
| Personal data | Purpose of data processing | Legal basis |
|---|---|---|
| Registration username | Identification, enabling registration | Consent, Article 6(1)(a) of the GDPR |
| Password (stored in encrypted form) | Secure login | Consent, Article 6(1)(a) of the GDPR |
| Surname and first name | Contact, purchase, invoicing, exercising the right of withdrawal | Performance of a contract, Article 6(1)(b) of the GDPR |
| Email address | Communication, order confirmation | Performance of a contract, Article 6(1)(b) of the GDPR |
| Telephone number | Communication, coordination regarding delivery/invoicing | Performance of a contract, Article 6(1)(b) of the GDPR |
| Billing name and address | Issuing a valid invoice, charging fees | Compliance with a legal obligation, Article 6(1)(c) of the GDPR (Section 169(2) of Act C of 2000) |
| Delivery name and address | Arranging delivery | Performance of a contract, Article 6(1)(b) of the GDPR |
| Date of purchase/registration and IP address | Carrying out technical operations, protection against fraud | Performance of a contract / legitimate interest, Article 6(1)(b) and (f) of the GDPR |
5.2 Data subjects
All natural persons who register or make a purchase on the Website.
5.3 Duration of data processing
Data relating to registration and purchases may be processed until the data subject requests erasure or until the limitation period for civil law claims arising from the contract expires. An exception to this is accounting documentation, which must be retained for at least 8 years in accordance with Section 169(2) of Act C of 2000 on Accounting.
5.4 Provision of Information
The provision of data is a condition for the performance of the contract (order); failure to do so will result in the order not being fulfilled.
6. Use of cookies
The Website uses cookies to function; the Data Controller sets out the detailed rules governing these – including a specific list of categories, purposes, legal bases and retention periods – in a separate (Cookie) Policy, which is available on the Website at [to be added: link to the cookie policy] and forms an integral part of this Policy.
In brief, the following main categories of cookies may be used on the Website:
| Category | Is consent required? | Legal basis |
|---|---|---|
| Essential (strictly necessary) cookies | No | Legitimate interest / Section 13/A of the Eker Act |
| Functional cookies | Yes | Consent, Article 6(1)(a) of the GDPR |
| Statistical (analytical) cookies | Yes | Consent, Article 6(1)(a) of the GDPR |
| Marketing (targeting/advertising) cookies | Yes | Consent, Article 6(1)(a) of the GDPR |
The User may at any time amend or withdraw their consent to non-essential cookies via the cookie consent interface available on the Website.
7. Analytics and advertising services
Where third-party services for analytical (e.g. traffic measurement) or marketing purposes (e.g. remarketing, advertising conversion tracking), these are activated solely on the basis of the User’s prior, explicit consent, in accordance with the principles of Google Consent Mode V2 and the ePrivacy Directive.
Such services typically serve the following purposes:
- measuring website traffic and user behaviour (statistical/analytical service);
- displaying advertising campaigns and measuring their effectiveness, conversion tracking (marketing service, e.g. Google Ads).
These service providers have their own data processing policies, over which the Data Controller has no control. A detailed, up-to-date list of the third-party services currently in use can be viewed on the Website’s cookie settings page.
Note for finalisation: Where the Data Controller actually and continuously uses a specific service (e.g. Google Analytics, Google Ads conversion tracking, Meta Pixel), this must be listed here in detail, including the name of the service, the provider’s details and the specifics of data processing (e.g. data transfer to a third country, data retention period), in consultation with a legal expert.
8. Newsletters and direct marketing (DM) activities
Pursuant to Section 6 of Act XLVIII of 2008 on the fundamental conditions and certain restrictions of commercial advertising activities, advertising directed at a natural person – in particular via electronic mail – may only be sent with the prior, unambiguous and explicit consent of the addressee.
8.1 Data processed, purpose, legal basis
| Personal data | Purpose of data processing | Legal basis |
|---|---|---|
| Name, email address | Subscription to newsletters/special offers | Consent, Article 6(1)(a) of the GDPR |
| Date of subscription and IP address | Performance of a technical operation, verification of lawfulness | Consent, Article 6(1)(a) of the GDPR |
8.2 Other provisions
- Data subjects: all data subjects who have subscribed to the newsletter.
- Duration of data processing: until consent is withdrawn (unsubscription) or until the newsletter service ceases.
- Unsubscribing: may be initiated free of charge, without giving reasons and without restriction, at any time via the unsubscribe link in the newsletter or directly with the Data Controller.
- Withdrawal of consent does not affect the lawfulness of data processing prior to withdrawal.
9. Complaints handling
Pursuant to Section 17/A(7) of Act CLV of 1997 on Consumer Protection, the record of the complaint and the response to it must be retained for 3 years.
| Personal data | Purpose of data processing | Legal basis |
|---|---|---|
| Surname and first name, email address, telephone number | Identification, maintaining contact during the investigation of the complaint | Compliance with a legal obligation, Article 6(1)(c) of the GDPR |
| Billing name and address | Handling quality complaints relating to the ordered product | Compliance with a legal obligation, Article 6(1)(c) of the GDPR |
If the data is not provided, the Data Controller will be unable to investigate the complaint.
10. Data processors and other recipients
The Data Controller shall only engage data processors that provide adequate safeguards to ensure compliance with the requirements of the GDPR. The data processor shall process personal data solely in accordance with the Data Controller’s instructions.
10.1 Data processors
| Activity | Service provider | Contact details |
|---|---|---|
| Hosting service | [to be added/checked – e.g. BlazeArts Kft. (Forpsi)] | [to be added] |
| Online invoicing | [to be added/checked – e.g. KBOSS.hu Kft. (Számlázz.hu)] | [to be added] |
| Newsletter system | [to be added/checked] | [to be added] |
10.2 Data transfer to third parties (independent data controllers)
| Activity | Service provider | Contact details |
|---|---|---|
| Transport / courier service | [to be completed/checked] | [to be added] |
| Parcel locker delivery | [to be added/checked] | [to be added] |
| Online payment | [to be completed/checked] | [to be completed] |
Note for finalisation: The exact names, addresses and contact details of the service providers actually used must be included in the tables above, in accordance with any data processing agreements that may exist between them.
Third parties receiving the data process the personal data transferred to them in their own name and in accordance with their own privacy policies.
11. Social media platforms
The Data Controller is also present on social media platforms (e.g. Facebook, Instagram) for the purpose of presenting its services and maintaining contact with interested parties and customers.
| Description | Description |
|---|---|
| Scope of data processed | Data publicly available on the Data Subject’s social media profile (name, profile picture, interactions, e.g. comments, messages) |
| Data subjects | Those who follow the Data Controller’s page, interact with it or send a message |
| Purpose | To present activities and services, for marketing purposes, and to maintain contact |
| Legal basis | The Data Subject’s voluntary consent, Article 6(1)(a) of the GDPR |
| Duration | For the duration of the interaction / until the content is deleted; in the case of correspondence, for a maximum of 2 years |
11.1 Joint data processing with Facebook / Meta
Where the Data Controller uses the Facebook Page Insights feature, the associated data processing for statistical purposes is carried out jointly by the Data Controller and Meta Platforms Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, D2 Dublin, Ireland), the details of which are set out in the data controllers’ addendum for the Facebook Page Insights feature (https://www.facebook.com/legal/terms/page_controller_addendum). The Data Controller will only communicate via private message if the Data Subject initiates such communication.
12. Customer relations and other data processing
- In the event of any questions or issues relating to the Data Controller’s services, the Data Subject may contact the Data Controller via the contact details provided on the Website (telephone, email, social media).
- The Data Controller shall retain messages received (by email, telephone or social media) for a maximum of 2 years from the date of receipt.
- The Data Controller will provide information regarding any data processing operations not expressly listed in this Notice at the time the data is collected.
- The Data Controller is obliged to disclose data in response to a request from a public authority or where authorised by law; in such cases, it shall disclose only the data necessary to fulfil the purpose of the request.
13. Rights of data subjects
| Right | Brief description |
|---|---|
| Right of access | To request confirmation as to whether data processing is taking place and, if so, to access the data being processed. |
| Right to rectification | To request the rectification of inaccurate data without undue delay. |
| Right to erasure | To request the erasure of data where certain conditions are met. |
| Right to be forgotten | Notification to other data controllers of the request for erasure in the event of the erasure of data that has been made public. |
| Right to restriction of processing | Requesting the restriction of data processing (e.g. in the event of disputed accuracy or unlawful processing). |
| Right to data portability | Requesting and receiving the data provided in a structured, machine-readable format. |
| Right to object | Objecting to data processing based on legitimate interests, including profiling. |
| Objection in the case of direct marketing | You may object at any time, after which the data may no longer be processed for this purpose. |
| Right to object to automated decision-making | The data subject shall not be subject to a decision based solely on automated processing, without any exceptions. |
The exercise of these rights is free of charge and may be initiated via the contact details set out in point 2.
14. Time limit for taking action
The Data Controller shall inform the Data Subject of the measures taken without undue delay, but no later than one month from receipt of the request. If necessary, this deadline may be extended by a further 2 months, of which the Data Controller shall give notice within 1 month. If no action is taken, the Data Controller shall inform the Data Subject of the reasons for this, as well as of the options for lodging a complaint and seeking judicial redress.
15. Security of data processing
The Data Controller and data processors shall implement appropriate technical and organisational measures based on the state of the art, the costs of implementation and the risks associated with data processing, including in particular:
Physical protection - Storage of documents in a secure, lockable room. - Access to personal data is restricted to authorised persons only. - The building is equipped with fire and security systems.
IT security - Use of anti-virus and intrusion protection software. - Regular data backup and archiving. - Access control via username and password, according to authorisation levels. - Only designated personnel may access the central systems.
16. Handling of data protection incidents
If a data protection incident is likely to pose a high risk to the rights and freedoms of data subjects, the Data Controller shall, without undue delay, inform the data subjects of the nature of the incident, its likely consequences and the measures taken or planned.
The Data Controller shall, where possible, notify the competent supervisory authority of the data breach within 72 hours of becoming aware of it, unless the incident is unlikely to pose a risk to the rights and freedoms of data subjects.
17. Review of mandatory data processing
Unless otherwise provided for by law, the Data Controller shall, at least every three years from the commencement of data processing, review whether the processing of the personal data concerned is necessary for the fulfilment of the purpose of the data processing. The Data Controller shall retain the documentation of the review for 10 years following the review.
18. Complaints and remedies
In the event of any breach of the law by the Data Controller, the Data Subject may lodge a complaint with the following authority or court:
National Authority for Data Protection and Freedom of Information (NAIH) Address: 1055 Budapest, Falk Miksa utca 9–11. Postal address: 1363 Budapest, PO Box 9. Telephone: +36-1-391-1400 Email: ugyfelszolgalat@naih.hu Website: www.naih.hu
The Data Subject may also seek redress at the court with jurisdiction over their place of residence or habitual residence.
19. Legal framework
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR);
- Act CXII of 2011 on the right to informational self-determination and freedom of information;
- Act CVIII of 2001 on electronic commerce services (in particular Section 13/A);
- Act XLVII of 2008 on the Prohibition of Unfair Commercial Practices against Consumers;
- Act XLVIII of 2008 on commercial advertising (in particular Section 6);
- Act CLV of 1997 on consumer protection (in particular Section 17/A);
- Act C of 2000 on Accounting (in particular Section 169);
- Act C of 2003 on Electronic Communications (in particular Section 155);
- the ePrivacy Directive (2002/58/EC, as amended by Directive 2009/136/EC).
20. Final provisions
This Privacy Notice may be updated in the event of changes to the above legal framework, the Data Controller’s activities or the technologies used on the Website. The current version is available on the Website.
DS-MEDICAL Kft. 4600 Kisvárda, Szent László u. 32. Tax number: HU-32017672 https://intactbody.com
Legal notice: This document is a draft. It is recommended that you consult a legal expert before finalising it, with particular regard to the following:
- The inclusion of accurate, up-to-date details of the data processors and third parties actually used (hosting provider, invoicing system, courier service, payment service provider, newsletter distribution system, etc.) in point 10.
- The specific names and detailed descriptions of the analytics/marketing services actually in use (e.g. Google Analytics, Google Ads, Meta Pixel) in section 7, where such services are in continuous operation.
- The technical operation of the cookie consent banner must be consistent with this Notice and the separate Cookie Notice.