Privacy Notice

Privacy Notice – IntactBody / DS-MEDICAL Kft.

Privacy Notice

DS-MEDICAL Ltd. – intactbody.com

This document is a draft; it is recommended that it be reviewed by a legal expert before finalisation. The information in square brackets [ ] is to be completed or verified.

Date of entry into force: [to be completed] Version number: 2.0 Last revised: [month] 2026


Table of Contents

  1. Introduction
  2. The data controller and their contact details
  3. Definitions
  4. Principles of data processing
  5. Data processing in connection with the operation of the online shop
  6. Management of cookies
  7. Analytics and advertising services
  8. Newsletters and direct marketing (DM) activities
  9. Complaints handling
  10. Data processors and other recipients
  11. Social media platforms
  12. Customer relations and other data processing activities
  13. Rights of data subjects
  14. Time limits for measures
  15. Security of data processing
  16. Handling of data protection incidents
  17. Review of mandatory data processing
  18. Complaints and remedies
  19. Legal framework
  20. Final provisions

1. Introduction

DS-MEDICAL Kft. (hereinafter: “Service Provider” or “Data Controller”) is committed to protecting the personal data of its customers and visitors to the Website (hereinafter: “Data Subject” or “User”).

The purpose of this Privacy Notice (hereinafter: “Notice”) is to provide transparent, easily understandable information on how the Data Controller operates the website https://intactbody.com (hereinafter: “Website”) and the online shop operated through it, as well as in the provision of related services; furthermore, it explains what rights the Data Subject may exercise in this context.

Through the Website, the Data Controller sells various products online as part of its online shop service (currently including, amongst others, Tenmag-branded dietary supplements and vitamin preparations, with further product categories to be added in the future).

This Notice relates to Regulation (EU) 2016/679 of the European Parliament and of the Council (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter: ‘GDPR’), as well as the relevant Hungarian legislation.

The current version of the Privacy Notice is available on the Website at [to be added: e.g. intactbody.com/adatvedelem]. Amendments to the Privacy Notice shall take effect upon publication on that page.


2. The data controller and its contact details

DataValue
Company nameDS-MEDICAL Kft.
Registered office4600 Kisvárda, Szent László u. 32.
Company registration number[to be completed]
Tax numberHU-32017672
Emailinfo@dsmedical.hu
Telephone+36 30 257 4550
Websitehttps://intactbody.com

Should the Data Controller appoint a data protection officer or designate a data protection contact person, their contact details will be included in each updated version of this Notice.


3. Definitions

TermDefinition
Personal dataAny information relating to an identified or identifiable natural person.
Data processingAny operation carried out on personal data (collection, recording, storage, use, transmission, erasure, etc.).
Data controllerThe party that determines the purposes and means of processing personal data – in this case, DS-MEDICAL Kft.
Data processorA person who processes personal data on behalf of the Data Controller and in accordance with the Data Controller’s instructions.
RecipientThe person to whom personal data is disclosed, regardless of whether they are a third party.
Consent of the data subjectA voluntary, specific, informed and unambiguous expression of will.
Data breachA breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, the data being processed.
ProfilingThe automated processing of personal data aimed at evaluating the personal characteristics of the data subject (e.g. preferences, behaviour).
Third partyA person other than the data subject, the data controller, the data processor or a person acting under their direct control.

4. Principles of data processing

The Data Controller applies the following principles when processing personal data:

PrincipleContent
Lawfulness, fairness and transparencyData processing shall be carried out lawfully, fairly and in a manner that is transparent to the Data Subject.
Purpose limitationData shall be collected only for specified, explicit and legitimate purposes.
Data minimisationOnly data that is necessary and relevant to achieving the purposes shall be processed.
AccuracyThe data processed shall be accurate and, where necessary, kept up to date.
Limited storageData is stored only for as long as is necessary.
Integrity and confidentialityAppropriate technical and organisational measures ensure the security of the data.
AccountabilityThe Data Controller can demonstrate compliance with the above principles.

5. Data processing in connection with the operation of the online shop

DS-MEDICAL Kft. provides an online shop service via the Website, through which it currently sells primarily Tenmag-branded dietary supplements and vitamin products; the product range may be expanded to include further categories in the future. The provisions of this section apply uniformly to all products and services sold via the Website, regardless of the specific product category.

5.1 Scope, purpose and legal basis of data processing

Personal dataPurpose of data processingLegal basis
Registration usernameIdentification, enabling registrationConsent, Article 6(1)(a) of the GDPR
Password (stored in encrypted form)Secure loginConsent, Article 6(1)(a) of the GDPR
Surname and first nameContact, purchase, invoicing, exercising the right of withdrawalPerformance of a contract, Article 6(1)(b) of the GDPR
Email addressCommunication, order confirmationPerformance of a contract, Article 6(1)(b) of the GDPR
Telephone numberCommunication, coordination regarding delivery/invoicingPerformance of a contract, Article 6(1)(b) of the GDPR
Billing name and addressIssuing a valid invoice, charging feesCompliance with a legal obligation, Article 6(1)(c) of the GDPR (Section 169(2) of Act C of 2000)
Delivery name and addressArranging deliveryPerformance of a contract, Article 6(1)(b) of the GDPR
Date of purchase/registration and IP addressCarrying out technical operations, protection against fraudPerformance of a contract / legitimate interest, Article 6(1)(b) and (f) of the GDPR

5.2 Data subjects

All natural persons who register or make a purchase on the Website.

5.3 Duration of data processing

Data relating to registration and purchases may be processed until the data subject requests erasure or until the limitation period for civil law claims arising from the contract expires. An exception to this is accounting documentation, which must be retained for at least 8 years in accordance with Section 169(2) of Act C of 2000 on Accounting.

5.4 Provision of Information

The provision of data is a condition for the performance of the contract (order); failure to do so will result in the order not being fulfilled.


6. Use of cookies

The Website uses cookies to function; the Data Controller sets out the detailed rules governing these – including a specific list of categories, purposes, legal bases and retention periods – in a separate (Cookie) Policy, which is available on the Website at [to be added: link to the cookie policy] and forms an integral part of this Policy.

In brief, the following main categories of cookies may be used on the Website:

CategoryIs consent required?Legal basis
Essential (strictly necessary) cookiesNoLegitimate interest / Section 13/A of the Eker Act
Functional cookiesYesConsent, Article 6(1)(a) of the GDPR
Statistical (analytical) cookiesYesConsent, Article 6(1)(a) of the GDPR
Marketing (targeting/advertising) cookiesYesConsent, Article 6(1)(a) of the GDPR

The User may at any time amend or withdraw their consent to non-essential cookies via the cookie consent interface available on the Website.


7. Analytics and advertising services

Where third-party services for analytical (e.g. traffic measurement) or marketing purposes (e.g. remarketing, advertising conversion tracking), these are activated solely on the basis of the User’s prior, explicit consent, in accordance with the principles of Google Consent Mode V2 and the ePrivacy Directive.

Such services typically serve the following purposes:

  • measuring website traffic and user behaviour (statistical/analytical service);
  • displaying advertising campaigns and measuring their effectiveness, conversion tracking (marketing service, e.g. Google Ads).

These service providers have their own data processing policies, over which the Data Controller has no control. A detailed, up-to-date list of the third-party services currently in use can be viewed on the Website’s cookie settings page.

Note for finalisation: Where the Data Controller actually and continuously uses a specific service (e.g. Google Analytics, Google Ads conversion tracking, Meta Pixel), this must be listed here in detail, including the name of the service, the provider’s details and the specifics of data processing (e.g. data transfer to a third country, data retention period), in consultation with a legal expert.


8. Newsletters and direct marketing (DM) activities

Pursuant to Section 6 of Act XLVIII of 2008 on the fundamental conditions and certain restrictions of commercial advertising activities, advertising directed at a natural person – in particular via electronic mail – may only be sent with the prior, unambiguous and explicit consent of the addressee.

8.1 Data processed, purpose, legal basis

Personal dataPurpose of data processingLegal basis
Name, email addressSubscription to newsletters/special offersConsent, Article 6(1)(a) of the GDPR
Date of subscription and IP addressPerformance of a technical operation, verification of lawfulnessConsent, Article 6(1)(a) of the GDPR

8.2 Other provisions

  • Data subjects: all data subjects who have subscribed to the newsletter.
  • Duration of data processing: until consent is withdrawn (unsubscription) or until the newsletter service ceases.
  • Unsubscribing: may be initiated free of charge, without giving reasons and without restriction, at any time via the unsubscribe link in the newsletter or directly with the Data Controller.
  • Withdrawal of consent does not affect the lawfulness of data processing prior to withdrawal.

9. Complaints handling

Pursuant to Section 17/A(7) of Act CLV of 1997 on Consumer Protection, the record of the complaint and the response to it must be retained for 3 years.

Personal dataPurpose of data processingLegal basis
Surname and first name, email address, telephone numberIdentification, maintaining contact during the investigation of the complaintCompliance with a legal obligation, Article 6(1)(c) of the GDPR
Billing name and addressHandling quality complaints relating to the ordered productCompliance with a legal obligation, Article 6(1)(c) of the GDPR

If the data is not provided, the Data Controller will be unable to investigate the complaint.


10. Data processors and other recipients

The Data Controller shall only engage data processors that provide adequate safeguards to ensure compliance with the requirements of the GDPR. The data processor shall process personal data solely in accordance with the Data Controller’s instructions.

10.1 Data processors

ActivityService providerContact details
Hosting service[to be added/checked – e.g. BlazeArts Kft. (Forpsi)][to be added]
Online invoicing[to be added/checked – e.g. KBOSS.hu Kft. (Számlázz.hu)][to be added]
Newsletter system[to be added/checked][to be added]

10.2 Data transfer to third parties (independent data controllers)

ActivityService providerContact details
Transport / courier service[to be completed/checked][to be added]
Parcel locker delivery[to be added/checked][to be added]
Online payment[to be completed/checked][to be completed]

Note for finalisation: The exact names, addresses and contact details of the service providers actually used must be included in the tables above, in accordance with any data processing agreements that may exist between them.

Third parties receiving the data process the personal data transferred to them in their own name and in accordance with their own privacy policies.


11. Social media platforms

The Data Controller is also present on social media platforms (e.g. Facebook, Instagram) for the purpose of presenting its services and maintaining contact with interested parties and customers.

DescriptionDescription
Scope of data processedData publicly available on the Data Subject’s social media profile (name, profile picture, interactions, e.g. comments, messages)
Data subjectsThose who follow the Data Controller’s page, interact with it or send a message
PurposeTo present activities and services, for marketing purposes, and to maintain contact
Legal basisThe Data Subject’s voluntary consent, Article 6(1)(a) of the GDPR
DurationFor the duration of the interaction / until the content is deleted; in the case of correspondence, for a maximum of 2 years

11.1 Joint data processing with Facebook / Meta

Where the Data Controller uses the Facebook Page Insights feature, the associated data processing for statistical purposes is carried out jointly by the Data Controller and Meta Platforms Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, D2 Dublin, Ireland), the details of which are set out in the data controllers’ addendum for the Facebook Page Insights feature (https://www.facebook.com/legal/terms/page_controller_addendum). The Data Controller will only communicate via private message if the Data Subject initiates such communication.


12. Customer relations and other data processing

  1. In the event of any questions or issues relating to the Data Controller’s services, the Data Subject may contact the Data Controller via the contact details provided on the Website (telephone, email, social media).
  2. The Data Controller shall retain messages received (by email, telephone or social media) for a maximum of 2 years from the date of receipt.
  3. The Data Controller will provide information regarding any data processing operations not expressly listed in this Notice at the time the data is collected.
  4. The Data Controller is obliged to disclose data in response to a request from a public authority or where authorised by law; in such cases, it shall disclose only the data necessary to fulfil the purpose of the request.

13. Rights of data subjects

RightBrief description
Right of accessTo request confirmation as to whether data processing is taking place and, if so, to access the data being processed.
Right to rectificationTo request the rectification of inaccurate data without undue delay.
Right to erasureTo request the erasure of data where certain conditions are met.
Right to be forgottenNotification to other data controllers of the request for erasure in the event of the erasure of data that has been made public.
Right to restriction of processingRequesting the restriction of data processing (e.g. in the event of disputed accuracy or unlawful processing).
Right to data portabilityRequesting and receiving the data provided in a structured, machine-readable format.
Right to objectObjecting to data processing based on legitimate interests, including profiling.
Objection in the case of direct marketingYou may object at any time, after which the data may no longer be processed for this purpose.
Right to object to automated decision-makingThe data subject shall not be subject to a decision based solely on automated processing, without any exceptions.

The exercise of these rights is free of charge and may be initiated via the contact details set out in point 2.


14. Time limit for taking action

The Data Controller shall inform the Data Subject of the measures taken without undue delay, but no later than one month from receipt of the request. If necessary, this deadline may be extended by a further 2 months, of which the Data Controller shall give notice within 1 month. If no action is taken, the Data Controller shall inform the Data Subject of the reasons for this, as well as of the options for lodging a complaint and seeking judicial redress.


15. Security of data processing

The Data Controller and data processors shall implement appropriate technical and organisational measures based on the state of the art, the costs of implementation and the risks associated with data processing, including in particular:

Physical protection - Storage of documents in a secure, lockable room. - Access to personal data is restricted to authorised persons only. - The building is equipped with fire and security systems.

IT security - Use of anti-virus and intrusion protection software. - Regular data backup and archiving. - Access control via username and password, according to authorisation levels. - Only designated personnel may access the central systems.


16. Handling of data protection incidents

If a data protection incident is likely to pose a high risk to the rights and freedoms of data subjects, the Data Controller shall, without undue delay, inform the data subjects of the nature of the incident, its likely consequences and the measures taken or planned.

The Data Controller shall, where possible, notify the competent supervisory authority of the data breach within 72 hours of becoming aware of it, unless the incident is unlikely to pose a risk to the rights and freedoms of data subjects.


17. Review of mandatory data processing

Unless otherwise provided for by law, the Data Controller shall, at least every three years from the commencement of data processing, review whether the processing of the personal data concerned is necessary for the fulfilment of the purpose of the data processing. The Data Controller shall retain the documentation of the review for 10 years following the review.


18. Complaints and remedies

In the event of any breach of the law by the Data Controller, the Data Subject may lodge a complaint with the following authority or court:

National Authority for Data Protection and Freedom of Information (NAIH) Address: 1055 Budapest, Falk Miksa utca 9–11. Postal address: 1363 Budapest, PO Box 9. Telephone: +36-1-391-1400 Email: ugyfelszolgalat@naih.hu Website: www.naih.hu

The Data Subject may also seek redress at the court with jurisdiction over their place of residence or habitual residence.


19. Legal framework

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR);
  • Act CXII of 2011 on the right to informational self-determination and freedom of information;
  • Act CVIII of 2001 on electronic commerce services (in particular Section 13/A);
  • Act XLVII of 2008 on the Prohibition of Unfair Commercial Practices against Consumers;
  • Act XLVIII of 2008 on commercial advertising (in particular Section 6);
  • Act CLV of 1997 on consumer protection (in particular Section 17/A);
  • Act C of 2000 on Accounting (in particular Section 169);
  • Act C of 2003 on Electronic Communications (in particular Section 155);
  • the ePrivacy Directive (2002/58/EC, as amended by Directive 2009/136/EC).

20. Final provisions

This Privacy Notice may be updated in the event of changes to the above legal framework, the Data Controller’s activities or the technologies used on the Website. The current version is available on the Website.

DS-MEDICAL Kft. 4600 Kisvárda, Szent László u. 32. Tax number: HU-32017672 https://intactbody.com