top of page

CHÍNH SÁCH BẢO MẬT

Back & Rosta, Ltd. Chính sách Bảo mật {Cập nhật: Ngày 27 tháng 4 năm 2020}

 

Chính sách quyền riêng tư này mô tả cách thông tin cá nhân của bạn được thu thập, sử dụng và chia sẻ khi bạn truy cập hoặc thực hiện giao dịch mua hàng tại trang web www.the-magic-wall.com (gọi tắt là “Trang web”).

 

THÔNG TIN CÁ NHÂN VÀ THIẾT BỊ CHÚNG TÔI THU THẬP

 

Khi bạn truy cập Trang web, chúng tôi tự động thu thập một số thông tin về thiết bị của bạn, bao gồm trình duyệt web, địa chỉ IP, múi giờ và một số cookie được cài đặt trên thiết bị. Ngoài ra, khi bạn duyệt Trang web, chúng tôi thu thập thông tin về các trang hoặc sản phẩm bạn đã xem, các trang web hoặc từ khóa tìm kiếm dẫn bạn đến Trang web, cũng như cách bạn tương tác với Trang web. Những thông tin này được gọi chung là “Thông tin thiết bị”.

Chúng tôi thu thập Thông tin thiết bị thông qua các công nghệ sau:

  • “Cookie”: là các tệp dữ liệu được lưu trữ trên thiết bị hoặc máy tính của bạn, thường bao gồm một mã định danh ẩn danh duy nhất. Để biết thêm thông tin về cookie và cách vô hiệu hóa cookie, vui lòng truy cập: http://www.allaboutcookies.org.

  • “Tệp nhật ký” (Log files): theo dõi các hành động diễn ra trên Trang web và thu thập dữ liệu như địa chỉ IP, loại trình duyệt, nhà cung cấp dịch vụ Internet, trang giới thiệu/thoát, và dấu thời gian truy cập.

  • “Web beacons”, “tags”, “pixels”: là các tệp điện tử được sử dụng để ghi lại cách bạn duyệt Trang web.

Ngoài ra, khi bạn đăng ký vào danh sách gửi thư hoặc điền vào biểu mẫu liên hệ, chúng tôi có thể thu thập thêm các thông tin cá nhân như: họ tên, địa chỉ email, số điện thoại, quốc gia và công ty.

CÁCH CHÚNG TÔI SỬ DỤNG THÔNG TIN CỦA BẠN

Chúng tôi sử dụng Thông tin thiết bị để:

  • Sàng lọc các rủi ro và hành vi gian lận (đặc biệt là địa chỉ IP)

  • Cải thiện và tối ưu hóa Trang web (ví dụ, thông qua phân tích cách khách hàng truy cập và tương tác với Trang web)

  • Đánh giá hiệu quả của các chiến dịch tiếp thị và quảng cáo

Đối với những người đã đăng ký nhận bản tin hoặc điền thông tin qua các biểu mẫu, chúng tôi sử dụng thông tin cá nhân để gửi các thông báo định kỳ như: bản tin hàng tháng, cập nhật sản phẩm, ưu đãi đặc biệt,…

CHIA SẺ THÔNG TIN CỦA BẠN

Chúng tôi có chia sẻ một số thông tin cá nhân và thiết bị với các bên thứ ba:

Chúng tôi cũng có thể chia sẻ thông tin cá nhân để:

  • Tuân thủ luật pháp và quy định hiện hành

  • Phản hồi yêu cầu pháp lý như trát đòi, lệnh khám xét hoặc yêu cầu hợp pháp khác

  • Bảo vệ quyền lợi hợp pháp của chúng tôi

Chúng tôi cam kết không bán, cho thuê hoặc phân phối thông tin của bạn cho bất kỳ bên nào ngoài các bên đã liệt kê ở trên.

Trang web không thay đổi hoạt động thu thập dữ liệu khi trình duyệt gửi tín hiệu “Do Not Track” (Không theo dõi).

Nếu bạn là cư dân của Liên minh Châu Âu, bạn có quyền truy cập, sửa đổi hoặc yêu cầu xóa thông tin cá nhân mà chúng tôi lưu trữ. Nếu muốn thực hiện quyền này, vui lòng liên hệ với chúng tôi qua thông tin dưới đây.

Ngoài ra, xin lưu ý rằng dữ liệu của bạn có thể được chuyển ra ngoài Châu Âu, bao gồm Canada và Hoa Kỳ, nhằm phục vụ cho các mục đích nêu trên.

TRẺ VỊ THÀNH NIÊN​

Trang web không dành cho người dùng dưới 18 tuổi.

CẬP NHẬT CHÍNH SÁCH

Chúng tôi có thể cập nhật chính sách quyền riêng tư này định kỳ để phản ánh các thay đổi về hoạt động, quy định pháp lý, hoặc các lý do vận hành khác.

LIÊN HỆ

Nếu bạn có bất kỳ câu hỏi nào liên quan đến chính sách quyền riêng tư này hoặc muốn gửi khiếu nại, vui lòng liên hệ chúng tôi qua:

 

Email: info@the-magic-wall.com

 

Địa chỉ: Back & Rosta, Ltd.
Stromfeld Aurél út 28, Budapest, BU, 1124, Hungary

Tên công ty
Văn phòng đăng ký
Dịch vụ được cung cấp

Back and Rosta Information Technology (Shanghai) Ltd. 

Số 111–113 Đường Huashi, Quận Xuhui, 200235 Thượng Hải, Trung Quốc

Vận hành trang web

Shanghai Back & Rosta Cultural Development Co. Ltd. 

SỐ 111-113, Đường Huashi Quận Xuhui, 200235 Thượng Hải, Trung Quốc

Điều phối triển lãm

Magic Wall LLC 

30 N Gould St #42881
Sheridan, WY 82801 Hoa Kỳ

Bán hàng và tiếp thị

Back and Rosta GmbH 

Schumanngasse 22/7.
Viên 1180 Áo

Bán hàng và tiếp thị

16. Third-Party Service Providers  

 

In the course of operating the Website, the Data Controller engages Third-Party Service Providers, with whom the Data Controller cooperates.  

With regard to Personal Data processed in the systems of Third-Party Service Providers, the provisions set forth in the Third-Party Service Providers’ own privacy policies shall apply. The Data Controller will do everything in its power to ensure that the External Service Provider processes the Personal Data transferred to it in accordance with the law and uses such data exclusively for the purposes specified by the Data Subject or set forth below in this Notice. 

The Data Controller shall inform Data Subjects about data transfers to Third-Party Service Providers within the framework of this Notice. 

 

17. Data Security and Access to Data 

 

The Data Controller ensures the security of the data, takes the technical and organizational measures, and establishes the procedural rules necessary to enforce applicable laws and data and confidentiality protection rules. The Data Controller protects the data with appropriate measures against unauthorized access, alteration, transmission, disclosure, deletion, or destruction, as well as against accidental destruction or damage, and against becoming inaccessible due to changes in the technology used.  

 

The Data Controller maintains records of the data it processes in accordance with applicable laws, ensuring that the data is accessible only to those employees and other persons acting on behalf of the Data Controller (data processors) who need it to perform their job duties or tasks. The Data Controller’s employees shall perform individual searches or specific operations on the data only at the request of the Data Subject or when necessary for the provision of the service.  

 

When defining and implementing measures to ensure data security, the Data Controller takes into account the current state of the art. The Data Controller selects, from among several possible data processing solutions, the one that ensures a higher level of protection for personal data, unless this would entail disproportionate difficulty.  

 

As part of its IT security responsibilities, the Data Controller shall ensure, in particular: 

  • Measures to protect against unauthorized access, including the protection of software and hardware devices, as well as physical security (access control, network security); 

  • Measures to ensure the recoverability of data files, including regular backups and the separate, secure management of copies (mirroring, backup); 

  • Protection of data files against viruses (virus protection); 

  • The physical protection of data files and the devices on which they are stored, including protection against fire, water damage, lightning strikes, and other natural disasters, as well as the recoverability of data damaged as a result of such events (archiving, fire protection). 

Employees and other persons acting on behalf of the Data Controller are required to securely store and protect data storage media containing personal data that they use or possess—regardless of the method of data recording—against unauthorized access, alteration, transmission, disclosure, deletion, or destruction, as well as against accidental destruction and damage.  
 
The Data Controller operates the electronic registry using software that complies with data security requirements. The software ensures that data is accessed only for specific purposes, under controlled conditions, and only by those individuals who need it to perform their duties. 

 

18. Duration of Data Processing 

 

In addition to the specific provisions described above for each data processing operation, the Data Controller shall delete personal data if  

 

a) the processing is unlawful; 

If it becomes apparent that the data is being processed unlawfully, the Data Controller shall delete it without delay.  

 

b) the Data Subject requests the erasure of their data (except for data processing based on law);  

The Data Subject may request the erasure of data processed on the basis of the Data Subject’s voluntary consent. In this case, the Data Controller shall erase the data. Erasure may be refused only if the processing of the data is authorized by law. The Data Controller shall in all cases provide information regarding the refusal of the erasure request and the legal basis permitting the data processing.  

 

c) the data is incomplete or incorrect—and this condition cannot be lawfully remedied—provided that the law does not preclude erasure; 

 

d) the purpose of data processing has ceased to exist, or the statutory retention period for the data has expired;  

Erasure may be refused (i) for the purpose of exercising the right to freedom of expression and the right to information, or (ii) if the processing of Personal Data is authorized by law; and (iii) for the purpose of asserting, exercising, or defending legal claims.  

 

In all cases, the Data Controller shall notify the Data Subject of the refusal of a request for erasure, specifying the reason for the refusal. Once a request for the erasure of personal data has been fulfilled, the previous (erased) data cannot be restored. 

 

 

Since the Data Controller provides ongoing services to the Data Subject, the relationship between the parties is not subject to a time limit. Based on the foregoing—in the absence of a request from the Data Subject—the Data Controller will process the data for as long as the relationship between the Data Controller and the Data Subject exists and for as long as the Data Controller is able to provide services to the Data Subject.  

The Data Controller will delete all other data if it is clear that the data will not be used in the future, meaning that the purpose of data processing has ceased to exist.  

 

e) it has been ordered by a court or the National Authority for Data Protection and Freedom of Information: 

  

If a court or the National Authority for Data Protection and Freedom of Information issues a final and binding order to delete the data, the Data Controller shall carry out the deletion.  

Instead of erasure, the Data Controller—after informing the Data Subject—shall block the personal data if the Data Subject so requests, or if, based on the information available to the Data Controller, it can be presumed that erasure would harm the Data Subject’s legitimate interests. Personal data blocked in this manner may be processed only for as long as the purpose of data processing that precluded the erasure of the personal data remains valid. The Data Controller shall mark the personal data it processes if the Data Subject disputes its correctness or accuracy, but the incorrectness or inaccuracy of the disputed personal data cannot be clearly established.  

In the case of data processing required by law, the provisions of the applicable law shall govern the erasure of data.  

 

In the event of erasure, the Data Controller shall render the data unfit for identification. If required by law, the Data Controller shall destroy the data medium containing the personal data. 

 

19. Rights of Data Subjects and Their Enforcement 

 

19.1. Upon initial contact, the Data Controller shall inform the Data Subject about the processing of their data by drawing their attention to this privacy notice and providing access to it on the Website. The Data Subject is also entitled at any time to request information regarding the processing of their data.  

 

At the Data Subject’s request, the Data Controller shall provide information regarding the Data Subject’s data processed by the Data Controller or by a data processor commissioned by the Data Controller or in accordance with its instructions, including the source of such data, the purpose, legal basis, and duration of the data processing, as well as the name, address, and activities of the data processor related to the data processing, the circumstances and effects of a data breach and the measures taken to address it; and—in the event of a transfer of the Data Subject’s Personal Data—the legal basis for the transfer and the recipient of the data. The Data Controller is obligated to provide the information in writing, in an easily understandable form, at the Data Subject’s request, as soon as possible after the request is submitted, but no later than 25 days thereafter. This information is provided free of charge if the person requesting the information has not previously submitted a request for information regarding the same set of data in the current year. In other cases, a fee may be charged. Any fee already paid must be refunded if the data was processed unlawfully or if the request for information led to a correction.  

 

19.2. The Data Subject may request that the Data Controller correct any inaccurate personal data. If the data to be corrected is used for regular data disclosures, the Data Controller shall, if necessary, notify the recipient of the data disclosure of the correction and shall inform the Data Subject that they must also request the correction from other data controllers.  

 

19.3. Except for data processing required by law, the Data Subject may request the erasure of their personal data. The Data Controller shall inform the Data Subject of the erasure.  

 

19.4. The Data Subject may object to the processing of their personal data as specified in the GDPR.  

 

19.5. The Data Subject may submit a request for access, rectification, or erasure in writing, by mail addressed to the Data Controller’s registered office or business location, or by email sent to the email address provided in Section 3 above.  

 

19.6. The Data Subject may request that the Data Controller restrict the processing of their Personal Data if the Data Subject disputes the accuracy of the Personal Data being processed. In this case, the restriction shall apply for a period that allows the Data Controller to verify the accuracy of the Personal Data. The Data Controller shall mark the Personal Data it processes if the Data Subject disputes its correctness or accuracy, but the incorrectness or inaccuracy of the disputed Personal Data cannot be clearly established.  

 

The Data Subject may request that the Data Controller restrict the processing of their Personal Data even if the processing is unlawful, but the Data Subject objects to the erasure of the processed Personal Data and instead requests that its use be restricted. 

 

The Data Subject may also request that the Data Controller restrict the processing of their Personal Data if the purpose of the processing has been fulfilled, but the Data Subject requires the Data Controller to continue processing such data for the purpose of asserting, exercising, or defending legal claims. 

 

19.7. The Data Subject may request that the Data Controller provide the Data Subject with the Personal Data provided by the Data Subject and processed by the Data Controller by automated means in a structured, commonly used, machine-readable format and/or transfer such data to another data controller. 

 

19.8. If the data controller does not comply with the Data Subject’s request for rectification, blocking, or erasure, it shall, within 25 days of receiving the request, provide in writing the reasons for rejecting the request for rectification, blocking, or erasure. In the event of a rejection of a request for rectification, erasure, or blocking, the data controller shall inform the Data Subject of the possibility of seeking judicial remedy and of filing a complaint with the National Authority for Data Protection and Freedom of Information.  

 

19.9. The Data Subject may submit the above statements regarding the exercise of their rights using the contact information for the data controller provided in Section 2. 

 

19.10. The Data Subject may also file a complaint directly with the National Authority for Data Protection and Freedom of Information (address: 1055 Budapest, Falk M. u. 9-11; phone: +3630 683-5969; email: ugyfelszolgalat@naih.hu; website: www.naih.hu). In the event of a violation of the Data Subject’s rights, the Data Subject is entitled to bring a lawsuit before a court pursuant to Section 22(1) of the Information Act. The court has jurisdiction over the case. The lawsuit may also be filed—at the Data Subject’s discretion—before the court having jurisdiction over the Data Subject’s place of residence or place of stay. Upon request, the Data Controller shall provide the Data Subject with detailed information regarding the possibilities and means of legal remedy. 

 

20. Scope and Amendment of the Privacy Notice 

20.1. This Privacy Notice enters into force on the date indicated in the header for an indefinite period. Previous versions may be obtained from the Data Controller by sending a message to the email address provided in Section 3 above. 

 

20.2. The Data Controller reserves the right to amend this Notice at any time by its unilateral decision, which it will publish on the Website. Therefore, please visit the Website periodically to stay up to date.  

bottom of page