top of page

隱私政策

Back&Rosta,Ltd.隐私权政策{2020年4月27日更新}

 

本隐私政策描述了当您访问www.the-magic.wall.com(以下简称“网站”)或从中进行购买时如何收集,使用和共享您的个人信息。

 

我们收集的个人和设备信息

 

当您访问本网站时,我们会自动收集有关您设备的某些信息,包括有关您的Web浏览器,IP地址,时区以及设备上安装的某些Cookie的信息。此外,在您浏览网站时,我们会收集有关您查看的各个网页或产品的信息,哪些网站或搜索字词将您引到了网站,以及有关您如何与网站互动的信息。我们将此自动收集的信息称为“设备信息”。

 

我们使用以下技术收集设备信息:

 

-“ Cookie”是放置在设备或计算机上的数据文件,通常包含匿名唯一标识符。有关cookie以及如何禁用cookie的更多信息,请访问http://www.allaboutcookies.org。

-“日志文件”跟踪站点上发生的操作,并收集数据,包括您的IP地址,鲮览器类型,Internet服务提供商,参考/退出页面以及日期/时间戳。

-“网络信标”,“标签”和“像素”是用于记录有关您如何浏览网站的信息的电子文件。

 

此外,当您订阅我们的由件列表或填写我们的联系表时,我们可能会收集其他个人信息,例如姓名,电子由件,电话号码,国家和公司。

 

 

我们如何使用您的个人和设备信息?

 

我们使用收集到的设备信息来帮助我们筛查潜在的风险和欺诈行为(特别是您的IP地址),并且更广泛地说是改善和优化我们的网站(例如,通过生成有关客户如何浏览和互动的分析)网站,并评估我们的营销和广告活动的成功)。

 

如果您已订阅我们的由件列表或通过其他方式选择了我们,则我们会将您的个人信息用于定期交流,其中可能包括每月新闻通讯,产品更新,特价优惠等。

 

共享您的个人和设备信息

 

我们确实与第三方共享您的一些个人和设备信息。例如,我们使用Google Analytics(分析)来帮助我们了解客户如何使用本网站-您可以在此处阅读有关Google如何使用您的个人信息的更多信息:https://www.google.com/intl/zh-CN/policies/privacy/ 。我们还利用Mailchimp与已订阅我们由件列表的人进行电子由件通信。您可以在以下位置找到MailChimp的隐私政策: https : //mailchimp.com/legal/privacy/ 。目前,我们的网站託管在Wix.com上,因此“个人和设备”信息也安全地存储在其服务器上。可以在以下位置找到Wix.com隐私政策: https : //www.wix.com/about/privacy 。

 

最后,我们也可能会分享您的个人信息,以遵守使用的法律和法规,回应传票,搜查令或我们收到的信息的其他合法请求,或以其他方式保护我们的权利。

 

请注意,当您从浏览器中看到“不跟踪”信号时,我们不会改变我们网站的数据收集和使用惯例。

 

如果您是欧洲居民,则有权访问我们持有的有关您的个人信息,并要求更正,更新或删除您的个人信息。如果您想行使此权利,请通过以下联系信息与我们联系。

 

此外,如果您是欧洲居民,我们注意到我们正在处理您的信息,以便履行与您的合同(例如,如果您通过本网站订阅我们的由件列表),或以其他方式追求我们列出的合法商业利益以上。此外,请注意,您的信息将被转移到欧洲以外,包括加拿大和美国。

 

未成年人

本网站不适用于18岁以下的个人。

 

变化

我们可能会不时更新本隐私政策,以反映(例如)我们的做法发生变化或出于其他运营,法律或法规方面的原因。

 

联系我们

有关我们的隐私惯例的更多信息,如果您有任何疑问或想要投诉,请通过电子由件info@the-magic-wall.com与我们联系,或使用以下提供的详细信息与我们联系:

 

Back&Rosta,Ltd.

StromfeldAurélút28,布达佩斯,BU,1124,匈牙利

Company Name
Registered Office
Service Provided

Back and Rosta Information Technology (Shanghai) Ltd. 

No. 111–113 Huashi Road, Xuhui District, 200235 Shanghai, China

Website operation 

Shanghai Back & Rosta Cultural Development Co. Ltd. 

NO.111-113, Huashi Road Xuhui District, 200235 Shanghai,China 

Exhibition coordination 

Magic Wall LLC 

30 N Gould St #42881 
Sheridan, WY 82801 USA 

Sales and marketing

Back and Rosta GmbH 

Schumanngasse 22/7. 
Vienna 1180  Austria 

Sales and marketing

16. Third-Party Service Providers  

 

In the course of operating the Website, the Data Controller engages Third-Party Service Providers, with whom the Data Controller cooperates.  

With regard to Personal Data processed in the systems of Third-Party Service Providers, the provisions set forth in the Third-Party Service Providers’ own privacy policies shall apply. The Data Controller will do everything in its power to ensure that the External Service Provider processes the Personal Data transferred to it in accordance with the law and uses such data exclusively for the purposes specified by the Data Subject or set forth below in this Notice. 

The Data Controller shall inform Data Subjects about data transfers to Third-Party Service Providers within the framework of this Notice. 

 

17. Data Security and Access to Data 

 

The Data Controller ensures the security of the data, takes the technical and organizational measures, and establishes the procedural rules necessary to enforce applicable laws and data and confidentiality protection rules. The Data Controller protects the data with appropriate measures against unauthorized access, alteration, transmission, disclosure, deletion, or destruction, as well as against accidental destruction or damage, and against becoming inaccessible due to changes in the technology used.  

 

The Data Controller maintains records of the data it processes in accordance with applicable laws, ensuring that the data is accessible only to those employees and other persons acting on behalf of the Data Controller (data processors) who need it to perform their job duties or tasks. The Data Controller’s employees shall perform individual searches or specific operations on the data only at the request of the Data Subject or when necessary for the provision of the service.  

 

When defining and implementing measures to ensure data security, the Data Controller takes into account the current state of the art. The Data Controller selects, from among several possible data processing solutions, the one that ensures a higher level of protection for personal data, unless this would entail disproportionate difficulty.  

 

As part of its IT security responsibilities, the Data Controller shall ensure, in particular: 

  • Measures to protect against unauthorized access, including the protection of software and hardware devices, as well as physical security (access control, network security); 

  • Measures to ensure the recoverability of data files, including regular backups and the separate, secure management of copies (mirroring, backup); 

  • Protection of data files against viruses (virus protection); 

  • The physical protection of data files and the devices on which they are stored, including protection against fire, water damage, lightning strikes, and other natural disasters, as well as the recoverability of data damaged as a result of such events (archiving, fire protection). 

Employees and other persons acting on behalf of the Data Controller are required to securely store and protect data storage media containing personal data that they use or possess—regardless of the method of data recording—against unauthorized access, alteration, transmission, disclosure, deletion, or destruction, as well as against accidental destruction and damage.  
 
The Data Controller operates the electronic registry using software that complies with data security requirements. The software ensures that data is accessed only for specific purposes, under controlled conditions, and only by those individuals who need it to perform their duties. 

 

18. Duration of Data Processing 

 

In addition to the specific provisions described above for each data processing operation, the Data Controller shall delete personal data if  

 

a) the processing is unlawful; 

If it becomes apparent that the data is being processed unlawfully, the Data Controller shall delete it without delay.  

 

b) the Data Subject requests the erasure of their data (except for data processing based on law);  

The Data Subject may request the erasure of data processed on the basis of the Data Subject’s voluntary consent. In this case, the Data Controller shall erase the data. Erasure may be refused only if the processing of the data is authorized by law. The Data Controller shall in all cases provide information regarding the refusal of the erasure request and the legal basis permitting the data processing.  

 

c) the data is incomplete or incorrect—and this condition cannot be lawfully remedied—provided that the law does not preclude erasure; 

 

d) the purpose of data processing has ceased to exist, or the statutory retention period for the data has expired;  

Erasure may be refused (i) for the purpose of exercising the right to freedom of expression and the right to information, or (ii) if the processing of Personal Data is authorized by law; and (iii) for the purpose of asserting, exercising, or defending legal claims.  

 

In all cases, the Data Controller shall notify the Data Subject of the refusal of a request for erasure, specifying the reason for the refusal. Once a request for the erasure of personal data has been fulfilled, the previous (erased) data cannot be restored. 

 

 

Since the Data Controller provides ongoing services to the Data Subject, the relationship between the parties is not subject to a time limit. Based on the foregoing—in the absence of a request from the Data Subject—the Data Controller will process the data for as long as the relationship between the Data Controller and the Data Subject exists and for as long as the Data Controller is able to provide services to the Data Subject.  

The Data Controller will delete all other data if it is clear that the data will not be used in the future, meaning that the purpose of data processing has ceased to exist.  

 

e) it has been ordered by a court or the National Authority for Data Protection and Freedom of Information: 

  

If a court or the National Authority for Data Protection and Freedom of Information issues a final and binding order to delete the data, the Data Controller shall carry out the deletion.  

Instead of erasure, the Data Controller—after informing the Data Subject—shall block the personal data if the Data Subject so requests, or if, based on the information available to the Data Controller, it can be presumed that erasure would harm the Data Subject’s legitimate interests. Personal data blocked in this manner may be processed only for as long as the purpose of data processing that precluded the erasure of the personal data remains valid. The Data Controller shall mark the personal data it processes if the Data Subject disputes its correctness or accuracy, but the incorrectness or inaccuracy of the disputed personal data cannot be clearly established.  

In the case of data processing required by law, the provisions of the applicable law shall govern the erasure of data.  

 

In the event of erasure, the Data Controller shall render the data unfit for identification. If required by law, the Data Controller shall destroy the data medium containing the personal data. 

 

19. Rights of Data Subjects and Their Enforcement 

 

19.1. Upon initial contact, the Data Controller shall inform the Data Subject about the processing of their data by drawing their attention to this privacy notice and providing access to it on the Website. The Data Subject is also entitled at any time to request information regarding the processing of their data.  

 

At the Data Subject’s request, the Data Controller shall provide information regarding the Data Subject’s data processed by the Data Controller or by a data processor commissioned by the Data Controller or in accordance with its instructions, including the source of such data, the purpose, legal basis, and duration of the data processing, as well as the name, address, and activities of the data processor related to the data processing, the circumstances and effects of a data breach and the measures taken to address it; and—in the event of a transfer of the Data Subject’s Personal Data—the legal basis for the transfer and the recipient of the data. The Data Controller is obligated to provide the information in writing, in an easily understandable form, at the Data Subject’s request, as soon as possible after the request is submitted, but no later than 25 days thereafter. This information is provided free of charge if the person requesting the information has not previously submitted a request for information regarding the same set of data in the current year. In other cases, a fee may be charged. Any fee already paid must be refunded if the data was processed unlawfully or if the request for information led to a correction.  

 

19.2. The Data Subject may request that the Data Controller correct any inaccurate personal data. If the data to be corrected is used for regular data disclosures, the Data Controller shall, if necessary, notify the recipient of the data disclosure of the correction and shall inform the Data Subject that they must also request the correction from other data controllers.  

 

19.3. Except for data processing required by law, the Data Subject may request the erasure of their personal data. The Data Controller shall inform the Data Subject of the erasure.  

 

19.4. The Data Subject may object to the processing of their personal data as specified in the GDPR.  

 

19.5. The Data Subject may submit a request for access, rectification, or erasure in writing, by mail addressed to the Data Controller’s registered office or business location, or by email sent to the email address provided in Section 3 above.  

 

19.6. The Data Subject may request that the Data Controller restrict the processing of their Personal Data if the Data Subject disputes the accuracy of the Personal Data being processed. In this case, the restriction shall apply for a period that allows the Data Controller to verify the accuracy of the Personal Data. The Data Controller shall mark the Personal Data it processes if the Data Subject disputes its correctness or accuracy, but the incorrectness or inaccuracy of the disputed Personal Data cannot be clearly established.  

 

The Data Subject may request that the Data Controller restrict the processing of their Personal Data even if the processing is unlawful, but the Data Subject objects to the erasure of the processed Personal Data and instead requests that its use be restricted. 

 

The Data Subject may also request that the Data Controller restrict the processing of their Personal Data if the purpose of the processing has been fulfilled, but the Data Subject requires the Data Controller to continue processing such data for the purpose of asserting, exercising, or defending legal claims. 

 

19.7. The Data Subject may request that the Data Controller provide the Data Subject with the Personal Data provided by the Data Subject and processed by the Data Controller by automated means in a structured, commonly used, machine-readable format and/or transfer such data to another data controller. 

 

19.8. If the data controller does not comply with the Data Subject’s request for rectification, blocking, or erasure, it shall, within 25 days of receiving the request, provide in writing the reasons for rejecting the request for rectification, blocking, or erasure. In the event of a rejection of a request for rectification, erasure, or blocking, the data controller shall inform the Data Subject of the possibility of seeking judicial remedy and of filing a complaint with the National Authority for Data Protection and Freedom of Information.  

 

19.9. The Data Subject may submit the above statements regarding the exercise of their rights using the contact information for the data controller provided in Section 2. 

 

19.10. The Data Subject may also file a complaint directly with the National Authority for Data Protection and Freedom of Information (address: 1055 Budapest, Falk M. u. 9-11; phone: +3630 683-5969; email: ugyfelszolgalat@naih.hu; website: www.naih.hu). In the event of a violation of the Data Subject’s rights, the Data Subject is entitled to bring a lawsuit before a court pursuant to Section 22(1) of the Information Act. The court has jurisdiction over the case. The lawsuit may also be filed—at the Data Subject’s discretion—before the court having jurisdiction over the Data Subject’s place of residence or place of stay. Upon request, the Data Controller shall provide the Data Subject with detailed information regarding the possibilities and means of legal remedy. 

 

20. Scope and Amendment of the Privacy Notice 

20.1. This Privacy Notice enters into force on the date indicated in the header for an indefinite period. Previous versions may be obtained from the Data Controller by sending a message to the email address provided in Section 3 above. 

 

20.2. The Data Controller reserves the right to amend this Notice at any time by its unilateral decision, which it will publish on the Website. Therefore, please visit the Website periodically to stay up to date.  

联系我们 | 隐私政策 | 使用条款 |

  • LinkedIn
  • Facebook
  • YouTube

© 2024 佰路得信息技术有限公司

bottom of page