for visitors and customers of the datalistshop.com online store, and for data subjects whose data has been collected from public websites
Version: 1.0 · Effective: September 28, 2026 · Prepared: September 28, 2026
This notice has been prepared pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation, hereinafter the GDPR) and Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (Infotv.). This English text is a translation; in the event of any discrepancy, the Hungarian version prevails.
1. Who processes your data?
1.1. The controller
| Name | dr. Tóth András E.V. (Hungarian sole proprietor) |
|---|---|
| Registered office and mailing address | 1149 Budapest, Nagy Lajos Király útja 125. B lph. 2em 1. a., Hungary |
| Registration number | 52016532 |
| Tax number | 68626116-1-22 |
| Online store | https://datalistshop.com |
| General email | drtothandras@gmail.com |
| Data protection requests | adatvedelem@datalistshop.com |
| Telephone | +36 30 737 5612 |
| Data protection officer | We have not appointed a data protection officer, because none of the cases set out in Article 37(1) GDPR applies: we are not a public authority, our processing does not involve regular and systematic monitoring of data subjects (we do not track behavior or build personal profiles), and it does not extend to the special categories of data or criminal offence data referred to in Articles 9 and 10. We handle data protection matters ourselves, at adatvedelem@datalistshop.com. |
In this notice, “we” means the controller, and “you” means the data subject (the person whose data is concerned).
1.2. Who is this notice for?
It covers two separate processing activities:
- Part A: visitors to the online store, people requesting samples, newsletter subscribers, and customers (or the contact persons of customer companies) — they provide their data themselves.
- Part B: people whose data publicly disclosed on their own website (e.g., a business email address or telephone number) has been included in the databases we compile and sell. If you arrived here because of your website’s address, this part is for you.
A) Visitors and customers of the online store
A1. What data do we process, for what purpose, on what legal basis, and for how long?
| Purpose | Data processed | Legal basis | Retention |
|---|---|---|---|
| Order and performance of the contract (providing the download of the purchased list) | the customer company’s name, tax number, and billing address; the contact person’s name, email address, and telephone number; the order details | performance of a contract — Article 6(1)(b) GDPR; for the data of the customer company’s contact person, legitimate interest in performing the contract concluded with the customer — Article 6(1)(f) | 5 years from the termination of the contract (the general limitation period under the Hungarian Civil Code) |
| Invoicing and accounting | the mandatory content of the invoice | legal obligation — Article 6(1)(c) GDPR; Section 169 of Act C of 2000 on Accounting; Act CXXVII of 2007 on Value Added Tax | 8 years |
| Payment (card payment through Barion) | the transaction ID, amount, and time, and the customer’s name and email address; card data never reaches us | performance of a contract — Article 6(1)(b) GDPR | the same as for invoicing (8 years); at Barion, as set out in Barion’s own privacy notice |
| Proof of acceptance of the Terms and Conditions, the license terms, and the declaration on the right of withdrawal | the fact and time of acceptance, and the order ID | legitimate interest (proof of legal claims) — Article 6(1)(f) GDPR | 5 years from the termination of the contract |
| Verifying download entitlement and detecting unauthorized disclosure (unique marking under Section 5.6 of the Terms and Conditions) | the time and number of downloads, IP address, the unique marking of the issued copy, and its assignment to the customer | legitimate interest (protection of copyright and database maker’s rights) — Article 6(1)(f) GDPR | download log (IP address): 1 year; record of copy markings: 5 years from the termination of the contract |
| Sending the free sample file | name, company name, email address | at your request, as a step prior to entering into a contract — Article 6(1)(b) GDPR | 1 year from sending the sample |
| Newsletter (information about our products and new lists) | email address, name, company name; data on email opens and link clicks; truncated IP address | consent — Article 6(1)(a) GDPR; Section 6 of Act XLVIII of 2008 on the Essential Conditions of and Certain Restrictions on Commercial Advertising Activities | until consent is withdrawn (unsubscription); the unsubscribed address remains on a suppression list so that it is not added again |
| Contact and customer service | name, email address, telephone number, content of the message | legitimate interest (responding to the inquiry) — Article 6(1)(f) GDPR | 1 year from closing the matter |
| Complaint handling | the complainant’s data, the complaint, and the response | legal obligation — Article 6(1)(c) GDPR; Section 17/A of Act CLV of 1997 on Consumer Protection | 5 years |
| Operation and security of the website (hosting logs, blocking attacks) | IP address, technical data of the browser and device, time of the visit, the page opened | legitimate interest (secure operation of the service) — Article 6(1)(f) GDPR | up to 90 days |
| Fraud prevention in payments (Barion Pixel, basic version) | technical data of browsing and the purchase process, device identifier | processed by Barion Payment Zrt. as an independent controller, on the basis of its own legitimate interest (Barion Privacy Notice, Section 5.4); we do not process personal data in this context. The basic Barion Pixel is a strictly necessary cookie. | as set out in Barion’s own privacy notice |
| Visitor statistics (Google Analytics) | cookies and similar identifiers, visit data, truncated IP address | consent — Article 6(1)(a) GDPR (given in the cookie banner) | 14 months |
| Ad measurement and retargeting (Google Ads, Meta Pixel) | cookies and similar identifiers, pages visited, the fact of a sample request or purchase | consent — Article 6(1)(a) GDPR (given in the cookie banner) | until consent is withdrawn, and at most for the period set by the provider |
Providing the data required for an order is a condition of entering into the contract: without it, we cannot fulfill the order. Subscribing to the newsletter and accepting statistics or advertising cookies is voluntary and is not a condition of purchase.
A2. Cookies
We use cookies necessary for the website to function without consent; statistics and advertising cookies are used only after you give your consent in the cookie banner. You can withdraw or change your consent at any time in the cookie settings at the bottom of the page. A detailed list of cookies: https://datalistshop.com/cookies/.
A3. About the newsletter
Subscribing to the newsletter is voluntary. You can unsubscribe with one click at the bottom of every email; after you unsubscribe, we place your address on a suppression list so that a later import does not add it again. We measure email opens and link clicks in order to improve our communications. The measurement takes place on our own server operated in Hungary (t.datalistshop.com), and IP addresses are stored in truncated form.
A4. Who has access to your data? — processors and recipients
| Who | What they do | Role |
|---|---|---|
| Profi Tárhely Kft. — Szolnoki út 23., 6000 Kecskemét, Hungary; ugyfelszolgalat@profitarhely.hu | hosting of the website and the downloadable files | processor |
| Barion Payment Zrt. — Irinyi József utca 4–20., Building B, 2nd floor, 1117 Budapest, Hungary; company reg. no. 01-10-048552; https://www.barion.com | card payments, Barion Pixel (fraud prevention) | independent controller (for both payments and the Barion Pixel) |
| KBOSS.hu Kft. (Számlázz.hu) — Záhony utca 7., 1031 Budapest, Hungary; company reg. no. 01-09-303201 | issuing and storing electronic invoices | processor |
| Makroteam Kft. — Pesti út 237., 1173 Budapest, Hungary | bookkeeping and tax returns (data from invoices and accounting documents) | processor |
| Brevo SAS — 106 boulevard Haussmann, 75008 Paris, France | delivery of the newsletter, order emails, and sample-request emails | processor |
| Google Ireland Limited — Gordon House, Barrow Street, Dublin 4, Ireland | Google Analytics statistics, Google Ads measurement; email (Gmail) and storage of backups (Google Drive) | processor; independent controller for advertising data |
| Meta Platforms Ireland Limited — Merrion Road, Dublin 4, D04 X2K5, Ireland | Meta Pixel (measurement of Facebook/Instagram ads) | joint controller for the collection and transmission of data, and independent controller thereafter |
| Defiant Inc. (Wordfence) — 1700 Westlake Ave N Ste 200, Seattle, WA 98109, USA | protection of the website against attacks (checking IP addresses) | processor |
We do not sell personal data to third parties and do not disclose it beyond the providers above and our legal obligations (e.g., requests from authorities). Customer data is not included in the database described in Part B.
A5. Transfers outside the European Union
With the services of Google, Meta, and Defiant, data may also be transferred to the United States. Such transfers take place on the basis of the adequacy decision under the EU–U.S. Data Privacy Framework or the standard contractual clauses adopted by the European Commission (Articles 45 and 46 GDPR).
B) Data collected from public websites
This part is for people whose contact details published on their website have been included in our database. We did not collect this data from you, so we provide this information on this public page in accordance with Article 14 GDPR.
B1. Where does the data come from?
Using an automated program (a crawler), we visit publicly accessible websites — typically the home page and the pages containing legally mandated disclosures (legal notice, contact, terms and conditions, privacy notice) — and collect the data publicly disclosed there. We compile the list of domains from publicly available sources.
- We do not access password-protected pages, do not circumvent access restrictions, and do not purchase data from third parties.
- The crawler identifies itself, respects the restrictions in the website’s robots.txt file, and operates with a low load.
- For each data item, we store the address of the page it comes from.
B2. What data do we process?
As published on the website: the name, registered office, tax number, and company or registration number of the business or operator, its email address and telephone number, the website address, the e-commerce or website platform used, the product categories offered, the website’s own description, and the address of the page from which the data comes.
This is typically business data. It qualifies as personal data where it relates to a natural person — for example, the name and contact details of a sole proprietor, or an email address containing a personal name (lastname.firstname@…).
We do not process special categories of data (e.g., health, religious, or political data), financial data, identity document numbers, or visitors’ IP addresses or browsing histories. We do not create profiles and do not make automated decisions about natural persons. We do not record email addresses and telephone numbers that appear on more than 20 websites (typically hosting or agency contact details).
B3. For what purpose and on what legal basis?
| Purpose | Legal basis |
|---|---|
| surveying the Hungarian and European market for online stores and websites (e.g., how many online stores operate, and on which platforms) | legitimate interest — Article 6(1)(f) GDPR |
| compiling and selling a business directory (data list) for businesses | legitimate interest — Article 6(1)(f) GDPR |
Our legitimate interest is to produce market information useful to businesses from publicly disclosed business data. Before starting the processing, we carried out a legitimate interest assessment, a summary of which we will send you upon request.
B4. Who receives the data?
- The data list may be purchased only by businesses (under our Terms and Conditions). The purchaser becomes an independent controller of the data and undertakes by contract to use it only in compliance with the GDPR and advertising rules — among other things, not to send advertising to natural persons without their prior consent, and to inform the data subjects itself in accordance with Article 14 GDPR.
- The purchaser may not transfer or publish the list.
- The lists do not contain the names of representatives or contact persons.
B5. How long do we keep it?
We keep the data for 24 months from the last crawl; after that, it is deleted or overwritten by a newer crawl. Only the data needed to identify the request — the website address or the deleted contact detail — remains on the suppression list (B6), and only for as long as the suppression list serves its purpose.
B6. Objection and erasure — what we do when you ask
If you do not want us to process your data, write to adatvedelem@datalistshop.com and include your website address (domain) and the email address or telephone number concerned.
- We carry out your request within 72 hours: we delete your data from our database and send you a confirmation.
- We place the website or contact detail on a suppression list so that a later crawl does not collect it again.
- If the data was included in a list already sold, we notify the purchasers who bought it, who are obliged under our Terms and Conditions to delete it from their own copies as well.
B7. Why didn’t you receive a separate notification?
We collected the data not from you but from your public website. In such cases, Article 14 GDPR requires information to be provided, but contacting the operators of several hundred thousand websites individually would involve a disproportionate effort. Therefore, in accordance with Article 14(5)(b) GDPR, we publish this public notice and keep it continuously available; our crawler also refers to this page.
C) General provisions
C1. Your rights
| Right | What it means |
|---|---|
| Access (Article 15 GDPR) | you may ask whether we process data about you and, if so, which data, for what purpose, from what source, and for how long |
| Rectification (Article 16) | you may request the correction of inaccurate data |
| Erasure (Article 17) | you may request the erasure of your data if it is no longer needed, if you withdraw your consent, or if your objection has been upheld |
| Restriction (Article 18) | you may request that we only store the data but not use it — e.g., for the duration of a dispute |
| Data portability (Article 20) | you may obtain the data you provided, processed on the basis of a contract or consent, in a machine-readable format |
| Objection (Article 21) | you may object at any time to processing based on legitimate interest; in the case of direct marketing, after your objection we no longer use the data for that purpose |
| Withdrawal of consent (Article 7) | you may withdraw your consent at any time; this does not affect the lawfulness of processing before the withdrawal |
You can send your request to adatvedelem@datalistshop.com. We respond within one month at the latest (Article 12 GDPR); where necessary, we may ask you to verify your identity.
C2. Remedies
If you believe that the processing of your data is unlawful, you may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH; Falk Miksa utca 9–11., 1055 Budapest, Hungary; mailing address: 1363 Budapest, Pf. 9.; telephone: +36 1 391 1400; email: ugyfelszolgalat@naih.hu; https://naih.hu), or bring an action before a court; you may also bring the action before the regional court (törvényszék) of your place of residence or stay. We ask that you contact us first so that we can resolve your complaint quickly.
C3. Data security and personal data breaches
We receive data over an encrypted connection (HTTPS), protect access with passwords and two-factor authentication, and make regular backups. In the event of a personal data breach that poses a risk, we notify the NAIH within 72 hours and, where the risk is high, we also inform the data subjects (Articles 33–34 GDPR).
C4. Automated decision-making
We do not make automated decisions about, or create profiles of, natural persons. The classification described in Part B (e.g., whether a website is an online store) relates to the website, not to a person.
C5. Changes to this notice
We may amend this notice if the law or our processing changes; the version in effect is always available on this page, and we will send previous versions upon request. The contractual terms of purchase are set out in the Terms and Conditions: https://datalistshop.com/terms-and-conditions/.
This notice is version 1.0, effective as of September 28, 2026.