This English version is an informative translation of the Hungarian Privacy Notice. In the event of any discrepancy or difference in interpretation between the Hungarian and English versions, the Hungarian version shall prevail.
1. Purpose of this notice
With this notice, we wish to inform the visitors of the website and assure them that, in the course of operating and maintaining the website, the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), as well as the provisions of Act CXII of 2011 on informational self-determination and freedom of information (Hungarian Information Act), relating to the processing and protection of personal data of natural persons, are fully observed.
This notice explains how the website, its operator and data controller collect, store and process personal data, and how we ensure that Data Subjects may exercise their rights of informational self-determination in relation to their personal data, as provided by EU and Hungarian legislation.
Ruppert Borház Borászati Kft. reserves the right to amend this privacy notice unilaterally at any time, and shall inform customers of such amendments through the webshop interface. This Privacy Notice is effective from 28 July 2026.
2. Website URL
www.ruppert.hu
3. Operator and data controller
The operator and data controller of the website:
Company name: Ruppert Borház Borászati Kft.
Company registration number: 02-09-081649
Tax number: 14928899-2-02
Registered seat: 7814 Babarcszőlős, Táncsics Mihály u. 34.
Email: ruppert@ruppert.hu
Telephone: +36 70 7783735
Registering court: Company Registry Court of the Pécs Regional Court
Represented by: Ruppert Ákos
Hosting provider: Impressive.hu Informatikai Szolgáltató Kft.
Program and content maintenance: Scitus Group Ltd.
4. Purpose of the website
The presentation of products offered by Ruppert Borház Borászati Kft. to interested parties and potential customers, as well as the processing of orders placed by customers and the delivery of products to them;
Online information for existing customers, and providing a contact option for potential customers;
Acquiring new customers;
Providing online public access to public-interest information related to our company’s activities.
5. Basic GDPR definitions
User: a natural person who views the website (Visitor), or who provides personal data for the purpose of using a service of the website (User).
Data Subject: a natural person whose personal data are requested, recorded, stored, processed and used by the website.
Personal data: any information and data by which the Data Subject, as a natural person, can be identified directly or indirectly.
Data processing: any operation performed on personal data, such as collecting, recording, storing, using, transmitting or deleting data.
Data Controller: a natural or legal person or an organisation without legal personality that, alone or jointly with others, determines and implements decisions regarding the purposes and means of data processing, or has such decisions implemented by a data processor engaged by it.
Data Processor: a natural or legal person or an organisation without legal personality that processes personal data transferred by the Data Controller in the manner determined by the Data Controller and uses them for the specified purpose.
Personal data breach: a breach of data protection security that results in the accidental or unlawful destruction, loss, alteration or unavailability of collected, stored and processed personal data, or in unauthorised access to, unauthorised use of, or disclosure of such data.
6. Collection and processing of data
6.1. Anonymous data collection during website visits
The public content of our website may be freely viewed by anyone. We do not request any personal data from visitors in order to view the website. However, like every website, ours also uses small technical codes (cookies), which are stored for a shorter or longer period on the device used by the visitor for browsing (computer or mobile device) and on the web server when the pages are viewed.
Cookies perform partly technical and partly traffic-statistical functions. During their use, no information suitable for identifying visitors personally is generated, and the cookies are automatically deleted after a certain period.
Through the information bar displayed on our website, we draw the attention of all visitors to the use of cookies on the first page viewed, requesting their consent to the use of cookies or enabling them to disable the use of cookies for the relevant visit.
In addition, every visitor has the option to set a global prohibition of cookie use in their own browser, applicable to all websites visited. In this case, the browser will not accept or store cookies from any website. Enabling or disabling the use of cookies is therefore expressly in the hands of visitors and users. Each visitor can set the enabling or disabling of cookies, as well as the deletion of cookies previously placed on their device, in their own browser.
6.2. Viewing embedded content from other websites
It may occur that certain elements of the content available on our website originate from external sources, i.e. from other websites (e.g. embedded YouTube videos, Facebook posts, articles, images, etc.). Such embedded content behaves as if the visitor had viewed the website where the embedded element is available in its original form.
The websites used as sources are likely to collect statistical data about the viewing of such content, using cookies or third-party tracking codes (e.g. from Google), in order to obtain data on visitor interest in the embedded content, the number of views and the frequency of views.
In such cases, the operator of the original source website is responsible for the statistical data collection performed by the external source and for the lawful processing of data obtained through cookies or tracking codes. The statistical data generated are not suitable for identifying the visitors of our website personally.
6.3. Web analytics tools
For traffic analysis purposes, our website collects statistical data and technical information relating to the operation of the website using official Google analytics tools. These do not collect personal data, but provide anonymous statistics on the geographical distribution and interests of visitors, search keywords, pages viewed and visitor behaviour, such as the proportion of returning visitors and the time spent on the website.
Our website uses the following Google tools:
Google Analytics
Google Analytics prepares statistical reports on website traffic. It helps analyse traffic and thereby supports the development and optimisation of the website. It shows the search terms through which visitors found the website, the geographical areas they arrived from, how much time they spent on the website and what they were most interested in.
Google Analytics does not collect data necessary to identify visitors personally.
Google Analytics first-party cookies are created when the user visits the webshop, because the Google Analytics tracking code has been installed on our portal. The cookies are stored on the user’s device for a maximum of 2 years from the time indicated above. Further information on this is available by clicking here.
Google Search Console
Google Search Console (formerly Google Webmaster Tools) is a tool for webmasters. It helps determine how many pages Google has indexed, how the website appears in Google search results, whether there are programming errors on the website, and what needs to be done for search engine optimisation and successful website operation. It does not collect personal data.
Further information: www.reelweb.hu
6.4. Online marketing tools
Google Ads (formerly AdWords) and Facebook advertisements
Google Ads is an online advertising system based on Google Search. It helps businesses, merchants and service providers reach more easily those interested users in Google Search who are looking for the products or services they offer. Advertisers’ text advertisements appear in Google Search, while image banner advertisements appear on websites whose owners have agreed with Google to display Google advertisements on their own websites. In order for advertisers to “find” their target audiences on the internet, the technical and statistical data collected by Google provide assistance.
Advertisers using Google Ads may place two types of Google tracking codes in the source code of their own website or webshop in relation to interested visitors who view their website. One is the remarketing tracking code. This tracking code places a special reminder cookie on the visitor’s computer and on Google’s server when a visitor views the advertiser’s website using remarketing code after clicking on a Google Ads advertisement. The cookie does not contain personal data; it only marks the visitor’s computer or mobile device, and later, based on this, displays image banner advertisements to that person on other websites in relation to the product or service previously viewed on the advertiser’s website. The remarketing code enables advertisers using this option to “find” their interested users later on the internet with banner advertisements and product or service offers.
Our website also uses Google remarketing tracking code, as we also offer our services to interested users through Google advertisements.
The other tracking code is the conversion tracking code. Google’s conversion tracking code enables webshops using Google’s advertising system to count how many online orders they have received thanks to their advertisements, and on this basis to optimise the effectiveness of their advertisements. Since our website has an online ordering function, we use Google conversion tracking code. AdWords cookies are stored for 90 days after the user’s visit to the webshop.
On our website, we use the so-called “Facebook Pixel” operated by Facebook Inc. (1 Hacker Way, Menlo Park, CA 94025, USA) and Facebook Ireland Ltd. (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland) (“Facebook”). With the help of the Facebook Pixel, we can analyse the effectiveness of our advertisements appearing on Facebook for statistical and market research purposes, as we can learn whether users reached our website by clicking on a Facebook advertisement. Facebook directly embeds the Facebook Pixel when our website is opened, which may place a cookie on your device. If you later log in to Facebook, or visit Facebook pages while logged in, your visit to our website may be registered in your profile. The data obtained about you are anonymous for us, meaning that we cannot identify you based on them. However, Facebook stores and processes the data, and they may therefore be linked to the relevant user profile. Facebook processes the data according to its own privacy policy. Further information on the operation of the remarketing pixel and on the display of Facebook advertisements in general is available in Facebook’s privacy policy at: https://www.facebook.com/policy.php.
You may prohibit the recording of data by the Facebook Pixel and the use of your data for displaying Facebook advertisements. To do this, open the page created by Facebook and follow the instructions regarding personal advertising settings: https://www.facebook.com/settings?tab=ads. The US page is available at: http://www.aboutads.info/choices/ and the EU page at: http://www.youronlinechoices.com/. The settings are platform-independent, meaning that they apply both to desktop computers and mobile devices.
The purpose of the data processing described in sections 6.1 to 6.4 of this Privacy Notice is: identifying users, distinguishing users from each other, identifying user sessions, storing the data provided during such sessions, preventing data loss, performing web analytics measurements, ensuring the proper operation of the website, improving the user experience and displaying advertisements to users.
The legal basis of the data processing is the consent of the Data Subject, given by the user by clicking the “I consent” / “Accept” button in the pop-up cookie notice, based on the appropriate information provided in this notice (pursuant to Section 5(1)(a) of the Information Act and Article 6(1)(a) of the GDPR).
The scope of data processed: identification number, date, time and the previously visited page. Data are stored electronically, and no data transfer takes place.
6.5. Registration
Please note that only one registration may belong to one email address. The Data Subject bears all responsibility for any damage arising from providing incorrect or false data. Ruppert Borház Borászati Kft. reserves the right to delete obviously incorrect or false registrations, and in case of doubt to verify the authenticity of the data provided. We expressly draw attention to the fact that Data Subjects are fully responsible for the accuracy and up-to-date nature of the data. Accordingly, if there is any change in your personal data, please update such changes in the data recorded in your account.
Purpose of data processing: carrying out registration in the webshop, obtaining the data required for the fulfilment of orders placed by Data Subjects as customers and, in the case of purchase, for issuing invoices.
Legal basis of data processing: the voluntary, informed and specific consent of the Data Subject, given by the user by ticking the checkbox displayed during registration, based on the information contained in this document (pursuant to Section 5(1)(a) of the Information Act and Article 6(1)(a) of the GDPR).
Scope of data processed: name, address (postal code, town/city, address – both billing address and shipping address), tax number, telephone number, email address, username and password.
Data retention period: until the withdrawal of the Data Subject’s consent or the final deletion of the user account, which the user may request by submitting a request to the contact details of the Data Controller.
Place of data processing: IT devices located at the registered seat / premises of the Data Controller.
Method of data storage: electronic.
No data transfer takes place.
Data Processor: Impressive.hu Informatikai Szolgáltató Kft. (registered seat: Hungary, 7030 Paks, Építők útja 33.; company registration number: 17-09-007652; contact: info@impressive.hu; Telephone: +36 (75) 200 190, +36 (20) 2188 726; Fax: +36 (75) 200 440). Data processing activity performed: hosting services.
6.6. Purchase in the webshop
Purpose of data processing: receiving orders placed by users in the webshop, confirming orders, fulfilling and delivering orders, issuing invoices and other accounting documents for purchases, and complying with the accounting and document-retention obligations incumbent on the Data Controller.
Legal basis of data processing: the processing is necessary for the performance of a contract to which the Data Subject is a party (Article 6(1)(b) GDPR). If the sales contract concluded between the parties has been fully performed (the Data Subject, as buyer, has paid the purchase price and the Data Controller, as seller, has handed over the ordered product to the buyer, who has received it), the legal basis of the processing is Section 169(2) of the Accounting Act.
Scope of data processed: name, address (postal code, town/city, address – both billing address and shipping address), tax number, telephone number, email address, username and password.
Data retention period: pursuant to Section 169(2) of the Accounting Act, until the last day of the 8th year following the last day of the year in which the invoice was issued.
Place of data processing: IT devices located at the registered seat / premises of the Data Controller; in the case of paper-based documents and invoices, the archive of the Data Controller.
Data transfer: data affected by the processing described in this section are transferred to the following data controllers:
UPS Magyarország Kft. (registered seat: 2220 Vecsés, Lőrinci utca 154, Airport City Logistic Park; company registration number: 13-09-139285; contact: +36 1 877 0000). Purpose of data transfer: home delivery of ordered products. Scope of transferred data: customer data indicated on the invoice (name, shipping and billing address). Legal basis of data transfer: data transfer is necessary for the performance of a contract to which the Data Subject is a party.
BHS Trans Kft. (registered seat: 2120 Dunakeszi, Pallag u. 7.; tax number: 23196081-2-44; telephone: +36 20 414 5555; email: info@bhstrans.hu). Purpose of data transfer: home delivery of ordered products. Scope of transferred data: customer data indicated on the invoice (name, shipping and billing address). Legal basis of data transfer: data transfer is necessary for the performance of a contract to which the Data Subject is a party.
MAGYAR POSTA Zrt. (registered seat: 1138 Budapest, Dunavirág u. 2-6.; tax number: 17784083-5-44; telephone: +36 1 333 7777; fax: +36 46 320 136). Purpose of data transfer: home delivery of ordered products. Scope of transferred data: customer data indicated on the invoice (name, shipping and billing address). Legal basis of data transfer: data transfer is necessary for the performance of a contract to which the Data Subject is a party.
Data Processors:
SHS Kft. (registered seat: 7642 Mágocs, Szabadság u. 31.; company registration number: 02-09-000356; contact: +36 30 3776 755, www.shskft.hu). Data processing activity performed: all personal data specified in this notice.
Impressive.hu Informatikai Szolgáltató Kft. (registered seat: Hungary, 7030 Paks, Építők útja 33.; company registration number: 17-09-007652; contact: info@impressive.hu; Telephone: +36 (75) 200 190, +36 (20) 2188 726; Fax: +36 (75) 200 440). Data processing activity performed: hosting services.
6.7. Sending newsletters
In connection with sending newsletters, we process the following personal data: email address.
The processing is carried out on the basis of your voluntary, informed declaration, which contains your express consent to the use of the personal data provided during newsletter subscription. Pursuant to Article 6(1)(a) of the GDPR, the legal basis of the data processing is the voluntary consent of the Data Subject.
You give your consent to the data processing related to newsletter sending by voluntarily ticking the consent checkbox during newsletter subscription. The purpose of data processing is to ensure that the newsletter is sent to the email address you provided. The Data Controller does not verify the personal data provided to it. The person providing the data is solely responsible for the truthfulness of the data provided. When providing your email address, you also assume responsibility that only you use services from the provided email address. In view of this assumption of responsibility, all liability related to logins made with a provided email address lies exclusively with you, as the Data Subject who registered the email address.
In the case of newsletters, the Data Controller processes the data provided during newsletter subscription until you unsubscribe from the newsletter by clicking the “Unsubscribe” button at the bottom of the newsletter. In the event of unsubscribing, the Data Controller will no longer contact you with newsletters. You may unsubscribe from the newsletter and withdraw your consent at any time, free of charge.
6.8. Processing of online withdrawal declarations
When using the “Withdrawal from the contract” online function available on the website, the Data Subject provides personal data to the Data Controller in order to exercise the right of withdrawal.
Purpose of data processing: receiving, confirming and recording the Data Subject’s withdrawal declaration, processing the withdrawal request, handling matters related to the withdrawal, as well as carrying out any refund and related administration.
Legal basis of data processing: the processing is necessary for the performance of the contract and for exercising the right of withdrawal related to the contract, and is also connected to compliance with legal obligations applicable to the Data Controller. The legal basis of the data processing is Article 6(1)(b) and (c) of the GDPR.
Scope of data processed: name, email address, order identifier, name of the product(s) affected by the withdrawal, content of the withdrawal declaration, and the date and time of submission of the declaration.
Data retention period: for the period necessary to process the withdrawal declaration, to enforce legal claims arising from it, and to comply with legal obligations applicable to the Data Controller.
Place of data processing: IT devices located at the registered seat / premises of the Data Controller, as well as the systems of the hosting provider ensuring the operation of the website.
Method of data storage: electronic.
Data may be transferred to the extent necessary for handling the withdrawal declaration, particularly in the case of payment refunds or delivery-related administration.
Data Processor: Impressive.hu Informatikai Szolgáltató Kft. (registered seat: Hungary, 7030 Paks, Építők útja 33.; company registration number: 17-09-007652; contact: info@impressive.hu; Telephone: +36 (75) 200 190, +36 (20) 2188 726). Data processing activity performed: hosting services.
7. Data security
The Data Controller respects the requirements relating to the security of personal data, and therefore both the Data Controller and any authorised data processor take all technical and organisational measures and establish all procedural rules necessary to enforce the confidentiality and data-security rules of the Information Act and the GDPR.
The Data Controller protects the data it processes by appropriate measures against unauthorised access, alteration, transmission, disclosure, deletion or destruction, as well as against accidental destruction or damage.
In the course of its data processing, the Data Controller preserves:
confidentiality: it protects information so that only those authorised may access it;
integrity: it protects the accuracy and completeness of the information and the method of processing;
availability: it ensures that when an authorised user needs access, the desired information and the related tools are actually available.
The Data Controller appropriately protects its IT systems and networks against computer fraud, espionage, fire and flood, as well as viruses and computer intrusions. Security is ensured through server-level and application-level protection procedures. The Data Controller monitors its systems in order to record all security incidents and to provide evidence of all security events. System monitoring also makes it possible to verify the effectiveness of the precautions applied. The Data Controller requires and verifies compliance with the information-protection measures it applies, based on the provisions of contracts concluded with the data processors it uses.
8. Rights of Data Subjects
Right of access
After verifying their identity, the Data Subject is entitled to receive feedback from the Data Controller regarding the processing of their personal data. Information related to exercising the right of access is provided by the Data Controller in writing, by post or electronically.
The Data Subject is entitled to receive confirmation from the Data Controller as to whether their personal data are being processed, and if such processing is in progress, the Data Subject is entitled to access the personal data and the following information:
the purposes of processing;
the categories of personal data concerned;
the recipients or categories of recipients to whom the personal data have been or will be disclosed, including in particular recipients in third countries and international organisations;
where applicable, the envisaged period for which the personal data will be stored, or if this is not possible, the criteria used to determine that period;
the Data Subject’s right to request from the Data Controller the rectification or erasure of personal data concerning them, or the restriction of processing, and to object to such processing;
the right to lodge a complaint with a supervisory authority;
where the data are not collected from the Data Subject, any available information as to their source.
Right to rectification
The Data Subject has the right to obtain from the Data Controller without undue delay the rectification of inaccurate personal data concerning them. Taking into account the purposes of processing, the Data Subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.
Right to erasure
The Data Subject has the right to obtain from the Data Controller the erasure of personal data concerning them without undue delay, and the Data Controller is obliged to erase personal data concerning the Data Subject without undue delay where one of the following grounds applies:
the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
the Data Subject withdraws the consent on which the processing is based and there is no other legal basis for the processing;
the Data Subject objects to the processing pursuant to Article 21(1) of the GDPR and there are no overriding legitimate grounds for the processing, or the Data Subject objects to the processing pursuant to Article 21(2) of the GDPR;
the personal data have been unlawfully processed;
the personal data have to be erased for compliance with a legal obligation under EU or Member State law applicable to the Data Controller;
the personal data have been collected in relation to the offer of information society services referred to in Article 8(1) of the GDPR.
Right to restriction of processing
The Data Subject has the right to obtain from the Data Controller restriction of processing where one of the following applies:
the Data Subject contests the accuracy of the personal data, in which case the restriction applies for a period enabling the Data Controller to verify the accuracy of the personal data;
the processing is unlawful and the Data Subject opposes the erasure of the data and requests the restriction of their use instead;
the Data Controller no longer needs the personal data for the purposes of processing, but the Data Subject requires them for the establishment, exercise or defence of legal claims; or
the Data Subject has objected to processing pursuant to Article 21(1) of the GDPR, in which case the restriction applies until it is determined whether the legitimate grounds of the Data Controller override those of the Data Subject.
Where processing has been restricted on the basis of the above, such personal data may, with the exception of storage, be processed only with the Data Subject’s consent, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or a Member State. The Data Controller shall inform the Data Subject who requested the restriction before the restriction of processing is lifted.
Right to data portability
The Data Subject has the right to receive the personal data concerning them, which they have provided to a Data Controller, in a structured, commonly used and machine-readable format, and has the right to transmit those data to another Data Controller without hindrance from the Data Controller to which the personal data were provided, where the processing is based on consent or on a contract and the processing is carried out by automated means.
Right to object
The Data Subject has the right to object at any time, on grounds relating to their particular situation, to the processing of personal data concerning them based on Article 6(1)(e) or (f) of the GDPR, including profiling based on those provisions. In such case, the Data Controller may no longer process the personal data unless the Data Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the Data Subject, or which are related to the establishment, exercise or defence of legal claims.
Right to information
By publishing this notice, the Data Controller takes measures to ensure that all information relating to the processing of personal data required under Article 13 of the GDPR is available to the Data Subject. If the data made available are not obtained by the Data Controller from the Data Subject, the acquisition of the data is in all cases prescribed by EU or Member State law applicable to the Data Controller.
Deadline for handling Data Subject requests
The Data Controller responds to requests submitted in relation to the above rights within the following deadlines:
right to information: when the data are collected (if provided by the Data Subject) or within one month (if not provided by the Data Subject)
right of access: 1 month
right to rectification: 1 month
right to erasure: without undue delay
right to restriction of processing: without undue delay
right to data portability: 1 month
right to object: upon receipt of the objection
9. Remedies
If your rights as a Data Subject are infringed in connection with the exercise of your rights or during the processing of your personal data, you may initiate civil proceedings against the Data Controller. Proceedings may be initiated before the regional court of the Data Subject’s place of residence or place of stay. If an infringement is established, you may claim damages and compensation for non-material damage, and the court may order the Data Controller to comply with the exercise of Data Subject rights. Further information and the contact details of regional courts are available at: http://birosag.hu/torvenyszekek.
Furthermore, if you suffer harm in connection with the processing of personal data, you may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information. Contact details of the authority:
Hungarian National Authority for Data Protection and Freedom of Information
Registered seat: 1055 Budapest, Falk Miksa utca 9-11.
Mailing address: 1363 Budapest, Pf.: 9.
Email: ugyfelszolgalat@naih.hu
Telephone: +36 (1) 391 1400; +36 (30) 683 5969; +36 (30) 549 6838
Website: www.naih.hu
10. Contact
If the user wishes to contact the Data Controller, they may do so through the contact details of the Data Controller specified in section 3 of this notice.
11. SimplePay Statement
By accepting this Privacy Notice, the user acknowledges that the following personal data stored by Ruppert Borház Kft. (registered seat: 7814 Babarcszőlős, Táncsics Mihály utca 34.) as Data Controller in the user database of www.ruppert.hu are transferred to OTP Mobil Kft. as Data Processor.
The scope of data transferred by the Data Controller is as follows: name (company name), address (registered seat), tax number, email address and telephone number.
The nature and purpose of the data processing activity performed by the Data Processor can be found in the SimplePay Privacy Notice at the following link: https://simplepay.hu/adatkezelesi-tajekoztatok/