Panier
Paiement

CHATBOT PRIVACY NOTICE

PRIVACY NOTICE 

 

The ManyChat Chatbot used by BioTech USA Kft. processes the personal data of people interacting with BioTech USA Kft. through the ManyChat interface. 

In drafting and applying this Notice, the Controller acts in the spirit of and applying Act CXII of 2011 on Informational Self-Determination and Freedom of Information, and Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter referred to as “GDPR”), in full compliance with these in all regards. 

 

Data of the Controller 

BioTech USA Kft. (registered office: H-1033 Budapest, Huszti út 60., branch office: H-1033 Budapest, Kiscsikós köz 11., company registration number: 01 09 352550, tax number: 25114681-2-44, telephone: 06 1 453 2716, email: adatvedelem@biotechusa.com) 

Contact details of our Data Protection Officer: Postal address: H-1277 Budapest, Pf. 83; E-mail address: dpo.btu@dnui.hu 

 

Chat feature 

Scope of the processed data 

Processed data: The visitor's public Facebook profile, first and last name, preferred language, time zone, gender, their unique identifier created by ManyChat, and other data provided during the conversation. 

The personal data processed may be disclosed primarily to the Controller and the Controller’s employees. 

Legal basis for processing 

The data subject’s consent pursuant to Article 6(1)(a) of the GDPR. 

The processing of your personal data is based on your voluntary and explicit consent given in awareness of this information. You may withdraw consent at any time; however, this shall not affect the lawfulness of processing prior to such withdrawal. 

Purpose of processing 

Replying to incoming messages.  

Duration of processing 

Until the withdrawal of consent, but no later than the deletion of the Facebook page of BioTech USA Slovakia, BioTech USA France. 

 

 

 

Product recommendation quiz 

Scope of the processed data 

Processed data: The visitor's public Facebook profile, first and last name, preferred language, time zone, gender, their unique identifier created by ManyChat, responses to product-related queries (e.g. training frequency, selected goal, food intolerance) 

The personal data processed may be disclosed primarily to the Controller and the Controller’s employees. 

Legal basis for processing 

The consent of the data subject pursuant to Article 6(1)(a) of the GDPR and, in the case of processing health data (e.g. questions concerning food intolerance), Article 9(2)(a) of the GDPR. 

The processing of your personal data is based on your voluntary and explicit consent given in awareness of this information. You may withdraw consent at any time; however, this shall not affect the lawfulness of processing prior to such withdrawal. 

Purpose of processing 

Replying to incoming messages. 

Duration of processing 

Until the withdrawal of consent, but no later than the deletion of the Facebook page of BioTech USA Slovakia, BioTech USA France. 

 

Cart abandonment system 

Scope of the processed data 

Processed data: The visitor's public Facebook profile, first and last name, preferred language, time zone, gender, their unique identifier created by ManyChat and products added to the cart in case of purchases initiated from ManyChat. 

Legal basis for processing 

When the purchase process is interrupted, the Controller will call on the customer to complete the contracting process, the legal basis for which is Article 6(1)(f) of the GDPR. 

Indication of legitimate interest: the Controller wishes to draw the attention of the data subject to the contracting process initiated by the data subject. The Controller will process the data for a limited period of time; after 24 hours the data will be automatically deleted. 

Purpose of processing 

Ensuring that the purchase process continues. 

Duration of processing 

24 hours after abandoning the cart, after which the system automatically deletes the data processed. 

 

 

 

Remarketing 

Remarketing allows the Controller to display advertisements to people who have previously used the Controller’s Chatbot feature. 

Personal data processed: The visitor's public Facebook profile and their unique identifier created by ManyChat. 

Purpose of processing: displaying advertisements to previous users on Facebook. 

Legal basis for processing: the Controller’s legitimate interest as per Article 6(1)(f) of the GDPR (direct marketing). The user's public Facebook profile is transferred to the Service Provider after using the Chatbot, with the data subject’s consent. This means that the Controller is processing the visitor’s public Facebook profile also for a purpose (remarketing) other than the purpose of data collection (operation of chatbot functions). 

Duration of processing: the data subject shall have the right to object at any time to the processing of personal data concerning him or her for such remarketing purposes. Should the user withdraw his or her consent given while using the Chatbot features (which he or she may do at any time), the user’s data will not be processed for remarketing purposes either. In order to ensure that the data are not kept longer than necessary, the controller will erase the personal data after 3 years from the date of the consent even if no objection or the withdrawal of consent is submitted. 

Recipients: employees of the Data Controller, and Shopify International Ltd. (registered office: 2nd Floor, 1-2 Victoria Buildings, Haddington Road, Dublin 4, D04 Xn32) and ManyChat INC. (registered office: San Francisco, California, United States, https://manychat.com/privacy.html) as data processors 

 

Data Processors 

  1. The Controller uses a server service, which is operated – and maintained in the event of any arising problems – by a contracted company. 

Details of the data processor company: JLM PowerLine Korlátolt Felelősségű Társaság (registered office: H-2111 Szada, Ipari park út 12–14, postal address: H-1033 Budapest, Huszti út 60, company registration number: 13 09 066529, tax number: 10819768-2-13, telephone, fax: +36 1 453 2716, e-mail: jog.jlm@biotechusa.com). 

  1. The Controller’s servers are operated – and maintained in the event of any arising problems – by companies contracted for this purpose. 

Details of the data processor company: Mongouse Kft. (registered office: H-1117 Budapest, Budafoki út 183, company registration number: 01 09 711243, tax number: 12943762-2-43, Tel. / Fax: +36 1 464 5856, e-mail: info@mongouse.hu). 

Details of the data processor company: Servergarden Kft. (registered office: H-1023 Budapest, Lajos utca 28–32, company registration number: 01 09 186097, tax number: 24855608-2-42, e-mail: info@servergarden.hu) 

  1. The Controller uses the assistance of an external service provider to develop the chatbot system. 

Details of the data processor company: ManyChat INC. (registered office: San Francisco, California, United States, https://manychat.com/privacy.html) 

  1. The Controller uses the assistance of an external service provider to operate the chatbot. 

Details of the data processor company: Bence Benkő, sole trader (Registered office: 1108 Budapest, Sibrik Miklós út 82-84 B ép. 3/1 a.; Tax number: 56182334-1-42) 

  1. The chatbot is powered by Facebook Messenger. 

Details of the data processor company: Facebook Ireland Ltd. (address: 4 Grand Canal square, Grand Canal Harbour, D2 Dublin, Ireland) 

 

  1. Rights of data subjects in relation to the processing 

The Controller shall provide information without any undue delay, and in any event within one month of receipt of the request, of the action taken in response to the request under paragraphs (a) to (e) below. That period may be extended by two further months where necessary, taking into account the complexity and number of the requests. The Controller shall provide information on any such extension within one month of receipt of the request, together with the reasons for the delay. 

  1. Right of access: you shall have the right to obtain feedback from the Controller on the processing of your personal data, to request information on the details of the processing, and to obtain from the Controller, in a portable format, your personal data processed in relation to the campaign. 
  1. Right to rectification: you shall have the right to obtain from the Controller without undue delay the rectification of inaccurate personal data concerning you, and to request your incomplete personal data to be supplemented. 
  1. Right to erasure (“right to be forgotten”): You may request, in writing sent to the Controller’s contact e-mail address indicated above, by fax or post, or by making a recorded communication to the telephone number provided, the termination of the processing of your personal data. In such case, the Controller will take all reasonable steps to inform all additional processors of your request to terminate processing. 
  1. Right to object: you shall have the right to object at any time to the processing of your personal data, where processing is based on the Controller’s legitimate interests.  
  1. Right to restriction of processing: you shall have the right to obtain from the Controller restriction of processing where you contest the accuracy of the personal data; the processing is unlawful; the Controller no longer needs the personal data for the purposes of the processing, but you require them for the establishment, exercise or defence of legal claims; or you have objected to processing.  

 

  1. Supervisory body, right to a remedy 

If you are not satisfied with our processing, you can lodge a complaint with the following authority: 

Name: Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság)[Körbefuttatás-törés]Registered seat: H-1055 Budapest, Falk Miksa utca 9-11., mailing address: H-1363 Budapest, Pf.: 9 [Körbefuttatás-törés]Telephone: +36 1 391 1400[Körbefuttatás-törés]Fax: +36 1 391 1410[Körbefuttatás-törés]E-mail: ugyfelszolgalat@naih.hu[Körbefuttatás-törés]Website: http://www.naih.hu 

You also have the right to take legal action to protect your data. In such case you may as well choose to start proceedings against the Controller at the competent court of your domicile or residence. You can find the contact details of the competent courts of your domicile or residence in the following link: http://birosag.hu/ugyfelkapcsolati-portal/birosag-kereso. 

 

  1. Contact details of the Controller 

If you have any questions or observations regarding data processing by BioTechUSA, please contact us using any of the contact details below, and our staff will be glad to provide assistance: 

Email: adatvedelem@biotechusa.com, telephone, fax: +36 1 453 2716 (Monday-Friday: 09.00-15.00), postal address: H-1033 Budapest, Kiscsikós köz 11. 

In effect from: 21/12/2021 

BioTech USA Kft.