Privacy policy
1. DATA CONTROLLER
The controller responsible for the processing described in this Privacy Policy is:
Monautix Kft.
Monautix Korlátolt Felelősségű Társaság
Registered office:
8230 Balatonfüred
Zákonyi Ferenc utca 2.
Hungary
Email: monautixkft@gmail.com
Telephone: +36 30 942 2393
Company Registration Number: 19-09-516081
Hungarian Tax Number: 24254849-2-19
EU VAT Number: HU24254849
For questions concerning this Privacy Policy or the exercise of your data-protection rights, please contact us using the details above.
2. PERSONAL DATA WE MAY PROCESS
Depending on how you interact with the online store, we may process the following categories of personal data.
Identification and contact data
This may include:
- name;
- email address;
- telephone number;
- billing address;
- delivery address; and
- other contact information you provide.
Business and invoicing information
Where relevant, this may include:
- company name;
- registered address;
- tax or VAT number;
- billing details; and
- information required for issuing an invoice.
Order and transaction information
This may include:
- products viewed, ordered, returned or cancelled;
- quantities, prices and discounts;
- order number;
- delivery method and collection point;
- payment method;
- payment status;
- return, refund and exchange information; and
- previous transactions.
Payment-related information
When you pay online, payment information necessary to process the transaction is handled through Shopify Payments and its payment processors and financial-service providers.
Full payment-card details are processed through the relevant payment infrastructure and are not stored by Monautix as ordinary customer or order records.
Where cash on delivery (COD) is selected, information necessary for collecting and settling the COD amount may be provided to the relevant carrier.
Customer account information
Where you create or use a customer account, we may process:
- account identifiers;
- contact details;
- order history;
- account preferences; and
- account-security information.
Customer-service and legal communications
This may include information contained in:
- enquiries;
- emails;
- complaints;
- return requests;
- withdrawal requests;
- warranty or conformity claims;
- photographs submitted in connection with a defective Product; and
- other communications with Monautix.
Marketing information
Where you consent to marketing, we may process:
- your email address and/or telephone number;
- your marketing consent and the date and method by which it was given;
- subscription status;
- withdrawal or unsubscribe information; and
- information concerning interaction with marketing communications, where permitted.
Technical and usage information
When you visit the online store, technical information may be processed, including:
- IP address;
- device and browser information;
- operating system;
- language;
- network information;
- identifiers;
- website interactions;
- pages and Products viewed;
- cart activity;
- referral information; and
- cookie and consent preferences.
Some of this information is collected through cookies, pixels or similar technologies as described below.
3. SOURCES OF PERSONAL DATA
We primarily receive personal data:
- directly from you when you browse the online store, place an order, create an account, contact us or subscribe to marketing;
- automatically from your browser or device when you use the online store;
- through Shopify and services integrated with Shopify;
- through our logistics, payment and invoicing systems where necessary to complete or administer a transaction; and
- from service providers where this is necessary for fraud prevention, payment processing, delivery, returns or customer service.
We do not purchase general consumer databases for the purpose of sending unsolicited marketing communications.
4. PROCESSING ORDERS AND PERFORMING CONTRACTS
We process identification, contact, order, billing, payment-status and delivery information in order to:
- receive and process your order;
- communicate with you about the order;
- process payment;
- arrange delivery or collection;
- manage returns and refunds;
- provide customer service; and
- otherwise perform the sales contract.
Legal basis: Article 6(1)(b) GDPR – processing necessary for taking steps at your request before entering into a contract and for performing a contract.
Providing the information marked as required during checkout is necessary to process and fulfil your order. If you do not provide the required information, we may be unable to conclude or perform the contract.
5. DELIVERY AND LOGISTICS
For delivery, we disclose only the personal data reasonably necessary to the carrier selected or applicable to your order.
This may include:
- recipient name;
- delivery address or selected parcel point;
- email address;
- telephone number;
- parcel and delivery information; and
- COD amount where cash on delivery is selected.
Depending on the delivery method, recipients may include:
DPD Hungary Kft.
Magyar Posta Zrt. / MPL
FOXPOST
The carrier may also process certain personal data as an independent controller for purposes connected with the provision of its postal, courier or payment-collection services.
Legal basis for Monautix's processing and disclosure: Article 6(1)(b) GDPR – performance of the sales contract.
DPD confirms, for example, that it receives recipient name, address, telephone number and email from senders for parcel delivery purposes; Magyar Posta similarly maintains its own privacy framework for postal and parcel processing.
6. KOSR CHECKOUT, SHIPPING AND BILLING INTEGRATION
Monautix uses the kosR Shopify application, provided by TotalStudio, to support functions including Hungarian checkout customisation, delivery and parcel-point selection, COD handling, business-customer data such as tax numbers, shipping integrations and invoicing processes.
Personal data necessary for these functions may therefore be processed through kosR.
This may include customer identification and contact information, delivery information, order information, invoicing information and other information required for the selected functionality.
The kosR integration is also used by Monautix to transfer the necessary invoicing information to Billingo.
kosR receives access through Shopify only to data permitted for the installed application and necessary for its enabled functions.
Legal bases: Article 6(1)(b) GDPR where processing is necessary for checkout, delivery or contract performance; and Article 6(1)(c) GDPR where information is processed to comply with invoicing or other statutory obligations.
The Shopify App Store confirms that kosR is provided by TotalStudio and has access to customer and order information necessary for its checkout, delivery and billing functionality.
7. INVOICING AND BILLINGO
Monautix uses Billingo for electronic invoicing.
The invoicing data necessary for issuing and retaining invoices is transferred from the Shopify order process through the kosR integration to Billingo.
The data may include:
- customer name or company name;
- billing address;
- email address where necessary for electronic invoicing;
- tax or VAT number where applicable;
- Products, quantities and prices;
- payment and transaction information; and
- other information legally required on the invoice.
Billingo is operated by:
Billingo Technologies Zrt.
1133 Budapest
Árbóc utca 6.
Hungary
Legal basis: Article 6(1)(c) GDPR – compliance with Monautix's statutory accounting, invoicing and taxation obligations.
Personal data forming part of invoices and accounting records are retained for the period required by Hungarian accounting law. Accounting documents supporting bookkeeping must generally be retained for at least 8 years.
Billingo's current privacy information identifies Billingo Technologies Zrt. as the operator of the invoicing service.
8. ONLINE PAYMENTS – SHOPIFY PAYMENTS
Monautix uses Shopify Payments for supported online payments.
When you select an online payment method, data necessary to process and authenticate the transaction may be processed by Shopify, its payment processors, financial institutions, card networks and other payment-service providers involved in the transaction.
This may include:
- payment-card information;
- billing information;
- payment amount;
- transaction identifier;
- IP/device information;
- authentication information; and
- fraud-prevention information.
Legal basis for Monautix's processing: Article 6(1)(b) GDPR – performance of the sales contract.
Fraud-prevention and security processing may additionally be based on legitimate interests under Article 6(1)(f) GDPR and/or legal obligations applicable to the relevant payment provider.
Shopify Payments may involve payment processors that act as processors or, for certain regulatory functions such as anti-money-laundering, sanctions or financial compliance, as independent controllers under their own privacy terms. Shopify expressly describes these roles in its current Shopify Payments terms.
9. CASH ON DELIVERY
Where you select cash on delivery (COD), the carrier may receive the information necessary to collect the amount due and account for the payment.
Such information may include your identity and delivery details, the amount to be collected and information recording whether payment was successfully collected.
Legal basis: Article 6(1)(b) GDPR – performance of the contract.
Where the carrier is subject to its own accounting, payment or other statutory obligations, it may independently process relevant data on the basis of those obligations.
11. CUSTOMER ACCOUNTS
Where customer-account functionality is used, Monautix processes the information necessary to:
- create and maintain the account;
- authenticate access;
- display eligible order information;
- enable applicable return and cancellation functions; and
- maintain account security.
Legal basis: Article 6(1)(b) GDPR where the account is used in connection with orders and requested services, and Article 6(1)(f) GDPR for reasonable account-security measures.
Account information is retained while the account remains active or until deletion is requested, subject to information which Monautix must retain separately because of accounting, contractual, warranty, complaint or other statutory obligations.
12. CUSTOMER SERVICE, RETURNS, WITHDRAWAL AND WARRANTY CLAIMS
We process personal data where you contact us concerning:
- a general enquiry;
- an order;
- cancellation;
- statutory withdrawal;
- return or exchange;
- defective Products;
- legal conformity rights;
- warranty or guarantee claims; or
- refunds.
Depending on the matter, the legal basis is:
Article 6(1)(b) GDPR – performance of or steps connected with a contract;
Article 6(1)(c) GDPR – compliance with statutory consumer-protection, warranty or complaint-handling obligations; and/or
Article 6(1)(f) GDPR – Monautix's legitimate interest in establishing, exercising or defending legal claims.
Information is retained only for the period necessary for the relevant purpose and any applicable statutory retention or limitation period.
13. CONSUMER COMPLAINTS
Where a formal consumer complaint is made, Monautix processes the information necessary to investigate, document and respond to the complaint.
Legal basis: Article 6(1)(c) GDPR – compliance with statutory consumer-protection obligations.
Hungarian consumer-protection law currently requires the relevant complaint and substantive response records to be retained for three years.
14. MARKETING EMAIL AND SMS
Where you choose to receive marketing communications, Monautix may use Shopify's marketing functionality, including Shopify Messaging, to send email and/or SMS marketing communications.
Marketing may include information concerning Products, offers, promotions, events or other Monautix news.
Legal basis: Article 6(1)(a) GDPR – your consent.
Marketing consent is voluntary and is not a condition of purchasing from Monautix.
Hungarian law generally requires prior explicit consent before direct electronic advertising is sent to a natural person, and such consent may be withdrawn free of charge at any time.
You may withdraw consent at any time:
- by using the unsubscribe mechanism contained in the marketing communication; or
- by contacting Monautix at monautixkft@gmail.com.
Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
We retain marketing contact data until consent is withdrawn or the relevant marketing activity is discontinued, subject to limited retention of evidence necessary to demonstrate that consent or withdrawal was properly recorded.
Transactional messages concerning an order, customer account, delivery, return or legal obligation are not marketing messages and may continue to be sent where necessary even if you unsubscribe from marketing.
15. COOKIES AND SIMILAR TECHNOLOGIES
The Monautix online store uses cookies and similar technologies.
Some are strictly necessary for functions such as:
- checkout;
- shopping cart;
- security;
- authentication;
- session management; and
- remembering essential privacy choices.
Other technologies may be used for:
- analytics;
- personalisation;
- marketing;
- advertising; and
- measurement.
Where consent is required, non-essential cookies and similar technologies are used only in accordance with your consent choices.
Monautix currently uses Shopify's automated cookie consent banner for the applicable European regions.
You can review or change your consent choices using the Cookie Preferences function available through the store.
Shopify states that in configured EEA/UK regions its cookie banner collects non-essential data only after the required consent and that Shopify pixels follow those consent preferences.
16. GOOGLE ANALYTICS 4
This Section applies once Google Analytics 4 has been activated on the Monautix online store.
Monautix uses or intends to use Google Analytics 4 (“GA4”), provided by Google, to understand how visitors use the online store and to measure website performance.
GA4 may process information including:
- device and browser information;
- approximate location derived from network information;
- interactions with pages and Products;
- session and event information;
- referral information; and
- online identifiers and other technical data.
For EEA visitors, analytics technologies requiring consent must be controlled through the applicable cookie-consent mechanism.
Legal basis where consent is required: Article 6(1)(a) GDPR.
Where GA4 is enabled, the developer must configure it so that the Monautix cookie consent mechanism and the applicable Google consent signals are respected.
Google's current documentation requires EEA consent choices to be communicated to Google for relevant measurement and advertising uses, and Shopify specifically supports Google Consent Mode v2 through its customer-privacy settings.
For EEA users, the relevant Google entity is generally:
Google Ireland Limited
Gordon House
Barrow Street
Dublin 4
Ireland.
Google processes data in accordance with its own applicable privacy documentation.
17. SECURITY AND FRAUD PREVENTION
Monautix and its service providers may process technical, transaction and account information where necessary to:
- secure the online store;
- authenticate transactions;
- detect fraud or misuse;
- prevent unauthorised access;
- investigate security incidents; and
- protect Monautix, customers and third parties.
Legal basis: Article 6(1)(f) GDPR – legitimate interests in protecting the online store, transactions, customers and information systems; and where relevant Article 6(1)(c) GDPR for statutory obligations.
We seek to use appropriate technical and organisational safeguards taking into account the nature of the processing and associated risks.
No internet-based system can be guaranteed to be completely secure.
18. LEGAL OBLIGATIONS AND LEGAL CLAIMS
Personal data may be processed where necessary to:
- comply with applicable laws;
- satisfy tax, accounting and consumer-protection requirements;
- respond to a lawful request from a court, regulator or public authority;
- establish, exercise or defend legal claims; or
- investigate suspected unlawful conduct.
Depending on the circumstances, the legal basis is Article 6(1)(c) GDPR (legal obligation) or Article 6(1)(f) GDPR (legitimate interest in establishing, exercising or defending legal claims).
We disclose personal data to authorities only where there is an appropriate legal basis or binding legal requirement.
19. RECIPIENTS AND SERVICE PROVIDERS
Depending on the relevant transaction or service, personal data may be disclosed to or processed by:
Shopify and Shopify subprocessors – hosting, ecommerce platform, checkout, customer accounts, order management, marketing and technical services;
Shopify Payments and relevant payment processors and financial institutions – online payment processing, authentication, fraud prevention and payment compliance;
kosR / TotalStudio – checkout customisation, shipping and parcel-point functions, COD processing and Billingo integration;
Billingo Technologies Zrt. – invoicing;
DPD Hungary Kft., Magyar Posta Zrt./MPL and FOXPOST – delivery, parcel handling and, where relevant, COD collection;
Google Ireland Limited and relevant Google entities – where Google Analytics 4 is enabled and consented to as applicable;
competent courts, authorities or regulatory bodies – where disclosure is required or permitted by law; and
professional advisers or service providers engaged by Monautix only where access is reasonably necessary for a legitimate business or legal purpose and subject to appropriate confidentiality and data-protection obligations.
We do not disclose personal data to third parties merely so that unrelated third parties can independently send you their own direct marketing.
20. INTERNATIONAL DATA TRANSFERS
Although Monautix is established in Hungary and Shopify's primary customer-data hosting location for the Monautix store is currently configured as the European Union, some service providers operate internationally.
Personal data may therefore be processed outside Hungary and, in some circumstances, outside the European Economic Area.
Shopify states that EEA customer data is initially processed by Shopify International Limited in Ireland but may subsequently be processed by affiliated entities and subprocessors in other countries.
Shopify Payments may also involve transfers to locations including Canada and the United States and to relevant payment processors and financial institutions.
Where the GDPR requires safeguards for a transfer outside the EEA, the relevant transfer will be based on an applicable legal transfer mechanism, such as:
- an adequacy decision of the European Commission;
- Standard Contractual Clauses;
- another mechanism recognised under Chapter V GDPR; or
- a statutory derogation where applicable.
Information concerning Shopify's international transfer arrangements is available through Shopify's privacy documentation.
21. DATA RETENTION
We do not retain all personal data for the same period.
Retention depends on the purpose for which the information is processed and applicable statutory requirements.
In particular:
Order and contractual information is retained for the period necessary to perform the contract and thereafter for the period reasonably necessary to comply with legal obligations and establish, exercise or defend contractual claims.
Invoices and accounting records containing personal data are retained for the statutory accounting period, generally at least 8 years.
Consumer complaint records and responses are retained for 3 years where Hungarian consumer-protection law applies.
Marketing data is processed until consent is withdrawn or the relevant marketing activity ends, subject to limited retention where necessary to document consent or withdrawal.
Customer-account data is generally retained while the account remains active, subject to information that must be retained separately under another legal basis.
Cookie, analytics and technical information is retained according to the purpose and settings of the relevant technology and service provider.
Where litigation, a regulatory investigation, warranty claim or other dispute is ongoing, relevant information may be retained until the matter and the applicable legal-retention requirements have ended.
At the end of the applicable retention period, information is deleted or anonymised unless further retention is legally required.
22. YOUR RIGHTS UNDER THE GDPR
Subject to the conditions and exceptions provided by applicable law, you have the right to:
Access – request confirmation as to whether we process your personal data and obtain access to the relevant data.
Rectification – request correction of inaccurate or incomplete personal data.
Erasure – request deletion of personal data where the statutory conditions are satisfied.
Restriction – request restriction of processing in the circumstances provided by law.
Data portability – receive certain personal data you provided to us in a structured, commonly used and machine-readable format and, where legally applicable, request its transmission to another controller.
Object – object to processing based on legitimate interests, including profiling based on that legal basis.
Where personal data is processed for direct marketing, you have the right to object to that processing at any time.
Withdraw consent – where processing is based on consent, withdraw that consent at any time. Withdrawal does not affect processing lawfully carried out before withdrawal.
Complain to a supervisory authority – lodge a complaint concerning the processing of your personal data.
These rights follow from the GDPR's access, rectification, erasure, restriction, portability and objection framework.
To exercise rights in relation to processing for which Monautix is controller, contact:
We may request information reasonably necessary to confirm your identity before acting on a request.
23. SHOPIFY PRIVACY RIGHTS
For certain Shopify Enhanced Services, including processing associated with Shopify Network Intelligence, Shopify may itself be the controller.
Requests specifically relating to Shopify's independent controller processing may therefore also be exercised through the Shopify Privacy Portal.
A request to Monautix for deletion of relevant customer data may also trigger deletion processes applicable to Shopify systems in accordance with Shopify's functionality and legal obligations. Shopify describes this relationship in its Network Intelligence documentation.
24. RIGHT TO LODGE A COMPLAINT WITH THE NAIH
You have the right to lodge a complaint with the Hungarian supervisory authority:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)
Address:
1055 Budapest
Falk Miksa utca 9–11.
Hungary
Postal address:
1363 Budapest, Pf. 9.
Email: ugyfelszolgalat@naih.hu
Telephone: +36 1 391 1400
You may also have the right to contact the competent supervisory authority in another EEA Member State, in particular in the Member State of your habitual residence, place of work or place of an alleged infringement.
The NAIH currently publishes the above Budapest address, postal address, email and telephone number as its official contact information.
25. AUTOMATED DECISION-MAKING AND PROFILING
Monautix does not currently make decisions concerning customers solely through automated processing that produce legal effects or similarly significantly affect the individual, within the meaning of Article 22 GDPR.
Certain service providers may nevertheless use automated systems for matters such as fraud detection, payment authentication, security, analytics or personalisation.
Where a provider acts as an independent controller for such processing, its own privacy notice and applicable legal safeguards apply.
Shopify Network Intelligence may involve profiling or personalisation for Enhanced Services, but the applicable consent choices and Shopify's independent privacy rights remain available as described above.
26. CHILDREN'S DATA
The Monautix online store is not intended to solicit personal data from children for independent online purchasing.
If we become aware that personal data relating to a child has been provided or processed without an appropriate legal basis or required authorisation, we will take reasonable steps to delete or otherwise appropriately handle that information in accordance with applicable law.
Parents or legal guardians who have concerns regarding a child's personal data may contact us at:
27. THIRD-PARTY WEBSITES
The online store may contain links to third-party websites, services or social-media platforms.
Monautix is not responsible for the independent privacy practices of third parties merely because the Monautix website links to them.
Before providing personal data directly to another organisation, you should review that organisation's privacy information.
28. CHANGES TO THIS PRIVACY POLICY
We may amend this Privacy Policy where necessary to reflect:
- changes in our processing activities;
- changes to the Shopify platform or integrated services;
- new or removed service providers;
- changes in technology; or
- legal or regulatory developments.
Where required by applicable law, we will provide appropriate notice of material changes.
The current version and its last-updated date will be available through the Monautix online store.
29. CONTACT
For privacy questions, requests or complaints relating to processing carried out by Monautix, please contact:
Monautix Kft.
8230 Balatonfüred
Zákonyi Ferenc utca 2.
Hungary
Email: monautixkft@gmail.com
Telephone: +36 30 942 2393
Last updated: 11 August 2026