Privacy Policy

Privacy Notice

Vetera Webshop – updated 22 September 2026

 

1. Data Controller

Controller: HYD LLC for Cancer Research and Drug Development (HYD Rákkutató és Gyógyszerfejlesztő Kft.) (HYD LLC)

  • Registered office: H-1119 Budapest, Fehérvári út 79., Hungary
  • Company registration no.: 01-09-260799
  • Tax no.: 10805459-2-43
  • E-mail: info@vetera.hu
  • Telephone: +36 1 365 1660; +36 1 381 0765
  • Data protection officer/contact: Zsuzsanna Sári

This Notice applies to the use of https://www.vetera.hu, the Webshop, orders for Vetera-DDW-25® veterinary anticancer deuterium-depleted medicinal product and other products offered in the Webshop, complaint handling, customer communications and newsletter services.

2. Principles and legal bases

HYD processes personal data lawfully, fairly, transparently, for specified purposes and in a data-minimised manner. Depending on the activity, processing is based on steps prior to or performance of a contract, a legal obligation, consent, or the legitimate interests of HYD or a third party.

3. Processing activities

Activity Data Purpose / legal basis Retention
Account/registration Name, e-mail, phone, address, encrypted password hash Account creation, identification, convenience functions;

User's consent (Art. 6 (1) a) of the GDPR)

Until account deletion or the withdrawal of consent.
Performing the order Name, e-mail, phone, billing/delivery address and country, products, quantity, price, payment/delivery method, order ID, comments, in case of legal person: company/tax data, name and contact data of the contact person Order handling, contract performance, delivery, support and claims;

Performance of contract (Art. 6 (1) b) of GDPR)

In relation to legal claims and processing of contact person’s data the legitimate interest of data controller (Art. 6 (1) f) of GDPR)

Generally 5 years for contract/claim data.
Invoicing Billing name/address, country, company, tax number, products, price and payment data Fulfilment of accounting obligations under Section 169 of Act C on Accounting (Art. 6 (1) c) of GDPR) 8 years for accounting documents.
Online payment – Stripe; SimplePay Order ID, amount, currency, status, contact and technical data; card data are collected and processed directly by Stripe/SimplePay, HYD does not have any access to them. Payment, fraud prevention, refunds and legal compliance; contract/legitimate interests

(Art. 6 (1) b), c) and f) of GDPR)

HYD retains transaction data under contract/accounting periods; Stripe/simplePay under its own rules.
Contact Name, e-mail, phone (optional), message, reply Contact;

User's consent (GDPR Article 6 (1) a)

Until the withdrawal of consent, but not more than 1 year.
Complaint handling Name, contact details, message, order data, complaint and response Support, complaint handling and claims; Fulfilment of a legal obligation pursuant to Section 17/B of Act CLV of 1997 on Consumer Protection (Article 6 (1) c) of the GDPR) 3 years or until a dispute closes.
Newsletter Name if supplied, e-mail, subscription/withdrawal time and consent evidence Electronic marketing;

User's consent (GDPR Article 6 (1) a)

Until withdrawal; suppression data as needed to prevent further messages.
Security/fraud logs IP address, time, device/browser data and order/payment events Security and abuse prevention; legitimate interest of the data controller (Art. 6 (1) f) of GDPR) Normally 30 days; longer where needed for an incident or dispute.

 

4. Recipients and service providers

Function Provider / recipient
Hosting and webshop technology NetBlaze Group Social Cooperative, H-8790 Zalaszentgrót, Cser-Zilai u. 10, Hungary; company registration no.: 20-02-050340; tax no.: 24804413-1-20; e-mail: info@netblaze.hu

United Call Center, H-3525 Miskolc, Kis-Hunyad utca 9/2; company registration no.: 05-09-018137; tax number: 11843157-2-05; e-mail: info@unitedcallcenters.hu

Payments (as an independent data controller) Stripe Payments Europe, Limited, Stripe Technology Europe, Limited and relevant Stripe group companies (Ireland/other countries). Privacy information: https://stripe.com/privacy

SimplePay Zrt. (1138 Budapest, Váci út 135-139. B. ép. 5. floor; ugyfelszolgalat@simple.hu; +36 1/20/30/70 3-666-611)

Domestic GLS General Logistics Systems Hungary Csomag-Logisztikai Kft., 2351 Alsónémedi, GLS Európa u. 2, Hungary
Delivery to European countries DPD (DPD Hungary Kft.: 1134 Budapest, Váci út 33., Building A, 2nd floor)
US delivery FedEx Express Hungary Transportation Kft. and FedEx group companies involved in carriage, customs clearance and tracking. FedEx may act as an independent controller for some operations. Privacy notice: https://www.fedex.com/en-hu/privacy-policy.html
Delivery to other countries Custom offer based on EMS express mail
Invoicing Progen Kft. (1118 Budapest, Homonna u. 8/A)
Analytics – with consent only Where enabled in cookie settings: Google Analytics / Google Ireland Limited. Current cookies and details are shown in the cookie preference tool.
Professional recipients/authorities (as independent data controller) Accountants, lawyers, banks, insurers, customs and tax authorities, courts and other authorised bodies where required by law or for legal claims.

 

5. Transfers outside the EEA

SimplePay, Stripe, FedEx, Google and some of their subcontractors operate global groups. Personal data may therefore be transferred outside the European Economic Area, including to the United States. Such transfers must rely on appropriate safeguards under Chapter V GDPR, such as an adequacy decision, EU Standard Contractual Clauses or another lawful mechanism.

6. Card data

HYD does not receive or store the full card number, CVC/CVV or card authentication credentials. SimplePay and Stripe collects these directly. HYD may process payment status, amount, currency, transaction identifier and data needed for refunds.

7. Cookies and similar technologies

Strictly necessary cookies may be used without consent. Analytics, preference and marketing cookies are activated only after prior consent. Consent can be withdrawn at any time in cookie settings. The current cookie panel lists the cookies, providers, purposes and lifetimes actually in use.

8. Your rights

The rights specified in this section belong to the user's contact person in the case of a user who is not registered as a natural person.

Access to personal data

At the request of the user, the data controller shall provide information on whether the data controller is carrying out data processing in respect of his/her personal data, and if so, the user shall be entitled to obtain the following information related to the data processing carried out by the data controller in relation to the user's personal data:

  • the purposes of the processing;
  • the name of the personal data;
  • the legal basis for the processing;
  • in the case of the transfer of the user's personal data, the legal basis, time and recipient(s) of the data transfer, as well as the name of the transferred data, as well as the name, contact details and activities related to data processing of the data processors;
  • the duration of the processing;
  • the user's rights in relation to the processing of their personal data;
  • the possibility of turning to the National Authority for Data Protection and Freedom of Information (NAIH);
  • the source of the data;
  • whether the controller uses automated decision-making and its logic, including profiling.

The data controller shall provide the user with a copy of the personal data subject to data processing free of charge. For further copies requested by the user, the data controller may charge a reasonable fee based on administrative costs.

The data controller shall provide the information without undue delay, but no later than one month from the submission of the request, in an easily understandable form. The user may submit his request for access at the contact details specified in Section 1.

Rectification of processed data

The user may request the correction of inaccurate personal data from the data controller (at the contact details specified in Section 1) or the completion of the incomplete data, taking into account the purpose of data processing. If the user can credibly prove the accuracy of the corrected data, the data controller shall carry out the correction in its records without undue delay, but within a maximum of one month, and shall notify the user in writing of the occurrence thereof.

Deletion of processed data (right to be forgotten)

The user may request the data controller to delete the personal data concerning him or her without undue delay, but no later than one month after the receipt of the request, in respect of which the data controller is not obliged by law to retain them, via the contact details specified in Section 1.

The user may request the deletion of his or her data in respect of data processing based on consent, except if the data controller is obliged to retain any personal data by law.

The data controller shall not delete the personal data processed within the framework of and for the purpose of data processing related to orders, invoicing and complaint handling for the period specified in Section 3. if the user requests the deletion of the data, with regard to the fact that they are necessary for the fulfilment of the related purposes and for the fulfilment of the retention obligation laid down in the relevant legislation.

If the data controller has disclosed the personal data (made it available to a third party) and is obliged to delete it in accordance with the above, it must take reasonable steps and measures, taking into account the available technology and the costs of implementation, in order to inform the data controllers processing the personal data concerned that the user has requested them to delete the links to the personal data in question or the copy or duplicate of these personal data.

The data controller does not delete the personal data if they are necessary for the submission, enforcement or defence of legal claims.

Restriction of processing (right to blocking)

The user has the right to request that the data controller restricts data processing instead of correcting or deleting personal data, if one of the following is true:

  • the user contests the accuracy of the personal data, in which case the restriction applies to the period that allows the controller to verify the accuracy of the personal data;
  • the processing is unlawful and the user opposes the erasure of the data and instead requests the restriction of its use;
  • the controller no longer needs the personal data for the purposes of the processing, but the user requires them for the establishment, exercise or defence of legal claims; or
  • the user has objected to the data processing; in this case, the restriction shall apply for the period until it is established whether the legitimate grounds of the data controller take precedence over the legitimate grounds of the data subject.

The data controller shall inform the user in advance of the lifting of the restriction of data processing.

Right to data portability

If the data processing is based on the user's consent, the user has the right to receive the personal data concerning him or her, which he or she has provided to the data controller, in a structured, commonly used, machine-readable format and to transmit these data to another data controller.

Right to object

If the processing of personal data is carried out due to the legitimate interest of the data controller, the user has the right to object to the processing of his or her personal data at any time, if in his or her opinion the data controller does not process his or her personal data properly in connection with the data processing purpose specified in this policy.

In the event of the user's objection, the controller will no longer process the personal data, unless it can demonstrate compelling legitimate grounds for the processing which override the interests, rights and freedoms of the user, or which are related to the establishment, exercise or defence of legal claims.

The data controller's action in connection with the user's request

The data controller shall inform the user of the measures taken in response to the request for access, rectification, deletion, restriction, objection and data portability without undue delay, but no later than within one month from the receipt of the request. If necessary, taking into account the complexity of the request and the number of requests, this deadline may be extended by a further two months. The data controller shall inform the user of the extension of the deadline within one month of receipt of the request, indicating the reasons for the delay. If the user has submitted the request electronically, the information shall be provided electronically if possible, unless the data subject requests otherwise.

If the data controller does not take action in response to the user's request, it shall inform the user without delay, but no later than one month from the receipt of the request, of the reasons for the failure to take action, and of the fact that the user may file a complaint with a supervisory authority and exercise his or her right to judicial remedy.

In the case of the user's request, the information, the information and the action taken on the basis of the user's request shall be provided free of charge. If the user's request is clearly unfounded or excessive, in particular due to its repetitive nature, the data controller, taking into account the administrative costs involved in providing the requested information or information or taking the requested action, may charge a reasonable fee or refuse to act on the request. The burden of proving that the request is clearly unfounded or excessive shall be borne by the data controller.

9. Law enforcement options

The data controller makes every effort to ensure that the personal data is processed in accordance with the law, but if the user feels that he or she has not complied with this, he or she has the opportunity to write to the contact details specified in Section 1.

If the user feels that his or her right to the protection of personal data has been violated, he or she may seek legal remedy in accordance with the applicable legislation to the competent bodies:

  • NAIH (1055 Budapest, Falk Miksa utca 9-11.; ugyfelszolgalat@naih.hu; naih.hu)
  • at the user's choice at the court competent according to his/her place of residence or temporary address, or at the court competent according to the registered office of the data controller. The competent court according to user’s place of residence or temporary address can be found on the following site: birosag.hu/ugyfelkapcsolati-portal/birosag-kereso. According to the registered office of the data controller, the Metropolitan Court of Budapest has jurisdiction for the lawsuit.

10. Security and changes

HYD applies appropriate technical and organisational security measures. This Notice may be updated when services, law or providers change; the current version is published on the Website.