Privacy and Cookie Notice
For visitors, subscribers and customers of www.duelofwizards.com
Controller: Alec Media és Design Solution Kft. • Effective: 1 August 2026 • Version: 1.0
In brief: Without the necessary data, an order or message cannot be processed. Newsletters are sent only with prior consent, which may be withdrawn free of charge at any time. Non-essential cookies and external content may be activated only after the visitor has made a choice.
1.1. Purpose and scope of this Notice
This Notice explains how Alec Media és Design Solution Kft. processes the personal data of visitors, contacts, newsletter subscribers and customers of the website and online shop at https://www.duelofwizards.com. It covers the website, contact form, newsletter, orders, payment, delivery, withdrawal, complaints and conformity claims, and the use of cookies and similar technologies.
The Controller processes personal data in accordance with the European Union's General Data Protection Regulation (GDPR), the Hungarian Privacy Act and the Hungarian laws applicable to the individual processing activities. This version describes the data-processing arrangements prepared for the Webshop's operation in 2026.
2.2. Controller details
|
Item |
Details |
|
Controller |
Alec Media és Design Solution Korlátolt Felelősségű Társaság |
|
Short company name |
Alec Media és Design Solution Kft. |
|
Registered office and postal address |
4031 Debrecen, Derék utca 18. 2. em. 17. ajtó, Hungary |
|
Company registration number |
09-09-036693 |
|
Tax number |
32739853-1-09 |
|
Registering court |
Company Court of the Debrecen Regional Court (Debreceni Törvényszék Cégbírósága) |
|
Represented by |
Takács Sándor, managing director |
|
|
|
|
Website |
The Controller has not appointed a data protection officer. Privacy enquiries and requests to exercise data-subject rights may be sent to
3.3. Data-protection principles
Lawfulness, fairness and transparency: the purpose and legal basis of processing are made known in advance.
Purpose limitation and data minimisation: only data necessary for the stated purpose are processed.
Accuracy: inaccurate data identified by the Controller are corrected; Customers must also provide accurate data.
Storage limitation: data are retained for the periods stated below or for as long as necessary for legal claims.
Integrity and confidentiality: technical and organisational measures proportionate to the risk are applied.
Accountability: processing decisions, consents and data-subject requests are documented in a demonstrable manner.
4.4. Individual processing activities
4.1. Website visits, logs and IT security
Purpose: displaying the website, troubleshooting, preventing unauthorised access and abuse, and ensuring availability
Data processed: IP address, request and response time, page visited, browser and device technical data, error and security logs
Legal basis: Article 6(1)(f) GDPR - the Controller's legitimate interests in secure and demonstrable operation
Retention: normally 30 days; in the event of a security incident, for as long as necessary to investigate and close the incident and to pursue or defend legal claims
Recipients: hosting and server operator, IT maintenance provider and, where justified, a competent authority
Provision of data: automatic; without it the website cannot be served securely
4.2. Contact form and e-mail
Purpose: receiving and answering questions, press enquiries and other messages and tracking the matter
Data processed: name, subject, e-mail address, message content and any further data voluntarily supplied
Legal basis: Article 6(1)(b) GDPR where the enquiry concerns steps before entering into or performing a contract; otherwise Article 6(1)(f) GDPR - the legitimate interest in handling enquiries
Retention: one year after the matter is closed; three years for an enquiry treated as a consumer complaint and the corresponding response; in the case of a legal claim, no longer than the end of the applicable limitation period
Recipients: website and e-mail provider and, where necessary, a professional adviser
Provision of data: voluntary, but an enquiry cannot be handled on the merits without a name and a working reply address
4.3. Newsletter and direct marketing
Purpose: sending news, new editions, events and offers
Data processed: e-mail address, the text and time of consent, confirmation and unsubscribe data and, if requested during subscription, name and data required for an age check
Legal basis: Article 6(1)(a) GDPR and the prior, specific, informed and unambiguous consent required by the Hungarian Advertising Act
Retention: until unsubscribe; evidence of consent and withdrawal may be stored separately for up to five years after withdrawal for the establishment, exercise or defence of legal claims
Recipients: the e-mail and newsletter-system provider, if used by the Controller
Provision of data: voluntary; refusal or withdrawal of consent does not affect purchasing or other services
Every newsletter contains a simple, free unsubscribe option. Consent may also be withdrawn by writing to
4.4. Basket and preparation of the order
Purpose: maintaining the selected products and the checkout process and allowing input errors to be corrected
Data processed: session identifier, basket contents, quantity, language and technical settings
Legal basis: Article 6(1)(b) GDPR - steps taken at the Customer's request before entering into a contract; Article 6(1)(f) GDPR for security elements
Retention: until the end of the session or, for an abandoned basket, up to 30 days; marketing messages about an abandoned basket are sent only where a separate appropriate legal basis exists
Recipients: webshop and hosting provider and IT operator
Provision of data: necessary to use the basket
4.5. Order and performance of the contract
Purpose: receiving and acknowledging the order, managing payment and delivery status, performance and customer communication
Data processed: name, e-mail address, telephone number, billing and delivery address, products and quantities ordered, price, order identifier, payment method and status, delivery information and communications
Legal basis: Article 6(1)(b) GDPR - entering into and performing the contract
Retention: five years after performance or termination of the contract, having regard to the civil-law limitation period; longer separate retention applies to accounting records
Recipients: webshop and hosting provider, payment provider, invoicing provider, accountant, selected carrier and IT operator
Provision of data: the mandatory fields are contractual requirements; without them the order cannot be performed
4.6. Invoicing and accounting
Purpose: issuing and retaining invoices and complying with tax and accounting obligations
Data processed: name or company name, billing address, tax number, order and invoice data, consideration and payment status
Legal basis: Article 6(1)(c) GDPR - compliance with legal obligations
Retention: eight years, in accordance with the record-retention requirements of the Hungarian Accounting Act
Recipients: electronic invoicing provider, accountant, the Hungarian tax authority and other competent authorities
Provision of data: mandatory; a lawful invoice cannot be issued without the necessary data
4.7. Delivery
Purpose: delivery of the ordered goods, addressing, delivery notifications and tracking
Data processed: recipient name, delivery address, telephone number, e-mail address, order or parcel identifier and cash-on-delivery amount where applicable
Legal basis: Article 6(1)(b) GDPR - performance of the contract
Retention: five years as part of the Controller's order records; the carrier's own notice governs its retention periods
Recipients: the courier, postal or parcel-point provider selected at checkout
Provision of data: mandatory where the Customer requests delivery
4.8. Withdrawal, returns, complaints and conformity claims
Purpose: providing the right of withdrawal, acknowledging an online withdrawal statement, refunds, complaints and investigation of conformity claims
Data processed: name, contact details, address, order identifier, product and payment data, content and time of the withdrawal or complaint, evidence and case-handling records
Legal basis: Article 6(1)(b) GDPR - performance of the contract; Article 6(1)(c) GDPR - consumer-protection and accounting obligations; where justified, Article 6(1)(f) GDPR - the establishment, exercise or defence of legal claims
Retention: three years for the consumer complaint and response; normally five years for documents connected with contractual claims; eight years for an accounting correction document
Recipients: payment provider, return carrier, accountant, expert, legal adviser, consumer conciliation body, authority or court
Provision of data: the relevant order must be identified in order to exercise the right
4.9. Card payment and Barion
Purpose: processing card payment, confirming payment and preventing abuse
Data processed: the Controller receives the payment identifier, amount and status; it does not receive the card number, CVC or complete card details. Barion may process technical, device and transaction data through its own interface and Pixel
Legal basis: Article 6(1)(b) GDPR for the Controller; Barion's own notice and legal bases apply to Barion's processing, including legitimate interests in fraud prevention and consent for marketing
Retention: according to the Controller's order and accounting periods; at Barion according to Barion's notice in force
Recipients: Barion Payment Zrt., 1117 Budapest, Irinyi József utca 4-20., 2nd floor, Hungary; Barion may also act as an independent controller
Provision of data: necessary when card payment is selected; any other available payment method is shown at checkout
4.10. External OpenStreetMap content
Purpose: displaying contact or location details on a map
Data processed: IP address, browser and device data, requested map tile and time; the OpenStreetMap provider may process additional technical data under its own notice
Legal basis: Article 6(1)(a) GDPR - the visitor's prior consent; the external map must not load before consent
Retention: the Controller retains only the consent choice for up to 13 months; the external provider's own retention period applies
Recipients: OpenStreetMap Foundation and its technical service providers
Provision of data: voluntary; without consent the address remains available in text form
5.5. Cookies and similar technologies
A cookie is a small data file stored by the browser on the user's device. A pixel, local storage and browser fingerprinting may perform similar identification or measurement functions. Technologies strictly necessary for the website and checkout may be used; preference, analytics or marketing technologies may be activated only with an appropriate legal basis, normally prior consent.
|
Technology / provider |
Category |
Purpose |
Duration and legal basis |
|
Joomla/HikaShop session identifier (dynamic name) |
Strictly necessary |
Session, basket and security functions. |
Session or up to 30 days; provision of the service and legitimate interests. |
|
YOOtheme consent setting |
Strictly necessary |
Stores the cookie choice so that it does not have to be entered again on every page. |
Up to 13 months; evidence of the consent decision and legitimate interests. |
|
ba_vid and ba_vid.xxx - Barion |
Necessary payment fraud prevention |
Browser and visit identification for Barion Smart Gateway fraud prevention. |
Up to 1.5 years from the last update; Barion's legitimate interests. |
|
ba_sid and ba_sid.xxx - Barion |
Necessary payment fraud prevention |
Session identification and abuse prevention. |
30 minutes; Barion's legitimate interests. |
|
BarionMarketingConsent.xxx - Barion |
Marketing |
Stores the choice made for Barion's marketing measurement and personalisation. |
Up to 1.5 years from the last update; consent only. |
|
Barion Pixel and browser fingerprinting |
Fraud prevention / marketing |
Payment fraud prevention; marketing use only with separate consent. |
According to Barion's notice; legitimate interests or, for marketing, consent. |
|
External OpenStreetMap map content |
Preferences |
Displays the map; the provider may receive the IP address and technical data with the request. |
On loading / according to the provider's rules; prior consent. |
The cookie panel makes 'Accept', 'Reject' and 'Settings' equally easy to access. Consent can be given by category, withdrawn at any time and requested again no later than thirteen months afterwards. Blocking cookies in browser settings does not replace the website's prior-consent management.
According to Barion's notice, the basic fraud-prevention component of Barion Pixel may rely on legitimate interests; marketing use and the BarionMarketingConsent technology may be enabled only with consent. The website also communicates the consent decision to Barion Pixel.
6.6. Recipients, processors and transfers
To the extent necessary for the relevant purpose, the Controller may use the following categories of recipients:
hosting, server, domain, e-mail and IT-operations providers;
webshop, invoicing, accounting and customer-service system providers;
the payment and delivery provider selected at checkout;
legal, tax, accounting, information-security or other professional advisers;
authorities, courts, consumer conciliation bodies or other recipients authorised by law.
A processor may act only on the Controller's documented instructions and under appropriate confidentiality, security and deletion obligations. Providers acting as independent controllers - particularly Barion and the OpenStreetMap Foundation - are responsible for their own processing.
The Controller seeks to process data within the European Economic Area. Personal data are transferred to a third country only where an adequacy decision, an appropriate safeguard - such as the European Commission's standard contractual clauses - or a specific GDPR derogation permits the transfer. Information on the applicable safeguard is provided on request.
7.7. Automated decision-making and profiling
The Controller does not make a decision based solely on automated processing that produces legal effects concerning a data subject or similarly significantly affects them. The payment provider may use automated risk analysis for fraud prevention under its own privacy notice. If a payment is rejected, the data subject may request information from the payment provider and contact the Seller's customer service.
8.8. Data-subject rights
Subject to the applicable conditions, a data subject may:
obtain information about and access to their personal data, including a copy;
require correction of inaccurate data and completion of incomplete data;
require erasure where no overriding legal basis or retention obligation applies;
require restriction of processing;
receive data portability for automated processing based on a contract or consent;
object to processing based on legitimate interests; following an objection to direct marketing, the data may no longer be processed for that purpose;
withdraw consent at any time without affecting the lawfulness of processing before withdrawal;
lodge a complaint with a supervisory authority and seek a judicial remedy.
A request may be sent to
9.9. Security and personal-data breaches
The Controller applies measures proportionate to the risk, including encrypted data transfer, access control, entitlement reviews, backups, updates, logging and contractual oversight of processors. The Seller does not store card data.
If a personal-data breach occurs, the Controller assesses the risk and documents the event. Where the statutory conditions are met, the breach is notified to the supervisory authority within seventy-two hours. Data subjects are informed without undue delay where the breach is likely to result in a high risk.
10.10. Data relating to minors
The website and product are intended for adults. The Controller does not knowingly collect newsletter or purchase data from a person under eighteen. If the Controller obtains reliable knowledge that a minor supplied data without an appropriate legal basis, the data are erased or the required condition of lawfulness is established.
11.11. Complaints and remedies
A data subject may first contact the Controller at
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
1055 Budapest, Falk Miksa utca 9-11., Hungary
Postal address: 1363 Budapest, P.O. Box 9, Hungary
E-mail:
Telephone: +36 1 391 1400
Website: https://www.naih.hu
A data subject may also seek a judicial remedy and, subject to the legal conditions, bring proceedings before the court competent for their residence or place of stay. Compensation or damages for non-material harm may be claimed where the relevant conditions are met.
12.12. Changes to this Notice
The Controller updates this Notice following a change in law, a new function or provider, or another material change to processing. The current version is accessible from the Webshop footer. If a change concerns consent-based processing, fresh consent is requested where necessary.
13.13. Principal legal and service-provider sources
Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR)
Act CXII of 2011 - Hungarian Privacy Act
Act CVIII of 2001 - electronic commerce and online processing
Act XLVIII of 2008 - electronic advertising and consent
NAIH - privacy requirements for online shops
NAIH - customer service and contact

