Privacy policy
Effective from 1 October 2026
1. Introduction
The purpose of this policy is to provide transparent information about the processing of personal data in the PulóWear online shops (the "Shop") by EMERZY Group Kft. (the "Controller"), in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and Hungarian Act CXII of 2011 on the right to informational self-determination and freedom of information. This policy applies together with the annex for the relevant shop (Annex 1).
For any questions about data protection, please contact us at: hello@pulowear.com.
2. Controller details
- Controller: EMERZY Group Kft.
- Registered office: 2371 Dabas, Szent János út 347., Hungary
- Company registration number / tax number: 13-09-221059 / 32009558-2-13
- Email: hello@pulowear.com
- Phone: +36 30 609 1780
The Controller is not required to appoint a data protection officer (DPO) and has not appointed one.
3. Key terms
Personal data: any information relating to an identified or identifiable natural person. Data subject: the natural person to whom the personal data relate. Processing: any operation performed on personal data. Processor: a person who processes personal data on behalf of the Controller. Consent: a freely given, specific, informed and unambiguous indication of the data subject's wishes. Further terms are defined in Article 4 GDPR.
4. Principles and legal bases of processing
The Controller processes personal data lawfully, fairly and transparently, for specified purposes, to the extent necessary, accurately, for a limited period and with appropriate security.
The legal basis for processing may be: the data subject's consent [Art. 6(1)(a) GDPR], performance of a contract [point (b)], compliance with a legal obligation [point (c)] or the Controller's legitimate interest [point (f)].
5. Processing activities
5.1. Orders and performance of the contract
Purpose: processing orders and performing the contract. Data processed: name, delivery and billing address, phone number, email address, order details. Legal basis: performance of a contract [Art. 6(1)(b)]. Retention period: the general limitation period, i.e. 5 years. Processor: Shopify International Limited.
5.2. Online payment
Purpose: processing card and digital wallet payments (Shop Pay, Apple Pay, Google Pay). Data processed: name, data required for payment, amount and purchase identifier; the Controller does not know or store full card details. Legal basis: performance of a contract [Art. 6(1)(b)]. Retention period: 5 years. Processor: Shopify (Shopify Payments).
5.3. Invoicing and accounting
Purpose: issuing and keeping invoices as required by law. Data processed: name, billing address and the data required by VAT rules. Legal basis: compliance with a legal obligation [Art. 6(1)(c)]. Retention period: 8 years, under Section 169 of Hungarian Act C of 2000 on Accounting. Processors: Billingo Technologies Zrt. (invoicing), Vödrös Judit (accounting).
5.4. Delivery of products
Purpose: delivering the products ordered. Data processed: name, delivery address, phone number, email address and, for cash on delivery, the amount to be collected. Legal basis: performance of a contract [Art. 6(1)(b)]. Retention period: 5 years. Processor: GLS General Logistics Systems Hungary Kft. and the GLS network partner in the country of destination that delivers the parcel. The Controller ships parcels from its own warehouse in Dabas.
5.5. Complaints and claims relating to conformity
Purpose: handling complaints and claims relating to the conformity of products. Data processed: name, address, phone number, email address, purchase and complaint details. Legal basis: compliance with a legal obligation [Art. 6(1)(c)]. Retention period: 5 years, under Section 17/A of Hungarian Act CLV of 1997 on Consumer Protection.
5.6. Contact (email, phone)
Purpose: answering questions. Data processed: name, email address, phone number, content of the message. Legal basis: the data subject's consent [Art. 6(1)(a)] and, for order-related questions, performance of a contract [point (b)]. Retention period: a reasonable period after the matter is resolved, at most 5 years, or until consent is withdrawn. Processor: Google Ireland Limited (Google Workspace email service).
5.7. Social media and messages
The Controller runs the PulóWear page on Facebook, Instagram and YouTube, where it shows advertisements and communicates with interested people via messages.
Purpose: brand presence, communication, replying to messages. Data processed: the user's public name and profile picture, their comments, reactions and the content of messages. Legal basis: the Controller's legitimate interest in brand communication [Art. 6(1)(f)] and, for message exchanges, the data subject's consent [point (a)]. Retention period: a reasonable period after the communication ends, or until the data subject deletes the content on the platform.
For the Facebook and Instagram page statistics (Page Insights), the Controller and Meta Platforms Ireland Limited are joint controllers under Article 26 GDPR. The essence of the joint controller agreement is available on Meta's website; data subjects may also exercise their rights against Meta. The platforms' own processing is governed by the privacy policies of Meta and Google.
5.8. Newsletter and marketing (email, SMS)
Purpose: sending newsletters, offers and marketing messages by email and SMS. Data processed: name, email address, phone number and data used to prove consent (time, IP address). Legal basis: the data subject's freely given consent [Art. 6(1)(a)], which can be withdrawn at any time free of charge, for example via the unsubscribe link in every newsletter. Retention period: until consent is withdrawn; data proving consent for 5 years thereafter. Processor: Klaviyo, Inc. Subscription is separate from purchasing and is based on separate consent.
5.9. Prize draws
Purpose: organising occasional prize draws and notifying winners. Data processed: name, address, phone number, email address, data used to prove consent. Legal basis: the data subject's consent [Art. 6(1)(a)]. Retention period: for non-winners, until the end of the prize draw; for winners, 8 years under accounting rules.
Age limit: only persons aged over 16 may subscribe to the newsletter or enter prize draws (Article 8 GDPR).
6. Profiling and automated decision-making
The Controller does not itself make decisions based solely on automated processing that produce legal effects for the data subject.
When advertising and remarketing tools are used (Google Ads, Meta Pixel, TikTok Pixel), profiling for the purpose of targeting advertisements may take place on the basis of consent to cookies. The legal basis is the data subject's consent, which can be changed or withdrawn at any time in the cookie settings.
For online payments, Shopify may carry out automated risk and fraud checks (for example, temporarily blocking a card number or IP address in the case of a suspicious transaction). This check does not have significant legal effects for the data subject.
7. Cookies
The Shop uses cookies. Strictly necessary cookies are essential for the Shop to function (session, cart and cookie-consent cookies); their legal basis is the Controller's legitimate interest. Statistics and marketing cookies are only used with the data subject's prior express consent [Art. 6(1)(a) GDPR].
In the cookie banner shown on the first visit to the Shop, visitors can give or refuse consent by category (including a "reject all" option) and can change their choice at any time later. Tools that require consent are not activated until consent is given.
- Strictly necessary cookies: session, cart and consent cookies required for the Shopify shop to function.
- Statistics cookies (with consent): Google Analytics.
- Marketing cookies (with consent): Google Ads, Meta Pixel, TikTok Pixel.
Visitors can also block or delete cookies at any time in their browser settings; blocking cookies other than strictly necessary ones may limit some functions.
8. Processors
The Controller uses the following processors:
- Shopify International Limited – Victoria Buildings, 2nd Floor, 1-2 Haddington Road, Dublin 4, D04 XN32, Ireland (shop platform, hosting, Shopify Payments)
- Billingo Technologies Zrt. – 1133 Budapest, Árbóc utca 6. III. emelet, Hungary (invoicing)
- Vödrös Judit – 8000 Székesfehérvár, Zámoly utca 56., Hungary (accounting)
- GLS General Logistics Systems Hungary Kft. – 2351 Alsónémedi, GLS Európa utca 2., Hungary (delivery), and the GLS network partner in the country of destination
- Klaviyo, Inc. – 125 Summer Street, Boston, MA 02110, USA (email and SMS marketing)
- Google Ireland Limited – Gordon House, Barrow Street, Dublin 4, Ireland (email service, web analytics, advertising)
- Meta Platforms Ireland Limited – 4 Grand Canal Square, Dublin 2, Ireland (advertising, social media)
- TikTok Technology Limited – 10 Earlsfort Terrace, Dublin 2, D02 T380, Ireland (advertising)
The online withdrawal function in the Shop (EU Withdrawal Form) is provided by herrlich media GmbH; we process the data given in the withdrawal statement (name, email address, order number and, for cash on delivery, bank account) for the purpose of handling the withdrawal, on the basis of compliance with a legal obligation [Art. 6(1)(c)], for 5 years. The Controller only uses processors that undertake to comply with the obligations under Article 28 GDPR (data processing agreement – DPA).
9. Transfers to third countries
Some processors (Klaviyo and certain services of Google, Meta, TikTok and Shopify) may also transfer personal data outside the European Economic Area (EEA), usually to the United States or Canada.
Transfers are made with the safeguards provided for in Chapter V GDPR: on the basis of an adequacy decision of the European Commission (including for Canada and the EU–US Data Privacy Framework) or standard contractual clauses (SCCs) under Art. 46(2)(c) GDPR. In view of the judgment of the Court of Justice of the EU in Case C-311/18 (Schrems II), the Controller points out that the level of data protection in countries outside the EEA may differ from that in the EU.
10. Data security
The Controller ensures the security of personal data through appropriate technical and organisational measures against unauthorised access, alteration, transmission, disclosure, deletion, destruction and damage, in particular through encryption, access restriction, backups and regular review of the measures. In the event of a personal data breach, the Controller acts in accordance with Articles 33–34 GDPR.
11. Data subject rights and remedies
The data subject has the right to information, access, rectification, erasure, restriction of processing, data portability and to object, and, where processing is based on consent, the right to withdraw consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Requests can be sent to hello@pulowear.com. The Controller responds without undue delay and at the latest within one month; depending on the complexity of the request, this period may be extended by a further two months, of which the Controller informs the data subject. Information is provided free of charge.
The data subject may lodge a complaint:
- with the supervisory authority at the Controller's registered office: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH – Hungarian National Authority for Data Protection and Freedom of Information), 1055 Budapest, Falk Miksa utca 9–11., Hungary, phone: +36 1 391 1400, email: ugyfelszolgalat@naih.hu;
- with the supervisory authority of the Member State of their habitual residence (Article 77 GDPR) – see Annex 1.
In the event of an infringement of their rights, the data subject may also bring proceedings before the courts, including the courts of their country of residence.
12. Applicable legislation
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR);
- Hungarian Act CXII of 2011 on the right to informational self-determination and freedom of information;
- the Hungarian Civil Code (Act V of 2013);
- Hungarian Act C of 2000 on Accounting;
- Hungarian Act CLV of 1997 on Consumer Protection;
- and the national legislation of the data subject's country, as set out in Annex 1.
13. Final provisions
The Controller reserves the right to amend this policy; the amended policy will be published in the Shop. This policy enters into force on 1 October 2026.
Annex 1 – Annex for pulowear.com
- Shop: pulowear.com
- Language of the policy: English
- Data protection contact: hello@pulowear.com, +36 30 609 1780
- Delivery: the parcel is delivered by the GLS network partner in the country of destination, which receives the recipient's name, address, phone number and email address for this purpose
- Local supervisory authority: the data protection authority of the EU Member State of the data subject's habitual residence; a list of the national data protection authorities is available on the website of the European Data Protection Board: https://www.edpb.europa.eu/about-edpb/about-edpb/members_en
- National legislation: the national laws implementing the GDPR and the ePrivacy Directive (2002/58/EC – cookies, commercial communications, newsletters) in the data subject's country of residence