Privacy Policy

Version 1.0 — effective 2026.08.30

This Privacy Policy explains how ITEMVENDOR collects, uses, stores and shares personal data when you visit the Website, create an Account, place an Order, contact customer support or otherwise interact with ITEMVENDOR.

Capitalised terms used but not defined in this Privacy Policy have the meaning given to them in the ITEMVENDOR Terms and Conditions.


1. Controller

 

FieldInformation
ControllerBikkes Renáta, sole proprietor, trading as ITEMVENDOR
Address1101 Budapest, Kőbányai út 43.A 3/13, Hungary
Email[email protected]
Telephone+36 30 733 1937
Websitehttps://itemvendor.com
Data Protection OfficerITEMVENDOR has not appointed a Data Protection Officer, as it is not required to do so under Article 37 GDPR. This assessment is reviewed if the nature or scale of processing changes. Privacy-related requests may be sent to the email address above.


2. Personal Data We Process

 

Depending on how you use ITEMVENDOR, we may process the following categories of personal data:

  • Identity and contact data: name, billing address, country, email address, telephone number and Account identifiers.
  • Account data: Account identifier, registration information, Account status and security-related records.
  • Order and delivery data: selected Product or Service, game, platform, region, server, realm, league or mode where relevant, quantity, delivery information, instructions, Order status and Delivery Evidence.
  • Payment data: payment status, transaction identifiers, payment method, billing information, authentication results, risk indicators, refunds, chargebacks and payment-dispute records. Full payment-card details are processed by the applicable payment provider and are not stored by ITEMVENDOR.
  • Age-assurance data: the result of any age check carried out at checkout. ITEMVENDOR records only the outcome of the check and does not retain copies of identity documents submitted for that purpose.
  • Customer-service and legal communications: support requests, complaints, withdrawal or refund requests and other correspondence.
  • Fraud and security data: IP address, device and browser information, login and security records, payment-country or location indicators, verification results and other information reasonably necessary to prevent fraud or unauthorised transactions.
  • Marketing data: email address, marketing preferences and records of consent where you have chosen to receive marketing communications.
  • Cookie and technical data: cookie identifiers, consent records, website activity and similar technical information as described in the Cookie Policy.

ITEMVENDOR does not request or process Customer game-account passwords, login credentials or platform account credentials. ITEMVENDOR does not offer services requiring access to a Customer’s game account.

We may receive certain payment, security or verification information from payment providers, acquiring banks, fraud-prevention services or other service providers involved in an Order.


3. Purposes, Legal Bases and Retention

 

PurposeLegal basisRetention
Account creation and administrationSteps taken at the request of the data subject prior to entering into a contract, and performance of a contract (Art. 6(1)(b) GDPR)For the lifetime of the Account. Following closure, only data reasonably necessary for legal, fraud or dispute purposes is retained for the relevant limitation period.
Order processing and deliveryPerformance of a contract (Art. 6(1)(b) GDPR)Until the Order is completed or cancelled.
Retention of Order records for legal claimsLegitimate interests in establishing, exercising or defending legal claims (Art. 6(1)(f) GDPR)5 years from completion of the Order, corresponding to the general limitation period under Hungarian law.
Payment processingPerformance of a contract (Art. 6(1)(b) GDPR)Payment and transaction records are retained with the relevant Order record. Payment providers retain their own records under their applicable policies and legal obligations.
Invoicing, taxation and mandatory accounting recordsCompliance with a legal obligation (Art. 6(1)(c) GDPR)8 years, in accordance with Section 169 of the Hungarian Accounting Act.
Age assurance at checkoutCompliance with a legal obligation and legitimate interests in preventing contracts with persons lacking legal capacity (Art. 6(1)(c) and (f) GDPR)The outcome of the check is retained with the Order record. Identity documents submitted for verification are deleted immediately after the check is completed.
Customer supportPerformance of a contract and legitimate interests in customer service and dispute resolution (Art. 6(1)(b) and (f) GDPR)Retained with the relevant Order record.
Complaints and substantive complaint responsesCompliance with a legal obligation (Art. 6(1)(c) GDPR)3 years, in accordance with Hungarian consumer protection law.
Fraud prevention, security and verificationLegitimate interests in preventing fraud, protecting Customers, ITEMVENDOR and payment systems, and establishing or defending legal claims (Art. 6(1)(f) GDPR)For as long as reasonably necessary for the investigation or dispute, and where necessary for legal claims, up to the applicable limitation period.
Chargeback and payment-dispute evidenceLegitimate interests in defending against fraudulent or incorrect payment disputes and establishing or defending legal claims (Art. 6(1)(f) GDPR)For the duration of the dispute and afterwards where reasonably necessary for legal claims, normally no longer than 5 years.
Marketing emailConsent (Art. 6(1)(a) GDPR)Until consent is withdrawn. Limited evidence of consent or withdrawal is retained where reasonably necessary to demonstrate compliance.
Non-essential cookies and similar technologiesConsent (Art. 6(1)(a) GDPR)As described in the Cookie Policy and the applicable cookie register.
Website and Account security logsLegitimate interests in security, abuse prevention and fraud detection (Art. 6(1)(f) GDPR)12 months, unless a longer period is required for an ongoing investigation or legal claim.


Where processing relies on legitimate interests, ITEMVENDOR has assessed the necessity of the processing against the rights and interests of the individuals concerned. Information about that assessment may be requested at [email protected].

Information identified as mandatory during Account registration or checkout is required in order to create the Account, process or deliver an Order, process payment, carry out verification or comply with legal obligations. If required information is not provided, ITEMVENDOR may be unable to create the Account or to accept or complete the Order.

4. Recipients and Service Providers

 

Recipient categoryProviderPurpose
Hosting and infrastructureDigitalOcean, LLC — hosting region: Frankfurt, GermanyWebsite hosting, database infrastructure, backups and security.
Payment providers and acquiring partners[insert provider name once contracted]Payment processing, authentication, fraud prevention, refunds and payment disputes.
---
Email and customer communicationBrevo (Sendinblue SAS), FranceTransactional emails, customer communications and, where separately consented to, marketing communications.
Accounting and invoicingBillingo Technologies Zrt., HungaryInvoicing and related statutory record keeping.
Controlled fulfilment subcontractorsSelected subcontractors involved in fulfilment where necessary for an OrderSourcing and delivery of an accepted Order. Only the information reasonably necessary for the relevant delivery is provided.
Professional advisersLegal, accounting, tax or audit advisers where requiredProfessional advice, compliance and legal claims.
Authorities and public bodiesCompetent authorities where disclosure is required or permitted by lawLegal and regulatory compliance, fraud investigation and enforcement.


Controlled fulfilment subcontractors receive only the information reasonably necessary to perform the assigned part of an Order. They are not provided with payment-card details, and ITEMVENDOR does not hold Customer game-account credentials to provide.

Service providers processing personal data on behalf of ITEMVENDOR act as processors and are engaged under a written data-processing agreement meeting the requirements of Article 28 GDPR. They may process the data only on ITEMVENDOR’s documented instructions and are subject to appropriate confidentiality and security obligations.

5. International Data Transfers

ITEMVENDOR selects service providers that process personal data within the European Economic Area wherever reasonably possible.

DigitalOcean, LLC is established in the United States. ITEMVENDOR uses its Frankfurt hosting region so that personal data is stored within the EEA. Where the provider may nonetheless access personal data from outside the EEA for support or infrastructure purposes, that transfer takes place under the European Commission’s Standard Contractual Clauses together with the provider’s supplementary technical and organisational measures.

Where personal data is otherwise transferred outside the EEA, ITEMVENDOR uses a transfer mechanism permitted under Chapter V of the GDPR, such as:

  • a European Commission adequacy decision;
  • Standard Contractual Clauses approved by the European Commission;
  • another transfer mechanism permitted by applicable data-protection law.

Additional safeguards are applied where required following a transfer impact assessment.

Information concerning the safeguards applicable to a particular transfer may be requested at [email protected].

6. Security

ITEMVENDOR uses appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, loss or misuse.

These measures include:

  • access controls and restricted internal permissions;
  • encrypted transmission of data;
  • Account and Website security monitoring;
  • fraud-prevention controls;
  • security logging;
  • contractual and technical restrictions on access by service providers and subcontractors;
  • appropriate backup and infrastructure-security measures.

Customers are responsible for maintaining the confidentiality of their ITEMVENDOR Account credentials and should notify ITEMVENDOR promptly if they suspect unauthorised access.

ITEMVENDOR does not store full payment-card details. Those details are processed directly by the applicable payment provider.

7. Personal Data Breaches

ITEMVENDOR maintains procedures for detecting, investigating and recording personal data breaches.

Where a breach is likely to result in a risk to the rights and freedoms of individuals, ITEMVENDOR notifies the National Authority for Data Protection and Freedom of Information without undue delay and, where feasible, within 72 hours of becoming aware of it.

Where a breach is likely to result in a high risk to the rights and freedoms of individuals, ITEMVENDOR also informs the affected individuals without undue delay, describing the nature of the breach, its likely consequences and the measures taken.

8. Cookies and Similar Technologies

ITEMVENDOR uses cookies and similar technologies necessary for Website functionality, Account sessions, security, fraud prevention and checkout operation.

Non-essential analytics, advertising or marketing cookies are used only where the required consent has been obtained. Consent may be withdrawn at any time through the cookie settings available on the Website.

Further information about the cookies and similar technologies used on the Website, including their purposes and retention periods, is provided in the Cookie Policy.

9. Marketing Communications

ITEMVENDOR sends marketing emails only where the Customer has given prior consent.

Every marketing email contains a clearly visible unsubscribe link. Consent may also be withdrawn at any time by contacting [email protected], at no cost to the Customer.

Withdrawing marketing consent does not affect transactional communications relating to an Order, which are sent on the basis of contract performance.

10. Data-Subject Rights

Subject to the conditions of the GDPR, you have the right to:

  • request access to your personal data;
  • request correction of inaccurate or incomplete personal data;
  • request erasure of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • receive eligible personal data in a portable format;
  • withdraw consent at any time where processing is based on consent;
  • object at any time to the use of personal data for direct marketing.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

Requests may be submitted to [email protected].

ITEMVENDOR may request reasonable information necessary to verify the identity of the person making a request before disclosing, modifying or deleting personal data.

ITEMVENDOR responds to valid data-protection requests without undue delay and in any event within one month of receipt. That period may be extended by two further months where necessary, taking into account the complexity and number of requests; the Customer is informed of any such extension within one month.

You also have the right to lodge a complaint with a competent supervisory authority. For ITEMVENDOR’s Hungarian establishment, the supervisory authority is:

National Authority for Data Protection and Freedom of Information (NAIH)
1055 Budapest, Falk Miksa utca 9-11, Hungary
Email: [email protected]
Telephone: +36 1 391 1400
Website: https://www.naih.hu

11. Automated Processing and Fraud Controls

ITEMVENDOR uses fraud, security and payment-risk indicators to identify transactions requiring additional verification or manual review.

An Order is never delayed beyond the applicable review period, refused or cancelled on the basis of automated processing alone. Where fraud or payment-risk indicators suggest a concern, the Order is referred for human review before any refusal or cancellation decision is taken.

ITEMVENDOR does not carry out solely automated decision-making within the meaning of Article 22 GDPR that produces legal effects concerning Customers or similarly significantly affects them.

Payment providers and financial institutions operate their own authentication, fraud-detection and payment-authorisation systems under their respective privacy and compliance frameworks.

12. Children

ITEMVENDOR is intended for persons aged 18 or older. Orders may not be placed by persons under 18.

ITEMVENDOR applies age-assurance measures at checkout and may refuse or cancel an Order where the Customer appears not to meet the age requirement. ITEMVENDOR records only the outcome of an age check and does not retain identity documents submitted for that purpose.

ITEMVENDOR does not knowingly collect personal data relating to persons under 18. If ITEMVENDOR becomes aware that such data has been collected, it will delete the data without undue delay unless a legal obligation requires its retention, and will cancel and refund any related Order.

A parent or guardian who believes that a person under 18 has provided personal data to ITEMVENDOR may contact [email protected], and the data will be deleted in accordance with this Section.

13. Changes to this Privacy Policy

ITEMVENDOR may update this Privacy Policy to reflect changes in applicable law, processing activities, service providers, Website functionality or business operations.

The current version displays its effective date.

Where the change is material, ITEMVENDOR informs Customers through the Website or another appropriate communication method before the change takes effect.

14. Contact

Questions or requests concerning this Privacy Policy or the processing of personal data may be sent to the controller identified in Section 1, at [email protected].