Barion Pixel
Skip to main content
The cart is empty

Privacy and Cookie Notice

For visitors, subscribers and customers of www.duelofwizards.com

Controller: Alec Media és Design Solution Kft. • Effective: 1 August 2026 • Version: 1.0

In brief: Without the necessary data, an order or message cannot be processed. Newsletters are sent only with prior consent, which may be withdrawn free of charge at any time. Non-essential cookies and external content may be activated only after the visitor has made a choice.

1.1. Purpose and scope of this Notice

This Notice explains how Alec Media és Design Solution Kft. processes the personal data of visitors, contacts, newsletter subscribers and customers of the website and online shop at https://www.duelofwizards.com. It covers the website, contact form, newsletter, orders, payment, delivery, withdrawal, complaints and conformity claims, and the use of cookies and similar technologies.

The Controller processes personal data in accordance with the European Union's General Data Protection Regulation (GDPR), the Hungarian Privacy Act and the Hungarian laws applicable to the individual processing activities. This version describes the data-processing arrangements prepared for the Webshop's operation in 2026.

2.2. Controller details

Item

Details

Controller

Alec Media és Design Solution Korlátolt Felelősségű Társaság

Short company name

Alec Media és Design Solution Kft.

Registered office and postal address

4031 Debrecen, Derék utca 18. 2. em. 17. ajtó, Hungary

Company registration number

09-09-036693

Tax number

32739853-1-09

Registering court

Company Court of the Debrecen Regional Court (Debreceni Törvényszék Cégbírósága)

Represented by

Takács Sándor, managing director

E-mail

This email address is being protected from spambots. You need JavaScript enabled to view it.

Website

Duel of Wizards website

The Controller has not appointed a data protection officer. Privacy enquiries and requests to exercise data-subject rights may be sent to This email address is being protected from spambots. You need JavaScript enabled to view it. or by post to the Controller's registered office.

3.3. Data-protection principles

Lawfulness, fairness and transparency: the purpose and legal basis of processing are made known in advance.

Purpose limitation and data minimisation: only data necessary for the stated purpose are processed.

Accuracy: inaccurate data identified by the Controller are corrected; Customers must also provide accurate data.

Storage limitation: data are retained for the periods stated below or for as long as necessary for legal claims.

Integrity and confidentiality: technical and organisational measures proportionate to the risk are applied.

Accountability: processing decisions, consents and data-subject requests are documented in a demonstrable manner.

4.4. Individual processing activities

4.1. Website visits, logs and IT security

Purpose: displaying the website, troubleshooting, preventing unauthorised access and abuse, and ensuring availability

Data processed: IP address, request and response time, page visited, browser and device technical data, error and security logs

Legal basis: Article 6(1)(f) GDPR - the Controller's legitimate interests in secure and demonstrable operation

Retention: normally 30 days; in the event of a security incident, for as long as necessary to investigate and close the incident and to pursue or defend legal claims

Recipients: hosting and server operator, IT maintenance provider and, where justified, a competent authority

Provision of data: automatic; without it the website cannot be served securely

4.2. Contact form and e-mail

Purpose: receiving and answering questions, press enquiries and other messages and tracking the matter

Data processed: name, subject, e-mail address, message content and any further data voluntarily supplied

Legal basis: Article 6(1)(b) GDPR where the enquiry concerns steps before entering into or performing a contract; otherwise Article 6(1)(f) GDPR - the legitimate interest in handling enquiries

Retention: one year after the matter is closed; three years for an enquiry treated as a consumer complaint and the corresponding response; in the case of a legal claim, no longer than the end of the applicable limitation period

Recipients: website and e-mail provider and, where necessary, a professional adviser

Provision of data: voluntary, but an enquiry cannot be handled on the merits without a name and a working reply address

4.3. Newsletter and direct marketing

Purpose: sending news, new editions, events and offers

Data processed: e-mail address, the text and time of consent, confirmation and unsubscribe data and, if requested during subscription, name and data required for an age check

Legal basis: Article 6(1)(a) GDPR and the prior, specific, informed and unambiguous consent required by the Hungarian Advertising Act

Retention: until unsubscribe; evidence of consent and withdrawal may be stored separately for up to five years after withdrawal for the establishment, exercise or defence of legal claims

Recipients: the e-mail and newsletter-system provider, if used by the Controller

Provision of data: voluntary; refusal or withdrawal of consent does not affect purchasing or other services

Every newsletter contains a simple, free unsubscribe option. Consent may also be withdrawn by writing to This email address is being protected from spambots. You need JavaScript enabled to view it..

4.4. Basket and preparation of the order

Purpose: maintaining the selected products and the checkout process and allowing input errors to be corrected

Data processed: session identifier, basket contents, quantity, language and technical settings

Legal basis: Article 6(1)(b) GDPR - steps taken at the Customer's request before entering into a contract; Article 6(1)(f) GDPR for security elements

Retention: until the end of the session or, for an abandoned basket, up to 30 days; marketing messages about an abandoned basket are sent only where a separate appropriate legal basis exists

Recipients: webshop and hosting provider and IT operator

Provision of data: necessary to use the basket

4.5. Order and performance of the contract

Purpose: receiving and acknowledging the order, managing payment and delivery status, performance and customer communication

Data processed: name, e-mail address, telephone number, billing and delivery address, products and quantities ordered, price, order identifier, payment method and status, delivery information and communications

Legal basis: Article 6(1)(b) GDPR - entering into and performing the contract

Retention: five years after performance or termination of the contract, having regard to the civil-law limitation period; longer separate retention applies to accounting records

Recipients: webshop and hosting provider, payment provider, invoicing provider, accountant, selected carrier and IT operator

Provision of data: the mandatory fields are contractual requirements; without them the order cannot be performed

4.6. Invoicing and accounting

Purpose: issuing and retaining invoices and complying with tax and accounting obligations

Data processed: name or company name, billing address, tax number, order and invoice data, consideration and payment status

Legal basis: Article 6(1)(c) GDPR - compliance with legal obligations

Retention: eight years, in accordance with the record-retention requirements of the Hungarian Accounting Act

Recipients: electronic invoicing provider, accountant, the Hungarian tax authority and other competent authorities

Provision of data: mandatory; a lawful invoice cannot be issued without the necessary data

4.7. Delivery

Purpose: delivery of the ordered goods, addressing, delivery notifications and tracking

Data processed: recipient name, delivery address, telephone number, e-mail address, order or parcel identifier and cash-on-delivery amount where applicable

Legal basis: Article 6(1)(b) GDPR - performance of the contract

Retention: five years as part of the Controller's order records; the carrier's own notice governs its retention periods

Recipients: the courier, postal or parcel-point provider selected at checkout

Provision of data: mandatory where the Customer requests delivery

4.8. Withdrawal, returns, complaints and conformity claims

Purpose: providing the right of withdrawal, acknowledging an online withdrawal statement, refunds, complaints and investigation of conformity claims

Data processed: name, contact details, address, order identifier, product and payment data, content and time of the withdrawal or complaint, evidence and case-handling records

Legal basis: Article 6(1)(b) GDPR - performance of the contract; Article 6(1)(c) GDPR - consumer-protection and accounting obligations; where justified, Article 6(1)(f) GDPR - the establishment, exercise or defence of legal claims

Retention: three years for the consumer complaint and response; normally five years for documents connected with contractual claims; eight years for an accounting correction document

Recipients: payment provider, return carrier, accountant, expert, legal adviser, consumer conciliation body, authority or court

Provision of data: the relevant order must be identified in order to exercise the right

4.9. Card payment and Barion

Purpose: processing card payment, confirming payment and preventing abuse

Data processed: the Controller receives the payment identifier, amount and status; it does not receive the card number, CVC or complete card details. Barion may process technical, device and transaction data through its own interface and Pixel

Legal basis: Article 6(1)(b) GDPR for the Controller; Barion's own notice and legal bases apply to Barion's processing, including legitimate interests in fraud prevention and consent for marketing

Retention: according to the Controller's order and accounting periods; at Barion according to Barion's notice in force

Recipients: Barion Payment Zrt., 1117 Budapest, Irinyi József utca 4-20., 2nd floor, Hungary; Barion may also act as an independent controller

Provision of data: necessary when card payment is selected; any other available payment method is shown at checkout

4.10. External OpenStreetMap content

Purpose: displaying contact or location details on a map

Data processed: IP address, browser and device data, requested map tile and time; the OpenStreetMap provider may process additional technical data under its own notice

Legal basis: Article 6(1)(a) GDPR - the visitor's prior consent; the external map must not load before consent

Retention: the Controller retains only the consent choice for up to 13 months; the external provider's own retention period applies

Recipients: OpenStreetMap Foundation and its technical service providers

Provision of data: voluntary; without consent the address remains available in text form

5.5. Cookies and similar technologies

A cookie is a small data file stored by the browser on the user's device. A pixel, local storage and browser fingerprinting may perform similar identification or measurement functions. Technologies strictly necessary for the website and checkout may be used; preference, analytics or marketing technologies may be activated only with an appropriate legal basis, normally prior consent.

Technology / provider

Category

Purpose

Duration and legal basis

Joomla/HikaShop session identifier (dynamic name)

Strictly necessary

Session, basket and security functions.

Session or up to 30 days; provision of the service and legitimate interests.

YOOtheme consent setting

Strictly necessary

Stores the cookie choice so that it does not have to be entered again on every page.

Up to 13 months; evidence of the consent decision and legitimate interests.

ba_vid and ba_vid.xxx - Barion

Necessary payment fraud prevention

Browser and visit identification for Barion Smart Gateway fraud prevention.

Up to 1.5 years from the last update; Barion's legitimate interests.

ba_sid and ba_sid.xxx - Barion

Necessary payment fraud prevention

Session identification and abuse prevention.

30 minutes; Barion's legitimate interests.

BarionMarketingConsent.xxx - Barion

Marketing

Stores the choice made for Barion's marketing measurement and personalisation.

Up to 1.5 years from the last update; consent only.

Barion Pixel and browser fingerprinting

Fraud prevention / marketing

Payment fraud prevention; marketing use only with separate consent.

According to Barion's notice; legitimate interests or, for marketing, consent.

External OpenStreetMap map content

Preferences

Displays the map; the provider may receive the IP address and technical data with the request.

On loading / according to the provider's rules; prior consent.

The cookie panel makes 'Accept', 'Reject' and 'Settings' equally easy to access. Consent can be given by category, withdrawn at any time and requested again no later than thirteen months afterwards. Blocking cookies in browser settings does not replace the website's prior-consent management.

According to Barion's notice, the basic fraud-prevention component of Barion Pixel may rely on legitimate interests; marketing use and the BarionMarketingConsent technology may be enabled only with consent. The website also communicates the consent decision to Barion Pixel.

6.6. Recipients, processors and transfers

To the extent necessary for the relevant purpose, the Controller may use the following categories of recipients:

hosting, server, domain, e-mail and IT-operations providers;

webshop, invoicing, accounting and customer-service system providers;

the payment and delivery provider selected at checkout;

legal, tax, accounting, information-security or other professional advisers;

authorities, courts, consumer conciliation bodies or other recipients authorised by law.

A processor may act only on the Controller's documented instructions and under appropriate confidentiality, security and deletion obligations. Providers acting as independent controllers - particularly Barion and the OpenStreetMap Foundation - are responsible for their own processing.

The Controller seeks to process data within the European Economic Area. Personal data are transferred to a third country only where an adequacy decision, an appropriate safeguard - such as the European Commission's standard contractual clauses - or a specific GDPR derogation permits the transfer. Information on the applicable safeguard is provided on request.

7.7. Automated decision-making and profiling

The Controller does not make a decision based solely on automated processing that produces legal effects concerning a data subject or similarly significantly affects them. The payment provider may use automated risk analysis for fraud prevention under its own privacy notice. If a payment is rejected, the data subject may request information from the payment provider and contact the Seller's customer service.

8.8. Data-subject rights

Subject to the applicable conditions, a data subject may:

obtain information about and access to their personal data, including a copy;

require correction of inaccurate data and completion of incomplete data;

require erasure where no overriding legal basis or retention obligation applies;

require restriction of processing;

receive data portability for automated processing based on a contract or consent;

object to processing based on legitimate interests; following an objection to direct marketing, the data may no longer be processed for that purpose;

withdraw consent at any time without affecting the lawfulness of processing before withdrawal;

lodge a complaint with a supervisory authority and seek a judicial remedy.

A request may be sent to This email address is being protected from spambots. You need JavaScript enabled to view it. or to the Controller's postal address. The Controller responds without undue delay and normally within one month. For a complex or large number of requests, the period may be extended by two further months; the data subject is informed of the extension within one month. Only additional data necessary to verify identity may be requested.

9.9. Security and personal-data breaches

The Controller applies measures proportionate to the risk, including encrypted data transfer, access control, entitlement reviews, backups, updates, logging and contractual oversight of processors. The Seller does not store card data.

If a personal-data breach occurs, the Controller assesses the risk and documents the event. Where the statutory conditions are met, the breach is notified to the supervisory authority within seventy-two hours. Data subjects are informed without undue delay where the breach is likely to result in a high risk.

10.10. Data relating to minors

The website and product are intended for adults. The Controller does not knowingly collect newsletter or purchase data from a person under eighteen. If the Controller obtains reliable knowledge that a minor supplied data without an appropriate legal basis, the data are erased or the required condition of lawfulness is established.

11.11. Complaints and remedies

A data subject may first contact the Controller at This email address is being protected from spambots. You need JavaScript enabled to view it.. Independently of this, a complaint may be lodged with the competent supervisory authority:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
1055 Budapest, Falk Miksa utca 9-11., Hungary
Postal address: 1363 Budapest, P.O. Box 9, Hungary
E-mail: This email address is being protected from spambots. You need JavaScript enabled to view it.
Telephone: +36 1 391 1400
Website: https://www.naih.hu

A data subject may also seek a judicial remedy and, subject to the legal conditions, bring proceedings before the court competent for their residence or place of stay. Compensation or damages for non-material harm may be claimed where the relevant conditions are met.

12.12. Changes to this Notice

The Controller updates this Notice following a change in law, a new function or provider, or another material change to processing. The current version is accessible from the Webshop footer. If a change concerns consent-based processing, fresh consent is requested where necessary.

13.13. Principal legal and service-provider sources

Regulation (EU) 2016/679 - General Data Protection Regulation (GDPR)

Act CXII of 2011 - Hungarian Privacy Act

Act CVIII of 2001 - electronic commerce and online processing

Act XLVIII of 2008 - electronic advertising and consent

NAIH - privacy requirements for online shops

NAIH - customer service and contact

Barion - Pixel consent-management requirements

Barion - Privacy Notice

OpenStreetMap Foundation - Privacy Policy

The ultimate wizard-themed drinking card game. Cast spells, curse friends, and drink to power up.

Stay Updated

Subscribe for news, expansions, and exclusive offers.

© 2026 Duel of Wizards. All rights reserved.