Privacy Notice

on data processing in connection with the website of Hegyenjáró Accommodation and Catering Ltd.

Hegyenjáró Accommodation and Catering Ltd., as the data controller, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (27 April 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, hereby informs Data Subjects of the following regarding the processing of their personal data.

1. Name and contact details of the data controller

Hegyenjáró Accommodation and Catering Ltd. (registered office: 8237 Tihany, 9 Cserhegy Street, Company Registration Number: 19 09 522738, tax number: 27727416-2-19, email: ferencpince@gmail.com)

2. Description of the data processing to be carried out

Data processing in connection with the data controller’s website, accessible at ferencpince.hu

APurpose of data processingLegal basis for data processingScope of data processedDuration of data processing
Handling enquiries received via the contact form, including requests for a call-back and requests for a quote.The consent of the volunteer concerned.The data subject’s name, email address, telephone number and any personal data which the data subject refuses to provide for the purpose of establishing contact.Until the purpose of the data processing ceases to apply.

No automated decision-making, including profiling, takes place during data processing.

The service provider is under no obligation to verify whether the data subject is authorised to provide the data they have submitted. The applicant bears sole responsibility for ensuring that such authorisation exists.

3. Information on the use of data processors

Access to the data is restricted to those employees acting on behalf of the Data Controller who require it to carry out their duties and who are aware of their obligations regarding the processing of the data.

Personal data will not be transferred to third parties for the purposes of data processing.

4. The rights of data subjects in relation to data processing

Right to information

General rules on providing information to data subjects and the right to information

Before data processing begins, and at the latest when the data subject’s personal data are collected, the data controller must provide the data subject with detailed information. This information relates to the data processing and is set out in this Notice.

The data controller is responsible for providing the preliminary information.

In addition to the preliminary information provided above, you may request information from the data controller at any stage of data processing, as set out below. In such cases, the data controller must provide the information without delay, but no later than within 30 days. The one-month deadline may only be extended by a maximum of two months in justified cases.

The data controller may refuse to provide the information only if it can demonstrate that the data subject cannot be identified, or that the data subject’s request is manifestly unfounded, repetitive or excessive.

If the data controller fails to take action, that is to say, fails to fulfil its duty to provide information, it must, within 30 days, inform the data subject of the failure to take action, the reason for this, and the data subject’s right to lodge a complaint or bring a legal action in relation to the processing of personal data. This notice contains further details regarding complaints and judicial remedies.

The data controller must provide the information and take the necessary measures free of charge to the data subject. However, in exceptional cases, the data controller may charge a reasonable fee or refuse to provide the information or take the requested action if the data subject’s request is manifestly unfounded, repetitive or excessive.

The data subject’s right of access

The data subject is entitled to receive confirmation from the data controller as to whether their personal data are being processed and, where such processing is taking place, is entitled to access their personal data and the following information:

Under the right of access, the data subject must be provided with the following information upon request:

The data controller shall provide the data subject with a copy of the personal data being processed. For any further copies requested by the data subject, the data controller may charge a reasonable fee based on administrative costs; should such a fee apply, the data subject will be informed of the costs in advance.

Where the data subject has submitted the request electronically, our company will make the information available to the data subject in a widely used electronic format, unless the data subject requests it in a different format.

Right to rectification

The data subject has the right to have inaccurate personal data concerning them rectified by the data controller without undue delay upon request. Taking into account the purposes of the data processing, the data subject has the right to request that incomplete personal data be completed, including, amongst other things, by means of a supplementary statement.

Right to erasure, „the right to be forgotten”

The data subject has the right to request that the data controller erase personal data relating to them without undue delay, and the data controller is obliged to erase personal data relating to the data subject without undue delay if any of the following grounds apply:

Where the data controller has made the personal data public and is obliged to erase it in accordance with the above list, it shall take all steps that can reasonably be expected, taking into account the available technology and the costs of implementation – including technical measures – to inform the data controllers processing the data that the data subject has requested the deletion of links to, or copies or duplicates of, the personal data in question.

The data controller is not obliged to comply with a request for erasure made in the above cases if the processing is necessary:

Where any of the above grounds apply and the data controller is not obliged to comply with the data subject’s request for erasure, the data controller must inform the data subject of this fact within 25 days, stating the reasons therefor.

The right to restrict processing

The data subject is entitled to request that the data controller restrict the processing of their data if any of the following conditions are met:

Where data processing is subject to restrictions in accordance with the above, such personal data may, apart from storage, only be processed with the data subject’s consent, or for the purpose of asserting, or to protect the rights of another natural or legal person, or for reasons of substantial public interest of the Union or of a Member State.

The data controller shall inform the data subject, in respect of whom data processing has been restricted at their request in accordance with the above, in advance of the lifting of the restriction on data processing.

The obligation to provide notice in relation to the rectification or erasure of personal data, or the restriction of processing

The data controller is obliged to inform any recipient to whom the personal data has been disclosed of any rectification, erasure or restriction of processing, unless this proves impossible or would involve a disproportionate effort.

The right to data portability

The data subject has the right to receive the personal data concerning them, which they have provided to a data controller, in a structured, commonly used and machine-readable format, and is also entitled to transmit those data to another data controller without hindrance from the data controller to whom the personal data were provided, where:

When exercising the right to data portability as set out above, the data subject is entitled – where technically feasible – to request that their personal data be transferred directly from one data controller to another.

The exercise of the right to data portability must not infringe the right to erasure. The right to data portability must not adversely affect the rights and freedoms of others.

The right to protest

The data subject has the right to object at any time to the processing of their personal data on grounds relating to their particular situation. In such cases, the data controller may no longer process the personal data, unless the data controller demonstrates that there are compelling legitimate grounds for the processing which override the data subject’s interests, rights and freedoms, or which relate to the establishment, exercise or defence of legal claims.

Where personal data is processed for the purposes of direct marketing (e.g. sending marketing letters to customers), the data subject has the right to object at any time to the processing of their personal data for this purpose, including profiling, insofar as it is related to direct marketing. If the data subject objects to the processing of personal data for the purposes of direct marketing, the personal data may no longer be processed for that purpose.

Right to withdraw consent

Where the legal basis for data processing is the data subject’s consent (e.g. sending a newsletter for marketing purposes), the data subject is entitled to withdraw their consent to the data processing at any time. However, the withdrawal of consent does not render the data processing carried out prior to the withdrawal unlawful.

Consent is withdrawn if the data subject deletes their user account themselves; alternatively, consent to the processing of personal data may also be withdrawn by email, by sending a message to ferencpince@gmail.com sent to that address, requesting its deletion.

Legal remedies, Right to complain, Judicial remedies

In other words, what can the data subject do if they believe their personal data is not being processed in accordance with the rules?

Right to complain

The data subject is entitled to lodge a complaint with a supervisory authority – in particular in the Member State of their habitual residence, their place of work or the Member State in which the alleged infringement took place – if the data subject considers that the processing of their personal data is unlawful. In Hungary, the competent supervisory authority is the National Authority for Data Protection and Freedom of Information (NAIH).

Exercising the right to lodge a complaint does not preclude the data subject from seeking other administrative or judicial remedies if they consider that their personal data is being processed in breach of the law. Therefore, even when exercising their right to lodge a complaint, they may simultaneously initiate administrative or judicial redress proceedings.

Complaints may be lodged with the National Authority for Data Protection and Freedom of Information, whose contact details are as follows:

Name: National Authority for Data Protection and Freedom of Information

Registered office: 1055 Budapest, Falk Miksa Street 9–11.

Postal address: 1530 Budapest, PO Box 5.

Telephone: +36 1 391 1400

Fax: +36 1 391 1410

Website: http://www.naih.hu

Email: ugyfelszolgalat@naih.hu

Data processing registration number: NAIH-126761/2017

The right to a judicial remedy against a decision by the NAIH or another supervisory authority

If you have lodged a complaint with the supervisory authority (NAIH) regarding the processing of your personal data, and the authority has issued a decision on your case, then, as the data subject, you are entitled to seek judicial redress against that decision, that is, to challenge the decision in court. The data subject is entitled to the aforementioned right to judicial remedy even if the competent supervisory authority (NAIH) fails to deal with the complaint or fails to inform the data subject within three months of the progress of the proceedings relating to the complaint or of its outcome.

Proceedings against the supervisory authority (NAIH) must be brought before a court in the Member State where the supervisory authority has its registered office.

The right to seek judicial redress against the data controller or the data processor

The data subject is entitled to seek judicial redress if they consider that their rights in relation to data processing have been infringed as a result of the unlawful processing of their personal data. Exercising the right to judicial redress does not preclude the data subject, if they consider that their personal data is being processed in breach of the law, to have recourse to other administrative or judicial remedies, or to exercise their right to lodge a complaint.

Proceedings against the data controller or the data processor must be brought before the courts of the Member State in which the data controller or the data processor has its place of business.

In the case of Hegyenjáró Accommodation and Catering Ltd., the courts with jurisdiction are those in Hungary, based on the place where the business is carried out. Meanwhile, the court with jurisdiction over the registered office of Hegyenjáró Accommodation and Catering Ltd. is the Veszprém District Court.

Judicial proceedings may also be brought before the courts of the Member State in which the data subject has his or her habitual residence, unless the data controller or data processor is a public authority of a Member State acting in the exercise of its public powers.

Liability for damages and compensation for pain and suffering

In other words, how is the data controller or data processor liable to the data subject in the event of damage?

Where improper data processing has caused damage to the data subject, the data controller is liable for compensation for that damage. Damage may be said to have occurred where the processing of data was unlawful or in breach of contract, and this has resulted in financial loss to the data subject. In the event of unlawful data processing, the data subject may also claim compensation for non-pecuniary damage.

You may primarily assert your claim for compensation or damages against the data controller. The data processor is only liable for damages if it has breached the rules applicable to it or has failed to follow the data controller’s lawful instructions. In other words, the data processor is not liable for errors committed by the data controller.

5. Storage of personal data and data security

We select and use the IT tools and solutions employed for data processing, in particular security systems, in such a way that the personal data being processed is accessible to authorised persons, their authenticity and integrity are guaranteed, their immutability can be verified, and they are protected against unauthorised access.

Taking into account the current state of the art, we ensure the security and protection of our data processing activities through technical, organisational and structural measures that guarantee an appropriate level of protection for your personal data.

24 September 2026.