PartSide Balatonfüred (hereinafter: Accommodation) respects the personal rights of its Guests, and therefore makes the following Data Management Notice (hereinafter: Notice) available electronically on the official website (www.partsidebalatonfured.hu) and in paper form at the Accommodation.
The Accommodation, as the data controller, declares that it handles personal data in accordance with the provisions of REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL (27 April 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter: GDPR).
This Notice provides general information on data processing conducted in connection with the services provided by the Accommodation. Due to the diverse needs of Guests, the method of data processing may occasionally differ from what is described in this Notice; such deviations occur at the Guest’s request, and the Accommodation will inform the Guest in advance about the exact method. Any data processing not explicitly covered in this Notice will be communicated prior to the data being processed.
The Accommodation collects and processes personal data only for a predefined purpose, for the duration necessary to exercise rights and fulfill obligations. The Operator handles only those personal data necessary and adequate to achieve the purpose of data processing.
For minors under the age of sixteen, any declaration of consent is valid only with the approval or subsequent confirmation of their legal representative. In all cases where the Accommodation uses data for a purpose different from the original collection purpose, the data subject will be informed and their prior explicit consent will be requested, or they will be given the opportunity to prohibit such use.
During data processing, personal data obtained by the Operator will be accessible only to persons authorized by the Accommodation or those employed under a work relationship with the Accommodation who have tasks related to the data processing.
By making a reservation, the Guest accepts the provisions of this Data Protection Notice
(hereinafter: Data Protection Notice).
I. Basic Concepts
- personal data: Information relating to an identified or identifiable natural person (data subject), in particular the data subject’s name, identification number, or one or more factors specific to their physical, physiological, mental, economic, cultural, or social identity, as well as any conclusions drawn from the data relating to the data subject.
- data set: The totality of data managed in a single record.
- data subject: Any natural person identified or identifiable, directly or indirectly, based on information.
- technical tasks related to data processing: Any technical operations performed on data, regardless of the methods, tools, or location used, provided the technical tasks are performed on the data itself.
- third party: Any natural or legal person, or organization without legal personality, that is not identical to the data subject, the data controller, or the data processor.
- data protection: The combination of technologies and organizational methods that ensure the integrity, usability, confidentiality, and inviolability of collected data.
- data protection incident: Any breach of data security that results in accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or unauthorized access to transmitted, stored, or otherwise processed personal data.
- data processing: Any operation or set of operations performed on data, regardless of the procedure applied, including but not limited to collection, recording, organization, structuring, storage, alteration, use, retrieval, disclosure, transmission, dissemination, or making available, alignment or combination, restriction, deletion, destruction, prevention of further use, taking photographs, audio or video recordings, and recording physical characteristics suitable for identifying the person (e.g., fingerprints, palm prints, DNA sample, iris image).
- data controller: The natural or legal person, or organization without legal personality, who alone or jointly with others determines the purpose of data processing, makes and executes decisions regarding data processing (including the tools used), or has them executed by a data processor.
- data transfer: Making data accessible to a specific third party.
- data deletion: Rendering data unrecognizable so that recovery is no longer possible.
- restriction of data processing: Marking stored personal data to limit their future processing.
- consent: The data subject’s voluntary, specific, and unambiguous expression of will, based on clear information, by which the data subject gives their agreement—either by statement or by unambiguous affirmative action—for the processing of their personal data, either in full or for specific operations. Consent includes checking a box during website use or completing a reservation, performing relevant technical settings, or any other declaration or action (electronic or paper) that clearly indicates the data subject’s agreement to the planned processing of their personal data.
- special categories of data: Personal data revealing racial or ethnic origin, political opinions or party affiliation, religious or other beliefs, trade union membership, sexual life, health, pathological addictions, or criminal data.
- objection: The data subject’s declaration challenging the processing of their personal data and requesting that processing be ceased or the data be deleted.
- disclosure: Making data accessible to anyone.
- profiling: Any form of automated processing of personal data intended to evaluate certain personal aspects of a natural person, in particular to analyze or predict aspects related to work performance, economic situation, health, personal preferences, interests, reliability, behavior, location, or movement.
II. Data Controller
Accommodation Name: PartSide Balatonfüred
Accommodation Address: 8230 Balatonfüred, Germering street 13/A
Data Controller, Accommodation Operator: tAX Kft.
Data Controller, Operator Address: 8200 Veszprém, Óváros tér 22.
Legal Representative, Data Protection Officer: Antal Lakatos, Managing Director
Contact Information:
(hereinafter: Operator / Accommodation)
III. Purpose of Data Processing
The Data Controller processes Guests’ personal data for the following purposes:
- Primarily, to enable booking at the Accommodation, certain personal data must be provided, as detailed below.
- Personal data are also required for issuing invoices related to the accommodation.
- Personal data are important for communication regarding the booking, so that the Accommodation can notify the Guest of any significant circumstances that they need to be aware of.
- Data processing is also necessary to comply with legal obligations.
IV. Legal Basis of Data Processing
The Data Controller processes Guests’ personal data on the following legal bases:
- For the purpose described in III.1, in accordance with GDPR Article 6(1)(b) – processing is necessary for the performance of a contract to which the Guest, as the data subject, is a party.
- For the purpose described in III.2, in accordance with GDPR Article 6(1)(c) – processing is necessary to comply with a legal obligation applicable to the Data Controller, specifically the obligation to issue receipts and invoices.
- For the purpose described in III.3, in accordance with GDPR Article 6(1)(a) – processing is based on the Guest’s consent, in order to provide proper information regarding essential matters arising from the contractual relationship.
If any additional purpose or legal basis for data processing arises, the Data Controller is obliged to inform the data subject individually before the processing begins about all relevant information concerning the intended data processing and the rights related thereto.
V. Data Processing, Scope of Processed Data
In the provision of services, all data relating to the data subject is processed based on voluntary consent, with the purpose of ensuring the service and maintaining communication. The personal data listed in this section are retained by the Operator in accordance with current tax and accounting regulations and are deleted after the applicable retention period. For certain services, Guests may provide additional data to help the Operator fully understand their needs; however, this is not required for booking a room or using other services.
Website – Request for Quotation
Using the booking or quote request interface on the Operator’s website does not require separate registration, but the following personal data must be provided for booking or requesting a quote:
- Name (first and last name)
- Phone number
- Email address
External Service Providers
If a booking is made through an external service provider (e.g., Szallas.hu, Booking.com), the Guest accepts the Privacy Policy of the external provider and consents to the Operator processing the personal data received from the external provider for the purpose of the booking.
Room Booking
For online, in-person (paper-based), or telephone bookings, the Accommodation requests the following data from the Guest:
- Salutation (optional)
- Name (first and last name)
- Address (street, city, postal code, country)
- Phone number
- Email address
Guest Registration Form
When using accommodation services, the Guest completes a registration form, providing consent for the Accommodation to process the following mandatory data in accordance with applicable laws (including immigration and tourist tax regulations). By providing these data, the Guest consents to their use for fulfilling legal obligations and verifying the Guest’s identity:
- Name (first and last name)
- Birth name
- Address (street, city, postal code, country)
- Place and date of birth
- Mother’s name
- Gender (required by NTAK for statistical purposes, processed in a non-identifiable manner)
- Citizenship (required by NTAK for statistical purposes, processed in a non-identifiable manner)
By law, the following additional data are processed for guests who are not Hungarian citizens:
- Travel document (passport) identification data
- Accommodation address
- Start and end dates of accommodation
- Visa or residence permit number
- Date and place of entry
A third-country national is any person, other than a Hungarian citizen, who is not a citizen of an EEA member state. EEA member states include EU member states, Iceland, Liechtenstein, and Norway, as well as Switzerland as an equal-status state.
The provision of mandatory data by the Guest is a condition for using the accommodation services. By signing the registration form, the Guest consents to the Accommodation processing and archiving their personal data provided on the form for the purposes of establishing the contract, fulfilling the contract, proving performance, and asserting any potential claims, within the retention periods indicated above.
VI. Duration of Data Processing
The processing of the Guest’s phone number and email address begins from the date of booking and continues for 6 months after the Guest’s departure from the Accommodation.
The processing of the Guest’s name, personal data, and billing address is carried out for the period required by the Accounting Act, i.e., for 8 (eight) years, after which the Data Controller destroys the data.
VII. Website Visit Data
References and Links
The Accommodation’s website may contain links that are not operated by the Accommodation and are provided solely for the visitor’s information. The Accommodation has no control over the content or security of websites operated by partner companies and is therefore not responsible for them. Please review the privacy policy or data protection notice of any website you visit before providing any personal data on that site.
Analytics and Cookies
The Accommodation uses an analytics tool to monitor its website, which creates a dataset and tracks how visitors use the website. When a page is viewed, the system creates a cookie to record information about the visit (such as pages visited, time spent on pages, browsing data, exits, etc.), which cannot be linked to the identity of the visitor. This tool helps improve website ergonomics, create a user-friendly website, and enhance the online experience for visitors.
The Operator does not use analytics systems to collect personal information. Most web browsers automatically accept cookies, but visitors can delete them or refuse them automatically. Since browsers differ, each visitor can individually set their cookie preferences using their browser’s tools.
VIII. Guest Rights and Remedies
- The Guest has the right to request confirmation from the Data Controller as to whether their personal data are being processed, and if so, to receive information about the data being processed and all relevant information regarding the processing.
- The Guest may request that the Data Controller rectify inaccurate personal data without undue delay. Considering the purpose of data processing, the Guest may also request the completion of their personal data.
- The Guest may request the deletion of their personal data, except where processing is necessary for the Data Controller to fulfill legal obligations, submit, exercise, or defend legal claims. The Data Controller shall delete personal data without undue delay if the processing is unlawful, incomplete, or incorrect, the purpose of processing has ceased, the retention period has expired, or if deletion is ordered by a court or authority, or is required by law.
- If personal data are processed based on the Guest’s consent, the Guest may withdraw this consent at any time. If there is no other legal basis for processing, the Data Controller shall delete the personal data affected by the withdrawn consent.
- The Guest has the right to request that the Data Controller restrict data processing if:
a) The Guest disputes the accuracy of the personal data – for the time required to verify accuracy;
b) The processing is unlawful, but the Guest opposes deletion and requests restriction;
c) The Data Controller no longer needs the personal data for processing purposes, but the Guest requires them for submitting, exercising, or defending legal claims; or
d) The Guest objects to the processing of their data based on public interest or the legitimate interest of the Data Controller or a third party.
During the restriction period, the Data Controller may only store the personal data and may not use it for other purposes.
- Upon exercising their rights, the Data Controller shall examine the Guest’s request, take necessary measures, and inform the Guest within one month of the receipt of the request about the actions taken or the reasons for inaction.
- Enforcement of Rights:
The Guest may submit any request related to data processing to the Data Controller at the address or email provided in Section II. In the event of a violation of rights, the Guest may bring a claim before the court competent according to the Data Controller’s address, or at their place of residence, or if absent, their place of stay. The Guest may also submit a complaint to the National Authority for Data Protection and Freedom of Information (1055 Budapest, Falk Miksa utca 9-11, hereinafter:NAIH, http://naih.hu, phone: +36 (1) 391-1400, mail adress, 1363 Budapest, Pf.: 9, email: ugyfelszolgalat@naih.hu), and may request an investigation on the grounds that a violation or imminent risk regarding the processing of their personal data has occurred.
IX. Data Security
The Accommodation ensures the traceability and verifiability of personal data, including which authorities the data have been or may be transmitted to using data transfer devices, which personal data, by whom, and when were entered into the system, as well as the system’s recoverability in case of a malfunction. Reports are generated for errors occurring during automated processing. The Accommodation treats personal data confidentially and does not disclose them to unauthorized parties. Personal data are protected against unauthorized access, alteration, transmission, disclosure, deletion, destruction, damage, and inaccessibility caused by changes in technology. To ensure the technical protection of personal data, the Accommodation takes all necessary security measures. The Data Controller takes every step to guarantee the security of personal data provided by Guests, both during network transmission and while the data are stored and maintained. The system operating through the Data Controller’s website is hosted with an external secure storage provider, to which the provider does not have access. The Data Controller performs its workflows on computers protected with passwords and antivirus software.