0-24+36 30 383 5969
  • HU
  • EN
  • DE
0

Use and Data Protection

Introduction

Zala-Kraft Kereskedelmi Kft. (Address: 8749 Zalakaros, Sport u. 10., Hungary; e-mail: info@hotelaphrodite.hu, tax number: 11816799-2-20, company registration number: 20-09-064144) (hereinafter: the Service Provider, data controller) subjects itself to the following notice.

We provide the following information in accordance with REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

This privacy notice governs the data processing carried out on the https://hotelaphrodite.hu/ website and by Wellness Hotel Aphrodite. The privacy notice is available at the following page: https://hotelaphrodite.hu/adatvedelem/. Amendments to the notice take effect upon publication at the above address.

The data controller and its contact details

Definitions

1. “personal data”: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;

2. “processing”: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;

3. “controller”: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;

4. “processor”: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;

5. “recipient”: a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing;

6. “consent” of the data subject: any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;

7. “personal data breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

Principles relating to the processing of personal data

Personal data shall be:

  • a) processed lawfully, fairly and in a transparent manner in relation to the data subject (“lawfulness, fairness and transparency”);
  • b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical
    research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (“purpose limitation”);
  • c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (“data minimisation”);
  • d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed,
    are erased or rectified without delay (“accuracy”);
  • e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1), subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (“storage
    limitation”);
  • f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures
    (“integrity and confidentiality”).

The controller shall be responsible for, and be able to demonstrate compliance with the above (“accountability”).

Data processing activities

Room reservation, quotation requests

1. The fact of data collection, the scope of data processed, and the purpose of processing:

Personal data
Purpose of processing
Name (first and last name)
Required for the quotation request and room reservation.
E-mail address
Maintaining contact.
Phone number
More efficient coordination of questions related to the room reservation or quotation request.
Data related to the room reservation/quotation request (arrival date, departure date, number of adults, number of children, children’s ages, room type)
To enable the room reservation and quotation request.
Date/time of the room reservation/quotation request
Performance of a technical operation.
IP address at the time of the room reservation/quotation request
Performance of a technical operation.

2. Scope of data subjects: All data subjects who book a room or request a quotation on the website.

3. Duration of processing, deadline for erasure of data: The data are erased immediately after the User’s request for a quotation has been answered (in which case the controller is no longer entitled to send a newsletter either), provided that no room was booked. If the User booked a room in the Service Provider’s system, a contract was thereby created, so the erasure deadline for the personal data differs for accounting documents, since under Section 169(2) of Act C of 2000 on Accounting, such data must be retained for 8 years.
Accounting documents directly or indirectly supporting bookkeeping entries (including general ledger accounts as well as analytical or detailed records) must be retained in a legible form, traceable by reference to the accounting entries, for at least 8 years.

4. Persons who may be authorised to access the data as controllers, recipients of the personal data: The personal data may be processed by the sales and marketing staff of the controller, subject to the principles set out above.

5. Description of the data subjects’ rights in connection with the processing:

  • The data subject may request from the controller access to, rectification, erasure or restriction of processing of the personal data concerning them, and
  • may object to the processing of such personal data, as well as
  • the data subject has the right to data portability and to withdraw consent at any time.

6. The data subject may initiate access to, erasure, modification or restriction of processing of personal data, data portability, and objection to processing in the following ways:

  • by post, at 8749 Zalakaros, Sport út 10.
  • by e-mail, at info@hotelaphrodite.hu,
  • by phone, at +36 30 383 5969.

7. the data subject’s consent, Article 6(1)(a) and (b), Section 5(1) of the Information Act (Infotv.), Section 169(2) of Act C of 2000 on Accounting, and Section 13/A(3) of Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (hereinafter: the E-Commerce Act):
The service provider may process personal data that are technically indispensable for the provision of the service, for the purpose of providing the service. Under otherwise identical conditions, the service provider must select and, in every case, operate the tools used in the provision of the information society service in such a way that personal data are processed only when this is absolutely necessary for the provision of the service and for the fulfilment of other purposes set out in this Act, and even then only to the extent and for the duration necessary.

8. We inform you that

  • the processing is based on Your consent.
  • you are required to provide the personal data so that we can fulfil the room reservation or quotation request.
  • failure to provide the data has the consequence that we will not be able to process your room reservation or quotation request.

Data processors used

Hosting provider

1. Activity performed by the processor: Hosting services

2. Name and contact details of the processor:


3. The fact of processing, the scope of data processed: All personal data provided by the data subject.

4. Scope of data subjects: All data subjects using the website.

5. Purpose of processing: Making the website available and ensuring its proper operation.

6. Duration of processing, deadline for erasure of data: Processing lasts until the termination of the agreement between the controller and the hosting provider, or until the data subject submits an erasure request to the hosting provider.

7. Legal basis for the processing: Article 6(1)(c) and (f), and Section 13/A(3) of Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services.

The following processors are used to process inquiries

1. The fact of data collection, the scope of data processed, and the purpose/location of processing:

Processor
Purpose and location of processing
Mistral AI (France, Paris; company registration number 952 418 325)
Interpreting the inquiry and drafting the reply.
Location of processing: European Union. The provider retains the data for 30 days for abuse-monitoring purposes, after which it is deleted; it is not used to train its models.
Microsoft Ireland Operations Ltd.
The hotel’s e-mail mailbox (Microsoft 365 / Outlook)
Location of processing: European Union
Google Ireland Ltd.
Storage of inquiries and reply drafts (Firebase)
Location of processing: European Union
Vercel Inc. (United States)
Running the system
Location of processing: European Union (Frankfurt region); the provider’s registered seat is in the United States
Twilio Inc. / SendGrid (United States)
Sending e-mails, if the hotel chooses sending option 2
Location of processing: United States. It becomes a processor only if the hotel chooses this route; the key is currently not configured.
Babicz Mihály e.v. (8220 Balatonalmádi, Sátorhegyi út 46/A; registration number 17466981, tax number 91993229-1-39)
Development, operation and troubleshooting of the system
Location of processing: Hungary

We have entered into an agreement compliant with Article 28 of the GDPR with each processor, permitting the data to be used exclusively for the tasks described above.

Vercel Inc., which runs the system, and Twilio Inc., which provides backup e-mail delivery, are providers registered in the United States. The legal basis for the data transfer is the European Commission’s adequacy decision on the EU–US Data Privacy Framework, as well as the standard contractual clauses (SCCs) adopted by the European Commission. Otherwise, the processing and storage of inquiries takes place within the European Union.

2. Scope of data subjects: All data subjects who book a room or request a quotation on the website.

3. Duration of processing, deadline for erasure of data: see the table above, by processor.

4. Persons who may be authorised to access the data as controllers, recipients of the personal data: see the table above, by processor.

5. Description of the data subjects’ rights in connection with the processing:

  • The data subject may request from the controller access to, rectification, erasure or restriction of processing of the personal data concerning them, and
  • may object to the processing of such personal data, as well as
  • the data subject has the right to data portability and to withdraw consent at any time.

6. The data subject may initiate access to, erasure, modification or restriction of processing of personal data, data portability, and objection to processing in the following ways:

  • by post, at 8749 Zalakaros, Sport út 10.
  • by e-mail, at info@hotelaphrodite.hu,
  • by phone, at +36 30 383 5969.

7. the data subject’s consent, Article 6(1)(a) and (b), Section 5(1) of the Infotv., Section 169(2) of Act C of 2000 on Accounting, and Section 13/A(3) of Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (hereinafter: the E-Commerce Act):
The service provider may process personal data that are technically indispensable for the provision of the service, for the purpose of providing the service. Under otherwise identical conditions, the service provider must select and, in every case, operate the tools used in the provision of the information society service in such a way that personal data are processed only when this is absolutely necessary for the provision of the service and for the fulfilment of other purposes set out in this Act, and even then only to the extent and for the duration necessary.

8. We inform you that

  • the processing is based on Your consent.
  • you are required to provide the personal data so that we can fulfil the room reservation or quotation request.
  • failure to provide the data has the consequence that we will not be able to process your room reservation or quotation request.

Use of cookies

1. The fact of processing, the scope of data processed: Unique identifier, dates, timestamps

2. Scope of data subjects: All data subjects visiting the website.

3. Purpose of processing: Identifying users and tracking visitors.

4. Duration of processing, deadline for erasure of data:

Type of cookie
Session cookies
Persistent or stored cookies
Legal basis for processing
Section 13/A(3) of Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (E-Commerce Act)
Duration of processing
The period until the end of the relevant visitor session
until deletion by the data subject, maximum 30 days
Scope of data processed
connect.sid

5. Persons who may be authorised to access the data as controllers: The controller does not process personal data through the use of cookies.

6. Description of the data subjects’ rights in connection with the processing: Data subjects have the option to delete cookies in their browser’s Tools/Settings menu, generally under the Privacy settings.

7. Legal basis for the processing: The data subject’s consent is not required where the sole purpose of the cookies is to carry out the transmission of a communication over an electronic communications network, or where it is strictly necessary for the service provider to provide an information society service explicitly requested by the subscriber or user.

Use of Google Ads (Adwords) conversion tracking

1. The controller uses the online advertising program “Google Ads (Adwords)” and, within its framework, uses Google’s conversion tracking service. Google conversion tracking is an analytics service of Google Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”).

2. When the User reaches a website via a Google ad, a cookie required for conversion tracking is placed on their computer. These cookies have limited validity and do not contain any personal data, so the User cannot be identified through them.

3. When the User browses certain pages of the website and the cookie has not yet expired, both Google and the controller can see that the User clicked on the ad.

4. Each Google Ads (Adwords) customer receives a different cookie, so they cannot be tracked through the websites of Ads (Adwords) customers.

5. The information obtained using conversion tracking cookies serves the purpose of generating conversion statistics for customers who have opted for Ads (Adwords) conversion tracking. This allows customers to learn about the number of users who clicked on their ad and were directed to a page tagged with a conversion tracking tag. However, they do not gain access to information that could be used to identify any user.

6. If you do not wish to participate in conversion tracking, you can reject it by disabling cookies in your browser. In that case, you will no longer appear in the conversion tracking statistics.

7. Further information, as well as Google’s privacy policy, is available at the following page: www.google.de/policies/privacy/

Use of Google Analytics

1. This website uses Google Analytics, a web analytics service provided by Google Inc. (“Google”). Google Analytics uses so-called “cookies,” text files that are stored on your computer, which help analyse how the User uses the website they visit.

2. The information generated by the cookie about the User’s use of the website is usually transmitted to and stored on a Google server in the USA. By activating IP anonymisation on the website, Google will first shorten the User’s IP address within the Member States of the European Union or in other states party to the Agreement on the European Economic Area.

3. Only in exceptional cases is the full IP address transmitted to a Google server in the USA and shortened there. On behalf of the operator of this website, Google will use this information for the purpose of evaluating the User’s use of the website, compiling reports on website activity for the website operator, and providing other services relating to website and internet usage.

4. Within the framework of Google Analytics, the IP address transmitted by the User’s browser is not merged with other data held by Google. The User can prevent the storage of cookies through the appropriate settings of their browser; however, please note that in this case you may not be able to use all functions of this website to their full extent. You can also prevent Google from collecting and processing data related to your use of the website generated by cookies (including your IP address) by downloading and installing the browser plugin available at the following link: https://tools.google.com/dlpage/gaoptout?hl=hu

Customer contact

1. The fact of data collection, the scope of data processed, and the purpose of processing:

Personal data
Purpose of processing
Name, e-mail address, phone number.
Maintaining contact, identification, performance of contracts, business purposes.

2. Scope of data subjects: All data subjects who maintain contact with the controller by phone, e-mail or in person, or who are in a contractual relationship with the controller.

3. Duration of processing, deadline for erasure of data: Processing lasts until the termination of the legal relationship between the controller and the data subject, or, in the case of claims, for 5 years following the contract. Data relating to a quotation request (including the text of the inquiry) are retained in the processing system for a maximum of 90 days from receipt of the inquiry, after which they are automatically deleted. The retention period begins upon receipt of the inquiry, not from the date of booking or the date of arrival. In periods of high volume, the oldest items may be deleted sooner, which is why the text uses the word “maximum.” If a booking results from the inquiry, the retention periods relating to the performance of the contract and to accounting obligations apply to the data (8 years in the case of accounting documents).

4. Persons who may be authorised to access the data as controllers, recipients of the personal data: The personal data may be processed by the controller’s authorised staff, subject to the principles set out above.

5. Description of the data subjects’ rights in connection with the processing:

  • The data subject may request from the controller access to, rectification, erasure or restriction of processing of the personal data concerning them, and
  • the data subject has the right to data portability and to withdraw consent at any time.

6. The data subject may initiate access to, erasure, modification or restriction of processing of personal data, and data portability, in the following ways:

  • by post, at 8749 Zalakaros, Sport út 10.
  • by e-mail, at info@hotelaphrodite.hu,
  • by phone, at +36 30 383 5969.

7. Legal basis for the processing:

7.1. Article 6(1)(b) and (c) of the GDPR.

7.2. In the case of enforcement of claims arising from the contract, 5 years under Section 6:21 of Act V of 2013 on the Civil Code.

Section 6:22 [Limitation]
(1) Unless this Act provides otherwise, claims become time-barred after five years.
(2) The limitation period begins when the claim becomes due.
(3) An agreement to modify the limitation period must be made in writing.
(4) An agreement excluding limitation is void.

8. We inform you that

  • the processing is necessary for the performance of the contract and for providing a quotation.
  • you are required to provide the personal data so that we can fulfil your order/other request.
  • failure to provide the data has the consequence that we will not be able to process your order/request.

Contact form

1. The fact of data collection, the scope of data processed, and the purpose of processing:

Personal data
Purpose of processing
Name
Identification
E-mail address
Maintaining contact, sending reply messages
Phone number
Maintaining contact
Content of the message
Necessary for providing a reply
Date/time of contact
Performance of a technical operation.
IP address at the time of contact
Performance of a technical operation.

The e-mail address is not required to contain personal data.

2. Scope of data subjects: All data subjects who send a message via the contact form.

3. Duration of processing, deadline for erasure of data: Processing lasts until the data subject’s erasure request. Data relating to a quotation request (including the text of the inquiry) are retained in the processing system for a maximum of 90 days from receipt of the inquiry, after which they are automatically deleted. The retention period begins upon receipt of the inquiry, not from the date of booking or the date of arrival. In periods of high volume, the oldest items may be deleted sooner, which is why the text uses the word “maximum.” If a booking results from the inquiry, the retention periods relating to the performance of the contract and to accounting obligations apply to the data (8 years in the case of accounting documents).

4. Persons who may be authorised to access the data as controllers, recipients of the personal data: The personal data may be processed by the controller’s authorised staff.

5. Description of the data subjects’ rights in connection with the processing:

  • The data subject may request from the controller access to, rectification, erasure or restriction of processing of the personal data concerning them, and
  • the data subject has the right to data portability and to withdraw consent at any time.

6. The data subject may initiate access to, erasure, modification or restriction of processing of personal data, and data portability, in the following ways:

  • by post, at 8749 Zalakaros, Sport út 10.
  • by e-mail, at info@hotelaphrodite.hu,
  • by phone, at +36 30 383 5969.

7. Legal basis for the processing: the data subject’s consent, Article 6(1)(a) and (b).

8. We inform you that

  • this processing is based on Your consent and is necessary for making contact or providing a quotation.
  • you are required to provide the personal data so that you can contact us.
  • failure to provide the data has the consequence that you will not be able to contact the Service Provider.

Processing of quotation requests using an AI-supported system

The Hotel processes quotation requests submitted through the website and accommodation booking inquiries received by e-mail
using an AI-supported system. The system extracts the data needed for the booking (dates, number of guests,
room type, requested services) from the text of the inquiry; the price of the quotation is
calculated by program code based on predefined, verified rules, while the text of the reply letter
is drafted by a language model.

1. The fact of data collection, the scope of data processed, and the purpose of processing:

Personal data
Purpose of processing
Name (first and last name)
Required for the quotation request and room reservation.
E-mail address
Maintaining contact.
Phone number
Answering the quotation request, providing the quotation, and preparing the accommodation booking.
Data related to the room reservation/quotation request (arrival date, departure date, number of adults, number of children, children’s ages, room type)
To enable the room reservation and quotation request. We process children’s ages because the price of the quotation varies by age bracket. Data relating to minors are provided in every
case by the adult initiating the booking.
Full text of the inquiry and the reply correspondence
Necessary for providing a reply. Please only include in your inquiry the data necessary for the booking. Please do not include health-related or other
special category data (for example, information concerning an illness, medical treatment, or the medical reason for a dietary restriction) in the message. If such circumstances
are relevant to your care, we will discuss them separately with you after the booking has been confirmed.
Date/time of the room reservation/quotation request
Performance of a technical operation.
IP address at the time of the room reservation/quotation request
Performance of a technical operation.

The e-mail address is not required to contain personal data.

2. Scope of data subjects: All data subjects who book a room or request a quotation on the website.

3. Duration of processing, deadline for erasure of data: The data are erased immediately after the User’s request for a quotation has been answered (in which case the controller is no longer entitled to send a newsletter either), provided that no room was booked. If the User booked a room in the Service Provider’s system, a contract was thereby created, so the erasure deadline for the personal data differs for accounting documents, since under Section 169(2) of Act C of 2000 on Accounting, such data must be retained for 8 years.
Accounting documents directly or indirectly supporting bookkeeping entries (including general ledger accounts as well as analytical or detailed records) must be retained in a legible form, traceable by reference to the accounting entries, for at least 8 years.

4. Persons who may be authorised to access the data as controllers, recipients of the personal data: The personal data may be processed by the sales and marketing staff of the controller, subject to the principles set out above.

5. Description of the data subjects’ rights in connection with the processing:

  • The data subject may request from the controller access to, rectification, erasure or restriction of processing of the personal data concerning them, and
  • may object to the processing of such personal data, as well as
  • the data subject has the right to data portability and to withdraw consent at any time.

6. The data subject may initiate access to, erasure, modification or restriction of processing of personal data, data portability, and objection to processing in the following ways:

  • by post, at 8749 Zalakaros, Sport út 10.
  • by e-mail, at info@hotelaphrodite.hu,
  • by phone, at +36 30 383 5969.

7. Legal basis for the processing: Article 6(1)(b) of the GDPR, i.e. steps taken at the request of
the data subject prior to entering into a contract. Providing the data is not mandatory, but without it
we are unable to provide a quotation in response to the inquiry.

8. We inform you that

  • the processing is based on Your consent.
  • you are required to provide the personal data so that we can fulfil the room reservation or quotation request.
  • failure to provide the data has the consequence that we will not be able to process your room reservation or quotation request.

Guestbook

1. The fact of data collection, the scope of data processed, and the purpose of processing:

Personal data
Purpose of processing
Name
Identification
E-mail address
Maintaining contact, identification.
Date/time, IP address
Performance of a technical operation.

The e-mail address is not required to contain personal data.

2. Scope of data subjects: All data subjects who write in the guestbook.

3. Duration of processing, deadline for erasure of data: Processing lasts until the data subject’s erasure request.

4. Persons who may be authorised to access the data as controllers, recipients of the personal data: The personal data may be processed by the controller’s authorised staff.

5. Description of the data subjects’ rights in connection with the processing:

  • The data subject may request from the controller access to, rectification, erasure or restriction of processing of the personal data concerning them, and
  • the data subject has the right to data portability and to withdraw consent at any time.

 

6. The data subject may initiate access to, erasure, modification or restriction of processing of personal data, and data portability, in the following ways:

  • by post, at 8749 Zalakaros, Sport út 10.
  • by e-mail, at info@hotelaphrodite.hu,
  • by phone, at +36 30 383 5969.

7. Legal basis for the processing: the data subject’s consent, Article 6(1)(a) and (b).

8. We inform you that

  • this processing is based on Your consent, and
  • you are required to provide the personal data in order to write in the guestbook.
  • failure to provide the data has the consequence that you will not be able to write in the guestbook.

Newsletter, direct marketing activity

1. Pursuant to Section 6 of Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions of Commercial Advertising Activity, the User may give prior and express consent to being contacted by the Service Provider with advertising offers and other communications at the contact details provided at registration.

2. Furthermore, having regard to the provisions of this notice, the Customer may consent to the Service Provider processing their personal data necessary for sending advertising offers.

3. The Service Provider does not send unsolicited advertising messages, and the User may unsubscribe from receiving offers free of charge, without restriction or justification, at any time. In this case, the Service Provider will delete all personal data necessary for sending advertising messages from its records and will no longer contact the User with further advertising offers. The User may unsubscribe from advertisements by clicking the link contained in the message.

4. The fact of data collection, the scope of data processed, and the purpose of processing:

Personal data
Purpose of processing
Name, e-mail address.
Identification, enabling subscription to the newsletter.
Date/time of subscription
Performance of a technical operation.
IP address at the time of subscription
Performance of a technical operation.

5. Scope of data subjects: All data subjects who subscribe to the newsletter.

6. Purpose of processing: sending electronic messages containing advertising (e-mail, SMS, push notification) to the data subject, providing information about current news, products, promotions, new features, etc.

7. Duration of processing, deadline for erasure of data: processing lasts until the consent statement is withdrawn, i.e. until unsubscription.

8. Persons who may be authorised to access the data as controllers, recipients of the personal data: The personal data may be processed by the sales and marketing staff of the controller, subject to the principles set out above.

9. Description of the data subjects’ rights in connection with the processing:

  • The data subject may request from the controller access to, rectification, erasure or restriction of processing of the personal data concerning them, as well as
  • may object to the processing of their personal data, and
  • the data subject has the right to data portability and to withdraw consent at any time.

10. The data subject may initiate access to, erasure, modification or restriction of processing of personal data, data portability, and objection, in the following ways:

  • by post, at 8749 Zalakaros, Sport út 10.
  • by e-mail, at info@hotelaphrodite.hu,
  • by phone, at +36 30 383 5969.

11. The data subject may unsubscribe from the newsletter free of charge at any time.

12. Data processor used in the processing:

  • MailChimp
  • The Rocket Science Group, LLC
  • 675 Ponce de Leon Ave NE
  • Suite 5000
  • Atlanta, GA 30308 USA

13. Legal basis for the processing: the data subject’s consent, Article 6(1)(a) and (f), and Section 6(5) of Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions of Commercial Advertising Activity:

The advertiser, the advertising service provider, and the publisher of the advertisement shall keep a record of the personal data of persons who have given consent to them, to the extent specified in the consent. The data recorded in this register relating to the addressee of the advertisement may be processed only in accordance with the consent statement, until it is withdrawn, and may only be transferred to a third party with the prior consent of the data subject.

14. We inform you that

  • the processing is based on Your consent.
  • you are required to provide the personal data if you wish to receive a newsletter from us.
  • failure to provide the data has the consequence that we will not be able to send you a newsletter.

Complaint handling

1. The fact of data collection, the scope of data processed, and the purpose of processing:

Personal data
Purpose of processing
First and last name
Identification, maintaining contact.
E-mail address
Maintaining contact.
Phone number
Maintaining contact.
Billing name and address
Identification, handling of quality complaints, questions and issues arising in connection with the services.

2. Scope of data subjects: All data subjects who raise a quality complaint or file a complaint in connection with the hotel’s services.

3. Duration of processing, deadline for erasure of data: Copies of the record, transcript and reply drawn up regarding the complaint received must be retained for 5 years pursuant to Section 17/A(7) of Act CLV of 1997 on Consumer Protection.

4. Persons who may be authorised to access the data as controllers, recipients of the personal data: The personal data may be processed by the sales and marketing staff of the controller, subject to the principles set out above.

5. Description of the data subjects’ rights in connection with the processing:

  • The data subject may request from the controller access to, rectification, erasure or restriction of processing of the personal data concerning them, and
  • may object to the processing of such personal data, as well as
  • the data subject has the right to data portability and to withdraw consent at any time.

6. The data subject may initiate access to, erasure, modification or restriction of processing of personal data, data portability, and objection to processing in the following ways:

  • by post, at 8749 Zalakaros, Sport út 10.
  • by e-mail, at info@hotelaphrodite.hu,
  • by phone, at +36 30 383 5969.

7. Legal basis for the processing: Article 6(1)(c), and Section 17/A(7) of Act CLV of 1997 on Consumer Protection.

8. We inform you that

  • the provision of the personal data is based on a contractual obligation.
  • the processing of the personal data is a precondition for concluding the contract.
  • you are required to provide the personal data so that we can handle your complaint.
  • failure to provide the data has the consequence that we will not be able to handle the complaint received from you.

Internal data protection (registration form)

1. Legal basis for the processing: Article 6(1)(c) of the GDPR.

2. Purpose of processing: compliance with the statutory requirements relating to the tourism tax.

3. Duration of processing, deadline for erasure of data: until such time as the competent authority may audit compliance with the obligations set out in the relevant legislation; furthermore, in the case of a contract, the deadline — in accordance with Section 169(2) of Act C of 2000 on Accounting — is 31 December of the 7th year following the given year.

4. Scope of data processed: name, e-mail, address, ID document number, nationality, date of birth, licence plate number, other personal data.

5. Persons who may be authorised to access the data as controllers: The personal data may be processed by the controller’s staff, subject to the principles set out above.

6. Description of the data subjects’ rights in connection with the processing:

  • The data subject may request from the controller access to, rectification, erasure or restriction of processing of the personal data concerning them, and
  • the data subject has the right to data portability and to withdraw consent at any time.

7. The data subject may initiate access to, erasure, modification or restriction of processing of personal data, and data portability, in the following ways:

  • by post, at 8749 Zalakaros, Sport út 10.
  • by e-mail, at info@hotelaphrodite.hu,
  • by phone, at +36 30 383 5969.

Social media pages

1. The fact of data collection, the scope of data processed: the User’s registered name on Facebook/Google+/Twitter/Pinterest/YouTube/Instagram etc., as well as the User’s public profile picture.

2. Scope of data subjects: All data subjects who are registered on Facebook/Google+/Twitter/Pinterest/YouTube/Instagram etc. and have “liked” the website.

3. Purpose of data collection: sharing or “liking” and promoting certain content elements, products, promotions of the website, or the website itself, on social media platforms.

4. Duration of processing, deadline for erasure of data, persons who may be authorised to access the data as controllers, and description of the data subjects’ rights in connection with the processing: The data subject may obtain information about the source of the data, its processing, and the manner and legal basis of its transfer on the relevant social media platform. The processing takes place on the social media platforms, so the duration, manner of processing, and the possibilities for erasure and modification of the data are governed by the rules of the given social media platform.

5. Legal basis for the processing: the data subject’s voluntary consent to the processing of their personal data on the social media platforms.

Customer relations and other data processing

1. If a question arises or the data subject has a problem in connection with the use of our services, they may contact the controller via the means provided on the website (phone, e-mail, social media, etc.).

2. The controller deletes incoming e-mails, messages, and details provided by phone, Facebook, etc., together with the inquirer’s name and e-mail address and any other personal data voluntarily provided, no later than 2 years after the data were submitted.

3. We provide information about any data processing not listed in this notice at the time the data are collected.

4. In the case of an exceptional request from an authority, or a request from other bodies authorised by law, the Service Provider is obliged to provide information, disclose data, and make documents available.

5. In such cases, the Service Provider discloses personal data to the requesting party — provided the exact purpose and scope of the data have been specified — only to the extent and in the amount that is absolutely necessary to fulfil the purpose of the request.

Automated decision-making

The price of the quotation is calculated by program code, and the text of the reply letter is drafted by artificial intelligence; however, the letter is in every case reviewed and sent by our staff member. Accordingly, no decision based solely on automated processing is made in your matter.

Information on the use of artificial intelligence

The text of the reply letters sent in response to inquiries is drafted by artificial intelligence. We inform you of this separately in every letter sent. The prices and conditions contained in the letter are not AI estimates: they are calculated by program code based on the hotel’s official price list.

Rights of data subjects

You may at any time request a copy of the data processed in connection with your inquiry, as well as its rectification or erasure, and you may also object to the processing. You may indicate your request by sending it to info@hotelaphrodite.hu; we will carry out the erasure within 30 days at the latest and will send you a confirmation. The erasure covers both the processing system and the hotel’s e-mail mailbox. You may lodge a complaint with the National Authority for Data Protection and Freedom of Information (1055 Budapest, Falk Miksa utca 9-11., ugyfelszolgalat@naih.hu), or turn to a court.

1. Right of access: You have the right to obtain confirmation from the controller as to whether personal data concerning you are being processed, and, where that is the case, to access the personal data and the information listed in the Regulation.

2. Right to rectification: You have the right to obtain from the controller, without undue delay, the rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

3. Right to erasure: You have the right to obtain from the controller the erasure of personal data concerning you without undue delay, and the controller shall have the obligation to erase personal data concerning you without undue delay where certain conditions apply.

4. Right to be forgotten: Where the controller has made the personal data public and is obliged to erase it, the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers processing the personal data that you have requested the erasure by such controllers of any links to, or copies or replications of, that personal data.

5. Right to restriction of processing: You have the right to obtain from the controller restriction of processing where one of the following applies:

  • you contest the accuracy of the personal data, for a period enabling the controller to verify the accuracy of the personal data;
  • the processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead;
  • the controller no longer needs the personal data for the purposes of the processing, but you require them for the establishment, exercise or defence of legal claims;
  • you have objected to processing; in that case, the restriction applies for the period pending the verification whether the legitimate grounds of the controller override those of you as the data subject.

6. Right to data portability: You have the right to receive the personal data concerning you, which you have provided to a controller, in a structured, commonly used and machine-readable format, and to transmit those data to another controller without hindrance from the controller to which the personal data have been provided.

7. Right to object: You have the right to object, at any time, on grounds relating to your particular situation, to the processing of personal data concerning you, including profiling based on the relevant provisions.

8. Objection in the case of direct marketing: Where personal data are processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing, including profiling to the extent that it is related to such direct marketing. Where you object to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.

9. Automated individual decision-making, including profiling: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

The preceding paragraph shall not apply if the decision:

  • is necessary for entering into, or performance of, a contract between you and the controller;
  • is authorised by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard your rights and freedoms and legitimate interests; or
  • is based on your explicit consent.

Deadline for taking action

The controller shall provide information to you on action taken on the above requests without undue delay, and in any event within one month of receipt of the request.

That period may, where necessary, be extended by two further months. The controller shall inform you of any such extension, together with the reasons for the delay, within one month of receipt of the request.
Where the controller does not take action on your request, it shall inform you without delay, and at the latest within one month of receipt of the request, of the reasons for not taking action, and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.

Security of processing

Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including, among others, as appropriate:

  • a) the pseudonymisation and encryption of personal data;
  • b) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
  • c) the ability to restore the availability of, and access to, personal data in a timely manner in the event of a physical or technical incident;
  • d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing.

The controller’s specific data security measures:

The hotel uses the front-office software of Com-Passz Kft. (8640 Fonyód, Szent István u. 4.; Phone: +36 21 22 33 444; E-mail: budapest@com-passz.hu) to manage guest traffic, statistical services, and invoicing-related tasks.

The following measures ensure the protection of personal data:

  • 1. Only the hotel’s managing director and the front office manager have access authorisation to the front office system’s database.
  • 2. Only verified and authentic data, whose integrity can be certified, may be entered into the system.
  • 3. Protection against unauthorised access to, and unauthorised entry of, data is ensured.
  • 4. It can be verified and established who entered the personal data into the system, when, and whether its content has since been modified.
  • 5. Recovery of the installed IT systems in the event of a malfunction, and safeguarding of the databases.

Informing the data subject about a personal data breach

Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall, without undue delay, inform the data subject of the personal data breach.

The information provided to the data subject shall describe, in clear and plain language, the nature of the personal data breach, and shall include the name and contact details of the data protection officer or other contact point where more information can be obtained; it shall describe the likely consequences of the personal data breach; and it shall describe the measures taken or proposed to be taken by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.

Communication to the data subject shall not be required if any of the following conditions are met:

  • the controller has implemented appropriate technical and organisational protection measures, and those measures were applied to the personal data affected by the personal data breach, in particular those that render the personal data unintelligible to any person who is not authorised to access it, such as encryption;
  • the controller has taken subsequent measures which ensure that the high risk to the rights and freedoms of data subjects referred to above is no longer likely to materialise;
  • it would involve disproportionate effort. In such cases, there shall instead be a public communication or similar measure whereby the data subjects are informed in an equally effective manner.

If the controller has not already communicated the personal data breach to the data subject, the supervisory authority, having considered the likelihood of the personal data breach resulting in a high risk, may require it to do so.

Notification of a personal data breach to the authority

The controller shall, without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the competent supervisory authority pursuant to Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification is not made within 72 hours, it shall be accompanied by reasons for the delay.

Right to lodge a complaint

Complaints against a potential infringement by the controller may be lodged with the National Authority for Data Protection and Freedom of Information:

  • National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság)
  • 1055 Budapest, Falk Miksa utca 9-11., Hungary
  • Postal address: 1530 Budapest, Pf.: 5.
  • Phone: +36-1-391-1400
  • Fax: +36-1-391-1410
  • E-mail: ugyfelszolgalat@naih.hu
  • Web: https://naih.hu

Closing remarks

In preparing this notice, we have taken into account the following legislation:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
  • Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (hereinafter: the Infotv.)
  • Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (in particular Section 13/A)
  • Act XLVII of 2008 on the Prohibition of Unfair Business-to-Consumer Commercial Practices;
  • Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions of Commercial Advertising Activity (in particular Section 6)
  • Act XC of 2005 on the Freedom of Electronic Information
  • Act C of 2003 on Electronic Communications (specifically Section 155)
  • Opinion 16/2011 on the EASA/IAB Best Practice Recommendation on Online Behavioural Advertising
  • The recommendation of the National Authority for Data Protection and Freedom of Information on the data protection requirements of prior information
  • Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC

Downloadable documents

Zalakaros, 25 May 2018