top of page
  • Google-512_edited
  • Booking-com-Logo-EPS-vector-image-300x14
  • facebook-social-media-fb-logo-square-446
  • Instagram

1.Purpose of the Document

This document is the privacy notice for the guests and enquirers of the Bed & Badacsony private accommodation service. Its purpose is to explain clearly how we handle personal data in connection with bookings, the accommodation service, the guest data recording required by law, invoicing and communication.

2.Introduction

Dear Guests,

We would like to inform you that we process personal data when you make a booking, while we provide the accommodation service, when we record guest data as required by law (in particular for VIZA), and for invoicing and communication. Only statistical data that contains no personal data is sent to NTAK from the accommodation management software. This notice explains the purpose and legal basis of our data processing, the data concerned, the recipients, how long we keep the data, our data security principles and your rights as a data subject. Our data processing follows Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and the applicable Hungarian legislation.

Making a booking or using the service does not count as general consent to all of the data processing described in this notice. The Guest reads and acknowledges this notice. The data controller asks for consent only for separate, voluntary purposes where consent is the appropriate legal basis (see sections 3.13 and 6).

3.​Key Terms

  1. ​personal data: any information relating to an identified or identifiable natural person (the data subject) that can be linked to that person - in particular the data subject's name and identification number, and any detail characteristic of their physical, physiological, mental, economic, cultural or social identity -, as well as any conclusion about the data subject that can be drawn from the data.

  2. data set: all data handled within one register;

  3. data subject: a natural person who is identified, or who can be identified directly or indirectly, on the basis of any information;

  4. data processing by a processor: carrying out the technical tasks related to data processing operations, regardless of the method and means used and of where they are carried out, provided that the technical task is performed on the data;

  5. third party: a natural or legal person, or an organization without legal personality, that is not the data subject, the data controller or the data processor;

  6. data protection: the set of technologies and organizational methods that keep the collected data assets intact and ensure their integrity, usability and confidentiality;

  7. personal data breach: a breach of data security that leads to the accidental or unlawful destruction, loss, alteration or unauthorized disclosure of, or unauthorized access to, personal data transmitted, stored or otherwise processed;

  8. data processing: any operation or set of operations performed on data, regardless of the procedure used, in particular collecting, capturing, recording, organizing, structuring, storing, transforming or altering, using, querying, disclosing, transmitting, distributing or otherwise making public or accessible, aligning or combining, restricting, erasing and destroying data, as well as preventing any further use of the data, taking photographs or making audio or video recordings, and recording physical characteristics suitable for identifying a person (e.g. fingerprint or palm print, DNA sample, iris image).

  9. data controller: the natural or legal person, or organization without legal personality, that alone or jointly with others determines the purpose of the data processing, and takes and implements the decisions on the data processing (including the means used), or has them implemented by the data processor.

  10. data transfer: making data accessible to a specified third party.

  11. erasure of data: making data unrecognizable in a way that it can no longer be restored.

  12. restriction of data processing: marking stored personal data in order to limit its processing in the future;

  13. consent: the data subject's voluntary, specific, informed and unambiguous statement of intention by which they agree to their personal data being processed for a specified purpose. Consent may be withdrawn at any time, withdrawal does not affect the lawfulness of the processing carried out beforehand. Finalizing a booking by email or through an accommodation booking system (Booking.com, Szallas.hu), as well as accepting the GTC, counts as consent.

  14. mandatory data processing: where the data processing is ordered for a purpose in the public interest by an act of law, or - based on an authorization given in an act of law and within the scope defined in it - by a decree of a local authority.

  15. disclosure: making data accessible to anyone.

  16. profiling: any form of automated processing of personal data in which personal data is used to evaluate certain personal characteristics of a natural person, in particular to analyze or predict characteristics relating to that person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements.

4.Contact Details of the Data Controller

  1. 2030 Érd, Kőműves u. 16..

  2. bedandbadacsony@outlook.com

5.​Purposes of Data Processing

The data controller processes the personal data of Guests and enquirers for the following separate purposes:

  1. Recording guest data and transmitting it to VIZA as required by law and completing the statutory administration of the accommodation service.

  2. Invoicing, issuing accounting documents and meeting accounting obligations.

  3. Completing the administration related to paying the tourist tax to the local authority.

  4. Handling enquiries, creating and fulfilling bookings, and communicating with and informing the Guest as needed for the stay.

6. Legal Basis for Data Processing

Depending on the purpose, the data controller processes personal data on the following main legal bases:

  1. For the guest data recording and VIZA data transfer required by law: compliance with a legal obligation under Article 6(1)(c) GDPR.

  2. For invoicing and accounting data processing: compliance with a legal obligation under Article 6(1)(c) GDPR.

  3. Recording guest data as required by law and transmitting it to the local authority, on the grounds of the tourist tax payment obligation and the related data reporting.

  4. For data processing related to enquiries, bookings and the communication needed to provide the stay: Article 6(1)(b) GDPR - performance of a contract or taking steps at the data subject's request before entering into the contract, and communication during and after the contract.

​If it becomes necessary to process data for any other purpose or on any other legal basis, the data controller must inform the data subject individually, before the data processing begins, about all important information relating to the intended processing and about their related rights.

7.Personal Data We Process

The data we process depends on the purpose of the processing. The data controller only processes the data needed for the given purpose; the data used for VIZA, the tourist tax, booking communication and invoicing must be kept separate.

  1. Name

  2. Gender

  3. Date of birth

  4. Place of birth

  5. Nationality

  6. Type and number of the identity document 

  7. Home address: postcode, country, city, full address

  8. Phone number (for communication)

  9. E-mail address (for communication and for sending electronic documents)

  10. Billing address

8.How Long We Keep Your Data

Data used for enquiries and communication is processed until the given matter is closed, or for as long as it is needed to handle any legal claims. Data that is no longer needed must be archived, erased or anonymized; in this case the deletion rules based on access rights are provided by the Microsoft cloud service.

Invoices and accounting documents are kept for the period required by accounting legislation. This does not mean that all guest identification data is automatically kept for eight years. Guest data related to VIZA is processed by the accommodation provider until the deadline set by law. The VIZA system keeps the submitted data for a maximum of two years. A separate retention rule must be applied to each group of data. Personal data is kept for a maximum of 8 years for the data listed in section 7, after which it is archived.

9.VIZA AND NTAK DATA PROCESSING

For the VIZA system, the accommodation provider records the data required by law for every guest staying at the property. Guests who have reached the age of 14 must present an identity document suitable for identification. For guests under the age of 14, the required data may also be recorded based on a statement by their legal representative.

NTAK receives anonymous statistical data from the accommodation management software that contains no personal data. NTAK does not record or store personal data.

10.DATA PROCESSORS AND RECIPIENTS

To provide the service, the data controller may use accommodation management and VIZA connection solution, as well as invoicing, e-mail and hosting providers and, where applicable, a booking intermediary. The specific providers, the purpose of each data transfer and the safeguards for any data transfer outside the EEA are handled in line with the current, up-to-date provider register. Providers:

  1. VENDÉGEM application and NTAK system

  2. Számlázz.hu

  3. Booking.com

  4. Szállás.hu

  5. Microsoft M365

  6. WIX

11.Data Security

The data controller protects personal data against unauthorized access, alteration, disclosure, loss or destruction with technical and organizational measures proportionate to the risk of the data processing.

The data controller accesses the data that Guests enter in the contact form on the website through a protected service.

The data controller processes the data in IT and hosting services where access is limited by access rights.  The data controller carries out its work on a computer protected by password and antivirus software.

12.Guest Rights and Ways to Enforce Them

  1. The Guest has the right to receive confirmation from the data controller as to whether their personal data is being processed and, if it is, to be informed about the data processed and about all relevant information concerning the processing.

  2. The Guest may request that the data controller correct any inaccurate personal data concerning them without undue delay. Taking into account the purpose of the processing, they may also request that their personal data be completed.

  3. You may request the erasure of your personal data, except where the processing is necessary for the data controller to meet its legal obligations or to bring, enforce or defend legal claims. The data controller erases personal data without undue delay if the processing of the data is unlawful, incomplete or incorrect, if the purpose of the processing has ceased, if the storage period has expired, if a court or an authority has ordered it, or if erasure is necessary for the data controller to meet an obligation set out in law.

  4. If the data controller processes personal data based on the data subject's consent, the data subject may withdraw that consent. If there is no other legal basis for the processing, the data controller erases the personal data covered by the withdrawn consent.

  5. The Guest has the right to request that the data controller restrict the processing if the Guest disputes the accuracy of the personal data - for the period needed to check the accuracy; or if the processing is unlawful but the Guest objects to the erasure of the data and requests that its use be restricted instead; or if the data controller no longer needs the personal data for the purpose of the processing, but the data subject needs it in order to bring, enforce or defend a legal claim; or if the data subject objects to their data being processed in the public interest or on the basis of the legitimate interest of the data controller or of a third party. While the restriction is in place, the data controller may not use the personal data for any purpose other than storage.

  6. Where the applicable conditions are met, the Guest has the right to exercise the right to data portability and may also object to their personal data being processed based on legitimate interest.

  7. If the Guest exercises their rights, the data controller reviews the request and, within the deadline set out in the GDPR, informs them about the measures taken or about the reason why no measure was taken. Generally, the response deadline is one month from the date the request is received.

Enforcing rights: the Guest may send any request relating to data processing to the data controller at the contact details given in section 4, by e-mail or by post. If their rights are infringed, they may turn to a court and may also lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH). The address of NAIH is: 1055 Budapest, Falk Miksa utca 9-11., Hungary; website: www.naih.hu.

bottom of page