NFORMATION FOR GUESTS AND WEBSITE USERS REGARDING THE PROCESSING OF THEIR PERSONAL DATA
(Effective from May 1, 2024)
Club 218 Kft, the operator of Colors Holiday Hotel (hereinafter: Accommodation), as Data Controller, provides the following information to its customers, guests, and website visitors regarding the processing of their personal data, based on Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: GDPR).
Data of the Data Controller and the Internal Data Protection Officer:
Club 218 Kft.
Registered office: 8600 Siófok, Öreghegyi u. 7.
Company registration number: 14-09-313438 Tax number: 14001372-2-14 Represented by: Győző Mészáros, Managing Director
Contact details: Email:
Website: https://colorsholidayhotel.hu/
Phone: +36-720-68-10 Mailing address: 8600 Siófok, Öreghegyi u. 7.
Internal Data Protection Officer: Győző Mészáros, Managing Director (hereinafter: "Data Controller")
The operator of Colors Holiday Hotel (hereinafter: Accommodation) respects the personal rights of its Guests and therefore acts in accordance with the following data processing information during its data processing activities. The Data Controller reserves the right to modify this information due to alignment with changes in the legal background and other internal regulations. The current version of the data protection information is always available on the website www.balatoncolorsbeachhotel.hu, as well as in hard copy at the Accommodation's reception.
This information regulates the data processing activities related to the services provided by the Accommodation named Colors Holiday Hotel, located at 15 Tihany Street, 8600 Siófok, and available through the website.
- PURPOSE OF DATA PROCESSING
The primary purpose of this information is to define and adhere to the fundamental principles and provisions regarding the processing of data of natural persons and guests who come into contact with the Hotel, in order to protect the privacy of natural persons in accordance with the relevant legal requirements, and to inform guests about the scope of personal data processed by the data controller, the purpose and method of data processing, and all other facts related to data processing, including but not limited to their rights related to data processing and the available legal remedies.
1.2. Referring to the provisions of point 1.1, the purpose of this information is to ensure that the Accommodation complies with all provisions of the applicable laws related to data protection, including but not limited to:
- Regulation (EU) 2016/679 of the European Parliament and of the Council on the general data protection (hereinafter: GDPR),
- Act CXII of 2011 on the right to informational self-determination and freedom of information,
- Act CVIII of 2001 on certain issues of electronic commerce services and information society services,
- Act XLVII of 2008 on the prohibition of unfair commercial practices against consumers,
- Act XLVIII of 2008 on the basic conditions and certain limitations of economic advertising activities.
1.3. The Data Controller therefore considers it of paramount importance and is committed to protecting the personal data provided by the data subject on the website or through other forums or in any other way and processed by it, and to respecting the data subjects' right to informational self-determination. In this regard, it fully complies with the relevant current legal provisions, thereby contributing to the creation of secure internet Browse opportunities for data subjects.
- DEFINITIONS
- Data Subject, or User, or Guest: any natural person identified or identifiable – directly or indirectly – on the basis of personal data;
- Personal Data: any data relating to the data subject – in particular the name, identification mark, and one or more physical, physiological, mental, economic, cultural or social characteristics of the data subject – and any inference that can be drawn from the data concerning the data subject;
- Accommodation: The Colors Holiday Hotel Accommodation located at 15 Tihany Street, 8600 Siófok, operated by the Data Controller;
- Consent: any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
- Data Controller: the natural or legal person, or unincorporated organisation, who or which, alone or jointly with others, determines the purposes and means of the processing of data (including the tools used), makes and executes decisions concerning the data processing, or has them executed by a processor contracted by him/her; for the purposes of this information and the Accommodation, the data controller is: Club 218 Kft;
- Data Processing: any operation or set of operations which is performed on data, irrespective of the procedure applied, such as collection, recording, organisation, storage, alteration, use, retrieval, disclosure, transmission, alignment or combination, blocking, erasure and destruction, and the prevention of further use of the data, the making of photographic, sound or video recordings, and the recording of physical characteristics suitable for identifying a person;
- Data Transfer: making data available to a specified third party;
- Data Processing (by processor): the performance of technical tasks related to data processing operations, irrespective of the method and tools used for the execution of the operations, and the place of application, provided that the technical task is performed on the data;
- Data Erasure: rendering data unrecognisable in such a way that their restoration is no longer possible;
- Data Blocking: marking data with an identification mark for the purpose of restricting their further processing permanently or for a specified period;
- Data Destruction: the complete physical destruction of the data carrier containing the data;
- Data File: the totality of data managed in a single register;
- Third Party: a natural or legal person, or an unincorporated organisation, who or which is not the same as the data subject, the data controller or the data processor;
- Data Protection Incident: unlawful processing or handling of personal data, including unauthorised access, alteration, transmission, disclosure, deletion or destruction, as well as accidental destruction and damage;
- Website: the www.balatoncolorsbeachhotel.hu portal and all its sub-pages, operated by the Data Controller;
- Facebook page: the page located at https://www.facebook.com/colorsholidayhotel/.
- PRINCIPLES OF DATA PROCESSING
3.1. Principle of Proportionality and Necessity: Only personal data that is essential for achieving the purpose of data processing and suitable for achieving that purpose may be processed. Personal data may only be processed to the extent and for the duration necessary for achieving the purpose.
3.2. Principle of Purpose Limitation: Personal data may only be processed for a specified purpose, for the exercise of a right and the fulfillment of an obligation. Data processing must comply with the purpose of data processing at all stages, and data collection and processing must be fair and lawful.
3.3. Personal data retains its quality throughout data processing as long as its connection with the data subject can be restored. The connection with the data subject can be restored if the data controller possesses the technical conditions necessary for restoration.
3.4. During data processing, the accuracy, completeness, and – if necessary for the purpose of data processing – up-to-dateness of the data must be ensured, as well as that the data subject can only be identified for the time necessary for the purpose of data processing.
3.5. Principle of Voluntariness: The provision of data by the data subject is voluntary. The Data Controller processes personal data with the consent of the data subject. Voluntary consent, as agreement, means the user's behavior by which the user accepts that all regulations related to the use of the website automatically extend to them by using the website.
- STATEMENTS OF THE DATA CONTROLLER
4.1. The Data Controller declares that:
- during data processing, it acts in accordance with the provisions of Act CXII of 2011 on the right to informational self-determination and freedom of information and the GDPR.
- during data processing, personal data that comes to the knowledge of the Data Controller may only be accessed by those persons employed by the Data Controller and its contractual partners who have a task related to the given data processing.
- it ensures that the current information is continuously accessible to the data subject, thereby enforcing the principle of transparency.
- the website handles the personal data of visitors confidentially, in accordance with the applicable legal regulations, ensures their security, implements technical and organizational measures, and has established procedural rules to fully comply with data protection principles.
- it handles the personal data of Guests staying at the Hotel confidentially, in accordance with the applicable legal regulations, ensures their security, implements technical and organizational measures, and has established procedural rules to fully comply with data protection principles.
- to preserve the data it processes, it takes and ensures all measures related to IT and other secure data processing for data storage, processing, and data transfer.
- it does everything reasonably expected to ensure the protection of personal data it processes against unauthorized access, alteration, disclosure, deletion, damage, destruction, and to guarantee the necessary technical conditions for this.
- it does not check the personal data provided to it and excludes its responsibility for their accuracy.
- it only transfers personal data to a third party exceptionally and only if the data subject expressly consents to it, or if permitted by law, and if the conditions for data processing are met for each personal data.
- it operates exclusively in Hungary and does not belong to a multinational hotel chain, therefore it is not necessary to implement and operate mandatory organizational regulations.
- it transfers personal data to a data controller or data processor in a third country as set out in this information.
- it keeps records for the purpose of verifying measures related to data protection incidents and informing the data subject, which include the scope of affected personal data, the scope and number of data subjects affected by the data protection incident, the date, circumstances, effects of the data protection incident, and the measures taken to eliminate it, as well as other data specified in the legislation prescribing the data processing.
4.2. The Data Controller excludes its responsibility for the lawfulness of data processing by its contractual partner in a legal relationship with it.
4.3. By applying appropriate security measures, the Data Controller ensures the prevention of accidental or unlawful destruction, or accidental loss, as well as unauthorized access, alteration, or dissemination, in order to protect the personal data stored in the data files.
- ACTIVITIES AND SCOPE OF DATA AFFECTED BY DATA PROCESSING
5.1. Request for Quotation
Processed data: Name*, Email*, Phone number*, City*, Postal code*, Address*, Arrival date*, Departure date*, Number of adults*, Number of children, Room type*, Board basis*, Payment method*, Comments Purpose of data processing: Providing an accurate quote, preparing the booking Legal basis for data processing: Consent (Article 6(1)(a) GDPR) Duration of data processing: In case of a successful quote request, according to the booking rules; - if the quote is rejected, until the day of rejection; - if no response is received to the quote, until the day after the expiration of the quote's validity period. Data transfer takes place?: Yes, to the Pass Kft. (1061 Budapest, Király u. 30-32.) for the purpose of operating the online quote request system.
During a quote request related to room booking via the website, the data subject voluntarily provides their data to the Data Controller for the purpose of receiving a price offer from the Data Controller.
The data processing activity and process are as follows:
- The data subject clicks on the "Booking" button on the website to reach the relevant page, where by clicking on the "Request a Quote" button, they reach the section of the website where they can provide the data specified in point 5.1, and accept the booking and cancellation conditions and this data processing information. After providing the data and accepting the conditions and information, the data subject can submit the specified data to the Data Controller by pressing the "Continue" button.
- In case of a booking, the data sent to the Data Controller are automatically recorded by the Data Controller's SabeeApp and Mirai software, and the available apartments and their prices are presented to the data subject.
- In case of a quote request, the Data Controller's reception staff prepares a quote, which is sent to the data subject by email.
5.2. Room Booking
Processed data: Name*, Email*, Phone number*, Arrival date*, Departure date*, Number of adults*, Number of children, Room type*, Postal code*, City*, Street, house number*, Payment method*, Message to the hotel Purpose of data processing: Providing the service, fulfilling the room booking Legal basis for data processing: Performance of a contract (Article 6(1)(b) GDPR), Consent (Article 6(1)(a) GDPR) Duration of data processing: Personal data received during the booking will be processed for the duration of the contractual relationship with the data subject, except: data to be retained for 8 years according to Act C of 2000 on Accounting, and data to be retained until the last day of the 5th year following the subject year according to Act CL of 2017 on the Rules of Taxation, or according to the current regulations of the loyalty program. Data transfer takes place?: Yes, to the Pass Kft. (1061 Budapest, Király u. 30-32.) for the purpose of operating the online booking system.
Online booking pages are considered independent data controllers; no data processor is used in this process.
The data processing activity and process are as follows:
- If the data subject accepts the quote and informs the Data Controller verbally or in writing, the Data Controller takes the steps related to room booking.
- The SabeeApp program used by the Data Controller automatically links the booking received from the online booking page to the specific room of the Accommodation, thereby creating the room booking.
- The employee in the above-mentioned job role notifies the data subject in writing about the room booking.
5.3. Check-in and Registration Form
Processed data: Last name*, First name*, Birth name*, Place and date of birth*, Mother's maiden name*, Address*, Nationality*, Gender*, Arrival date*, Departure date*, Identification document*, ID number*, Email address, Phone number, Company name, Vehicle registration number Purpose of data processing: Contact and fulfillment of legal obligations Legal basis for data processing: Legal obligation (Article 6(1)(c) GDPR), Consent (Article 6(1)(a) GDPR) Duration of data processing: The personal data provided will be processed for the duration of the contractual relationship with the data subject, except: data to be retained for 8 years according to Act C of 2000 on Accounting, and data to be retained until the last day of the 5th year following the subject year according to Act CL of 2017 on the Rules of Taxation, or according to the current regulations of the loyalty program. Data transfer takes place?: NTAK (National Tourism Data Supply Centre), VIZA (Guest Information and Registration System)
Upon arrival at the Accommodation, before occupying the booked room, the data subject fills out a Guest Registration Form, thereby consenting to the Data Controller processing the data provided below for the purpose of fulfilling its obligations specified in the relevant legislation, proving fulfillment, and identifying the Guest, as long as the competent authority can verify the fulfillment of the obligations specified in the relevant legislation.
The data processing activity and process are as follows:
- The provision of mandatory data by the Guest is a condition for using the Accommodation services.
- By signing the registration form, the guest consents to the Data Controller processing and archiving the data provided by filling out the registration form for the purpose of concluding and proving the performance of the contract, and for potential claim enforcement, within the deadline specified above.
- On the registration form, the guest has the opportunity to join the Accommodation's loyalty program.
5.4. Invoicing
Processed data: Last name*, First name*, Address, duration of stay at the hotel, Bank account details* Purpose of data processing: Invoicing for Accommodation services, fulfillment of invoicing obligation, conducting payment transactions Legal basis for data processing: Legitimate interest (Article 6(1)(f) GDPR); Fulfillment of a legal obligation (Article 6(1)(c) GDPR) Duration of data processing: Data to be retained for 8 years according to Act C of 2000 on Accounting, and data to be retained until the last day of the 5th year following the subject year according to Act CL of 2017 on the Rules of Taxation. Data transfer takes place?:
- KBOSS.hu Kft, Számlázz.hu (1031 Budapest, Záhony u. 7/D.)
- Affected Financial Institutions (joint controllership)
- The Data Controller uses and may use the bank/credit card/bank account data provided by the data subject to the Data Controller only to the extent and for the duration necessary for the exercise of its rights and the fulfillment of its obligations. The data are processed by the Data Controller's contractual banking partners. Information about this data processing can be found on the websites of the relevant banks.
- Guests can receive further information about credit card data processed by certain sub-systems of the Data Controller by sending a request to
This email address is being protected from spambots. You need JavaScript enabled to view it. .
5.5. Newsletter Sending
Processed data: Last name*, First name*, Email address* Purpose of data processing: Informing the data subject about the Data Controller's events, news, and latest promotions. Legal basis for data processing: Consent (Article 6(1)(a) GDPR) Duration of data processing: Until consent is withdrawn, until the date of unsubscribing from the newsletter. Data transfer takes place?: BITHUSZÁROK Számítástechnikai Bt. (2051 Biatorbágy, Damjanich u. 8. tetőtér 4.)
- Subscribing and unsubscribing from the newsletter are voluntary.
- The purpose of data processing related to sending newsletters is to manage a database for sending newsletters and to provide comprehensive general or personalized information to the recipient about the Data Controller's latest promotions.
- The Data Controller sends newsletters only with the consent of the data subject.
- The provided personal data are stored by the Data Controller on a separate list, separately from data provided for other purposes, and this list may only be accessed by authorized employees of the Data Controller and its data processors. The Data Controller's Data Processor is: BITHUSZÁROK Számítástechnikai Bt.
- The Data Controller does not transfer the list or data to unauthorized third parties and takes all security measures to ensure that unauthorized persons cannot access them.
- The Data Controller only processes personal data collected for this purpose until the data subject unsubscribes from the newsletter list or requests the deletion of their data. The Data Controller reviews the newsletter list once a year. The objective retention period for data is 4 years.
The data subject can unsubscribe from the newsletter at any time by clicking the link at the bottom of the emails, or by sending an unsubscribe request to
- The Data Controller keeps statistics on the readership of sent newsletters and clicks on links in the newsletters.
- The Guest can subscribe to the news feed published on the Facebook page's wall by clicking the "like" button on the page, and unsubscribe by clicking the "dislike" button in the same place, or delete unwanted news feeds appearing on the wall using the wall settings.
5.6. Loyalty Program
Processed data: Last name*, First name*, address*, place and date of birth*, ID card number*, passport*, duration of stay Purpose of data processing: Providing discounts to returning guests Legal basis for data processing: Consent (Article 6(1)(a) GDPR) Duration of data processing: 8 years, or until withdrawal of consent to participate in the loyalty program. Data transfer takes place?: Morgens Design Kft. (8800 Nagykanizsa, Csányi László utca 2.)
- Participation in the loyalty program is voluntary.
- Participants in the program give their explicit consent to the Data Controller processing their personal data provided for this purpose for the operation of the Loyalty Program system, and for sending newsletters specifically created for loyalty guests. Based on this consent, the processing of the provided personal data lasts as long as the data subject participates in the program.
- Loyalty program membership status becomes inactive after 5 (five) years from the last use of Accommodation services. The Data Controller stores the member's personal data for the period specified in the current tax and accounting regulations and deletes them after the deadline.
- The provided data are stored by the Data Controller in a separate data file, separately from other provided data. This data file may only be accessed by authorized employees of the Data Controller.
- The data of Loyalty Guests (natural persons) may be used for market research purposes, but the Loyalty Guest must be informed of this in advance and their prior consent must be obtained.
- The Data Controller deletes the data processed by the loyalty program at the request of the Guest sent to
This email address is being protected from spambots. You need JavaScript enabled to view it. .
5.7. Facebook Page
Processed data: Image, Facebook ID, Name provided there Purpose of data processing: Utilizing the possibilities of the social media page to promote the Accommodation. Legal basis for data processing: Consent (Article 6(1)(a) GDPR) Duration of data processing: Until consent is withdrawn, until the date of unsubscribing. Data transfer takes place?: No
- By clicking the "like" button on the Data Controller's Facebook page, the data subject consents to the Data Controller publishing its news and offers on their own wall.
- The Data Controller also publishes images/videos of various events/hotels/fitness clubs/restaurants etc. on its Facebook page. Unless it is a crowd shot, the Data Controller always asks for the data subject's written consent before publishing the images.
- Information about Facebook page data processing can be obtained from the privacy policy and rules on the Facebook website, at www.facebook.com.
5.8. Gift Voucher
Processed data: Purchaser's name*, Purchaser's email address*, Purchaser's phone number*, Purchaser's mailing address* (country, postal code, city, street, house number), Purchaser's billing address* (country, postal code, city, street, house number), Purchaser's IP address (online identifier)*, Name(s) of recipient(s) Purpose of data processing: Opportunity to purchase a gift voucher Legal basis for data processing: Legal obligation (Article 6(1)(c) GDPR) - data necessary for invoicing (name, address); Performance of a contract (Article 6(1)(b) GDPR) - purchaser's email address, phone number, and recipient's data, for gift voucher purchase. Duration of data processing: Data to be retained for 8 years according to Act C of 2000 on Accounting, and data to be retained until the last day of the 5th year following the subject year according to Act CL of 2017 on the Rules of Taxation. Data transfer takes place?: No
- The Accommodation allows Guests to purchase various gift vouchers that can be used for Accommodation services up to the specified value.
- Ordering and using the gift voucher are voluntary.
- The Data Controller issues an invoice for the agreed and ordered voucher amount, and a numbered voucher after receiving the payment, then delivers it to the specified address.
- The provided personal data are stored by the Data Controller in a separate data file, separately from other provided data. This data file may only be accessed by authorized employees of the Data Controller.
- The Data Controller provides more detailed information about data processing related to gift vouchers upon request sent to
This email address is being protected from spambots. You need JavaScript enabled to view it. . Deletion from the data file can also be requested here.
5.9. Guestbook
Processed data: Data subject's name*, email address*, City*, Data subject's opinion* Purpose of data processing: Managing a guestbook on the www.club218apartman.hu website. Legal basis for data processing: Consent (Article 6(1)(a) GDPR) Duration of data processing: Until consent is withdrawn. Data transfer takes place?: No
- Data subjects can provide their opinions online to the Data Controller to improve the quality of service.
- Providing the data is not mandatory; it only serves to ensure a thorough investigation of potential complaints and to provide a response from the Data Controller to the guest.
- The opinions received in this way, and any potentially provided data that cannot be traced back to the specific Guest or linked to the Guest's name, may also be used by the Data Controller for statistical purposes.
- The provided personal data are stored by the Data Controller in a separate data file, separately from other provided data. This data file may only be accessed by authorized employees of the Data Controller.
- WEBSITE VISIT DATA (REFERENCES AND LINKS)
6.1. The Data Controller's website may also contain links that are not operated by the Data Controller, but merely serve to inform visitors. The Data Controller has no influence over the content and security of websites operated by partner companies and therefore is not responsible for them.
6.2. Please review the data processing policy and privacy statement of the pages you visit before providing your data in any form on that page.
6.3. Analytics, Cookies
- The Data Controller uses an analytical tool to monitor its websites, which creates a data series and tracks how visitors use the internet pages. The system creates a cookie when viewing the page, with the aim of recording information related to the visit (pages visited, time spent on our pages, Browse data, exits, etc.), which, however, cannot be linked to the person of the visitor. This tool helps to improve the ergonomic design of the website, create a user-friendly website, and enhance the online experience of visitors. The Data Controller does not use analytical systems to collect personal information. Most internet browsers automatically accept cookies, but visitors have the option to delete them or reject them automatically. Since each browser is different, visitors can individually set their cookie preferences using the browser's toolbar. It is possible that you may not be able to use certain features on our website if you choose not to accept cookies.
- We use a session cookie (small data packet) on the website, which is valid until the end of the given session, meaning it is created for the duration of the visit, and then automatically deleted from the user's computer. The so-called cookie is necessary for the security of the website and user-friendly solutions, for a better user experience.
- The technological background for the hosting required for website operation is provided by Elin.hu Informatikai Kft. (Registered office: 9024 Győr, Déry T. u. 11., Tax number: 14315754-2-08), as Data Processor.
- STORAGE OF PERSONAL DATA, INFORMATION SECURITY
7.1. Personal data may only be processed in accordance with the activities described in Chapter 5 and for the purpose of data processing.
7.2. Personal data can be modified and deleted, voluntary consent can be withdrawn, and information about personal data processing can be requested by sending a notification to
7.3. The Data Controller ensures the security of the data. To this end, it takes the necessary technical and organizational measures, establishes and enforces procedural rules.
7.4. The Data Controller protects data with appropriate measures against unauthorized access, alteration, transmission, disclosure, deletion or destruction, as well as against accidental destruction and damage, and against becoming inaccessible due to changes in the technology used. The Data Controller takes all necessary technical and organizational measures to prevent a potential data protection incident (e.g., damage to, loss of, or unauthorized access to files containing personal data). In the event of an incident, the data controller keeps records for the purpose of verifying the necessary measures and informing the data subject, which include the scope of affected personal data, the scope and number of data subjects affected by the data protection incident, the date, circumstances, effects of the data protection incident, and the measures taken to eliminate it, as well as other data specified in the legislation prescribing the data processing.
7.5. To ensure the conditions of data security, the Data Controller ensures the appropriate training of the affected Employees.
7.6. When determining and applying measures to ensure data security, the Data Controller considers the current state of technology and chooses from several possible data processing solutions the one that provides a higher level of protection for personal data, unless it would cause disproportionate difficulty.
7.7. In the scope of its tasks related to IT protection, the Data Controller ensures, in particular:
- Measures to protect against unauthorized access, including the protection of software and hardware tools, and physical protection (access control, network protection);
- Measures to ensure the possibility of restoring data files, including regular backups and the separate, secure handling of copies (mirroring, backup);
- Protection of data files against viruses (antivirus protection);
- Physical protection of data files and the devices carrying them, including protection against fire, water damage, lightning strikes, other natural disasters, and the possibility of restoring damage caused by such events (archiving, fire protection).
7.8. The Data Controller shall provide the expected level of protection when processing data - in particular their storage, correction, deletion - upon the request or objection of the data subject for information.
7.9. Data transfer shall be carried out with the consent of the data subject, without prejudice to his or her interests, confidentially,
in a manner that is fully consistent with this. IT system is provided in compliance with the purpose, legal basis and principles of data processing. The Data Controller does not transfer the personal data of the data subject without his/her consent, and does not make it available to a third party, unless this is mandatory by law.
7.10. Other data of the data subject that cannot be directly or indirectly linked to him/her,
unidentifiable – hereinafter referred to as anonymous – are not considered personal data.
- EXERCISE OF THE DATA SUBJECT’S RIGHTS
8.1. Data subject’s rights
The data subject may request information from the Data Controller about the processing of his/her personal data, and may request the correction, deletion, withdrawal, restriction of data processing, and may exercise his/her right to data portability and objection.
a.) Right to information:
Upon request by the data subject, the Data Controller shall take appropriate measures to provide the data subject with all information and communication concerning the processing of personal data as specified in the General Data Protection Regulation in a concise, transparent, intelligible and easily accessible form, in clear and plain language.
b.) Right of access by the data subject:
13
The data subject shall have the right to obtain from the Data Controller information on whether personal data concerning him or her are being processed and, if so, to have access to the personal data and the following information:
- the purposes of the processing;
- the categories of personal data concerned;
- the recipients or categories of recipients to whom the personal data have been or will be disclosed, including in particular recipients in third countries or international organisations;
- the planned period for which the personal data will be stored; the right to rectification, erasure or restriction of processing and to object; the right to lodge a complaint with a supervisory authority;
- information on the sources of the data;
- the fact of automated decision-making, including profiling, as well as intelligible information on the logic involved and the significance of such processing and the likely consequences for the data subject.
The Data Controller shall provide the data subject with a copy of the personal data subject to the processing. For additional copies requested by the data subject, the Data Controller may charge a reasonable fee based on the administrative costs. At the request of the data subject, the Data Controller shall provide the information in electronic form.
The right to information may be exercised in writing via the contact details specified in point 1. Upon request, the data subject may also be provided with information orally, following credible verification and identification of his or her identity.
c.) Right to rectification:
The data subject may request the Controller to rectify inaccurate personal data concerning him or her and to complete incomplete data.
d.) Right to erasure:
The data subject shall have the right to obtain from the Controller the erasure of personal data concerning him or her without undue delay where one of the following grounds applies:
- the personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
- the data subject withdraws his or her consent on which the processing is based and there is no other legal basis for the processing;
- the data subject objects to the processing and there are no overriding legitimate grounds for the processing;
- the personal data have been processed unlawfully;
- the personal data must be erased for compliance with a legal obligation to which the Controller is subject under European Union or Member State law.
- the personal data were collected in connection with the provision of information society services.
The erasure of data cannot be requested if the processing is necessary:
- for the purpose of exercising the right to freedom of expression and information;
- for the purpose of fulfilling an obligation under European Union or national law to which the controller is subject to processing, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
- in the field of public health, or for archiving, scientific and historical research purposes or statistical purposes in the public interest;
- or for the establishment, exercise or defence of legal claims.
e.) Right to restriction of processing:
At the request of the data subject, the Data Controller shall restrict processing where one of the following
conditions is met:
- the data subject contests the accuracy of the personal data, in which case the restriction shall apply for a period of time which allows the accuracy of the personal data to be verified;
- the processing is unlawful and the data subject opposes the erasure of the data and requests the restriction of their use instead;
- the Controller no longer needs the personal data for the purposes of the processing, but the data subject requires them for the establishment, exercise or defence of legal claims;
or
- the data subject has objected to the processing; in this case, the restriction shall apply for a period of time until it is established whether the legitimate grounds of the Controller override those of the data subject.
If processing is restricted, the personal data may only be processed, with the exception of storage, with the consent of the data subject, or for the establishment, exercise or defence of legal claims, or for the protection of the rights of another natural or legal person, or for important public interests of the European Union or a Member State. The Controller shall inform the data subject in advance of the lifting of the restriction on processing.
f.) Right to data portability:
The data subject shall have the right to receive the personal data concerning him or her, which he or she has provided to the Data Controller, in a structured, commonly used and machine-readable format and to transmit those data to another data controller.
g.) Right to object:
The data subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of his or her personal data for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller, or for the purposes of the legitimate interests pursued by the Data Controller or by a third party.
In the event of an objection, the Data Controller shall no longer process the personal data unless there are compelling legitimate grounds for doing so which override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.
The Data Controller does not process personal data for the purpose of direct marketing.
8.2. Procedural rules
15
The Data Controller shall inform the data subject without undue delay, but in any case within one month of receipt of the request, of the measures taken in response to the request. If necessary, taking into account the complexity of the request and the number of requests, this deadline may be extended by a further two months. The Data Controller shall inform the data subject of the extension of the deadline within one month of receipt of the request, indicating the reasons for the delay. If the data subject has submitted the request electronically, the information shall be provided electronically, unless the data subject requests otherwise.
If the Data Controller does not take action on the request of the data subject, it shall, without delay,
but no later than one month from the receipt of the request, inform the
data subject of the reasons for not taking action and of the right to lodge a complaint with a supervisory authority and to seek a judicial remedy.
The Data Controller shall provide the requested information and communication free of charge. If the data subject's
request is manifestly unfounded or excessive, in particular because of its repetitive nature,
the Data Controller may charge a reasonable fee, taking into account the administrative costs incurred in providing the requested information or communication or in taking the requested
measure,
or may refuse to take action on the request.
The Data Controller shall inform any recipient to whom or with whom the personal data have been communicated of any rectification, erasure or restriction of processing made by it, unless this proves impossible or involves a disproportionate effort. The Data Controller shall inform the data subject of these recipients upon request.
The Data Controller shall provide the data subject with a copy of the personal data subject to processing. For any further copies requested by the data subject, the Data Controller may charge a reasonable fee based on the administrative costs. If the data subject has submitted the request electronically, the information shall be provided in electronic formatto be made available, unless the data subject requests otherwise.
8.3. Compensation and damages
Any person who has suffered material or non-material damage as a result of a breach of the General Data Protection Regulation shall be entitled to compensation from the Controller or the processor for the damage suffered. The Processor shall only be liable
for damage caused by the processing if it has not complied with the obligations expressly imposed on processors by law, or if it has disregarded or acted contrary to the lawful instructions of the Controller.
If both the Controller and the processor are involved in the same processing and are liable for damage caused by the processing, the Controller and the processor shall be jointly and severally liable for the full damage.
The Data Controller or the data processor shall be exempt from liability if it proves that it is not liable in any way for the event causing the damage.
8.4. Data protection authority procedure
The data subject may submit a complaint regarding the processing of his or her personal data by the Data Controller to the National Data Protection and Freedom of Information Authority, as the supervisory authority. Contact details of the supervisory authority
National Data Protection and Freedom of Information Authority (NAIH)
address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
16
postal address: 1530 Budapest, Pf.: 5.
e-mail:
telephone: +36 (1) 391-1400
fax: +36 (1) 391-1410
In case of violation of your rights related to content that offends minors, incites hatred, excludes minors, rectification, the rights of a deceased person, or violation of good reputation, you can file a report or complaint with:
National Media and Communications Authority
address: 1015 Budapest, Ostrom u. 23-25.
e-mail:
mailing address: 1525. Pf. 75
phone: (06 1) 457 7100
fax: (06 1) 356 5520
- DATA PROTECTION INCIDENT REPORTING SYSTEM
9.1. Data protection incident: a breach of security that results in the accidental or unlawful destruction,
loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored or
otherwise processed.
9.2. Notification of a data protection incident to the supervisory authority
- The Controller shall notify the data protection incident to the competent supervisory authority without undue delay and, where
possible, not later than 72 hours after having become aware of the data protection incident, unless the
data protection incident is unlikely to result in a risk to the rights and freedoms of natural persons. If the notification is not made within 72
hours, the reasons justifying the delay shall be included.
- The Data Processor shall notify the Data Controller of the data protection incident without undue delay after becoming aware of it. (24 hours
maximum)
- If and to the extent that it is not possible to communicate the information simultaneously, it may be communicated in parts at a later date without further undue delay.
- The Data Controller shall keep records of data protection incidents, indicating the facts relating to the data protection incident, its effects and the measures taken to remedy it.
9.3. Informing the data subject about the data breach
- Where the data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall inform the data subject about the data breach without undue delay (maximum 24 hours)
17
- The information provided to the data subject shall describe the nature of the data breach in a clear and intelligible manner and shall include the information and measures referred to above.
- The data subject shall not be required to be informed if any of the following conditions are met:
- the controller has implemented appropriate technical and organisational protection measures and those measures have been applied to the data affected by the data
breach, in particular measures such as encryption which render the data unintelligible to persons not authorised to access the personal data;
- the Data Controller has taken additional measures following the data protection incident to ensure that the high risk to the rights and freedoms of the data subject referred to in the previous paragraph is unlikely to materialise in the future;
- providing information would involve a disproportionate effort. In such cases, the data subjects shall be informed by means of publicly published information or a similar measure shall be taken to ensure that the data subjects are informed in a similarly effective manner.
Date: Siófok, 1 May 2024.
Data marked with * are mandatory.
Győző Mészáros
CEO / Club 218 Kft
Colors Holiday Hotel