Privacy Policy

Introduction
Thermal Villa Berekfürdő, the operator of the www.thermalvillaberekfurdo.hu website, as Data Controller, processes personal data for various purposes and intends to do so while respecting the rights of Data Subjects and complying with legal obligations (in particular the General Data Protection Regulation, hereinafter referred to as GDPR). Thermal Villa Berekfürdő also considers it important to inform Data Subjects about the processing of personal data obtained during its data processing activities and its most important characteristics.

Data processing related to the use of the www.thermalvillaberekfurdo.hu website


Who processes your personal data?
Your personal data is processed by Thermal Villa Berekfürdő (hereinafter referred to as the Data Controller). Contact details:
Postal address: 5309 Berekfürdő, Bagoly utca 1/c
Website: https://thermalvillaberekfurdo.hu
Phone: +36 70 282 2042

Cookie management:
The Data Controller's website uses cookies to operate the website, facilitate its use, and track activities performed on the website. Detailed information about cookies is displayed separately when entering the website.

About cookies:

Cookies are small data files that are placed on your computer when you visit a website, created, saved and stored by the websites you visit. The most commonly used browsers (Chrome, Firefox, etc.) generally accept and enable the downloading and use of cookies by default; however, users may modify their browser settings to reject or disable them, and cookies already stored on the computer may also be deleted. Further information about the use of cookies is available in the “Help” section of each browser.

Basically, we distinguish between two types of cookies. One group consists of cookies that do not require the user's consent. Information about these is provided when the user first visits our website. Examples include “user input” cookies, authentication cookies, user-centric security cookies, multimedia player session cookies, load-balancing session cookies, and cookies used to customize the user interface.

The other group consists of cookies that require the user's consent. If data processing begins upon visiting the website, users are informed about these cookies when they first visit the website and their consent is requested. Examples include social content-sharing tracking cookies, cookies related to third-party advertising, and our own visitor analytics cookies.

Accepting cookies is not mandatory; however, we inform users that disabling cookies may affect the operation of the website, and therefore we accept no responsibility if our website does not function as expected due to cookies being disabled.

Cookies used

Type: Session cookies.
Name: Cookies essential for providing the service.
Consent: Not required.
Description: These cookies are necessary to enable users to use the website.
Purpose: Ensuring the operation of the website.
Validity: Until the end of the browsing session.

Type: Functional cookies.
Name: Cookies storing previous settings.
Consent: Required.
Description: Saving information provided during login (“Stay logged in”) and accepting the use of cookies (“I accept the use of cookies”).
Purpose: Remembering users' settings.
Validity: Depends on the settings, but no longer than 2 years.

Type: Tracking cookie for visitor analytics purposes (third-party).
Name: Google Analytics (_gat and _ga).
Consent: Required.
Description: They collect information about the use of the website and the user's activity.
Purpose: Connection to services provided by third parties (e.g. Google) during visits to the website.
Validity: 2 years.

Further information is available at the following links:
Internet Explorer: http://windows.microsoft.com/en-us/internet-explorer/delete-manage-cookies#ie=ie-11
Firefox: https://support.mozilla.org/en-US/kb/cookies-information-websites-store-on-your-computer
Chrome: https://support.google.com/chrome/answer/95647?hl=en
Safari: https://support.apple.com/en-us/HT201265

While browsing the website, technical information is also recorded (for example, in the form of log files containing the user's IP address, the time of the page visit and the URL address(es) of the page(s) visited). This information cannot be used for personal identification but serves statistical purposes.

Whose data do we process?
The Data Controller processes the data of persons visiting the https://thermalvillaberekfurdo.hu website as follows.

Basic information regarding data processing activities:

1. Contact
Purpose: Handling enquiries/questions, identifying the person making the enquiry and recording the question.
Legal basis: Article 6(1)(a) – based on the consent of the Data Subject.
Nature: Automated and manual
Data processed: Name, E-mail, Phone number, Message.
Duration: The Data Controller processes the data until consent is withdrawn.
Data Subjects: Persons making enquiries or initiating contact.
Data Processor(s):
Details:
WebHostIcon Tárhely- és Domain Szolgáltató Kft.
1081 Budapest, Légszesz u. 4. 1. em. 5.
https://webhosticon.hu/
Activity:
Hosting service provider
Details:
Aktiv Digital Media Kft.
5600 Békéscsaba, Lencsési út 35-37. 8. em. 46.
office@aktivdigital.hu
+36 30 160 6979
Activity:
Website developer
Recipient(s) of data transfer: None -

2. Requests for quotation
Purpose: Handling requests for quotation, identifying the person requesting the quotation and sending them a quotation.
Legal basis: Article 6(1)(a) – based on the consent of the Data Subject.
Nature: Automated and manual
Data processed: Name, E-mail, Phone number, Message.
Duration: The Data Controller processes the data until consent is withdrawn.
Data Subjects: Persons requesting a quotation through the website.
Data Processor(s):
Details:
WebHostIcon Tárhely- és Domain Szolgáltató Kft.
1081 Budapest, Légszesz u. 4. 1. em. 5.
https://webhosticon.hu/
Activity:
Hosting service provider
Details:
Aktiv Digital Media Kft.
5600 Békéscsaba, Lencsési út 35-37. 8. em. 46.
office@aktivdigital.hu
+36 30 160 6979
Activity:
Website developer
Recipient(s) of data transfer: None -

3. Accommodation booking
Purpose: Managing accommodation bookings, identifying persons booking accommodation and communicating with them.
Legal basis: Article 6(1)(a) – based on the consent of the Data Subject.
Nature: Automated and manual
Data processed: Name, E-mail, Phone number, Message.
Duration: The Data Controller processes the data until consent is withdrawn.
Data Subjects: Persons booking accommodation through the website.
Data Processor(s):
Details:
WebHostIcon Tárhely- és Domain Szolgáltató Kft.
1081 Budapest, Légszesz u. 4. 1. em. 5.
https://webhosticon.hu/
Activity:
Hosting service provider
Details:
Aktiv Digital Media Kft.
5600 Békéscsaba, Lencsési út 35-37. 8. em. 46.
office@aktivdigital.hu
+36 30 160 6979
Activity:
Website developer
Details:
Chrome-Soft Kft.
8226 Alsóörs Rege köz 9.
chrome@chrome.hu
+36 1 225 8494
Activity:
Company developing the hotel software and online booking system
Recipient(s) of data transfer: None -

4. Notification of a personal data breach
Purpose: Providing information about the occurrence of a personal data breach, communication
Legal basis: Article 6(1)(c) of the GDPR – processing is necessary for compliance with a legal obligation to which the Data Controller is subject
Nature: Automated and manual
Data processed: Identification data, contact details
Duration: 5 years or until the conclusion of the legal dispute
Data Subjects: Affected persons
Data Processor(s): None -
Recipient(s) of data transfer: None -

In the case of data processing based on consent, you may withdraw your consent at any time. In the case of processing based on the legitimate interests of the Data Controller, the Data Subject may object to the processing.


What principles do we consider important when processing data?
We process personal data in accordance with the applicable legal regulations.
The Data Controller processes only the personal data specified for each individual data processing activity.
The security of the personal data provided is protected by all necessary technical and organizational measures.
Particular attention is paid to ensuring the confidentiality, integrity and availability of personal data.
The Data Controller is responsible for the authenticity and accuracy of personal data after it has been provided by you.
The terms used in this privacy notice are interpreted in accordance with the definitions set out in Act CXII of 2011 on Informational Self-Determination and Freedom of Information.

What rights do you have regarding your personal data processed by the Data Controller?
The Data Controller ensures that Data Subjects are able to exercise their rights specified in the GDPR. The Data Controller may not refuse a request to exercise these rights unless it proves that it is unable to identify the Data Subject. Therefore, the Data Subject must identify themselves in order for their request to be fulfilled.
The Data Controller must fulfil the request without undue delay and no later than 1 month after receipt, or inform the Data Subject of any obstacles to or delays in fulfilling the request. In such cases, the deadline may be extended by a further 2 months, provided that the Data Subject is informed of the extension and the reasons for it within 1 month.
The Data Controller shall respond to the Data Subject's request in the same form in which it was received. The Data Subject may also submit the request electronically, in which case the response will also be provided electronically unless the Data Subject expressly requests otherwise.
In order to ensure the exercise of Data Subject rights, the rights set out in this notice may be exercised free of charge, and therefore the Data Controller does not charge a fee, unless the request is manifestly unfounded or excessive, in particular because of its repetitive nature.
If and insofar as the requested measure or information is excessive or manifestly unfounded, the Data Controller may charge a reasonable fee for fulfilling the request (in particular to cover the increased administrative costs of excessive requests), or may refuse to act on the request.
In such cases, the Data Controller is obliged to provide reasons to the Data Subject.

In accordance with applicable legislation, Data Subjects may exercise the following rights:
a.) Throughout the entire period of data processing, the Data Subject has the right to request information and access to the personal data processed by the Data Controller and the characteristics of the processing through the contact details provided, in particular regarding:
- the identity and contact details of the Data Controller and its contact person, and, where the Data Controller has appointed a data protection officer, the contact details of the data protection officer,
- the purpose, legal basis and duration of the processing,
- the name and address of the Data Processor and its activities related to data processing, where a Data Processor is used,
- the legal basis and recipient of any data transfer, where data transfer takes place,
- any personal data breach that may have occurred.
b.) The Data Subject has the right to request the rectification or modification of their personal data. If their data has changed or is inaccurate, the Data Controller shall amend it at any time during the processing period upon request. Such requests may be submitted through the contact details provided.
c.) The Data Subject may withdraw their consent at any time and request that the Data Controller erase their data.
The Data Subject's personal data shall also be erased if the processing is unlawful, the purpose of the processing has ceased to exist, or the specified data retention period has expired; or if a court or the Hungarian National Authority for Data Protection and Freedom of Information has ordered its erasure by a final decision.
d.) At the request of the Data Subject, the Data Controller shall restrict the processing of personal data:
- where the Data Subject contests the accuracy of their data, in which case the restriction applies for the period necessary for the Data Controller to verify the accuracy of the personal data
- where the processing is unlawful and the Data Subject opposes the erasure of the data and requests the restriction of its use instead
- where the Data Controller no longer needs the personal data for the purposes of processing, but the Data Subject requires it for the establishment, exercise or defence of legal claims
- where the Data Subject has objected to processing, in which case the restriction applies for the period required to determine whether the legitimate grounds of the Data Controller override those of the Data Subject.
e.) The Data Subject may object to the processing of their personal data where the Data Controller processes the data on the legal basis that processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party. In such cases, the Data Controller may no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the Data Subject, or grounds related to the establishment, exercise or defence of legal claims.
f.) Where processing is based on consent or is necessary for the performance of a contract and the processing is carried out by automated means, i.e. the Data Subjects' data is processed using computerized records, the Data Subject has the right to receive the personal data concerning them, which they have provided to the Data Controller, in a structured, commonly used and machine-readable format. Furthermore, they have the right to transmit such data to another Data Controller without hindrance from the Data Controller. (The Data Subject's right to data portability)

Legal remedies available to the Data Subject
In the event of a suspected infringement relating to the processing of your personal data, you may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information or apply to the competent court (http://bíróság.hu/torvenyszekek).
Contact details of the Hungarian National Authority for Data Protection and Freedom of Information:
Address: 1055 Budapest, Falk Miksa utca 9-11. Postal address: 1363 Budapest, Pf.: 9.
Phone: +36 1 391 1400, E-mail: ugyfelszolgalat@naih.hu