(upon guest check-in)
1. Name, seat and representative of the controller
- Name: Kolping Hotel Kft.
- Seat: 8394 Alsópáhok Fő út 120.
- Statutory representative: Csaba Baldauf Managing Director
- Contact person in relation to data protection matters: Judit Nyírő Deputy Director responsible for operation
2. Data protection officer
- Dr. Boldizsár Morvay - firstname.lastname@example.org
3. Definition of the processed data
- date of birth
- registration number
- phone number
- e-mail address
- whether newsletter is requested or not
- date of arrival/departure
- children’s name and date of birth
- number of previous hotel stays (application for regular’s programme)
- identity card No.
- usage data of the room key card
- information about having food allergy
4. Purpose of processing
- name, address required for billing
- the age is required for the assessment of tourist tax liability
- the children’s name is also necessary for their participation in the sessions
- the children’s age is required for pricing and the preparation of the meals
- the registration number is needed for the parking
- the e-mail address is required for marketing purposes
- the purpose of the phone number is that the guests could be called during their stay
- the data of earlier stays are important for the regular’s programme
- the identity card No. is needed for property security purposes
- the data relating to nationality serves statistical, marketing and sales support purposes
- the data of the room key card are needed for property security purposes
- the information concerning food allergy is required to provide meals appropriate to the guest’s state of health.
5. Legal basis for processing
- as regards name and address, the fulfilment of legal obligations laid down in Article 169 of Act C of 2000 on Accounting - point (c) of Article 6(1) of the GDPR
- as regards the name and age of service users, the fulfilment of legal obligations laid down in Articles 30 and 31 of Act C of 1990 on Local Taxes - point (c) of Article 6(1) of the GDPR
- as regards the e-mail address and phone number as well as the identity card No. and nationality, the data subject’s consent - point (a) of Article 6(1) of the GDPR
- as regards the registration number, the performance of the contract - point (b) of Article 6(1) of the GDPR
- as regards the data of the room key card, the legitimate interest of the controller - point (f) of Article 6(1) of the GDPR
6. Legal consequences of failure to provide data
- the data subject cannot use the controller’s service, thus the processing will not take place.
7. Transfer of personal data
- the data will only be transferred to data-processing company operating the online quotation and booking systems; the name of that processor: Flexys Kft. seat: 1037 Budapest, Máramaros utca 23/a
- data will not be transferred to third country.
8. Data transfer and its legal basis
- performance of the contract (operation of hotel management system)
9. Duration of the processing of personal data
- billing name, address – 8 years
- service recipients’ name and age, identity card No. and nationality – 5 years after the last day of the current year
- e-mail address – until unsubscription, until the withdrawal of processing
- registration number, phone number and the data of the room key card until departure
- data of earlier stay – until withdrawal
10. Information about the rights of the data subject
The data subject shall have the right:
- to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data.
- to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her.
- to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay if certain other conditions are met.
- to obtain from the controller restriction of processing if
- the accuracy of the personal data is contested by the data subject /the restriction lasts until the controller verifies the accuracy of the personal data,/
- the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;
- the controller no longer needs the personal data, but they are required by the data subject for the establishment, exercise or defence of legal claims.
- the data subject has objected to processing pending the verification whether the legitimate grounds of the controller override those of the data subject.
- to receive the personal data concerning him or her, which he or she has provided to the controller, in a structured format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where the processing is based on consent or on a contract, and it is carried out by automated means.
- where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing.
- not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
11. Information about profiling, automated decision-making
- profiling and automated decision-making do not take place
12. Data storage, data security
The controller and the organisation involved as a processor store the data on their own computing devices which are held at the registered seat, and in the case of the processor, they can be found in a server farm. The controller and processor choose and operate their IT devices so that the data processed could be accessed by the authorised persons, their credibility and validation remain assured, it could be verified that they had not been modified and they are protected against unauthorised access. Data are protected against unauthorised access, modification, transfer, disclosure, erasure or destruction as well as accidental destruction, damage and unavailability due to the change of the applied technology in such a way that, by having regard to the current technological development, the controller takes care of the protection of processing security with technological, organisational and structural measures that provide an adequate level of protection against the risks associated with processing.
13. Right of access to the competent authority
In the event of any breach of their rights, the data subject may have recourse to court against the controller. The reconsideration of the legal action falls within the competence of the regional court (Contact detail of Zalaegerszeg Regional Court: 8900 Zalaegerszeg Várkör u 2.). At the data subject’s option, the action can be brought to the regional court in whose jurisdiction the data subject’s home address or temporary residence is located. Such cases will be given priority by the court.
You may lodge an appeal or a complaint to the Hungarian National Authority for Data Protection and Freedom of Information. Name: Hungarian National Authority for Data Protection and Freedom of Information Seat: 1125 Budapest, Szilágyi Erzsébet fasor 22/C. Postal address: 1530 Budapest, Pf.: 5. Phone: 06.1.391.1400 Fax: 06.1.391.1410 E-mail: email@example.com Website: http://www.naih.hu