Adatvédelmi tájékoztató
- Az adatkezelő neve: Event Horizon Capital Zrt. (a továbbiakban: Adatkezelő)
- Registered office: 1053 Budapest, Veres Pálné u. 9., II. em.
- Company registration number: Cg. 01-10-049274.
- Képviseli: Dr. Varga János vezérigazgató önállóan
- Honlap: https://leprimore.hu/en
- Adatvédelmi tisztviselő neve:
- Dr. Kéri Ádám fő adatvédelmi tisztviselő
- Dr. Kéri Szonja adatvédelmi tisztviselő
- Adatvédelmi tisztviselő elérhetősége:
- adam.keri.office@icloud.com
- szonja.keri@drkeri.hu
- 1281 Budapest, Pf.12.
The data processing activities covered by this Privacy Notice
The data controller, Le Primore Hotel & Spa (hereinafter: the Hotel), also operates a gourmet restaurant whose services are presented on a separate website (https://lavierestaurant.hu). This Privacy Notice provides a clear overview of the data processing activities carried out through the website. Should you have any further questions, please contact us!
This Privacy Notice covers the following data processing activities:
I. HOSTING PROVIDER
II. COOKIES USED ON THE WEBSITE
III. CONTACTING US
IV. ONLINE ROOM RESERVATIONS
V. TABLE RESERVATIONS
VI. REQUESTS FOR QUOTATION
VII. NEWSLETTERS
VIII. SOCIAL MEDIA PRESENCE
IX. DATA SUBJECT RIGHTS
X. LEGISLATION, DEFINITIONS AND PRINCIPLES
Below, we provide a summary of the most important data processing activities. Should you have any further questions, please contact our Data Protection Officer.
I. Hosting provider
Web hosting is an internet service in which the resources of a server are shared among several users. Each user is allocated dedicated storage space within the system, the public content of which is accessible under a unique domain name. In this case, the domain name is https://lavierestaurant.hu. To operate the website, the data controller uses the services of a hosting provider.
The hosting provider acting as a data processor:
MORGENS Design Ltd. (8800 Nagykanizsa, Magyar utca 79., Company registration no. 20-09-072782, kapcsolat@morgensdesign.hu), as the operator and maintenance provider of the website and the services associated with it.
The sub-processor engaged by the data processor as hosting provider is:
- Name of hosting provider: Tárhely.Eu Kft.
- Registered office of hosting provider: 1144 Budapest, Ormánság utca 4. X. em. 241. ajtó
- Company registration number of hosting provider: Cg.01-09-909968
- Contact details of hosting provider: iroda@tarhely.eu, iroda@tarhely.hu
You can read about your data subject rightsin Section IX.
II. Cookies used on the website
Anonymous visitor identifiers (cookies) are files or pieces of informationthat are stored on the data subject’s computer or internet-enabled device, smartphone or tablet when the website is visited.
Cookies help the website and certain features function, and they also collect statistical and other information about website visitors (e.g. IP address, time of access, navigation on the website and the referring website) in order to improve usability. Marketing cookies are used to display personalised advertisements. Based on their purpose, we distinguish the following types of cookies:
Cookie type and legal basis
Necessary (essential)
The website cannot function without these cookies, and we therefore do not request your consent for them.
The legal basis for processing is the data controller’s legitimate interest pursuant to Article 6(1)(f) GDPR.
Preferences (settings)
These cookies help us make the website more informative and easier for you to use. Examples include your preferred language or the region in which you are located.
The legal basis for processing is the data subject’s freely given consent pursuant to Article 6(1)(a) GDPR.
Analytics (statistics)
By collecting and reporting information anonymously, analytics cookies help us understand how visitors interact with the website.
The legal basis for processing is the data subject’s freely given consent pursuant to Article 6(1)(a) GDPR.
Marketing (advertising)
Marketing cookies are used to track visitors’ activity on the website. Their purpose is to display relevant advertisements to individual users.
The legal basis for processing is the data subject’s freely given consent pursuant to Article 6(1)(a) GDPR.
The website allows you to accept or reject preference (settings), analytics (statistics) and marketing (advertising) cookies separately by purpose. Necessary cookies, however, are always active.
Please note that certain cookies may transfer personal data to a so-called third country (e.g. the USA). Third countries are countries outside the European Economic Area. If you do not wish this to happen, do not allow these cookies to be installed when you visit the website. Where data are transferred to a third country, the Data Controller must ensure an equivalent level of protection for the personal data of data subjects.
The following providers participate in the EU–US Data Privacy Framework, and the adequacy of the transfer is therefore ensured:
Google LLC
Alfonso Lugo Chief Compliance Officer
Google LLC 1600 Amphitheatre Pkwy
Mountain View, CA 94043, E-mail: dpf-core-team@google.com, Phone: +1 650 253 0000
Meta Platforms, Inc
Michel Protti, Chief Privacy Officer, Product Meta Platforms, Inc.
1 Meta Way Menlo Park, California 94025-1453
E-mail: dpfinquiry@support.facebook.com, Phone: (650) 543-4800
Microsoft Corporation
Brian Quirk Data Protection Officer
Microsoft Corporation
1 Microsoft Way Redmond, Washington 98052-8300
E-mail: dpoffice@microsoft.com, Phone: +353 1 706 3117
For cookie settings, Cookiebot is used as a service. The provider’s details are as follows:
Usercentrics A/S
Havnegade 39, 1058 Copenhagen, Denmark
Phone: + 45 50 333 777, E-mail: mail@usercentrics.com
Company registration number DK34624607
The provider’s privacy policy is available here: (https://www.cookiebot.com/en/privacy-policy/?utm_source=google&utm_medium=cpc&utm_term=cookiebot&utm_campaign=cb_dm_hu_eng_brand-phrase_search&utm_content=hu-eng-brand&campaign_id=22126487411&adset_id=179123687691&ad_id=729064133884&matchtype=p&utm_device=c&gclid=Cj0KCQjwj8jDBhD1ARIsACRV2TvthHfNU5mycjEGg9TSWM8nDtFEfBKBgV_fcct7pTHEMTraaI5rrygaAoT5EALw_wcB)
For cookie settings, Stape, Inc. (8 The Green, Suite # 12892 Dover, DE 19901, USA) is also used as a service. The provider is a so-called third-country service provider. Its privacy policy is available at https://stape.io/gdpr and it can be contacted at privacy@stape.io.
Finally, please note that when other content embedded on our website (e.g. a YouTube video) is loaded, the provider making that content available (Google Inc.) may place its own cookie on your device, over which we have no control.
When visiting our website, please read our Cookie Privacy Notice and decide on that basis whether to accept or reject cookies. We reiterate that you may delete cookies from your devices (laptop, desktop computer or phone) at any time.
You can read about your data subject rightsin Section IX.
III. Contacting us
You can contact our restaurant in two ways: via the lavie@leprimore.hu email address or through the contact tab. The related data processing activities are described below:
I. Contact via the lavie@leprimore.hu email address
You may also contact La Vie restaurant by email. Below, we describe how personal data contained in general enquiries are processed.
If you would like to request a quotation for a restaurant function or other event, please read the description of the related data processing in Section VI.
If your message is a general enquiry, data are processed as follows:
Purpose of processing: To provide information in response to the enquiry.
Legal basis for processing: The legal basis for processing is consent pursuant to Article 6(1)(a) GDPR.
If special-category data (e.g. a food allergy) are provided, processing requires the data subject’s consent .
You may withdraw your consent at any time without giving reasons; in that case, the enquiry will be deleted.
Legitimate interest pursued:
Processing is not based on a legitimate interest.
Categories of data subjects (i.e. the person to whom the personal data relate):
Persons who contact the Data Controller using the contact details above.
Categories of personal data processed:
The enquirer’s email address, name provided, date and time and content of the enquiry, and the response given.
Source of the personal data:
The data are provided by the data subject.
Duration of processing:
Typically 6 months.
Recipients (persons to whom data are disclosed):
The Data Controller uses Microsoft Corporation (WA 98052, Redmond, 1. Microsoft Way., Data protection officer: Brian Quirk: dpoffice@microsoft.com) as the provider of its email system.
Transfer to a third country:
The company Microsoft Corporation is a so-called third-country service provider. However, it participates in the EU–US Data Privacy Framework, and the transfer can therefore be regarded as providing adequate protection.
Automated decision-making/profiling:
None.
Is the provision of data mandatory?
No.
What are the consequences if the data subject does not provide their personal data?
The Data Controller will be unable to provide adequate information.
You can read about your data subject rightsin Section IX.
II. Contact via the contact tab
You may also contact us through the contact tab by providing certain personal data. A summary of the details is provided below.
Purpose of processing
To provide information in response to the enquiry.
Legal basis for processing:
The legal basis for processing is consent pursuant to Article 6(1)(a) GDPR.
If special-category data (e.g. a food allergy) are provided, processing requires the data subject’s consent .
You may withdraw your consent at any time without giving reasons; in that case, the enquiry will be deleted.
Legitimate interest pursued:
Processing is not based on a legitimate interest.
Categories of data subjects (i.e. the person to whom the personal data relate):
Persons who contact the Data Controller using the contact details above.
Categories of personal data processed:
The enquirer’s name, email address, telephone number and message.
Source of the personal data:
The data are provided by the data subject.
Duration of processing:
Typically 6 months.
Recipients (persons to whom data are disclosed):
For email:
The Data Controller uses Microsoft Corporation (WA 98052, Redmond, 1. Microsoft Way., Data protection officer: Brian Quirk: dpoffice@microsoft.com) as the provider of its email system.
For the contact tab:
Where contact is made through the message tab, MORGENS Design Ltd. (8800 Nagykanizsa, Magyar utca 79., Company registration no. 20-09-072782, kapcsolat@morgensdesign.hu), acting as a data processor, is the operator.
Transfer to a third country:
The company Microsoft Corporation is a so-called third-country service provider. However, it participates in the EU–US Data Privacy Framework, and the transfer can therefore be regarded as providing adequate protection.
Automated decision-making/profiling:
None.
Is the provision of data mandatory?
No.
What are the consequences if the data subject does not provide their personal data?
The Data Controller will be unable to provide adequate information.
You can read about your data subject rightsin Section IX.
IV. Online table reservations
You can reserve a table at our La Vie gourmet restaurant through our website using the ReservOurs restaurant reservation service. The service also offers a guest review feature and the option to subscribe to the newsletter. Personal data are processed in connection with these online functions as follows:
Purpose of processing
To enable online restaurant reservations.
Legal basis for processing:
The legal basis for processing is consent pursuant to Article 6(1)(a) GDPR.
If special-category data (e.g. a food allergy) are provided, processing requires the data subject’s consent .
Legitimate interest pursued:
Processing is not based on a legitimate interest.
Categories of data subjects (i.e. the person to whom the personal data relate):
Persons making a restaurant reservation through the online booking interface.
Categories of personal data processed:
Name, contact details (email address, telephone number), date and time, number of guests, comments, occasion, and whether or not the newsletter is requested.
Source of the personal data:
The data are provided by the data subject.
Duration of processing:
Reservation data are processed by the Data Controller until the date of the reservation. If you have also requested the newsletter, the data will be processed until you unsubscribe.
Recipients (persons to whom data are disclosed):
Code Kitchen Kft. (4400 Nyíregyháza, Leffler Sámuel utca 65., Company registration no. 15-09-091192, email: mate.delceg@reservours.com, privacy policy: https://reservours.com/privacy-policy), acting as data controller and operator of the ReservOurs system. Information about the partners involved is available at: https://reservours.com/privacy-policy
Transfer to a third country:
The Data Controller does not transfer data to third countries.
Automated decision-making/profiling:
None.
Is the provision of data mandatory?
Contact details are required to make an online reservation. An email address is required to subscribe to the newsletter.
What are the consequences if the data subject does not provide their personal data?
Without contact details, the online reservation cannot be confirmed and prompt information about any changes cannot be provided. Without the other reservation details, the online reservation cannot be recorded. An email address is required to send the newsletter.
On the restaurant reservation provider’s website, further information about the processing carried out by the restaurant service provider (operator of the ReservOurs system) as data controller is available in the Website Terms of Use and Privacy Policy accessible through the reservation interface. You may also contact the service provider directly.
If you subscribe to our newsletter, please read Section VII of this Privacy Notice.
You can read about your data subject rightsin Section IX.
The provider’s description does not indicate whether data are transferred anywhere, and its role under data protection law is also unclear.
V. Online room reservations
You can also make an online room reservation at the Hotel through the La Vie restaurant website. The Hotel and the restaurant use the same room reservation system. In this case, we process the data necessarily connected with the reservation, as well as data that facilitate contacting and communicating with you. Your personal data are processed as follows:
Purpose of processing
To enable online reservations through the website and to establish a civil-law relationship with the enquirer.
Legal basis for processing:
For natural persons:
The legal basis for processing is performance of a contract pursuant to Article 6(1)(b) GDPR.
For legal persons:
The legal basis for processing is the Data Controller’s legitimate interest pursuant to Article 6(1)(f) GDPR.
For the establishment, exercise and defence of legal claims, the legal basis for processing is the Data Controller’s legitimate interest pursuant to Article 6(1)(f) GDPR. Under Section 6:22 of the Hungarian Civil Code, civil-law claims become time-barred after 5 years. The same legal basis applies to the processing of data relating to the legal representative and contact person of a legal person.
The legal basis for processing the telephone number as contact data is your freely given consentunder Article 6(1)(a) GDPR. You may withdraw your consent at any time without giving reasons.
For personal data required to comply with record-keeping obligations, the legal basis for processing is Article 6(1)(c) GDPR , namely compliance with a legal obligation. The legal obligation is based on Sections 159 and 169 of Act CXXVII of 2007 on Value Added Tax and Sections 166–169 of Act C of 2000 on Accounting.
Legitimate interest pursued:
Establishing and maintaining contact with the legal person, exercising rights and performing obligations arising from the contractual relationship, and establishing, exercising and defending legal claims during the limitation period.
Categories of data subjects (i.e. the person to whom the personal data relate):
Persons making an online reservation.
Categories of personal data processed:
Reservation details:
-stay period, number of guests, number of rooms, promotional code, room offer, additional requests: pet, bouquet of flowers, fruit, massage, early arrival and late departure.
Contact details:
-name, email address, telephone number and message.
Billing details:
-name and address of a natural person, name and contact details of a company contact person (other details of the legal person are not personal data)
Payment details:
-whether payment is made by bank transfer or bank card; for a card guarantee, card number, expiry date and cardholder’s name
Source of the personal data:
The data are provided by the data subject.
Duration of processing:
Until the last day of the eighth year following provision of the service, in accordance with the record-keeping obligation.
Recipients (persons to whom data are disclosed):
MORGENS Design Ltd. (8800 Nagykanizsa, Magyar utca 79., Company registration no. 20-09-072782, kapcsolat@morgensdesign.hu), acting as a data processor and operator of the online reservation system. The data processor integrates the RoomSome booking engine.
Rocket Science Group (675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, privacy@rocketscience.gg), acting as a data processor, is responsible for sending the confirmation emailand for the guest review feature. Its privacy documentation is available at: https://www.rocketscience.gg/privacy/
The online payment function on the website is available through the Simple Pay application. The application is provided by OTP Mobil Kft. (1138 Budapest, Váci út 135-139, Building B, 5th floor, Company registration no. 01-09-174466), acting as data controller. Its Privacy Notice is available here:
https://simplepay.hu/wp-content/uploads/2025/03/OTPM_kereskedoi_kapcsolattartoi_adatkezeles_hun_20250316.pdf
For online payments, the Data Controller processes only the date and time, amount and identifier of the payment.
PayPal (Europe) S.á.r.l. et Cie, S.C.A. (22-24 Boulevard Royal, 2449 Luxembourg, enquiry@paypal.com), acting in relation to payments made through the PayPal system as a payment service providerand data controller. Its Privacy Notice is available at: https://www.paypal.com/myaccount/privacy/privacyhub
Barion Payment Zrt. (1117 Budapest, Irinyi József u. 4-20, 2nd floor, Company registration no. 01-10-048552, hello@barion.hu), a payment service providerinvolved in executing online payment transactions, acting as data controller. Its Privacy Notice is available at: https://www.barion.com/hu/adatvedelmi-tajekoztato/
SZÉP Card payments involve: MHB Bank Nyrt. (1056 Budapest, Váci utca 38., Company registration no. 01-10-040952), OTP Pénztárszolgáltató Zrt. (1138 Budapest, Váci út 135-139, Building A, 3rd floor, Company registration no. 01-10-045076), and K & H Bank Zrt. (1095 Budapest, Lechner Ödön fasor 9., Company registration no. 01-10-041043), acting as payment service providers operating the SZÉP Card online payment systemand as data controllers.
BIG FISH Kft. (1066 Budapest, Nyugati tér 1-2., Company registration no. 01-09-872150, cafe@bigfish.hu), a data processor used in connection with online payment transactions to confirm the transaction status. Its Privacy Notice is available at: https://bigfish.hu/adatvedelmi-tajekoztato.
Global Payments Europe s.r.o. (GPE) (V Olšinách 626/80, Strašnice, 100 00 Prague 10, Czech Republic, privacy@globalpay.com), a payment service provideroperating an online payment system, acting as data controller. Its Privacy Notice is available at: https://www.globalpayments.com/hu-hu/adatkezelesi-tajekoztato?_gl=1*14a42ri*_up*MQ..*_gs*MQ..&gclid=CjwKCAjw9uPCBhATEiwABHN9KwLd7ZtyVFyMAn6IIqK4exKZqKVQpHtQRMJVdY8bXkdCtf2p4BBLthoCmpgQAvD_BwE&gbraid=0AAAAAqujR1VwICoNyKqw7nbsyz6AsQATK
Worldline Financial Services (Europe) Ltd. (1034 Budapest, Tímár u. 20.) is a payment service provider operating an online payment system and acting as data controller. Its Privacy Notice is available at: https://worldline.com/hu-hu/compliancy/privacy
Stripe Payments Europe Limited (SPEL) (1 Grand Canal Street Lower, Grand Canal Dock, D02 H210 Dublin, Ireland), a payment service provider acting as data controller. Its Privacy Notice is available here:
https://stripe.com/au/privacy
Transfer to a third country:
Technology providers often engage partners located in so-called third countries. Please make sure you read their privacy notices.
Rocket Science Group (675 Ponce de Leon Ave NE, Suite 5000, Atlanta, GA 30308, privacy@rocketscience.gg), acting as a data processor, is responsible for sending confirmation emails and for the guest review feature. Its privacy documentation is available at: https://www.rocketscience.gg/privacy
The Stripe Payments Europe Limited (SPEL) may transfer personal data to third countries, including the United States or India. The provider participates in the EU–US Data Privacy Framework. Its US contact details are: Legal Office of the DPO, Office of the DPO, Stripe, Inc.
354 Oyster Point Blvd
South San Francisco, CA 94080
Email: dataprotection@stripe.com
Phone: +1 415 223 0377
BIG FISH Kft. (1066 Budapest, Nyugati tér 1-2., Company registration no. 01-09-872150, cafe@bigfish.hu), a data processor used in connection with online payment transactions to confirm the transaction status. Its Privacy Notice is available at: https://bigfish.hu/adatvedelmi-tajekoztato.
Automated decision-making/profiling:
None.
Is the provision of data mandatory?
Providing a telephone number as contact data is voluntary. The remaining personal data are required to complete the reservation.
What are the consequences if the data subject does not provide their personal data?
The online reservation cannot be completed.
Please note that when checking in on site, you will also be required to provide additional data in order to comply with a legal obligation pursuant to Article 6(1)(c) GDPR, based on Act CLVI of 2016 on the State Responsibilities for the Development of Tourism Areas. To protect the rights, security and property of the data subject and others, and to verify compliance with the provisions governing the stay of third-country nationals and persons enjoying the right of free movement and residence, the accommodation provider records, at check-in and through its accommodation management software, the following data in the storage space provided by the hosting provider designated by Government Decree: the guest’s surname and given name, surname and given name at birth, place and date of birth, sex, nationality, mother’s surname and given name at birth, the identification details of the guest’s identity document or travel document, and, for third-country nationals, the number of the visa or residence permit and the date and place of entry, as well as the address of the accommodation and the start date, expected end date and actual end date of the stay. The guest must present the document to the accommodation provider so that the data can be recorded. If the document is not presented, the accommodation provider will refuse to provide the accommodation service.
You can read about your data subject rightsin Section IX.
I cannot yet see this as available on the restaurant website.
VI. Requests for quotation
You may also submit a request for quotation via the restaurant’s email address. In such cases, we use the contact details provided by the person requesting the quotation to contact them. The requesting party may be a natural person or a legal person, and personal data are processed accordingly.
Personal data are processed as follows:
Purpose of processing
To provide a quotation to the interested person.
Legal basis for processing:
For natural persons:
The legal basis for processing is performance of a contract pursuant to Article 6(1)(b) GDPR. Under the GDPR, a request for quotation may be processed on the legal basis of taking steps at the request of the data subject prior to entering into a contract.
For legal persons:
The legal basis for processing is the Data Controller’s legitimate interest pursuant to Article 6(1)(f) GDPR.
The legal basis for processing the telephone number as contact data is your freely given consentunder Article 6(1)(a) GDPR. You may withdraw your consent at any time without giving reasons.
If special-category data (e.g. a food allergy) are provided, processing requires the data subject’s consent .
Legitimate interest pursued:
Establishing and maintaining contact with the legal person.
Categories of data subjects (i.e. the person to whom the personal data relate):
Persons requesting an online quotation.
Categories of personal data processed:
The requesting party’s name, email and/or telephone contact details, and the personal data required to prepare the quotation.
Source of the personal data:
The data are provided by the data subject.
Duration of processing:
Until expiry of the period for which the quotation is binding.
Recipients (persons to whom data are disclosed):
The Data Controller uses Microsoft Corporation (WA 98052, Redmond, 1. Microsoft Way., Data protection officer: Brian Quirk: dpoffice@microsoft.com) as the provider of its email system.
Transfer to a third country:
The company Microsoft Corporation is a so-called third-country service provider. However, it participates in the EU–US Data Privacy Framework, and the transfer can therefore be regarded as providing adequate protection.
Automated decision-making/profiling:
None.
Is the provision of data mandatory?
Providing a telephone number as contact data is voluntary. The remaining personal data are required to fulfil the request for quotation.
What are the consequences if the data subject does not provide their personal data?
The request for quotation may not be fulfilled.
You can read about your data subject rightsin Section IX.
VII. Newsletters
You can subscribe to our newsletter through our website to receive valuable and interesting offers and programme recommendations. We send newsletters only to persons who have expressly requested them, i.e. who have given prior consent. Please note that you may withdraw your consent to receive newsletters at any time without giving reasons. The easiest way to do so is to click the unsubscribe link in the email. You may also contact us by email at sales@leprimore.hu. In that case, we will no longer send you newsletters.
Your personal data are processed as follows:
Purpose of processing
Direct marketing and informing data subjects who have expressly requested it about our services, promotions and programmes.
Legal basis for processing:
The legal basis for processing is consent pursuant to Article 6(1)(a) GDPR.
You may withdraw your consent at any time without giving reasons.
Legitimate interest pursued:
Processing is not based on a legitimate interest.
Categories of data subjects (i.e. the person to whom the personal data relate):
Persons who subscribe to the newsletter.
Categories of personal data processed:
The subscriber’s name, email address and delivery status.
Source of the personal data:
The data are provided by the data subject.
Duration of processing:
Until consent is withdrawn, which can be done most easily by clicking the unsubscribe link in the newsletter.
However, if there is no activity, the personal data will be deleted after one year.
Recipients (persons to whom data are disclosed):
Online Marketing Stratégia Kft. (1039 Budapest, Pünkösdfürdő u. 52-54., Company registration no. 01-09-276442), acting as a data processor, engages Optimonk International Zrt. (4028 Debrecen, Kassai u. 129., Company registration no. 09-10-000583, Privacy Notice: https://optimonk.hu/adatvedelmi-nyilatkozat/) as a sub-processor and uses the ActiveCampaign software (ActiveCampaign LLC, contact: EU-REP.Global GmbH, Attn: ActiveCampaign, Hopfenstr. 1d, 24114 Kiel, Germany, or activecampaign@eu-rep.globalprivacy@activecampaign.com, Privacy Notice: https://www.activecampaign.com/legal/terms-of-service.)
Transfer to a third country:
Optimonk International Zrt. may transfer data to third countries in connection with its data processing services.
Automated decision-making/profiling:
None.
Is the provision of data mandatory?
No.
What are the consequences if the data subject does not provide their personal data?
The data subject will not receive the newsletter.
You can read about your data subject rightsin Section IX.
VIII. Social media presence
Our restaurant is also present on Instagram and Facebook. Both platforms belong to Meta Platforms Inc., a company registered in the United States. These providers are so-called third-country service providers and participate in the Data Privacy Framework between the European Union and the United States. Their privacy notices are available on the respective websites.
On these platforms, you may like, comment on and share our content in accordance with the social media provider’s own rules.
The details of Meta Platforms Inc. are as follows:
Meta Platforms, Inc
Michel Protti, Chief Privacy Officer, Product Meta Platforms, Inc.
1 Meta Way Menlo Park, California 94025-1453
E-mail: dpfinquiry@support.facebook.com, Phone: (650) 543-4800
IX. Data subject rights
Below, we explain the rights available to a data subject whose personal data are processed by the Data Controller:
Rights of data subjects in connection with processing: the right to be informed whether processing is taking place; the right of access to the information above concerning processing; the right to obtain a copy of the personal data processed; the right to data portability (where processing is based on performance of a contract or consent); the right to request rectification or erasure of personal data relating to the data subject, or restriction of their processing; the right to object to processing of personal data (where processing is based on legitimate interest); the right to lodge a complaint with the supervisory authority (Hungarian National Authority for Data Protection and Freedom of Information: postal address: 1055 Budapest, Falk Miksa u. 9-11.; 1363 Budapest, P.O. Box 9; telephone: +36 (30) 683-5969, +36 (30) 549 6838; email: ugyfelszolgalat@naih.hu, website: www.naih.hu); and the right to seek a judicial remedy.
Explanation of the data subject rights listed above:
Right to information:
You may request information from the Data Controller about the processing of your personal data.
The Data Controller must provide all information concerning the processing of personal data in a concise, transparent, intelligible and easily accessible form, using clear and plain language.
The Data Controller shall provide the information in writing without undue delay and in any event within one month of receipt of the request. At the data subject’s request, the information may also be provided orally, provided that the identity of the data subject has first been proven by other means.
Where requests are complex or numerous, the one-month period may be extended by a further two months. The Data Controller shall inform the data subject of any such extension within one month of receipt of the request, together with the reasons for the delay. Where the data subject makes the request electronically, the information shall be provided electronically where possible, unless otherwise requested by the data subject.
If the Data Controller does not take action on the data subject’s request, it shall inform the data subject without delay and at the latest within one month of receipt of the request of the reasons for not taking action and of the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.
Right of access to personal data and information concerning processing:
The data subject has the right to obtain confirmation from the Data Controller as to whether or not personal data concerning them are being processed and, where that is the case, access to the personal data and the following information:
- a) the purposes of the processing;
- b) the categories of personal data concerned;
- c) the recipients or categories of recipient to whom the personal data have been or will be disclosed;
- d) the envisaged period for which the personal data will be stored, or the criteria used to determine that period;
- e) information that the data subject may request rectification or erasure of personal data or restriction of processing of personal data concerning them, or object to such processing;
- f) the right to lodge a complaint with the supervisory authority (NAIH);
- g) where the personal data are not collected from the data subject, any available information as to their source;
- h) whether automated decision-making, including profiling, is carried out by the Data Controller and, if so, in which areas, meaningful information about the logic involved, and the significance and envisaged consequences of such processing for the data subject.
The Data Controller again informs the data subject that personal data are not transferred to any third country or international organisation in any form.
Right to obtain a copy:
At the data subject’s request, the Data Controller shall provide a copy of the personal data undergoing processing. For any further copies requested by the data subject, the Data Controller may charge a reasonable fee based on administrative costs. Where the data subject makes the request electronically, the information shall be provided in a commonly used electronic format, unless otherwise requested by the data subject.
The right to obtain a copy must not adversely affect the rights and freedoms of others.
Right to data portability:
The data subject has the right to receive the personal data concerning them, which they have provided to the Data Controller, in a structured, commonly used and machine-readable format, and has the right to transmit those data to another controller without hindrance from the Data Controller, where the processing is based on the data subject’s consent or explicit consent, or on performance of a contract, and the processing is carried out by automated means.
Where the above conditions are met, the data subject also has the right, where technically feasible, to have the personal data transmitted directly from one controller to another.
The right to data portability must not adversely affect the rights and freedoms of others.
Right to rectification:
The data subject has the right to obtain from the Data Controller without undue delay the rectification of inaccurate personal data concerning them and to have incomplete personal data completed, including by means of providing a supplementary statement.
Right to erasure:
The data subject has the right to obtain from the Data Controller the erasure of personal data concerning them without undue delay, and the Data Controller is obliged to erase such personal data without undue delay where one of the following grounds applies:
- a) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
- b) the data subject withdraws the consent (or explicit consent) on which the processing is based, and there is no other legal ground for the processing;
- c) the data subject objects to processing based on public interest or legitimate interests and there are no overriding legitimate grounds for the processing, or the data subject objects to processing for direct marketing purposes;
- d) the personal data have been unlawfully processed;
- e) the personal data must be erased for compliance with a legal obligation in Union or Member State law to which the Data Controller is subject.
Where the Data Controller has made the personal data public and is obliged to erase them, it shall, taking account of available technology and the cost of implementation, take reasonable steps, including technical measures, to inform other controllers processing the personal data that the data subject has requested the erasure of any links to, or copies or replications of, those personal data.
Erasure cannot be requested where processing is necessary:
- a) for exercising the right of freedom of expression and information;
- b) for compliance with a legal obligation requiring processing under Union or Member State law to which the Data Controller is subject, or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the Data Controller;
- c) for reasons of public interest in the area of public health;
- d) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, where the right to erasure is likely to render impossible or seriously impair the achievement of the objectives of that processing; or
- e) for the establishment, exercise or defence of legal claims.
Right to restriction of processing:
The data subject has the right to obtain restriction of processing from the Data Controller where one of the following applies:
- a) the accuracy of the personal data is contested by the data subject, for a period enabling the Data Controller to verify the accuracy of the personal data;
- b) the processing is unlawful and the data subject opposes erasure of the personal data and requests restriction of their use instead;
- c) the Data Controller no longer needs the personal data for the purposes of processing, but they are required by the data subject for the establishment, exercise or defence of legal claims; or
- d) the data subject has objected to processing, pending verification of whether the objection is lawful and well-founded.
Where processing has been restricted, such personal data shall, with the exception of storage, be processed only with the data subject’s consent, or for the establishment, exercise or defence of legal claims, for the protection of the rights of another natural or legal person, or for reasons of important public interest of the Union or a Member State.
The Data Controller shall inform the data subject before the restriction of processing is lifted.
Right to object to processing:
The data subject has the right to object, on grounds relating to their particular situation, at any time to the processing of personal data concerning them based on legitimate interests or on the performance of a task carried out in the public interest/exercise of official authority . Where the data subject objects to processing of personal data for direct marketing purposes, the personal data shall no longer be processed for such purposes.
In other cases, the Data Controller shall no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or grounds relating to the establishment, exercise or defence of legal claims.
Right to lodge a complaint:
If any of the rights listed above are infringed, the data subject has the right to lodge a complaint with the supervisory authority.
The supervisory authority is the Hungarian National Authority for Data Protection and Freedom of Information (postal address: 1055 Budapest, Falk Miksa u. 9-11.; 1363 Budapest, P.O. Box 9; telephone: +36 (30) 683-5969, +36 (30) 549 6838; email: ugyfelszolgalat@naih.hu, website: www.naih.hu), with which you may lodge a complaint or request an investigation on the grounds that you have suffered, or are at imminent risk of suffering, an infringement in connection with the processing of your personal data or that your rights have been violated.
We also inform you that, if you have suffered or are at imminent risk of suffering an infringement in connection with the processing of your personal data, or if your rights have been violated, you may bring proceedings directly before a court.
You may also submit your comments, questions or complaint to the Data Protection Officer.
X. Legislation, definitions and principles
Key applicable legislation:
The principal legislation governing the processing of personal data and defining the fundamental rights and obligations of the parties is listed below.
-Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation: GDPR)
The following may assist in interpreting the rules:
-Opinions and guidelines of the European Data Protection Board (https://edpb.europa.eu)
-Guidelines of the European Data Protection Supervisor (https://edps.europe.eu)
-Opinions, guidance and individual decisions of the Hungarian National Authority for Data Protection and Freedom of Information (NAIH, supervisory authority) (www.naih.hu)
-Decisions of the Court of Justice of the European Union in Luxembourg (https://curia.europe.eu)
-Decisions of Member State supervisory authorities
Applicable legislation is available free of charge in the Hungarian National Legislation Database (https://www.njt.hu), and through the European Commission’s website (https://eur-lex.europa.eu/legal-content/HU/TXT/HTML/?uri=CELEX:32016R0679&from=HU)
Definitions
The purpose of the definitions is to explain who is subject to the rules and precisely what is meant by the individual terms used in the regulatory framework. The most important definitions are set out below:
“Personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“Data concerning health” means personal data related to the physical or mental health of a natural person, including the provision of healthcare services, which reveal information about their health status.
“Genetic data” means personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or health of that natural person and which result, in particular, from an analysis of a biological sample from that natural person.
“Biometric data” means personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, which allow or confirm the unique identification of that natural person, such as facial images or dactyloscopic data;
“Sensitive data”: a category of personal data developed in data protection practice and case law, the processing of which entails an increased risk, but which does not qualify as either special-category or criminal-offence data. Examples include bank card data, data concerning children, location data, interests, data capable of damaging a person’s reputation, and large combinations of data.
“Processing” means any operation or set of operationsperformed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
“Restriction of processing” means the marking of stored personal data with the aim of limiting their processing in the future.
“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law. In this case, the Event Horizon Capital Zrt. is the Controller.
“Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
“Recipient”: a natural or legal person, public authority, agency or another body to which the personal data are disclosed, whether or not a third party.
“Third party” means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
“Profiling” means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
“Pseudonymisation” means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data are not attributed to an identified or identifiable natural person.
“Filing system” means any structured set of personal data which is accessible according to specific criteria, whether centralised, decentralised or dispersed on a functional or geographical basis.
“Consent of the data subject” means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
“Personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
“Enterprise” means a natural or legal person engaged in an economic activity, irrespective of its legal form, including partnerships or associations regularly engaged in an economic activity.
“Supervisory authority” means an independent public authority established by a Member State pursuant to Article 51. In this case, the supervisory authority is the Hungarian National Authority for Data Protection and Freedom of Information (1363 Budapest, P.O. Box 9, ugyfelszolgalat@naih.hu).
Principles relating to processing of personal data
Personal data must be processed in accordance with the following principles, and the Data Controller processes them accordingly:
- a) processed lawfully, fairly and in a transparent manner in relation to the data subject (“lawfulness, fairness and transparency”);
- b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes (“purpose limitation”);
- c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (“data minimisation”);
- d) accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (“accuracy”);
- e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as they will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1), subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (“storage limitation”);
- f) processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (“integrity and confidentiality”).
The Data Controller is responsible for, and must be able to demonstrate compliance with, the provisions above (“accountability”).
Date of the last amendment to this Privacy Notice:
1 June 2026.


