Skip to content
neti neti

Privacy Policy

Effective from 3 August 2026

1. Introduction

neti neti Karikavölgy Kft. considers the protection of personal data important and therefore processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (the General Data Protection Regulation, "GDPR"), Hungarian Act CXII of 2011 on informational self-determination and freedom of information ("Info Act"), and other applicable Hungarian and European Union legislation.

This notice describes the processing activities related to the use of the netineti.hu website, requests for quotations for accommodation services, bookings, payment, check-in, stays, communication, complaint handling and marketing communication.

This notice covers the processing carried out by neti neti Karikavölgy Kft.. Processing carried out by third-party providers such as SimplePay, Booking.com, Airbnb or other intermediary platforms for their own purposes is also governed by the respective provider's own privacy notice.

2. Details of the controller

Name of the controller: neti neti Karikavölgy Kft.
Registered office: 8795 Zalaszentgrót, hrsz. 5277.
Company registration number: 20-09-079581
Tax number: 32762561-2-20
Email: info@netineti.hu
Website: https://www.netineti.hu

The company has not appointed a data protection officer, as it is not required to do so based on its processing activities. Data protection questions and data subject requests may be submitted at info@netineti.hu.

3. Key definitions

  • Data subject: an identified or identifiable natural person, in particular a website visitor, a person requesting a quotation, a person placing a booking, a payer, a Guest, a contact person or a newsletter subscriber.
  • Contracting party: the natural person, legal person or other organisation that places the booking and concludes a contract with the Provider. In the case of a legal person, this notice applies to its natural person representative or contact person.
  • Guest: the natural person who actually uses the accommodation. The Contracting party and the Guest are not necessarily the same person.
  • Personal data: any information relating to a data subject.
  • Processing: any operation performed on personal data, in particular collection, recording, organisation, storage, use, transfer, restriction or erasure.
  • Processor: a natural or legal person who processes personal data on behalf of and on the instructions of the controller.
  • Recipient: the person or organisation to whom personal data is disclosed.
  • Third country: a country outside the European Economic Area.

4. Principles of processing

The Controller processes personal data:

  • lawfully, fairly and in a transparent manner;
  • for specified, explicit and legitimate purposes;
  • to the extent necessary for the purpose of the processing;
  • accurately and, where necessary, kept up to date;
  • only for as long as necessary;
  • with appropriate technical and organisational protection.

The Controller does not request personal data that is not necessary for the given administration, service or compliance with a legal obligation.

5. Bookings and management of the accommodation contract

5.1. Purpose of the processing

The purposes of the processing are:

  • responding to requests for quotations;
  • recording and confirming the booking;
  • managing the availability of the accommodation and the dates;
  • concluding and performing the service contract;
  • identifying the Contracting party and the Guests;
  • communication related to the booking;
  • modification or cancellation of the booking;
  • handling of the service fee, penalties or refunds;
  • appropriate preparation of the accommodation;
  • managing claims and legal claims arising from the contract.

5.2. Categories of data processed

Depending on the booking channel and the nature of the service:

  • surname and given name;
  • email address;
  • phone number;
  • residential or billing address;
  • country;
  • company name, registered office and tax number, if the invoice is issued to a business;
  • date of arrival and departure;
  • selected accommodation or House;
  • number of Guests and, where relevant for the booking, their age group;
  • requested additional services;
  • information on pets, early arrival, late departure or other service requests;
  • booking identifier;
  • payment method and payment status;
  • correspondence and other communications related to the booking;
  • data relating to the performance, modification, cancellation or termination of the contract.

As a general rule, the Controller does not request health data. If the data subject, on their own initiative, provides information regarding allergies, health condition, accessibility needs or other special circumstances, the Controller processes such data solely for the purpose of handling the request and safely providing the service, to the extent strictly necessary.

5.3. Legal basis of the processing

  • for quotation requests and bookings, Article 6(1)(b) GDPR: steps taken at the request of the data subject prior to entering into a contract, and performance of the contract;
  • for the representative or contact person of a legal person Contracting party, Article 6(1)(f) GDPR: the legitimate interest in business communication between the Controller and the contractual partner;
  • for data required by law, Article 6(1)(c) GDPR;
  • for special category data provided voluntarily, where its processing is necessary, explicit consent under Article 9(2)(a) GDPR.

5.4. Source of the data

The data may originate from:

  • the data subject directly;
  • the Contracting party placing the booking;
  • the Previo booking system;
  • the system of Booking.com, Airbnb or another intermediary platform;
  • an email or other message sent by the data subject.

If the Contracting party also provides the data of other Guests, they must ensure that the disclosure is lawful and that the Guests concerned have the opportunity to access this notice.

5.5. Consequences of not providing data

Without the data marked as mandatory, a quotation cannot be prepared, the booking cannot be finalised and the service contract cannot be performed.

5.6. Retention period

A quotation request that does not result in a contract is retained by the Controller for a maximum of one year following the expiry of the offer or the closure of the matter, unless a legal claim is expected.

Data relating to a concluded contract and its performance is, as a general rule, processed for five years from the performance or termination of the contract, in line with the limitation period for civil law claims.

Data included in accounting documents is retained for the period set out in Section 9.

6. Previo booking system and property management

The booking engine of the Website and the property management solution used to handle bookings are provided by Previo.

Provider: Previo, s.r.o.
Registered office: Kubánské náměstí 1391/11, 100 00 Prague 10, Czech Republic.

Previo may act as the Controller's processor when providing the booking and property management service. Its system may process data necessary for bookings, communication, payment status, guest management and the administration of the accommodation service.

The purpose of the processing is to operate the booking interface, record and manage bookings, communicate with Guests, technically support the payment process and carry out property management tasks.

The legal basis is Article 6(1)(b) GDPR for the booking and the service contract, and Article 6(1)(c) GDPR for statutory data reporting.

Processing carried out by Previo for its own purposes, such as service security, legal compliance or the operation of its own website, is governed by Previo's own privacy notice.

7. Alfred application, online check-in and self check-in

neti neti operates with self check-in. Prior to the Guest's arrival, the Controller may use an online check-in interface, the Alfred application connected to the Previo system, or another technical solution.

7.1. Purpose of the processing

  • registration of the Guest before arrival;
  • linking the booking and the Guest;
  • recording guest data required by law;
  • carrying out the check-in process;
  • verifying the Guest's identity;
  • sending access information and the key safe code;
  • preparing and fulfilling VIZA and NTAK data reporting;
  • communication regarding arrival and the stay.

7.2. Categories of data processed

In addition to booking data, the following may be processed:

  • the Guest's birth details;
  • nationality;
  • gender;
  • mother's birth name;
  • type and identification data of the identity or travel document;
  • for third-country nationals, further residence data required by law;
  • arrival information;
  • the status of online check-in;
  • data confirming that identity verification has taken place;
  • the access information sent by the Controller and its delivery data.

Images or copies of identity documents may not be retained for general guest record purposes. The purpose of document scanning is to read and record the prescribed data, not to permanently store the image of the document.

7.3. Legal basis

  • Article 6(1)(b) GDPR for the provision of the accommodation service;
  • Article 6(1)(c) GDPR for the mandatory recording and transfer of guest data.

7.4. Consequences of not providing data

Presenting the identity document required by law and recording the prescribed data are conditions for using the accommodation service. If the document is not presented or the mandatory data is not recorded, the Controller is obliged to refuse to provide the accommodation service.

8. Mandatory guest data processing, VIZA and NTAK

8.1. Purpose of VIZA processing

Under the applicable tourism legislation, the Controller is obliged to record certain personal data of Guests using the accommodation service and to transfer it, via the property management software, to the VIZA storage space operated by the hosting provider designated by the Government.

The purposes of the processing are in particular:

  • protecting the rights, safety and property of the data subject and other persons;
  • supporting crime prevention and law enforcement purposes;
  • protecting public order, public security and national security;
  • verifying compliance with the rules on the stay of third-country nationals and persons enjoying the right of free movement and residence;
  • fulfilling the statutory data reporting obligation to the authorities.

8.2. Data recorded in the VIZA system

Based on the applicable legislation:

  • family name and given name;
  • family name and given name at birth;
  • place and date of birth;
  • gender;
  • nationality;
  • mother's family name and given name at birth;
  • identification data of the identity document or travel document;
  • for third-country nationals, the visa or residence permit data and entry data specified by law;
  • the address of the accommodation service;
  • the start date, expected end date and actual end date of the stay.

Data not contained in the given document does not have to be recorded.

For Guests under 14 years of age, the personal data specified by law may also be recorded on the basis of a declaration by the legal representative. Under the applicable rules, presenting the identity document of a Guest under 14 and recording its document identifier is not mandatory.

8.3. Document scanning

Guests who have reached the age of 14 are obliged to present a document suitable for identification. If the document is not presented, the Controller may not provide the accommodation service.

Data may be recorded through on-site scanning or through remote digital document scanning supported by the property management software. In the case of remote scanning, the Controller must verify the Guest's identity and the accuracy of the previously recorded data.

Neither the document scanner nor the VIZA system may store the image of the scanned document.

8.4. Legal basis

Article 6(1)(c) GDPR, i.e. compliance with a legal obligation to which the Controller is subject, in particular under Hungarian Act CLVI of 2016 on the state tasks of developing tourism regions.

8.5. Recipients and retention period

The mandatory data is transferred by the property management software to the designated VIZA storage space. The hosting provider stores the data in encrypted form and, as a general rule, may not access its content.

Data stored in the VIZA storage space may be accessed by the bodies authorised by law for the purposes set out in legislation.

The accommodation provider processes VIZA data in its property management software until the data reporting obligation is fulfilled. The designated hosting provider erases the data stored in the VIZA storage space after the last day of the first year following the recording of the data.

8.6. NTAK data reporting

The Controller transfers the statistical and turnover data specified by law to the National Tourism Data Supply Centre (NTAK) through the property management software.

General turnover reporting to NTAK does not serve the direct identification of Guests. VIZA processing and NTAK statistical reporting are processing activities with different purposes.

9. Invoicing, accounting and tax obligations

9.1. Purpose of the processing

  • issuing invoices or other accounting documents;
  • recording payments and refunds;
  • fulfilling accounting and tax obligations;
  • providing evidence during official inspections.

9.2. Categories of data processed

  • billing name;
  • billing address;
  • tax number, where required;
  • name, consideration and performance data of the service;
  • payment method and payment status;
  • invoice serial number;
  • other data that must be indicated on the invoice or accounting document.

The Controller does not request guest data for invoicing that is not required by law and is not necessary to issue the invoice.

9.3. Legal basis

Article 6(1)(c) GDPR, in particular on the basis of accounting and taxation legislation.

9.4. Retention period

The Controller retains accounting documents and the underlying data for at least eight years.

9.5. Recipients

The data may be accessed by the invoicing service provider, the bookkeeper, the tax advisor, the auditor and, where the statutory conditions are met, the National Tax and Customs Administration or another competent authority.

10. Online card payment – SimplePay

10.1. The payment process

In the case of online card payment or another supported electronic payment, the payment transaction is handled by the SimplePay system.

SimplePay Zrt.
Registered office: Váci út 135–139. building B, 5th floor, 1138 Budapest, Hungary
Company registration number: 01-10-143303
Tax number: 32835155-2-44.

The Guest enters the payment instrument and card details directly on SimplePay's secure payment interface. The Controller does not learn or store the full card number, the expiry date or the security code.

10.2. Data transferred by the Controller

Depending on the actual technical configuration and the selected payment method, the following may be transferred to SimplePay:

  • surname and given name;
  • country;
  • email address;
  • phone number;
  • billing address;
  • booking or order identifier;
  • amount payable and currency;
  • technical data necessary to carry out the transaction.

10.3. Purpose of the data transfer

  • initiating and carrying out the payment transaction;
  • confirming the outcome of the transaction;
  • handling refunds;
  • providing payment-related customer support;
  • preventing fraud, abuse and unauthorised payments;
  • handling chargebacks and other payment disputes;
  • fulfilling financial and legal obligations.

10.4. Legal basis and controller roles

The legal basis for the data transfer carried out by the Controller in order to initiate the payment is Article 6(1)(b) GDPR, i.e. performance of the service contract.

Depending on the nature of the given processing operation, SimplePay may act as a processor, as an independent controller, or as a joint controller in respect of the processing activities set out in SimplePay's documents in force from time to time.

SimplePay's own privacy notices govern its own legal obligations and its payment service, fraud prevention, security and law enforcement purposes.

10.5. SimplePay data transfer statement

The payer acknowledges that the personal data necessary to carry out the payment, stored by neti neti Karikavölgy Kft. (8795 Zalaszentgrót, hrsz. 5277.) as controller in the user database of the https://www.netineti.hu website and the Previo booking system, will be transferred to SimplePay Zrt.

The scope of the transferred data: name, country, email address, phone number, billing address, booking or order identifier, amount payable and currency, and the technical data necessary to carry out the payment.

Detailed information on the nature and purpose of the processing carried out by SimplePay is available in SimplePay's privacy notices in force from time to time: https://simplepay.hu/adatkezelesi-tajekoztatok/

SimplePay's terms for customers: https://simplepay.hu/vasarlo-aff/

10.6. Payment data received by the Controller

From the SimplePay system, the Controller typically receives:

  • the transaction identifier;
  • the payment status;
  • the time of payment;
  • the amount paid and the currency;
  • the refund status;
  • the technical feedback needed to process the transaction.

This data is retained for as long as necessary for the performance of the contract, accounting, refunds and the handling of any payment dispute.

11. Bank transfer and refunds

In the case of a bank transfer, the Controller may learn:

  • the name of the account holder;
  • the bank account number;
  • the amount and date of the transaction;
  • the payment reference;
  • the transaction identifier.

The purpose of the processing is to identify the payment, account for the booking fee, carry out refunds and fulfil accounting obligations.

The legal basis is Article 6(1)(b) and (c) GDPR. Banking and accounting data is processed until the end of the applicable accounting retention period.

12. Contact and customer service communication

12.1. Categories of data processed

  • name;
  • email address;
  • phone number, if provided by the data subject;
  • booking identifier;
  • the content of the message, question or request;
  • the correspondence generated during the handling of the matter;
  • other data necessary to close the matter.

12.2. Purpose and legal basis

The purpose of the processing is to respond to the enquiry and handle the matter.

  • Article 6(1)(b) GDPR for enquiries related to a booking or contract;
  • Article 6(1)(f) GDPR for general enquiries that do not lead to a contract, based on the legitimate interest in customer communication and the operation of the Controller.

12.3. Retention period

Enquiries not related to a contract are retained for a maximum of one year after the matter is closed.

Correspondence relating to a booking, contract, claim or legal claim may be retained together with the related contractual documentation for a maximum of five years, or, in the case of an ongoing legal dispute, until its final conclusion.

13. Complaint handling and legal claims

13.1. Data processed

  • the complainant's name and contact details;
  • the details of the booking and the service;
  • the content of the complaint;
  • documents and evidence submitted by the complainant;
  • the record of the complaint;
  • the Controller's response and measures taken;
  • refund, compensation or other settlement data.

13.2. Purpose and legal basis

The purpose of the processing is to investigate, answer and document consumer complaints, and to establish, exercise or defend legal claims.

Legal basis:

  • Article 6(1)(c) GDPR for complaint handling required by law;
  • Article 6(1)(f) GDPR, legitimate interest, for the handling of legal claims.

13.3. Retention period

The Controller retains the record of the complaint and a copy of the response for the period specified in consumer protection legislation, currently three years.

If a legal dispute or other legal claim arises from the matter, the related data may be processed until the claim becomes time-barred or the proceedings are finally concluded.

14. Newsletter and direct marketing

14.1. Categories of data processed

  • email address;
  • given name, if provided by the data subject;
  • time and source of subscription;
  • technical data required to evidence consent;
  • delivery, open and click data of newsletters, where the system used and the consent settings allow this;
  • time of unsubscribing.

14.2. Purpose and legal basis

The purpose of the processing is to send news, offers, programmes, content and discounts.

The legal basis is voluntary consent under Article 6(1)(a) GDPR, as well as the prior consent required under legislation on electronic and advertising communications.

Booking the accommodation may not be made conditional on subscribing to the newsletter.

14.3. Unsubscribing

Consent may be withdrawn at any time without giving reasons:

  • by using the unsubscribe link in the newsletter;
  • by sending a message to info@netineti.hu.

Withdrawal does not affect the lawfulness of processing carried out beforehand.

14.4. Retention period

The Controller processes data used for sending newsletters until consent is withdrawn or the data subject unsubscribes.

The Controller may retain the fact of unsubscribing and the data strictly necessary to evidence it, on the basis of its legitimate interest, in order to demonstrate that no further newsletters are sent to the data subject.

14.5. Mailchimp

The Controller uses the Mailchimp service to send newsletters and manage the subscriber list.

Provider: The Rocket Science Group LLC, part of the Intuit group
Address: 675 Ponce de Leon Avenue NE, Suite 5000, Atlanta, Georgia 30308, United States of America.

Mailchimp acts as the Controller's processor when providing the service. Using the service may involve a transfer of data to the United States. Depending on the certifications and contractual terms in place at the given time, appropriate safeguards for the transfer may be the EU–US Data Privacy Framework or the standard contractual clauses adopted by the European Commission.

Processing carried out by Mailchimp for its own purposes is governed by the provider's own privacy notice.

15. Website, log data and IT security

When the website is visited, the web server and the security systems may automatically record technical data, in particular:

  • IP address;
  • time of access;
  • page or resource opened;
  • browser and operating system type;
  • referring page;
  • server response and error code;
  • data indicating a security event or attempted abuse.

The purposes of the processing are:

  • ensuring the proper operation of the website;
  • detecting and fixing errors;
  • IT and network security;
  • detecting unauthorised access, automated attacks and abuse;
  • investigating technical incidents.

The legal basis is Article 6(1)(f) GDPR, the legitimate interest in a secure and functioning online service.

As a general rule, security and server logs are retained for a maximum of 90 days, unless longer retention is necessary due to a security event, abuse or legal claim.

16. Google reCAPTCHA

The Controller may use the Google reCAPTCHA service to protect online forms against automated abuse, spam and bots.

In the course of the service, Google may process in particular the following data:

  • IP address;
  • browser and device data;
  • interactions with the website;
  • technical and behavioural signals needed to detect abuse;
  • identifiers placed or read by Google.

The purpose of the processing carried out by the Controller is to maintain the security of the website and its forms and to prevent spam and automated attacks.

The legal basis is the legitimate interest under Article 6(1)(f) GDPR.

The use of reCAPTCHA may involve a transfer of data to a third country. Google's own processing operations are governed by Google's privacy policy.

17. Cookies and similar technologies

17.1. What is a cookie?

A cookie is a small data file placed on, or read from, the visitor's device by the website or its service provider. Cookies may be session or persistent cookies, and first-party or third-party cookies.

17.2. Cookie categories

Strictly necessary cookies

These are necessary for the basic operation and security of the website, for maintaining the booking process, for remembering the selected privacy settings or for the technical operation of the payment process.

Their legal basis is the legitimate interest under Article 6(1)(f) GDPR and, in respect of storage on the end-user device, technical necessity under electronic communications rules.

These cookies cannot be switched off on the consent interface, but blocking them in the browser may render certain website functions inoperable.

Functional cookies

These are used to remember the visitor's choices and convenience settings.

Where they are not strictly necessary, their legal basis is consent under Article 6(1)(a) GDPR.

Statistical or analytics cookies

These are used to measure use of the website, produce traffic and interaction statistics and develop the website.

Their legal basis is consent under Article 6(1)(a) GDPR.

Marketing and advertising cookies

These may be used to measure advertising performance, build audiences, carry out remarketing and display personalised advertisements.

Their legal basis is consent under Article 6(1)(a) GDPR.

17.3. Google services

With the visitor's consent, the Controller may use in particular:

  • Google Analytics;
  • Google Ads;
  • Google Tag Manager;
  • Google Consent Mode v2.

Google Tag Manager is used primarily to manage the measurement and marketing tags used on the website. Other services loaded through Tag Manager may only be activated in line with the visitor's consent settings.

Google Analytics may produce statistics on the use of the website. Google Ads may be used to measure advertising campaigns and, subject to consent, for remarketing.

Without consent, the Controller does not place statistical or marketing cookies. Due to the technical operation of Google Consent Mode, Google may receive limited, cookieless technical signals depending on the consent status and the actual configuration.

17.4. Managing consent

On the consent interface displayed when the website is first visited, the visitor may:

  • accept all non-essential cookies;
  • reject them;
  • set their consent by category.

Consent may be changed or withdrawn at any time using the "Cookie settings" link in the website footer or the cookie icon displayed.

Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

17.5. Detailed cookie list

The current name, provider, purpose and expiry of the cookies actually used on the website can be viewed in the detailed cookie list of the consent management interface. The list may change automatically as the website changes technically.

18. Bookings received through intermediary platforms

For bookings placed through Booking.com, Airbnb or another intermediary platform, the given platform is an independent controller in respect of the processing carried out in its own system.

The Controller may receive from the platform the data necessary to fulfil the booking, for example:

  • the name of the Contracting party or Guest;
  • contact details;
  • the dates of the booking;
  • the selected accommodation;
  • the number of Guests;
  • payment and cancellation status;
  • messages sent through the platform;
  • special requests.

The Controller processes the data received in this way in order to fulfil the booking and the service contract, comply with legal obligations and handle any legal claims.

Processing, profiling, payment processing, fraud prevention and marketing carried out by the given platform for its own purposes are governed by the platform's own privacy notice.

19. Social media

If a data subject sends a message, posts a comment, reacts or otherwise interacts with a neti neti social media page, the Controller may process:

  • the name and profile picture publicly available in the social media profile;
  • the content of the message or comment;
  • the time of contact;
  • interaction data made available by the social platform.

The purpose of the processing is to respond to the enquiry, manage the social media presence and present the Controller's services.

Legal basis:

  • Article 6(1)(b) GDPR for contract-related enquiries;
  • Article 6(1)(f) GDPR, legitimate interest, for other communication;
  • the data subject's consent for direct marketing, where required.

Processing carried out by the social platform in its own system is governed by the platform's own privacy notice.

20. Camera surveillance

The Controller operates a camera surveillance system in certain common or outdoor areas of the accommodation only if it has documented in advance the purpose, necessity and proportionality of such surveillance and has appropriately informed data subjects before they enter the monitored area.

Cameras may only be used for the protection of property, accident prevention, personal safety, or the prevention and evidencing of unlawful acts. Cameras may not be directed at areas where surveillance would violate human dignity or privacy, in particular:

  • the interiors of the Houses;
  • bathrooms or toilets;
  • the interior of the sauna;
  • areas used for changing or washing;
  • private areas handed over for the exclusive use of the Guest.

If camera surveillance is operated, the Controller makes a separate camera surveillance privacy notice available, which contains at least:

  • the location and field of view of each camera;
  • the exact purpose and legal basis of the processing;
  • the retention period of the recordings;
  • the persons who have access to the recordings;
  • the rules for viewing and transferring the recordings;
  • how data subject rights can be exercised.

The retention period must be set per camera and per purpose, for the shortest necessary time. Recordings may only be retained beyond the general deadline in the case of an unlawful act, accident, damage event or other documented reason, until the related procedure or legal claim is concluded.

21. Processors and other recipients

The Controller discloses personal data only to recipients that are necessary for providing the service, complying with its legal obligations or enforcing its legitimate interests.

21.1. Main processors and categories of providers

Hosting provider:
Websupport Magyarország Kft.
Fehérvári út 97–99., 1119 Budapest, Hungary
Task: web hosting, server and related IT services.

Booking and property management system:
Previo, s.r.o.
Kubánské náměstí 1391/11, 100 00 Prague 10, Czech Republic.
Task: booking engine, property management, guest communication, online check-in and related technical services.

Online check-in solution:
Previo/Alfred system.
Task: online registration of Guests, handling of arrival data and support of self check-in.

Online payment service provider:
SimplePay Zrt.
Váci út 135–139. building B, 5th floor, 1138 Budapest, Hungary.
Depending on the given processing operation, its role may be that of a processor, an independent controller or a joint controller.

Newsletter provider:
The Rocket Science Group LLC / Intuit – Mailchimp.
Task: sending newsletters, managing the subscriber list and campaign statistics.

Web analytics, advertising and security provider:
Google Ireland Limited, or another member of the Google group in respect of the given service.
Task: subject to consent, web analytics and advertising measurement, and abuse prevention in the case of reCAPTCHA.

Invoicing service provider:
The electronic invoicing provider used by the Controller from time to time.
Task: issuing, transmitting and storing invoices.

Bookkeeper and tax advisor:
The bookkeeper or accounting firm engaged by the Controller.
Task: bookkeeping, tax returns and financial administration.

Email and communication provider:
The email and messaging provider used by the Controller from time to time.
Task: delivery of electronic mail and messages.

IT service providers:
The Controller's system operators, web developers and IT maintenance providers.
Task: operating, maintaining, troubleshooting and securing the systems.

21.2. Authorities and other recipients

Data may be transferred in particular to:

  • the designated hosting provider of the VIZA system;
  • the National Tourism Data Supply Centre (NTAK);
  • the National Tax and Customs Administration;
  • the police, courts, prosecution service or other authorities;
  • a conciliation body or the consumer protection authority;
  • legal counsel, debt collectors or insurers;
  • banks, card companies or payment service providers;
  • other parties involved in a damage event or legal dispute,

where the transfer has an appropriate legal basis and is limited to what is necessary.

22. Transfers to third countries

Certain providers – in particular Mailchimp, Google or social media platforms – may process personal data outside the European Economic Area, including in the United States of America.

The Controller transfers personal data to a third country, or engages such a processor, only if the transfer complies with the requirements of Chapter V of the GDPR.

Appropriate safeguards may be in particular:

  • an adequacy decision of the European Commission;
  • a valid certification under the EU–US Data Privacy Framework;
  • the standard contractual clauses adopted by the European Commission;
  • another transfer mechanism recognised by the GDPR.

Data subjects may request further information about the safeguards applied at info@netineti.hu.

23. Automated decision-making and profiling

The Controller does not use solely automated decision-making that would produce legal effects concerning the data subject or similarly significantly affect them.

Analytics and advertising services operating on the basis of consent may create audiences or interest categories based on visitors' online behaviour. On the part of the Controller, this does not result in automated decisions about the availability or conditions of the accommodation service.

The payment service provider may apply its own fraud prevention and risk assessment procedures. These are governed by SimplePay's own notices.

24. Data security

To ensure the security of personal data, the Controller applies technical and organisational measures appropriate to the level of risk, in particular:

  • encrypted HTTPS connection;
  • individual user permissions;
  • access restrictions;
  • strong passwords and, where possible, multi-factor authentication;
  • regular backups;
  • logging and security monitoring;
  • up-to-date software and security updates;
  • data protection agreements concluded with processors;
  • confidentiality obligations for staff and contributors;
  • data minimisation and erasure procedures.

Personal data may only be accessed by those staff members, contributors and providers for whom this is necessary to perform their tasks.

25. Personal data breaches

A personal data breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

The Controller investigates and documents the breach and takes the measures necessary to mitigate any damage.

Where the breach is likely to result in a risk to the rights and freedoms of natural persons, the Controller notifies the Hungarian National Authority for Data Protection and Freedom of Information without undue delay and, where feasible, within 72 hours of becoming aware of it.

Where the breach is likely to result in a high risk to the rights and freedoms of data subjects, the Controller also informs the data subjects without undue delay, unless an exception under the GDPR applies.

26. Rights of the data subject

Data subjects may exercise the following rights, subject to the applicable conditions.

26.1. Right of access

Data subjects may request information as to whether the Controller processes their personal data and, if so, may request access to:

  • the data processed;
  • the purposes of the processing;
  • the categories of data;
  • the recipients;
  • the retention period;
  • data subject rights;
  • the source of the data;
  • information on automated decision-making;
  • the safeguards applied in the case of third-country transfers.

Data subjects may request a copy of the personal data processed about them.

26.2. Right to rectification

Data subjects may request the rectification of inaccurate personal data and the completion of incomplete data.

26.3. Right to erasure

Data subjects may request the erasure of their personal data, in particular where:

  • the data is no longer necessary;
  • they withdraw their consent and there is no other legal basis;
  • they successfully object to processing based on legitimate interest;
  • the processing is unlawful;
  • erasure is required by law.

Erasure may not be requested where, among other cases, the processing is necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims.

26.4. Right to restriction of processing

Data subjects may request restriction of processing where:

  • they contest the accuracy of the data;
  • the processing is unlawful but they oppose erasure;
  • the Controller no longer needs the data, but the data subject requires it for a legal claim;
  • the data subject has objected and it has not yet been established whether the Controller's legitimate grounds override.

26.5. Right to data portability

Data subjects may request to receive the personal data they have provided, processed by automated means on the basis of consent or a contract, in a structured, commonly used, machine-readable format, or to have it transmitted by the Controller to another controller, where technically feasible.

26.6. Right to object

Data subjects may object at any time, on grounds relating to their particular situation, to processing based on Article 6(1)(f) GDPR.

In the event of an objection, the Controller no longer processes the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or the processing is necessary for the handling of legal claims.

Data subjects may object at any time, without giving reasons, to processing for direct marketing purposes. In such cases, the personal data may no longer be processed for direct marketing purposes.

26.7. Withdrawal of consent

Data subjects may withdraw their consent at any time. Withdrawal does not affect the lawfulness of earlier processing.

26.8. Rights relating to automated decision-making

Data subjects have the right not to be subject to a decision based solely on automated processing which produces legal effects concerning them or similarly significantly affects them, except in the cases set out in the GDPR.

27. Submitting and handling data subject requests

Data subject requests may be submitted at the following contact details:

Email: info@netineti.hu
Postal address: neti neti Karikavölgy Kft., 8795 Zalaszentgrót, hrsz. 5277.

The Controller responds to the request without undue delay and at the latest within one month of its receipt.

That period may be extended by a further two months, taking into account the complexity and number of the requests. The Controller informs the data subject of any such extension and its reasons within the original one-month period.

Where the Controller has reasonable doubts concerning the identity of the requester, it may request additional information necessary for identification.

Requests are handled free of charge as a general rule. Where a request is manifestly unfounded or excessive, in particular because of its repetitive character, the Controller may charge a reasonable fee or refuse to act.

28. Remedies

28.1. Complaint to the supervisory authority

Data subjects may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information.

Nemzeti Adatvédelmi és Információszabadság Hatóság
Registered office: Falk Miksa utca 9–11., 1055 Budapest, Hungary
Postal address: 1363 Budapest, Pf. 9., Hungary
Phone: +36 1 391 1400
Email: ugyfelszolgalat@naih.hu
Website: https://www.naih.hu

Data subjects may also lodge a complaint with the data protection supervisory authority of another EU Member State, in particular that of their habitual residence, place of work or the place of the alleged infringement.

28.2. Judicial remedy

In the event of unlawful processing of their personal data or infringement of their rights under the GDPR, data subjects may turn to the courts.

At the data subject's choice, proceedings may be brought before the regional court competent for the Controller's registered office or for the data subject's domicile or place of residence.

29. External websites

The Website may contain links to external websites, social media pages, booking platforms or the pages of payment service providers.

Once an external site is opened, the operator of that site is responsible for the processing carried out there. Data subjects are advised to read the privacy notice of the given provider.

30. Amendments to this notice

The Controller is entitled to amend this notice, in particular in the event of:

  • changes in legislation;
  • changes in the practice of authorities or courts;
  • engagement of a new provider or processor;
  • introduction of a new processing activity;
  • technical modification of the website or the booking system.

The version in force from time to time is available on the Website. In the case of a material amendment, the Controller may also inform data subjects separately, in a manner appropriate to the circumstances.

Questions about this notice may be sent to info@netineti.hu.