PRIVACY NOTICE
(for Guests)
Data Controller Information:
Company Name: Integritás Kft. – Vis Vitalis Hotel (hereinafter: Data Controller, Company)
Registered Office: 2144 Kerepes, Szabadság út 102., Hungary
Company Registration Number: 13 09 061520
Tax Number: 10387214-2-13
Representative: Anikó Krasznai-Rapavi
Phone: +36-28-999-055
E-mail: info@visvitalishotel.eu
Website: www.visvitalishotel.eu
Data Protection Officer
Pursuant to Article 37 of the GDPR, the Data Controller is not obliged to designate a Data Protection Officer and therefore does not employ a dedicated Data Protection Officer. Inquiries regarding data protection may be directed to the Data Controller via the contact details specified in this notice.
Introduction
The purpose of this notice is to provide appropriate information to guests, clients, and website visitors of Vis Vitalis Hotel regarding the personal data processed by it, the principles and practice of data processing, as well as the rights of data subjects and how to exercise them.
The Hotel is committed to protecting the personal data of its guests and visitors, placing paramount importance on respecting its clients’ right to informational self-determination. The Data Controller declares that it respects the personal rights of its partners, clients, and website visitors. It handles collected personal data confidentially, in accordance with data protection legislation and this Privacy Notice, and takes all security, technical, and organizational measures required to guarantee data security.
If a Data Subject feels that they have further questions beyond what is contained in this Notice, or if certain elements are unclear, please contact the Hotel (as Data Controller) using the contact details provided. Upon request by the Data Subject, detailed information will always be provided regarding personal data processed, the purpose, legal basis, duration of processing, and activities related to data processing.
Information regarding the data processing activities of Vis Vitalis Hotel and the current valid version of this Privacy Notice are available on the Hotel’s website.
The Hotel reserves the right to unilaterally modify this Notice and ensures that the current Privacy Notice is always accessible on its website. Guests will be notified of any changes in a timely and appropriate manner. The Data Controller undertakes that if it changes its purposes, principles, and/or practices regarding personal data processing, it will inform data subjects so they always clearly understand the applicable rules. If the Hotel intends to use personal data in a manner different from the principles, practices, or purposes stated at the time of collection, Data Subjects will be notified in advance via email and offered the opportunity to decide whether they consent to the processing of their personal data under the new terms.
The Data Controller hereby undertakes that this Notice always reflects the principles actually applied and the real practice. The processing of personal data of individuals interacting with the Hotel is conducted in accordance with this Notice.
Purpose of the Notice
The purpose of this Notice is to provide adequate information to data subjects regarding their rights and to ensure that Vis Vitalis Hotel complies with applicable data protection laws, in particular:
- Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Infotv.);
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation / GDPR);
- Act XLVII of 2008 on the Prohibition of Unfair Commercial Practices against Consumers;
- Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities;
- Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services;
- Act CXXXIII of 2005 on the Rules of Personal and Property Protection and Private Investigation Activities;
- Act XCVII of 2018 amending Act CLVI of 2016 on the State Tasks for the Development of Tourism Areas and related acts.
Scope of the Notice
Temporal Scope
This Notice is effective from 1 March 2026, until further notice or revocation.
Personal Scope
The personal scope of this Notice covers all natural persons (data subjects) whose personal data is processed by Vis Vitalis Hotel within the framework of data processing specified in this Notice, as well as persons whose rights or legitimate interests are affected by data processing.
Material Scope
The material scope of this Notice covers all data processing activities involving personal data carried out in all organizational units of the Hotel.
Definitions
- Data Subject: any natural person who is identified or identifiable based on specific personal data
- Personal Data: any information relating to an identified or identifiable natural person (e.g. name, identification number), or conclusions that can be drawn from such data
- Special Categories of Personal Data (Sensitive Data): personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, or data concerning a natural person’s sex life or sexual orientation
- Consent: any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which they signify agreement to the processing of personal data relating to them
- Objection: a declaration by the data subject objecting to the processing of their personal data
- Data Filing System: any structured set of personal data accessible according to specific criteria
- Data Controller: the natural or legal person, or entity without legal personality, which determines the purposes and means of the processing of personal data
- Data Processor: a natural or legal person, or entity without legal personality, which processes personal data on behalf of the controller based on a contract (including contracts mandated by law)
- Data Processing: any operation or set of operations performed on personal data, whether or not by automated means (e.g. collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction, as well as capturing photos, video, or audio recordings, or physical characteristics)
- Restriction of Processing: the marking of stored personal data with the aim of limiting their processing in the future
- Profiling: any form of automated processing of personal data evaluating certain personal aspects relating to a natural person
- Filing System: any set of personal data structured according to specific criteria
- Data Transfer: making personal data accessible to a specific third party
- Data Blocking: marking data with an identification mark to limit its further processing permanently or for a specified time
- Data Erasure: destruction of data to render recovery impossible
- Public Disclosure: making data accessible to anyone
- Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed
Principles of Data Processing
Principles under the GDPR:
- Lawfulness, Fairness, and Transparency (Art. 5(1)(a)): Data processing must be conducted lawfully, fairly, and transparently.
- Purpose Limitation (Art. 5(1)(b)): Data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes.
- Data Minimization (Art. 5(1)(c)): Data processing must be adequate, relevant, and limited to what is necessary.
- Accuracy (Art. 5(1)(d)): Data must be accurate and kept up to date; inaccurate data must be erased or rectified without delay.
- Storage Limitation (Art. 5(1)(e)): Data must be kept in a form permitting identification for no longer than necessary.
- Integrity and Confidentiality (Art. 5(1)(f)): Data must be processed securely against unauthorized processing, loss, or damage using technical/organizational measures.
- Accountability (Art. 5(2)): The controller is responsible for, and must be able to demonstrate, compliance with these principles.
Lawfulness of Processing
Personal data may be processed lawfully if at least one of the following legal bases applies (GDPR Art. 6(1)):
a. Consent of the data subject;
b. Performance of a contract to which the data subject is party, or in order to take steps at the request of the data subject prior to entering into a contract;
c. Compliance with a legal obligation to which the controller is subject;
d. Protection of the vital interests of the data subject or another natural person;
e. Performance of a task carried out in the public interest or in the exercise of official authority;
f. Legitimate interests pursued by the controller or a third party, except where overridden by the interests or fundamental rights and freedoms of the data subject, particularly where the data subject is a child.
Processing Data of Minors
The Hotel pays special attention to protecting the personal data of minors. Where processing is based on consent and the data subject is under 16 years of age, consent must be given or authorized by the holder of parental responsibility, particularly in connection with information society services. The Hotel takes all reasonable steps to process minors’ data lawfully and will promptly delete any illegally recorded data of children.
Scope, Purpose, and Duration of Data Processing Activities
8.1 Correspondence
- Activity frequency: continuous
- Processed data: name, email address, correspondence content
- Retention period: 1 year from offer expiration for unsuccessful quotes; up to 5 years for concluded contracts (considering accounting/civil law limitation periods)
- Purpose: communication, handling inquiries, sending offers to individual/group guests
- Internal access: managing director, deputy, reception staff
- Legal basis: performance of a contract (GDPR Art. 6(1)(b)) for bookings; legitimate interest (GDPR Art. 6(1)(f)) for general inquiries
- Data subjects: inquiring individuals, prospective guests, travel agency representatives
- Data transfers: none
- Data processor: hosting provider
8.2 Direct Room Bookings
- Activity frequency: for the duration of the contractual relationship
- Processed data: name, address, phone number, email address, number of guests (number/age of children)
- Retention period: duration of the contractual relationship. Exceptions: name & address — 8 years pursuant to Section 169 of Act C of 2000 on Accounting; guests’ name & age — until the last day of the 5th year following the tax year, pursuant to Sections 78(3) and 202(1) of Act CLI of 2017 on the Order of Taxation
- Purpose: hotel room reservation, booking confirmation, service provision
- Internal access: managing director, deputy, reception staff
- Legal basis: performance of a contract (GDPR Art. 6(1)(b)); compliance with legal obligations (GDPR Art. 6(1)(c)), specifically: NTAK tourism reporting (Act CLVI of 2016), local tourism tax (Act C of 1990), accounting record retention (Act C of 2000), tax obligations (Act CLI of 2017)
- Data subjects: hotel guests
- Data transfers: National Tourism Data Centre (NTAK — independent controller), Municipality of Kerepes Town (independent controller)
- Data processors: hotel management software provider, accountant
- Payment processors: OTP Bank (bank card processing), K&H Bank Zrt. (wire transfers)
8.3 Guest Registration upon Arrival (Registration Form)
- Activity frequency: one-time operation per stay
- Processed data: arrival/departure dates, payment method, full name (birth name), date/place of birth, gender, nationality, ID/passport number, vehicle license plate, address, billing address
- Purpose: performance of the accommodation contract, guest registration, statutory reporting, assessment/declaration of local tourism tax, accounting compliance
- Retention period: personal data registered under Chapter II/A, Section 6/B of Act CLVI of 2016 — 1 year. Name, address, billing address under Section 169 of Act C of 2000 — 8 years
- Internal access: managing director, deputy, reception staff
- Legal basis: contract performance (GDPR Art. 6(1)(b)); legal obligation compliance (GDPR Art. 6(1)(c)) including NTAK, the Local Tourism Tax Act, and the Accounting Act
- Data subjects: hotel guests
- Data transfers: National Tourism Data Centre (NTAK), Municipality of Kerepes Town
- Data processors: hotel software provider, accountant
8.4 Bookings via Intermediaries (e.g. Booking.com)
- Activity frequency: upon booking and for the duration of contract performance
- Processed data: name, email, phone number, number of guests (children count/ages), and, where applicable, credit card data (virtual card number, expiry, CVC, cardholder name, transaction amount/time). The Data Controller does not store bank card details; they are processed solely during transaction execution
- Purpose: booking, service delivery, payment settlement via a virtual credit card provided by Booking.com
- Retention period: duration of the contractual relationship. Exceptions: accounting details — 8 years; tax records — 5 years (until the tax assessment statute of limitations expires)
- Data source: Booking.com online intermediary platform
- Legal basis: contract performance (GDPR Art. 6(1)(b)); legal obligations (GDPR Art. 6(1)(c))
- Data transfers: NTAK, Municipality of Kerepes Town. OTP Bank Nyrt. acts as an independent controller regarding credit card processing
- Data processors: hotel software provider, accountant
8.5 Additional/Special Hotel Services
- Activity frequency: per service usage
- Processed data: name, address, phone, email, contractual/declaration data, billing info
- Purpose: delivery of requested additional services
- Legal basis: contract performance (GDPR Art. 6(1)(b)); legal obligation (GDPR Art. 6(1)(c))
- Retention period: 5 years for legal claims; 8 years for billing data
- Data subjects: hotel guests and visitors
- Data transfers: none
- Data processors: hotel software provider, accountant
8.6 Invoicing and Payment
- Activity frequency: based on services used during the stay
- Processed data: name, address, billing name, billing address, tax number, bank card details (where applicable; not stored after the transaction)
- Purpose: service billing and payment execution
- Retention period: 8 years pursuant to Section 169 of Act C of 2000 on Accounting
- Legal basis: GDPR Art. 6(1)(b) & Art. 6(1)(c)
- Data transfers: accounting service provider, payment processor banks, account-holding bank
- Independent controllers for payment: OTP Bank Nyrt. (card payments), K&H Bank Zrt. (transfers)
8.7 Local Tourism Tax Obligations
- Activity frequency: monthly
- Processed data: name, address, place/date of birth, ID number, arrival/departure date, signature
- Purpose: fulfilment of a legal obligation under GDPR Art. 6(1)(c)
- Retention period: until the statute of limitations for local taxes expires
- Legal basis: Act C of 1990 on Local Taxes; Decree 21/2025 (XI.27.) of Kerepes Town Municipality; Act CLVI of 2016 (NTAK reporting)
- Data transfers: NTAK (independent controller), Municipality of Kerepes Town (independent controller)
8.8 Guest Book / Complaints
- Activity frequency: per feedback/complaint submission
- Processed data: complaint ID, contact info (name, address, phone, email), location/time/method of complaint, submitted evidence, complaint description, service/invoice details, protocol records
- Purpose: investigation, resolution, record-keeping, and legal compliance regarding complaints
- Retention period: 5 years under Section 17/A(7) of Act CLV of 1997 on Consumer Protection
- Legal basis: contract performance (GDPR Art. 6(1)(b)); Consumer Protection Act
- Data transfers: none
8.9 Lost and Found Items
- Activity frequency: per event
- Processed data: location found, finder’s name, item description, date found
- Purpose: registry and return of lost items to guests
- Retention period: 3 months. If unclaimed, the item may be released to the finder upon request
- Legal basis: contract performance (GDPR Art. 6(1)(b)); legal obligation under Act V of 2013 (Civil Code)
8.10 Business Cards
- Activity frequency: one-time
- Processed data: name, title, company name/contact info, phone, email, website, other card details
- Purpose: facilitating business contact
- Retention period: until consent is withdrawn / an instruction to destroy the card is given
- Legal basis: consent (GDPR Art. 6(1)(a))
8.11 Website Visitor Processing
- Activity frequency: upon visiting the website
- Purpose: operating essential session cookies
- Retention period: until browser closure
- Processed data: IP address, browser type, session ID
- Legal basis: legitimate interest (GDPR Art. 6(1)(f))
- Data processor: hosting provider
8.12 Corporate Events & Conferences
- Processed data: company details, contact person’s name, email, phone number
- Purpose: business relationship maintenance, event/conference organization and execution
- Retention period: invoicing data kept for 8 years (Accounting Act); contact info kept for the duration of the cooperation, or deleted immediately upon termination
- Legal basis: Accounting Act / GDPR Art. 6(1)(c) for invoices; legitimate interest (GDPR Art. 6(1)(f)) for business contact details
Recipients and Data Transfers
Personal data is disclosed to third parties only under the following conditions:
- Statutory obligations: when requested by courts, prosecutors, police, administrative, or data protection authorities acting within their legal scope. Data transferred is limited to what is necessary and proportionate (GDPR Art. 6(1)(c)).
- Data processors: external providers bound by written data processing agreements (e.g. software, accounting, web hosting).
- Third country transfers: the Data Controller does not transfer personal data to third countries outside the European Economic Area (EEA).
- External links: the website may contain links to external sites. The Hotel assumes no responsibility for third-party privacy practices.
List of Data Processors
- Cloudio Kft. (1024 Budapest, Margit krt. 43-45. 2. em. 7., Hungary — Reg: 01-09-444158, Email: support@cloudio.hu) — web hosting & site operation
- Hostware Kft. (1149 Budapest, Róna u. 120-122., Hungary — Reg: 01 09 263594, Email: hostware@hostware.hu) — hotel management software, booking, billing, and accounting data access
- Soós Hoom Kft. (2640 Szendehely, Ady Endre u. 23., Hungary — Reg: 12 09 010226, Email: attilanesoos@gmail.com) — accounting and payroll services
- AB Plusz Bt. (2049 Diósd, IV. Béla király u. 48., Hungary — Reg: 01-06-757647, Email: ablusz@abplusz.hu) — internal IT systems, email, cloud services support
- K&H Bank Zrt. (1095 Budapest, Lechner Ödön fasor 9., Hungary) — banking service provider for transfers
- OTP Bank Nyrt. (1051 Budapest, Nádor u. 16., Hungary) — banking service provider for payment card processing
Surveillance Camera System (CCTV) Notice
An electronic CCTV camera system operates throughout Vis Vitalis Hotel (front garden, back garden, corridors, laundry room, restaurant, and reception area).
- Controller: the Company (Integritás Kft.)
- Purposes: protection of human life, physical integrity, and property; prevention/detection of offenses; unauthorized entry monitoring; investigation of extraordinary incidents/accidents
- Legal basis: legitimate interest of the Controller (GDPR Art. 6(1)(f)) & Section 30 of Act CXXXIII of 2005
- Processed data: images/video of individuals, behavior, date/time of recording
- Camera locations: restricted strictly to common areas (reception, entrance, corridors, parking). Cameras are not installed in guest rooms, restrooms, changing rooms, or areas where dignity would be violated
- Retention period: 3 business days for recordings without incidents; maximum 30 days for recordings containing extraordinary incidents
- Viewing access: restricted to Managing Directors, designated employees, the IT system administrator, and authorized authorities (e.g. police). Reviewing recordings requires protocol documentation detailing the reviewer, purpose, timestamp, and duration
- Data transfers: footage is transferred strictly to official authorities upon formal legal request. Guests may request footage of themselves, provided it does not infringe on third-party rights. External media devices cannot be plugged into hotel IT systems; necessary export media costs must be reimbursed by the requester
Data Security Measures
The Company implements technical and organizational security measures to protect data against unauthorized access, alteration, disclosure, deletion, or destruction.
Key measures include:
- Role-based access controls
- Password protection & firewalls/antivirus on IT systems
- Regular system backups
- Physical locking of paper documents
- Employee confidentiality obligations
Personal Data Breach Management
A personal data breach is any security breach leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, personal data.
- Incident reporting: employees, partners, or data subjects must report breaches immediately to the hotel’s central contact details.
- Investigation: management investigates and assesses severity immediately upon report.
- Incident register: kept for 5 years, detailing timestamp, description, affected data/persons, and remediation steps.
- Authority & data subject notification: breaches with risks to individuals’ rights are notified to the Supervisory Authority (NAIH) within 72 hours. High-risk breaches are communicated to affected data subjects without undue delay.
Rights of the Data Subject
Data subjects have the following rights under GDPR Articles 15–22:
- Right to information & transparency (Art. 13–14): clear, concise, easily accessible information.
- Right of access (Art. 15): confirmation of processing and a copy of personal data.
- Right to rectification (Art. 16): correction of inaccurate or incomplete data.
- Right to erasure / “right to be forgotten” (Art. 17): deletion of data when no longer needed, consent is withdrawn, or processing is unlawful (unless required by statutory retention laws).
- Right to restriction of processing (Art. 18): temporarily freezing processing under specific conditions.
- Right to data portability (Art. 20): receiving personal data in a structured, machine-readable format.
- Right to object (Art. 21): right to object to processing based on legitimate interest or direct marketing.
- Right not to be subject to automated decision-making (Art. 22): the Hotel does not use automated decision-making/profiling.
- Right to withdraw consent: consent may be withdrawn at any time without affecting prior lawful processing.
Procedural rules: requests are handled free of charge within 1 month (extendable by 2 months for complex cases).
Legal Remedies
In case of a rights violation, data subjects may lodge a complaint with the National Authority for Data Protection and Freedom of Information (NAIH):
- Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/C., Hungary
- Mailing address: 1530 Budapest, Pf.: 5.
- Phone: +36-1-391-1400
- Email: ugyfelszolgalat@naih.hu
- Website: https://www.naih.hu
Data subjects may also bring court proceedings before the competent court.
Miscellaneous Provisions
The Controller reserves the right to update this notice. Updates will be published on the Vis Vitalis Hotel website.
Annex 1: Cookie Policy for Website Visitors
Data Controller Details:
Integritás Kft. – Vis Vitalis Hotel
Registered Office: 2144 Kerepes, Szabadság út 102., Hungary
Website: www.visvitalishotel.eu | Email: info@visvitalishotel.eu
What Are Cookies?
Cookies are small text files placed on a visitor’s browser to ensure technical website operation.
Cookie Types & Legal Basis:
The website exclusively uses strictly necessary session cookies.
- Purpose: ensuring proper technical operation, user session identification, smooth navigation, and preventing data loss
- Legal basis: legitimate interest under GDPR Art. 6(1)(f) / consent under GDPR Art. 6(1)(a)
- Data processed: session ID (random string), visit timestamp, technical browser data
- Duration: session cookies remain active only until the browser is closed and are automatically deleted thereafter. No persistent, analytics, or marketing tracking cookies are used
Managing Cookies:
Visitors can modify, block, or delete cookies at any time via their web browser’s privacy/security settings.
Kerepes, 2026