Privacy Notice

Dunapark Café

1. Purpose and scope of this prospectus

This Privacy Notice sets out how the operator of Dunapark Kávéház, as the data controller (hereinafter: „Data Controller”), processes the https://dunaparkkavehaz.hu/ the personal data of website visitors, guests who make online table bookings, and those who contact us via the contact form, by email or by telephone.

This information sheet covers, in particular, the technical operation and security of the website, data processing in connection with table bookings, amending and cancelling bookings, responding to enquiries, service notifications, complaint handling, social media communications, and the use of cookies and similar technologies.

This privacy notice does not cover specific data processing activities for which the Data Controller publishes a separate privacy notice, in particular prize draws, event registrations, CCTV surveillance, job applications or the sending of newsletters.

2. Details of the data controller

Name of the data controllerZestory Operating Limited Liability Company
Abbreviated nameZestroy Ltd.
Brand name / business unitDunapark Café
Registered office38 Pozsonyi út, Budapest 1137.
Company registration number01 09 450527
Tax number32939558-2-41
Member of ParliamentBeáta Ando
Shop address38 Pozsonyi út, Budapest 1137.
Websitehttps://dunaparkkavehaz.hu/
Emailasztalfoglalas@dunaparkkavehaz.hu
Telephone+36 30 434 38 65

3. The fundamental principles of data processing

The Data Controller processes personal data in accordance with Regulation (EU) 2016/679 (GDPR) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.

  • lawfully, fairly and in a manner that is transparent to the data subject;
  • for a specific, clear and lawful purpose;
  • limited to the data necessary and proportionate to achieving the objective;
  • accurate and – where necessary – up to date;
  • only for as long as necessary;
  • protected by appropriate technical and organisational measures;
  • in accordance with the requirement for accountability, and in a documented manner.

4. Individual data processing operations

4.1. Technical operation and IT security of the website

Data processing elementContents
Purpose of data processingTo ensure the secure and proper operation of the website; to identify and rectify faults; and to prevent, log and investigate cyber-attacks and misuse.
Data processedIP address, time of visit, page viewed or resource requested, browser and device details, operating system, referring page, technical log data, error codes and security incidents.
Legal basisArticle 6(1)(f) of the GDPR: the Data Controller’s legitimate interests in operating the website, ensuring the security of the service, protecting the IT system and preventing misuse.
Source of dataThe user’s device, browser, and the systems operating the website and the web hosting service.
Retention periodAs a general rule, standard server and security logs are retained for a maximum of 30 days. In the event of a security incident, misuse or a legal dispute, the relevant data may be retained for as long as is necessary to investigate the incident or to enforce a legal claim.
Consequences of data reportingTechnical data processing is an essential part of using the website. Without this data, the secure operation of the website cannot be guaranteed.

4.2. Contact us via the contact form, by email or by telephone

It is not necessary to seek consent for data processing in order to submit the contact form. The data subject must confirm that they have read the privacy notice; the legal basis for data processing is determined by the purpose of the enquiry.

Data processing elementContents
Purpose of data processingReceiving enquiries, identifying the data subject, responding to questions or requests, making arrangements for any services or bookings, maintaining contact and handling administrative matters.
Data processedName, email address, telephone number – if provided by the data subject – the subject and content of the enquiry, the date and time of submission, any correspondence arising during the handling of the matter, and any other data voluntarily provided by the data subject.
Legal basis – contractual requestArticle 6(1)(b) of the GDPR, where, at the data subject’s request, steps are taken prior to entering into a booking, hospitality service, event, offer or other contract, or where the processing is necessary for the performance of a contract that has already been concluded.
Legal basis – other enquiriesArticle 6(1)(f) of the GDPR, where the enquiry is not related to the preparation or performance of a contract. It is in the Data Controller’s legitimate interest to respond to and document general, professional, press, partner or other enquiries received.
Source of dataDirectly from the person concerned.
Retention periodIf the enquiry does not result in a contract or booking: 1 year from the date the matter is substantively concluded. In matters relating to a contract or booking, the retention period applicable to the specific data processing operation shall apply. In the event of a legal claim or dispute, the necessary data may be processed for a maximum of the period until the expiry of the general civil law limitation period.
Consequences of data reportingWithout the information marked as mandatory, the Data Controller will be unable to accept or respond to the enquiry. A telephone number may only be mandatory if it is genuinely necessary due to the nature of the enquiry.

4.3. Online table booking

Data processing elementContents
Purpose of data processingReceiving and recording booking requests, checking availability, securing a table, verifying the guest’s identity and contact details, confirming, amending or cancelling bookings, managing guest arrivals, and handling service-related communications in connection with the booking.
Data processedName, email address, telephone number, date and time of booking, number of guests, chosen dining area or table preference, booking reference and status, details of any amendments or cancellations, waiting list details – if applicable –, any comments necessary for fulfilling the booking, and technical details of communications relating to the booking.
Legal basisArticle 6(1)(b) of the GDPR: taking steps at the data subject’s request prior to entering into a contract, and subsequently fulfilling the contract for the provision of hospitality services.
Source of dataDirectly from the person concerned; the technical details of the booking from the booking system.
Retention period90 days following the fulfilment, cancellation or failure of the booking. In the event of a specific complaint, claim for damages, payment dispute, misuse or other legal claim, the necessary data may be processed until the matter is resolved or, at the latest, until the end of the applicable limitation period. In the case of invoicing or advance payments, separate statutory retention periods apply to accounting documents.
Consequences of data reportingAn online booking cannot be made without providing the required details. You may choose not to provide any optional preferences or comments.
Automatic notificationsConfirmation, reminders, amendments and cancellations of bookings are service messages relating to the performance of the contract. No separate marketing consent is required to send these.

4.4. Managing the waiting list – if this function is active

Data processing elementContents
Purpose of data processingNotifying the guest if a booking slot close to their preferred date or a newly available slot becomes available.
Data processedName, email address and/or telephone number, preferred date and time slot, number of guests, waiting list status, date of notification.
Legal basisArticle 6(1)(b) of the GDPR: taking steps at the data subject’s request prior to entering into a booking contract.
Retention period30 days following the selected date or the end of the waiting list period, unless a booking is made from the waiting list; in which case the rules governing the retention of online bookings shall apply.
Consequences of data reportingThe waiting list service cannot be provided without the necessary details.

4.5. Booking confirmations, reminders and cancellation notices

Data processing elementContents
Purpose of data processingTo confirm that a booking has been made, to provide booking details, to reduce the number of no-shows, to allow for changes or cancellations, and to maintain the contact necessary for the provision of the service.
Data processedName, email address, telephone number, booking reference, date, time, number of guests, booking status, the time the message was sent and technical details of its delivery.
Legal basisArticle 6(1)(b) of the GDPR: the preparation and performance of the contract relating to the booking.
Retention periodFor the same period as the booking data; delivery logs are generally retained for a maximum of 90 days.
NoteThe service message must not contain any advertising or other marketing content unrelated to the booking unless the data subject has given their separate consent to this.

4.6. The comments field and the processing of special categories of personal data

In the free-text field, the guest may also provide information that the Data Controller does not require. The Data Controller therefore requests that the data subject provide only the information necessary to fulfil the booking, and refrain from providing, without good reason, any health, religious, political, biometric or other special categories of personal data.

Data processing elementContents
General booking noteFor example, a high chair, a quieter table, accessible access or notification of a special occasion. Legal basis: Article 6(1)(b) of the GDPR, where the data is necessary for the preparation or performance of the requested service.
Allergies, intolerances or medical informationSuch data may constitute special categories of personal data within the meaning of Article 9 of the GDPR. It may only be collected on a regular basis in a separate field designated for a specific purpose, with the data subject’s explicit consent, in accordance with Article 6(1)(a) and Article 9(2)(a) of the GDPR.
Retention periodIt is recommended that health-related information be retained only for as long as is necessary to fulfil the booking in question, up to a maximum of 30 days following the booking, after which it should be deleted from the guest profile and the comments section, unless further retention is required due to a legal claim.
AccessAccess to sensitive data is restricted to those staff members who genuinely require the information in order to process bookings and provide hospitality services securely.
WithdrawalConsent may be withdrawn at any time, but this does not affect the lawfulness of any data processing carried out prior to the withdrawal. As a result of the withdrawal, the Data Controller may be unable to fulfil the specific request.

4.7. Handling of no-shows and abuse – only where actually applied

If the Data Controller records recurring instances of non-attendance without prior cancellation in order to safeguard capacity, it must document this as a separate data processing operation and carry out a balancing test before commencing operations.

Data processing elementContents
Purpose of data processingTo prevent abusive bookings, repeated no-shows and the unjustified tying up of capacity.
Data processedThe details required to identify the booking; the fact and date of a no-show; the fact of a prior cancellation; and any notes relating to the handling of the matter.
Legal basisArticle 6(1)(f) of the GDPR: the Data Controller’s legitimate interest in safeguarding capacity and business operations. The applicability of this legal basis must be verified by means of a prior data protection impact assessment.
Retention periodUp to 1 year from the date of the person’s last failure to appear, subject to regular review.
Data subject rightsThe data subject has the right to object and may request that the accuracy of the data be reviewed. No substantive disadvantage may be imposed solely on the basis of an automated decision.

4.8. Guest complaints and consumer reports

Data processing elementContents
Purpose of data processingInvestigating and responding to guest complaints, safeguarding consumer rights, documenting the complaint-handling process, and managing legal claims.
Data processedName, contact details, the substance of the complaint, details of the service in question, the date of the complaint, documents relating to the investigation and response, and, where necessary, receipts and other evidence.
Legal basisArticle 6(1)(c) of the GDPR: compliance with a legal obligation to which the Data Controller is subject, in particular Section 17/A of Act CLV of 1997 on consumer protection; and, in the event of legal claims, Article 6(1)(f) of the GDPR.
Retention periodCopies of the written complaint and the reply shall be retained for 3 years in accordance with the Consumer Protection Act; in the event of a legal claim, the necessary data shall be retained until the end of the proceedings or the expiry of the limitation period.
Consequences of data reportingIn the absence of the data required to investigate the complaint, the Data Controller may not necessarily be able to carry out a thorough investigation.

4.9. Documentation of data subjects’ requests and data protection incidents

Data processing elementContents
Purpose of data processingReceiving requests from data subjects to exercise their rights, verifying the identity of the data subject to the extent necessary, assessing the request and providing confirmation of its fulfilment; identifying, assessing, managing and documenting data protection incidents.
Data processedName, contact details, the content of the request or incident, data required for identification, actions taken, responses, deadlines, categories of data concerned and the documents relating to the case.
Legal basisArticle 6(1)(c) of the GDPR: compliance with legal obligations arising from Articles 12–22, 33–34 and Article 5(2) of the GDPR.
Retention periodFor a period of 5 years from the date on which the request or incident is closed, or, in the case of ongoing administrative or court proceedings, until such proceedings are finally concluded.
Consequences of data reportingIn the absence of the data strictly necessary for identification, the Data Controller may refuse to comply with the request in order to protect the data subject’s rights, or may request further identification.

4.10. Social media platforms

Data processing elementContents
Purpose of data processingSocial media communication, guest relations, handling enquiries and messages, and promoting the services of the Dunapark Café.
Data processedThe profile name and public profile details visible on the social media platform, as well as the content and timestamps of posts, reactions and messages, and the data required for administrative purposes.
Legal basisDepending on the purpose of the data processing, Article 6(1)(b) of the GDPR – the preparation or performance of a contract – or Article 6(1)(f) – the Data Controller’s legitimate interest in maintaining community communication and guest relations.
Retention periodDepending on the platform and the relevant settings; messages recorded separately by the Data Controller shall be retained for one year following the closure of the case, or, in the event of a legal dispute, for the period necessary to enforce a claim.
The role of the platformThe operator of the social media platform acts as an independent data controller with regard to the processing of its own platform data. In the case of website statistics, joint data processing may also take place in accordance with the platform’s terms and conditions.

5. Cookies and similar technologies

This website may use cookies and other local storage or tracking technologies. Technologies that are strictly necessary for the website to function are required to provide the service requested by the user, to ensure security, to manage the session and to store consent choices. Analytics, marketing and other non-essential technologies may only be activated following the data subject’s prior consent.

Consent to non-essential cookies is voluntary, can be given on a category-by-category basis, may be withdrawn at any time, and refusing them must not prevent the basic use of the website. Withdrawing consent must be just as easy as giving it.

CategoryTypical targetLegal basisActivationPreservation
Absolutely essentialWebsite loading, session, security, load balancing, booking process, storing cookie preferencesArticle 6(1)(f) of the GDPR; technical necessity as defined in Section 155(4) of Act C of 2003 on Electronic CommunicationsWithout consentA session or a short period justified by the service provider; specified in the list of cookies
FunctionalNon-essential preferences, embedded external service, convenience featureArticle 6(1)(a) of the GDPROnly with prior consentAccording to the actual technology
AnalyticalTraffic, usage statistics, error tracking, website developmentArticle 6(1)(a) of the GDPROnly with prior consentAccording to the service provider’s settings, the recommended maximum is 14 months
MarketingAdvertising measurement, remarketing, conversion tracking, profilingArticle 6(1)(a) of the GDPROnly with prior consentAccording to the service provider’s settings and the list of cookies

The names, providers, purposes, expiry dates and types of the actual cookies, as well as any data transfers to third countries, are set out in a dynamic or regularly updated list of cookies, based on a technical analysis of the website.

6. Data processors, service providers and recipients

Access to personal data is restricted to those employees and contractors who require it to carry out their duties. The Data Controller enters into a contract with data processors who process personal data on its behalf, in accordance with Article 28 of the GDPR.

Service provider / categoryTaskData protection roleData processed / comment
[hosting provider – to be completed]Hosting, servers, backups, loggingData processorData processed on the website and in logs; the contract and the location of the data centre must be verified.
[web developer / system administrator – to be completed]WordPress maintenance, bug fixes, technical administrationData processor, if they have access to personal dataOnly documented, person-specific and necessary access.
PG Info Service and Trading Ltd.Technical support for the online table booking systemIn the case of booking data processed in accordance with the catering establishment’s instructions, the entity is expected to be a data processor; the exact role is to be verified on the basis of the contractThe service provider may also act as an independent data controller in relation to its own account and system administration data processing activities.
[email provider – to be completed]Email delivery and mailboxData processor / role dependent on the serviceCorrespondence regarding enquiries and bookings.
[SMS provider – if active]Delivery of booking notificationsData processorTelephone number, message, technical delivery details.
[spam and security provider – if active]Form protection, bot and fraud preventionDepending on the service, either a data processor or an independent data controllerIP address, device and behavioural data; external CAPTCHA only following a prior technical and data protection assessment.
Authority, court, legal representativeLegal obligation, request from a public authority, legal claimRecipient / independent data controllerOnly in the event of a lawful enquiry or the assertion of a claim, and limited to the necessary data.

7. Data transfers outside the European Economic Area

The Data Controller primarily uses service providers operating within the European Economic Area. However, certain technical, analytical, advertising, email or security service providers may process data in, or provide access to data from, countries outside the European Economic Area.

Such data transfers may only take place in accordance with the conditions set out in Chapter V of the GDPR, for example by means of an adequacy decision, standard contractual clauses adopted by the European Commission and, where necessary, supplementary technical or organisational safeguards. The actual service providers, countries to which data is transferred and the safeguards in place are specified in the cookie list and in the service provider register.

8. Automated decision-making and profiling

The Data Controller does not use any fully automated decision-making in the core processes described in this notice which would produce legal effects concerning the data subject or similarly significantly affect them.

9. Data security

The Data Controller protects personal data against unauthorised or unlawful access, alteration, disclosure, erasure, destruction and loss by means of technical and organisational measures proportionate to the risks involved.

  • access rights that are personalised and based on the minimum necessary authorisation;
  • strong passwords, multi-factor authentication and regular reviews of access rights;
  • encrypted data transmission and secure administration;
  • up-to-date WordPress, plugins, themes and server components;
  • back-up and recovery procedure;
  • logging, vulnerability and incident management;
  • security and contractual checks on data processors;
  • staff training on confidentiality and data protection;
  • Documented deletion or anonymisation upon expiry of retention periods.

10. The data subject’s rights

Under the terms of the GDPR, the data subject may exercise the following rights:

Right to information and access: The data subject may request confirmation as to whether their personal data is being processed, and may request access to the data and to key information regarding the processing.

Right to rectification: The data subject may request that any inaccurate data be corrected and that any incomplete data be supplemented.

Right to erasure: The data subject may request the erasure of their personal data in the circumstances set out in the GDPR. Erasure may not be requested if the processing is necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims.

Right to restriction: The data subject may request that the processing of their data be restricted in the circumstances set out in the GDPR.

Right to data portability: In the case of automated data processing based on consent or a contract, the data subject may request to receive the data they have provided in a structured, commonly used, machine-readable format, or – where technically feasible – that the data be transferred to another data controller.

The right to protest: The data subject may object at any time to the processing of data on the grounds of Article 6(1)(f) of the GDPR on grounds relating to their particular situation. In such cases, the Data Controller shall no longer process the data, unless it demonstrates compelling legitimate grounds for the processing, or the data is required for the establishment, exercise or defence of legal claims.

Withdrawal of consent: Consent may be withdrawn at any time without giving any reason. Withdrawal does not affect the lawfulness of any data processing carried out prior to withdrawal.

Complaints and legal remedies: The data subject may lodge a complaint with the supervisory authority and may bring the matter before a court.

11. Handling requests from data subjects

The data subject may send their request to the Data Controller’s data protection contact details provided in point 2. The Data Controller shall respond to the request without undue delay, but no later than one month from the date of receipt. The complexity of the request or the number of requests may justify an extension of the deadline by a further two months; the Data Controller will provide information on this within the first month.

If the Data Controller has reasonable doubts as to the identity of the person submitting the request, it may only request further information necessary for identification purposes. As a general rule, there is no charge for complying with requests. In the case of manifestly unfounded or particularly repetitive or excessive requests, the Data Controller may, in accordance with the provisions of the GDPR, charge a reasonable fee or refuse to take the requested action.

12. Legal remedies

If the data subject considers that the processing of their personal data infringes the GDPR, they may lodge a complaint with the National Authority for Data Protection and Freedom of Information:

Name of authorityNational Authority for Data Protection and Freedom of Information
Title1055 Budapest, 9–11 Falk Miksa Street.
Postal address1363 Budapest, PO Box 9.
Emailugyfelszolgalat@naih.hu
Telephone+36 (1) 391-1400
Websitehttps://www.naih.hu/

You may also bring the matter before the relevant court. You may bring the action – at your discretion – before the court with jurisdiction over the Data Controller’s registered office or over your own place of residence or habitual residence.

13. Amendments to the prospectus

The Data Controller may amend this privacy notice, in particular in the event of changes to the website’s functions, data processing procedures, service providers or the legal framework. The current version is available on the website. The Data Controller will provide separate notification in an appropriate manner of any significant changes that substantially affect the rights of data subjects or the conditions of data processing.

Date of entry into force: 25 July 2026.