Privacy policy

1. Details of the Data Controller

Name of the Data Controller: HOTEL CABERNET Szállodaüzemeltető és Borértékesítő Korlátolt Felelősségű Társaság

Registered office: 7772 Villánykövesd, Petőfi utca 29., Hungary

Company registration number: 02 09 076752

Tax number: 23087866-2-02

Representative: Katalin Szvitacs-Mokos

Telephone: +36 72 493 200

E-mail: info@hotelcabernet.hu

Website: https://hotelcabernet.hu/

NTAK registration number: SZ19000430

2. Purpose and Scope of this Privacy Policy

The purpose of this Privacy Policy is to provide clear and understandable information about what personal data the Data Controller processes, for what purposes, on what legal basis, for how long and in what manner in connection with the provision of Hotel Cabernet’s services, operation of the website, communication, bookings, marketing and other business activities.

This Privacy Policy applies in particular to website visitors, persons requesting offers, persons making bookings, hotel guests, purchasers and users of gift vouchers, newsletter and Cabernet Club subscribers, participants of events and programmes, and natural persons who contact the Company.

Effective date: 14 August 2026

Version: 2.0

This Privacy Policy replaces the previous Privacy Policy effective from 15 October 2018.

3. Applicable Legislation and Principles

The Data Controller processes personal data in accordance with, in particular:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR);
  • Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Hungarian Data Protection Act);
  • applicable Hungarian legislation concerning electronic commerce services and information society services;
  • tourism, accommodation, accounting, tax, immigration and other sector-specific legislation applicable to the relevant data processing activities.

The Data Controller processes personal data lawfully, fairly and transparently; collects data for specified purposes; processes only the data necessary for those purposes; strives to ensure accuracy; stores data only for as long as necessary; and protects personal data using appropriate technical and organisational measures.

4. Definitions

  • Data Subject: an identified or identifiable natural person.
  • Personal data: any information relating to an identified or identifiable natural person.
  • Processing: any operation or set of operations performed on personal data.
  • Data Controller: the entity that determines the purposes and means of processing personal data.
  • Data Processor: an entity that processes personal data on behalf of the Data Controller.
  • Recipient: a person or entity to whom personal data is disclosed.
  • Consent: a freely given, specific, informed and unambiguous indication of the Data Subject’s wishes.

5. Detailed Rules on Data Processing

5.1 Requests for Offers

Purpose of processing Preparing a quotation for accommodation or an event requested by the prospective customer and maintaining communication.
Data processed Name, e-mail address, telephone number, arrival/departure dates, catering/board arrangement, number of rooms, comments, promotional code, package and, where necessary, any additional information provided for the preparation of the offer.
Legal basis Primarily Article 6(1)(b) GDPR – taking steps at the request of the Data Subject prior to entering into a contract. A separate appropriate legal basis is required for marketing purposes.
Retention period If no booking is made: 6 months from the last communication. If the request for an offer results in a booking or other contractual relationship, the data will be processed in accordance with the retention rules applicable to that relationship.
Recipients / Data Processors Hosting provider, booking/PMS system, e-mail service provider – the actual service providers are listed in Section 6.
Source of data Directly from the Data Subject.
Consequences of failure to provide data Without the data necessary to prepare the offer, the preparation of the offer or communication may be limited.

5.2 Accommodation Bookings and Performance of the Contract

Purpose of processing Recording bookings, securing rooms, providing accommodation and related services, and maintaining communication.
Data processed Name, billing details, address, e-mail address, telephone number, arrival/departure dates, room, board arrangement, comments, package, promotional code, payment-related data and other data necessary for fulfilling the booking.
Legal basis Article 6(1)(b) GDPR – performance of a contract; for data required by law, Article 6(1)(c) GDPR.
Retention period Data relating to the booking and the accommodation services contract will be processed for as long as necessary to perform the contract and handle any potential legal claims. Data and documents qualifying as accounting records are retained for 8 years. Other booking and communication data that are no longer necessary will be deleted once the purpose has ceased, or processed in accordance with the retention rules configured by the Data Controller in the PMS.
Recipients / Data Processors Previo / PMS, hosting provider, e-mail service provider, payment service provider, accountant and, where necessary, cooperating partners.
Source of data Directly from the Data Subject.
Consequences of failure to provide data The booking/service cannot be fulfilled without the essential data.

5.3 Guest Registration, Guest Data, VIZA/NTAK and Other Mandatory Data Transfers

Purpose of processing Identification of guests, compliance with statutory obligations, provision of data required for accommodation and tourism records, and fulfilment of tourism tax and other obligations.
Data processed Data required by applicable legislation and the accommodation management system, including guest identification data, stay details, required identification document data, nationality and other mandatory data.
Legal basis Primarily Article 6(1)(c) GDPR – compliance with a legal obligation; for contractual elements, Article 6(1)(b) GDPR. The consent-based legal basis included in the current policy should not generally be maintained for mandatory data processing.
Retention period Guest data processed by the accommodation provider for the purpose of fulfilling VIZA reporting obligations are retained until the last day of the first year following the date on which the data became known to the provider. Data transmitted to the VIZA system are retained by the system for a maximum of 2 years. For other data that must be retained under specific legislation, the retention period prescribed by that legislation applies.
Recipients / Data Processors VIZA, NTAK, KSH and other authorities/systems authorised by law; PMS/Previo and the technical service providers used.
Source of data Directly from the Data Subject.
Consequences of failure to provide data Without data required by law, the lawful provision of accommodation services may be prevented.

5.4 Invoicing, Accounting and Tax Obligations

Purpose of processing Issuing invoices, accounting, and fulfilling tax and accounting obligations.
Data processed Name, address, billing details, services used and necessary payment-related data.
Legal basis Article 6(1)(c) GDPR – compliance with a legal obligation.
Retention period 8 years for accounting records and documents directly or indirectly supporting accounting records, in accordance with applicable accounting legislation.
Recipients / Data Processors Hungarian Tax and Customs Administration (NAV), accountant, invoicing software/PMS, bank or payment service provider, and other recipients authorised by law.
Source of data Directly from the Data Subject.
Consequences of failure to provide data Without billing data, lawful invoicing and provision of the service cannot be ensured.

5.5 Gift Vouchers

Purpose of processing Issuing, registering, redeeming and verifying gift vouchers.
Data processed Purchaser’s name, e-mail address, telephone number, recipient’s name, voucher number, value, issue date and validity period, and redemption data.
Legal basis Article 6(1)(b) GDPR where necessary for performance of a contract; Article 6(1)(c) GDPR for accounting and tax-related data. A separate legal basis is required for marketing purposes.
Retention period During the validity period of the voucher and, following redemption, for as long as necessary to comply with accounting and legal obligations. Data and documents qualifying as accounting records are retained for 8 years.
Recipients / Data Processors Invoicing/accounting system, e-mail service provider and technical service providers.
Source of data Directly from the Data Subject.
Consequences of failure to provide data The voucher cannot be issued or redeemed without the necessary data.

5.6 Contact Forms and E-mail

Purpose of processing Responding to enquiries from prospective customers and guests and handling requests.
Data processed Name, e-mail address, telephone number, message and any other data voluntarily provided in the enquiry.
Legal basis Article 6(1)(b) GDPR where the contact is initiated by the Data Subject in connection with steps prior to entering into a contract; for other general enquiries, Article 6(1)(a) or (f) GDPR depending on the specific purpose.
Retention period 6 months from the last communication. If the enquiry results in a contract, booking, complaint handling or other legal matter, the data will be processed according to the retention rules applicable to that processing activity.
Recipients / Data Processors E-mail and hosting service providers and employees involved in communication.
Source of data Directly from the Data Subject.
Consequences of failure to provide data Without contact details, the enquiry cannot be answered or can only be answered to a limited extent.

5.7 Newsletter, Marketing and Cabernet Club

Purpose of processing Communicating promotions, offers, programmes, news and the benefits of the Cabernet Club.
Data processed Name, e-mail address, date of subscription, source of consent, unsubscribing information and technical data relating to campaigns; profiling is used only where it is actually implemented and appropriately documented.
Legal basis For electronic direct marketing, as a general rule, freely given consent under Article 6(1)(a) GDPR, taking into account applicable electronic communications legislation. Consent may be withdrawn at any time.
Retention period Data relating to newsletters and marketing communications are processed until consent is withdrawn or for as long as necessary to demonstrate the existence of consent.
Recipients / Data Processors MailerLite Limited, 88 Harcourt Street, Dublin 2, D02 DK18, Ireland (company registration number: 689826) – Data Processor. MailerLite processes personal data uploaded to the service by Hotel Cabernet or provided by persons subscribing to the newsletter on the instructions of Hotel Cabernet as Data Controller. For customers established in the EEA, subscriber data are stored within the European Union, in data centres in Germany or the Netherlands used by MailerLite. MailerLite uses further Data Processors, including Google Cloud EMEA Ltd. and Vercom S.A.
Source of data Directly from the Data Subject.
Consequences of failure to provide data Failure to subscribe does not prevent accommodation bookings or use of the services.

5.8 Website, Server Logs and Technical Data

Purpose of processing Ensuring the secure and proper operation of the website, troubleshooting, IT security and essential functionality.
Data processed IP address, date and time, URL, browser and device technical data, error messages and server log data.
Legal basis Depending on the purpose of the processing, Article 6(1)(f) GDPR – legitimate interest, or, where necessary, compliance with a legal obligation.
Retention period Server logs are processed for as long as necessary for the secure operation and maintenance of the service. Tárhely.Eu retains server logs for 52 weeks on a rotation basis, or, depending on contractual and statutory obligations, for a maximum of 14 months.
Recipients / Data Processors Tárhely.Eu Szolgáltató Kft. (registered office: 1144 Budapest, Ormánság utca 4. X. emelet 241., Hungary) – hosting and server operation provider.
Source of data Directly from the Data Subject.
Consequences of failure to provide data Certain technical data are necessary for the operation of the website.

5.9 Cookies, Analytics and Marketing Technologies

Purpose of processing Operating the website, measuring visitor numbers, improving user experience and, where consent is provided, marketing/remarketing.
Data processed Depending on the type of cookie and online technology, online identifiers, device and browser data, visit events, campaign information, session data and consent data.
Legal basis For necessary cookies, processing necessary for website operation; for analytics and advertising cookies, prior consent. The CookieYes consent management system records consent preferences.
Retention period Varies by cookie. According to the CookieYes scan performed on 14 August 2026: _ga and ga: 1 year 1 month 4 days; _gcl_au: 3 months; _fbp: 3 months; hjSessionUser: 1 year; hjSession: 1 hour; IDE: 1 year 24 days; test_cookie: 15 minutes; _GRECAPTCHA: 6 months; cookieyes-: 1 year; vchideactivationmsg: 3 years; vchideactivationmsg_vc11: 3 years; session cookies remain active until the end of the session; rc::a and rc::f: do not expire according to CookieYes.
Recipients / Data Processors CookieYes – consent management; Google (Analytics, Tag Manager, reCAPTCHA, DoubleClick); Meta (Facebook Pixel); Hotjar; Visual Composer / WPBakery Page Builder. The data protection role of the service providers and any data transfers must be handled in accordance with the current privacy terms of the relevant services.
Source of data Directly from the Data Subject.
Consequences of failure to provide data Apart from refusing non-essential cookies, the basic functions of the website can generally still be used.

5.10 Facebook and Instagram Presence

Purpose of processing Maintaining Hotel Cabernet’s social media presence, communication, content sharing and providing information to interested persons.
Data processed Data provided by the Data Subject on Facebook and Instagram and data generated through interactions with Hotel Cabernet’s pages, including profile data, comments, reactions, messages and other interaction data.
Legal basis Article 6(1)(f) GDPR – the Data Controller’s legitimate interest in social media communication, informing persons interested in its services and maintaining contact.
Retention period
Recipients / Data Processors Meta Platforms Ireland Limited (Facebook and Instagram). Meta acts as an independent Data Controller for processing carried out on its own platforms; for certain functions, such as Page Insights, the Data Controller and Meta may qualify as joint controllers.
Source of data Directly from the Data Subject and from interactions taking place on Facebook and Instagram.
Consequences of failure to provide data Without a Facebook or Instagram account, or without using the platform selected by the Data Subject, the Data Subject cannot contact Hotel Cabernet through the platform or interact with Hotel Cabernet’s content on that platform.

5.11 CCTV System

Purpose of processing Protection of life, physical safety and property, security of the accommodation facility and persons staying there, investigation of incidents and enforcement/defence of legal claims.
Data processed Image recordings of the Data Subject, as well as the time and location of recording. Cameras are located in the following areas: car park, entrance, terrace, hall, Borgerező restaurant, cellar restaurant, kitchen, Fehér restaurant, garden and service yard.
Legal basis Primarily Article 6(1)(f) GDPR – legitimate interest, taking into account the specific Hungarian rules applicable to video surveillance.
Retention period Unless used, recordings are retained for no longer than 3 working days from the time of recording and are then deleted. If a recording is used in connection with an unlawful act, damage or other legal claim, it may be retained for as long as necessary in the relevant legal or official proceedings.
Recipients / Data Processors No external Data Processor. The data are processed by the Data Controller’s own employees.
Source of data Directly from the Data Subject / CCTV system.
Consequences of failure to provide data Entering areas monitored by cameras results in image recording. The location of the cameras is indicated in this Privacy Policy and by signs/pictograms on site.

5.12 Events, Programmes and Photo/Video Recordings

Purpose of processing Organising and documenting events and programmes and, where an appropriate legal basis exists, using recordings for marketing purposes.
Data processed Name, contact details, registration data; photographs and video recordings only in accordance with the appropriate legal basis and information provided to the Data Subject.
Legal basis For event organisation: performance of a contract / compliance with a legal obligation; for public use for marketing purposes: the applicable specific legal basis.
Retention period For as long as necessary for communication and marketing purposes, but no longer than 3 years.
Recipients / Data Processors The external photographer/Data Processor commissioned to photograph the particular event. The photographer may vary from event to event. If the photographer also processes the recordings for their own independent purposes, they may qualify as an independent Data Controller in respect of such processing.
Source of data Directly from the Data Subject.
Consequences of failure to provide data Participation may be limited without the necessary registration data.

5.13 Complaint Handling and Legal Claims

Purpose of processing Investigating and responding to complaints and submitting, enforcing and defending legal claims.
Data processed Name, contact details, content of the complaint, related documents and data necessary for resolving the matter.
Legal basis Article 6(1)(c) GDPR – compliance with a legal obligation, and Article 6(1)(f) GDPR – legal claims and legitimate interests.
Retention period The record of the complaint and the response to the complaint are retained for 5 years from the date the complaint was submitted.
Recipients / Data Processors No external Data Processor. The data are processed by the Data Controller’s employees.
Source of data Directly from the Data Subject.
Consequences of failure to provide data Investigation of the complaint may be limited without the necessary data.

5.14 Restaurant Table Reservations

Purpose of processing Recording and managing restaurant table reservations and maintaining the communication necessary to fulfil the reservation.
Data processed Name, telephone number, number of persons and reservation date/time.
Legal basis Article 6(1)(b) GDPR – taking steps at the request of the Data Subject necessary to fulfil the reservation.
Retention period For as long as necessary to fulfil the reservation, followed by deletion once the data are no longer necessary for providing the service; in the event of a legal obligation or legal claim, for as long as necessary.
Recipients / Data Processors Restaurant Agent Inc. / TableAgent. According to the publicly available privacy policy, the TableAgent service is operated by Restaurant Agent Inc., and the service provider shares reservation data with restaurants for the purpose of managing reservations.
Source of data Directly from the Data Subject.
Consequences of failure to provide data Without providing a name and telephone number, the table reservation cannot be fulfilled or can only be fulfilled to a limited extent.

International data transfer: The provider of the TableAgent service is located in the United States. Hotel Cabernet uses the service under TableAgent’s general terms and conditions, in the free plan. The provider’s current privacy and data transfer safeguards must be reviewed before use and on an ongoing basis.

5.15 Recording of Guest Consumption

Purpose of processing Recording and accounting for guests’ restaurant consumption and, where consumption can be charged to a room, linking it to the accommodation accounting system.
Data processed Consumption items, quantities and amounts, as well as table or room number. The guest’s name is not recorded in the system.
Legal basis Article 6(1)(b) GDPR – performance of the ordered service; Article 6(1)(c) GDPR where accounting/tax obligations apply.
Retention period Data forming part of accounting records and accounting records underlying such data must be retained for 8 years in accordance with accounting legislation. Data processed exclusively for operational purposes are retained until the relevant purpose ceases.
Recipients / Data Processors Esystem Magyarország Korlátolt Felelősségű Társaság – provider of the hospitality accounting and business management system, acting as Data Processor. Registered office: 1097 Budapest, Vaskapu utca 20.; company registration number: 01-09-284903; tax number: 25708736-2-43.
Source of data Data entered by the Data Controller’s employees when recording consumption.
Consequences of failure to provide data Consumption and the related accounting cannot be processed or can only be processed to a limited extent.

5.16 Guest Wi-Fi

Purpose of processing Providing wireless internet access to guests.
Data processed Technical data necessary for using the Wi-Fi connection may be processed temporarily when establishing and maintaining the connection. No persistent, personally identifiable usage logging is carried out.
Legal basis Article 6(1)(b) GDPR where processing is necessary to provide the Wi-Fi service.
Retention period No persistent Wi-Fi usage logging is carried out, therefore no personal data are retained for this purpose. Technical data necessary for the connection may be processed for no longer than the duration of the relevant network connection.
Recipients / Data Processors No external Data Processor is used for Wi-Fi usage logging.
Source of data Directly from the Data Subject and from the network connection of the Data Subject’s device.
Consequences of failure to provide data The Wi-Fi service cannot be used.

6. Data Processors and Service Providers

The following list is a working list based on the service providers included in this Privacy Policy and the systems known to be used in Hotel Cabernet’s operations. Before final publication, each service provider and its legal role must be verified.

Service provider / system Function Data Data protection role Registered office
Tárhely.Eu Szolgáltató Kft. Website and e-mail/hosting Technical and contact data Data Processor 1097 Budapest, Könyves Kálmán körút 12–14.; company registration number: 01-09-909968; tax number: 14571332-2-42.
Previo.hu Kft. PMS / online booking system Guest and booking data Data Processor 1119 Budapest, Petzvál József u. 4/A.; company registration number: 01-09-397840; tax number: 27786330-2-43; tel.: +36 1 445 3737; e-mail: adminisztracio@previo.hu; Appendix 3 to the Previo General Terms and Conditions contains a Data Processing Agreement.
Chrome-Soft Informatikai, Kiadói és Grafikai Kft. HotRest PMS / hotel system Guest and booking data Data Processor 9700 Szombathely, Semmelweis Ignác utca 4–6. 1st floor, door 103; company registration number: 18-09-115052; tax number: 13306612-2-18.
MailerLite Limited Newsletter and marketing automation Name, e-mail address, campaign data Data Processor 88 Harcourt Street, Dublin 2, D02 DK18, Ireland.
Google Ireland Limited Google Analytics / Google Ads Online identifiers, event and campaign data Independent Data Controller and/or Data Processor depending on the service Gordon House, Barrow Street, Dublin 4, Ireland; registration number: 368047; VAT: IE6388047V.
Meta Platforms Ireland Limited Facebook / Instagram / Meta Pixel Online identifiers, interactions, campaign and measurement data Independent Data Controller, joint controller and/or Data Processor depending on the service Merrion Road, Dublin 4, D04 X2K5, Ireland.
Vukovics Hajnalka e.v. Accounting Billing and accounting data Data Processor 7622 Pécs, Verseny utca 1/B.; tax number: 64992396-1-22; registration number: 12613873.
KBOSS.hu Kft. / Számlázz.hu Invoicing, electronic invoicing Billing and invoice data Data Processor / service provider 1031 Budapest, Záhony utca 7.; company registration number: 01-09-303201; tax number: 13421739-2-41.
Esystem Magyarország Korlátolt Felelősségű Társaság Recording guest consumption Consumption items, amounts and table or room number Data Processor 1097 Budapest, Vaskapu utca 20.; company registration number: 01-09-284903; tax number: 25708736-2-43.
TableAgent / Restaurant Agent Inc. Restaurant table reservation system Name, telephone number, number of persons, reservation date/time Independent Data Controller / service provider 4858 Mercury St. Suite 200, San Diego, CA 92111, USA.
WordPress / Advanced Contact Form 7 DB Recording website forms and booking data in Hotel Cabernet’s WordPress database Personal data provided through booking and other forms Data Controller’s own system The plugin operates within Hotel Cabernet’s own WordPress system; hosting provider: Tárhely.Eu.
Teya Iceland hf. Online / card payments Payment and transaction data Independent Data Controller / Data Processor depending on the service Katrínartún 4, 105 Reykjavík, Iceland; registration number: 440686-1259; EEA-based service provider.
Wi-Fi system Providing guest Wi-Fi Technical data required for the connection; no persistent usage logging Data Controller’s own system No persistent logging.

6.1 Intermediaries and Voucher Sales Partners

Partner Role Processing / data transferred
Booking.com B.V. Accommodation intermediary platform, independent Data Controller Guest data necessary for arranging and fulfilling the booking.
Szallas Group Zrt. (Szallas.hu, SzállásGuru) Accommodation and voucher intermediary platform, independent Data Controller Data necessary for bookings, offer requests and voucher redemption.
ÉlményPláza Kft. Experience voucher intermediary, independent Data Controller Data necessary for voucher redemption and provision of the service.
Skoopy Kft. (Bónusz Brigád) Voucher/service intermediary, independent Data Controller Data necessary for voucher redemption and provision of the service.
EXTRÉM Élményajándékok Kft. (Meglepkék) Experience voucher intermediary, independent Data Controller Data necessary for voucher redemption and provision of the service.
FDB Kereskedelmi és Szolgáltató Kft. (Feldobox) Experience voucher/experience package intermediary, independent Data Controller Data necessary for redeeming the Feldobox experience package/experience card and providing the service.

7. Transfers of Personal Data to Third Countries

Where the Data Controller uses a service provider or technology through which personal data may be transferred outside the European Economic Area, the Data Controller carries out such transfers only with appropriate safeguards in accordance with applicable data protection legislation.

The third-country data transfers and safeguards currently identified are:

  • Hotjar: Data are primarily stored in the EU (Ireland), but in limited cases access to or transfers outside the EU may occur, for which Hotjar applies Standard Contractual Clauses (SCCs) and other appropriate safeguards.
  • MailerLite: For customers billed within the EEA, subscriber data processed by MailerLite Limited (Ireland) remain within the EU; any potential third-country transfers by MailerLite’s subcontractors are subject to appropriate safeguards applied by MailerLite, such as SCCs/DPF.
  • Meta: Meta Platforms, Inc. and its US subsidiaries are certified under the EU–US Data Privacy Framework (DPF).
  • Google: According to Google’s information on international data transfers, Google LLC and relevant US subsidiaries are certified under the EU–US Data Privacy Framework (DPF); where the DPF does not apply, Google uses the Standard Contractual Clauses (SCCs) adopted by the European Commission where appropriate.
  • TableAgent: The service provider operates in the United States. TableAgent applies data protection and data security measures intended to comply with GDPR requirements and, based on its contractual documentation, provides appropriate safeguards for transfers of personal data to third countries, in particular the use of Standard Contractual Clauses (SCCs).

8. Data Security

The Data Controller applies technical and organisational measures proportionate to the risks in order to protect personal data. The purpose of these measures is to ensure the confidentiality, integrity and availability of personal data.

  • Access to personal data is restricted to the extent necessary for the relevant job role and task.
  • Only authorised employees may access IT systems and online services.
  • Individual user accounts and appropriately strong passwords are required when using the systems.
  • WordPress, PMS and other online systems and their plugins must be updated regularly.
  • Backups provided by the hosting provider are supplemented with additional backups necessary for business continuity, in accordance with actual technical practices.
  • Paper documents containing personal data must be stored in a manner that protects them against unauthorised access.
  • Personal data breaches are handled and documented internally by the Data Controller.
  • Once the applicable retention period has expired, personal data must be deleted or destroyed, except for data that must be retained for a longer period under applicable law.

9. Personal Data Breaches

A personal data breach is a security breach that results in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, personal data transmitted, stored or otherwise processed.

The Data Controller handles personal data breaches in accordance with the procedure prescribed by the GDPR and, where required by law, notifies the supervisory authority and the affected Data Subjects.

Internal contact for reporting incidents: Hotel Cabernet Szállodaüzemeltető és Borértékesítő Kft.

Primary e-mail: info@hotelcabernet.hu

Telephone: +36 72 493 200

The Data Controller’s representative/management acts as the contact person.

Contact person: Katalin Szvitacs-Mokos

10. Rights of Data Subjects

Subject to the conditions set out in the GDPR, the Data Subject may exercise the following rights:

  • Right to information and access: the Data Subject may request information as to whether their personal data are being processed by the Data Controller and may request access to the processed data.
  • Right to rectification: the Data Subject may request the rectification of inaccurate personal data and completion of incomplete data.
  • Right to erasure: under certain conditions, the Data Subject may request the deletion of their personal data.
  • Right to restriction of processing: under certain circumstances, the Data Subject may request restriction of processing.
  • Right to data portability: where personal data are processed by automated means on the basis of consent or a contract, and the conditions set out in the GDPR are met, the Data Subject may request the transfer of their personal data.
  • Right to object: where processing is based on legitimate interests, the Data Subject may object to the processing. In the case of processing for direct marketing purposes, the right to object is particularly broad.
  • Right to withdraw consent: where processing is based on consent, the Data Subject may withdraw their consent at any time.

Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.

The Data Subject may exercise the above rights by e-mail at info@hotelcabernet.hu or by post at the Data Controller’s registered office:

Hotel Cabernet Kft.
7772 Villánykövesd, Petőfi utca 29., Hungary

11. Handling of Data Subject Requests

The Data Controller handles requests from Data Subjects within the deadlines and in accordance with the procedures prescribed by the GDPR. Where the complexity or number of requests justifies it, the deadline may be extended under the conditions set out in the GDPR.

Where necessary, the Data Controller may request additional information to verify the identity of the Data Subject in order to protect personal data.

12. Remedies

The Data Subject may primarily contact the Data Controller with a complaint at info@hotelcabernet.hu.

The Data Subject has the right to lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH) and may seek judicial remedies under the GDPR and applicable Hungarian law.

NAIH current official contact details:

National Authority for Data Protection and Freedom of Information (NAIH)
1055 Budapest, Falk Miksa utca 9–11., Hungary
Postal address: 1363 Budapest, Pf. 9., Hungary
E-mail: ugyfelszolgalat@naih.hu
Telephone: +36 (1) 391 1400

The NAIH has a separate online platform for reporting personal data breaches.

13. Automated Decision-Making and Profiling

The Data Controller does not currently use decision-making based solely on automated processing that produces legal effects concerning the Data Subject or similarly significantly affects the Data Subject.

Through Google Analytics, Google Ads, Meta Pixel and Hotjar services used on the website, Hotel Cabernet may, subject to the required consent, process data relating to website use, visits and the effectiveness of marketing activities.

The Data Controller does not use these services to make automated decisions concerning Data Subjects that produce legal effects or similarly significant effects.

Any profiling or audience creation carried out by marketing and analytics services may arise from the operation of the respective service provider; the Data Controller relies on these services only where the user has provided the appropriate consent.

The detailed conditions of processing and the cookies used are set out in the cookie-related section of this Privacy Policy and in the CookieYes consent management interface.

14. Data of Minors

During the provision of hotel services, data relating to minor guests may also be processed to the extent necessary for providing the service and fulfilling statutory obligations.

The legal basis for processing is always determined by the specific purpose and applicable legislation; processing necessary for providing the service should not generally be treated as being based on consent.

15. Cookies and Online Technologies – Separate Appendix

A separate, easily accessible cookie policy and CookieYes consent management interface are available to users regarding cookies and similar technologies used on the website.

Based on the successful CookieYes scan performed on 14 August 2026 at 12:35:01 UTC, the following cookies were identified:

  • Google Analytics / GA4 – analytics cookies: _ga and ga*; retention period: 1 year 1 month 4 days.
  • Google Ads / remarketing – advertising cookies: IDE; retention period: 1 year 24 days. The DoubleClick test_cookie has a retention period of 15 minutes.
  • Google Tag Manager – analytics technology: _gcl_au; retention period: 3 months.
  • Meta Pixel – advertising/marketing technology: _fbp; retention period: 3 months.
  • Based on the CookieYes scan of 14 August 2026, no separate cookie associated with YouTube or other embedded content was identified.
  • Based on the CookieYes scan of 14 August 2026, no separate cookie associated with Google Maps was identified.
  • Based on the CookieYes scan of 14 August 2026, no separate cookie associated with the Previo booking system was identified in the scanned cookie list.
  • CookieYes – consent management: cookieyes-*; retention period: 1 year.
  • WordPress / website – necessary cookies: wpEmojiSettingsSupports (session) and wordpress_test_cookie (session).
  • Google reCAPTCHA – necessary cookies: _GRECAPTCHA (6 months), rc::a (no expiry), rc::f (no expiry), rc::c (session), rc::b (session).
  • Hotjar – analytics cookies: hjSessionUser* (1 year) and hjSession* (1 hour).

Cookie list – CookieYes scan, 14 August 2026:

Necessary (8): _GRECAPTCHA, rc::a, rc::f, wpEmojiSettingsSupports, rc::c, rc::b, cookieyes-*, wordpress_test_cookie.

Functional (2): vchideactivationmsg and vchideactivationmsg_vc11, both with a retention period of 3 years.

Analytics (6): _gcl_au, ga, _ga, _fbp, hjSessionUser, hjSession*.

Advertising (2): test_cookie and IDE.

Performance: 0.

Uncategorised: 0.

16. Data Retention Matrix

Processing activity Retention period Legal basis
Request for offer 6 months from the last communication Article 6(1)(b) GDPR / where applicable (f)
Accommodation booking Booking data may be processed for as long as necessary for contract performance, handling legal claims and complying with statutory obligations. Data supporting accounting records: at least 8 years. Automatic deletion by the service provider’s systems is not guaranteed in Previo and HotRest; retention is aligned with the processing purpose and applicable statutory obligations. Article 6(1)(b) and (c) GDPR
Guest data / VIZA / NTAK Hotel Cabernet processes VIZA-related guest data until the last day of the first year following the date on which the data became known. The VIZA system retains submitted data for a maximum of two years. NTAK reporting itself does not impose a general 5- or 8-year retention period for personal data in the PMS; longer retention may be justified by other statutory obligations, particularly retention of accounting records. Article 6(1)(c) GDPR
Invoicing 8 years Article 6(1)(c) GDPR
Gift vouchers During validity/redemption, followed by the necessary legal and accounting period; accounting records: 8 years Article 6(1)(b) and (c) GDPR
Newsletter / Cabernet Club Marketing: until consent is withdrawn Article 6(1)(a) GDPR
Contact 6 months from the last communication Article 6(1)(b), (a) or (f), depending on the purpose
Google Analytics _ga and ga* cookies identified by CookieYes: 1 year 1 month 4 days Article 6(1)(a) GDPR – consent
Google Ads / remarketing IDE: 1 year 24 days; test_cookie: 15 minutes Article 6(1)(a) GDPR – consent
Meta / Pixel _fbp: 3 months Article 6(1)(a) GDPR – consent
CCTV recordings Unless used, no longer than 3 working days; in the event of unlawful activity, damage or legal claim, for as long as necessary in the relevant proceedings Article 6(1)(f) GDPR
Events / photo / video For as long as necessary for communication/marketing purposes, up to 3 years According to the legal basis applicable to the processing
Complaints 5 years Article 6(1)(c) and (f) GDPR
CookieYes / cookies Varies by cookie; according to the 14 August 2026 scan: cookieyes-* 1 year; _gcl_au 3 months; _ga/ga* 1 year 1 month 4 days; _fbp 3 months; Hotjar 1 year/1 hour; IDE 1 year 24 days; test_cookie 15 minutes; _GRECAPTCHA 6 months; session cookies until the end of the session; vchideactivationmsg* 3 years Necessary cookies: operation; analytics/advertising: consent
TableAgent / restaurant table reservations The service provider does not specify a specific period; data are retained for as long as necessary to manage the reservation and, in the event of a legal obligation/dispute, for as long as necessary Article 6(1)(b) GDPR
E-system / guest consumption Data relating to accounting records: 8 years; operational data only: until the purpose ceases Article 6(1)(b) and (c) GDPR
WordPress / Advanced CF7 DB 1 year Article 6(1)(b), (c) or (f) GDPR depending on the purpose of the form
Teya payment service Transaction and payment data are retained for as long as necessary to provide the service and fulfil legal obligations; Teya’s public documentation does not specify one single retention period applicable to all transactions According to the service and legal obligation
Wi-Fi No persistent usage logging; therefore no personal data are retained for this purpose Article 6(1)(b) GDPR

17. Final Provisions

The Data Controller reserves the right to amend this Privacy Policy in response to changes in legislation, technology or operations. The amended Privacy Policy will be published on the website and, where required by law, Data Subjects will be informed in an appropriate manner.

Last reviewed: 14 August 2026

Approved by: Katalin Szvitacs-Mokos, representative of Hotel Cabernet Kft.

One of our offers is nice?


Click on the booking button and select the desired package offer from the drop-down menu, or request our offer!

Do you have a special request?
We are happy to assist you!

Book a room Ask for an offer Buy a Coupon