Cookie settings
Information about the cookies used on this website, their purpose, and how they are managed.
COOKIE POLICY
relating to the visitbudavar.hu, visitbudavar.com and visitbudavar.eu websites
Effective from: 30 June 2026
Details of the Data Controller:
| Item | Details |
|---|---|
| Data Controller: | Budavári Turisztikai Korlátolt Felelősségű Társaság (Buda Castle Tourism Ltd.) |
| Company registration number: | 01-09-449584 |
| Registered office: | 1011 Budapest, Iskola utca 16. |
| E-mail: | budavariturisztika@budavar.hu |
| Website: | https://visitbudavar.hu / https://visitbudavar.com / https://visitbudavar.eu |
| Managing Director: | Naszódi Péter |
| Data Protection Officer (DPO): | Fodor Gabriella – adatvedelem@turisztika.budavar.hu |
1. GENERAL PROVISIONS
1.1. This Cookie Policy (hereinafter: the Policy) applies to the visitbudavar.hu, visitbudavar.com and visitbudavar.eu websites (hereinafter jointly: the Website) operated by Budavári Turisztikai Korlátolt Felelősségű Társaság (Buda Castle Tourism Ltd.) (hereinafter: the Controller or the Company).
1.2. The purpose of the Policy is to provide Data Subjects (visitors to and users of the Website) with transparent, clear and detailed information about the cookies used on the Website, their purpose and legal basis, and the manner of giving and withdrawing consent.
1.3. The Policy has been prepared on the basis of the following legislation:
-
Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR),
- Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Infotv.),
- Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (Ekertv.),
- Section 155(4) of Act C of 2003 on Electronic Communications (Eht.),
- the guidelines of the European Data Protection Board (EDPB) on consent and cookie management.
1.4. This Policy shall be applied together with the Company's Privacy Notice. The general conditions of data processing, the detailed description of data subject rights and the available legal remedies are set out in the Privacy Notice published on the Website.
2. WHAT IS A COOKIE?
2.1. A cookie is a small text file that the Website's web server places, via the visitor's browser, on the visitor's computer, mobile phone, tablet or other terminal equipment (hereinafter: the Device). The cookie enables the web server to recognise the Device on the next visit. A cookie does not in itself contain personal data – it typically stores a short identifier or a setting value.
2.2. Cookies may serve various purposes: they may be essential for the basic operation of the Website (technical cookies), improve the user experience (functional cookies), measure traffic on the Website (analytics cookies), or enable the display of targeted advertisements (marketing cookies).
2.3. Lifespan of cookies
Based on their lifespan, cookies fall into two groups:
- Session cookies: these are automatically deleted from the browser when the browser is closed. They typically contain a random identifier that the web server uses to keep track of the session. Depending on the server settings, the server-side session may also expire earlier, irrespective of the deletion of the cookie. Session cookies are necessary for the technical operation of the Website (e.g. maintaining the login state or the contents of the shopping cart). When browsing as a guest without registration, the session cookie is not linked to an identified user.
- Persistent cookies: these remain on the Device after the browser is closed, until the predefined expiry date or until deleted by the user. They make it possible to remember settings and to collect statistics.
2.4. First-party and third-party cookies
- First-party cookies: cookies belonging to the visitbudavar.hu, visitbudavar.com or visitbudavar.eu domain, placed directly by the Controller's web server.
- Third-party cookies: cookies belonging to other domains, placed by external service providers engaged by the Controller (e.g. web analytics provider, map service provider, payment service provider). A detailed description of third-party cookies is set out in Chapter 8.
3. CATEGORIES OF COOKIES
3.1. The Website uses the following categories of cookies:
| Category | Consent required? | Purpose |
|---|---|---|
| Strictly necessary (technical) | No | Essential for the basic operation of the Website |
| Functional | Yes | Improving the user experience (language, currency, etc.) |
| Analytics (statistical) | Yes | Traffic statistics, analysis of usage |
| Marketing | Yes | Targeted advertising, remarketing (not currently used) |
3.2. For the categories of cookies subject to consent, cookies are placed solely on the basis of the Data Subject's prior, voluntary, unambiguous and informed consent. Consent may be withdrawn at any time (see Section 9).
4. STRICTLY NECESSARY (TECHNICAL) COOKIES
4.1. Strictly necessary cookies are essential for the basic operation of the Website. Without them, certain functions of the Website (login, ticket purchase, form security) would not work properly.
4.2. Pursuant to Section 13/A(3) of the Ekertv., these cookies may be placed without the Data Subject's consent, as they are strictly necessary for the provision of the service expressly requested by the Data Subject.
4.3. Technical cookies used on the Website
| Cookie name | Purpose | Type | Expiry | Legal basis |
|---|---|---|---|---|
| [session identifier] | Session management, maintaining login state | First-party, session | End of session | Art. 6(1)(f) GDPR – legitimate interest |
| [CSRF protection] | Protection against CSRF attacks (prevention of form forgery) | First-party, session | End of session | Art. 6(1)(f) GDPR – legitimate interest |
| [cookie consent] | Storing cookie consent settings | First-party, persistent | 12 months | Art. 6(1)(f) GDPR – legitimate interest |
| [cart identifier] | Preserving the contents of the shopping cart during the purchase process | First-party, session | End of session | Art. 6(1)(b) GDPR – performance of a contract |
Note: The exact cookie names in the table above will be finalised during the technical implementation of the Website. The Policy will contain the final cookie names when the Website goes live.
4.4. If the Data Subject blocks strictly necessary cookies in their browser settings, certain functions of the Website – including login, ticket purchase and use of the shopping cart – will not work properly. The Website will alert the Data Subject to this.
5. FUNCTIONAL COOKIES
5.1. The purpose of functional cookies is to improve the user experience: they remember the language and currency settings chosen by the Data Subject, so that these do not have to be entered again on the next visit.
5.2. When the Website is first loaded, the system determines the display language based on the browser's language setting (Accept-Language header). If the Data Subject manually selects a different language on the Website, the functional cookie saves this choice, and on the next visit the system applies the language stored in the cookie instead of the browser's language setting.
5.3. Functional cookies used on the Website:
| Cookie name | Purpose | Type | Expiry | Legal basis |
|---|---|---|---|---|
| [language setting] | Preserving the language setting manually selected by the user | First-party, persistent | 12 months | Art. 6(1)(a) GDPR – consent |
| [currency setting] | Preserving the selected currency setting (HUF, EUR, etc.) | First-party, persistent | 12 months | Art. 6(1)(a) GDPR – consent |
Note: The exact cookie names will be finalised during the technical implementation of the Website.
5.4. Functional cookies are placed solely with the Data Subject's consent. Refusing consent does not prevent the use of the Website; it merely means that the Data Subject must set the language and currency settings again on each visit.
6. ANALYTICS (STATISTICAL) COOKIES
6.1. The purpose of analytics cookies is to measure traffic on the Website, to analyse user behaviour anonymously (in anonymised form) and to improve the service. The data collected by means of analytics cookies do not allow the direct identification of the Data Subject.
6.2. The Website uses Google Analytics 4 (GA4) as its analytics service.
| Cookie name | Purpose | Type | Expiry | Legal basis |
|---|---|---|---|---|
| _ga | Distinguishing unique visitors (anonymised) | Third-party (Google), persistent | 2 years | Art. 6(1)(a) GDPR – consent |
| ga[identifier] | Storing the Google Analytics session state | Third-party (Google), persistent | 2 years | Art. 6(1)(a) GDPR – consent |
Note: The exact names and parameters of the GA4 cookies will be finalised after the Google Analytics account has been configured. The table above contains the standard GA4 cookie names.
6.3. Analytics cookies are placed solely on the basis of the Data Subject's prior consent. Refusing consent has no adverse consequences whatsoever; the Website can be used in full without analytics cookies.
6.4. As part of the analytics service, the Controller may collect the following types of data (the exact scope of data depends on the Google Analytics configuration):
- the Data Subject's IP address (by default, GA4 anonymises the IP address of traffic originating from the EU),
- the addresses of the pages visited and the order of the visit,
- the date, time and duration of the visit,
- the referring page (referrer URL),
- the type and version of the browser and operating system used,
- the screen resolution of the Device,
- geographical location (at country/region level only, based on an IP-based estimate).
6.5. Google Ireland Limited acts as a data processor on behalf of the Controller. The data processing conditions of Google Analytics are governed by the Google Ads Data Processing Terms. In the GA4 settings, the Controller opts for EU-based data processing (EU Data Boundary) where available. If Google processes certain data outside the EU/EEA, this may take place solely on the basis of the appropriate safeguards under Chapter V of the GDPR (the standard contractual clauses adopted by the European Commission – SCC, and, in respect of the USA, the adequacy decision on the EU–U.S. Data Privacy Framework).
7. MARKETING COOKIES
7.1. As at the entry into force of the Policy, the Website does not use marketing (advertising, remarketing) cookies.
7.2. If marketing cookies are introduced in the future, they may be used only if all of the following conditions are met:
- prior amendment of this Policy, with a detailed listing of the specific marketing cookies,
- obtaining the Data Subject's prior, voluntary, express and informed consent,
- simultaneous supplementation of the Privacy Notice.
8. THIRD-PARTY COOKIES
8.1. In the course of the operation of the Website, external service providers engaged by the Controller may place third-party cookies on the Data Subject's Device. Third-party cookies may also be created when external content embedded in the Website (e.g. map service, analytics code, payment interface) is loaded.
8.2. Embedded services
8.2.1. The Website uses the following embedded external services, which may place third-party cookies:
| Service provider | Activity | Cookie category | Privacy notice |
|---|---|---|---|
| Google Ireland Ltd. (Google Analytics 4) | Web analytics | Analytics (subject to consent) | https://policies.google.com/privacy |
| Google Ireland Ltd. (Google Maps) | Map display (attractions, stops, routes) | Functional (subject to consent) | https://policies.google.com/privacy |
| [name of payment service provider – to be completed] | Online ticket and pass sales | Strictly necessary | [URL – to be completed] |
8.2.2. To embed the Google Maps map service, the Website uses the Google Maps Embed API. When the map is loaded, Google may place its own cookies on the Data Subject's Device. Google Maps is embedded only after the Data Subject has given consent (by accepting functional cookies); in the absence of consent, a static image and a link are displayed instead of the map.
8.2.3. If the Website uses additional embedded services in the future (e.g. reCAPTCHA, social media plug-ins, embedded videos), this Policy must be supplemented with the cookie management conditions of the given service before their introduction.
8.3. Social media
8.3.1. The social media references placed on the Website (Facebook, Instagram, etc.) operate solely as links; the Website does not use social media plug-ins (social plugins) that would automatically transfer data to third parties when the user visits the Website.
8.4. Management of third-party cookies
8.4.1. The Controller cannot directly influence the cookie management activities of third parties. The Data Subject may obtain information on the management of third-party cookies from the privacy notice of the relevant service provider (see Section 8.2.1).
9. MANAGING CONSENT
9.1. Cookie banner (cookie consent banner)
On the first visit to the Website, a cookie consent banner (cookie banner) is displayed, which contains:
- brief, easily understandable information about the use of cookies,
- a link to this Policy,
- an itemised list of the cookie categories with checkboxes,
- the “Accept all”, “Accept only necessary” and “Manage settings” buttons.
9.2. Manner of giving consent
- Consent may be given solely by an active, unambiguous action (Article 4(11) GDPR, EDPB guidelines).
- The use of pre-ticked checkboxes is prohibited.
- The “Accept all” and “Accept only necessary” buttons are of identical size and colour; the Website does not use so-called “dark pattern” techniques that steer the user towards giving consent.
- While the cookie banner is displayed, browsing of the Website is limited to strictly necessary cookies; cookies subject to consent are not placed before the banner has been responded to.
9.3. Withdrawal of consent
The Data Subject may withdraw their consent at any time, without giving reasons:
- via the “Cookie settings” menu item available on the Website (in the footer of the Website), or
- by deleting the relevant cookies in the browser settings.
Withdrawal of consent does not affect the lawfulness of the placement of cookies prior to the withdrawal.
9.4. Documenting consent
Pursuant to Article 7(1) GDPR, the Controller documents the fact of consent and is able to demonstrate it. The Controller also records the cookie consent settings in the web server access log, with the following data:
- the time of the consent,
- the cookie categories accepted,
- the version number of the Policy in force at the time of the consent,
- the Data Subject's IP address (in anonymised form, for evidentiary purposes – a dynamic IP address does not in itself allow the identification of a natural person).
9.5. Renewal of consent
The Controller asks the Data Subject to renew their consent every 12 months in respect of the cookie categories subject to consent (in line with the expiry of the cookie consent cookie). In addition, the Controller also requests renewed consent in the event of a material amendment to the Policy.
10. MANAGING COOKIES IN THE BROWSER
10.1. The Data Subject may change the settings for accepting cookies in their browser settings, may restrict or block the placement of cookies, and may delete cookies that have already been placed.
10.2. The cookie management settings of the main browsers are available at the following addresses:
- Google Chrome: chrome://settings/cookies
- Mozilla Firefox: about:preferences#privacy
- Apple Safari: Settings > Privacy
- Microsoft Edge: edge://settings/privacy
10.3. Changing cookie settings in the browser does not always have the same effect as changing the settings in the Website's cookie banner. For the fullest control, the Controller recommends using the “Cookie settings” menu item available on the Website.
10.4. Cookie settings are tied to the given browser on the given Device. If the Data Subject uses several browsers (e.g. Chrome and Safari) or several devices (e.g. a computer and a mobile phone), the cookie settings must be configured separately in each. Consent given in one browser or on one device is not valid in another.
10.5. Please note that completely blocking cookies in the browser may render certain functions of the Website (login, ticket purchase, shopping cart) unavailable.
11. DATA TRANSFERS AND DATA SECURITY
11.1. The Controller endeavours to process the data collected by means of cookies within the European Union and the European Economic Area (EEA). With regard to the analytics service (Google Analytics 4), if Google processes certain data outside the EU/EEA, this takes place solely on the basis of the appropriate safeguards under Chapter V of the GDPR (see Section 6.5).
11.2. In order to protect the data collected by means of cookies, the Controller applies the technical and organisational measures required by Article 32 GDPR:
- the Website is accessible solely via an encrypted HTTPS (TLS 1.2+) connection,
- the data stored in cookies do not contain directly identifying information (passwords, payment data),
- analytics data collection takes place with anonymised IP addresses,
- the web server access logs (Section 9.4) are protected by access restrictions.
12. RIGHTS OF DATA SUBJECTS
12.1. Where the data collected by means of cookies qualify as personal data (e.g. where non-anonymised identifiers are used), the Data Subject has the following rights under the GDPR:
- right to be informed (Articles 13–14 GDPR) – fulfilled by means of this Policy,
- right of access (Article 15 GDPR) – the Data Subject may request information about the personal data relating to them processed by means of cookies,
- right to erasure (Article 17 GDPR) – the Data Subject may request the erasure of their personal data collected by means of cookies, provided that these can be identifiably linked to their person,
- right to restriction of processing (Article 18 GDPR),
- right to object (Article 21 GDPR) – in respect of technical cookies based on legitimate interest,
- right to withdraw consent – in respect of cookies subject to consent, at any time (see Section 9.3).
12.2. Owing to the nature of cookies, in most cases the Controller processes anonymised or pseudonymised data on the basis of which the natural person cannot be directly identified. Data subject rights can therefore be exercised most effectively primarily by withdrawing consent (Section 9.3) and by deleting cookies from the browser (Chapter 10).
12.3. With regard to data collected by third-party service providers (in particular Google), the Data Subject may exercise their rights directly vis-à-vis the given service provider (see Section 8.2.1).
12.4. The Data Subject may exercise their rights at the following contact details:
- By e-mail: adatvedelem@turisztika.budavar.hu
- By post: Budavári Turisztikai Kft., 1011 Budapest, Iskola utca 16.
13. LEGAL REMEDIES
13.1. The Data Subject may first address their complaint to the Controller's Data Protection Officer:
13.2. The Data Subject may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):
| Item | Details |
|---|---|
| Address: | 1055 Budapest, Falk Miksa u. 9-11. |
| Postal address: | 1363 Budapest, Pf.: 9. |
| E-mail: | ugyfelszolgalat@naih.hu |
| Telephone: | +36 (1) 391 1400 |
| Website: | https://naih.hu |
13.3. In the event of an infringement of their rights, the Data Subject may also bring the matter before the regional court (törvényszék) having jurisdiction over their place of residence or place of stay (Article 79 GDPR).
14. AMENDMENT OF THE POLICY
14.1. The Controller reserves the right to amend this Policy unilaterally. The amended Policy shall be published on the Website, together with an indication of the date on which the amendment enters into force.
14.2. In the event of a material amendment to the Policy (introduction of new cookie categories, engagement of new third-party service providers, changes to the purpose of the cookies), the Controller shall request renewed consent from the Data Subjects in respect of the cookie categories subject to consent.
14.3. Previous versions of the Policy are available in the Website's archive.
Budapest, 26 June 2026
Naszódi Péter
Managing Director
Budavári Turisztikai Kft.