Privacy
The visitbudavar.hu website privacy notice and the Budavári Turisztikai Kft. data protection and security policy.
PRIVACY NOTICE
on data processing related to the use of the visitbudavar.hu, visitbudavar.com and visitbudavar.eu websites
Effective from: 30 June 2026
Details of the Controller:
| Item | Details |
|---|---|
| Controller: | Budavári Turisztikai Korlátolt Felelősségű Társaság (Buda Castle Tourism Ltd.) |
| Company registration number: | 01-09-449584 |
| Registered office: | 1011 Budapest, Iskola utca 16. |
| E-mail: | budavariturisztika@budavar.hu |
| Website: | https://visitbudavar.hu / https://visitbudavar.com / https://visitbudavar.eu |
| Managing Director: | Naszódi Péter |
| Data Protection Officer (DPO): | Fodor Gabriella – adatvedelem@turisztika.budavar.hu |
1. INTRODUCTION
1.1.
Budavári Turisztikai Korlátolt Felelősségű Társaság (Buda Castle Tourism Ltd.) (hereinafter: the Controller or the Company), as a business association wholly owned by the Budavári Municipality of District I of Budapest, is a body performing public duties that is required to designate a Data Protection Officer pursuant to Article 37(1)(a) GDPR.
1.2.
The Controller, as the operator of the visitbudavar.hu, visitbudavar.com and visitbudavar.eu websites (hereinafter collectively: the Website), hereby informs the visitors and users of the Website (hereinafter: Data Subject) by means of this Privacy Notice (hereinafter: the Notice) about the processing of their personal data.
1.3.
This Notice has been prepared on the basis of the following legislation:
-
Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR),
- Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Infotv.),
- Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (Ekertv.),
- Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activity (Grtv.),
- Act CXXVII of 2007 on Value Added Tax (Áfa tv. – Hungarian VAT Act),
- Act C of 2000 on Accounting (Szt.).
1.4.
This Notice shall be applied in conjunction with the Controller's Data Protection and Data Security Policy and its Cookie Policy. The general rules of data processing are set out in the Data Protection and Data Security Policy, while the detailed terms of the use of cookies are set out in the Cookie Policy; both documents are available on the Website.
2. PRINCIPLES OF DATA PROCESSING
When processing personal data, the Controller applies the principles laid down in Article 5 GDPR: lawfulness, fairness and transparency; purpose limitation; data minimisation; accuracy; storage limitation; integrity and confidentiality; accountability. A detailed explanation of these principles is set out in the Controller's Data Protection and Data Security Policy.
3. CREATION AND MANAGEMENT OF USER ACCOUNTS
3.1. Categories of personal data processed
| Data processed | Mandatory / Voluntary |
|---|---|
| E-mail address | Mandatory |
| Password (stored exclusively in hashed form) | Mandatory |
| Surname, first name | Mandatory |
| User ID (generated by the system) | Automatic |
| Date and time of registration | Automatic |
| Date and time of last login | Automatic |
| IP address (at login, for security purposes) | Automatic |
3.2. Purpose of the processing
The creation and maintenance of a user account enables the Data Subject to purchase tickets online for the Budavár circuit shuttle service (Budavári körjárat), to view previous purchases and to store tickets/passes digitally.
3.3. Legal basis of the processing
- Article 6(1)(b) GDPR – performance of a contract: the creation of a user account is a necessary precondition for concluding and performing the ticket purchase contract.
- Article 6(1)(f) GDPR – legitimate interest: the login IP address is recorded to protect the security of the account and to prevent unauthorised access. A legitimate interest assessment (balancing test) has been carried out and is available from the Controller.
3.4. Duration of the processing
- For active accounts: for as long as the account exists.
- In the event of a deletion request: at the user's request, the account and the data associated with it will be deleted within 30 days of receipt of the request, with the exception of data that must be retained by law (e.g. invoicing data – see Section 5).
- Inactive accounts: after 24 months of inactivity (a period without any login), the Controller notifies the Data Subject by e-mail, and after a further 30 days deletes the account and the personal data, with the exception of data that must be retained by law.
3.5. Nature of the provision of data
Providing the data required to create a user account is a precondition for purchasing tickets online. The consequence of failure to provide the data is that the user will not be able to purchase tickets online. (On-site ticket purchase is of course possible without providing any personal data.)
4. ONLINE TICKET PURCHASE
4.1. Categories of personal data processed
| Data processed | Mandatory / Voluntary |
|---|---|
| The user account data listed in Section 3 | Mandatory |
| Type and number of tickets purchased | Mandatory |
| Date and time of purchase | Automatic |
| Transaction ID | Automatic |
| Payment status (successful/unsuccessful) | Automatic |
4.2. Purpose of the processing
Provision of the online ticket purchase service: conclusion and performance of the ticket/pass purchase contract for the Budavár circuit shuttle service (Budavári körjárat) and, in the future, the Budavár Card/Pass services, including the issuance and delivery of the electronic ticket.
4.3. Legal basis of the processing
Article 6(1)(b) GDPR – conclusion and performance of the purchase contract.
4.4. Duration of the processing
- Ticket purchase data: 5 years from the date of purchase (limitation period pursuant to Section 6:22 of the Ptk.).
- Data relating to accounting records: 8 years (Section 169(2) of the Szt.).
5. PROCESSING OF INVOICING DATA
5.1. General rule
If the Data Subject does not request an invoice, the Controller issues a receipt in accordance with the Áfa tv., which does not contain any personal data.
5.2. Issuing an invoice to a natural person
If the Data Subject requests an invoice, the following data must be provided:
| Data processed | Statutory basis |
|---|---|
| Name (surname, first name) | Áfa tv. 169. § a) |
| Home address (postcode, town, street, house number) | Áfa tv. 169. § a) |
| Tax identification number (if provided) | Áfa tv. 169. § a) |
5.3. Issuing an invoice to a legal person / sole trader
| Data processed | Statutory basis |
|---|---|
| Company name / name of sole trader | Áfa tv. 169. § a) |
| Registered office / home address | Áfa tv. 169. § a) |
| Tax number | Áfa tv. 169. § a) |
| EU VAT number (for EU customers) | Áfa tv. 169. § a) |
5.4. Legal basis of the processing
Article 6(1)(c) GDPR – compliance with a legal obligation: Sections 159(1) and 169 of the Áfa tv., and the obligation to retain accounting records under the Szt.
5.5. Duration of the processing
For a period of 8 years from the issuance of the invoice (Section 169(2) of the Szt.). This retention obligation continues to apply even if the user account is deleted.
5.6. Nature of the provision of data
Providing invoicing data is voluntary (the customer may choose not to request an invoice, in which case a receipt is issued). However, if the Data Subject requests an invoice, providing the data listed in Section 5.2 or 5.3 is mandatory under the Áfa tv.; an invoice cannot be issued with incomplete data.
6. ONLINE PAYMENT
6.1. The payment service provider
The Controller uses an external payment service provider to process online payments on the Website:
| Item | Details |
|---|---|
| Name of payment service provider: | [name of payment service provider – to be completed after selection] |
| Registered office of payment service provider: | [registered office – to be completed] |
| Privacy notice of payment service provider: | [URL – to be completed] |
6.2. Data processed during payment
The bank card details provided during online payment (card number, expiry date, CVV/CVC code) are processed exclusively by the payment service provider; the Controller does not access, store or process these data in any form.
The payment service provider acts as an independent data controller with regard to the bank card details, in accordance with its own privacy notice and the PCI DSS standard.
The Controller receives only the following information from the payment service provider:
- whether the payment was successful (successful/unsuccessful),
- the unique identifier of the transaction,
- the date and time of the payment,
- the amount paid.
6.3. Legal basis of the processing
Article 6(1)(b) GDPR – performance of the purchase contract (payment is a necessary element of the performance of the contract).
7. NEWSLETTER SUBSCRIPTION
7.1. Data processed
| Data processed | Mandatory / Voluntary |
|---|---|
| E-mail address | Mandatory |
| Surname, first name | Voluntary |
| Date and time of subscription | Automatic |
| IP address at subscription | Automatic (for the purpose of proving consent) |
| Method of subscription (checkbox, subscription form) | Automatic |
7.2. Purpose of the processing
Sending electronic newsletters about the Controller's tourism services (circuit shuttle, Budavár Card, programmes, special offers).
7.3. Legal basis of the processing
Article 6(1)(a) GDPR – the Data Subject's freely given, explicit consent. Consent is given by the Data Subject by actively ticking a checkbox on the subscription form. The use of pre-ticked checkboxes is prohibited.
7.4. Duration of the processing
Until withdrawal of consent (unsubscription). The Data Subject may unsubscribe at any time, without giving reasons, by clicking on the “Unsubscribe” link included in every newsletter or by sending a request to budavariturisztika@budavar.hu.
7.5. Nature of the provision of data
Subscribing to the newsletter is entirely voluntary; not subscribing has no adverse consequences whatsoever.
8. CONTACT FORM
8.1. Data processed
| Data processed | Mandatory / Voluntary |
|---|---|
| Name | Mandatory |
| E-mail address | Mandatory |
| Telephone number | Voluntary |
| Subject and content of the message | Mandatory |
| Date and time of submission | Automatic |
8.2. Purpose of the processing
Responding to the Data Subject's enquiry and providing information about the Company's services.
8.3. Legal basis of the processing
Article 6(1)(b) GDPR – steps taken at the request of the Data Subject prior to entering into a contract (where the message relates to the service), or Article 6(1)(f) GDPR – the Controller's legitimate interest in responding to incoming enquiries.
8.4. Duration of the processing
1 year from the closure of the enquiry (from the sending of the reply), after which the data are deleted.
9. USE OF COOKIES
9.1. What is a cookie?
Cookies are small text files that the Website's web server places on the Data Subject's computer, mobile device or other terminal equipment via the browser. Cookies enable the web server to recognise the Data Subject's browser and thereby improve the user experience.
9.2. Cookies used by the Website
9.2.1. Strictly necessary (technical) cookies
| Cookie name | Purpose | Expiry | Legal basis |
|---|---|---|---|
| [session identifier] | Session management, maintaining login status | Until the end of the session | Art. 6(1)(f) GDPR – legitimate interest |
| [CSRF protection] | Protection against CSRF attacks | Until the end of the session | Art. 6(1)(f) GDPR – legitimate interest |
| [cookie consent] | Storing cookie settings | 12 months | Art. 6(1)(f) GDPR – legitimate interest |
| [cart identifier] | Preserving the contents of the cart during purchase | Until the end of the session | Art. 6(1)(b) GDPR – performance of a contract |
Note: The exact cookie names will be finalised during the technical implementation of the Website.
These cookies are necessary for the basic operation of the Website and therefore do not require the Data Subject's consent. If the Data Subject's browser blocks these cookies, certain functions of the Website (login, ticket purchase) will not work.
9.2.2. Functional cookies
| Cookie name | Purpose | Expiry | Legal basis |
|---|---|---|---|
| [language setting] | Preserving the language setting chosen by the user | 12 months | Art. 6(1)(a) GDPR – consent |
| [currency setting] | Preserving the selected currency setting | 12 months | Art. 6(1)(a) GDPR – consent |
Note: The exact cookie names will be finalised during the technical implementation of the Website.
These cookies serve to improve the user experience. They are not placed without consent; in the absence of consent, the settings must be entered again on each visit.
9.2.3. Analytics (statistical) cookies
The Website uses Google Analytics 4 (GA4) as its analytics service.
| Cookie name | Purpose | Expiry | Legal basis |
|---|---|---|---|
| _ga | Distinguishing unique visitors (anonymised) | 2 years | Art. 6(1)(a) GDPR – consent |
| ga[identifier] | Storing the Google Analytics session state | 2 years | Art. 6(1)(a) GDPR – consent |
Note: The exact names and parameters of the GA4 cookies will be finalised after the configuration of the Google Analytics account. The table above contains the standard GA4 cookie names.
These cookies are placed exclusively on the basis of the Data Subject's consent. Refusal of consent has no adverse consequences whatsoever.
9.2.4. Marketing cookies
The Website does not currently use marketing (advertising) cookies. If such cookies are introduced in the future, they may be placed only with the Data Subject's prior consent, subject to the appropriate amendment of this Notice and the Cookie Policy.
9.3. Managing cookies in the browser
The Data Subject may at any time change the settings for accepting cookies in their browser settings and may delete cookies that have already been placed. Cookie settings are tied to the specific browser on the specific device; if the Data Subject uses several browsers or several devices, the settings must be configured separately in each of them.
Cookie management guides for the main browsers:
- Google Chrome: chrome://settings/cookies
- Mozilla Firefox: about:preferences#privacy
- Apple Safari: Settings > Privacy
- Microsoft Edge: edge://settings/privacy
9.4. Managing cookie consent
On the first visit to the Website, a cookie consent banner (cookie banner) is displayed to the Data Subject, in which the Data Subject can select individually which cookie categories they wish to allow. The Data Subject may change their consent at any time via the “Cookie settings” menu item available on the Website.
9.5. Cookie Policy
The detailed terms of the use of cookies – including the precise description of each cookie, the handling of third-party cookies, the technical implementation of consent management and the detailed rights of the Data Subject – are set out in the Controller's separate Cookie Policy, which is available on the Website.
10. WEB ANALYTICS
10.1.
The Controller uses the Google Analytics 4 (GA4) web analytics service to measure traffic on the Website and to improve the user experience:
| Item | Details |
|---|---|
| Name of service provider: | Google Ireland Limited |
| Registered office of service provider: | Gordon House, Barrow Street, Dublin 4, Ireland |
| Privacy notice of service provider: | https://policies.google.com/privacy |
10.2.
Data collected in the context of the web analytics service: the Data Subject's IP address (by default, GA4 anonymises the IP address of traffic originating from the EU), the pages visited, the date, time and duration of the visit, the referring page (referrer), the type of browser and operating system used, the screen resolution, and geographical location (at country/region level only, estimated on the basis of the IP address).
10.3.
The legal basis of the processing is Article 6(1)(a) GDPR – the Data Subject's consent (based on the permission given via the cookie consent banner). If consent is refused, no analytics cookies are placed.
10.4.
Google Ireland Limited acts as a data processor on behalf of the Controller. In the GA4 settings, the Controller opts for data processing within the EU (EU Data Boundary), where available. If Google processes certain data outside the EU/EEA, this may take place only on the basis of appropriate safeguards under Chapter V of the GDPR (see Section 16).
11. EMBEDDED SERVICES
11.1. Google Maps map service
11.1.1. The Website uses the Google Maps Embed API map service to display the stops and routes of the Budavár circuit shuttle and the sights of the surrounding area. The service is provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland; privacy notice: https://policies.google.com/privacy).
11.1.2. Google Maps is embedded only after the Data Subject has given consent (by accepting functional cookies). In the absence of consent, a static image and a link to Google Maps are displayed instead of the map.
11.1.3. When the map is loaded, Google may place its own cookies on the Data Subject's Device. The handling of these cookies is governed by Google's own privacy notice. A detailed description of the cookies associated with the embedding of Google Maps is set out in Section 8.2 of the Cookie Policy.
11.2. Other embedded services
If the Website uses additional embedded services in the future (e.g. video embedding, reCAPTCHA), this Notice and the Cookie Policy must be supplemented with the data processing and cookie terms of the given service before its introduction.
12. SOCIAL MEDIA
12.1.
The social media buttons placed on the Website (Facebook, Instagram, etc.) function exclusively as links; the Website does not use social media plugins that would automatically transfer data to social media platforms when opened by the user.
12.2.
If the Data Subject leaves the Website by clicking on such a link, the social media platform's own privacy notice applies.
13. RIGHTS OF DATA SUBJECTS
The Data Subject has the following rights in relation to the processing of their personal data:
13.1. Right to be informed (Articles 13-14 GDPR)
The Data Subject has the right to be informed about the processing of their personal data before the processing begins – by means of this Notice.
13.2. Right of access (Article 15 GDPR)
The Data Subject has the right to obtain confirmation from the Controller as to whether or not their personal data are being processed and, where that is the case, to access the personal data and the information specified in Article 15 GDPR.
13.3. Right to rectification (Article 16 GDPR)
The Data Subject has the right to obtain from the Controller, without undue delay, the rectification of inaccurate personal data concerning them. The Data Subject may also modify their user account data independently in the account settings.
13.4. Right to erasure / “right to be forgotten” (Article 17 GDPR)
The Data Subject has the right to obtain from the Controller, without undue delay, the erasure of personal data concerning them, where one of the conditions set out in Article 17 GDPR applies. The right to erasure does not extend to data that must be retained by law (e.g. invoicing data for 8 years).
13.5. Right to restriction of processing (Article 18 GDPR)
The Data Subject has the right to obtain from the Controller the restriction of processing where one of the conditions set out in Article 18 GDPR applies.
13.6. Right to data portability (Article 20 GDPR)
The Data Subject has the right to receive the personal data concerning them which they have provided to the Controller in a structured, commonly used, machine-readable format, where the processing is based on consent or on a contract and is carried out by automated means.
13.7. Right to object (Article 21 GDPR)
The Data Subject has the right to object at any time, on grounds relating to their particular situation, to the processing of their personal data based on legitimate interest.
13.8. Withdrawal of consent
Where the processing is based on the Data Subject's consent, the Data Subject has the right to withdraw their consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
13.9. How to exercise these rights
The Data Subject may exercise the above rights via the following contact details:
- By e-mail: adatvedelem@turisztika.budavar.hu
- By post: Budavári Turisztikai Kft., 1011 Budapest, Iskola utca 16.
The Controller responds to requests concerning the exercise of data subject rights within 1 month of receipt. Where necessary, this deadline may be extended by a further 2 months, of which the Data Subject will be informed.
14. DATA SECURITY
14.1.
The Controller applies the following technical and organisational measures to protect personal data:
- the Website is accessible exclusively via an encrypted HTTPS (TLS 1.2+) connection,
- user passwords are stored exclusively in one-way hashed form (bcrypt or equivalent),
- payment data are processed exclusively by a PCI DSS-certified payment service provider,
- restricted access to personal data (only the staff members who need it have access),
- regular backups,
- logging and monitoring to detect unauthorised access attempts,
- the detailed measures are set out in the IT Security Policy (IBSZ).
15. DATA PROCESSORS
The Controller uses the following data processors in the operation of the Website:
| Data processor | Activity | Registered office | Data processing agreement |
|---|---|---|---|
| [name of hosting provider – to be completed] | Website hosting, server operation | [registered office – to be completed] | Yes |
| [name of payment service provider – to be completed] | Processing of online payments | [registered office – to be completed] | Yes |
| [name of invoicing software / provider – to be completed] | Issuing invoices | [registered office – to be completed] | Yes |
| [name of newsletter service provider – to be completed, if external] | Sending newsletters | [registered office – to be completed] | Yes |
| Google Ireland Limited | Web analytics (Google Analytics 4) | Gordon House, Barrow Street, Dublin 4, Ireland | Yes (Google Ads Data Processing Terms) |
| Google Ireland Limited | Map service (Google Maps Embed API) | Gordon House, Barrow Street, Dublin 4, Ireland | Yes (Google Maps Platform Terms of Service) |
The data processors process personal data exclusively on the instructions of the Controller, under data processing agreements compliant with Article 28 GDPR.
16. DATA TRANSFERS TO THIRD COUNTRIES
16.1.
The Controller endeavours to process the personal data processed in connection with the operation of the Website within the European Union and the European Economic Area (EEA).
16.2.
As its cloud-based office service, the Controller uses a Microsoft 365 EU Data Boundary subscription, which ensures that data are stored and processed within the territory of the EU, under the terms published by Microsoft and the data protection agreement (DPA).
16.3.
The online ticketing system and the dispatcher system store and process data exclusively on servers operating within the EU/EEA; no data transfers to third countries take place.
16.4.
For on-site payments made via POS terminal, bank card data are processed exclusively by a payment system operated by a financial institution with its registered office in Hungary or another EU/EEA Member State. When selecting the POS terminal, the Controller excludes the use of any provider that would transfer data to a third country.
16.5.
When using the web analytics service (Google Analytics 4) and the map service (Google Maps), Google Ireland Limited acts as a data processor. In the GA4 settings, the Controller opts for data processing within the EU (EU Data Boundary), where available. If Google processes certain data outside the EU/EEA, this may take place only on the basis of appropriate safeguards under Chapter V of the GDPR, in particular:
- standard contractual clauses adopted by the European Commission (SCC, Article 46(2)(c) GDPR), and
- with regard to the United States, the EU–U.S. Data Privacy Framework (DPF) adequacy decision (European Commission Implementing Decision of 10 July 2023).
16.6.
If, in the future, the use of any data processor or service provider beyond those listed above were to involve data transfers to a third country, the Controller will carry out the transfer only where the safeguards set out in Chapter V of the GDPR are in place, and will amend this Notice accordingly in advance.
17. AUTOMATED DECISION-MAKING AND PROFILING
17.1.
In connection with the operation of the Website, the Controller does not use decision-making based solely on automated processing – including profiling – which would produce legal effects concerning the Data Subject or similarly significantly affect them (Article 22 GDPR).
17.2.
The Controller does not create user profiles of Data Subjects that would serve as the basis for automated decisions on pricing, access to services or other matters affecting the Data Subject.
18. LEGAL REMEDIES
18.1.
If the Data Subject considers that their rights have been infringed in the course of the processing of their personal data, they may first lodge a complaint with the Controller's Data Protection Officer:
18.2.
The Data Subject may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):
| Item | Details |
|---|---|
| Address: | 1055 Budapest, Falk Miksa u. 9-11. |
| Postal address: | 1363 Budapest, Pf.: 9. |
| E-mail: | ugyfelszolgalat@naih.hu |
| Telephone: | +36 (1) 391 1400 |
| Website: | https://naih.hu |
18.3.
In the event of an infringement of their rights, the Data Subject may also bring the matter before the regional court (törvényszék) having jurisdiction according to their place of residence or stay (Article 79 GDPR).
19. AMENDMENT OF THE NOTICE
19.1.
The Controller reserves the right to amend this Notice unilaterally. The amended Notice will be published on the Website, together with the date on which the amendment takes effect.
19.2.
In the event of a material amendment (new processing purposes, new legal bases, engagement of new data processors), the Controller will also inform registered users of the changes by e-mail.
19.3.
Previous versions of the Notice are available in the archive of the Website.
Budapest, 30 June 2026
Naszódi Péter
Managing Director
Budavári Turisztikai Kft.