Privacy Notice

1. The data controller

Name: Proper Hospitality Ltd.

Registered office and postal address: 1037 Budapest, Szépvölgyi út 33.

Company registration number: 01-09-309875

Tax number: 25924181-2-41

Registering court: Commercial Register of the Budapest Regional Court

Member of Parliament: Ágnes Vilmos

Email: info@properhospitality.hu

Telephone: +36 30 982 7289

Website: https://properhospitality.hu/

Proper Hospitality Kft. is the organiser of the programme, the seller of admission tickets and the data controller responsible for the data processing described in this information notice. Comp-Let Party Service Kft. is the operator of the Teátrum Bistro / Moulin Rouge venue and a partner in the programme.

This privacy notice applies to data processing carried out in connection with the properhospitality.hu website, the online shop, ticket purchases, participation in events, customer service, marketing, and the taking of photographs and audio recordings.

2. The fundamental principles of data processing

The Data Controller processes personal data lawfully, fairly and transparently, for a specific purpose, and to the extent and for the duration necessary. It ensures the accuracy and security of the data and that the rights of data subjects are upheld.

The GDPR referred to in this information notice is Regulation (EU) 2016/679 of the European Parliament and of the Council. Data processing is also governed, in particular, by Act CXII of 2011, Act C of 2000 on Accounting, Act CLV of 1997 on Consumer Protection and Act XLVIII of 2008 on Commercial Advertising.

3. Ticket purchase and performance of the contract

Purpose of data processing: recording ticket purchases, establishing and fulfilling the contract, managing payment status, issuing confirmations, verifying eligibility to attend, maintaining contact, and handling cancellations and rebookings. Legal basis: Article 6(1)(b) of the GDPR – performance of a contract or pre-contractual measures. Data processed: name, email address, telephone number (where necessary), billing details, booking reference, programme and date, number of tickets, payment method and status, details of any discounts or vouchers, and the content of communications. Retention period: the general limitation period under civil law from the date of performance of the contract, which is generally 5 years; the longer period specified in point 4 applies to accounting documents.

The provision of this information is required for the conclusion of the contract. Without the mandatory details, it is not possible to purchase a ticket or to ensure participation in the Programme.

4. Invoicing and accounting records

Purpose of data processing: issuing and sending invoices, and retaining accounting records. Legal basis: Article 6(1)(c) of the GDPR – a legal obligation to which the Data Controller is subject. Data processed: billing name and address, tax number where required, email address, service purchased, amount and payment details. Retention period: 8 years in accordance with the Accounting Act.

Recipients/data processors: the provider of the electronic invoicing system and the Data Controller’s accountant, to the extent necessary for the performance of their duties.

EDITOR’S NOTE: The name, registered office and role of the invoicing service provider and the accountant must be specifically stated in the final information document.

5. Online payment

Purpose of data processing: to process online credit card payments, to confirm the outcome of the transaction and to manage refunds. Legal basis: Article 6(1)(b) of the GDPR – performance of a contract. The payment service provider may also act as a separate data controller in accordance with its own privacy notice. The Data Controller does not have access to, nor does it store, the full credit card details. Typically, only the transaction ID, amount, date and status are made available to the Data Controller.

Payment service provider: Barion Payment Zrt. – https://www.barion.com/hu/adatvedelmi-tajekoztato/.

6. Programme management and on-site support

Purpose of data processing: to welcome participants, verify eligibility to attend, organise the programme and catering, and ensure the event is conducted safely. Legal basis: Article 6(1)(b) of the GDPR – performance of a contract; where justified on security and organisational grounds, Article 6(1)(f) of the GDPR – legitimate interests.

Data processed: the name or booking reference required to verify attendance; the selected Programme; the date and time; the number of participants; and – solely on the basis of information provided by the volunteer concerned – details of any food allergies or special dietary requirements.

The data controller or data processor may be the venue operator and organiser, Comp-Let Party Service Kft., solely in respect of the data necessary for the organisation of the programme. Retention period: the list of participants will be retained until the end of the Programme, or, in the event of a complaint or legal claim, until the matter has been resolved; details of special dietary requirements will be deleted no later than after the Programme, provided that their further retention is not necessary.

7. Contact and customer service

Purpose of data processing: to respond to enquiries, requests for quotations, complaints and other enquiries. Legal basis: Article 6(1)(b) of the GDPR for enquiries relating to a contract or the preparation thereof; for other customer service enquiries, legitimate interest pursuant to Article 6(1)(f) of the GDPR. Data processed: name, email address, telephone number, the content of the enquiry and details of the handling of the matter. Retention period: 1 year following the closure of the case; in the event of a complaint, the period specified in consumer protection legislation; in the event of a legal claim, up to the end of the limitation period.

Data relating to customer service enquiries may only be used for marketing purposes on a separate and appropriate legal basis.

8. Handling complaints

Purpose of data processing: to investigate, respond to and substantiate consumer complaints, and to comply with statutory record-keeping obligations. Legal basis: Article 6(1)(c) of the GDPR – legal obligation under consumer protection law. Data processed: name, contact details, order details, the content of the complaint and the claim, and details of the investigation and the response. Retention period: the period specified under consumer protection legislation; as a general rule, the relevant complaint and response must be retained for 3 years.

9. Newsletters and digital marketing

Purchasing a ticket does not automatically subscribe you to a newsletter and does not authorise the Data Controller to send you promotional emails.

Purpose of data processing: sending newsletters, programme guides and other direct marketing messages. Legal basis: Article 6(1)(a) of the GDPR and prior, explicit consent in accordance with the Act on Commercial Advertising. Data processed: name – if provided – email address, the date and proof of consent, and unsubscription details. Retention period: until consent is withdrawn; proof of consent and withdrawal may be retained until the limitation period for legal claims expires.

Consent may be withdrawn at any time, without giving reasons and without incurring any disadvantage, by using the unsubscribe option provided in the message or by contacting info@properhospitality.hu. Withdrawal does not affect the lawfulness of any data processing carried out prior to it.

10. User account

If the online shop allows users to create an account, the purpose of this is to manage and facilitate purchases. Legal basis: Article 6(1)(b) of the GDPR. Data processed: name, username, email address, contact and billing details, encrypted password, previous orders. Retention period: for as long as the account remains active or until a request for deletion is made, provided that invoicing and contractual data required to be retained under the law may be retained even after the account has been deleted.

11. Cookies and website traffic data

Cookies that are strictly necessary for the website to function may be used without consent, in accordance with the regulations on electronic communications. All other cookies – in particular those used for analytical, performance, convenience and marketing purposes – may only be activated with the data subject’s prior consent. Consent may be amended or withdrawn at any time via the cookie settings.

Cookie data – in particular IP addresses, online identifiers, browser and device data – may in some cases constitute personal data. The detailed list of cookies includes the name, provider, purpose, type and expiry date of each cookie, as well as any data transfers to third countries.

12. Photographs and audio recordings

Purpose of data processing: to document the Programme and – where there is a separate legal basis – to promote the Programme and the Data Controller’s services. Data processed: image, audio, and the place and time the recording was made.

As a general rule, the legal basis for the use of an individual’s personal data for marketing purposes is consent under Article 6(1)(a) of the GDPR. Consent is voluntary; refusal to give consent does not affect participation in the Programme, and consent may be withdrawn at any time in the future. In the case of mass recordings, data processing may, depending on the circumstances, be based on the Data Controller’s legitimate interests, in respect of which separate information will be provided on site.

Retention period: in the case of data collected on the basis of consent, until such consent is withdrawn or the purpose of data processing ceases to apply; in the case of data collected on the basis of a legitimate interest, for the period specified in the separate information notice.

13. Data processors and recipients

The Data Controller shall transfer personal data to the following recipients only to the extent necessary: hosting and website operation service providers; online shop and IT service providers; electronic invoicing service providers; accountants; payment service providers; newsletter distributors – in the case of newsletters –; and Comp-Let Party Service Kft., should it receive participants’ data for the purposes of organising the Programme.

Data processors may process data only in accordance with the Data Controller’s documented instructions and subject to appropriate data security obligations. Recipients acting as independent data controllers shall act in accordance with their own privacy notices.

14. Data transfers to third countries

The Data Controller processes data primarily within the European Economic Area. If a service provider transfers data to a country outside the EEA or provides access to it from there, such data transfer may only take place subject to the appropriate safeguards set out in Chapter V of the GDPR. The data subject may request information about the safeguards applied and a copy thereof by writing to info@properhospitality.hu.

15. Data security

The Data Controller protects personal data by means of technical and organisational measures commensurate with the level of risk, including, in particular, access control, authorisation management, logging, backups, encrypted data transmission and regular updates, where justified by the system in question.

In the event of a data breach, the Data Controller will assess the risk in accordance with the GDPR, notify the supervisory authority where necessary, and inform the data subjects in the event of a high-risk breach.

16. The data subject’s rights

The data subject may request access to, rectification or erasure of their personal data, or restriction of their processing; they may object to data processing based on legitimate interests; they may request data portability; and they may withdraw their consent at any time.

The request may be sent to info@properhospitality.hu or to the Data Controller’s postal address. The Data Controller shall respond without undue delay, but no later than one month from receipt of the request. If necessary, this time limit may be extended by a further two months in accordance with the provisions of the GDPR.

As a general rule, there is no charge for complying with a request. If the request is manifestly unfounded or excessive, the Data Controller may charge a reasonable fee or refuse to take the requested action. The Data Controller may only request additional information necessary to verify the identity of the applicant.

17. Legal remedies

The data subject may lodge a complaint with the National Authority for Data Protection and Freedom of Information: 1055 Budapest, Falk Miksa utca 9–11; postal address: 1363 Budapest, PO Box 9; email: ugyfelszolgalat@naih.hu; website: https://naih.hu/.

You may also bring a claim before the relevant court if you consider that the processing of your personal data infringes the GDPR or other data protection legislation. The claim may be brought, at your discretion, before the court with jurisdiction over your place of residence or place of stay.

18. Automated decision-making and profiling

The Data Controller does not carry out any fully automated decision-making – including profiling – in connection with the purchase of tickets or participation in the Programme which would produce legal effects concerning the data subject or similarly significantly affect them.

19. Scope and amendment of the prospectus

The Data Controller is entitled to amend this privacy notice in the future. The current version is available on the website. If the amendment substantially affects the purpose or legal basis of data processing, the Data Controller will inform the data subjects separately in an appropriate manner.

Effective date: 25 August 2026.