Privacy Policy
This policy explains what personal data we process when you book through the Guest House website, why, and for how long.
Document version: 2026-08-26
1. Data controller
Awaiting information from the owner – to be completed before launch
To be completed: the name, registered address, registration number, tax number and contact details of the data controller. These must match the details given in the Imprint.
2. What we collect
When you make a booking we process:
- your name
- your email address
- your phone number, if you provide one
- your check-in and check-out dates and the number of guests
- any message you add to the booking
- the language of your booking, so that we write to you in that language
- the amounts of your booking and its payment status
- the time at which you accepted the booking terms and this policy, and the version of those documents
To protect against abuse, the server briefly keeps the IP address of the visitor submitting the booking form in memory only. IP addresses are not stored in the database.
3. Purpose and legal basis
- Purpose
- to record, confirm and perform your booking, and to contact you about it
- Legal basis
- performance of a contract, and steps taken at your request prior to entering into a contract (GDPR Article 6(1)(b))
The automated emails (booking received, confirmation, expiry) are part of performing the service and are not marketing. We do not send newsletters.
4. How long we keep your data
Awaiting information from the owner – to be completed before launch
To be completed: how long booking data is retained after the stay, taking account of accounting and tax retention obligations. Data must be deleted once that period ends.
5. Processors
Awaiting information from the owner – to be completed before launch
To be completed with the actual providers used, including their names and registered addresses. Currently planned: the hosting provider running the server, and the transactional email provider that delivers our messages. If an accountant or other party has access to the data, they must be listed too.
6. Booking.com
For bookings made through Booking.com, Booking.com acts as an independent controller under its own privacy policy. Only booked date ranges are synchronised between this website and Booking.com; no guest data is exchanged between the systems.
7. Your rights
You may at any time request:
- information about the data we hold about you
- correction of your data
- erasure of your data, where no legal obligation prevents it
- restriction of processing
- a copy of your data in a portable format
- to object to the processing
Requests can be sent to sutooliver19@gmail.com. You may also lodge a complaint with the Hungarian data protection authority (NAIH) or bring the matter before a court.
8. Security
The website is served over an encrypted connection (HTTPS). The database is not reachable directly from the internet. The administration area is password protected and passwords are stored only in hashed form. Backups are taken regularly.
The Hungarian version of this document is authoritative. The English and German translations are provided for information only.