Back to Home
Legal Information

Privacy Policy

Last updated: 15 August 2026 • Complies with EU GDPR (2016/679/EU) and applicable data protection regulations.

Data Protection Commitment

At CeglédSzállás, we are fully committed to safeguarding the personal data of our guests and website visitors. The purpose of this Privacy Policy is to provide transparent, detailed, and clear information on what personal data we collect, why, on what legal bases, how long we retain it, and the legal rights available to you under the GDPR (EU 2016/679) and applicable privacy laws.

I. Key Definitions & Legal Terms

The primary legal definitions used in this policy under the GDPR:

Personal Data:

Any information relating to an identified or identifiable natural person (specifically: full name, address, phone number, email address, IP address, payment transaction reference).

Data Subject (Guest / User):

An identified or identifiable natural person who uses our accommodation services or visits our website.

Data Controller:

The natural or legal person who determines the purposes and means of the processing of personal data (in this case, the Service Provider).

Data Processor:

A natural or legal person that processes personal data on behalf of the Controller (e.g. cloud hosting provider, electronic invoicing provider, card payment gateway).

Data Processing:

Any operation performed on personal data, whether or not by automated means (such as collection, recording, storage, retrieval, transfer, erasure, or destruction).

Personal Data Breach:

A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data.

Consent:

Any freely given, specific, informed, and unambiguous indication of the data subject's wishes (such as checking a checkbox during the booking flow).

II. Data Controller Details

The controller of your personal data (hereinafter referred to as Controller or Service Provider):

Company / Service Provider:Gasztro-Gorilla Kft.
Registered Address:
2700 Cegléd, Dózsa György út 58.
Tax Number:23289020-2-13
Phone Number:
Email Address:

III. Legal Framework

We process personal data in full compliance with current European Union and Hungarian legislation, in particular:

  • Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) on personal data protection and free movement of data
  • Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Hungarian Info Act)
  • Act C of 2000 on Accounting (Accounting Act – mandatory retention of financial records)
  • Act V of 2013 on the Hungarian Civil Code (Civil Code – contractual obligations and statute of limitations)
  • Act CVIII of 2001 on Electronic Commerce and Information Society Services (E-Commerce Act)

IV. Categories of Data, Purposes, Legal Bases and Retention Periods

We only collect and process personal data for specified, explicit, and legitimate purposes as set out below:

Online Booking & Guest Communication

Categories of Data: Full name, email address, phone number, check-in and check-out dates, number of guests, selected accommodation, special notes and requests.
Legal Basis (GDPR): GDPR Art. 6(1)(b) (performance of a contract and pre-contractual steps taken at the guest's request).
Retention Period: The general civil statute of limitations following completion of the stay and departure (5 years under the Civil Code).

Invoicing & Financial Compliance

Categories of Data: Billing name, billing address (postal code, city, street, house number), tax number (if company invoice requested), amount paid, and transaction ID.
Legal Basis (GDPR): GDPR Art. 6(1)(c) (compliance with a legal obligation – Accounting Act and tax regulations).
Retention Period: Strictly 8 years from the close of the financial year in which the invoice was issued (mandatory under Section 169 (2) of the Accounting Act).

Contact & Customer Inquiries

Categories of Data: Name, email address, phone number, subject and text of inquiry.
Legal Basis (GDPR): GDPR Art. 6(1)(a) (consent) or Art. 6(1)(f) (legitimate interest in responding to guest inquiries).
Retention Period: Until the inquiry is resolved and closed, or until consent is withdrawn.

V. Data Processors and International Transfers

To deliver a secure and reliable service, we work exclusively with the following contracted, specialized data processors. For US-based providers, transfers are covered by the EU-US Data Privacy Framework (DPF) and European Commission Standard Contractual Clauses (SCC):

Vercel Inc. (Website Hosting & Edge CDN)

Address: 440 N Barranca Ave #4133, Covina, CA 91723, USA

Website hosting, cloud infrastructure, DDoS mitigation, and global edge network serving.

Supabase Inc. (Database & Backend Infrastructure)

Address: 970 Toa Payoh North #07-04, Singapore / Lehi, UT, USA (EU data center)

Secure managed relational PostgreSQL database; encrypted storage and handling of reservation data within European Union data centers.

KBOSS.hu Kft. – Számlázz.hu (Electronic Invoicing)

Address: 1031 Budapest, Záhony utca 7., Hungary

Statutory electronic invoice and deposit invoice generation and automated email delivery.

Stripe Payments Europe Ltd. (Online Card Payments)

Address: 1 Grand Canal Street Lower, Grand Canal Dock, Dublin, D02 H210, Ireland

PCI-DSS Level 1 certified online payment processing for card deposits. Card details are never handled or stored on our servers.

Resend, Inc. (Email Dispatching)

Address: 2261 Market Street #5039, San Francisco, CA 94114, USA

Transactional email service for automated booking confirmations and invoice delivery.

Accounting Services Partner

Address: Hungary

Processing invoices and financial documents to fulfill mandatory statutory tax and accounting obligations.

VI. Data Security Measures

We apply robust organizational and technical security measures to protect your personal data. All communication on our website is secured using modern SSL/TLS (HTTPS) encryption. Access to stored data is restricted to authorized personnel only, protected by strict password policies and access controls. Regular automated backups are maintained to prevent data loss.

VII. Rights of Data Subjects (Your Rights)

Under Chapter III of the GDPR, you have the following rights regarding your personal data:

Right of Access (GDPR Art. 15): You may request confirmation as to whether your personal data is being processed and obtain a copy of it.
Right to Rectification (GDPR Art. 16): You may request the immediate correction or completion of inaccurate or incomplete personal data.
Right to Erasure ('Right to be Forgotten', GDPR Art. 17): You may request deletion of your data when processing is no longer necessary, except where statutory retention applies (e.g. 8-year invoice retention).
Right to Restriction of Processing (GDPR Art. 18): You may request restriction of processing in specific contested cases.
Right to Data Portability (GDPR Art. 20): You have the right to receive your personal data in a structured, machine-readable format.
Right to Object (GDPR Art. 21): You may object at any time to the processing of your data based on legitimate interests.
To exercise any of these rights, please contact us at: info@cegledszallas.hu. We will respond to your request free of charge within 30 days.

VIII. Legal Remedies and Regulatory Complaints

If you believe your data protection rights have been violated, we encourage you to contact us first so we can quickly address the issue. You also have the right to lodge a complaint with the supervisory authority or pursue judicial remedies:

Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)

Cím: 1055 Budapest, Falk Miksa utca 9-11.

Levelezési cím: 1363 Budapest, Pf. 9.

Telefon: +36 (1) 391-1400

E-mail: ugyfelszolgalat@naih.hu

Weboldal: www.naih.hu

Judicial Remedy:

You may bring legal proceedings before the competent Regional Court (Törvényszék) of your place of residence.