West Budapest Apartment · Privacy

Privacy Notice

Information about the processing of your personal data.

West Budapest Apartment is committed to protecting the personal data of its guests and visitors. This Privacy Notice explains what personal data we process, why we process it, the legal basis for such processing, and the rights available to data subjects.

Zombori Andrea Data Controller
GDPR Regulation (EU) 2016/679
VIZA / NTAK statutory reporting
13 September 2026 last updated
Privacy information

Transparent processing of personal data

This Privacy Notice applies to personal data processed in connection with enquiries, booking requests, accommodation services, communication, invoicing and statutory reporting obligations relating to West Budapest Apartment.

Data Controller

West Budapest Apartment

Data Controller Zombori Andrea, private individual with a tax number
Tax number 57396932-1-41
Accommodation 1132 Budapest, Váci út 46/A, Hungary
NTAK registration number MA24091467
Important: submitting a booking request or using the accommodation service does not constitute a waiver of any data-protection rights. Personal data may only be processed for a specified purpose and on an appropriate legal basis.
I. Definitions

Personal data: any information relating to an identified or identifiable natural person.

Data subject: the natural person to whom the personal data relates, including an enquirer, booking guest or accommodation guest.

Processing: any operation performed on personal data, including collection, recording, storage, use, disclosure or deletion.

Processor: a person or organisation processing personal data on behalf of the Data Controller.

GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council.

II. Data Controller and contact details

Data Controller: Zombori Andrea, private individual with a tax number.

  • Telephone: +36 30 421 5644
  • E-mail: westbudapestapartman@gmail.com
  • Tax number: 57396932-1-41
  • Accommodation: West Budapest Apartment, 1132 Budapest, Váci út 46/A, Hungary
  • NTAK registration: MA24091467

Questions or requests concerning personal data may be submitted using the contact details above.

III. Purposes of processing

Personal data may be processed for purposes including:

  • responding to enquiries;
  • processing booking requests and preparing offers;
  • concluding and performing the accommodation contract;
  • communication before, during and, where necessary, after the stay;
  • issuing invoices and accounting documents;
  • complying with statutory NTAK and VIZA reporting obligations;
  • compliance with other legal obligations;
  • establishing, exercising or defending legal claims.
IV. Legal bases for processing

The applicable legal basis depends on the purpose of the processing.

  • Article 6(1)(b) GDPR: processing necessary for the performance of a contract or in order to take steps at the request of the data subject prior to entering into a contract, including booking requests.
  • Article 6(1)(c) GDPR: processing necessary for compliance with a legal obligation, including invoicing and statutory accommodation reporting obligations.
  • Article 6(1)(a) GDPR: consent, where a specific processing activity is based on the data subject's consent.

Where processing is based on consent, consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

V. Categories of personal data processed

In connection with enquiries and reservations, we may process information including:

  • name of the booking guest;
  • e-mail address;
  • telephone number;
  • billing name and address;
  • company and tax information where a business invoice is requested;
  • number of guests;
  • arrival and departure dates;
  • expected arrival time;
  • other information voluntarily provided where necessary for managing the booking.

VIZA – mandatory guest data recording

Hungarian accommodation providers are required by law to record specified personal data concerning every guest using accommodation services.

Depending on the applicable legislation and the information contained in the identity document, these data may include name, name at birth, place and date of birth, sex, citizenship, mother's name and identification-document data.

Guests aged 14 and over must present a document suitable for establishing their identity.

For guests younger than 14, the required personal data may be recorded on the basis of information provided by their representative, such as a parent or guardian.

Personal data must nevertheless be recorded for all guests regardless of age.

Images of identification documents scanned for the statutory registration process may not be stored by the accommodation provider's scanning device or by the VIZA system.

If a guest aged 14 or over fails to present the required identification document, the accommodation provider is required by Hungarian law to refuse the accommodation service.

Official information concerning the VIZA system is available at vizainfo.hu.

VI. Retention periods

Personal data are retained only for as long as necessary for the applicable processing purpose or as required by law.

  • Telephone and e-mail contact data: during the booking and accommodation process and, where no other lawful retention reason applies, generally for no longer than 90 days after departure.
  • Enquiries that do not result in a booking: generally for no longer than 90 days after the enquiry has been closed, unless further retention is required.
  • Accounting and invoice information: for the statutory accounting retention period, generally 8 years.
  • Statutory accommodation data: retained for the periods specified by applicable Hungarian legislation and the rules governing the VIZA system.

Where personal data are required in connection with a legal dispute, authority procedure or legal claim, they may be retained until the relevant matter has been finally resolved.

VII. Cookies and the Webnode website
VIII. Data security

The Data Controller seeks to use appropriate technical and organisational measures to protect personal data processed in connection with the accommodation service.

Access to personal data is limited to the extent necessary for providing the accommodation service, complying with legal obligations or enabling an authorised processor to perform its tasks.

Reasonable measures are taken to protect personal data against unauthorised access, alteration, disclosure, loss or destruction.

IX. Recipients and external service providers

Personal data are disclosed to another organisation only where there is an appropriate purpose and legal basis for doing so.

Relevant recipients or systems may include:

  • Webnode: in connection with hosting, technical operation and website functionality;
  • NTAK / VIZA: where required for statutory accommodation-sector reporting;
  • Hungarian tax authorities: where required in connection with invoicing or taxation;
  • financial service providers: to the extent required for payments made by bank transfer;
  • courts or public authorities: where disclosure is required or authorised by applicable law.

Guest personal data are not sold to third parties.

X. Rights of the data subject

Subject to the conditions set out in the GDPR, data subjects may have the following rights:

Right of access You may request information about whether and how your personal data are being processed.
Rectification You may request correction of inaccurate or incomplete personal data.
Erasure You may request deletion where the applicable legal conditions are met.
Restriction You may request restriction of processing in circumstances provided by the GDPR.
Data portability Where applicable, you may request your data in a structured and portable format.
Right to object You may object to processing in the circumstances provided by the GDPR.
Withdrawal of consent Where processing is based on consent, consent may be withdrawn at any time.
Right to complain You may lodge a complaint with a supervisory authority or seek judicial remedy.

These rights are subject to the conditions and limitations set out in applicable law. For example, personal data cannot be erased where the Data Controller is legally required to retain them.

XI. Exercising your data-protection rights

Requests concerning personal data may be submitted to the Data Controller by e-mail or telephone using the contact details provided above.

The Data Controller will assess the request and, as a general rule, provide information on the action taken within one month of receiving the request, subject to the rules of the GDPR.

If you believe that the processing of your personal data infringes your rights, you may lodge a complaint with the Hungarian supervisory authority or seek judicial remedy.

XII. Amendments to this Privacy Notice

This Privacy Notice may be amended where necessary, including following changes in legislation, regulatory practice, website functionality or data-processing activities.

The current version of this Privacy Notice is published on this website.

Last updated: 13 September 2026.

Supervisory authority

Hungarian National Authority for Data Protection and Freedom of Information

Address 1055 Budapest
Falk Miksa utca 9–11.
Hungary
Postal address 1363 Budapest
P.O. Box 9.
Hungary
E-mail ugyfelszolgalat@naih.hu
Telephone +36 1 391 1400