Kolping Hotel**** Spa & Family Resort
(processing of photos and video recordings)
1. Name, seat and representative of the controller
- Name: Kolping Hotel Kft.
- Seat: 8394 Alsópáhok Fő út 120.
- Statutory representative: Csaba Baldauf Managing Director
- Contact person in relation to data protection matters: Judit Nyírő Deputy Director responsible for operation
2. Data protection officer
- Dr. Boldizsár Morvay - firstname.lastname@example.org
3. Definition of the processed data
- facial image, voice of people in photos or video recordings
4. Purpose of processing
- marketing purpose, promoting the hotel’s services
5. Legal basis for processing
- data subject’s consent – point (a) of Article 6(1) of the GDPR
6. Legal consequences of failure to provide data
- the processing does not take place.
7. Transfer of personal data
- data will be transferred to Facebook Inc., to a third country – in order to be published at www.facebook.com and www.instagram.com.
8. Duration of the processing of personal data
- 5 years from the time the photo or video has been taken
9. Information about the rights of the data subject
The data subject shall have the right:
- to obtain from the controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data.
- to obtain from the controller without undue delay the rectification of inaccurate personal data concerning him or her.
- to obtain from the controller the erasure of personal data concerning him or her without undue delay and the controller shall have the obligation to erase personal data without undue delay if certain other conditions are met.
- to obtain from the controller restriction of processing if
- the accuracy of the personal data is contested by the data subject /the restriction lasts until the controller verifies the accuracy of the personal data,/
- the processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead;
- the controller no longer needs the personal data, but they are required by the data subject for the establishment, exercise or defence of legal claims.
- the data subject has objected to processing pending the verification whether the legitimate grounds of the controller override those of the data subject.
- to receive the personal data concerning him or her, which he or she has provided to the controller, in a structured format and have the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided, where the processing is based on consent or on a contract, and it is carried out by automated means.
- where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing.
- not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
10. Information about profiling, automated decision-making
- profiling and automated decision-making do not take place
11. Data storage, data security
The controller and the organisation involved as a processor store the data on their own computing devices which are held at the registered seat, and in the case of the processor, they can be found in a server farm. The controller and processor choose and operate their IT devices so that the data processed could be accessed by the authorised persons, their credibility and validation remain assured, it could be verified that they had not been modified and they are protected against unauthorised access. Data are protected against unauthorised access, modification, transfer, disclosure, erasure or destruction as well as accidental destruction, damage and unavailability due to the change of the applied technology in such a way that, by having regard to the current technological development, the controller takes care of the protection of processing security with technological, organisational and structural measures that provide an adequate level of protection against the risks associated with processing.
12. Right of access to the competent authority
In the event of any breach of their rights, the data subject may have recourse to court against the controller. The reconsideration of the legal action falls within the competence of the regional court (Contact detail of Zalaegerszeg Regional Court: 8900 Zalaegerszeg Várkör u 2.). At the data subject’s option, the action can be brought to the regional court in whose jurisdiction the data subject’s home address or temporary residence is located. Such cases will be given priority by the court.
You may lodge an appeal or a complaint to the Hungarian National Authority for Data Protection and Freedom of Information. Name: Hungarian National Authority for Data Protection and Freedom of Information Seat: 1125 Budapest, Szilágyi Erzsébet fasor 22/C. Postal address: 1530 Budapest, Pf.: 5. Phone: 06.1.391.1400 Fax: 06.1.391.1410 E-mail: email@example.com Website: http://www.naih.hu
“This is the first hotel which gives more than it promisses. Excellent, cannot wait for going back.”
Booking.com, 10. November 2018