Duna DreamBudapest
Back to homepage

Privacy Policy

Effective from: January 1, 2026

1. Data controller information

Data controller name: Duna Dream és Jakuzzi

Address: 1137 Budapest, Jászai Mari tér 6. 3rd floor, 3/18

Phone: +36 20 359 9222

Email: dunadreamapartman@gmail.com

The data controller is not required to appoint a Data Protection Officer (DPO), as the data processing does not qualify as a high-risk activity or one involving special categories of data.

2. Legal basis and purpose of data processing

We process your data based on the following legal grounds and purposes:

Performance of a contract – GDPR Article 6(1)(b)

Processing and confirming accommodation bookings, and maintaining contact with the guest. Providing this data is a precondition for entering into the booking contract – without it we cannot provide accommodation.

Compliance with a legal obligation – GDPR Article 6(1)(c)

Maintaining a guest register, NTAK reporting obligations, invoicing and financial record-keeping under accounting law.

Legitimate interest – GDPR Article 6(1)(f)

Security of the booking system and prevention of abuse.

3. Categories of personal data processed

During an online booking we request the following data:

  • Full name
  • Email address
  • Phone number
  • Home address
  • Check-in and check-out dates
  • Number and composition of guests (adults, children, infants)
  • Payment method
  • Any notes / special requests

For card payments, card details are processed exclusively by our payment provider, Stripe; we never see or store this information.

By law, an identity document (passport or ID card) must be presented at check-in, and its details are recorded in the guest register.

4. Retention period

  • Booking and invoicing data: 8 years after the booking (pursuant to Act C of 2000 on Accounting, Section 169)
  • Guest register data: for the period prescribed by law
  • Data of deleted or cancelled bookings: 8 years from the date of the original booking if an invoicing obligation arose; otherwise deleted immediately

5. Data processors and data transfers

We transfer your personal data to the following data processors, only to the extent necessary to provide the given service:

NTAK – National Tourism Data Supply Center (Hungary)

Accommodation providers are legally required to report guest data. Legal basis: GDPR Article 6(1)(c).

Resend (email service)

Used to deliver booking confirmations and reminders. Your data is used solely for delivering the message. Resend Inc., USA – GDPR compliance: based on Standard Contractual Clauses (SCC).

Stripe (online payment)

Used to process card payments. Card details are processed exclusively within Stripe's systems; we never see them. Stripe, Inc., USA – holds PCI DSS Level 1 certification; GDPR compliance: based on SCC.

Neon (database service)

Booking data is stored in a secure, encrypted PostgreSQL database. Neon Inc., USA – GDPR compliance: based on SCC; data stored in the EU region.

Google Maps (map service)

We display an embedded Google Maps map on our contact page to help you find the location. The map only loads after your explicit consent – until then, your browser does not contact any Google server. Upon consent, Google LLC (USA) may collect data (e.g. IP address, browser data). Legal basis: GDPR Article 6(1)(a) – consent. Google's privacy policy: policies.google.com/privacy. GDPR compliance: based on SCC.

Any transfer of data to a third country (outside the EEA) takes place exclusively as described above, with appropriate safeguards (Standard Contractual Clauses) in place.

6. Your rights

Under the GDPR, you have the following rights:

  • Right of access (Art. 15): you may request information about what data of yours we process
  • Right to rectification (Art. 16): you may request correction of inaccurate or incomplete data
  • Right to erasure (Art. 17): you may request deletion of your data if the purpose of processing has ended and the law does not require retention
  • Right to restriction of processing (Art. 18): you may request that processing be suspended in certain cases
  • Right to data portability (Art. 20): you may request your data in a machine-readable format (where the legal basis is a contract)
  • Right to object (Art. 21): you may object to processing based on legitimate interest

We respond to requests within 30 days (GDPR Art. 12). In complex cases this deadline may be extended by a further 60 days at most, of which we will inform you.

To exercise your rights, please contact us:

Email: dunadreamapartman@gmail.com

Phone: +36 20 359 9222

7. Remedies

If you believe our data processing infringes the GDPR, you may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):

Address: 1055 Budapest, Falk Miksa utca 9–11.

Phone: +36 1 391 1400

Web: naih.hu

You may also turn to the supervisory authority of the EU member state of your habitual residence, and you may seek judicial remedy.

8. Cookies

Our website uses only session cookies that are strictly necessary for its operation (e.g. the admin login session). These cookies do not require consent, as they are essential for the website's basic functioning.

We do not use third-party tracking, analytics, or marketing cookies.

9. Data security

Your personal data is processed over an encrypted connection (HTTPS/TLS). Data stored in the database is encrypted at rest. We perform regular backups to prevent data loss.

In the event of a data breach (e.g. unauthorized access), in accordance with GDPR Article 33 we will notify the supervisory authority within 72 hours and, if necessary, the affected individuals as well.

10. Changes to this policy

We reserve the right to amend this policy. In the event of significant changes, we will notify visitors on the website and update the effective date. The current version is always available on this page.