Privacy Policy

Privacy Policy

Effective: from 03/09/2026 until further notice

This Privacy Policy concerns natural persons' personal

concerning the protection of personal data and the free movement of such data

Regulation (EU) 2016/679 on the free movement of (General Data Protection

regulation, GDPR, as well as on the right to informational self-determination and

Act CXII of 2011 on the Right to Informational Self-Determination and on Freedom of Information (Infotv.)

prepared in accordance with its provisions.

  1. Data controller details
  • Data controller's name: Óré András E.V.
  • Company type: sole trader
  • VAT number: 62826727-1-24
  • Registered office 5700 Gyula, Rákóczi Ferenc u. 80
  • Site: 5700, Gyula, Kossuth Lajos u. 7
  • Contact details: [email protected]

The Controller a separate Data Protection Officer he/she is not obliged select

(Article 37 GDPR), as it is not a public authority, nor on a large scale special

organisation processing data, and the processing does not require regular and

systematic observation.

  1. The purpose, legal basis and duration of data processing

In the course of its activities, the Data Controller (The Service Provider offers escape room games, during which participants solve logical puzzles within 60 minutes.) of the following

processes personal data for the purposes of:

  1. a) Contract performance, liaison
  • Target: processing of orders, provision of services, keeping in touch.
  • Legal basis: Article 6(1)(b) of the GDPR — performance of a contract.
  • Duration: 5 years following the termination of the contract (the general limitation period under the Civil Code).
  1. b) Billing, bookkeeping
  • Target: issuing an invoice, fulfilling the bookkeeping obligation.
  • Legal basis: Article 6(1)(c) of the GDPR – compliance with a legal obligation (Section 169 of the Accounting Act).
  • Duration: 8 years (in accordance with the Accounting Act).
  1. d) Maintaining customer relations, handling complaints
  • Target: maintaining relationships with existing clients, handling complaints, customer service.
  • Legal basis: Article 6(1)(f) of the GDPR – Legitimate interests of the Data Controller (maintenance of customer service).
  • Duration: 5 years following the termination of the customer relationship.
  1. e) Statistical analysis, website development
  • Target: analysis of anonymous or pseudonymised traffic data to improve service quality.
  • Legal basis: Article 6(1)(f) of the GDPR – legitimate interest (service development), or in the case of cookie-based analysis, consent pursuant to point (a).
  • Duration: in aggregate form, 26 months from the date of collection.
  1. The scope of data processed

The Controller exclusively processes the personal data that

are strictly necessary for achieving the above purposes (principle of data minimisation).

Typically, the following data categories are processed:

  • Identifying data: name, company name
  • Contact details: email address, phone number, postal address
  • Billing details: billing name, address, tax number
  • Technical data: IP address, browser identifier, device type

Escape rooms operate a camera monitoring system, the purpose of which is:

  • continuous monitoring of player safety,
  • monitoring gameplay and providing assistance if necessary,
  • immediate detection of extraordinary events (e.g. accidents, sudden illness).
  • Camera footage is NOT stored by the service provider.
  1. Source of the data

The Data Controller processes the personal data directly from the person concerned contractor

in (during registration, ordering, quote request, and contact).

The data subject is not obliged to provide the data, but certain data

in the absence of which (e.g. email address) the provision of the service is not possible.

  1. Data processors, data transfer

The Data Controller may engage data processors to perform certain sub-tasks

utilise. On behalf of the data processors and with the data processing agreement concluded with them

the data may not be processed for purposes other than those set out in the contracts.

Typical data processors:

  • Hosting provider: website and email hosting
  • Invoicing service provider: issue of an electronic invoice
  • Email sending service: transactional emails
  • Payment provider: online card payment
  • Web analyst: Google Analytics 4 (Google Ireland Ltd.)
  • Ad pixel: Meta (Facebook) — Meta Platforms Ireland Ltd.

The current list of specific data processors is available from the Data Controller at [email protected]

Available upon request sent to the email address.

  1. Rights of the data subject

the data subject (the natural person whose data is processed by the Data Controller)

you have the following rights under the GDPR:

  • Right of access (Article 15): you can request information on whether

what data, for what purpose, and for how long the Data Controller processes.

  • Right to rectification (Article 16): may request inaccurate data

correction of it, and the completion of its missing data.

  • Right to erasure / „right to be forgotten” (Article 17): may request

deletion of their data if the purpose of processing has ceased, their consent

withdrawn, or the data processing was unlawful.

  • Restriction of processing (Article 18): they can request data processing

temporary suspension in the event of a dispute.

  • Data portability (Article 20): you can request a structured version of your data,

release in a machine-readable format (e.g. JSON, CSV).

  • Objection (Article 21): for direct marketing purposes

You can object to data processing at any time (e.g. newsletter unsubscribe).

  • Withdrawal of consent (Article 7): if data processing

it is based on consent, the data subject may withdraw it at any time

(the withdrawal does not affect the lawfulness of processing based on consent before its withdrawal).

The data subject may submit a request to exercise their rights to the Data Controller

can be sent to the e-mail address [email protected]. The Data Controller shall process the request

within 30 days at the latest answers, in justified cases this

can be extended by a further 60 days (subject to the prior

notification).

  1. Cookies

The website uses the following cookie categories:

  • Essential cookies legitimate interest, consent not required: for the basic operation of the website (session, CSRF token, cookie banner state).
  • Analytical cookies (Google Analytics 4): _ga, _ga_*, _gid — anonymised website usage statistics using Google Analytics 4 (Google Ireland Ltd.).
  • Advertising / remarketing cookies (Meta Pixel)_fbp, fr — for conversion tracking and audience building related to Facebook advertisements.
  • Other marketing/retargeting cookies: scripts enabling cookie-based tracking by third-party advertising platforms (e.g. Google Ads, LinkedIn).

The detailed cookie notice is available in a separate document, and

using the cookie banner placed on the website, the data subject

you can decide which cookies to accept.

  1. Data security measures

The Data Controller, by means of appropriate technical and organisational measures

ensures the confidentiality, integrity and availability of the processed data

its availability. As part of this:

  • uses an encrypted (HTTPS / TLS) connection for data transmission,
  • has access to the data only to the extent necessary for the performance of their duties

or an employee or data processor of the Data Controller,

  • takes regular backups,
  • the internal system uses password/two-factor authentication

to its systems.

In the event of a personal data breach, the Controller shall, upon becoming aware of such an incident,

following acquisition of knowledge within 72 hours notifies the National

National Authority for Data Protection and Freedom of Information (NAIH), if the incident

it likely entails a risk to the rights of the data subjects.

  1. Remedey, complaint

In the event of a breach of their rights under the GDPR, the data subject:

  • you can lodge a complaint with the National Authority for Data Protection and Freedom of Information

At the authority (NAIH):

– postal address: 1055 Budapest, Falk Miksa u. 9-11.

– email: [email protected]

– website: https://www.naih.hu

  • may seek judicial remedy — the lawsuit may be brought in his or her place of residence or

even before the competent court of their place of residence

initiable.

  1. Amendment of the Notice

The Data Controller reserves the right to amend this Notice

in justified cases (e.g., changes in legislation, new data processing purpose)

modify unilaterally. The modified Prospectus on the website

comes into force upon publication. Material (e.g. new-purpose

in the event of a modification introducing data processing, the Data Controller shall notify the data subjects

notify by email as well.