Privacy Policy
Effective from 1 October 2026
This is a courtesy translation. In case of any discrepancy, the Hungarian version is binding.
1. Controller
- Name: Borbély Gergő (Thermalia Guesthouses)
- Address: 4183 Kaba, Baross Gábor utca 46., Hungary
- E-mail: info@thermalia.hu
- Phone: +36 70 425 3330
- Tulipán Vendégház: 4183 Kaba, Mácsai Sándor utca 1.
- Levendula Vendégház: 4183 Kaba, Vörösmarty utca 1.
We process personal data under the EU General Data Protection Regulation (GDPR, 2016/679) and Hungarian Act CXII of 2011. We are not required to appoint a data protection officer.
2. Bookings
- Data: name, e-mail address, phone number (optional), postal address, if the invoice is issued to someone else: billing name or company name, address and, for companies, tax number, booking details (dates, rooms, number of adults, children’s ages – without names), notes, language, payment method and status, acceptance of the terms and its time.
- Purpose: concluding and performing the accommodation contract, issuing the invoice, communication, calculating the price (children’s ages determine discounts).
- Legal basis: performance of a contract [GDPR Art. 6(1)(b)].
- Retention: 5 years after the stay (general limitation period under the Hungarian Civil Code); data in accounting records for 8 years (Hungarian Accounting Act, Section 169).
- Booking requests not confirmed via the e-mailed link are deleted automatically after 30 days.
- For bookings made by phone or e-mail, we record the data for the same purpose and on the same legal basis.
3. Guest register on arrival
On arrival we record the guests’ identity document data and stay details as required by Hungarian law (Act CLVI of 2016 and its implementing decrees) and transmit them as required. Legal basis: legal obligation [GDPR Art. 6(1)(c)]. The retention period is set by law. Data needed for the local tourist tax is processed under the municipal tax decree.
4. Payments
- Card payments are processed on Stripe’s secure payment page. We neither see nor store card details; we only receive the payment ID, amount and status. Stripe (Stripe Payments Europe Ltd., Ireland) also acts as an independent controller for card payment data: https://stripe.com/privacy.
- Bank transfers: we use the details on the bank statement (payer name, amount, reference) to match the payment.
- Refunds: card payments via Stripe; transfers to a bank account provided by the guest for this purpose.
- Legal basis: performance of a contract and legal obligation (accounting) [GDPR Art. 6(1)(b) and (c)]. Retention: 8 years.
5. E-mails
Booking-related e-mails (verification link, confirmation, transfer details, payment reminder, cancellation) are sent to perform the contract [GDPR Art. 6(1)(b)]; they contain no advertising.
Newsletter: the newsletter checkbox on the booking form is ticked by default; untick it before submitting if you do not want newsletters. You can withdraw your consent [GDPR Art. 6(1)(a)] at any time at info@thermalia.hu or via the link in the newsletter. Kept until withdrawn.
6. Contact form and booking lookup
- Contact form: name, e-mail, message – to answer your enquiry; legal basis: legitimate interest [GDPR Art. 6(1)(f)]; retention: 1 year after the enquiry is closed.
- Booking lookup: the e-mail address and booking reference are only used to display that booking and are not stored separately.
7. Bot protection, cookies, logs
- Bot protection: the booking and contact forms are protected by Cloudflare Turnstile; Cloudflare, Inc. (USA) processes technical browser data (e.g. IP address, browser type) for this. Legal basis: legitimate interest [GDPR Art. 6(1)(f)].
- Cookies: our only own cookie stores the selected language (“locale”, 1 year), which is necessary for the site to work; the admin area uses a login cookie. Stripe’s payment page and Turnstile may set cookies needed for their operation. With your consent [GDPR Art. 6(1)(a)] we also use live chat (tawk.to) and visitor statistics (Google Analytics); these are only loaded if you choose “Accept” in the cookie banner. You can change your choice any time with the “Cookie settings” link at the bottom of the page. We use no advertising cookies.
- Live chat: messages sent in the tawk.to chat window, any name and e-mail address you provide, and technical browser data (IP address, browser, page viewed) are processed by tawk.to, Inc. (187 East Warm Springs Rd, Las Vegas, NV 89119, USA) as our processor to answer your enquiry. Retention: 1 year after the conversation is closed. Please do not share card or ID document details in the chat.
- Visitor statistics: Google Analytics produces pseudonymised statistics on how the website is used (pages viewed, device, approximate location, referral source); Google Analytics 4 does not store IP addresses. Provider: Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland) / Google LLC (USA). Retention: 14 months.
- Server logs: for security and troubleshooting, the server records technical request data (IP address, time, page, browser); legal basis: legitimate interest [GDPR Art. 6(1)(f)]; retention: up to 14 days.
- External links (e.g. Google Maps) lead to other sites, whose own privacy policies apply.
8. Booking portals
Guests booking on Booking.com or Szallas.hu are processed by those portals as independent controllers, which pass the booking on to us. From the portals’ calendars we automatically import only the booked periods (no guest data) to avoid double bookings. The guest’s name and contact details, if provided by the portal, may be recorded to perform the booking [GDPR Art. 6(1)(b)].
9. Automation and artificial intelligence
The content of the “Spas” and “Events” pages (opening hours, prices, events) is collected from public sources, translated and updated with an n8n automation workflow and Anthropic PBC’s (USA) Claude artificial intelligence. No personal data of guests is used or transferred for this. No automated decision-making or profiling concerning guests takes place.
10. Processors and recipients
- Hosting and operation: Cyber In Systems Kft., 4183 Kaba, Baross Gábor utca 46., Hungary, info@cyberin.hu; server infrastructure by Forpsi / Aruba Cloud, within the European Union.
- E-mail delivery: Forpsi (mail provider of thermalia.hu).
- Card payments: Stripe Payments Europe Ltd. (Ireland).
- Bot protection: Cloudflare, Inc. (USA).
- Live chat: tawk.to, Inc. (187 East Warm Springs Rd, Las Vegas, NV 89119, USA).
- Visitor statistics: Google Ireland Ltd. (Gordon House, Barrow Street, Dublin 4, Ireland) / Google LLC (USA).
- Accounting: invoice and accounting data is shared with our accountant to meet legal obligations.
- Authorities: guest register data to the bodies designated by law.
- Transfers to the USA (Cloudflare, Stripe, tawk.to, Google) are based on the EU–US Data Privacy Framework or the European Commission’s standard contractual clauses.
11. Security
Data is received over encrypted (HTTPS) connections and stored on an access-restricted server with daily backups; only authorised persons can access the admin area; passwords are stored hashed.
12. Your rights
- Access to your data and a copy of it; rectification; erasure where no legal basis remains (data under statutory retention cannot be erased); restriction; data portability; objection to processing based on legitimate interest; withdrawal of consent at any time without affecting prior processing.
- Send your request to info@thermalia.hu; we reply within one month.
13. Remedies
You may lodge a complaint with the Hungarian supervisory authority: Hungarian National Authority for Data Protection and Freedom of Information (NAIH), 1055 Budapest, Falk Miksa utca 9–11., postal address: 1363 Budapest, Pf. 9., phone: +36 1 391 1400, e-mail: ugyfelszolgalat@naih.hu, www.naih.hu, or with the supervisory authority of your EU country of residence, and you may go to court.