PRIVACY NOTICE
Processing of personal data in connection with online table reservations
Effective from: 27 July 2026
1. Purpose of this Privacy Notice
This Privacy Notice explains how Kedves Kávézó Kft. processes the personal data of individuals who make an online table reservation through the dorothea.hu website.
Personal data is processed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council, hereinafter referred to as the GDPR, and the applicable Hungarian data protection legislation.
2. Data Controller
Company name: Kedves Kávézó Kft.
Registered office: 2000 Szentendre, Hamvas Béla utca 44, 15, Hungary
Company registration number: 13-09-145167
Tax number: 23185737-2-13
Represented by: József Ludányi
Telephone: +36 20 270 3070
Email: [email protected]
Website: dorothea.hu
Hereinafter referred to as the Data Controller.
Data subjects may contact the Data Controller at the above contact details with any questions, requests or complaints concerning the processing of their personal data.
The Data Controller has not appointed a data protection officer, as the nature of its processing activities does not require such an appointment.
3. Hosting provider and Data Processor
Company name: Sonrisa Informatikai Kft.
Registered office: 1138 Budapest, Népfürdő utca 22., Hungary
Company registration number: 01-09-877659
Tax number: 13873222-2-41
Represented by: Miklós Szurdi, Managing Director
The hosting provider may access personal data in connection with hosting the Website, operating the relevant IT infrastructure and providing technical services.
The hosting provider processes personal data as a data processor, solely on the documented instructions of the Data Controller, and may not use the data for its own purposes.
4. Categories of data subjects
This processing applies to natural persons who:
- initiate an online table reservation through the dorothea.hu Website;
- modify or cancel a reservation;
- contact the Data Controller in connection with a reservation;
- make a reservation on behalf of another individual or a group of guests.
Where a person making a reservation provides another person’s personal data, they must ensure that they are authorised to provide such data.
5. Processing relating to online table reservations
5.1. Purposes of processing
Personal data is processed for the following purposes:
- recording the online table reservation;
- verifying and confirming the reservation;
- communicating with the person making the reservation;
- modifying or cancelling the reservation;
- discussing delays, changes of time or other circumstances affecting the reservation;
- preparing and providing the requested service;
- establishing, exercising or defending potential legal claims.
5.2. Categories of personal data processed
The Data Controller processes the following data in connection with an online table reservation:
- name;
- email address;
- telephone number;
- date and time of the reservation;
- number of guests;
- date and time when the reservation was submitted, modified or cancelled;
- content of communications relating to the reservation;
- technical reservation identifier, where such an identifier is generated by the system.
The Data Controller only requests personal data necessary for managing the reservation.
5.3. Legal basis for processing
The primary legal basis for processing is Article 6(1)(b) of the GDPR, as processing is necessary in order to take steps at the request of the data subject before providing the service and to perform the agreement relating to the reservation.
Without the required personal data, the Data Controller cannot record, confirm or fulfil the online table reservation.
Where personal data must be retained for the establishment, exercise or defence of legal claims, processing is based on the legitimate interests of the Data Controller under Article 6(1)(f) of the GDPR.
Where processing or retention is required by applicable legislation, the legal basis is compliance with a legal obligation under Article 6(1)(c) of the GDPR.
5.4. Retention period
Personal data provided for a reservation is processed until the reservation has been fulfilled, cancelled or otherwise concluded.
Once the reservation has been concluded, data that is no longer required will be deleted.
Where retention is necessary for the establishment, exercise or defence of legal claims, the relevant data may be retained for the applicable limitation period, generally for no longer than five years. Under the Hungarian Civil Code, the general limitation period for claims is five years.
Where legislation requires the retention of particular data or documents, the Data Controller retains such information for the period prescribed by the applicable legislation.
Where official authority or court proceedings are pending, the relevant data may be retained until the proceedings have been finally concluded.
6. Processing relating to enquiries
Where a data subject contacts the Data Controller by telephone or email, the Data Controller may process:
- the data subject’s name;
- email address;
- telephone number;
- date of the enquiry;
- content of the message or conversation;
- information required to identify the relevant reservation.
The purpose of processing is to respond to the enquiry, identify the reservation and resolve the relevant question or issue.
Where the enquiry concerns a reservation, the legal basis is Article 6(1)(b) of the GDPR. For other enquiries, processing is based on the Data Controller’s legitimate interest in responding to enquiries.
The data may be retained until the enquiry has been resolved or, where a legal claim may arise, until the relevant limitation period has expired.
7. Persons with access to data and recipients
Personal data may only be accessed by persons who require access in order to manage the reservation or provide the service.
Such persons may include:
- the management of the Data Controller;
- employees responsible for managing reservations;
- relevant employees of the hospitality venue;
- the data processor involved in operating the Website and its IT systems.
Personal data is only transferred to a third party where:
- the transfer is necessary for providing the service;
- the data subject has lawfully consented to the transfer;
- the transfer is required by legislation, a public authority or a court;
- the transfer is necessary for the establishment, exercise or defence of legal claims.
8. Transfers outside the European Economic Area
As a general rule, personal data processed in connection with online table reservations under this Privacy Notice is not transferred to a country outside the European Economic Area or to an international organisation.
Should such a transfer take place in the future, it will only be carried out subject to the appropriate safeguards required by the GDPR, and data subjects will be informed accordingly.
9. Automated decision-making and profiling
The processing of online reservation data does not involve decisions based solely on automated processing that produce legal effects concerning a data subject or similarly significantly affect them.
The Data Controller does not use reservation data for profiling.
10. Data security
The Data Controller implements appropriate technical and organisational measures to protect personal data against, in particular:
- unauthorised access;
- unauthorised alteration;
- unauthorised disclosure or transfer;
- accidental or unlawful deletion;
- destruction or damage;
- loss;
- unauthorised use of data processing systems.
Access to personal data is restricted to persons who require such access in order to perform their duties.
Although complete security of data transmitted over the internet cannot be guaranteed, the Data Controller and its Data Processor implement reasonable measures to protect personal data.
11. Rights of data subjects
Data subjects may exercise the following rights under the GDPR.
11.1. Right to information and access
The data subject may request confirmation as to whether their personal data is being processed and may request access to the personal data and information concerning the circumstances of processing.
11.2. Right to rectification
The data subject may request the correction of inaccurate personal data and the completion of incomplete personal data.
11.3. Right to erasure
The data subject may request the erasure of their personal data, particularly where:
- the data is no longer necessary for the purpose for which it was collected;
- the processing is unlawful;
- the data must be erased in order to comply with a legal obligation;
- the data subject has validly objected to the processing.
The right to erasure does not apply where processing is required for compliance with a legal obligation or for the establishment, exercise or defence of legal claims.
11.4. Right to restriction of processing
The data subject may request that processing be restricted where:
- the accuracy of the personal data is disputed;
- the processing is unlawful, but the data subject opposes erasure;
- the Data Controller no longer requires the data, but the data subject requires it for a legal claim;
- the data subject has objected to the processing and the objection is still being assessed.
11.5. Right to data portability
Where processing is based on a contract or consent and is carried out by automated means, the data subject may request to receive personal data they have provided in a structured, commonly used and machine-readable format.
The data subject may also request that this data be transmitted directly to another controller where technically feasible.
11.6. Right to object
The data subject has the right to object to processing based on the legitimate interests of the Data Controller.
Following an objection, the Data Controller will no longer process the personal data unless it demonstrates compelling legitimate grounds that override the interests and rights of the data subject or where processing is necessary for the establishment, exercise or defence of legal claims.
11.7. Exercising data subject rights
Requests may be submitted using the following contact details:
Email: [email protected]
Postal address: Kedves Kávézó Kft., 2000 Szentendre, Hamvas Béla utca 44, 15, Hungary
The Data Controller will respond without undue delay and, in any event, within one month of receiving the request.
Where necessary due to the complexity or number of requests, this period may be extended by a further two months. The data subject will be informed of the extension and its reasons within the initial one-month period.
Data subject rights and the rules governing responses to requests are set out in Articles 12–22 of the GDPR.
Where the Data Controller has reasonable doubts concerning the identity of the person making a request, it may request additional information necessary to confirm their identity.
Requests are generally handled free of charge. Where a request is manifestly unfounded or excessive, particularly because of its repetitive character, the Data Controller may charge a reasonable fee or refuse to act on the request.
12. Complaints and legal remedies
Where a data subject considers that the processing of their personal data infringes applicable data protection legislation, they may lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information.
Hungarian National Authority for Data Protection and Freedom of Information – NAIH
Address: 1055 Budapest, Falk Miksa utca 9–11., Hungary
Postal address: 1363 Budapest, P.O. Box 9, Hungary
Email: [email protected]
Telephone: +36 1 391 1400
Official gateway short name: NAIH
Official gateway KR ID: 429616918
The Authority’s current contact details and online procedures are available through its official website.
The data subject also has the right to bring proceedings before a competent court where they consider that their rights have been infringed as a result of the processing of their personal data.
Proceedings may also be brought before the court having jurisdiction at the data subject’s permanent or temporary place of residence, subject to the applicable rules of jurisdiction.
13. Cookies and technical processing
Detailed information concerning cookies, website analytics tools and other technical processing activities is provided in the separate Cookie Notice available on the Website.
Statistical, marketing or other cookies that are not strictly necessary may only be used on the basis of the visitor’s valid consent.
14. Amendments to this Privacy Notice
The Data Controller may amend this Privacy Notice, particularly in the event of:
- changes in legislation;
- changes in regulatory practice;
- modifications to the online reservation system;
- the engagement of a new Data Processor;
- changes to the purposes or methods of processing.
The amended Privacy Notice becomes effective when published on the Website.
Where a change is material, the Data Controller will appropriately draw the attention of data subjects to the amendment.
15. Applicable legislation
Matters not addressed in this Privacy Notice are governed in particular by the applicable provisions of:
- Regulation (EU) 2016/679 of the European Parliament and of the Council, the General Data Protection Regulation;
- Hungarian Act CXII of 2011 on Informational Self-Determination and Freedom of Information;
- Hungarian Act V of 2013 on the Civil Code;
- Hungarian Act CVIII of 2001 on Electronic Commerce and Information Society Services.