Privacy notice
1. Purpose and scope of this notice
The purpose of this Privacy Notice is to give data subjects appropriate, transparent and easy-to-understand information about the processing of personal data carried out by HDA Fesztivál Korlátolt Felelősségű Társaság, as data controller, in connection with the website https://bikeweek.hu/ it operates and with the Alsóörs Bike Week event — both current processing and processing planned once the ticket sales system is activated.
This notice applies to the processing of personal data of natural persons. Processing must comply with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and applicable Hungarian law. The principles of the GDPR include lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation and integrity and confidentiality (data security).
The website currently serves mainly to present the event, provide information and allow people to get in touch. Before any further services go live, we will review this notice and update it based on the actual technical service providers, processors, recipients and data flows.
2. Data controller details
| Name of data controller | HDA Fesztivál Korlátolt Felelősségű Társaság (HDA Fesztivál Kft.) |
|---|---|
| Registered office | 8226 Alsóörs, Strand sétány 20. a. ajtó, Hungary |
| Company registration number | 19-09-525933 |
| Tax number | 33122267-2-19 |
| Representative / managing director | Nagy Roland |
| info@bikeweek.hu | |
| Website | https://bikeweek.hu/ |
| Data protection contact | info@bikeweek.hu |
Data protection officer (DPO): the company has not currently designated a separate data protection officer. Should the appointment of a DPO become required by law, their name and contact details must be stated in this notice.
3. Applicable legislation
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR).
- Hungarian Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (Infotv.).
- Hungarian Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services (Eker. tv.), where it applies to the service concerned.
- The Hungarian and EU rules on electronic communications in force at any given time, in particular with regard to consent-based electronic marketing and cookies.
- Other Hungarian legislation relating to the event, consumer contracts, invoicing, complaint handling and future ticket sales.
4. Principles of data processing
The Data Controller processes personal data only for specified and lawful purposes, to the extent necessary, on an appropriate legal basis and in a manner transparent to data subjects. It restricts access to the data to those who need it to perform their tasks, and applies appropriate technical and organisational measures to ensure the confidentiality, integrity and availability of the data. Article 5 of the GDPR expressly sets out these principles.
5. Getting in touch, e-mail enquiries
The purpose of processing is to receive and answer questions, comments and enquiries sent via the bikeweek.hu website or to info@bikeweek.hu, and to maintain the necessary contact.
Data processed: name, e-mail address, telephone number, the content of the message and any other data voluntarily provided by the data subject in connection with the enquiry.
Legal basis: depending on the nature of the enquiry, the data subject's consent, the preparation/performance of a contract, or the Data Controller's legitimate interest or legal obligation. The specific legal basis must be determined based on the circumstances of the enquiry.
Retention period: until the enquiry is closed or, if it gives rise to a legal claim, a contractual matter or another documented matter, for the retention period applicable to that matter.
6. Newsletter and electronic direct marketing
A newsletter subscription option is available on the website. The purpose of the newsletter is to send news, programme information, announcements and events related to Alsóörs Bike Week electronically and — if the data subject has also given appropriate consent to this — marketing content.
Data processed: name and e-mail address, as well as the technical and evidential data of the subscription, in particular the time of subscription, the time of confirmation and the technical data recorded by the system.
Legal basis: consent. Consent must be freely given, specific, informed and unambiguous; a pre-ticked box or mere silence does not constitute valid consent.
Under the double opt-in process used on the website, the subscriber receives a confirmation e-mail, and the subscription only becomes active once the confirmation link has been used.
Consent may be withdrawn at any time without giving reasons. Every newsletter sent must include an appropriate way to unsubscribe.
Retention period: until consent is withdrawn, and for as long as necessary to be able to demonstrate the lawfulness of the consent. Where appropriate, unsubscription information may continue to be kept as a suppression list in order to prevent further contact.
7. Demonstrating consent
For processing based on consent, the Data Controller may record technical data in order to be able to demonstrate that consent was given. Such data may include, in particular, the time of consent, the time of confirmation, the subject of the consent, the technical identifier used for subscription and — where the system actually records it and its processing is necessary — the IP address.
The purpose of this processing is not to profile the user, but to demonstrate when, with what content and in what manner the consent required for the processing in question was given.
8. Photo, video and audio recordings at the event
At the Alsóörs Bike Week event, the Data Controller or a contractor engaged by it may take photographs, video and other audiovisual recordings for the purposes of documenting, communicating and promoting the event, for press and social media coverage, and for promoting future events.
The legal basis and manner of making, using and publishing recordings of people's likeness and voice at the event must be determined in each specific recording situation in accordance with applicable civil law and data protection rules. Prior information must therefore be provided in a clearly visible place in the event's communications, in particular on the purpose of the recordings, where they are expected to be used and how data subjects can exercise their rights.
It is particularly justified to document appropriate consent, or another appropriate legal basis, for individually and deliberately recorded portrait or interview-style footage.
Retention period of recordings: until the communication and archiving purpose in question has been fulfilled, or for the period necessary for the purpose of use in question.
9. Prize draws, promotions and campaigns
If the Data Controller organises a prize draw, promotion or campaign requiring registration, the purpose of processing is to enable participation, verify eligibility, select and notify the winner, and hand over the prize.
Data processed: the name, e-mail address and telephone number required by the terms of participation, as well as data necessarily generated during the game.
A separate privacy notice or a supplement to this notice may be prepared for individual games. Use for marketing purposes cannot be automatically inferred from participation in a prize draw.
10. Processing related to the technical operation of the website
In operating the website, the web server and IT system may process technical data necessary for its operation, in particular IP address, time, browser and device data, requested resources, and error and security log data.
Purpose: secure operation of the website, troubleshooting, availability, detection of unauthorised access and attacks, and ensuring the stability of the service.
Legal basis: depending on the circumstances of processing, legitimate interest or legal obligation. The scope and retention period of technical logging may not exceed what is necessary for security and operational purposes.
11. Cookies and similar technologies
bikeweek.hu may use cookies. Cookies are small data files that the browser stores on the device. The Data Controller categorises cookies as strictly necessary, preference/functional, statistical and — if actually used — marketing cookies.
Before any cookies that are not strictly necessary, or statistical or marketing cookies, are used, an appropriate consent mechanism must be provided. Consent must be based on a clear, prior and revocable decision. The NAIH treats cookie and privacy notices as a separate information topic.
The specific list of cookies — name, provider, purpose, type, lifetime, first or third party, and the condition of activation — may only be stated based on the technical elements actually installed. No Google, Meta, TikTok, advertising or other cookie that the website does not technically use may be listed in the notice.
12. Google Analytics
bikeweek.hu uses the Google Analytics service, the purpose of which is to produce aggregate statistics on the use of the website, analyse traffic and user journeys, and improve the website.
Statistical measurement can only be activated through the appropriate consent mechanism where the specific configuration requires prior consent. The scope of data processed by Google, the provider's role, the configuration and any international data transfers will be finalised based on the actual Google service and settings.
13. Social media and external links
bikeweek.hu may contain external links to Facebook and Instagram pages. A mere external link is not in itself the same as embedding third-party content. However, if the website embeds a social media module, video, map, font, analytics or other external content, we examine the relevant provider's data processing and cookie use separately.
The Data Controller is responsible for external providers' own data processing rules only within the scope of its own processing operations.
14. Data processors
The Data Controller may use data processors to perform certain tasks. The range of processors is determined in line with the activation of the actual services.
| Service | Processor / provider | Status |
|---|---|---|
| Hosting / infrastructure | None at present | For the technical operation of the website |
| Newsletter sending | None at present | Depending on the newsletter service |
| Analytics | Google Analytics – only if actually used | According to the consent configuration |
15. Transfers to third countries
If a service provider used processes personal data outside the European Economic Area, the legal basis and safeguards for the transfer must be determined separately. These may include, in particular, an adequacy decision of the European Commission, appropriate safeguards such as standard contractual clauses (SCCs), or another lawful mechanism applicable to the service in question.
We will only record the final list of third-country controllers and transfers after verifying the actual service contracts and configurations.
16. Complaint handling
The Data Controller handles data protection, consumer protection, event-related or service complaints it receives, for the purpose of investigating, answering and — where necessary — documenting them.
Data related to a complaint may include, in particular, the complainant's name, contact details, the subject and content of the complaint, the time and manner of submission, and documents necessary to investigate the matter.
The retention period is determined by the legislation applicable to the complaint in question and any legal claims. In the case of sales activities, we also ensure that complaint handling records are retained in accordance with consumer protection rules.
17. Data security
The Data Controller applies appropriate technical and organisational measures to protect personal data. Such measures may include, in particular, restricting access rights, strong authentication, logging, backups, regular updates, malware protection, encrypted data transmission, and contractually regulating processors' security requirements.
We adapt our security measures to the risks of the actual IT environment.
18. Personal data breaches
A personal data breach is any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
The Data Controller investigates and documents breaches and takes the necessary measures based on the risk. Where the conditions under the GDPR are met, the breach must be notified to the competent supervisory authority within the deadline set by the GDPR, and in the case of high risk we also consider informing the data subjects.
19. Automated decision-making and profiling
In the current operation of the website, the Data Controller does not use automated decision-making that produces legal effects concerning the data subject or similarly significantly affects them.
If marketing or analytics services are used in the future, we will examine separately whether the technology in question performs profiling, and will state this fact, its purpose, legal basis and the related data subject rights appropriately in this notice.
20. Rights of data subjects
Under the GDPR — depending on the legal basis and circumstances of the processing concerned — data subjects have, in particular, the following rights. According to the NAIH's guidance, as a general rule data subjects may request access, rectification, erasure, restriction and portability, and may object where processing is based on legitimate interest.
20.1. Right to information and access
The data subject has the right to obtain confirmation as to whether their personal data are being processed, and is entitled to the information on the processing required by the GDPR and to a copy of the personal data processed.
20.2. Right to rectification
The data subject may request the rectification of inaccurate personal data and the completion of incomplete data.
20.3. Right to erasure
The data subject may request the erasure of their personal data where the conditions under the GDPR are met. Erasure does not apply, for example, where processing is necessary for compliance with a legal obligation or for the establishment, exercise or defence of legal claims.
20.4. Right to restriction of processing
The data subject may request restriction of processing in the cases set out in the GDPR, for example where the accuracy of the data is contested, the processing is unlawful, or in connection with a legal claim or an objection.
20.5. Right to data portability
Where the conditions are met, the data subject has the right to receive the personal data concerning them that they have provided to the Data Controller in a structured, commonly used and machine-readable format, and may request that they be transmitted to another controller.
20.6. Right to object
The data subject has the right to object, on grounds relating to their particular situation, to processing based on legitimate interest. Where data are processed for direct marketing purposes, the right to object extends in particular to processing related to direct marketing.
20.7. Withdrawal of consent
Where processing is based on consent, the data subject may withdraw their consent at any time. Withdrawal does not affect the lawfulness of processing before the withdrawal.
20.8. Rights related to automated decision-making
Should the processing fall within the scope of automated decision-making under Article 22 of the GDPR, the Data Controller will separately inform the data subject of the specific rights they may have in that case.
21. Handling data subject requests
Data subjects may submit their requests to info@bikeweek.hu. Where necessary, the Data Controller verifies the identity of the requester in an appropriate manner, but may only ask for data that is necessary for that purpose.
The Data Controller provides information on the action taken on a request without undue delay and, as a general rule, within one month of receipt of the request. For complex or numerous requests, this deadline may be extended by a further two months under the conditions of the GDPR, of which the data subject will be informed within the first month.
22. Remedies
Data subjects may first contact the Data Controller directly with their data protection request or complaint.
Data subjects have the right to lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság, NAIH) if they consider that the processing of their personal data infringes the GDPR. Current NAIH contact details: 1055 Budapest, Falk Miksa utca 9–11., Hungary; postal address: 1363 Budapest, Pf. 9.; e-mail: ugyfelszolgalat@naih.hu; telephone: +36 (30) 683-5969, +36 (30) 549-6838, +36 (1) 391 1400.
Data subjects may also seek judicial remedy under the GDPR and applicable Hungarian law.
23. Disclosure to authorities, courts and other recipients
The Data Controller may disclose personal data to an authorised authority, court or other body in cases specified by law, or for compliance with a legal obligation or the establishment, exercise or defence of legal claims.
Any such disclosure is always limited to the data necessary.
24. Processing of minors' data
Minors may also be among the visitors of the Alsóörs Bike Week event. The Data Controller processes the personal data of children and minors with particular care. In the case of online services specifically aimed at children, or consent-based processing, the relevant specific rules must be taken into account when designing the process in question.
For photo and video recordings, we take particular care regarding the recognisable depiction of minors, in accordance with the applicable legislation.
25. Data retention principles
The Data Controller does not keep personal data for longer than is necessary to achieve the purpose of processing, to comply with a legal obligation or to handle legal claims. Retention periods must be determined for each processing purpose.
| Purpose of processing | Applicable period |
|---|---|
| Getting in touch | Until the enquiry is closed, or longer where necessary in connection with a legal claim |
| Newsletter | Until consent is withdrawn; longer to the extent necessary for evidential/suppression list purposes |
| Technical logs | The period necessary for security and operational purposes |
| Cookies | According to the actual lifetime of the cookie in question |
| Photo/video | For as long as necessary for the communication/archiving purpose in question |
| Complaint handling | According to the statutory and legal claim handling period applicable to the complaint in question |
26. Amendments to this privacy notice
The Data Controller is entitled to amend this notice, in particular in the event of changes to the website's functions, the event's services, the technologies used, processors or legislation.
The amended notice must be published with its effective date indicated. Where an amendment involves a new processing purpose, a new legal basis or a change materially affecting data subjects' rights, the Data Controller ensures that data subjects are appropriately informed in advance and — where necessary — that new consent is obtained.