
Privacy Policy
Privacy Policy
Effective date: 5 August 2026
This Privacy Policy provides information about the processing of personal data carried out on the www.agarditours.com website (the "Website"), operated by AgĂĄrdi BendegĂșz SzpĂrosz, sole trader (the "Data Controller" or "Service Provider").
The Data Controller is committed to protecting personal data and ensures that its data processing complies with Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation, the "GDPR") and with Hungarian Act CXII of 2011 on Informational Self-Determination and Freedom of Information ("Infotv.").
Important: The Website does not include an online payment system, no card payments are made on it, and the Website does not handle or store any bank card data.
1. Data controller details
- Name: AgĂĄrdi BendegĂșz SzpĂrosz, sole trader (egyĂ©ni vĂĄllalkozĂł)
- Registered seat: 2045 Törökbålint, Szent Istvån utca 86., Hungary
- Tax number: 59560362-1-33
- Registration number: 57606671 (Register of Private Entrepreneurs, Hungary)
- E-mail: contact@agarditours.com
- Phone: +36 30 180 8716
- Website: https://www.agarditours.com
The Data Controller does not carry out activities that would require the mandatory appointment of a Data Protection Officer (DPO) under Article 37 of the GDPR, and therefore has not appointed one. For data protection matters, please use the contact details above.
2. Legal bases for processing
The Data Controller processes personal data on one of the following legal bases (Article 6 GDPR):
- Performance of a contract and pre-contractual steps (Article 6(1)(b) GDPR) â for quote requests, bookings, provision of the service and customer relations.
- Compliance with a legal obligation (Article 6(1)(c) GDPR) â in particular for accounting and tax obligations (invoicing, retention of records).
- Consent of the data subject (Article 6(1)(a) GDPR) â for optional, non-mandatory data (e.g. additional information provided in the contact message).
- Legitimate interests of the Data Controller (Article 6(1)(f) GDPR) â to operate the Website securely, prevent abuse, and establish or defend legal claims.
3. Purposes of processing
The Data Controller processes personal data for the following purposes:
- making contact and staying in touch;
- providing quotes;
- receiving and handling bookings;
- performing the ordered service (transfer, tour, excursion);
- maintaining customer relations;
- invoicing and related accounting obligations;
- handling complaints;
- complying with legal obligations;
- operating the Website and maintaining its security.
4. Categories of personal data processed
Depending on the purpose, the Data Controller may process the following personal data, provided by the data subject via the contact form, by e-mail, by phone, or during the booking process:
- name;
- e-mail address;
- phone number;
- content of the message or quote request;
- departure address;
- arrival address;
- date of travel;
- time of travel;
- flight number (for airport transfers, where relevant);
- number of passengers;
- number of items of luggage;
- child seat requirement;
- other remarks provided by the data subject;
- booking data;
- quote request data;
- billing data (billing name, address and â for taxable persons â tax number);
- IP address;
- technical data derived from cookies.
The Data Controller does not request or process data that is not necessary for the provision of the service, and does not process special categories of (sensitive) data under Article 9 of the GDPR.
5. Duration of processing
| Processing | Retention period |
|---|---|
| Quote request, contact (if no contract is concluded) | Up to 1 year after the matter is closed |
| Data related to bookings / performed services | 5 years from performance of the service (general limitation period under the Hungarian Civil Code) |
| Billing and accounting data | 8 years (Section 169 of Act C of 2000 on Accounting) |
| Complaint handling data | 5 years under consumer protection law |
| Server logs (technical data, IP address) | Typically short (up to a few months) at the hosting provider |
| Consent-based processing | Until the consent is withdrawn |
After the retention period expires, the Data Controller permanently deletes or irreversibly anonymises the personal data.
6. Data processors
In the course of its activities, the Data Controller uses the following data processors. Processors handle personal data solely on the Data Controller's instructions, for the purposes set out in this Policy.
6.1. Hosting provider
- Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA) â operation and hosting of the Website, and processing of server logs (including IP address).
- Data transfers take place with appropriate safeguards: Vercel Inc. is a certified participant in the EUâUS Data Privacy Framework, and/or the transfer may rely on the European Commission's Standard Contractual Clauses (SCCs).
6.2. Contact form delivery
- Web3Forms (operator: Web3Forms; https://web3forms.com) â forwards the data submitted through the Website's contact/quote form to the Data Controller by e-mail. The provider processes the data solely as a technical intermediary for the purpose of delivery.
6.3. E-mail provider
- The provider hosting the Data Controller's mailbox (contact@agarditours.com): [KITĂLTENDĆ â e-mail provider name, if relevant].
6.4. Accounting and invoicing
- To fulfil its accounting obligations, the Data Controller may use an accountant and/or invoicing software: [KITĂLTENDĆ â accountant / invoicing software, if relevant].
The Data Controller uses a technical store (Upstash/Vercel KV) to store the Website's texts; this service stores only the Website's textual content and does not process any personal data.
7. Cookie management
The Website uses strictly necessary cookies required for its proper operation, for example to maintain the session of the hidden administration interface. These cookies are essential for the basic operation of the Website; their use is based on the Data Controller's legitimate interest and does not require separate consent.
The Website currently does not use analytics, advertising or other (non-essential) behaviour-tracking cookies, and does not use external tracking scripts; therefore no cookie consent banner is required.
Cookies can be managed, restricted or deleted at any time in the browser; however, disabling strictly necessary cookies may affect the operation of certain Website functions.
8. Details of individual processing activities
8.1. Contact form
- Data processed: name, e-mail address, phone number, message content, and any additional data voluntarily provided in the form (e.g. date of travel, destination, number of passengers).
- Purpose: answering the enquiry, making contact, providing a quote.
- Legal basis: Article 6(1)(b) GDPR (pre-contractual steps); for non-mandatory data, Article 6(1)(a) (consent).
8.2. Contact by e-mail
- Data processed: the data subject's e-mail address, name and the data provided in the message.
- Purpose: answering the enquiry, keeping in touch.
- Legal basis: Article 6(1)(b) or (f) GDPR (legitimate interest in answering the enquiry).
8.3. Contact by phone
- Data processed: phone number, name and data provided during the call. Calls are not recorded.
- Purpose: keeping in touch, coordination.
- Legal basis: Article 6(1)(b) or (f) GDPR.
8.4. Quote request
- Data processed: name, contact details, and the travel data required for the quote (destination, date, time, number of passengers, luggage, child seat requirement, flight number, etc.).
- Purpose: preparing an individual quote.
- Legal basis: Article 6(1)(b) GDPR.
8.5. Handling bookings
- Data processed: all data required to perform the service (departure and arrival address, date, time, flight number, number of passengers and luggage, child seat requirement, contact details).
- Purpose: confirming the booking and performing the service.
- Legal basis: Article 6(1)(b) GDPR.
8.6. Billing data
- Data processed: billing name, address, tax number (for taxable persons), and the mandatory content of the invoice.
- Purpose: complying with statutory invoicing and accounting obligations.
- Legal basis: Article 6(1)(c) GDPR (legal obligation).
9. Rights of the data subject
Under the GDPR, the data subject may exercise the following rights:
- Right of access â to obtain confirmation as to whether their personal data is being processed and, if so, what data and how.
- Right to rectification â to have inaccurate data corrected and incomplete data completed.
- Right to erasure ("right to be forgotten") â to request deletion of personal data, within the limits of the law.
- Right to restriction of processing â to request restriction in certain cases.
- Right to object â to object to processing based on legitimate interest.
- Right to data portability â to receive the provided data in a structured, machine-readable format, or to have it transmitted.
- Right to withdraw consent â for consent-based processing, consent may be withdrawn at any time, free of charge; withdrawal does not affect the lawfulness of prior processing.
The data subject may exercise these rights using the contact details above (e-mail, postal address). The Data Controller fulfils the request without undue delay, and at the latest within one month of receipt, or informs the data subject of any obstacles.
10. Data security
The Data Controller applies appropriate technical and organisational measures to protect personal data, in particular against unauthorised access, alteration, transmission, disclosure, deletion or destruction, and against accidental destruction and damage. Data is transmitted over an encrypted (HTTPS) connection, and access is limited to what is necessary.
11. Data transfers
The Data Controller transfers personal data to third parties only through the data processors identified in this Policy, or on the basis of a legal obligation (e.g. an official request). Data is not transferred to third parties for commercial purposes.
Any transfer outside the European Economic Area (EEA) takes place solely through the hosting provider identified in Section 6 (Vercel Inc., USA), with appropriate safeguards under the GDPR (EUâUS Data Privacy Framework and/or Standard Contractual Clauses).
12. Supervisory authority (NAIH) contact details
If the data subject considers that the processing of their personal data infringes the law, they may lodge a complaint with the supervisory authority:
- Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
- Address: Falk Miksa utca 9â11., 1055 Budapest, Hungary
- Postal address: 1363 Budapest, Pf. 9, Hungary
- Phone: +36 (1) 391-1400
- E-mail: ugyfelszolgalat@naih.hu
- Website: https://www.naih.hu
13. Legal remedies
In addition to lodging a complaint with the supervisory authority, the data subject is entitled to bring the matter before the competent court of their place of residence or stay if they consider that the Data Controller is processing their personal data in breach of the law.
14. Amendments to this Policy
The Data Controller reserves the right to unilaterally amend this Privacy Policy, in particular in the event of legislative changes or changes to the services. The Policy in force at any given time is available on the Website. We recommend that data subjects review this Policy from time to time.
This document is a translation of the authoritative Hungarian version. Translations are provided for information only; in the event of any discrepancy, the Hungarian version prevails. Professional (legal) review is recommended prior to publication.
