fbpx
adatvédelmi tájékoztató

Privacy Policy

Please read this!
        I. General Provisions

    1. Mirjam Kovács-Buka, sole proprietor, as the operator of the “Game of Rooms” escape rooms (hereinafter referred to as the Data Controller), provides this information under the General Data Protection Regulation (GDPR) of the European Union (Regulation 2016/679) regarding the processing of data obtained through online bookings, gift voucher orders, newsletter subscriptions, and bank transfers via the www.gameofrooms.hu website. By making a purchase or booking on the www.gameofrooms.hu site, you accept the provisions of this privacy policy.

    o About the Data Controller:
     Name: Mirjam Kovács-Buka, sole proprietor
     Registered address: 4002 Debrecen, Poszáta utca 15.
     Registration number: 54877072
     Tax number: 56241750-1-29
     Email: jatekmester@gameofrooms.hu

    2. The purpose of this privacy policy is to define the scope of the personal data processed, the method of data processing, and to ensure the implementation of constitutional principles of data protection, data security requirements, and prevent unauthorized access, arbitrary modification, and unauthorized disclosure and/or use of the data.

    3. To achieve the purpose outlined in section 2, your personal data will be processed confidentially, in compliance with the applicable legal framework. We ensure the security of the data and take the necessary technical and organizational measures and developments, as well as establish procedures required for the enforcement of the relevant legal provisions.

    II. Legal Framework

    The data processing carried out by the operator of Games of Rooms is primarily governed by the following legal regulations:
    • Act V of 2013 on the Civil Code, Section 2:43;
    • Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information (“Infotv.”);
    • Regulation (EU) 2016/679 of the European Parliament and Council (“GDPR”);
    • Act CVIII of 2001 on Electronic Commerce Services and Certain Aspects of Information Society Services (“Eker. tv.”);
    • Act C of 2003 on Electronic Communications;
    • Act XC of 2005 on Electronic Freedom of Information;
    • Act XLVII of 2008 on the Prohibition of Unfair Commercial Practices against Consumers;
    • Opinion 16/2011 on the EASA/IAB Best Practice Recommendation on Online Behavioural Advertising;
    • Act XLVIII of 2008 on the Basic Conditions and Certain Restrictions of Economic Advertising Activities (“Grt. tv.”);
    • Act VI of 1998 on the Promulgation of the Strasbourg Convention on the Protection of Individuals with regard to Automatic Processing of Personal Data of January 28, 1981;
    • Act CXIX of 1995 on the Use of Name and Address Information for Research and Direct Marketing Purposes (“Katv.”).

    III. Legal Basis for Data Processing

    Your personal data is processed according to the relevant data protection laws based on the following legal grounds:
    • GDPR Article 6(1)(a): Your voluntary consent based on appropriate information;
    • GDPR Article 6(1)(b): Data processing is necessary for the performance of a contract to which the user (as a data subject) is a party (contract performance);
    • GDPR Article 6(1)(c): Data processing is necessary to fulfill legal obligations applicable to the Data Controller (e.g., accounting and bookkeeping obligations);
    • Eker. tv. Section 13/A: Personal identification data and addresses of users may be processed without consent for the creation, definition, modification, monitoring of contract performance, invoicing, and enforcing claims related to the provision of information society services.
    IV. Scope, Purpose, and Duration of Data Processing

    1. User Identification and Registration (Online Booking, Gift Voucher Purchase)
    o Personal data processed: Full name, email address, phone number, mailing address (mandatory).
    o Purpose: To identify users, create contracts, and provide personalized services (online booking, gift voucher purchase).
    o Legal basis: GDPR Article 6(1)(b).
    o Data retention: 5 years (statute of limitations for claims arising from the contract).
    You may also provide the following data on a voluntary basis:
    o Personal preferences related to the booking or gift voucher purchase.
    o Purpose: Personalized service and evaluation of partnership relationships.
    o Data retention: Until the user’s consent is withdrawn or 5 years.

    2. Billing
    o Additional data processed: Billing name (if different), billing address.
    o Purpose: To complete the payment process for bookings or gift voucher purchases.
    o Legal basis: GDPR Article 6(1)(b) and Eker. tv. Section 13/A.
    o Data retention: 5 years for booking-related data; 8 years for billing data to fulfill accounting obligations.

    3. Sending Notifications
    o Data processed: Email address (for non-marketing messages like booking confirmation, invoice).
    o Purpose: To provide personalized service to registered users.
    o Legal basis: GDPR Article 6(1)(b).
    o Data retention: 5 years (statute of limitations for claims arising from the contract).

    4. Newsletter Service
    o Data processed: Full name, email address (for marketing communication).
    o Purpose: To send updates about the services provided by Game of Rooms.
    o Legal basis: GDPR Article 6(1)(a) (user’s voluntary consent).
    o Data retention: Until consent is withdrawn.
    5. Use of Cookies
    o Cookies are used to enhance user experience and analyze website traffic.
    o No personal identification data is collected unless voluntarily provided by the user.

    6. Log Files
    o Data processed: Dynamic IP address, browser type, operating system, user activity on the website.
    o Purpose: Technical maintenance and site usage statistics.
    o Data retention: 15 days after logging and evaluation.

    V. Data Controllers and Processors

    The website uses Google Analytics for web analytics, with Google Inc. acting as the data processor.

    VI. Details of the Hosting Provider:

    Company Name: Hostgator.com LLC, member of Endurance International Group, Inc.
    Mailing Address: 10 Corporate Drive, Burlington, MA 01803, United States
    Headquarters: 10 Corporate Drive, Burlington, MA 01803, United States
    Phone: +1-713-574-5287
    Content of Data Processing: Web hosting
    The operation and development of the booking system’s IT infrastructure is carried out by an appointed legal entity:
    Name: …………………………………
    Headquarters: …………………………………
    Phone: …………………………………………
    E-mail: …………………………………
    We reserve the right to engage additional data processors beyond those listed above. The data (name, address) of these processors will be made available to users no later than the commencement of data processing.
    Individuals Authorized to Access Personal Data
    Our employees, agents, and persons collaborating with us who need access to the processed data for the performance of their work duties and tasks are entitled to access the personal data. Taking this into account, we are obliged to ensure that those authorized to access the data comply with the provisions set out in this privacy notice and the applicable laws.

    VII. Your Rights Regarding Data Processing

    1. Right to Request Information
    a) Upon your request, we will inform you in writing—without undue delay, but no later than within 25 days from the submission of your request—about the data we process or that is processed on our behalf, including the source of the data, the purpose, legal basis, and duration of processing, the name and address of the data processor, and the activities related to data processing. Additionally, if your personal data is transferred, we will inform you about the legal basis and the recipient of the transfer.
    b) The information is provided free of charge. In the case of an obviously unfounded or excessive request (especially if it is repetitive), we may:
    o charge a reasonable fee based on administrative costs incurred by providing the requested information or measures;
    o refuse to take action on the request.
    The burden of proving that a request is unfounded or excessive lies with MindQuest.hu Kft.

    2. Right to Erasure
    a) We are obliged to delete personal data if:
    o its processing is unlawful;
    o you withdraw your consent and there is no other legal basis for processing;
    o the data is incomplete or inaccurate;
    o the purpose of processing has ceased, or the legal period for storing the data has expired;
    o a court or authority orders the deletion of the data.
    b) Instead of deletion, we may lock the data if requested by you, or if based on available information, deletion would harm your legitimate interests. Locked data can only be processed as long as the purpose of the data processing that prevented deletion exists.

    3. Right of Access
    You have the right to receive confirmation from us as to whether your personal data is being processed, and if so, you have the right to access the following information:
    o the purpose of data processing;
    o categories of personal data concerned;
    o the recipients of your personal data;
    o the retention period for the data, or if that is not possible, the criteria used to determine the period.
    You are also entitled to request:
    o the rectification, erasure, or restriction of your personal data;
    o to submit a complaint to a supervisory authority.
    We will provide you with a copy of your personal data. Additional copies may be subject to a reasonable fee based on administrative costs. If you submit your request electronically, we will provide the information electronically, unless you request otherwise.

    4. Right to Rectification
    Upon your request, we will rectify any inaccurate personal data related to you without undue delay.

    5. Right to Object
    You may object to the processing of your personal data if:
    o the data is processed solely for the fulfillment of a legal obligation or to enforce a legitimate interest, except in cases of mandatory data processing;
    o the data is used for direct marketing, opinion polling, or scientific research purposes;
    o in other cases defined by law.
    We will suspend data processing and review your objection within a maximum of 15 days, informing you of the outcome in writing.
    If your objection is well-founded, we will stop processing your data, block it, and notify those to whom we previously transferred the data.
    If you disagree with our decision, or if the 15-day deadline is exceeded, you may seek judicial remedy within 30 days of the decision or the deadline’s expiration.

    6. Right to Restrict Processing
    We will restrict data processing if:
    o you contest the accuracy of the personal data;
    o the processing is unlawful, and you oppose the deletion of the data and instead request the restriction of its use.
    If you have objected to data processing, your personal data will only be processed, except for storage, with your consent, for the assertion of legal claims, for the protection of the rights of another person, or for important public interests of the European Union or a Member State.

    7. Right to Data Portability
    You have the right to receive your personal data in a structured, commonly used, and machine-readable format if the processing is based on your consent or a contract.
    If we cannot fulfill your request for rectification, restriction, or deletion, we will inform you within 25 days of receiving the request, explaining the factual and legal reasons for the refusal.

    VIII. Legal Remedies
    In case of any legal disputes, you may seek redress from:

    1. The National Authority for Data Protection and Freedom of Information (NAIH)
    Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
    Mailing address: 1530 Budapest, Pf. 5
    Phone: +36-1-391-1400
    E-mail: ugyfelszolgalat@naih.hu

    2. The competent court based on your place of residence or habitual residence.
    IX. NOTICE REGARDING VIDEO SURVEILLANCE SYSTEM
    We inform you that security cameras are operated in the game area. By entering the room monitored by cameras, you give explicit consent to the data processing in accordance with this notice.
    Operation of the Camera System
    Data Collected:
    The cameras transmit and record images and sound, so the data collected during monitoring includes your image and voice.

    1. Purpose of Using the Video Surveillance System:
    o Service Fulfillment:
    Participation in the game includes assistance provided by our employee throughout the duration of the game. Since our employee is at the reception while the players are in the game room, monitoring via cameras is necessary to ensure the smooth running of the game.
    o Safety:
    If our employee observes any irregularities (e.g., a participant feeling unwell), they can immediately intervene and provide assistance.
    o Asset Protection:
    In case of improper use or damage to the escape room’s equipment, our employee can stop the game immediately.

    2. Legal Basis for Data Processing:
    Service fulfillment and personal and property protection.

    3.Location of Stored Data:

    The recorded data is stored in the digital video recorder or other computing devices used as part of the video surveillance system operated by Game of Rooms, as well as on the backup hard drive, which is stored on the premises of Game of Rooms.

    4. Retention Period of the Recordings:
    The recordings from the cameras are stored for 3 business days after recording, after which they are deleted, except in cases of official use, where the retention period is 30 days.

    5.Camera Locations:
    There is one camera per room in the game area.

    6. Data Processing and Access Rights:
    Only authorized employees have access to the live feed from the security cameras. Past footage may only be reviewed by authorized employees in justified cases.If you experience any legal violations, you may seek legal remedies at the following bodies: a.) National Authority for Data Protection and Freedom of Information (NAIH)
    Address: 1125 Budapest, Szilágyi Erzsébet fasor 22/c
    Phone: +36-1-391-1400
    E-mail: ugyfelszolgalat@naih.hu
    b.) The competent court based on your place of residence or habitual residence