ENIGMA Apartments – Hurghada
Hatályos: 2026.07.06
The purpose of this Privacy Notice is to establish the principles and rules governing the processing of personal data and other information provided by users while using the https://enigmaapartments.hu/ website and made available to the website operator (the “Data Controller”).
This Notice applies solely to data supplied to the Data Controller as required for use of the website. Its provisions do not apply where a person voluntarily makes all or part of their personal data publicly available on or through the website.
PURPOSE OF DATA PROCESSING
Enigma Apartments (hereinafter the “Data Controller”) is committed to protecting its customers’ personal data. It therefore takes particular care to ensure that the collection, processing, use, handling and potential transfer of personal data complies with Act CXII of 2011 on Informational Self-Determination and Freedom of Information; Act XLVIII of 2008 on the Basic Requirements and Certain Restrictions of Commercial Advertising Activities; Act CVIII of 2001 on Certain Issues of Electronic Commerce Services and Information Society Services; Act CXIX of 1995 on the Processing of Name and Address Data for Research and Direct Marketing Purposes; Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, applicable from 25 May 2018 (the “GDPR”); and all other applicable legislation and national and international recommendations.
This Privacy Notice forms an integral part of the contract (the “Contract”) concluded between the Data Controller and the person using the service (hereinafter the “Data Subject”).
By entering into the Contract with the Data Controller and/or using the website, the Data Subject acknowledges that they have read this Privacy Notice and consents to the Data Controller processing and recording the data supplied by the Data Subject in accordance with applicable law. The Data Subject also consents to the Data Controller recording their contact details in its database for the purpose of providing information about its services, changes to those services, news and updates, promotional offers and other changes affecting the Data Subject.
1. DEFINITIONS
Data Subject: Any identified natural person or natural person who can be identified, directly or indirectly, from personal data.
Personal Data: Any information relating to the Data Subject, including in particular their name, identifying details and information concerning one or more aspects of their physical, physiological, mental, economic, cultural or social identity, as well as any conclusion relating to the Data Subject that may be drawn from such information.
Special Categories of Personal Data: Personal data concerning racial origin, nationality, political opinions or party affiliation, religious or other philosophical beliefs, trade union membership, sex life, health, addictions or criminal matters.
Criminal Personal Data: Personal data relating to the Data Subject that is generated during or before criminal proceedings in connection with a criminal offence or criminal proceedings by bodies authorised to conduct criminal proceedings or investigate offences, or by the prison service, as well as personal data relating to criminal convictions.
Consent: A freely given and specific expression of the Data Subject’s wishes, based on adequate information, by which they unambiguously agree to the processing of personal data relating to them, either in full or for particular processing operations.
Objection: A statement by the Data Subject objecting to the processing of their personal data and requesting that processing cease or that the processed data be erased.
Data Controller: A natural or legal person, or an organisation with legal capacity under the law applicable to it, which, alone or jointly with others, determines the purposes of processing, makes and implements decisions concerning processing, including the means used, or has such decisions implemented by a Data Processor.
Processing: Any operation or set of operations performed on data, irrespective of the procedure used, including collection, recording, organisation, structuring, storage, alteration, use, retrieval, consultation, transmission, disclosure, alignment, combination, restriction, erasure and destruction; prevention of further use; taking photographs or making audio or video recordings; and recording physical characteristics capable of identifying a person, such as fingerprints, palm prints, DNA samples or iris images.
Data Transfer: Making data available to a specified third party.
Disclosure: Making data available to any person.
Erasure: Rendering data unrecognisable in such a way that it can no longer be restored.
Marking: Attaching an identifying mark to data for the purpose of distinguishing it.
Restriction of Processing: Attaching an identifying mark to data for the purpose of permanently restricting its further processing or restricting it for a specified period.
Data Destruction: Complete physical destruction of the storage medium containing the data.
Data Processing Services: Performance of technical tasks relating to processing operations, irrespective of the method, means or location used to carry out those operations, provided that the technical task is performed on the data.
Data Processor: A natural or legal person, or an organisation without legal personality, which processes data under a contract, including a contract concluded pursuant to a statutory provision.
Data File: The totality of data processed in a single filing system.
Third Party: A natural or legal person, or an organisation without legal personality, other than the Data Subject, Data Controller or Data Processor.
EEA State: A Member State of the European Union, another state party to the Agreement on the European Economic Area, or a state whose nationals enjoy the same legal status as nationals of an EEA state under an international agreement between the European Union and its Member States and a state that is not party to the EEA Agreement.
Third Country: Any state that is not an EEA State.
Personal Data Breach: Unlawful processing of personal data, including in particular unauthorised access, alteration, transfer, disclosure, erasure or destruction, as well as accidental loss, destruction or damage.
2. DATA CONTROLLERS AND PROCESSORS
Website Owner
Enigma Finance Kft.
Registered office: 1026 Budapest, Orsó utca 47, Ground Floor 2/A, Hungary
Company registration number: 01-09-993991
Tax number: 24173760-2-41
Email: info@enigmafinance.hu
Hosting Provider
Tárhely.Eu Szolgáltató Kft.
Registered office: 1144 Budapest, Ormánság utca 4, 10th Floor, Office 241, Hungary
Company registration number: 01-09-909968
Tax number: 14571332-2-42
Email: support@tarhely.eu
Website Designed by
PNGN Kft.
Registered office: 1034 Budapest, San Marco utca 19, 1st Floor, Unit 1, Hungary
Company registration number: 01-09-401627
Tax number: 22706034-2-41
Contact: info@pngn.hu
Hereinafter collectively referred to as the “Data Processors”.
3. CATEGORIES OF DATA PROCESSED
3.1. General provisions
The personal data processed by the Data Controller comprises data obtained or potentially obtained in connection with the use and performance of the Data Subject’s services, personal data provided by persons who order or may potentially order the Data Controller’s services, persons requesting quotations and users of the Data Controller’s online platform, as well as any other personal data transferred to the Data Controller by the Data Subject. Such data may include, without limitation:
Personal data:
- name;
- place and date of birth;
- mother’s birth name;
- identity card number, address card number and residential address;
- personal identification number;
- social security number, tax identification number and bank account number;
- work or personal email address and telephone number.
Special categories of personal data:
- racial origin and nationality;
- health data, including body weight, blood test results and screening results;
- data concerning addictions;
- criminal personal data.
3.2. Processing in connection with contractual relationships and quotations
In the course of its activities and for the purpose of providing services to customers, the Data Controller prepares quotations, concludes contracts and performs procurement, archiving and document-management activities necessary for its operations. It processes and retains the data listed below for the stated period for the following purposes:
- maintaining contact, including sales enquiries;
- concluding contracts;
- performing contracts;
- invoice and receivables management;
- enforcing contractual legal claims, including complaints and warranty claims;
- document management and archiving following termination of a contract by performance or otherwise.
a) Individual customers
For these purposes, the Data Controller processes the name, residential address, telephone number, email address, customer or order number and online identifier of an individual contracting with it as a customer. Processing lawfully begins before conclusion of the contract when the customer (Data Subject) contacts the Data Controller to request a quotation.
b) Representatives of corporate customers
The personal data processed comprises the natural person’s name, address, telephone number and email address.
3.3. Data processed in relation to all customers
The Data Controller retains all personal data until performance of the Contract has been completed. Such processing is necessary for performance of the Contract and compliance with the Data Controller’s legal obligations.
3.4. Registration on the Data Controller’s website
The Data Controller requests personal data from visitors to https://enigmaapartments.hu/ only where the Data Subject wishes to register or log in to request a quotation, or to request an appointment through the online interface provided for that purpose.
3.5. Other contractual partners
The Data Controller requests and processes data relating to the Data Subject’s other contractual partners and its own procurement partners to the extent and for the periods prescribed by the legislation referred to in the introduction.
4. DATA SUBJECTS AND LEGAL BASIS FOR PROCESSING
The Data Controller processes the data of customers, prospective customers and persons requesting quotations. This Notice also applies to the Data Controller’s contractual partners, visitors to https://enigmaapartments.hu/, subcontractors and other contributors.
The Data Controller processes personal data only where the individual has consented to the processing and, where applicable, transfer of their personal data to third parties, or where processing is ordered for a public-interest purpose by law or, under statutory authority and within the scope specified by law, by a local government decree.
Consent also includes ticking the relevant box while visiting the Data Controller’s website; sending personal data to the Data Controller’s postal address, email address or other contact point; configuring relevant technical settings while using information society services; or any other statement or action that clearly indicates, in the relevant context, the Data Subject’s agreement to the proposed processing of their personal data.
In addition, pursuant to Article 6 GDPR and Section 6 of the Hungarian Privacy Act, the Data Controller processes personal data where obtaining the Data Subject’s consent would be impossible or involve disproportionate expense, and processing is necessary to fulfil an obligation or pursue the legitimate interests of the Data Controller or a third party, provided that the restriction of the right to protection of personal data is proportionate to the interest pursued. The Data Controller processes personal data received from the Data Subject or another partner where the person concerned has consented to its transfer to a third party or to the Data Controller. Without the Data Subject’s express consent, the Data Controller may not transfer processed data for advertising or any other purpose.
For compliance with legal obligations, the Data Controller processes data prescribed by law concerning individuals with whom it has a business relationship as customers or suppliers for accounting and taxation purposes, including under Sections 169 and 202 of Act CXXVII of 2007 on Value Added Tax; Act CXVII of 1995 on Personal Income Tax; Act LIII of 2017 on the Prevention and Combating of Money Laundering and Terrorist Financing; and Act C of 2000 on Accounting.
By supplying personal data to the Data Controller, the Data Subject is deemed to have consented to its processing.
By supplying personal data, the Data Subject warrants that the Data Controller is authorised to process it, including transferring it where applicable.
The Data Controller excludes liability for claims arising from breach of this warranty. The Data Subject must compensate the Data Controller for all loss resulting from the warranty being untrue or inaccurate.
5. PURPOSES OF PROCESSING
The purposes for which personal data obtained by the Data Controller is processed are:
- concluding contracts;
- providing services requested from the Data Controller;
- providing discounts;
- supplying information about services and changes to them;
- maintaining the relationship between the Data Controller and the Data Subject;
- providing information through newsletters;
- providing personalised offers and services;
- supplying news and other information concerning the services provided by the Data Controller;
- carrying out marketing activities;
- creating and maintaining a marketing database;
- conducting direct marketing.
6. DURATION OF PROCESSING
Processing is limited to the personal data strictly necessary and suitable for achieving its purpose, and continues only to the extent and for the period required for that purpose, including while rights and obligations relating to informing the Data Subject, providing services and related administration remain in force.
Where a Contract is concluded, personal data is processed for the longer of:
a) the limitation period applicable to claims arising from the contractual relationship between the Data Subject and the Data Controller; or
b) the limitation period applicable to claims relating to the Data Controller’s statutory obligations under the Contract.
Where the Data Subject orders a service and provides an email address but no Contract is ultimately concluded, processing continues for as long as a contractual relationship could still be established between the parties. If it becomes clear that no contractual relationship can arise in the future—for example, because the company whose contact person supplied the personal data ceases to exist—or the Data Subject requests erasure, the personal data will be erased without delay.
7. DATA PROCESSING SERVICES
The Data Controller uses the assistance and services of one or more Data Processors, including accountants and IT service providers, in connection with its processing activities. Processing by such providers is performed under data-processing agreements concluded between the Data Controller and the relevant IT service provider or other Data Processor. These agreements impose confidentiality obligations on the Data Processors and thereby safeguard processing.
8. PERSONS AUTHORISED TO ACCESS DATA
Personal data supplied by the Data Subject may be accessed and processed by the Data Controller’s employees, executive officers, advisers and other personnel involved in processing, as well as partners to whom the Data Subject has consented to the transfer of data.
Courts and certain public authorities may access personal data processed by the Data Controller where required by law. Courts, the public prosecutor’s office and other authorities, including the police, tax authority and Hungarian National Authority for Data Protection and Freedom of Information, may contact the Data Controller to request information, data or documents. In such cases, the Data Controller must comply to the extent strictly necessary to fulfil the purpose of the request.
9. DISCLOSURE AND TRANSFER OF DATA
The Data Controller recognises the value of the Data Subject’s data and makes every effort to protect it during processing.
In certain cases, personal data supplied to the Data Controller is shared with cooperating third parties or third parties acting on its behalf where necessary to achieve the purpose for which the data was supplied. The Data Controller may also transfer personal data to a third party where this facilitates more effective service to the Data Subject or where the third party processes the data on the Data Controller’s behalf.
The Data Controller ensures that such third parties appropriately handle and protect the information and data supplied by the Data Subject.
Personal data may be transferred to third-party Data Processors that provide appropriate technical and organisational safeguards. In accordance with generally accepted data-protection practices, the Data Controller may use external service providers for regular server maintenance, data storage or other IT tasks.
The Data Controller shares information with other third parties only where:
- the Data Subject has consented;
- disclosure is required by law; or
- disclosure is necessary for or in connection with legal proceedings, or for exercising or protecting rights granted by law.
By supplying personal data, the Data Subject expressly consents to transfers of this kind and warrants that they are authorised to disclose the personal data to Data Processors for these purposes.
When the conditions for lawful processing or transfer cease to apply, the Data Controller will arrange without delay for the personal data to be erased from its database and will notify the Data Subject of the erasure.
10. DATA SECURITY
The Data Controller treats all data obtained during processing—whether stored electronically or on traditional paper media—with the utmost care and strict confidentiality. It uses all lawful means and appropriate technical and organisational measures to protect data against unauthorised access, alteration, transfer, disclosure, misuse, erasure, destruction, accidental loss and damage.
The Data Processors, the Data Controller’s partners and the Data Controller itself safeguard the data and use it strictly for specified purposes. Processed data is accessible only to authorised persons; its authenticity and integrity are safeguarded; and it is protected against unauthorised access.
The Data Controller applies technical, organisational and administrative measures providing a level of security appropriate to the risks associated with processing. To the greatest extent reasonably expected of it, the Data Controller protects personal data through appropriate confidentiality commitments and technical and security measures. Access is limited to authorised personnel who have appropriate permissions and are bound by confidentiality obligations.
Because the confidentiality, integrity and availability of data transmitted through the website are not entirely within the Data Controller’s control, the Data Controller cannot accept full responsibility in this regard. It nevertheless applies strict requirements to received data to protect the Data Subject’s information and prevent unlawful access.
11. DATA RELATING TO WEBSITE VISITORS
Purpose of processing: When the website is visited, visitor data is recorded for the purpose of providing and monitoring the services available through https://enigmaapartments.hu/ and preventing misuse.
Legal basis: The Data Subject’s consent and Sections 5–6 of Act CXII of 2011 on Informational Self-Determination and Freedom of Information.
Data processed: Date and time of the visit; address of the page visited and the previously viewed page; operating system and browser type; and IP address.
Retention period: 180 days from the date on which the website is viewed.
The HTML code of the portal available at https://enigmaapartments.hu/ contains links to and content from external servers that are independent of the Data Controller. Because users connect directly to those servers, their operators may collect user data.
Independent measurement of website traffic and other web-analytics data is provided by an external service provider, Google Analytics. Detailed information about its processing of analytics data is provided by Google at: Google Privacy & Terms.
12. NEWSLETTERS
By ordering a service through the website and providing an email address, the Data Subject consents to receiving information and notifications concerning the Data Controller’s activities in the form of newsletters sent to that email address. Subscription is voluntary and may be withdrawn at any time by using the link in the newsletter or replying by email.
The Data Controller creates a database from the details of persons who provide business contact information, including company name, name, position and business email address. It regularly sends newsletters to the organisations in that database, addressed to the business email addresses of their contact persons, on topics selected by them or which the Data Controller believes may be of interest to them. Contact details supplied during subscription are stored in the Data Controller’s customer relationship management system on servers located in Hungary within the European Union. The data is treated confidentially and is neither disclosed nor made accessible to unauthorised persons.
Such newsletters are addressed to the relevant organisations, including the Data Subject, rather than to contact persons in their private capacity. The Data Controller stores and processes the supplied details as business contact information for communicating with the Data Subject and not as the contact person’s private personal data.
The company operating the website reserves the right to exclude any person from newsletter distribution at any time.
The Data Controller processes the data until the Data Subject requests its erasure in the specified manner.
13. SOCIAL MEDIA
The Data Controller maintains social-media pages to introduce and promote its services. Communications on those pages do not create legal rights or obligations and may not be used to conclude contracts or request quotations.
The Data Controller does not process personal data published by visitors on its social-media pages. Visitors are subject to the privacy policy and terms of service of the relevant social-media platform.
If unlawful or offensive content is published, the Data Controller may remove the person concerned from the community or delete their comment without prior notice. The accommodation provider is not responsible for unlawful content or comments published by users. The Data Controller is not liable for errors, interruptions or problems resulting from the operation of a social-media platform or changes to its systems.
14. COOKIES
The Data Controller uses cookies to ensure the optimal operation of the website and online quotation-request service. Its servers may place a cookie—an individual identification file—on the computers or devices of website users. Users do not receive a separate notification each time this occurs. Cookies are used solely to facilitate technical identification of users and website visitors and to operate personalised services; the Data Controller does not use them for other purposes. Users can disable cookies by following the instructions for their browser. Disabling cookies does not prevent use of the Data Controller’s services, although it may affect certain website functions.
15. DATA SUBJECT RIGHTS
15.1. Right to information and access
The Data Subject may request information about the personal data supplied by them and processed by the Data Controller, its source, the purpose, legal basis and duration of processing, the Data Processor’s name and address and its activities relating to processing, and—where personal data has been transferred—the legal basis and recipient of the transfer.
To protect the Data Subject’s data, the Data Controller provides such information only following appropriate identification. Requests may be submitted in writing by post in the form of a private document having full evidentiary force, or by email with the appropriate identifying information. The Data Controller will provide the information in writing, in an intelligible form, to the address supplied by the Data Subject as soon as possible and no later than 30 days after receipt.
Information relating to one category of data once per year is provided free of charge. The Data Controller may charge a reasonable fee for additional requests.
15.2. Rectification
Where the Data Subject informs the Data Controller that processed personal data is inaccurate and simultaneously supplies the corrected data, or the Data Controller otherwise becomes aware of the error and the correct information, the Data Controller will rectify the personal data. The Data Subject will be notified of the rectification or of the rejection of their request.
15.3. Erasure or restriction
The Data Subject may request the erasure or restriction of their personal data. The Data Controller restricts personal data where the information available indicates that erasure could prejudice the Data Subject’s legitimate interests. Data restricted in this way is processed only while the purpose preventing its erasure continues to apply. The Data Controller notifies the Data Subject when erasure or restriction has been carried out or informs them if the request has been rejected.
15.4. Marking disputed data
The Data Controller marks personal data where the Data Subject disputes its correctness or accuracy but it cannot be clearly established that the disputed data is incorrect or inaccurate.
15.5. Right to object
Except in cases of mandatory processing, the Data Subject may object to processing:
- where the processing or transfer is necessary solely for compliance with a legal obligation applicable to the Data Controller or for the legitimate interests of the Data Controller or a third party;
- where personal data is used or transferred for direct marketing, public-opinion research or scientific research without the Data Subject’s consent; or
- in other cases specified by law.
The Data Controller examines an objection as soon as possible and no later than 15 days after its submission, decides whether it is justified and informs the applicant of its decision in writing.
If the objection is justified, the Data Controller ceases processing, including further collection and transfer, restricts the data and notifies all persons to whom the affected personal data was previously transferred of the objection and the measures taken. Those recipients must take the necessary steps to give effect to the right to object.
15.6. Data portability
Where processing is based on the Data Subject’s consent and is carried out by automated means, the Data Subject has the right to receive personal data concerning them that they supplied to the Data Controller in a structured, commonly used and machine-readable format and to transmit that data to another controller without hindrance from the Data Controller.
15.7. Refusal of direct marketing
The Data Subject may refuse direct-marketing communications at any time without giving reasons. They may require that their name not be included in contact or marketing lists and prohibit its use for direct marketing generally or for a specific direct-marketing purpose, or its transfer to a third party.
16. NOTIFICATION OF CHANGES TO DATA
The Data Subject is entitled and required to notify the Data Controller within 15 days of any change to data within their control that is processed by the Data Controller. The Data Subject bears all responsibility for consequences resulting from failure to do so.
17. WITHDRAWAL OF CONSENT
Where processing is based on the Data Subject’s consent, that consent may be withdrawn at any time without affecting the lawfulness of processing based on consent before its withdrawal. Where consent is the sole legal basis, the Data Controller will cease processing the personal data after withdrawal and erase it from all of its records.
By making a statement compliant with applicable law, the Data Subject supplies their email address and name to the Data Controller for processing so that the Data Controller may send the newsletters and information requested at subscription by electronic means and contact the Data Subject using the contact details supplied. The Data Subject expressly consents to the Data Controller recording and processing the supplied data for marketing purposes until consent is withdrawn. Consent may be withdrawn free of charge at any time, without restriction or explanation:
- by clicking the “Unsubscribe” button at the bottom of an email and unsubscribing through the linked page;
- by sending an email to info@enigmaapartments.hu; and
- by requesting erasure of the data supplied by the Data Subject and recorded by the Data Controller.
Consent is given voluntarily, taking the above information into account.
18. RIGHT TO A REMEDY
The Data Subject may submit complaints concerning personal-data protection or questions regarding processing to the Hungarian National Authority for Data Protection and Freedom of Information (1125 Budapest, Szilágyi Erzsébet fasor 22/C; postal address: 1530 Budapest, PO Box 5, Hungary) and may seek a judicial remedy before the courts.
19. RESTRICTION OF RIGHTS
The rights set out above may be restricted in exceptional cases under applicable law, including where necessary to protect the rights of the Data Subject or others.
The Data Controller discloses data contrary to the Data Subject’s privacy instructions only in cases prescribed by law and upon request from a body authorised by law to receive it.
20. MANAGEMENT OF PERSONAL DATA BREACHES
To prevent and manage personal data breaches and comply with applicable legal requirements, the Data Controller logs and continuously analyses and monitors access and attempted access to its IT systems.
A personal data breach may be reported using the Data Controller’s email address or telephone number specified in Section 2. Contractual partners and Data Subjects may use these channels to report relevant events and security weaknesses. Upon receipt of a report, the Data Controller investigates it without delay, identifies the event and determines whether it constitutes a genuine breach or a false alarm.
Where a personal data breach occurs, the Data Controller identifies and isolates the affected systems, persons and data and arranges for collection and preservation of evidence demonstrating the occurrence of the breach. It then begins remediation and restores lawful operation.
The Data Controller maintains a register of personal data breaches containing:
a) the categories of the Data Subject’s personal data affected;
b) the categories and number of Data Subjects affected;
c) the date and time of the breach;
d) the circumstances and effects of the breach;
e) the measures taken to remedy the breach; and
f) any other information required by the legislation governing processing.
Information concerning personal data breaches recorded in the register is retained for five years.
21. MISCELLANEOUS
The Data Controller reserves the right to amend this Privacy Notice unilaterally at any time. The Data Subject will be clearly informed in writing of any amendment through one of the contact channels supplied and, where necessary, the Data Controller will obtain renewed consent.
Questions and comments may be addressed to the Data Controller using any of the contact details specified in this Notice.
Issued in Budapest on 6 July 2026.