Effective from 26 August 2026
Transparent information about data processing
This notice covers the public Alma Mater Hostel website, booking enquiries and messages sent through its forms.
1. Controller and data protection officer
- Controller
- Gál Ferenc University (Gál Ferenc Egyetem, “GFE”)
- Registered office
- 6720 Szeged, Dóm tér 6., Hungary
- Tax number
- 18467303-2-06
- General contact
- info@gfe.hu · +36 62 425 738
- Hostel contact
- szallas@gfe.hu · +36 66 887 163
- Data protection officer
- Mayer és Társai Law Office, 1137 Budapest, Radnóti Miklós utca 38.; ugyved@drmayer.hu; +36 1 340 4151
The University’s detailed Data Protection and Data Management Policy also applies.
2. Principles and scope
Personal data is processed lawfully, fairly and transparently, only for specified purposes and only to the extent necessary. Data is kept accurate, protected against unauthorised access and erased or anonymised when it is no longer required.
Please do not include special-category data, identification-document numbers or other unnecessary sensitive information in the free-text fields.
3. Processing activities
Booking enquiry and pre-contract communication
Data: arrival and departure dates, apartment type, number of adults and children, name, email address, telephone number and optional message.
Purpose and legal basis: checking capacity, preparing an offer and taking steps at the Guest’s request before entering into a contract; Article 6(1)(b) GDPR.
Retention: an enquiry that does not result in a contract is erased no later than six months after the last communication. If a contract is concluded, contractual data is retained for the applicable five-year limitation period and accounting records for eight years where required by law.
General messages
Data: name, email address, optional telephone number, subject and message.
Purpose and legal basis: answering the message and maintaining contact; Article 6(1)(f) GDPR, based on the legitimate interest of both parties in effective communication. If the message requests pre-contract steps, Article 6(1)(b) GDPR applies.
Retention: no longer than one year after the matter is closed, unless the correspondence is required for a contract or legal claim.
Abuse prevention and technical security
Data: short-lived, pseudonymous submission counter derived from the IP address; security and server logs may contain IP address, timestamp, requested address and browser/device information.
Purpose and legal basis: preventing spam and attacks, ensuring system availability and investigating incidents; Article 6(1)(f) GDPR.
Retention: the form submission counter expires after 15 minutes; ordinary server logs are retained for up to 30 days unless an incident requires longer retention.
Accommodation and legal obligations
Where an enquiry results in a stay, additional data may be processed for guest registration, invoicing, tourist tax, payment, security and legal compliance. The Guest receives any additional information required before that processing begins. The legal bases may include performance of a contract, compliance with a legal obligation and legitimate interests.
4. Recipients and processors
Data may be accessed by authorised staff of GFE responsible for accommodation, administration, finance, legal matters and IT support. Technical providers operating the website, hosting and email systems may process data only on documented instructions and under appropriate contractual safeguards.
Data is disclosed to public authorities, courts or other bodies only where required or permitted by law. Personal data is not sold and is not used for automated decision-making or profiling.
5. External content, cookies and international transfers
The theme does not use advertising or analytics cookies. WordPress and the hosting environment may use strictly necessary technical cookies, for example for administration, security or language-related functionality.
The Google Maps embed on the home page loads automatically when the visitor’s browser reaches the map section. The separate Directions page loads its interactive map only after the visitor actively requests it. When a map is loaded, Google may receive the visitor’s IP address and device/browser information and may set its own cookies. For the automatic home-page embed, the Controller relies on Article 6(1)(f) GDPR and its legitimate interest in providing clear location information; on the Directions page the connection is initiated by the visitor’s action.
The website may retrieve font files from Google Fonts. In doing so, the visitor’s IP address and technical request data are transmitted to Google to display the site consistently. The Controller relies on Article 6(1)(f) GDPR and its legitimate interest in a readable, consistent presentation.
Google may process data outside the European Economic Area under its applicable transfer safeguards. Details are available in the Google Privacy Policy. Facebook and Instagram receive data only if the visitor follows the external social-media link.
6. Data security
The Controller applies appropriate technical and organisational measures proportionate to risk, including access restriction, encrypted transmission where available, input validation, anti-abuse controls, security headers, updates and incident handling. No internet transmission can be guaranteed to be completely secure.
7. Your rights
Subject to the conditions of the GDPR, you may request access to your data, rectification, erasure, restriction of processing and data portability, and may object to processing based on legitimate interests. Where processing is based on consent, consent may be withdrawn at any time without affecting prior lawful processing.
Requests may be sent to info@gfe.hu, the Hostel contact or the data protection officer. The Controller normally responds within one month and may request information necessary to verify identity.
8. Complaint and judicial remedy
If you believe that your personal data has been processed unlawfully, you may contact the Controller or the data protection officer, lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), or seek a judicial remedy.
NAIH: 1055 Budapest, Falk Miksa utca 9–11.; postal address: 1363 Budapest, P.O. Box 9.; email: ugyfelszolgalat@naih.hu; phone: +36 1 391 1400; website: naih.hu.
9. On-site cameras and updates
A separate notice applies to the camera system operated at the Hostel. The current camera notice is available here.
This Notice may be updated when processing activities or legal requirements change. The current version and effective date are always published on this page. The General Terms and Conditions contain the contractual rules for booking enquiries.