Alma Mater Hostel
  • Home
  • About Us
  • Apartments
  • Directions
  • Rates
  • Gallery
  • Things to Do
  • Contact
HU Booking

Alma Mater Hostel

Privacy Notice

How we process personal data on the website and when handling enquiries.

Important: This English translation is provided for convenience. If there is any discrepancy, the Hungarian version prevails.
Contents 1. Controller 2. Principles 3. Processing activities 4. Recipients 5. External services 6. Security 7. Your rights 8. Complaints 9. Updates

Effective from 26 August 2026

Transparent information about data processing

This notice covers the public Alma Mater Hostel website, booking enquiries and messages sent through its forms.

1. Controller and data protection officer

Controller
Gál Ferenc University (Gál Ferenc Egyetem, “GFE”)
Registered office
6720 Szeged, Dóm tér 6., Hungary
Tax number
18467303-2-06
General contact
info@gfe.hu · +36 62 425 738
Hostel contact
szallas@gfe.hu · +36 66 887 163
Data protection officer
Mayer és Társai Law Office, 1137 Budapest, Radnóti Miklós utca 38.; ugyved@drmayer.hu; +36 1 340 4151

The University’s detailed Data Protection and Data Management Policy also applies.

2. Principles and scope

Personal data is processed lawfully, fairly and transparently, only for specified purposes and only to the extent necessary. Data is kept accurate, protected against unauthorised access and erased or anonymised when it is no longer required.

Please do not include special-category data, identification-document numbers or other unnecessary sensitive information in the free-text fields.

3. Processing activities

Booking enquiry and pre-contract communication

Data: arrival and departure dates, apartment type, number of adults and children, name, email address, telephone number and optional message.

Purpose and legal basis: checking capacity, preparing an offer and taking steps at the Guest’s request before entering into a contract; Article 6(1)(b) GDPR.

Retention: an enquiry that does not result in a contract is erased no later than six months after the last communication. If a contract is concluded, contractual data is retained for the applicable five-year limitation period and accounting records for eight years where required by law.

General messages

Data: name, email address, optional telephone number, subject and message.

Purpose and legal basis: answering the message and maintaining contact; Article 6(1)(f) GDPR, based on the legitimate interest of both parties in effective communication. If the message requests pre-contract steps, Article 6(1)(b) GDPR applies.

Retention: no longer than one year after the matter is closed, unless the correspondence is required for a contract or legal claim.

Abuse prevention and technical security

Data: short-lived, pseudonymous submission counter derived from the IP address; security and server logs may contain IP address, timestamp, requested address and browser/device information.

Purpose and legal basis: preventing spam and attacks, ensuring system availability and investigating incidents; Article 6(1)(f) GDPR.

Retention: the form submission counter expires after 15 minutes; ordinary server logs are retained for up to 30 days unless an incident requires longer retention.

Accommodation and legal obligations

Where an enquiry results in a stay, additional data may be processed for guest registration, invoicing, tourist tax, payment, security and legal compliance. The Guest receives any additional information required before that processing begins. The legal bases may include performance of a contract, compliance with a legal obligation and legitimate interests.

4. Recipients and processors

Data may be accessed by authorised staff of GFE responsible for accommodation, administration, finance, legal matters and IT support. Technical providers operating the website, hosting and email systems may process data only on documented instructions and under appropriate contractual safeguards.

Data is disclosed to public authorities, courts or other bodies only where required or permitted by law. Personal data is not sold and is not used for automated decision-making or profiling.

5. External content, cookies and international transfers

The theme does not use advertising or analytics cookies. WordPress and the hosting environment may use strictly necessary technical cookies, for example for administration, security or language-related functionality.

The Google Maps embed on the home page loads automatically when the visitor’s browser reaches the map section. The separate Directions page loads its interactive map only after the visitor actively requests it. When a map is loaded, Google may receive the visitor’s IP address and device/browser information and may set its own cookies. For the automatic home-page embed, the Controller relies on Article 6(1)(f) GDPR and its legitimate interest in providing clear location information; on the Directions page the connection is initiated by the visitor’s action.

The website may retrieve font files from Google Fonts. In doing so, the visitor’s IP address and technical request data are transmitted to Google to display the site consistently. The Controller relies on Article 6(1)(f) GDPR and its legitimate interest in a readable, consistent presentation.

Google may process data outside the European Economic Area under its applicable transfer safeguards. Details are available in the Google Privacy Policy. Facebook and Instagram receive data only if the visitor follows the external social-media link.

6. Data security

The Controller applies appropriate technical and organisational measures proportionate to risk, including access restriction, encrypted transmission where available, input validation, anti-abuse controls, security headers, updates and incident handling. No internet transmission can be guaranteed to be completely secure.

7. Your rights

Subject to the conditions of the GDPR, you may request access to your data, rectification, erasure, restriction of processing and data portability, and may object to processing based on legitimate interests. Where processing is based on consent, consent may be withdrawn at any time without affecting prior lawful processing.

Requests may be sent to info@gfe.hu, the Hostel contact or the data protection officer. The Controller normally responds within one month and may request information necessary to verify identity.

8. Complaint and judicial remedy

If you believe that your personal data has been processed unlawfully, you may contact the Controller or the data protection officer, lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH), or seek a judicial remedy.

NAIH: 1055 Budapest, Falk Miksa utca 9–11.; postal address: 1363 Budapest, P.O. Box 9.; email: ugyfelszolgalat@naih.hu; phone: +36 1 391 1400; website: naih.hu.

9. On-site cameras and updates

A separate notice applies to the camera system operated at the Hostel. The current camera notice is available here.

This Notice may be updated when processing activities or legal requirements change. The current version and effective date are always published on this page. The General Terms and Conditions contain the contractual rules for booking enquiries.

Key-card access Safe environment Affordable rates Student discount for GFE students Convenient location on a quiet street

© 2026 Alma Mater Hostel - All rights reserved.

Facebook Instagram
Privacy Policy Legal Notice Terms and Conditions Contact
Website created by: Morvai Miklós·XperiComp Kft.