Direct booking on our website: save up to 15% compared with booking platforms — no intermediary fees.·Best price guarantee

Privacy Policy

Budapest Riverfront Lux – Kovberep Kft.

Effective date: 9 August 2026

1. Introduction and Scope

This Privacy Policy (hereinafter: the “Policy”) regulates the processing of personal data carried out by Kovberep Kft. (hereinafter: the “Controller” or “Service Provider”) on the website budapestriverfront.com (hereinafter: the “Website”).

The Controller is committed to the protection of personal data and processes data in accordance with the General Data Protection Regulation of the European Union (GDPR – Regulation (EU) 2016/679), Act CXII of 2011 on the Right of Informational Self-Determination and on Freedom of Information (Infotv.), as well as the relevant Hungarian and EU legislation.

By using the Website, filling out the contact form, or accepting cookies, you accept the provisions of this Policy.

2. Details of the Controller

  • Name: Kovberep Kft.
  • Registered office: 2161 Csomád, Szent István utca 48., Hungary
  • Company registration number / Tax number: 28825115-2-13
  • Licence number: EG25108768
  • Company registry: National Company Registry
  • E-mail (for data protection matters): hello@budapestriverfront.com
  • Additional e-mail: l.kovacs0312@gmail.com
  • Phone number: +36 20 401 5557

The Controller has not appointed a Data Protection Officer (DPO), as this is not mandatory based on the nature and scale of the activity.

3. Definitions

  • Personal data: any information relating to an identified or identifiable natural person.
  • Data subject: the natural person whose personal data is processed by the Controller.
  • Processing: any operation performed on personal data (collection, storage, use, transfer, deletion, etc.).
  • Processor: a natural or legal person who processes personal data on behalf of the Controller.
  • Consent: the data subject’s freely given, specific, informed and unambiguous indication of wishes.

4. Data Processing Activities on the Website

4.1. Contact Form

Through the contact form available on the Website, you can send us a message. When filling out the form, we process the following data:

  • Name
  • E-mail address
  • Phone number (if provided)
  • Content of the message
  • IP address and time of submission (for technical reasons)

Purpose of processing: responding to your enquiry, maintaining contact, and providing information about the apartments and services.

Legal basis: Article 6(1)(a) GDPR – your consent (by submitting the form), and Article 6(1)(b) GDPR – steps taken at the request of the data subject prior to entering into a contract.

Retention period: maximum 12 months from the last contact if no further relationship or contract is established. In case of a complaint or legal claim, until the end of the relevant limitation period (generally 5 years).

We use the data solely to respond to your enquiry and do not transfer it to third parties for marketing purposes.

4.2. Bookings and Payments

Important information: There is no possibility of direct booking or payment on the Website. Bookings and payments are handled by the SabeeApp system (thePass Kft.).

When you click the “Book” button, you will be redirected to the SabeeApp booking engine[](https://www.sabeeapp.com). The personal data provided during the booking process (name, e-mail, phone number, payment details, etc.) is processed by SabeeApp / thePass Kft.

You can find SabeeApp’s own privacy policy here: https://www.sabeeapp.com/hu/adatvedelem

The Controller (Kovberep Kft.) only accesses and processes the booking data generated in the SabeeApp system to the extent necessary for operating the accommodation.

4.2.1 Data Processing and Invoicing (Guest Data)

In the case of a valid booking, the guest is required to provide a contact phone number, which we retain until departure for potential issues or important questions.

Under Hungarian law, accommodation providers are obliged to report data to the Hungarian Tourism Agency (https://mtu.gov.hu/). In this context, upon arrival guests are required to present their identity documents (passport, ID card, address card), which are recorded using a Ministry of Interior document reader. More information about the mandatory data reporting can be found here: https://vizainfo.hu/szallashelyek.

If the guest does not wish to present the documents in person, they have the option to register them in advance themselves. Details of the procedure and the required form are available at the following link: https://info.vendegem.hu/media/uploads/dokumentumok/sci_vendeg.pdf.

In accordance with NAV (Hungarian Tax Authority) regulations, the accommodation operator is required to issue an invoice. Mandatory elements of the invoice include the name and address of the billed party, and in the case of a corporate booking, the tax number. The owner issues an electronic invoice, for which an e-mail address and residential address are required. If the guest does not wish to share their address card, the billing details may also be provided by e-mail.

We use guests’ personal data solely for the purpose of fulfilling the above-mentioned legal obligations and do not store them in printed form. Electronic data is retained only until the complaint deadline expires.

Legal basis: Article 6(1)(c) GDPR – compliance with a legal obligation (tourism data reporting, invoicing), and Article 6(1)(b) GDPR – performance of the accommodation service contract.

4.3. Cookies and Tracking Tools

The Website uses cookies and similar technologies. Non-essential cookies are only placed with your prior consent (cookie banner).

Summary table of cookies

Cookie / Tool Provider Purpose Type Validity Legal basis
WordPress session / login cookies WordPress (own) Ensuring the basic operation of the website Necessary Session / 1 year Legitimate interest / performance of contract
_ga, _ga_*, _gid Google Analytics (Google Ireland Ltd.) Visitor statistics, analysis of traffic sources Analytical 2 years / 24 hours Consent
_fbp, _fbc Meta Pixel (Meta Platforms Ireland Ltd.) Ad measurement, remarketing, conversion tracking Marketing 90 days Consent
Tags managed by Google Tag Manager (GTM) Google Ireland Ltd. Management and loading of tags (Analytics, Pixel, etc.) Technical / Analytical / Marketing According to the loaded tags Consent (depending on the type of tags)
Other technical cookies Own / hosting provider Security, load balancing, preferences Necessary / Functional Variable Legitimate interest

Google Analytics and the Meta Pixel are only activated if you consent to analytical and marketing cookies in the cookie banner. You can withdraw your consent at any time in your browser settings or via the cookie settings available on the Website.

4.4. Newsletter and Marketing Data Processing

If you subscribe to our newsletter, we process the following data:

  • Name (if provided)
  • E-mail address
  • Date of subscription and fact of consent

Purpose of processing: sending regular information about the apartments, discounts, Budapest tips and other current offers.

Legal basis: Article 6(1)(a) GDPR – your freely given prior consent.

Processor: We use the Brevo (Sendinblue) service for sending newsletters (Brevo, 55 rue d’Amsterdam, 75008 Paris, France). Brevo operates within the European Union and is a GDPR-compliant processor.

Retention period: until consent is withdrawn (unsubscribe). After unsubscribing, the e-mail address is immediately removed from further mailings, while the fact of consent is retained for a maximum of 3 years for verification purposes.

You can unsubscribe from the newsletter at any time by clicking the “Unsubscribe” link at the bottom of the emails or by sending a message to hello@budapestriverfront.com.

4.5. External Links and Social Media

The Website may contain links to external websites (for example, the SabeeApp booking system, Google Maps, or social media pages).

The Controller assumes no responsibility for the data processing practices of these external sites. Please always read the privacy policy of the respective website.

The Controller may also operate Facebook and Instagram pages. Data processing on these pages (e.g. comments, messages, reactions) is carried out in accordance with the privacy policy of Meta Platforms Ireland Ltd. The Controller is only responsible for personal data published on such pages in relation to its own publications and moderation activities.

5. Processors

The Controller uses the following processors:

5.1. Hosting Provider

  • Name: RackForest Informatikai Kereskedelmi Szolgáltató és Tanácsadó Zrt.
  • Office: 1132 Budapest, Victor Hugo utca 11., 5th floor
  • Server rooms: 1132 Budapest, Victor Hugo u. 18-22., 3rd floor | 1087 Budapest, Asztalos Sándor u. 13. | 1108 Budapest, Kozma u. 2.
  • Billing address: 1132 Budapest, Victor Hugo u. 11., 5th floor B05001
  • Tax number: 32056842-2-41
  • Bank account number (HUF): 10400968-50514955-49501007
  • IBAN: HU04 1040 0968 5051 4955 4950 1007
  • SWIFT: OKHBHUHB

RackForest stores the data solely within the framework of the hosting service and does not use it for its own purposes.

5.2. Other Processors / Joint Controllers

  • Google Ireland Ltd. – Google Analytics and Google Tag Manager (statistics and tag management)
  • Meta Platforms Ireland Ltd. – Meta (Facebook) Pixel (ad measurement and remarketing)
  • thePass Kft. (SabeeApp) – booking and payment system

5.3. Transfer of Data to Third Countries

Some of our processors (in particular Google Ireland Ltd. and Meta Platforms Ireland Ltd.) may also transfer data to the United States of America.

On 10 July 2023, the European Commission adopted the EU–US Data Privacy Framework adequacy decision. Google and Meta ensure an adequate level of protection under this framework.

In addition, transfers may also take place on the basis of the Standard Contractual Clauses (SCC) approved by the European Commission. The Controller only cooperates with processors that provide appropriate guarantees for the protection of personal data.

6. Duration of Data Storage

  • Contact form data: max. 12 months (or limitation period)
  • Cookies: according to the table above
  • Accounting and tax documents: 8 years (Accounting Act) or 5 years (Tax Act)
  • In other cases: until the purpose of processing is achieved or until the data subject’s request for deletion

6.5. Data of Minors

The Website and our services are not intended for persons under the age of 16. We do not knowingly collect or process personal data of persons under 16 years of age.

If we become aware that we have processed data of a person under 16 without consent, we will delete the data without delay. If you are a parent or legal guardian and believe that your minor child has provided us with data, please contact us at hello@budapestriverfront.com.

7. Rights of the Data Subject

Under the GDPR you have the following rights:

  • Right of access – you may request information about the data we process
  • Right to rectification – you may request correction of inaccurate data
  • Right to erasure (“right to be forgotten”)
  • Right to restriction of processing
  • Right to data portability
  • Right to object
  • Right to withdraw consent (withdrawal does not affect the lawfulness of processing based on consent before its withdrawal)

To exercise your rights, please write to hello@budapestriverfront.com. We will respond to your request within a maximum of 30 days.

8. Remedies

If you believe that the processing of your personal data violates your rights, you may lodge a complaint with the National Authority for Data Protection and Freedom of Information (NAIH):

  • Address: 1055 Budapest, Falk Miksa utca 9-11.
  • Postal address: 1363 Budapest, Pf. 9.
  • Phone: +36 1 391 1400
  • E-mail: ugyfelszolgalat@naih.hu
  • Website: www.naih.hu

You may also turn to a court.

9. Data Security

The Controller applies appropriate technical and organisational measures to protect personal data (encrypted connections, access restriction, regular security updates, security measures of the hosting provider).

9.1. Handling of Data Protection Incidents

A data protection incident means the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.

After becoming aware of an incident, the Controller shall report it to the National Authority for Data Protection and Freedom of Information (NAIH) without undue delay and, where feasible, not later than 72 hours, if the incident is likely to result in a risk to the rights and freedoms of data subjects.

If the incident is likely to result in a high risk, the Controller shall also inform the data subjects. In the notification we will describe the nature of the incident, the possible consequences and the measures we have taken.

We keep a record of incidents.

10. Amendment of the Policy

The Controller reserves the right to unilaterally amend this Policy. The amended version becomes effective upon publication on the Website. Please check the Policy regularly.

11. Contact

For data protection matters, please contact us:

  • E-mail: hello@budapestriverfront.com
  • Phone: +36 20 401 5557
  • Postal address: 2161 Csomád, Szent István utca 48.

© 2026 Kovberep Kft. – Budapest Riverfront Lux
This Privacy Policy reflects the status effective as of 9 August 2026.