PRIVACY POLICY
In connection with the use of the services provided by ROYAL HERITAGE Kft. and the use of the websites operated by it, and with regard to data processing, ROYAL HERITAGE Kft. provides the following information pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation, hereinafter referred to as “GDPR”).
Persons under the age of 16 are not permitted to give consent to the processing of their personal data independently. Therefore, in the case of a minor under the age of 16, we request that the personal data and consent for data processing be provided by the legal representative. The approval of the legal representative also implies full responsibility for the activities of the person under the age of 16 as a user.
DATA MANAGER AND CONTACTS:
In relation to the data processing associated with the use of the services provided by Indian Palate and the websites operated by the company, ROYAL HERITAGE Ltd. qualifies as the data controller, which independently determines the purposes and means of processing personal data.
Data controller: ROYAL HERITAGE Kft.
Registered office: 3–5 Veres Pálné Street, Budapest 1053, Hungary
Company Registration Number: 01-09-374738
Representative: Harshneet Singh Marwah, Managing Director (Executive Officer), Navneet Saluja, Managing Director (Executive Officer)
Operated restaurant: Indian Palate
Website: www.indianpalate.hu
E-mail: mail@indianpalate.hu
Phone: + 36-30-144-4000
The addressee of the prospectus is a natural person affected by his / her personal data. The person concerned is the person who reads this information – as a visitor, interested party or customer, customer, principal, customer.
DEFINITIONS
“personal data” means an identified or identifiable natural person (“data subject”) any relevant information; identifies a natural person who, directly or indirectly, in particular by reference to an identifier such as name, number, location, online identifier or one or more factors relating to the physical, physiological, genetic, mental, economic, cultural or social identity of the natural person identifiable;
“processing” means any operation or set of operations on personal data or files, whether automated or non automated, such as collection, recording, systematisation, sorting, storage, transformation or alteration, retrieval, consultation, use, communication, transmission or dissemination; by other means of access, coordination or interconnection, restriction, deletion or destruction;
“controller” means the natural or legal person, public authority, agency or any other body which alone or jointly with others determines the purposes and means of the processing of personal data; where the purposes and means of the processing are determined by Union or Member State law, the controller or the specific criteria for the designation of the controller may also be determined by Union or Member State law;
“processor” means any natural or legal person, public authority, agency or any other body which processes personal data on behalf of the controller;
“recipient” means a natural or legal person, public authority, agency or any other body to whom personal data are disclosed, whether a third party or not. Public authorities that may have access to personal data in the context of an individual investigation in accordance with Union or Member State law shall not be considered as recipients; the processing of such data by these public authorities must comply with the applicable data protection rules in accordance with the purposes of the processing;
“data subject’s consent” means voluntary, specific and proportionate to the will of the data subject an informed and unambiguous statement by which the data subject indicates, by means of a statement or an act unequivocally expressing the confirmation, that he or she consents to the processing of personal data concerning him or her;
“data protection incident” means a breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to, personal data which have been transmitted, stored or otherwise handled.
PROVISIONS CONCERNING THE HANDLING OF PERSONAL DATA
1.Data management of contracting natural person partners – customers, suppliers records
In relation to this data processing, an independent data controller is also considered to be any company belonging to Royal Heritage Ltd. that concludes a contract with the natural person partner, or that maintains contact with the natural person partner for the purpose of concluding a contract.
1.1 Purpose of data management: conclusion, performance, termination of a contract, contractual manages the data of the natural person contracted to him as a buyer or supplier in order to provide a discount.
1.2 Data management title: title based on a legal obligation.
1.3 Stakeholders: natural persons contracted to the company.
1.4 Recipient of the managed data: employees of the Company performing customer service related tasks, data processor performing accounting and tax tasks.
1.5 Data processed: natural person contracted as a buyer or supplier.
- name
- date of birth,
- mother’s name
- address,
- tax identification number,
- tax number, entrepreneurial, primary producer number
- identity card number,
- home address, registered office, site address,
- telephone number, e-mail address, website address,
- bank account number,
1.6 Such data processing shall be lawful even if the data processing is necessary to take steps at the request of the data subject prior to the conclusion of the contract.
1.7 The data subject must be informed before the start of the data processing that the data processing is based on the title of the performance of the contract, that information may also take place in the contract. The data subject shall be informed of the transfer of his or her personal data to the data processor.
1.8 Duration of storage of personal data: In respect of identification and contact data, the validity of the rights and obligations arising from the legal relationship in connection with which the Data Controller handles personal data expires, in respect of data that are documented and the document supports the accounting, the duration of data processing pursuant to Section 169 (2) of Act C of 2000 is at least 8 years.
1.9 Method of data management: electronic.
2.Contact details of natural person representatives of legal entity clients, customers, and suppliers
2.1 Purpose of processing personal data: To perform the contract concluded between the Company and its legal entity partner, and to maintain business communication.
2.2 Legal basis for data processing: The processing is necessary for the performance of a contract to which the data subject is a party.
2.3 Scope of data subjects: Natural person representatives of legal entity clients, customers, and suppliers.
2.4 Recipients of personal data: Employees of the Company performing customer service, accounting, and taxation tasks, as well as the data processor.
2.5 Processed data: The natural person’s. (please provide the rest of the sentence so I can complete the translation accurately).
- name,
- address,
- telephone number,
- email address
2.6 Duration of personal data storage: The data will be deleted immediately after the termination of the contract or in the event of a change in the contact person.
2.7 Method of data processing: Electronic.
2.8 Data processor:
Royal Heritage Kft.
Registered office: 1053 Budapest, Veres Pálné utca 3–5.
E-mail: mail@indianpalate.hu
Phone: +36 30 144 4000
- Dataprocessingrelated to images, video recordings, and audio recordings of data subjects and employees
3.1 The Data Controller, in compliance with Section 2:48 (1)of the applicable Civil Code, creates and processes audio, image, and video recordings of or featuring the data subject exclusively with the data subject’s prior consent, and takes only those actions (e.g. transfer, publication) to which the data subject has consented in their respective declaration.
3.2 Data processing may only take place based on the data subject’s voluntary, explicit, and specific consent.
3.3 Purpose of data processing: to strengthen the Company’s image and brand through marketing activities, including the creation and use of related photographs.
3.4 Legal basis for data processing: the processing of personal data based on consent.
3.5 Scope of data subjects: participants of events and employees.
3.6 Recipients of processed data: persons performing marketing tasks.
3.7 Processed data: the data subject’s voice and image, and any other data obtainable from the photograph.
3.8 Duration of personal data storage: until the withdrawal of consent.
3.9 The Data Controller may engage a data processor in connection with the creation and processing of images, video recordings, and audio recordings.
- SocialMedia / Data Processing on the Company’s Facebook and Instagram Pages
4.1 Indian Palate is present on the Facebook social networking platform, as well as on other social media platforms (TripAdvisor, YouTube, Instagram).
4.2 The use of social media platforms — particularly Facebook and Instagram — and any interaction with the Data Controller through these platforms, including communication and other actions permitted by the respective platforms, is based on voluntary consent.
4.3 Purpose of data processing: to maintain contact with Indian Palate followers via social media, and to present the restaurant’s services, activities, and events.
4.4 Scope of data subjects: natural persons who voluntarily follow, share, or like the Data Controller’s social media pages or content, especially on facebook.com and instagram.com.
4.5 The Data Controller does not process any personal data published by visitors on its Facebook or Instagram pages. Visitors are subject to the Privacy and Service Terms of Facebook and Instagram.
4.6 In the case of unlawful or offensive content being published, the Company may, without prior notice, exclude the individual from the group or delete their comment.
4.7 The Company assumes no responsibility for any unlawful content or comments posted by Facebook users, nor for any errors, malfunctions, or issues arising from changes in the operation of Facebook or Instagram.
- TableReservation – Appointment Scheduling
5.1 The Data Controller allows data subjects to reserve a table and discuss other related matters concerning the services provided by Indian Palate by providing the personal data detailed below.
5.2 Legal basis for data processing: processing of personal data based on the data subject’s consent.
5.3 Purpose of data processing: to provide table reservation services and maintain contact with the data subject.
5.4 Scope of data subjects: all natural persons who make a reservation by providing their personal data.
5.5 Recipients of personal data: the Data Controller and the employees of the company operating the restaurant where the reservation is made.
5.6 Processed data: Personal data of the natural person initiating the reservation:
- full name,
- mobile phone number,
- email address,
- reservation-related details (date and time, duration, number of persons, dietary preferences or food allergies, event type).
5.7 Process of data management:
- The data subject may arrange or request a reservation by phone or email using the contact details provided by the Data Controller, or by submitting a booking request through the website.
- During the scheduling process, the Data Controller records the data provided in an electronic registration system and confirms the reservation verbally and/or in writing to the data subject.
- By clicking on the “Reservation” link on the website and providing the necessary information, the Data Controller may also contact the data subject by phone before the reserved date to confirm or clarify details.
- Ideally, the data subject appears in person at the agreed time to use the restaurant’s services.
- In line with the purpose of data processing, the data subject voluntarily consents to being contacted via the provided contact details for the purpose of notifying them in case of any changes or cancellations, or to respond to complaints or take related actions.
5.8 Duration of personal data storage: until the purpose is fulfilled or consent is withdrawn.
5.9 Method of data processing: electronically.
6. Newsletter Subscription
6.1 Indian Palate may send advertising materials, promotional messages, information, offers, and/or newsletters related to the restaurant’s activities and services to data subjects who have given their consent. The data subject may withdraw their consent at any time by clicking on the link provided in the email newsletter or by sending a request to the Data Controller’s email address.
6.2 Legal basis for data processing: processing of personal data based on the data subject’s consent.
6.3 Purpose of data processing: to send newsletters and maintain contact with the data subject.
6.4 Scope of data subjects: all natural persons who, either during the table reservation process or by subscribing to the newsletter, have clearly given their consent to receive newsletters.
6.5 Recipients of personal data: the Data Controller and the employees of the company operating the restaurant where the data subject has made a reservation.
6.6 Processed data: Personal data of the natural person subscribing to the newsletter:
- full name,
- email address.
6.7 Duration of personal data storage: until the consent is withdrawn.
- DataProcessingRelated to Consent Declarations
7.1 The Data Controller requests data subjects to provide a written or electronic consent declaration for the purpose of accessing, processing, and, where applicable, transferring their personal data.
7.2 Legal basis for data processing: processing of personal data based on the data subject’s consent.
7.3 Purpose of data processing: to manage consent declarations in order to demonstrate the legal basis of data processing and to fulfil the requirements of consent (principle of accountability), as well as to maintain contact with the data subject.
7.4 Scope of data subjects: all natural persons who provide a consent declaration to the Data Controller for the processing of their data for a specific purpose.
7.5 Recipients of personal data: employees working in the area related to the specific data processing activity, and the data processor.
7.6 Processed data: the data appearing in the consent declaration related to the specific data processing activity.
7.7 Duration of personal data storage: until withdrawal upon the data subject’s request or until the completion of the given data processing activity.
7.8 Method of data processing: in paper-based or electronic form.
SECURITY OF DATA PROCESSING
The Data Controller and the data processors acting on its behalf implement appropriate technical and organizational measures to ensure a level of data security appropriate to the level of risk, taking into account the state of science and technology, the cost of implementation, as well as the nature, scope, context, and purposes of the data processing, and the varying likelihood and severity of risks to the rights and freedoms of natural persons.
RIGHTS OF THE DATA SUBJECTS
In accordance with the provisions of the GDPR, the Data Controller ensures the following rights for data subjects.
Right to Information
The data subject has the right to receive information from the Data Controller in a concise, transparent, comprehensible, and easily accessible form, expressed in clear and plain language, regarding the following:
- The identity and contact details of the Data Controller and the Data Controller’s representative;
- The contact details of the Data Protection Officer;
- The purposes of the intended processing of personal data and the legal basis for the processing;
- In the case of processing based on legitimate interest, the legitimate interests of the Data Controller or a third party;
- The recipients of the personal data, if any;
- Where applicable, the fact that the Data Controller intends to transfer personal data to a third country or an international organization;
- The period for which the personal data will be stored;
a) The data subject’s right to request access from the Data Controller to their personal data, to rectify it, to erase it or restrict its processing in certain cases depending on the legal basis, and to object to the processing of such personal data where applicable, as well as the data subject’s right to data portability;
- b)Ifthe data were not collected from the data subject, the source of the personal data and, where applicable, whether the data come from publicly available sources;
- c) Therightto withdraw consent at any time for processing based on consent, without affecting the lawfulness of processing carried out before the withdrawal;
- d) Therightto lodge a complaint with a supervisory authority;
- e)Whetherthe provision of personal data is based on a legal or contractual obligation or a prerequisite for concluding a contract, whether the data subject is obliged to provide the personal data, and the possible consequences of failing to provide the data.
The information must be provided in writing or by other means, including electronically where appropriate. Upon request, oral information may also be provided, provided the identity of the data subject has been verified by other means.
The Data Controller shall inform the data subject without undue delay, and in any case within 30 days of receipt of the request, of the measures taken in relation to the request concerning their personal data. If necessary, taking into account the complexity of the request and the number of requests, the 30-day period may be extended by a further 60 days. The Data Controller shall inform the data subject of any extension of the period, along with the reasons for the delay, within 30 days of receipt of the request.
We inform you that information and measures are provided free of charge; however, if a request is clearly unfounded or excessive, particularly due to its repetitive nature, the Data Controller may charge a reasonable fee taking into account the administrative costs of providing the requested information or taking the requested action, or may refuse to act on the request.
If the Data Controller intends to process personal data for a purpose other than that for which it was collected, the data subject shall be informed prior to such further processing of the new purpose and all other relevant supplementary information previously mentioned.
The Data Controller fulfills its obligation to provide mandatory information by publishing this Privacy Notice on the website.
Right of Access
The data subject has the right to receive confirmation from the Data Controller as to whether personal data concerning them is being processed. If such processing is underway, the data subject is entitled to access the personal data and the following information:
- The purposes of the processing;
- The categories of personal data concerning the data subject;
- The recipients or categories of recipients to whom the personal data have been or will be disclosed;
- Where applicable, the intended period for which the personal data will be stored;
- The data subject’s right to request from the Data Controller the rectification of inaccurate personal data concerning them, the erasure or restriction of processing of such data in cases depending on the legal basis, and to object to the processing of such personal data where applicable;
- The right to lodge a complaint with a supervisory authority;
- Where the data were not collected from the data subject, all available information about their source;
f) The existence of automated decision-making, including profiling, and, at least in these cases, meaningful information about the logic involved as well as the significance and envisaged consequences of such processing for the data subject.
The Data Controller shall provide a copy of the personal data undergoing processing upon request. The Data Controller may charge a reasonable administrative fee for additional copies requested by the data subject.
If the request is submitted electronically, the information shall be provided in a commonly used electronic format, unless otherwise requested by the data subject. The right to obtain a copy shall not adversely affect the rights and freedoms of others.
Right to Rectification
The Data Controller shall rectify, without undue delay, any inaccurate personal data concerning the data subject upon request. The data subject is entitled to request the completion of incomplete personal data, for example, through a supplementary statement.
Right to Erasure (“Right to be Forgotten”)
The data subject is entitled to request the erasure of their personal data.
The Data Controller shall erase personal data without undue delay if one of the following applies:
- The personal data are no longer necessary for the purposes for which they were collected or otherwise processed;
- The data subject withdraws consent on which the processing is based (in the case of consent-based processing), and there is no other legal ground for the processing;
- The data subject objects to the processing and there is no overriding legitimate ground for processing based on legitimate interests;
- The personal data have been unlawfully processed;
- The personal data must be erased to comply with a legal obligation under EU or member state law.
The Data Controller shall inform all recipients to whom personal data have been disclosed about the erasure.
The Data Controller is not obliged to comply with a request for erasure if the processing is necessary for:
- Exercising the right of freedom of expression and information;
- Compliance with a legal obligation under EU or member state law;
- Performance of a task carried out in the public interest;
- Exercise of official authority vested in the Data Controller;
- Public health purposes in the interest of community health;
- Archiving purposes in the public interest;
- Scientific or historical research or statistical purposes;
g) The establishment,exercise,or defense of legal claims.
Right to Restriction of Processing
The data subject has the right to request that the Data Controller restrict the processing of personal data if one of the following applies:
- The accuracy of the personal data is contested; restriction applies for the period allowing the Data Controller to verify the accuracy;
- The processing is unlawful, and the data subject opposes erasure and requests restriction instead;
- The Data Controller no longer needs the personal data for processing purposes, but the data subject requires them for the establishment, exercise, or defense of legal claims;
- The data subject has objected to processing based on legitimate interests; restriction applies until it is established whether the Data Controller’s legitimate grounds override those of the data subject.
Where processing is restricted under these circumstances, personal data may only be processed, aside from storage, with the data subject’s consent, for the establishment, exercise, or defense of legal claims, to protect the rights of another natural or legal person, or for important public interest of the EU or a member state.
The Data Controller shall inform all recipients to whom the personal data have been disclosed about the restriction.
Right to Object
The data subject has the right to object at any time, on grounds relating to their particular situation, to the processing of personal data for public interest, exercise of official authority, or legitimate interests of the Data Controller (or a third party), including profiling based on such grounds.
Upon such objection, the Data Controller shall cease processing unless it demonstrates compelling legitimate grounds overriding the interests, rights, and freedoms of the data subject, or for the establishment, exercise, or defense of legal claims.
If personal data are processed for direct marketing purposes, the data subject has the right to object at any time, and thereafter personal data shall no longer be processed for such purposes.
Right to Data Portability
The right to data portability applies to processing based on consent or a contract, where processing is carried out by automated means.
Upon request, the Data Controller shall provide the data subject with personal data provided by them in a structured, commonly used, machine-readable format and shall allow the transfer of these data to another controller where technically feasible.
Exercising the right to data portability shall not adversely affect the rights and freedoms of others and shall not override the right to erasure. It does not apply where processing is necessary for tasks carried out in the public interest or the exercise of official authority.
Right to Lodge a Complaint
If the data subject believes that the processing of their personal data violates the GDPR or applicable Hungarian law, they are entitled, without prejudice to other administrative or judicial remedies, to lodge a complaint with the National Authority for Data Protection and Freedom of Information (NAIH) at:
- Address: 1055 Budapest, Falk Miksa utca 9-11
- Mailing address: 1363 Budapest, Pf.: 9
- Website: http://www.naih.hu
- Phone: +36 (1) 391-1400, +36 (30) 683-5969, +36 (30) 549-6838
- Fax: +36 (1) 391-1410
- Email: ugyfelszolgalat@naih.hu
Without prejudice to any other administrative or non-judicial remedies, the data subject shall have the right to an effective judicial remedy against a legally binding decision of the NAIH concerning them.
Without prejudice to any other administrative or non-judicial remedies, the data subject shall have the right to an effective judicial remedy where the NAIH does not handle a complaint or fails to inform the data subject within three months of the progress or outcome of the submitted complaint.
Right to an effective judicial remedy against a controller or processor
Without prejudice to any available administrative or non-judicial remedies, including the right to lodge a complaint with a supervisory authority, the data subject shall have the right to an effective judicial remedy where they consider that their rights under the GDPR have been infringed as a result of the processing of their personal data in non-compliance with the GDPR.
The controller or the processor shall bear the burden of demonstrating that the processing of personal data complies with the requirements laid down by law or by a binding legal act of the European Union.
The data subject may bring the action, at their choice, before the competent court of their place of residence or habitual residence.