Privacy Policy

Second Hospitality Kft.
Effective from January 1, 2026

Company name: Second Hospitality Kereskedelmi és Szolgáltató Korlátolt Felelősségű Társaság
Abbreviated company name: Second Hospitality Kft.
Registered office: 1064 Budapest, Podmaniczky utca 57, 2nd floor, door 14
Company registration number: 01-09-458526
Tax identification number: 33089168-2-42
Represented by: Anita Zrena, Managing Director
Data protection contact email: info@strongholdoperativ.hu
Website: strongholdoperativ.hu

    This Privacy Notice has been prepared in accordance with the provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR), Act CXII of 2011 on the Right of Informational Self-Determination and on the Freedom of Information (Infotv.), and Act CVIII of 2001 on Electronic Commerce Services.

    2.1. Purchase, order

    Purpose of data processing: fulfillment of the order, conclusion and performance of the contract, issuance of an electronic invoice.
    Data processed:
    – full name,
    – e-mail address,
    – billing address (street, house number, city, postal code, country),
    – delivery address (in the case of printed products),
    – details of the ordered product and payment (amount, date/time, transaction ID).
    Legal basis: Article 6(1)(b) of the GDPR — performance of a contract.
    Retention period: 8 years pursuant to Section 169 of Act C of 2000 on Accounting (billing data); 5 years from the termination of the contractual relationship for other purchase data.

    2.2. Delivery of digital product (download link)

    Purpose of data processing: secure delivery of the purchased digital content (PDF publication) featuring a unique identifier.
    Data processed:
    – e-mail address,
    – unique download identifier (customer watermark: name, e-mail, order number, date).
    Legal basis: Article 6(1)(b) of the GDPR — performance of a contract.
    Retention period: 1 year from the expiration of the download entitlement (14 days).

    2.3. Consultation service

    Purpose of data processing: scheduling and conducting the 60-minute executive consultation.
    Processed data:
    – full name,
    – e-mail address,
    – phone number (optional, for coordination purposes),
    – operational information regarding the business shared during the consultation.
    Legal basis: Article 6(1)(b) of the GDPR — performance of a contract.
    Retention period: 5 years from the completion of the service. Business data shared during the consultation is treated confidentially by the Data Controller and is not shared with third parties.

    2.4. Contact and complaint handling

    Purpose of data processing: responding to inquiries, questions, and complaints received at the address info@strongholdoperativ.hu.
    Data processed: name, e-mail address, content of the inquiry.
    Legal basis: Article 6(1)(f) of the GDPR — legitimate interest of the Data Controller (provision of customer service).
    Retention period: 3 years from the closure of the inquiry.

    2.5. Website visits (cookies)

    When visiting the strongholdoperativ.hu website, the Data Controller may use cookies to ensure the website’s operation and improve the user experience. Detailed rules regarding cookies are set out in the website’s separate Cookie Notice.
    Website hosting provider: Rackhost Zrt. (address: 41 Tisza Lajos körút, Szeged, 6722). The hosting provider may automatically record the visitor’s IP address, the date and time of the visit, the pages viewed, and the browser type in web server log files. The hosting provider retains this data for a maximum of 90 days and processes it exclusively for technical purposes.

    3. Data Processors

    The Data Controller engages the following data processors for its data processing activities:
    – Hosting provider: Rackhost Zrt. (6722 Szeged, Tisza Lajos körút 41.) — website operation
    – Invoicing software provider — electronic invoicing (the name of the specific provider will be indicated following implementation)
    – Payment service provider — processing of online payment transactions (the name of the specific provider will be indicated following implementation; bank card details are handled exclusively by the payment service provider; the Data Controller does not see or store them)
    – Courier service / Magyar Posta Zrt. — to the extent necessary for the delivery of printed products (delivery address, contact person’s name)

      Data processors handle the data exclusively in accordance with the Data Controller’s instructions and to the extent necessary to achieve the purpose of data processing.

      The Data Controller does not transfer personal data to third parties—other than data processors—unless required by law (e.g., an official request from an authority) or if the Customer has expressly consented to such transfer.
      The Data Controller does not transfer personal data outside the European Union or the European Economic Area.

      Pursuant to Articles 15–22 of the GDPR, the Customer (data subject) may exercise the following rights:

        5.1. Right of access (Article 15 GDPR)

        The Customer is entitled to request information as to whether the Data Controller is processing their personal data and, if so, what data is being processed, for what purpose, and for how long.

        5.2. Right to rectification (Article 16 GDPR)

        The Customer may request the rectification of inaccurate or incomplete personal data.

        5.3. Right to erasure (GDPR Article 17)

        The Customer may request the erasure of their personal data if the purpose of the data processing has ceased, the data processing took place without a legal basis, or the data subject has withdrawn their consent—unless the data processing is required by law (e.g., statutory accounting retention obligations).

        5.4. Right to restriction of processing (GDPR Article 18)

        The Customer may request the restriction of data processing, for example, if they contest the accuracy of the data or object to the data processing.

        5.5. Right to data portability (GDPR Article 20)

        The Customer has the right to receive the personal data concerning them—which they have provided—in a structured, commonly used, and machine-readable format, and to transmit those data to another controller, provided the processing is based on consent or a contract.

        5.6. Right to object (GDPR Article 21)

        The Customer may object to the processing of their personal data based on legitimate interests. In such a case, the Data Controller may no longer process the data unless they demonstrate compelling legitimate grounds for the processing.

        5.7. Right to withdraw consent

        Where data processing is based on consent, the Customer has the right to withdraw their consent at any time. Such withdrawal does not affect the lawfulness of data processing carried out prior to the withdrawal.

        To exercise these rights, the Customer may contact the Data Controller at the email address info@strongholdoperativ.hu. The Data Controller will respond to the request within 30 days, in accordance with Article 12 of the GDPR.

        If the Customer believes that the processing of their personal data violates the provisions of the GDPR, they have the right to lodge a complaint with the supervisory authority:
        National Authority for Data Protection and Freedom of Information (NAIH) 1055 Budapest, Falk Miksa utca 9–11. Postal address: 1363 Budapest, Pf. 9. E-mail: ugyfelszolgalat@naih.hu Website: naih.hu
        The Customer also has the right to seek judicial remedy before the competent court if they consider that the Data Controller has processed their personal data in a manner that violates the GDPR.

        When processing personal data, the Data Controller implements appropriate technical and organizational measures to ensure data security, specifically including protection against unauthorized access, alteration, disclosure, and deletion.
        Digital products are issued with a unique customer identifier (watermark) containing the customer’s name, e-mail address, order number, and the date of purchase. This technical measure serves to enforce copyright protection and enable the tracing of unauthorized distribution.
        In the event of a personal data breach, the Data Controller shall notify the supervisory authority within 72 hours, in accordance with Article 33 of the GDPR, and, where necessary, the affected Customers as well.

        The Data Controller reserves the right to amend this Data Processing Notice. The Data Controller shall inform the data subjects of any amendments via the Website. Data collected prior to the entry into force of an amendment shall be processed in accordance with the original terms.
        This Data Processing Notice enters into force on January 1, 2026.

              Scroll to Top