top of page

Privacy Notice concerning the data processing activities associated with the website of Szafari Adventures Kft.

​

Szafari Adventures Kft., acting as data controller, hereby informs the Data Subjects of the processing of their personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter: "General Data Protection Regulation" or "GDPR").

​

1. Corporate Name and Contact Details of the Data Controller

 

Szafari Adventures Kft.

  • Registered office: 9700 Szombathely, Kertész utca 59., Hungary

  • Company registration number: Cg. 18-09-116167

  • Tax number: 32692657-2-18

  • E-mail: info@szafariadventures.com

​​

2. Title of the Data Processing Activity

​

Data processing associated with the website of the Data Controller, accessible at szafariadventures.com.

Purpose of Data ProcessingLegal Basis of Data ProcessingScope of Data Processed

Management of affairs based on message submission, callback requests, and requests for proposals (RFPs) via the contact form.The voluntary consent of the Data Subject.Name, e-mail address, and telephone number of the Data Subject, as well as any personal data provided by the Data Subject for the purpose of contact.

No automated decision-making, including profiling, takes place during the data processing.

The service provider is not obliged to verify whether the Data Subject possesses the requisite authority or right to provide the data. Responsibility for the existence of such authority lies solely with the applicant/provider of the data.

​

3. Information on the Engagement of Data Processors

​

Personal data is accessible to those employees acting within the interest of the Data Controller whose access is necessary for the performance of their activities and who are fully aware of the obligations relating to the processing of personal data.

Personal data shall not be transferred to third parties for data processing purposes.

​

4. Rights of the Data Subject in Relation to Data Processing

​

  • Right to be informed

  • Right of access

  • Right to rectification

  • Right to erasure ("right to be forgotten")

  • Right to restriction of processing

  • Right to object

  • Right to data portability

  • Right to withdraw consent

  • Right to lodge a complaint

  • Right to an effective judicial remedy

​

Right to be informed:

​

General rules of informing the Data Subject and the right to information.

The Data Controller must provide the Data Subject with detailed information concerning the data processing - comprising the information contained in this Privacy Notice - prior to the commencement of the data processing, and at the latest when the personal data are obtained.

The Data Controller shall be responsible for providing this prior information.

In addition to the prior information mentioned above, the Data Subject may request information from the Data Controller at any stage of the data processing as set out below. In such cases, the Data Controller shall provide the information without undue delay, and in any event within a maximum of 30 days. This one-month period may be extended by up to 2 additional months only in justified cases.

The Data Controller may refuse to provide information only if it demonstrates that the Data Subject cannot be identified, or if the Data Subject's request is manifestly unfounded, repetitive, or excessive.

If the Data Controller fails to take action - i.e., does not fulfill its obligation to provide information - it must inform the Data Subject within 30 days of the reasons for the failure to act, and of the Data Subject's right to lodge a complaint and seek a judicial remedy. Detailed information regarding complaints and judicial remedies is provided below in this Notice.

Information and actions must be provided to the Data Subject by the Data Controller free of charge. However, in exceptional cases, the Data Controller may charge a reasonable fee or refuse to act on the request if the Data Subject's request is manifestly unfounded, repetitive, or excessive.

​

Right of access by the Data Subject:

​

The Data Subject shall have the right to obtain from the Data Controller confirmation as to whether or not personal data concerning him or her are being processed, and, where that is the case, access to the personal data and the following information:

Based on the right of access, the Data Subject shall, upon request, be informed of:

  • the purposes of the processing;

  • the categories of personal data concerned;

  • the recipients or categories of recipients to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organizations;

  • where possible, the envisaged period for which the personal data will be stored;

  • the existence of the right to request from the Data Controller rectification or erasure of personal data or restriction of processing of personal data concerning the Data Subject or to object to such processing;

  • the right to lodge a complaint with the supervisory authority (NAIH);

  • where the personal data are not collected from the Data Subject, any available information as to their source;

  • the existence of automated decision-making, including profiling, and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the Data Subject.

The Data Controller shall provide a copy of the personal data undergoing processing. For any further copies requested by the Data Subject, the Data Controller may charge a reasonable fee based on administrative costs, about which the Data Subject will be informed in advance if such costs arise.

Where the Data Subject makes the request by electronic means, the information shall be provided in a commonly used electronic form, unless otherwise requested by the Data Subject.

​

Right to rectification:

​

The Data Subject shall have the right to obtain from the Data Controller without undue delay the rectification of inaccurate personal data concerning him or her. Taking into account the purposes of the processing, the Data Subject shall have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

​

Right to erasure ("right to be forgotten"):

​

The Data Subject shall have the right to obtain from the Data Controller the erasure of personal data concerning him or her without undue delay, and the Data Controller shall have the obligation to erase personal data without undue delay where one of the following grounds applies:

  • the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;

  • where the processing is based on the Data Subject’s consent (e.g., sending newsletters) and the Data Subject withdraws consent, and there is no other legal ground for the processing;

  • the Data Subject objects to the processing and there are no overriding legitimate grounds for the processing;

  • the personal data have been unlawfully processed;

  • the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the Data Controller is subject;

  • the personal data have been collected in relation to the offer of information society services.

Where the Data Controller has made the personal data public and is obliged pursuant to the above to erase the personal data, the Data Controller, taking into account available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that the Data Subject has requested the erasure by such controllers of any links to, or copy or replication of, those personal data.

The Data Controller shall not be obliged to comply with the erasure request in the cases specified above to the extent that processing is necessary:

  • for exercising the right of freedom of expression and information;

  • for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;

  • on the grounds of public interest in the area of public health;

  • for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, in so far as the right to erasure is likely to render impossible or seriously impair the achievement of the objectives of that processing; or

  • for the establishment, exercise, or defense of legal claims.

If any of the reasons above exist and the Data Controller is not obliged to comply with the Data Subject's erasure request, it shall inform the Data Subject of this circumstance within 25 days, specifying the reasons thereof.

​

Right to restriction of processing:

​

The Data Subject shall have the right to obtain from the Data Controller restriction of processing where one of the following applies:

  • the accuracy of the personal data is contested by the Data Subject, for a period enabling the Data Controller to verify the accuracy of the personal data;

  • the processing is unlawful and the Data Subject opposes the erasure of the personal data and requests the restriction of their use instead;

  • the Data Controller no longer needs the personal data for the purposes of the processing, but they are required by the Data Subject for the establishment, exercise, or defense of legal claims; or

  • the Data Subject has objected to processing; pending the verification whether the legitimate grounds of the Data Controller override those of the Data Subject.

Where processing has been restricted under the above, such personal data shall, with the exception of storage, only be processed with the Data Subject's consent or for the establishment, exercise, or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State.

A Data Subject who has obtained restriction of processing pursuant to the above shall be informed by the Data Controller before the restriction of processing is lifted.

Notification obligation regarding rectification or erasure of personal data or restriction of processing:

The Data Controller shall communicate any rectification or erasure of personal data or restriction of processing carried out to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort.

​

Right to data portability:

​

The Data Subject shall have the right to receive the personal data concerning him or her, which he or she has provided to a Data Controller, in a structured, commonly used, and machine-readable format and have the right to transmit those data to another data controller without hindrance from the Data Controller to which the personal data have been provided, where:

  • the processing is based on consent (e.g., sending newsletters) or on the performance of a contract existing between the parties; and

  • the processing is carried out by automated means.

In exercising his or her right to data portability pursuant to the above, the Data Subject shall have the right to have the personal data transmitted directly from one controller to another, where technically feasible.

The exercise of the right to data portability shall be without prejudice to the right to erasure. The right to data portability shall not adversely affect the rights and freedoms of others.

​

Right to object:

​

The Data Subject shall have the right to object, on grounds relating to his or her particular situation, at any time to processing of personal data concerning him or her. In such cases, the Data Controller shall no longer process the personal data unless the Data Controller demonstrates compelling legitimate grounds for the processing which override the interests, rights, and freedoms of the Data Subject, or for the establishment, exercise, or defense of legal claims.

Where personal data are processed for direct marketing purposes (e.g., sending marketing letters to clients), the Data Subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing. Where the Data Subject objects to processing for direct marketing purposes, the personal data shall no longer be processed for such purposes.

​

Right to withdraw consent:

​

Where the legal basis for the data processing is the consent of the Data Subject (e.g., sending newsletters for marketing purposes), the Data Subject shall have the right to withdraw his or her consent to the data processing at any time. However, the withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

Consent may be withdrawn if the Data Subject deletes their user account, or by submitting a request for erasure concerning the processing of personal data via e-mail to info@szafariadventures.com.

​

Remedies, Right to Lodge a Complaint, Judicial Remedy:

​

What can the Data Subject do if they believe their personal data are not being processed lawfully?

Right to Lodge a Complaint:

The Data Subject shall have the right to lodge a complaint with a supervisory authority—in particular in the Member State of his or her habitual residence, place of work, or place of the alleged infringement—if the Data Subject considers that the processing of personal data relating to him or her infringes the law. In Hungary, the competent supervisory authority is the National Authority for Data Protection and Freedom of Information (NAIH).

The exercise of the right to lodge a complaint shall be without prejudice to the right of the Data Subject to seek other administrative or judicial remedies if they consider that their personal data are being processed unlawfully. Therefore, even when exercising the right to lodge a complaint, the Data Subject may simultaneously initiate administrative or judicial proceedings.

Complaints may be lodged with the National Authority for Data Protection and Freedom of Information, the contact details of which are as follows:

​

  • Name: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH)

  • Registered office: 1055 Budapest, Falk Miksa utca 9-11., Hungary

  • Mailing address: 1530 Budapest, Pf.: 5., Hungary

  • Telephone: +36 1 391 1400

  • Fax: +36 1 391 1410

  • Website: http://www.naih.hu

  • E-mail: ugyfelszolgalat@naih.hu

  • Data Processing Registration Number: NAIH-126761/2017

​

Right to an effective judicial remedy against a decision of NAIH or other supervisory authorities:

If the Data Subject has turned to the supervisory authority (NAIH) regarding their data processing and the authority has made a decision on the matter, the Data Subject shall have the right to initiate judicial proceedings against this decision, i.e., to challenge the decision before a court. The aforementioned right to a judicial remedy also applies to the Data Subject if the competent supervisory authority (NAIH) does not handle the complaint or does not inform the Data Subject within three months on the progress or outcome of the complaint lodged.

Proceedings against a supervisory authority (NAIH) shall be brought before the courts of the Member State where the supervisory authority is established.

​

Right to an effective judicial remedy against the Data Controller or the Data Processor:

The Data Subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under the data protection regulations have been infringed as a result of the non-compliant processing of his or her personal data. The exercise of the right to a judicial remedy shall be without prejudice to the right of the Data Subject to seek other administrative or judicial remedies, or to exercise their right to lodge a complaint, if they consider that their personal data are being processed unlawfully.

Proceedings against the Data Controller or Data Processor shall be brought before the courts of the Member State where the Data Controller or Data Processor has an establishment.

In the case of Szafari Adventures Kft., the courts of Hungary constitute the courts of the place of establishment. The court having competent jurisdiction based on the registered office of Szafari Adventures Kft. is the Szombathely Regional Court (Szombathelyi Törvényszék).

Judicial remedy proceedings may also be brought before the courts of the Member State where the Data Subject has his or her habitual residence, unless the Data Controller or Data Processor is a public authority of a Member State acting in the exercise of its public powers.

Liability for Damages and Compensation for Violations of Personal Rights (compensation):

​

How are the Data Controller and the Data Processor liable to the Data Subject in the event of damage?

​

If non-compliant data processing has caused damage to the Data Subject, the Data Controller shall be liable for the compensation of such damage. Damage may be claimed if the data processing was unlawful or constituted a breach of contract, and the Data Subject suffered a financial disadvantage as a result. In the event of unlawful data processing, the Data Subject may also claim compensation for the violation of personal rights (compensation).

​

Claims for damages or compensation for violations of personal rights may primarily be asserted against the Data Controller. The Data Processor shall be liable for damages only where it has failed to comply with obligations specifically directed to data processors under the law, or where it has acted outside or contrary to the lawful instructions of the Data Controller. Consequently, the Data Processor shall not be liable for errors committed by the Data Controller.

​

5. Storage of Personal Data and Security of Processing

​

The information technology tools and solutions, particularly the security systems used for data processing, are selected and operated in such a manner as to ensure that the processed personal data remain accessible to authorized persons, their authenticity and authentication are secured, their integrity can be verified, and they are protected against unauthorized access.

Taking into account the state of the art at any given time, we implement technical, organizational, and structural measures to ensure the security and protection of our data processing, providing a level of protection appropriate to the risk of your personal data.

​

Szombathely, December 4, 2024

This website was created as part of the Sándor Demján Program and with its support.

  • facebook
  • youtube
  • instagram
  • TikTok
  • X

Main Partners

Africa's Sportsman Logo, hunting, hunting trips,
Wild en Jag, Game and hunt, hunting trips, hunting, safari,

© 2026 by Szafari Adventures.

bottom of page