GDPR
DATA PROCESSING NOTICE
Effective: July 1, 2026
1. Purpose of the privacy notice
The purpose of this Data Protection Notice is to explain the www.themagic2.hu (hereinafter referred to as the Data Controller), and provide information on the processing of personal data of website visitors, online gift voucher purchasers, persons initiating table reservations, users of the contact form and newsletter subscribers.
The Data Controller pays special attention to the protection of personal data and to ensuring that its data processing activities comply in all respects with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), Act CXII of 2011 on the Right to Informational Self-Determination and Freedom of Information, and with Hungarian and European Union legislation in force at all times.
The Data Controller processes personal data exclusively for the purposes specified in the legislation, to the necessary extent and for the necessary period.
The Data Controller ensures that the principles of lawfulness, fair procedure, transparency, purpose limitation, data economy, accuracy, limited storage, integrity and confidentiality are applied when processing personal data.
2.Data controller's data
Company name:
Magic Empire Limited Liability Company
Abbreviated company name:
Magic Empire Ltd.
Headquarters:
1065 Budapest, Hajós Street 25.
Company registration number:
Cg. 01-09-342499
Tax number:
26745677-2-42
E-mail:
info@themagic.hu
Phone number:
+36 30 984 9009
Website:
www.themagic2.hu
3.Principles applied during data processing
The Data Controller applies the following principles in particular when processing personal data:
- legality, due process and transparency;
- purpose-bound data processing;
- data saving;
- accuracy;
- limited storage capacity;
- integrity and confidentiality;
- accountability.
The Data Controller only processes personal data that is necessary to achieve the purpose of data management and only retains it for the necessary period of time.
4.Legal background of data processing
The data processing activities of the Data Controller are governed in particular by the following laws:
- Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR);
- Act CXII of 2011 on the right to informational self-determination and freedom of information;
- Act V of 2011 on the Civil Code;
- Act CVIII of 2011 on electronic commerce services;
- Act XLVIII of 2008 on economic advertising activities;
- Act C of 2011 on Accounting
- Act CXXVII of 2011 on general value added tax;
as well as the Hungarian and European Union data protection laws in force at all times.
- Act CXXVII of 2011 on general value added tax;
- Scope of data processing
This Data Protection Notice covers the www.themagic2.hu for all data processing activities carried out on the website, in particular:
- to visit the website;
- to use the contact form;
- to purchase a gift certificate online;
- to process electronic payments;
- to subscribe to the newsletter;
- data processing for marketing purposes;
- statistical and analytical data processing;
- to use cookies;
- data processing during online table reservations;
- customer service communication;
- for data processing necessary to fulfill legal obligations.
- Detailed description of each data processing
6.1 Data processing carried out when visiting the website
Purpose of data processing
Ensuring the proper functioning of the website, maintaining the security of the IT system, preventing abuse, and technically ensuring the operation of the website.
Scope of data processed
- IP address
- browser type and version
- operating system
- pages viewed
- date of visit
- referring page
- session ID
- technical log data
Legal basis for data processing
GDPR Article 6(1)(f) – legitimate interest of the Data Controller.
Duration of data processing
Technical log files are retained for a maximum of 30 days, unless legal requirements or a security incident warrant longer retention.
6.2 Contact form
Purpose of data processing
Responding to the User's inquiries, making contact and handling matters.
Scope of data processed
- name
- email address
- phone number (if provided)
- message content
- submission date
Legal basis for data processing
GDPR Article 6(1)(a) – consent.
Duration of data processing
Up to 1 year after the case is closed.
6.3 Contact by email
If the User contacts the Data Controller directly by e-mail, the Data Controller processes the personal data necessary for the response.
Managed data
- name
- email address
- phone number (if available)
- letter content
- attachments
- communication time
Legal basis
GDPR Article 6(1)(b) or (f).
Retention time
Up to 5 years after the case is closed.
6.4 Telephone contact
If the User contacts the Data Controller by telephone, the Data Controller processes the data necessary for the communication.
Managed data
- phone number
- name (if disclosed)
- data provided during conversation
The Data Controller records telephone conversations only if specifically informed.
Legal basis
GDPR Article 6(1)(b) or (f).
6.5 Buying a gift certificate online
The Data Controller processes the personal data necessary for the purchase of the gift voucher.
Managed data
- name
- billing name
- billing address
- email address
- phone number
- value of the ordered gift certificate
- order ID
- payment status
- account details
Purpose of data processing
- performance of contract
- payment processing
- electronic invoice issuance
- customer service
- fulfillment of legal obligations
Legal basis
GDPR Article 6(1)(b).
When processing billing-related data:
GDPR Article 6(1)(c).
Retention time
According to the legislation on accounting documents, 8 years.
6.6 Online payment (SimplePay)
Online credit card payments are processed by the SimplePay system.
Bank card details are not sent to the Data Controller.
During the payment transaction, only the data necessary to complete the transaction is transmitted to the payment service provider.
Detailed rules for data management are contained in SimplePay's own data management information.
Legal basis
GDPR Article 6(1)(b).
6.7 Electronic invoicing
The Data Controller uses the Számlázz.hu system to issue electronic invoices.
The personal data necessary for issuing invoices will be forwarded to Számlázz.hu.
Managed data
- name
- billing address
- email address
- purchase details
- tax number (in case of a legal entity)
Legal basis
GDPR Article 6(1)(c).
Retention time
8 years.
6.8 Newsletter subscription
The Data Controller provides Users with the opportunity to subscribe to a newsletter in order to receive information about The Magic II restaurant's news, events, promotions, offers and other marketing communications.
Scope of data processed
- name (if provided)
- email address
- date of registration
- IP address
- fact of subscription
- unsubscribe date
Purpose of data processing
- sending electronic newsletters;
- marketing communication;
- information about promotions and events.
Legal basis for data processing
GDPR Article 6(1)(a) – consent of the data subject.
Duration of data processing
Until you withdraw your consent or unsubscribe from the newsletter.
Unsubscribing from the newsletter is possible at any time, free of charge, using the unsubscribe link at the bottom of the newsletters or by sending an e-mail to the Data Controller.
6.9 Google Analytics 4
This website uses Google Analytics 4 to analyze website usage and generate statistical data.
The service uses cookies and other technologies to collect information about website usage.
Scope of data processed
- IP address (abbreviated)
- device type
- operating system
- browser type
- pages viewed
- number of sessions
- events
- clicks
- time spent on website
- approximate geographical location
- traffic sources
Purpose of data processing
- website usage analysis;
- preparing statistics;
- improving user experience;
- website development.
Legal basis for data processing
GDPR Article 6(1)(a) – consent.
Duration of data processing
Retention period according to Google Analytics settings.
6.10 Google Tag Manager
The website uses the Google Tag Manager service to manage various measurement codes and marketing tools.
Google Tag Manager itself does not store personal data, but it enables other services to function.
The detailed rules of data management are contained in the data management information of the given service.
Legal basis for data processing
GDPR Article 6(1)(a).
6.11 Google Ads conversion tracking and remarketing
The website uses Google Ads conversion tracking and remarketing services.
The purpose of the service is to measure the performance of ads and to display personalized ads.
Scope of data processed
- IP address
- cookie identifiers
- device identifiers
- browsing events
- conversion events
- clicks
- visit data
Purpose of data processing
- ad optimization;
- measuring conversions;
- remarketing campaigns;
- preparing marketing statistics.
Legal basis for data processing
GDPR Article 6(1)(a) – consent.
6.12 Meta Pixel
The website uses the Meta Pixel service provided by Meta Platforms Ireland Limited.
Meta Pixel allows you to analyze website usage, measure the effectiveness of ads, and create target audiences for remarketing purposes.
Scope of data processed
- IP address
- cookie identifiers
- browsing events
- visited pages
- conversion events
- clicks
- device identifiers
Purpose of data processing
- optimization of marketing campaigns;
- remarketing;
- measuring the performance of advertisements;
- conducting statistical analyses.
Legal basis for data processing
GDPR Article 6(1)(a) – consent.
6.13 Google Maps
The website has an embedded Google Maps map.
When using Google Maps, Google may process personal data, in particular your IP address and other technical data.
When using the service, data may be transmitted to Google.
Purpose of data processing
- displaying the restaurant's location;
- providing route planning.
Legal basis for data processing
GDPR Article 6(1)(a) – consent.
6.14 YouTube videos
Videos from the YouTube video sharing service may be embedded on the website.
During video playback, Google may process personal data and place cookies on the User's device.
Scope of data processed
- IP address
- device data
- browser data
- video viewing data
- cookie identifiers
Purpose of data processing
- displaying video content;
- improving user experience.
Legal basis for data processing
GDPR Article 6(1)(a) – consent.
7. Data processors and data transfer
In order to provide services, the Data Controller uses data processors to perform certain data management operations.
Data processors are authorized to process personal data solely on the instructions of the Data Controller and cannot make independent decisions.
The Data Controller only uses data processors that provide adequate guarantees for the secure handling of personal data.
7.1 Hosting provider
The Data Controller uses a hosting service provider to operate the website.
The hosting provider is responsible in particular for:
- operating the website;
- secure storage of data;
- creating backups;
- server operation;
- IT support.
The identity and contact details of the data processor are determined in accordance with the applicable service contract.
7.2 WordPress system
The website operates using the WordPress content management system.
During the operation of the WordPress system, technical data may be processed to ensure the secure operation of the website.
7.3 Reservours online booking system
Online table reservations are handled by the Reservours system.
The processing of personal data provided during the reservation process is also governed by Reservours' own data processing information.
The Data Controller only knows the data necessary to complete the reservation.
7.4 SimplePay
Online credit card payments are processed by SimplePay.The bank card details provided during payment do not come into the possession of the Data Controller.
The Data Controller only receives information about the success, identifier and status of the transaction.
7.5 Számlázz.hu
The issuance of electronic invoices is provided by Számlázz.hu.
The data required for invoicing will be transferred to the billing service provider.
7.6 Google services
The following Google services are used during the operation of the website:
- Google Analytics 4
- Google Tag Manager
- Google Ads
- Google Maps
- YouTube
When using the services, personal data may be transmitted to Google.
7.7 Meta Platforms
The website uses Meta Pixel.
With the help of Meta's services, the Data Controller performs statistical analyses, measures conversions and displays remarketing advertisements.
Only data necessary for the operation of the service will be transmitted to Meta.
7.8 Newsletter provider
The Data Controller may use an external service provider to send the newsletter.
The newsletter provider only processes the data necessary for sending newsletters.
The data processor is authorized to process data solely on the instructions of the Data Controller.
8. Data transfer to a third country
Some service providers used by the Data Controller – in particular Google and Meta – may use servers located outside the European Economic Area due to their operation.
In all cases, data transfer takes place with the application of guarantees in accordance with applicable data protection legislation.
The legal basis for the transfer of data is the European Commission's adequacy decisions, the Standard Contractual Clauses (SCC) adopted by the European Commission, and other appropriate safeguards provided for by the GDPR.
9.Data security
The Data Controller applies appropriate technical and organizational measures to protect the personal data processed, in particular:
- against unauthorized access;
- against unauthorized alteration;
- against unauthorized transmission;
- against unauthorized disclosure;
- against deletion or destruction;
- against accidental data loss;
- against IT attacks.
The Data Controller ensures that only those employees and collaborators who need this information to perform their job duties have access to personal data.
The Data Controller continuously monitors, maintains and protects the IT systems used to process personal data against external attacks, in accordance with technological possibilities.
The Data Controller shall take all reasonable measures to ensure that the confidentiality, integrity and availability of the personal data it processes are continuously ensured.
After that, only two major chapters remain:
- 10. Rights of data subjects (access, erasure, rectification, data portability, etc.)
- 11–13. Complaints handling, NAIH, final provisions
