AI Booking
Online appointment booking Your own booking page, available 24/7 Automatic reminders Email confirmation and reminder for every booking Google Calendar sync Two-way sync to reduce double bookings Online payment and deposit Stripe-based deposit and full payment handling Group booking Multiple participants per booking, with capacity management Hungarian invoicing Billingo and Számlázz.hu integration Booking widget Embeddable widget for websites and WordPress Reducing no-shows Reminders, deposits, and a clear cancellation process Avoiding double booking Transparent calendar and accurate availability Közös naptár kezelés Megosztott erőforrás (szék, pálya, szoba) kapacitással AI chatbot AI chatbot in the booking process SMS reminder Reliable SMS reminders to Hungarian numbers Guest CRM Guest CRM and history management AI no-show prediction Risk score for every booking AI price suggestion Dynamic pricing strategy based on utilization AI multilingual booking Booking in 6 languages for foreign guests Statistics and reports Detailed statistics on bookings and financial data AI assistant (MCP) Claude/ChatGPT for your bookings Gift Voucher Online voucher sales with redemption
AI Booking időpontfoglaló rendszer funkciók Try it for free

14-day trial period, no credit card required.

Free trial →
For hairdressers Booking system for modern salons For Beauticians Facial treatments, consultations and deposit For nail technicians Manicure, infill, gel polish on one platform For massage therapists 30/60/90-minute treatments and packages For psychologists Discreet, with automatic reminders For personal trainers Managing group and individual training sessions For Photographers Wedding, portrait, family photography with deposit For dentists Consultation and treatment with calendar sync For Coaches Consultations, packages and online payment For dog groomers Dogs, breeds and treatments organized For language teachers Managing group and individual sessions For Car Detailers Polishing, washing and interior cleaning For Private Doctors Private practice — check-up, online consultation For tattoo artists Consultation + high deposit + portfolio For barbers Haircut, beard, combo packages Wellness and Spa Combo packages, passes, gift vouchers Yoga and Pilates Group classes, passes, waiting list For physiotherapists Rehab pass, online practice consultation For Shooting Ranges Industry booking solution For escape rooms Industry booking solution For go-kart tracks Industry booking solution Team-building programs Industry booking solution
All industries →
Pricing
Find a provider Blog
FAQ
🇬🇧 EN ▾
🇭🇺 Magyar🇬🇧 English🇩🇪 Deutsch🇷🇴 Română🇸🇰 Slovenčina🇵🇱 Polski
Login Free trial
Features
Online appointment bookingAutomatic remindersGoogle Calendar syncOnline payment and depositGroup bookingHungarian invoicingBooking widgetReducing no-showsAvoiding double bookingKözös naptár kezelésAI chatbotSMS reminderGuest CRMAI no-show predictionAI price suggestionAI multilingual bookingStatistics and reportsAI assistant (MCP)Gift Voucher All Features →
Solutions
For hairdressersFor BeauticiansFor nail techniciansFor massage therapistsFor psychologistsFor personal trainersFor PhotographersFor dentistsFor CoachesFor dog groomersFor language teachersFor Car DetailersFor Private DoctorsFor tattoo artistsFor barbersWellness and SpaYoga and PilatesFor physiotherapistsFor Shooting RangesFor escape roomsFor go-kart tracksTeam-building programs All solutions →
Pricing Find a provider Blog FAQ Login Free trial

Login

Choose how you'd like to sign in.

Continue as guestYour bookings, passes and reviews in one place. → Log in as a providerManage your bookings, calendar, and clients. →
Legal Document

Privacy Notice – v2

Current version: v2 Published: March 8, 2026

Privacy Notice

Effective date: 2026. február 12. • Version: 1.11

Table of contents

  1. Summary – Our Data Processing in a Nutshell
  2. Details and contact information of the Data Controller
  3. Legal background
  4. Definitions
  5. Data Processors
  6. Legal bases for data processing
  7. Processed data in detail
  8. Cookies
  9. Retention periods
  10. Data security
  11. Your rights
  12. Legal remedy
  13. Provider features
  14. Frequently Asked Questions (FAQ)
  15. Contact
  16. Protection of minors
  17. Data Protection Officer (DPO)
  18. International data transfer
  19. Modification of the notice

1. Summary – Our data handling in a nutshell

Dear User!

Before diving into the legal details, we'd like to summarize in plain language how we handle your personal data. The full notice contains detailed information, but if you'd like to quickly understand the essentials, you'll find them here:

What data do we request, and why?

We only request the data that is absolutely necessary for you to use our service. We do not collect unnecessary information and we do not "snoop" on you.

DataWhy is it needed?What happens if they don't provide it?
Name So the provider knows who to expect and we can welcome them personally Can't register
Email address Confirmations, reminders, password resets – this is how we stay in touch with you Can't register
Phone number If you need to be reached urgently (e.g. schedule change), or want an SMS reminder Required for booking
Booking data We need to know when, where and for which service they are booking Cannot book

Who do we share your data with?

Your data We do NOT sell it, We do NOT rent it out, and We do NOT share it with third parties for marketing purposes. We only share your data with those who are essential for the operation of the service:

  • The chosen provider – the person you are booking an appointment with (hairdresser, masseur, trainer, etc.). They see your name, contact details, and the booking details.
  • Technical partners – who ensure the operation of the system (server, email sending, payment). They only have access to the necessary data and have contractually committed to confidentiality.
  • Authorities – but only when required by law (e.g. a tax audit, a court order).

How long do we keep your data?

  • Account data: As long as you actively use your account. If you delete it, we permanently remove it within 60 days.
  • Invoices, financial data: For 8 years – required of us by law.
  • Technical logs (IP address, browser): for 90 days, for security reasons.

What rights do you have?

You retain full control over your data:

  • You can view it – request information about what data we store about you
  • You can modify it – correct inaccurate or outdated data
  • You can delete – request the deletion of your data (with certain exceptions)
  • You can export it – take your data with you in a machine-readable format
  • Can object say no to direct marketing

How do we protect your data?

  • Encrypted connection (HTTPS) – all data travels securely
  • Encrypted passwords — not even we can see your password
  • Two-factor authentication – extra protection for your account
  • Continuous security monitoring – we watch for suspicious activity

2. Data controller's details and contact information

The data controller is the natural or legal person who determines the purposes and means of processing personal data. In the case of the AI Booking system, the data controller is:

Dobó Imre, sole trader

Registered office: 4029 Debrecen, Hajnal utca 14. 2/13
Tax number: 53669401-1-29
Registration number: 52110667
Email: info@aibooking.hu
Phone: +36 30 609 5404
Website: www.aibooking.hu
Client hours: Monday-Friday 9:00 AM-5:00 PM (CET)

Important: Who is the data controller in your case?

AI Booking is a multi-actor system, where data controller roles are shared. It's important to understand who is responsible for your data in a given situation:

1. If you use the system directly (register, change settings):

Data controller: Dobó Imre E.V. (the system operator)

2. If you book an appointment with a service provider:

The primary data controller: the service provider (e.g. hairdresser, masseur, trainer)
Role of Dobó Imre E.V.: Data processor (providing technical infrastructure)

What does this mean in practice?

  • The provider determines what data is requested from you for booking
  • The provider is responsible for how it uses your data
  • If you have a problem with the provider's data processing, please contact them first
  • We (Dobó Imre E.V.) provide the technical background and help if you have any questions

Practical example

Situation: You book an appointment at a hairdresser called "Szépség Szalon" through AI Booking.

What happens to your data?

  1. You provide your name, email address, phone number, and select the appointment time
  2. This data is stored in our system (we are the data processors)
  3. "Beauty Salon" has access to this data in order to be able to receive you (they are the data controller)
  4. We send the confirmation email on behalf of "Beauty Salon"

If you want to delete your data:

  • From the system (AI Booking): Contact us
  • From the records of "Beauty Salon": Please contact them directly

3. Legal background – Which laws protect your data?

The protection of your personal data is ensured by a complex legal framework, both at European Union and Hungarian level. Below we present these regulations and their most important provisions in detail.

3.1. European Union legislation

GDPR – General Data Protection Regulation

Regulation (EU) 2016/679 of the European Parliament and of the Council (27 April 2016)

The GDPR (General Data Protection Regulation) is the European Union's unified data protection regulation, directly applicable in all EU member states since 25 May 2018. It is one of the strictest data protection regulations in the world.

The key principles of GDPR:

  • Lawfulness, fairness, transparency (Article 5(1)(a)): Data processing must be lawful, fair, and transparent.
  • Purpose limitation (Article 5(1)(b)): Data may only be collected for specified, explicit and legitimate purposes.
  • Data minimization (Article 5(1)(c)): Only the necessary data may be collected — no more, no less.
  • Accuracy (Article 5(1)(d)): Data must be accurate; inaccurate data must be erased or rectified.
  • Storage limitation (Art. 5(1)(e)): Data may only be stored for as long as necessary.
  • Integrity and confidentiality (Article 5(1)(f)): The data must be properly protected.
  • Accountability (Article 5(2)): The data controller must be able to demonstrate compliance with these principles.

The relevant GDPR articles for our data processing:

ArticleContentHow does this affect you?
Article 4 Definitions Defines what counts as personal data, data controller, etc.
Article 6 Legal bases for data processing Determines the legal basis on which we may process your data
Article 7 Terms of consent You may withdraw your consent at any time
12-14. cikk Obligation to inform It is our duty to inform you in detail (this document)
15-22. cikk Data subject rights Your rights: access, rectification, erasure, restriction, portability, objection
Article 32 Data security We are obliged to properly protect your data
33-34. cikk Data breach In case of an incident, we must notify the authority and you
44-49. cikk International data transfer We may only transfer data outside the EU with appropriate safeguards
77-79. cikk Rights to legal remedy You may file a complaint with the authority or turn to court

3.2. Hungarian legislation

Infotv. – the Hungarian Act on Informational Self-Determination

Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information

This is the Hungarian basic data protection act, which supplements the GDPR with domestic specifics. Its most important elements:

  • Defines the operation and scope of authority of the National Authority for Data Protection and Freedom of Information (NAIH)
  • Regulates data protection authority procedures and sanctions
  • Contains additional provisions on the publicity of data of public interest

Civil Code (Hungary)

Act V of 2013 on the Civil Code

Sections 2:42-54 § contain the the protection of personal rights:

  • 2:42. §: General protection of personal rights
  • 2:43. §: Cases of violation of personality rights (including the right to protection of personal data)
  • 2:51-54. §: Sanctions for personality rights violations – non-pecuniary damages, compensation

What does this mean for you? If our data processing infringes your personal rights, you may claim compensation for damages and non-pecuniary damages.

Accounting Act

Act C of 2000 on Accounting

A Section 169(2) according to which accounting documents (including invoices, contracts, financial records) for 8 years must be retained.

Important consequence: If you paid for a service and received an invoice, we are required to retain the related data (your name, address, invoice content) for 8 years, even if you delete your account. This is not our decision — the law requires it of us.

VAT Act

Act CXXVII of 2007 on Value Added Tax

A 159. § és 169. § defines the mandatory content elements of invoices and the related record-keeping obligations.

Eker tv. – Act on Electronic Commerce

Act CVIII of 2001 on certain issues of electronic commercial services (Hungary)

A 13/A. § regulates that when providing an online service:

  • What data we may process and for how long
  • How to inform the customer about data processing
  • What data we may process for billing the service fee

Grt. — Hungarian Advertising Act

Act XLVIII of 2008 on the Basic Conditions of Economic Advertising Activity

A 6. § states that direct marketing communications – including newsletters sent by email – prior, explicit consent is required.

What does this mean in practice?
  • We only send newsletters or promotional emails if you have explicitly subscribed
  • Subscription must be active (you check the box)
  • A pre-checked checkbox is not sufficient
  • You can unsubscribe anytime with one click

Eht. – Electronic Communications Act

Act C of 2003 on Electronic Communications

It contains the rules regarding electronic communication and the use of cookies, in particular the 155. §, which regulates the conditions for placing cookies.

4. Definitions – What do the legal terms mean?

Under Article 4 of the GDPR

Data protection laws often use technical terms that may seem complicated at first. Below, we explain the most important ones in plain language, with examples.

4.1. Personal Data

Definition: Any information relating to an identified or identifiable natural person.

In plain terms: Any data that can identify you, or that can be linked to you as a person.

Examples of personal data:

Direct identifiers Name, personal ID number, passport number, photo
Contact details Email address, phone number, home address, work address
Online identifiers IP address, cookie identifier, device identifier, username
Financial data Bank account number, tax number, payment history
Activity data Booking history, browsing history, purchasing habits

Is an email address always personal data?

Igen, mert azonosítható személyhez kapcsolódik. Még a "xyz123@example.com" típusú cím is személyes adat, ha az adatbázisban összekapcsolható egy konkrét személlyel.

4.2. Special (sensitive) data

Definition: A particularly protected category of personal data, the processing of which is prohibited as a general rule, except in certain exceptional cases.

This includes:

  • Racial or ethnic origin referential data
  • Political opinion
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic data (DNS information)
  • Biometric data (fingerprint, facial recognition, retina)
  • Health Data (illnesses, medications, treatments)
  • Sexual life or orientation relevant data

AI Booking does NOT process special categories of data

Our system does not collect or store special (sensitive) data. If a service provider requests such data from you in the comments field (e.g. "do you have any allergies"), only that specific provider is responsible for it as an independent data controller.

4.3. Data subject

Definition: The natural person whose personal data is processed.

In plain terms: You! In the AI Booking system, the data subject can be:

  • Guest: Anyone who registers and books an appointment with providers
  • Provider user: Anyone using the system for business purposes (hairdresser, massage therapist, trainer, etc.)
  • Team member: Someone whom a service provider has added to their system

4.4. Data Controller

Definition: The natural or legal person that determines the purposes and means of the processing of personal data.

In plain terms: The one who decides, why és how processes your data. The data controller bears responsibility for the lawfulness of the processing.

Who is the data controller for AI Booking?

If you register in the system Dobó Imre E.V. (us)
If you book with a provider The given service provider (e.g. "Beauty Salon")
If the provider purchases a subscription Dobó Imre E.V. (us)

4.5. Data Processor

Definition: The natural or legal person who processes personal data on behalf of the data controller.

In plain terms: The one who, on behalf of the data controller and per their instructions, performs the "technical" work with the data.

Examples of data processor roles:

  • We (AI Booking) we act as data processors for the providers – they are the data controllers, we provide the technical background
  • SendGrid is a data processor for us – we decide who receives the email, they just send it
  • Hostinger (server + database) data processor – stores and runs the system, but does not make decisions about data processing

4.6. Data Processing

Definition: Any operation or set of operations performed on personal data.

In plain terms: Everything we do with personal data:

  • Collection (registration, form submission)
  • Recording (saving to the database)
  • Organization (categorization, grouping)
  • Storage (retention on the server)
  • Modification (updating data)
  • Query (viewing data)
  • Forwarding (sending data to others)
  • Linking (merging of data)
  • Restriction (data "freezing")
  • Deletion (data removal)
  • Destruction (permanent deletion)

4.7. Consent

Definition: A freely given, specific, informed and unambiguous indication of the data subject's wishes by which they signify agreement to the processing of their personal data.

The consent must meet the following criteria:

  • Voluntary: Szabad döntés, nem kikényszerített, nem jár hátránnyal a megtagadása
  • Specific: It applies to a specific purpose, not a general one
  • Informed: You know what you're consenting to
  • Clear: An active act (clicking, signing), not silence

What does NOT count as valid consent?

  • Pre-checked checkbox
  • "If you do not object, we will consider it as consent"
  • Conditional consent ("you only get the service if you agree to marketing")
  • Vague, generic wording

4.8. Data breach

Definition: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.

Types:

TypeWhat does it mean?Example
Breach of confidentiality Unauthorized access or disclosure A hacker steals the database; an employee sends an email to the wrong address
Breach of Integrity Unauthorized modification A virus alters the data; a faulty import overwrites data
Availability breach Loss or destruction Ransomware encrypts the database; a server fails without a backup

4.9. Profiling

Definition: Any form of automated processing of personal data used to evaluate certain characteristics of a person.

In plain terms: When we use computers to analyze your data in order to draw conclusions from it – for example, to predict what you will buy or which ads will interest you.

AI Booking does NOT engage in profiling

We do not automatically analyze your behavior, do not create a "profile" of you, and do not make automated decisions based on your data.

5. Data Processors – Who has access to your data and how?

For the AI Booking service to work, we need to cooperate with other companies. These partners are so-called "data processors" — they handle your data on our behalf and according to our instructions. We have signed a written agreement with every partner (a data processing agreement under Article 28 GDPR), which guarantees that they too comply with data protection requirements.

5.1. Server services — Where the data "lives"

Hostinger International Ltd. – VPS hosting, database, email and website

Registered office: 61 Lordou Vironos Street, 6023 Larnaca, Cyprus

Website: hostinger.com

Privacy notice: hostinger.com/privacy-policy

Outside the EU: No – EU member state (Cyprus), GDPR applies directly

What does it do? Hostinger provides the entire infrastructure for the AI Booking system:

  • VPS (Virtual Private Server) hosting: The web application and all backend services run on this server
  • PostgreSQL database: Storage of all structured data (users, bookings, settings)
  • Email service: Email accounts linked to the domain and certain transactional messages
  • Landing page hosting: Hosting of the aibooking.hu introductory website

What data does it have access to?

  • All data stored on the server (application, database, log files)
  • User data: names, email addresses, bookings, settings
  • Technical logs (for troubleshooting)

Security features:

  • Data storage within the European Union (GDPR-compliant)
  • Encrypted data transfer (TLS/SSL)
  • Regular security backups
  • Firewall and basic DDoS protection
  • 24/7 server monitoring

What can you NOT use it for? As an infrastructure provider, Hostinger does not access the data for business purposes, only to ensure the technical provision of the service. It has contractually undertaken data processor obligations under the GDPR.

Why is it good that the server is in the EU?

Since Hostinger is a Cyprus-based company and the data stays within the EU, no special data transfer safeguards are required (as would be the case for transfers to the USA). GDPR applies directly, which means stronger protection for your data.

Landing page – custom Node.js application

Page: aibooking.hu (introductory/landing page)

Platform: an in-house Node.js + Express + React application (the same codebase as app.aibooking.hu)

Hosting: Hostinger (see above)

What does it do? The aibooking.hu landing page is the introductory website of the service, from which visitors are directed toward the application. It's custom-built, sharing a codebase with the application — there is no external CMS (we replaced the earlier WordPress/Elementor version in May 2026).

Services used on the landing page:

  • Google Analytics 4: Visitor statistics (only with consent)
  • Cookie Management: Cookie banner for managing consent
  • AI chatbot: The AI assistant available in the bottom right corner (see the next section)

What data does the landing page process?

  • Technical data: IP address, browser type, device (in server logs)
  • Analytics data: page views, time on site (Google Analytics, only with consent)
  • Contact form data (if any): name, email, message
  • AI chatbot conversation history (with anonymous session ID, details below)

AI chatbot – Conversation storage (aibooking.hu)

What does it do? The AI assistant available in the bottom right corner of the landing page answers visitor questions and, if needed, guides them into the consultation booking process. Conversations are stored for auditing and quality assurance purposes.

What do we store in every case?

  • Conversation content (questions and AI response text)
  • Anonymous session identifier (4-hour lifetime, stored in the visitor's browser in localStorage — the session identifier alone is not identifying personal data)
  • Browser type (user agent)
  • Referring page (referer)

IP address storage — dual mode (GDPR / EDPB guidelines):

  • Masked IP (default, even without consent): If you have not accepted the analytics cookie category, we store your IP address in masked form. For IPv4, the last octet is replaced with 0 (e.g. 192.168.1.42 → 192.168.1.0), for IPv6 we remove everything except the first 3 hextets (e.g. 2001:db8:abcd:1234::5678 → 2001:db8:abcd::). This is identical to Google Analytics 4's default IP-anonymization behavior, and according to the EDPB (European Data Protection Board) is not identifiable personal data — so the legal basis is legitimate interest under GDPR Art. 6(1)(f) (spam filtering, abuse protection).
  • Full IP (with consent only): If you have expressly accepted the analytics category in the cookie banner, we store the full IP address. Legal basis: GDPR Art. 6(1)(a) — your consent. Consent can be withdrawn at any time by reopening the cookie banner.

Retention period: 90 days, after which it's automatically deleted. If you manually delete the conversation history (using the "Delete conversation" button in the chat window), it disappears immediately on the client side, and is deleted server-side according to the 90-day automatic retention policy.

AI model and third-party provider: A chatbot az Ollama Cloud platformon működő nyelvi modellt használja. A beszélgetés-tartalom az AI-szolgáltatóhoz (Ollama – ollama.com, üzemeltető: Ollama, Inc., Egyesült Államok; harmadik országba történő adattovábbítás) továbbítódik a válasz generálásához; az AI-szolgáltató nem őrzi meg a tartalmat (zero-retention beállítás). A válaszok elkészítéséhez az Ollama mellett az OpenAI (openai.com, üzemeltető: OpenAI, L.L.C., Egyesült Államok; harmadik országba történő adattovábbítás) MI-szolgáltatót is igénybe vehetjük, ugyanezen adatkezelési feltételekkel; az OpenAI vállalása szerint az API-n beküldött adatok alapértelmezetten nem szolgálnak a modelljei tanítására.

Landing page vs. Application

AI Booking consists of two main parts:

  • Landing page (aibooking.hu): Introductory website – custom Node.js application with Google Analytics and an AI chatbot
  • Application (app.aibooking.hu): The booking system — a custom-developed application

We apply the principles described in this privacy notice on both sides.

Cloudflare Inc. – CDN, security services and image storage

Registered office: 101 Townsend Street, San Francisco, CA 94107, USA

Website: cloudflare.com

Privacy notice: cloudflare.com/privacypolicy

Outside the EU: Yes (USA) – Safeguard: Standard Contractual Clauses (SCC)

What does it do? Cloudflare provides us with several critical services:

1. CDN (Content Delivery Network):

  • It stores the website's static content (CSS, JavaScript, icons) on servers located at various points around the world
  • This way you reach the page faster, wherever you are

2. Security services:

  • DDoS protection: Protects our system from overload attacks
  • WAF (Web Application Firewall): Filters out malicious requests (SQL injection, XSS attacks)
  • Bot protection: Distinguishes humans from malicious bots
  • SSL/TLS: Ensures an encrypted connection (HTTPS)

3. R2 Object Storage – Storing images and files:

  • Gallery images: Gallery images uploaded by providers (portfolio, showcase of work)
  • Profile pictures: Storage of user profile pictures
  • Documents: Uploaded files, attachments

Important about image storage

The Cloudflare R2 service S3-compatible cloud-based storage. Images are accessible via URL and load quickly through Cloudflare's global network. Image content is not analyzed or used for any other purpose.

What data does it have access to?

  • IP addresses (to identify the source of requests)
  • HTTP headers (browser type, language)
  • Request content (passes through the CDN)
  • Uploaded images and files (in R2 storage)

Data storage location: Cloudflare allows regional data restriction. Data in R2 storage is kept in the EU region wherever available.

5.2. Email services — How we communicate with you

SendGrid (Twilio Inc.) – Transactional emails

Registered office: 375 Beale Street, San Francisco, CA 94105, USA

Website: sendgrid.com

Privacy notice: twilio.com/legal/privacy

Outside the EU: Yes (USA) – Safeguard: SCC

What does it do? SendGrid sends all system messages to your email address:

  • Booking confirmations
  • Reminders (1 day and 1 hour before the booking)
  • Password reset links
  • Account activation emails
  • Booking modification/cancellation notifications
  • Newsletters (if subscribed)

What data does it have access to?

  • Your email address (recipient)
  • Email content (message text)
  • Delivery information (whether the email was opened, whether a link was clicked)

What can you NOT use it for? SendGrid may not send you its own marketing messages, nor may it sell your email address.

Hostinger International Ltd. – Alternative email

Registered office: 61 Lordou Vironos Street, 6023 Larnaca, Cyprus

Website: hostinger.com

Outside the EU: No – EU member state (Cyprus)

What does it do? It operates as an alternative email provider for certain transactional messages and domain-related email accounts.

5.3. Payment services — How we handle your money

Stripe Inc. – Online card payment

Registered office: 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA

European headquarters: Stripe Payments Europe, Ltd., Dublin, Ireland

Website: stripe.com

Privacy notice: stripe.com/privacy

Certificates: PCI DSS Level 1 (the highest level of payment card security standard)

What does it do? Stripe handles all online card payments. When you pay, you provide your card details directly to Stripe — this data NEVER reach us.

Data processed by Stripe:

  • Full card number
  • Expiry date
  • CVC/CVV code
  • Cardholder name
  • Billing address

What we see from Stripe:

  • Transaction ID (e.g. "pi_3ABC123...")
  • Amount paid and currency
  • Payment date and status
  • Last 4 digits of the card (e.g. "•••• 4242")
  • Card type (Visa, Mastercard, etc.)

WARNING: Fraud prevention

Mi We NEVER ask for your full bank card number, expiry date, or CVC code by email, phone, or chat. If anyone requests these on behalf of AI Booking, that is FRAUD. Kérjük, azonnal jelezze nekünk az címen!

Barion Payment Zrt. – Online payment

Registered office: 1117 Budapest, Irinyi József utca 4-20, 2nd floor

Company Registration Number: 01-10-048552

Website: barion.com

Privacy notice: barion.com/adatvedelmi-tajekoztato

Certificates: PCI DSS Level 1, payment institution supervised by the National Bank of Hungary (MNB) (license number: H-EN-I-1064/2013)

Outside the EU: No – Hungary

What does it do? Barion handles online payments in the Hungarian market. Providers can choose Barion as their payment service provider. Payment card data is handled directly by Barion – this data NEVER reach us.

Data processed by Barion:

  • Payment card details (card number, expiry, CVC)
  • Cardholder name
  • Email address (for Barion account)

What we see from Barion:

  • Transaction ID
  • Amount paid and currency
  • Payment date and status

OTP Mobil Kft. (SimplePay) – Online payment

Registered office: 1143 Budapest, Hungária krt. 17-19.

Company Registration Number: 01-09-174466

Website: simplepay.hu

Privacy notice: simplepay.hu/adatkezelesi-tajekoztatok

Certificates: PCI DSS Level 1

Outside the EU: No – Hungary

What does it do? SimplePay (OTP Mobil Kft.) is also an online payment solution in the Hungarian market. Providers can also choose SimplePay as their payment processor. Card data is handled directly by SimplePay.

Data processed by SimplePay:

  • Payment card details (card number, expiry, CVC)
  • Cardholder name
  • Email address

What we see from SimplePay:

  • Transaction ID
  • Amount paid and currency
  • Payment date and status

5.4. Billing Services

Billingo Technologies Zrt.

Registered office: 1085 Budapest, József körút 74. III/17.

Company Registration Number: 01-10-140802

Website: billingo.hu

Privacy notice: billingo.hu/adatkezelesi-tajekoztato

Outside the EU: No – Hungary

KBOSS.hu Kft. (Számlázz.hu)

Registered office: 1031 Budapest, Záhony utca 7.

Company Registration Number: 01-09-303201

Website: szamlazz.hu

Outside the EU: No – Hungary

What do they do? Online invoicing and data reporting to the NAV (Hungarian Tax Authority). Providers can choose which system to use.

What data do they have access to?

  • Invoice recipient's name
  • Billing address
  • Tax number (if any)
  • Name, quantity, and price of the purchased service
  • Payment method and date

Important: In accordance with Hungarian law, invoicing systems automatically forward invoice data to the NAV Online Invoice system.

5.5. SMS Service

LINK Mobility Hungary Kft. (SeeMe) – SMS sending

Registered office: 1062 Budapest, Andrássy út 68. Building C, 1st floor, 1.

Company Registration Number: 01-09-694287

Tax number: 12598582-2-42

Website: seeme.hu

Privacy notice: seeme.hu/adatvedelem

Outside the EU: No – Hungary

What does it do? SeeMe handles the sending of SMS notifications. Providers can enable SMS reminders for bookings, which the system sends via the SeeMe API.

Data managed by SeeMe:

  • Recipient's phone number
  • SMS message text (booking reminder, confirmation)
  • Send time and status

Important: SMS is only sent if the service provider has activated the SMS feature and the guest has provided their phone number. SMS messages can be transactional (booking confirmation, appointment reminder), or — at the service provider's discretion — marketing campaigns. Marketing SMS may only be sent with the recipient's prior, explicit consent (in accordance with Hungarian Act XLVIII of 2008 on commercial advertising activity), and every marketing SMS contains a unique, provider-specific unsubscribe link, with which the recipient can unsubscribe at any time, free of charge — exclusively from that particular provider's messages.

5.5.1. Platform marketing SMS to service providers. As the platform operator, AI Booking may occasionally send its own marketing or informational SMS messages to registered service providers (e.g. new features, promotions) at their provided phone number. Legal basis: the contractual relationship with the service provider, as well as the operator's legitimate interest (recommending its own, similar services); for natural person recipients — where the law requires it — based on prior consent. Every such SMS contains an unsubscribe link; unsubscribing is possible at any time, free of charge, and does not affect booking/system notifications. Delivery of these SMS messages is also carried out by LINK Mobility Hungary Kft. (SeeMe) as a processor.

5.6. Calendar and video conferencing integrations

Google LLC – Calendar, Meet, Analytics

Registered office: 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

European data controller: Google Ireland Limited, Dublin, Ireland

Privacy notice: policies.google.com/privacy

Outside the EU: Yes (USA) – Safeguard: SCC

Google Calendar integration:

  • When does it activate? If you (or the provider) enable calendar synchronization
  • What does it do? Bookings automatically appear in Google Calendar
  • What data is transferred? Booking time, service name, participants
  • Withdrawal: Can be disconnected anytime in account settings

Google Meet integration:

  • When does it activate? If the provider offers an online consultation option
  • What does it do? Automatically generates a meeting link that's included in the confirmation email
  • What data is transferred? Meeting link, time slot, and attendees' email addresses

Google Analytics 4:

  • When does it activate? If you have consented to analytics cookies
  • Where Do We Use It? Both on the landing page (aibooking.hu) and in the app
  • What does it do? Generates anonymous visitor statistics
  • Details: See the Cookie section

Zoom Video Communications Inc.

Registered office: 55 Almaden Boulevard, San Jose, CA 95113, USA

Website: zoom.us

Privacy notice: explore.zoom.us/en/privacy

Outside the EU: Yes (USA) – Safeguard: SCC

What does it do? Providers can connect their Zoom account to the system, so a meeting link is automatically generated for online consultations.

Important: With the Zoom integration, the provider uses the their own Zoom account. Amikor Ön részt vesz egy Zoom hívásban, a Zoom saját adatkezelési tájékoztatója vonatkozik a hívás során keletkező adatokra (videó, hang, chat).

5.7. Marketing and analytics

Meta Platforms Inc. (Facebook Pixel)

Registered office: 1 Hacker Way, Menlo Park, CA 94025, USA

European data controller: Meta Platforms Ireland Limited, Dublin, Ireland

Privacy notice: facebook.com/privacy/policy

Outside the EU: Yes (USA) – Safeguard: SCC

What does it do? If you have consented to marketing cookies, using the Facebook Pixel:

  • Measure the effectiveness of our Facebook ads
  • We can show you more relevant ads
  • We create statistics about visitors (in a non-identifiable way)

What data does it have access to?

  • That you visited our website
  • Which pages were viewed
  • Which actions were taken (e.g. registration, booking)
  • Technical data (browser, device)

Disabling: You can disable marketing cookies at any time in the cookie settings, and you can also limit targeted advertising in Facebook's ad settings.

5.8. Login providers (Social Login & Magic Link)

The AI Booking system uses the OAuth 2.0 protocol of the following third-party providers for login. These providers are involved only in the authentication process – the system does not get access to other data in the user's account (friends, messages, posts, etc.).

Google LLC – Google Login (OAuth 2.0 / OpenID Connect)

Registered office: 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA

European data controller: Google Ireland Limited, Dublin, Ireland

Privacy notice: policies.google.com/privacy

Outside the EU: Yes (USA) – Safeguard: EU-US DPF + SCCs

Data transferred: Name, email address, profile picture URL

Meta Platforms Inc. – Facebook Login

Registered office: 1 Hacker Way, Menlo Park, CA 94025, USA

European data controller: Meta Platforms Ireland Limited, Dublin, Ireland

Privacy notice: facebook.com/privacy/policy

Outside the EU: Yes (USA) – Safeguard: EU-US DPF + SCCs

Data transferred: Name, email address, profile picture URL

Apple Inc. – Sign in with Apple

Registered office: One Apple Park Way, Cupertino, CA 95014, USA

European data controller: Apple Distribution International Ltd., Cork, Ireland

Privacy notice: apple.com/legal/privacy

Outside the EU: Yes (USA) – Safeguard: EU-US DPF + SCCs

Data transferred: Name (optional), email address (real or Apple Private Relay address)

A unique feature of Apple login is that the user can decide whether to share their real email address or use a private relay address generated by Apple (e.g. xyz123@privaterelay.appleid.com). In both cases, the system works properly.

Microsoft Corporation – Microsoft Login

Registered office: One Microsoft Way, Redmond, WA 98052, USA

European data controller: Microsoft Ireland Operations Limited, Dublin, Ireland

Privacy notice: privacy.microsoft.com

Outside the EU: Yes (USA) – Safeguard: EU-US DPF + SCCs

Data transferred: Name, email address, profile picture URL

GitHub Inc. – GitHub Login

Registered office: 88 Colin P Kelly Jr St, San Francisco, CA 94107, USA

Parent company: Microsoft Corporation

Privacy notice: docs.github.com/privacy

Outside the EU: Yes (USA) – Safeguard: EU-US DPF + SCCs

Data transferred: Username, email address, profile picture URL

Magic Link – Passwordless login

How it works: The user enters their email address, and the system sends a one-time, time-limited login link.

Email sending: Through AI Booking's own SMTP configuration (see SendGrid / Hostinger Email in the sections above)

Token validity: Maximum 15 minutes, single use

Stored data: Only the email address. The token is automatically deleted after use or expiration.

6. Legal bases for data processing – Why may we process your data?

GDPR Article 6(1)

Under the GDPR, we may only process personal data if there is an appropriate our legal basis. A jogalap az a törvényes indok, amely feljogosít minket az adatkezelésre. Az alábbiakban részletesen bemutatjuk, milyen jogalapokat használunk.

6.1. Consent – GDPR Art. 6(1)(a)

What does it mean? You have actively and voluntarily consented to the data processing. The consent must be specific, informed, and unambiguous.

When do we use this legal basis?

Data processing activityHow do you give your consent?How can you withdraw it?
Newsletter, marketing emails Subscription via form or at registration Unsubscribe link at the bottom of the email, or account settings
Upload profile picture Selecting and uploading an image Remove photo from profile
Analytics cookies (GA4) Cookie banner acceptance Modify cookie settings
Marketing cookies (Facebook) Cookie banner acceptance Modify cookie settings
Google Calendar sync Enabling the integration in settings Disconnect integration

About withdrawing consent

Ön anytime, without justification may withdraw their consent — just as easily as they gave it. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. For example: if you unsubscribe from the newsletter, we can't "undo" previously sent emails, but we won't send any more.

6.2. Performance of a contract – GDPR Article 6(1)(b)

What does it mean? The data processing is necessary for us to fulfil the contract concluded with you, or to take pre-contractual steps at your request.

When do we use this legal basis?

  • Registration: Data required to create an account (name, email, password)
  • Booking: Data required to record and fulfill the booking
  • Confirmations and reminders: These are part of the service
  • Payment: Data required to process the transaction
  • Customer Service: To help resolve issues

Practical example

Situation: You are booking an appointment with a hairdresser.

Contract: By booking, a contract is formed between you and the provider (an agreement on the provision of the service).

Required data:

  • Their name – so the hairdresser knows who to expect
  • Email address – so we can send the confirmation
  • Phone number – so we can reach you if something changes
  • Time — so we know when they're coming

Without these we cannot fulfill the contract – meaning we cannot guarantee that the booking will work.

6.3. Legal obligation – GDPR Article 6(1)(c)

What does it mean? Data processing is necessary to fulfill a legal obligation. In such cases we have no choice – the law requires us to process this data.

When do we use this legal basis?

Legal obligationLegislationData concerned
Invoice retention Számv. tv. 169. § (2) Invoices, billing data – for 8 years
NAV data reporting VAT Act Automatic forwarding of invoice data
Authority Request Criminal Procedure Act, etc. Data requested based on a court order

Important: We cannot delete this data

If you request deletion of your account, we will do so – but data required by law (e.g. invoices) must be retained. We are legally obliged to do this and have no other choice.

6.4. Legitimate interest – GDPR Art. 6(1)(f)

What does it mean? The processing is necessary for the purposes of the legitimate interests pursued by us (or a third party), except where such interests are overridden by your interests, rights and freedoms.

This legal basis legitimate interest assessment requires: in every case we must weigh whether our interest or your rights take precedence. We may only use it if our interest does not override your fundamental rights.

When do we use this legal basis?

Legitimate interestData concernedWhy doesn't it override your rights?
IT security IP address, browser, login attempts Protecting your account and data is in our interest too; minimal data collection (90 days)
Fraud Prevention Logging of suspicious activities Fraud affects other users too; we investigate only in suspicious cases
Service development Aggregated, anonymized usage statistics Non-identifiable personal data; results in a better service for everyone
Enforcement of legal claims Contractual data, communication In case of a dispute, both parties have an interest in preserving evidence

Can I object to data processing based on legitimate interest?

Yes! Under Article 21 of the GDPR, you may object to data processing based on legitimate interest. In this case, we must examine whether our legitimate interest overrides your interest. If not, we must cease the processing.

7. Data processed in detail — What data exactly do we process?

GDPR Article 13(1)(e) and Article 14(1)(d) – Information obligation regarding the categories of data processed

Below we present in detail what personal data the AI Booking system processes, for what purpose, and on what legal basis. We only collect data that is strictly necessary for providing the service.

7.1. Registration and account data

When are they generated? When you create an account in the AI Booking system.

DataGoalLegal basisRetention
Full name Identification, greeting, booking confirmation Contract (6.1.b) Until account deletion + 60 days
Email address Login, confirmations, reminders, password reset Contract (6.1.b) Until account deletion + 60 days
Phone number Contact and SMS reminders (if enabled) Contract (6.1.b) Until account deletion + 60 days
Password (hash) Account protection – we store passwords only as bcrypt hashes; we can't see them either Contract (6.1.b) Until account deletion
Profile picture Visual identification in the system Consent (6.1.a) Until the image or account is deleted
Language setting Displaying the interface in the selected language Contract (6.1.b) Until account deletion

7.2. Booking Data

When are they generated? When you book an appointment with a service provider.

DataGoalLegal basisRetention
Booking date and time Appointment booking, calendar sync Contract (6.1.b) 3 years
Selected service The provider knows which service to prepare for Contract (6.1.b) 3 years
Selected provider/staff member The booking should be assigned to the right person Contract (6.1.b) 3 years
Note (optional) Sharing special requests or important information with the provider Consent (6.1.a) 3 years
Booking status Confirmed, cancelled, completed – tracking the process Contract (6.1.b) 3 years

Comment field — Please do not enter sensitive data!

In the booking notes field do not write special (sensitive) data (e.g. health information, allergies). If this is done nonetheless, responsibility for that the service provider is responsible as an independent data controller, not the AI Booking system.

7.3. Payment data

When are they generated? When you pay online for a service, or the provider purchases a subscription.

DataGoalWho stores it?Retention
Full card number, expiry date, CVC Payment processing Exclusively Stripe – we NEVER see it According to Stripe's own policy
Transaction ID Payment tracking and complaint handling AI Booking + Stripe 8 years (Accounting Act)
Amount paid, currency Invoicing and financial record-keeping AI Booking 8 years (Accounting Act)
Last 4 digits of the card, type Identifying the payment method for the user AI Booking 8 years (Accounting Act)
Billing name and address Invoice issuance (statutory obligation) AI Booking + Billingo/Számlázz.hu 8 years (Accounting Act)

7.4. Technical and security data

When are they generated? Automatically, every time you use the website or the app.

DataGoalLegal basisRetention
IP address Security logging, abuse prevention, geographic region determination Legitimate interest (6.1.f) 90 days
Browser type, version Ensuring compatibility, troubleshooting Legitimate interest (6.1.f) 90 days
Operating system Ensuring compatibility, troubleshooting Legitimate interest (6.1.f) 90 days
Login log Account security – detecting suspicious logins Legitimate interest (6.1.f) 1 year
Referring page (referrer) Where the visitor came from (search engine, ad, etc.) Legitimate interest (6.1.f) 90 days

7.5. Notification settings

DataGoalLegal basisRetention
Email notification preferences What type of emails would you like to receive (booking, reminder, marketing) Consent (6.1.a) / Contract (6.1.b) Until account deletion
SMS notification preferences Turn SMS reminders on/off Consent (6.1.a) Until account deletion
Newsletter subscription status Handling marketing communications (Section 6 of the Hungarian Advertising Act) Consent (6.1.a) After unsubscribing, we retain the fact of consent for 5 years (as evidence)

7.6. Data for social login and passwordless sign-in

When are they generated? If you register or log in to AI Booking using one of the following third-party providers: Google, Facebook, Apple, Microsoft, GitHub, or if Magic Link uses a passwordless login link sent by email.

DataWhere Does It Come From?GoalRetention
Social account identifier (ID) Google / Facebook / Apple / Microsoft / GitHub Account linking, sign-in Until account deletion or disconnection
Public name Google / Facebook / Apple / Microsoft / GitHub Automatic profile filling Until account deletion
Email address Google / Facebook / Apple / Microsoft / GitHub / Magic Link Account identification, sending notifications Until account deletion
Profile picture URL Google / Facebook / Microsoft / GitHub Profile picture display (we don't store it, only reference it) Until disconnection
Magic Link token AI Booking system (SMTP) Generating and verifying a passwordless, one-time login link It is automatically deleted after use or after 15 minutes

Available login methods

Service providerTypeTransferred data
Google OAuth 2.0 (OpenID Connect) Name, email, profile picture URL
Facebook OAuth 2.0 (Meta Login) Name, email, profile picture URL
Apple Sign in with Apple (OAuth 2.0) Name (optional), email (real or Apple Private Relay)
Microsoft OAuth 2.0 (Microsoft Identity Platform) Name, email, profile picture URL
GitHub OAuth 2.0 (GitHub Apps) Username, email, profile picture URL
Magic Link Email-based, passwordless authentication Email address (a one-time link sent via SMTP)

Important about social login

When using social login We NEVER get access to your password, contacts, messages, posts, or any other data not necessary for login. We only request the minimally necessary data listed above — this applies equally to every provider (Google, Facebook, Apple, Microsoft, GitHub).

Social login can be disconnected at any time in the account settings — the account then switches to email + password or Magic Link sign-in.

Apple Private Relay email: With Apple login, the user can choose to share their real email address or an Apple-generated private relay address. The system works correctly either way.

7.7. Provider (business) account data

Who does this apply to? To users who register as service providers (e.g. hairdresser, massage therapist, trainer) and use AI Booking for business purposes.

DataGoalLegal basisRetention
Business name Display on the booking page Contract (6.1.b) Until account deletion + 60 days
Tax number Invoicing (legal obligation) Legal obligation (6.1.c) 8 years (Accounting Act)
Business address Display on the booking page, map navigation Contract (6.1.b) Until account deletion + 60 days
List of services, prices Displaying booking options to guests Contract (6.1.b) Until account deletion + 60 days
Opening hours Defining available appointment times Contract (6.1.b) Until account deletion
Gallery images Portfolio showcase on the booking page (Cloudflare R2 storage) Consent (6.1.a) Until the image or account is deleted

7.8. Staff Data

Who does this apply to? To those individuals whom a provider adds to their system as a team member (e.g., an employed hairdresser, assistant).

DataGoalLegal basisRetention
Staff member's name Displayed in the booking system, informing guests Legitimate interest (6.1.f) Until the team member is removed
Team member's email address Notifications about the team member's bookings Legitimate interest (6.1.f) Until the team member is removed
Work schedule Display of bookable time slots in the staff member's calendar Legitimate interest (6.1.f) Until the team member is removed
Assigned services Defines which services you can accept bookings for Legitimate interest (6.1.f) Until the team member is removed

Important about staff data

For adding staff members and managing their data, the the given provider is responsible as data controller. The provider is obliged to inform their staff that their data will also appear in the AI Booking system. We (Imre Dobó, sole trader) act as data processor in this case.

Summary – Overview of data categories

Data categoryLegal basisRetention
Registration data Contract Account deletion + 60 days
Booking data Contract 3 years
Payment / billing data Legal obligation 8 years
Technical logs Legitimate interest 90 days
Notification settings Consent / Contract Until account deletion
Social login data Consent Until disconnection / account deletion
Provider business data Contract Account deletion + 60 days
Staff data Legitimate interest Until the team member is removed

8. Cookies

Eker tv. Section 13/A (4)-(5), GDPR Article 6(1)(a) and (f)

Cookies are small text files that a website stores on your device (computer, phone, tablet). They help the website "remember" you and your settings.

8.1. Types and Purpose of Cookies

Strictly necessary cookies (cannot be disabled)

Legal basis: GDPR Art. 6(1)(f) – Legitimate interest

These cookies are essential for the basic operation of the website. Without them you would not be able to log in, book, or use the site securely.

Cookie namePurposeExpirationType
session_id Maintaining your login state so you don't have to log in again on every page When the browser is closed, or 24 hours Session
csrf_token Cross-Site Request Forgery protection – prevents malicious sites from sending requests on your behalf At the end of the session Security
cookie_consent Storing your cookie preferences, so we don't have to ask you again on every visit 1 year Setup
locale Language setting (Hungarian) 1 year Setup
__cf_bm Cloudflare bot detection – distinguishes humans from automated programs 30 minutes Security

Analytics cookies (with consent)

Legal basis: GDPR Art. 6(1)(a) – Consent

These cookies help us understand how visitors use our website. We use this data to improve the user experience. We use Google Analytics 4 both on the landing page (aibooking.hu) and within the application.

CookieService providerGoalExpiration
_ga Google Analytics 4 Distinguishing unique visitors (random ID, not personally identifying) 2 years
_ga_* Google Analytics 4 Storing session state 2 years
_gid Google Analytics 4 Counting daily unique visitors 24 hours

What do we see in Google Analytics?

  • How many visitors do we have (daily, weekly, monthly)
  • Which pages are the most popular
  • Where visitors come from (direct, search engines, social media)
  • Which devices they browse from (mobile, tablet, desktop)
  • Which countries/cities they come from
  • How much time visitors spend on the site
  • Where visitors leave the page (bounce rate)

What we DON'T see?

  • Your name, email address, or any personally identifiable data
  • Your exact home address
  • The content of the forms you have filled in

Marketing cookies (with consent)

Legal basis: GDPR Art. 6(1)(a) – Consent

These cookies allow us to display our ads in a targeted way and measure their effectiveness.

CookieService providerGoalExpiration
_fbp Meta (Facebook) Identifying visitors for Facebook ad targeting and measurement 90 days
_fbc Meta (Facebook) Tracking clicks coming from Facebook ads 90 days
fr Meta (Facebook) Ad targeting and measurement 90 days

What does this mean in practice?

If you have consented to marketing cookies and visited the AI Booking website:

  • Facebook "remembers" that you visited us
  • Later, when scrolling on Facebook or Instagram, you may see an AI Booking ad
  • We see how many people clicked our ad and how many registered
  • We can't see that you specifically clicked — only aggregated numbers

If this bothers you: You can disable marketing cookies in the settings, and also restrict targeted ads in Facebook's ad settings.

8.2. Managing cookies – How can you decide?

1. Cookie banner:

On your first visit to the site, a banner appears where you can choose:

  • "Accept all" — allows all cookie types
  • "Necessary only" – allows only the cookies essential for operation
  • "Settings" — you can decide on each category individually

2. Changing cookie settings later:

You can change your decision at any time by clicking the "Cookie settings" link at the bottom of the page.

3. Browser settings:

You can also manage cookies in your browser:

Browser cookie settings

  • Google Chrome: support.google.com/chrome/answer/95647
  • Mozilla Firefox: support.mozilla.org/hu/kb/sutik
  • Safari: support.apple.com/safari
  • Microsoft Edge: support.microsoft.com/edge

Attention

If you disable all cookies in your browser, some functions of the website will not work (e.g. you won't be able to log in, or you'll have to log in again on every page).

9. Retention periods – How long do we store your data?

GDPR Art. 5(1)(e) – storage limitation principle, GDPR Art. 13(2)(a)

GDPR requires that personal data be stored only as long as the purpose of the processing requires. Below we specify exactly how long each category of data is retained, and what happens afterward.

9.1. Overview of retention periods

Data categoryRetention periodLegal Basis / ReasonWhat happens next?
Account data (name, email, phone, password hash) Until account deletion + 60 days Contract (6.1.b) – the 60 days is protection against accidental deletion Final, irreversible deletion
Booking history 3 years Legitimate interest (6.1.f) – handling complaints and legal disputes (Civil Code limitation period) Automatic anonymization (for statistical purposes)
Billing details (name, address, tax number, amount) 8 years Legal obligation (6.1.c) – Accounting Act Section 169(2) Permanent deletion
Payment transactions (transaction ID, amount, status) 8 years Legal obligation (6.1.c) – Accounting Act Section 169(2) Permanent deletion
Technical logs (IP, browser, referrer) 90 days Legitimate interest (6.1.f) – investigation of security incidents Automatic deletion
Login log 1 year Legitimate interest (Art. 6(1)(f)) – retrospective investigation of suspicious logins Automatic deletion
Cookie data Varies by cookie (see Chapter 8) Consent (6.1.a) / Legitimate interest (6.1.f) Automatic expiration
Fact of marketing consent After unsubscribing 5 years Legitimate interest (6.1.f) – proof that consent was given (Grt. Section 6) Permanent deletion
Notification settings Until account deletion Consent (6.1.a) / Contract (6.1.b) Deleted together with the account
Social login linking Until disconnection or account deletion Consent (6.1.a) Immediate deletion upon disconnection
Provider gallery images Until the image or account is deleted Consent (6.1.a) It is also deleted from Cloudflare R2
Staff data Until the team member is removed Legitimate interest (6.1.f) Immediate Deletion

9.2. Account Deletion Process

Account deletion happens in three steps:

StepAppointmentWhat happens?
1. Deletion request day 0 Account deactivation – login is not possible, data is not public, booking is not possible
2. Restoration Period 1–60. nap If you change your mind, you can request account restoration – all data remains intact
3. Final deletion day 61 All personal data is irreversibly deleted (except data that must be retained by law, e.g. invoicing – 8 years)

Important regarding retention periods

Certain data must be retained even after account deletion, based on legal obligation:

  • Billing data (8 years): Pursuant to Section 169(2) of Act C of 2000 (Accounting Act), accounting documents must be retained for 8 years
  • VAT data (8 years): Under Act CXXVII of 2007 (VAT Act), VAT documents must be retained for 8 years.
  • Fact of marketing consent (5 years): Proof that the marketing outreach was carried out lawfully (Section 6 of the Hungarian Advertising Act)

We automatically and permanently delete this data once the retention period expires.

10. Data Security – How do we protect your data?

GDPR Article 32 – Security of processing, GDPR Article 25 – Data protection by design and by default

Data protection is not just our legal obligation, but also our technical responsibility. In the AI Booking system we apply multi-layered security measures that meet the security level "appropriate to the risk" required by Article 32 of the GDPR.

10.1. Encryption

MeasureDetailsWhat does it protect?
TLS/SSL encryption All communication takes place over HTTPS (TLS 1.2 or newer). Certificates are renewed automatically. Protection against eavesdropping — data cannot be read in transit
Password hashing Bcrypt algorithm, with salt. Not even we can see your password – we only store the hash. Protection against password theft – cannot be decrypted even in a data breach
Database encryption The server's storage disks are encrypted (at-rest encryption). Against physical access – if the disk were stolen, the data would be unreadable

10.2. Access protection

MeasureDetailsWhat does it protect?
Role-based access control (RBAC) Admin, provider, staff member, guest – everyone only sees the data appropriate to their own permission level. Against unauthorized access
Two-factor authentication (2FA) Available/recommended for provider accounts – TOTP app (e.g. Google Authenticator) or email-based code Against password theft – the password alone is not enough to log in
Session management Sessions automatically expire after inactivity. Simultaneous login from multiple devices is also supported. Against forgotten logins (e.g. on a shared computer)
Admin access log Every system administrator action is logged (who, what, when) Against internal misuse

10.3. Protection against attacks

MeasureDetailsWhat does it protect?
Rate limiting Limiting login attempts – temporary lockout after too many failed attempts Against brute-force attacks
CSRF protection Every form includes a unique token that prevents request forgery Against forged requests (e.g. cancellation initiated from another site)
XSS protection Sanitization of input data, Content Security Policy (CSP) headers Against malicious code injection
Cloudflare WAF Web Application Firewall – automatically filters suspicious traffic and DDoS attacks Against web attacks and denial-of-service attacks
SQL injection protection Parameterized queries, ORM usage — user input never goes directly into the database query Against database breaches

10.4. Backup and recovery

MeasureDetails
Regular backups Daily automatic backup — database and files. Backups are encrypted and stored in a geographically separate location.
Point-in-time recovery Database restore is possible to any point in time within the last 30 days
Save & test Regular restore tests to ensure that backups actually work

10.5. Organizational measures

MeasureDetails
Principle of minimization We only collect and process the data strictly necessary (GDPR Article 5(1)(c) – data minimization).
Access restriction Personal data may only be accessed by the data controller (Dobó Imre E.V.) and the necessary systems of the data processors
Data processing agreements A written data processing agreement (DPA) is in effect with every data processor (Hostinger, Stripe, Cloudflare, etc.)
Updates and maintenance The server and application are regularly updated with security patches

10.6. Handling of data protection incidents

What happens in the event of a data breach?

If a security incident affecting your personal data occurs (e.g. data breach, unauthorized access), we will proceed as follows regarding the GDPR Article 33-34 in accordance with its requirements:

StepDeadlineTo-do
1. Detection and assessment Instantly Assessment of the nature, extent and risks of the incident
2. Regulatory Notification within 72 hours Notification to NAIH if the incident poses a risk to the rights of data subjects (GDPR Article 33)
3. Notifying data subjects Without undue delay If the incident high risk occurs, we will notify the affected parties by email (GDPR Article 34)
4. Damage Prevention Instantly Technical measures to reduce the damage (e.g. forcing a password reset, locking access)
5. Documentation Continuous Full documentation of the incident in the register (GDPR Art. 33(5))

In summary

In the AI Booking system, data protection is "privacy by design" (privacy by design) and the "privacy by default" (privacy by default) principles. This means data protection is not an afterthought, but a fundamental element of the system's design.

11. Your rights – How can you control your data?

GDPR Art. 15-22, Hungarian Info Act §14-21

The GDPR grants you extensive rights over your personal data. Below we present these rights in detail and how you can exercise them within the AI Booking system.

11.1. Right of access (GDPR Article 15)

What does it mean? You have the right to receive confirmation from us as to whether we process your personal data, and if so, the right to access that data, as well as the following information:

  • Purposes of data processing
  • Categories of data processed
  • Who has received or will receive the data (recipients)
  • Planned data retention period
  • Information about your further rights
  • If the data does not come from you, its source is

How can you exercise it?

  • Self-service: Under Account settings → "My Data" you can view most of the data we store
  • Written request: Write to and within 30 days we will send you a copy of all data stored about you in a machine-readable format (JSON or CSV)

11.2. Right to rectification (GDPR Art. 16)

What does it mean? You have the right to request, without undue delay, the correction of your inaccurate personal data, or the completion of incomplete data.

How can you exercise it?

  • Self-service: You can directly update your name, phone number, email address, and other details in the profile settings.
  • Written request: If the data cannot be modified in the system, write to us – within 15 days we will correct it

11.3. Right to erasure – "The right to be forgotten" (GDPR Art. 17)

What does it mean? You have the right to request that we erase your personal data without undue delay, if one of the following conditions applies:

  • The data is no longer needed for the purpose for which it was collected
  • You withdraw your consent, and there is no other legal basis for processing
  • You object to the processing, and there is no overriding legitimate ground
  • The data was processed unlawfully
  • The data must be deleted to fulfill a legal obligation

When can we NOT delete your data?

The right to erasure cannot be exercised if the processing is necessary:

  • To fulfill a legal obligation: E.g. invoicing data — we must retain it for 8 years (Accounting Act Section 169)
  • To assert or defend legal claims: E.g. in case of an ongoing legal dispute
  • For public interest archiving: If required by law

How can you exercise it?

  • Account deletion: Account Settings → "Delete Account" button → 60-day recovery period → permanent deletion
  • Written request: Write to the address – within 30 days we fulfill

11.4. The right to restriction of processing (GDPR Article 18)

What does it mean? You may request that we not delete your data but temporarily "freeze" it — meaning we don't actively process it. This is useful if:

  • You dispute the accuracy of the data – until we verify it, the data is restricted
  • The processing is unlawful, but you request restriction instead of deletion
  • We no longer need the data, but you need it to enforce a legal claim
  • You have objected to the data processing – while we assess whether the objection is justified

During the period of restriction, the data we only store, but we do not actively process it (we do not forward or use it), except with your consent or to enforce legal claims.

11.5. Right to data portability (GDPR Article 20)

What does it mean? You have the right to receive your personal data in a structured, widely used, machine-readable format receives, and to transmit them to another data controller.

In what format can we export it?

  • JSON – machine-readable structured format
  • CSV – a format that can be opened with spreadsheet apps

What data does this apply to? Only to those you have provided us with, based on consent or contract:

  • Registration data (name, email, phone)
  • Booking history
  • Notification settings

How can you exercise it?

Write to the address – within 30 days we will send the data in the requested format.

11.6. Right to object (GDPR Article 21)

What does it mean? You are entitled to object at any time against the processing of your personal data based on legitimate interest. In such cases, we must examine whether our legitimate interest overrides yours.

In particular, you may object to the following:

  • Direct marketing: If you object, instantly we must stop marketing-related data processing — no discretion involved
  • Logging based on legitimate interest: We review security logging, but for security reasons we cannot always discontinue it
  • Data processing for statistical purposes: Does not apply to aggregated, anonymized data (as it is not personal data)

11.7. Protection against automated decision-making (GDPR Article 22)

What does it mean? You have the right not to be subject to a decision based solely on automated processing – including profiling – which produces legal effects concerning you or similarly significantly affects you.

AI Booking does NOT apply automated decision-making

We do not make decisions about your personal data based solely on automated processing. We do not reject bookings, change prices, or restrict access based on automated systems. All such decisions are made by a human.

Summary of rights exercise

RightGDPR articleHow?Deadline
Access Article 15 Account settings / email 30 days
Rectification Article 16 Profile settings / email 15 days
Delete Article 17 Account deletion / email 30 days
Restriction Article 18 Email request 30 days
Data portability Article 20 Email request (JSON/CSV) 30 days
Objection Article 21 Email / unsubscribe link Immediate (direct marketing) / 30 days
Against automated decision- Article 22 Not applied — not relevant –

Important information for exercising your rights

  • Free: A kérelmek teljesítése ingyenes. Ha a kérelem nyilvánvalóan megalapozatlan vagy – különösen ismétlődő jellege miatt – túlzó, ésszerű díjat számíthatunk fel, vagy megtagadhatjuk a kérelem teljesítését.
  • Identification: Before fulfilling the request, we must verify your identity. This is usually done via a request sent from the registered email address.
  • Deadline extension: In particularly complex cases, the 30-day deadline may be extended by up to 2 months — you will be informed of this within the original deadline.
  • Rejection: If we are unable to fulfill the request, we will provide a reasoned response and inform you of the available remedies.

12. Remedies – Where can you file a complaint?

GDPR Art. 77-79, Hungarian Info Act §22-23

If you feel your rights regarding the processing of your personal data have been violated, several remedies are available to you. We recommend that you contact us directly first — we can resolve most issues quickly.

12.1. Direct contact — Reach out to us first!

Get in touch with us

Most data protection questions and complaints quickly and directly we can resolve it. Write to us:

  • Email: info@aibooking.hu
  • Response time: General inquiry – within 15 days, request to exercise rights – within 30 days

Please state in your request the your registered email address, so we can identify you — this speeds up the process.

12.2. Complaint to the authority – NAIH

What is the NAIH? The National Authority for Data Protection and Freedom of Information is Hungary's independent data protection supervisory authority, which anyone can contact free of charge with a data protection complaint.

DataContact
Full name Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Registered office 1055 Budapest, Falk Miksa utca 9-11.
Mailing address 1363 Budapest, P.O. Box 9.
Phone +36 (1) 391-1400
Email
Website www.naih.hu

The procedure of the NAIH (Hungarian Data Protection Authority)

  • Filing a complaint: In writing (letter, email) or via the NAIH online form
  • Fee: The procedure free
  • Review: The NAIH investigates the complaint and informs you of the outcome
  • Action: If it finds a violation, it may call on us to modify or suspend the data processing, or impose a fine

12.3. Legal recourse

If neither direct contact nor the NAIH procedure has brought the desired result, you are entitled to go to court.

QuestionAnswer
Which court can I turn to? to the court competent for your place of residence or stay, OR to the Debrecen Regional Court based on the data controller's registered seat (GDPR Art. 79, Infotv. Section 23)
What can I ask for? Establishing the lawfulness of the data processing, terminating the data processing, restoring the data, and compensation for damages (Ptk. 2:52. §)
Who bears the burden of proof? It is the data controller (us) who must prove that the processing was lawful (GDPR Article 5(2) – accountability principle)
Does It Cost Money? The procedure is exempt from fees (Infotv. Section 23(5))

12.4. Summary of legal remedies

OptionWhen is it worth it?CostExpected time
1. Direct contact Always the first step — we can resolve most issues Free 15-30 nap
2. NAIH complaint If a direct inquiry did not resolve the issue Free 2-6 months
3. Court Action If you wish to claim damages, or if you disagree with the NAIH's decision Duty-free 6-18 months

Important

The legal remedies are independent of each other regardless can also be used — you don't need to exhaust one path before choosing the other. Of course, we recommend that you contact us directly first.

13. Provider Features – Data Protection on the Provider Side

GDPR Article 26 – Joint Controllers, GDPR Article 28 – Processor

AI Booking is a multi-actor system: service providers (hairdresser, beautician, trainer, etc.) use the system as part of their own business, and they themselves become data controllers with regard to their guests' data. This chapter presents the data protection aspects of this.

13.1. Who is the data controller for provider-side operations?

Roles in the multi-user system

In the provider-guest relationship, the data processing roles are divided as follows:

ActionData ControllerData processor
Guest registers with AI Booking Dobó Imre E.V. (AI Booking) –
A guest books with a provider The provider (e.g. "Beauty Salon Ltd.") Imre Dobó, sole proprietor (AI Booking as a platform)
Provider adds a staff member the service provider Imre Dobó, sole proprietor (AI Booking as a platform)
The provider views statistics about their guests the service provider Imre Dobó, sole proprietor (AI Booking as a platform)
The Provider subscribes to AI Booking Dobó Imre E.V. (AI Booking) Stripe (payment), Billingo (invoicing)
AI Booking sends a reminder email to the guest The provider (on a commission basis) Dobó Imre E.V. + SendGrid

13.2. Data Processing Agreement (DPA)

What is a DPA? The Data Processing Agreement is a mandatory contract between the data controller (the service provider) and the data processor (AI Booking) that governs how the data processor handles personal data on the data controller's behalf.

When a provider registers and actively uses the AI Booking system, the General Terms and Conditions (GTC) by accepting this, you simultaneously accept the AI Booking Data Processing Agreement, which sets out:

  • The subject, duration, nature and purpose of the data processing
  • The types of personal data processed and the categories of data subjects
  • The rights and obligations of the data controller (provider)
  • The obligations of the data processor (AI Booking), including:
    • Acts solely according to the service provider's instructions
    • Ensures that persons with access are bound by confidentiality
    • Implements security measures under GDPR Article 32
    • If a sub-processor is engaged, the provider will be informed
    • Helps the provider fulfill data subjects' rights
    • Deletes the data after the agreement terminates

13.3. The provider's own obligations

Important for every service provider!

By using AI Booking, the provider an independent data controller in respect of your guests' personal data. This means the following:

ObligationWhat does this mean in practice?Need help?
Our own data protection notice The service provider must have its own privacy notice, referencing the use of AI Booking as a data processor Yes – we provide a template
Fulfillment of data subject rights If a guest contacts the provider (e.g. a cancellation request), the provider is responsible for fulfilling it — we provide technical support Yes – the system supports it
Informing employees The service provider is required to inform added staff members that their data will appear in the AI Booking system Yes – automatic notification email
Data minimization The provider should not request sensitive data (health, biometric, etc.) in the comment field. Yes – a warning message appears at the comment field
Reporting a data breach If the provider becomes aware that their guests' data has been compromised, they are required to report it to the NAIH (within 72 hours) Yes – we notify the provider if an incident occurs affecting our system

13.4. Provider data export and account deletion

What happens if a service provider leaves the AI Booking platform?

ActionDetailsDeadline
Data export The service provider may request an export of the guest's booking data in CSV or JSON format — under the right to data portability within 30 days
Account deactivation The provider profile disappears from search, new bookings are no longer possible, and existing bookings are closed out. Instantly
Recovery period Account restoration can be requested for 60 days – all data remains intact 60 days
Permanent deletion The provider's personal data and guest-related bookings remain anonymized (for statistics), while the rest of the data is deleted from day 61

Important regarding guest data upon account deletion

Deleting the provider's account does not delete guests' accounts. A vendégek továbbra is rendelkeznek AI Booking-fiókkal, és más szolgáltatóknál továbbra is foglalhatnak. A korábbi foglalási előzmények anonimizálva megmaradnak (a szolgáltató neve nélkül), hogy a vendég láthassa saját foglalási történetét.

13.5. Sub-processors for service provider functions

When AI Booking acts as a data processor on behalf of a provider, it uses the following sub-processors:

Sub-processorGoalLocation of data transfer
Hostinger Server, database storage EU (Netherlands)
Cloudflare CDN, image storage (R2), WAF EU / global network
SendGrid (Twilio) Sending booking confirmations and reminders USA (with EU SCC guarantees)
Google Google Calendar sync, Google Meet video calls EU / USA (with EU SCC guarantees)
Stripe Online payment processing EU (through an Irish entity)

Providers about changes to the list of sub-processors we will notify you in advance, and we provide the opportunity to object under Article 28(2) of the GDPR.

In summary

AI Booking and the providers they cooperate in the field of data protection. We provide the technical infrastructure and the GDPR-compatible system, while providers are responsible for informing their own guests and complying with data handling rules. We support all this with templates, automations, and guides.

14. Frequently Asked Questions (FAQ)

How do I delete my account and all my data?

Answer: You'll find the "Delete account" option in account settings. After deletion, the account can still be restored for 60 days (in case you change your mind), after which it's permanently deleted. Important: by law we must keep billing data for 8 years, so that cannot be deleted.

How can I find out what data is stored about me?

Answer: You have two options:

  1. Under Account Settings, in the "My Data" menu, you can view most of your data
  2. Write to us at , and within 30 days we will send you a copy of all data stored about you

Why am I still receiving emails after unsubscribing from the newsletter?

Answer: Unsubscribing from the newsletter only affects marketing emails. You will still receive transactional emails (booking confirmation, reminders, password reset) because they are necessary for the service to function. If you don't want any emails at all, you need to delete your account.

Is my credit card data safe?

Answer: Yes! We NEVER see or store the full card number, expiry date, or CVC code. Payments are handled by Stripe, which holds PCI DSS Level 1 certification (the highest security level). We only see the transaction ID and the last 4 digits of the card.

Who can see my bookings?

Answer:

  • Ön – in your own account
  • the service provider – the party they booked with (and their staff, if any)
  • We (AI Booking) – for technical reasons and customer support

Other users, other providers, or third parties CANNOT see your bookings.

What happens to my data if the service provider closes their account?

Answer: If a provider deletes their account from the AI Booking system:

  • Your account and data related to AI Booking will be retained
  • Previous bookings with the deleted provider are archived (but not deleted, due to accounting law requirements)
  • You cannot create more bookings for the given provider

How can I turn off Facebook ads?

Answer: In two steps:

  1. On the AI Booking site: Cookie Settings → Turn off marketing cookies
  2. On Facebook: Settings → Ads → Ad Preferences → Restrict

Where can I turn if I am not satisfied with the data handling?

Answer: You have three options:

  1. Contact us: – in most cases we can solve it
  2. Complaint to NAIH: www.naih.hu – the Hungarian data protection authority
  3. Court: If you suffered damage, you may claim compensation

Do they use artificial intelligence to analyze my data?

Answer: We do not use AI to analyze your personal data, build profiles, or make automated decisions. The AI Booking system serves solely to simplify appointment scheduling.

15. Contact

If you have any questions, comments, or requests regarding this notice or our data processing, please feel free to contact us at the following:

Our Contact Details

Data Controller: Dobó Imre, sole trader
Email: info@aibooking.hu
Phone: +36 30 609 5404
Postal address: 4029 Debrecen, Hajnal utca 14. 2/13
Website: www.aibooking.hu
Client hours: Monday-Friday 9:00 AM-5:00 PM (CET)

Response times

Request typeResponse time
General questions Within 5 business days
Access request (GDPR Article 15) within 30 days
Erasure request (GDPR Article 17) within 30 days
Data portability (GDPR Article 20) within 30 days
Rectification request within 15 days

16. Protection of Minors

Age Limit: 16 Years

The AI Booking service is not intended for persons under 16 years of age. A GDPR 8. cikke és az Infotv. alapján Magyarországon a 16. életévét be nem töltött személy hozzájárulása csak a szülői felügyeleti jogot gyakorló személy jóváhagyásával érvényes.

16.1. How do we handle this?

  • Registration: During the registration process, the user must confirm that they have reached the age of 16
  • Booking: Only persons over 16 years of age may initiate a booking
  • Provider account: A service provider account may only be created by a natural person over 18 with legal capacity, or a legal entity

16.2. What happens if we identify data belonging to a minor?

If we become aware that a person under 16 has registered in the system without parental consent:

  1. Immediate account suspension – account use will be temporarily restricted
  2. Notification – we will attempt to contact the parent/guardian
  3. Delete – if parental consent is not received within 30 days, we permanently delete the account and all related personal data

Parental notification: If you are a parent or guardian and believe your child has registered without your knowledge, please let us know:

17. Data Protection Officer (DPO)

Under Article 37 of the GDPR, appointing a data protection officer is mandatory if the data controller:

  • a public authority body or a body performing public duties,
  • its main activity requires large-scale, regular and systematic monitoring, or
  • main activity is the large-scale processing of special categories of data.

The status of AI Booking's data controller:

Dobó Imre, sole trader is not obliged to appoint a data protection officer, since none of the above conditions apply. AI Booking does not carry out large-scale data processing, does not process special categories of data, and does not operate as a public authority.

17.1. Data protection contact person

Although appointing a DPO is not mandatory, we are available for data protection questions at the following contact:

Contact Person: Dobó Imre (data controller)
Email: info@aibooking.hu
Response time: Within 5 business days

18. International data transfer

AI Booking's primary server infrastructure is located in the in the European Union is located (Hostinger – Lithuania). However, some of our providers are located outside the EU, mainly in the in the United States work.

18.1. Overview of data transfers outside the EU

Service providerCountryGuaranteeData processed
Stripe Inc. USA EU-US DPF + SCCs Payment data, transaction ID
Cloudflare Inc. USA EU-US DPF + SCCs IP address, security metadata
SendGrid (Twilio) USA EU-US DPF + SCCs Email address, transactional emails
Google LLC USA EU-US DPF + SCCs Calendar events, analytics, login (OAuth)
Meta Platforms Inc. USA EU-US DPF + SCCs Facebook Pixel, login (OAuth)
Apple Inc. USA EU-US DPF + SCCs Sign in (Sign in with Apple)
Microsoft Corporation USA EU-US DPF + SCCs Sign in (Microsoft OAuth)
GitHub Inc. USA EU-US DPF + SCCs Login (GitHub OAuth)

18.2. Applied guarantees

EU-US Data Privacy Framework (DPF)

On July 10, 2023, the European Commission adopted an adequacy decision on the EU-US Data Privacy Framework. Every US provider listed above holds DPF certification.

Standard Contractual Clauses (SCCs)

Standard Contractual Clauses (SCCs) approved by the European Commission are in place with every non-EU data processor, ensuring GDPR-level protection of data even during transfer.

Important note

Should the EU-US Data Privacy Framework decision be invalidated by the European Court of Justice or another competent authority, we will immediately review the legal basis for data transfer, and if necessary apply alternative safeguards or suspend the use of the affected providers.

19. Amendment of the Notice

We reserve the right to amend this Privacy Notice when necessary. Amendment is particularly necessary in the following cases:

  • Change in legislation (GDPR, applicable data protection laws, other relevant regulations)
  • Introducing a new service or feature
  • Change of data processor or involvement of a new processor
  • Regulatory recommendation or notice
  • Security or technological changes

19.1. How do we notify you of changes?

Type of changeMethod of notificationDeadline
Material change
(e.g. new data processing purpose, change in legal basis)
Email notification + in-app notification for every registered user At least 15 days before taking effect
Minor modification
(e.g. text refinement, availability update)
App notification + publication of the updated notice On the day it takes effect
Urgent modification
(e.g. data breach, official authority request)
Email notification + in-app notification, effective immediately Instantly

Tip: We recommend reviewing this page periodically to stay up to date with any changes. The current version number and date are always shown at the top of the page.

19.2. Version history

VersionDateDescription of change
1.00 2026. január 10. First edition – publication of the full privacy policy
1.10 February 12, 2026 Addition: protection of minors, DPO statement, international data transfer, notice amendment procedure, printer-friendly version. Expansion of login providers: adding Apple, Microsoft, GitHub, and Magic Link; replacing emojis with SVG icons; updating the international data transfer table

Handling of Google user data – Limited Use

AI Booking uses the information received from Google APIs (Google Calendar) exclusively to provide the service's advertised, user-visible features: entering confirmed bookings into the provider's Google Calendar, and reading busy times to avoid double bookings.

We do not sell Google user data, do not use it for advertising purposes, do not pass it on to third parties beyond the functions described above, and do not carry out human reading or analysis of it — unless the user has given explicit consent, it is required for security or legal reasons, or the data is in aggregated/anonymized form.

AI Booking complies with the following when using information received from Google APIs: Google API Services User Data Policy requirements, including the Limited Use requirements.

AI Booking's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Barion Pixel – security for card payments

To ensure the security of online card payments and prevent fraud, our website Barion Pixel we use a fraud-prevention tool called Barion Payment Zrt. (registered office: 1117 Budapest, Infopark sétány 1. I. épület; hereinafter: Barion). Barion Pixel collects data from visitor and customer activity (such as actions taken on the site, as well as device and browser data), based on which Barion performs an automated risk assessment to filter out bank card fraud.

Purpose of data processing: preventing credit card payment fraud and increasing payment security. Legal basis: the legitimate interest of the data controller and Barion (GDPR Art. 6(1)(f)). Recipient of the data: Barion Payment Zrt. as an independent data controller.

For details on Barion's data processing, see the on Barion's legal background and privacy page you can find out more.

Utolsó frissítés: 2026. február 12. • Verzió: 1.10

Published versions

  • v2 Privacy Notice – v2 March 8, 2026
  • v1 Privacy Notice – AI Booking System 2026. január 10.
AI Booking

A Hungarian-developed online booking system for service providers, with automated notifications, payment, and invoicing.

Navigation

  • Features
  • Solutions
  • Pricing
  • Find a provider Blog
  • FAQ
  • Product insight
  • Alternatives

Account

  • Login
  • Registration

Legal

  • Data Processing
  • Terms & Conditions
  • AI transparency
  • Cookie notice
© 2026 AI Booking. All rights reserved. info@aibooking.hu