Privacy Notice
Effective date: 2026. február 12. • Version: 1.11
Table of contents
- Summary – Our Data Processing in a Nutshell
- Details and contact information of the Data Controller
- Legal background
- Definitions
- Data Processors
- Legal bases for data processing
- Processed data in detail
- Cookies
- Retention periods
- Data security
- Your rights
- Legal remedy
- Provider features
- Frequently Asked Questions (FAQ)
- Contact
- Protection of minors
- Data Protection Officer (DPO)
- International data transfer
- Modification of the notice
1. Summary – Our data handling in a nutshell
Dear User!
Before diving into the legal details, we'd like to summarize in plain language how we handle your personal data. The full notice contains detailed information, but if you'd like to quickly understand the essentials, you'll find them here:
What data do we request, and why?
We only request the data that is absolutely necessary for you to use our service. We do not collect unnecessary information and we do not "snoop" on you.
| Data | Why is it needed? | What happens if they don't provide it? |
|---|---|---|
| Name | So the provider knows who to expect and we can welcome them personally | Can't register |
| Email address | Confirmations, reminders, password resets – this is how we stay in touch with you | Can't register |
| Phone number | If you need to be reached urgently (e.g. schedule change), or want an SMS reminder | Required for booking |
| Booking data | We need to know when, where and for which service they are booking | Cannot book |
Who do we share your data with?
Your data We do NOT sell it, We do NOT rent it out, and We do NOT share it with third parties for marketing purposes. We only share your data with those who are essential for the operation of the service:
- The chosen provider – the person you are booking an appointment with (hairdresser, masseur, trainer, etc.). They see your name, contact details, and the booking details.
- Technical partners – who ensure the operation of the system (server, email sending, payment). They only have access to the necessary data and have contractually committed to confidentiality.
- Authorities – but only when required by law (e.g. a tax audit, a court order).
How long do we keep your data?
- Account data: As long as you actively use your account. If you delete it, we permanently remove it within 60 days.
- Invoices, financial data: For 8 years – required of us by law.
- Technical logs (IP address, browser): for 90 days, for security reasons.
What rights do you have?
You retain full control over your data:
- You can view it – request information about what data we store about you
- You can modify it – correct inaccurate or outdated data
- You can delete – request the deletion of your data (with certain exceptions)
- You can export it – take your data with you in a machine-readable format
- Can object say no to direct marketing
How do we protect your data?
- Encrypted connection (HTTPS) – all data travels securely
- Encrypted passwords — not even we can see your password
- Two-factor authentication – extra protection for your account
- Continuous security monitoring – we watch for suspicious activity
2. Data controller's details and contact information
The data controller is the natural or legal person who determines the purposes and means of processing personal data. In the case of the AI Booking system, the data controller is:
Dobó Imre, sole trader
| Registered office: | 4029 Debrecen, Hajnal utca 14. 2/13 |
| Tax number: | 53669401-1-29 |
| Registration number: | 52110667 |
| Email: | info@aibooking.hu |
| Phone: | +36 30 609 5404 |
| Website: | www.aibooking.hu |
| Client hours: | Monday-Friday 9:00 AM-5:00 PM (CET) |
Important: Who is the data controller in your case?
AI Booking is a multi-actor system, where data controller roles are shared. It's important to understand who is responsible for your data in a given situation:
1. If you use the system directly (register, change settings):
Data controller: Dobó Imre E.V. (the system operator)
2. If you book an appointment with a service provider:
The primary data controller: the service provider (e.g. hairdresser, masseur, trainer)
Role of Dobó Imre E.V.: Data processor (providing technical infrastructure)
What does this mean in practice?
- The provider determines what data is requested from you for booking
- The provider is responsible for how it uses your data
- If you have a problem with the provider's data processing, please contact them first
- We (Dobó Imre E.V.) provide the technical background and help if you have any questions
Practical example
Situation: You book an appointment at a hairdresser called "Szépség Szalon" through AI Booking.
What happens to your data?
- You provide your name, email address, phone number, and select the appointment time
- This data is stored in our system (we are the data processors)
- "Beauty Salon" has access to this data in order to be able to receive you (they are the data controller)
- We send the confirmation email on behalf of "Beauty Salon"
If you want to delete your data:
- From the system (AI Booking): Contact us
- From the records of "Beauty Salon": Please contact them directly
3. Legal background – Which laws protect your data?
The protection of your personal data is ensured by a complex legal framework, both at European Union and Hungarian level. Below we present these regulations and their most important provisions in detail.
3.1. European Union legislation
GDPR – General Data Protection Regulation
Regulation (EU) 2016/679 of the European Parliament and of the Council (27 April 2016)
The GDPR (General Data Protection Regulation) is the European Union's unified data protection regulation, directly applicable in all EU member states since 25 May 2018. It is one of the strictest data protection regulations in the world.
The key principles of GDPR:
- Lawfulness, fairness, transparency (Article 5(1)(a)): Data processing must be lawful, fair, and transparent.
- Purpose limitation (Article 5(1)(b)): Data may only be collected for specified, explicit and legitimate purposes.
- Data minimization (Article 5(1)(c)): Only the necessary data may be collected — no more, no less.
- Accuracy (Article 5(1)(d)): Data must be accurate; inaccurate data must be erased or rectified.
- Storage limitation (Art. 5(1)(e)): Data may only be stored for as long as necessary.
- Integrity and confidentiality (Article 5(1)(f)): The data must be properly protected.
- Accountability (Article 5(2)): The data controller must be able to demonstrate compliance with these principles.
The relevant GDPR articles for our data processing:
| Article | Content | How does this affect you? |
|---|---|---|
| Article 4 | Definitions | Defines what counts as personal data, data controller, etc. |
| Article 6 | Legal bases for data processing | Determines the legal basis on which we may process your data |
| Article 7 | Terms of consent | You may withdraw your consent at any time |
| 12-14. cikk | Obligation to inform | It is our duty to inform you in detail (this document) |
| 15-22. cikk | Data subject rights | Your rights: access, rectification, erasure, restriction, portability, objection |
| Article 32 | Data security | We are obliged to properly protect your data |
| 33-34. cikk | Data breach | In case of an incident, we must notify the authority and you |
| 44-49. cikk | International data transfer | We may only transfer data outside the EU with appropriate safeguards |
| 77-79. cikk | Rights to legal remedy | You may file a complaint with the authority or turn to court |
3.2. Hungarian legislation
Infotv. – the Hungarian Act on Informational Self-Determination
Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information
This is the Hungarian basic data protection act, which supplements the GDPR with domestic specifics. Its most important elements:
- Defines the operation and scope of authority of the National Authority for Data Protection and Freedom of Information (NAIH)
- Regulates data protection authority procedures and sanctions
- Contains additional provisions on the publicity of data of public interest
Civil Code (Hungary)
Act V of 2013 on the Civil Code
Sections 2:42-54 § contain the the protection of personal rights:
- 2:42. §: General protection of personal rights
- 2:43. §: Cases of violation of personality rights (including the right to protection of personal data)
- 2:51-54. §: Sanctions for personality rights violations – non-pecuniary damages, compensation
What does this mean for you? If our data processing infringes your personal rights, you may claim compensation for damages and non-pecuniary damages.
Accounting Act
Act C of 2000 on Accounting
A Section 169(2) according to which accounting documents (including invoices, contracts, financial records) for 8 years must be retained.
Important consequence: If you paid for a service and received an invoice, we are required to retain the related data (your name, address, invoice content) for 8 years, even if you delete your account. This is not our decision — the law requires it of us.VAT Act
Act CXXVII of 2007 on Value Added Tax
A 159. § és 169. § defines the mandatory content elements of invoices and the related record-keeping obligations.
Eker tv. – Act on Electronic Commerce
Act CVIII of 2001 on certain issues of electronic commercial services (Hungary)
A 13/A. § regulates that when providing an online service:
- What data we may process and for how long
- How to inform the customer about data processing
- What data we may process for billing the service fee
Grt. — Hungarian Advertising Act
Act XLVIII of 2008 on the Basic Conditions of Economic Advertising Activity
A 6. § states that direct marketing communications – including newsletters sent by email – prior, explicit consent is required.
What does this mean in practice?- We only send newsletters or promotional emails if you have explicitly subscribed
- Subscription must be active (you check the box)
- A pre-checked checkbox is not sufficient
- You can unsubscribe anytime with one click
Eht. – Electronic Communications Act
Act C of 2003 on Electronic Communications
It contains the rules regarding electronic communication and the use of cookies, in particular the 155. §, which regulates the conditions for placing cookies.
4. Definitions – What do the legal terms mean?
Under Article 4 of the GDPR
Data protection laws often use technical terms that may seem complicated at first. Below, we explain the most important ones in plain language, with examples.
4.1. Personal Data
Definition: Any information relating to an identified or identifiable natural person.
In plain terms: Any data that can identify you, or that can be linked to you as a person.
Examples of personal data:
| Direct identifiers | Name, personal ID number, passport number, photo |
| Contact details | Email address, phone number, home address, work address |
| Online identifiers | IP address, cookie identifier, device identifier, username |
| Financial data | Bank account number, tax number, payment history |
| Activity data | Booking history, browsing history, purchasing habits |
Is an email address always personal data?
Igen, mert azonosítható személyhez kapcsolódik. Még a "xyz123@example.com" típusú cím is személyes adat, ha az adatbázisban összekapcsolható egy konkrét személlyel.
4.2. Special (sensitive) data
Definition: A particularly protected category of personal data, the processing of which is prohibited as a general rule, except in certain exceptional cases.
This includes:
- Racial or ethnic origin referential data
- Political opinion
- Religious or philosophical beliefs
- Trade union membership
- Genetic data (DNS information)
- Biometric data (fingerprint, facial recognition, retina)
- Health Data (illnesses, medications, treatments)
- Sexual life or orientation relevant data
AI Booking does NOT process special categories of data
Our system does not collect or store special (sensitive) data. If a service provider requests such data from you in the comments field (e.g. "do you have any allergies"), only that specific provider is responsible for it as an independent data controller.
4.3. Data subject
Definition: The natural person whose personal data is processed.
In plain terms: You! In the AI Booking system, the data subject can be:
- Guest: Anyone who registers and books an appointment with providers
- Provider user: Anyone using the system for business purposes (hairdresser, massage therapist, trainer, etc.)
- Team member: Someone whom a service provider has added to their system
4.4. Data Controller
Definition: The natural or legal person that determines the purposes and means of the processing of personal data.
In plain terms: The one who decides, why és how processes your data. The data controller bears responsibility for the lawfulness of the processing.
Who is the data controller for AI Booking?
| If you register in the system | Dobó Imre E.V. (us) |
| If you book with a provider | The given service provider (e.g. "Beauty Salon") |
| If the provider purchases a subscription | Dobó Imre E.V. (us) |
4.5. Data Processor
Definition: The natural or legal person who processes personal data on behalf of the data controller.
In plain terms: The one who, on behalf of the data controller and per their instructions, performs the "technical" work with the data.
Examples of data processor roles:
- We (AI Booking) we act as data processors for the providers – they are the data controllers, we provide the technical background
- SendGrid is a data processor for us – we decide who receives the email, they just send it
- Hostinger (server + database) data processor – stores and runs the system, but does not make decisions about data processing
4.6. Data Processing
Definition: Any operation or set of operations performed on personal data.
In plain terms: Everything we do with personal data:
- Collection (registration, form submission)
- Recording (saving to the database)
- Organization (categorization, grouping)
- Storage (retention on the server)
- Modification (updating data)
- Query (viewing data)
- Forwarding (sending data to others)
- Linking (merging of data)
- Restriction (data "freezing")
- Deletion (data removal)
- Destruction (permanent deletion)
4.7. Consent
Definition: A freely given, specific, informed and unambiguous indication of the data subject's wishes by which they signify agreement to the processing of their personal data.
The consent must meet the following criteria:
- Voluntary: Szabad döntés, nem kikényszerített, nem jár hátránnyal a megtagadása
- Specific: It applies to a specific purpose, not a general one
- Informed: You know what you're consenting to
- Clear: An active act (clicking, signing), not silence
What does NOT count as valid consent?
- Pre-checked checkbox
- "If you do not object, we will consider it as consent"
- Conditional consent ("you only get the service if you agree to marketing")
- Vague, generic wording
4.8. Data breach
Definition: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data.
Types:
| Type | What does it mean? | Example |
|---|---|---|
| Breach of confidentiality | Unauthorized access or disclosure | A hacker steals the database; an employee sends an email to the wrong address |
| Breach of Integrity | Unauthorized modification | A virus alters the data; a faulty import overwrites data |
| Availability breach | Loss or destruction | Ransomware encrypts the database; a server fails without a backup |
4.9. Profiling
Definition: Any form of automated processing of personal data used to evaluate certain characteristics of a person.
In plain terms: When we use computers to analyze your data in order to draw conclusions from it – for example, to predict what you will buy or which ads will interest you.
AI Booking does NOT engage in profilingWe do not automatically analyze your behavior, do not create a "profile" of you, and do not make automated decisions based on your data.
5. Data Processors – Who has access to your data and how?
For the AI Booking service to work, we need to cooperate with other companies. These partners are so-called "data processors" — they handle your data on our behalf and according to our instructions. We have signed a written agreement with every partner (a data processing agreement under Article 28 GDPR), which guarantees that they too comply with data protection requirements.
5.1. Server services — Where the data "lives"
Hostinger International Ltd. – VPS hosting, database, email and website
Registered office: 61 Lordou Vironos Street, 6023 Larnaca, Cyprus
Website: hostinger.com
Privacy notice: hostinger.com/privacy-policy
Outside the EU: No – EU member state (Cyprus), GDPR applies directly
What does it do? Hostinger provides the entire infrastructure for the AI Booking system:
- VPS (Virtual Private Server) hosting: The web application and all backend services run on this server
- PostgreSQL database: Storage of all structured data (users, bookings, settings)
- Email service: Email accounts linked to the domain and certain transactional messages
- Landing page hosting: Hosting of the aibooking.hu introductory website
What data does it have access to?
- All data stored on the server (application, database, log files)
- User data: names, email addresses, bookings, settings
- Technical logs (for troubleshooting)
Security features:
- Data storage within the European Union (GDPR-compliant)
- Encrypted data transfer (TLS/SSL)
- Regular security backups
- Firewall and basic DDoS protection
- 24/7 server monitoring
What can you NOT use it for? As an infrastructure provider, Hostinger does not access the data for business purposes, only to ensure the technical provision of the service. It has contractually undertaken data processor obligations under the GDPR.
Why is it good that the server is in the EU?
Since Hostinger is a Cyprus-based company and the data stays within the EU, no special data transfer safeguards are required (as would be the case for transfers to the USA). GDPR applies directly, which means stronger protection for your data.
Landing page – custom Node.js application
Page: aibooking.hu (introductory/landing page)
Platform: an in-house Node.js + Express + React application (the same codebase as app.aibooking.hu)
Hosting: Hostinger (see above)
What does it do? The aibooking.hu landing page is the introductory website of the service, from which visitors are directed toward the application. It's custom-built, sharing a codebase with the application — there is no external CMS (we replaced the earlier WordPress/Elementor version in May 2026).
Services used on the landing page:
- Google Analytics 4: Visitor statistics (only with consent)
- Cookie Management: Cookie banner for managing consent
- AI chatbot: The AI assistant available in the bottom right corner (see the next section)
What data does the landing page process?
- Technical data: IP address, browser type, device (in server logs)
- Analytics data: page views, time on site (Google Analytics, only with consent)
- Contact form data (if any): name, email, message
- AI chatbot conversation history (with anonymous session ID, details below)
AI chatbot – Conversation storage (aibooking.hu)
What does it do? The AI assistant available in the bottom right corner of the landing page answers visitor questions and, if needed, guides them into the consultation booking process. Conversations are stored for auditing and quality assurance purposes.
What do we store in every case?
- Conversation content (questions and AI response text)
- Anonymous session identifier (4-hour lifetime, stored in the visitor's browser in localStorage — the session identifier alone is not identifying personal data)
- Browser type (user agent)
- Referring page (referer)
IP address storage — dual mode (GDPR / EDPB guidelines):
- Masked IP (default, even without consent): If you have not accepted the analytics cookie category, we store your IP address in masked form. For IPv4, the last octet is replaced with 0 (e.g.
192.168.1.42→192.168.1.0), for IPv6 we remove everything except the first 3 hextets (e.g.2001:db8:abcd:1234::5678→2001:db8:abcd::). This is identical to Google Analytics 4's default IP-anonymization behavior, and according to the EDPB (European Data Protection Board) is not identifiable personal data — so the legal basis is legitimate interest under GDPR Art. 6(1)(f) (spam filtering, abuse protection). - Full IP (with consent only): If you have expressly accepted the analytics category in the cookie banner, we store the full IP address. Legal basis: GDPR Art. 6(1)(a) — your consent. Consent can be withdrawn at any time by reopening the cookie banner.
Retention period: 90 days, after which it's automatically deleted. If you manually delete the conversation history (using the "Delete conversation" button in the chat window), it disappears immediately on the client side, and is deleted server-side according to the 90-day automatic retention policy.
AI model and third-party provider: A chatbot az Ollama Cloud platformon működő nyelvi modellt használja. A beszélgetés-tartalom az AI-szolgáltatóhoz (Ollama – ollama.com, üzemeltető: Ollama, Inc., Egyesült Államok; harmadik országba történő adattovábbítás) továbbítódik a válasz generálásához; az AI-szolgáltató nem őrzi meg a tartalmat (zero-retention beállítás). A válaszok elkészítéséhez az Ollama mellett az OpenAI (openai.com, üzemeltető: OpenAI, L.L.C., Egyesült Államok; harmadik országba történő adattovábbítás) MI-szolgáltatót is igénybe vehetjük, ugyanezen adatkezelési feltételekkel; az OpenAI vállalása szerint az API-n beküldött adatok alapértelmezetten nem szolgálnak a modelljei tanítására.
Landing page vs. Application
AI Booking consists of two main parts:
- Landing page (aibooking.hu): Introductory website – custom Node.js application with Google Analytics and an AI chatbot
- Application (app.aibooking.hu): The booking system — a custom-developed application
We apply the principles described in this privacy notice on both sides.
Cloudflare Inc. – CDN, security services and image storage
Registered office: 101 Townsend Street, San Francisco, CA 94107, USA
Website: cloudflare.com
Privacy notice: cloudflare.com/privacypolicy
Outside the EU: Yes (USA) – Safeguard: Standard Contractual Clauses (SCC)
What does it do? Cloudflare provides us with several critical services:
1. CDN (Content Delivery Network):
- It stores the website's static content (CSS, JavaScript, icons) on servers located at various points around the world
- This way you reach the page faster, wherever you are
2. Security services:
- DDoS protection: Protects our system from overload attacks
- WAF (Web Application Firewall): Filters out malicious requests (SQL injection, XSS attacks)
- Bot protection: Distinguishes humans from malicious bots
- SSL/TLS: Ensures an encrypted connection (HTTPS)
3. R2 Object Storage – Storing images and files:
- Gallery images: Gallery images uploaded by providers (portfolio, showcase of work)
- Profile pictures: Storage of user profile pictures
- Documents: Uploaded files, attachments
Important about image storage
The Cloudflare R2 service S3-compatible cloud-based storage. Images are accessible via URL and load quickly through Cloudflare's global network. Image content is not analyzed or used for any other purpose.
What data does it have access to?
- IP addresses (to identify the source of requests)
- HTTP headers (browser type, language)
- Request content (passes through the CDN)
- Uploaded images and files (in R2 storage)
Data storage location: Cloudflare allows regional data restriction. Data in R2 storage is kept in the EU region wherever available.
5.2. Email services — How we communicate with you
SendGrid (Twilio Inc.) – Transactional emails
Registered office: 375 Beale Street, San Francisco, CA 94105, USA
Website: sendgrid.com
Privacy notice: twilio.com/legal/privacy
Outside the EU: Yes (USA) – Safeguard: SCC
What does it do? SendGrid sends all system messages to your email address:
- Booking confirmations
- Reminders (1 day and 1 hour before the booking)
- Password reset links
- Account activation emails
- Booking modification/cancellation notifications
- Newsletters (if subscribed)
What data does it have access to?
- Your email address (recipient)
- Email content (message text)
- Delivery information (whether the email was opened, whether a link was clicked)
What can you NOT use it for? SendGrid may not send you its own marketing messages, nor may it sell your email address.
Hostinger International Ltd. – Alternative email
Registered office: 61 Lordou Vironos Street, 6023 Larnaca, Cyprus
Website: hostinger.com
Outside the EU: No – EU member state (Cyprus)
What does it do? It operates as an alternative email provider for certain transactional messages and domain-related email accounts.
5.3. Payment services — How we handle your money
Stripe Inc. – Online card payment
Registered office: 354 Oyster Point Boulevard, South San Francisco, CA 94080, USA
European headquarters: Stripe Payments Europe, Ltd., Dublin, Ireland
Website: stripe.com
Privacy notice: stripe.com/privacy
Certificates: PCI DSS Level 1 (the highest level of payment card security standard)
What does it do? Stripe handles all online card payments. When you pay, you provide your card details directly to Stripe — this data NEVER reach us.
Data processed by Stripe:
- Full card number
- Expiry date
- CVC/CVV code
- Cardholder name
- Billing address
What we see from Stripe:
- Transaction ID (e.g. "pi_3ABC123...")
- Amount paid and currency
- Payment date and status
- Last 4 digits of the card (e.g. "•••• 4242")
- Card type (Visa, Mastercard, etc.)
WARNING: Fraud prevention
Mi We NEVER ask for your full bank card number, expiry date, or CVC code by email, phone, or chat. If anyone requests these on behalf of AI Booking, that is FRAUD. Kérjük, azonnal jelezze nekünk az címen!
Barion Payment Zrt. – Online payment
Registered office: 1117 Budapest, Irinyi József utca 4-20, 2nd floor
Company Registration Number: 01-10-048552
Website: barion.com
Privacy notice: barion.com/adatvedelmi-tajekoztato
Certificates: PCI DSS Level 1, payment institution supervised by the National Bank of Hungary (MNB) (license number: H-EN-I-1064/2013)
Outside the EU: No – Hungary
What does it do? Barion handles online payments in the Hungarian market. Providers can choose Barion as their payment service provider. Payment card data is handled directly by Barion – this data NEVER reach us.
Data processed by Barion:
- Payment card details (card number, expiry, CVC)
- Cardholder name
- Email address (for Barion account)
What we see from Barion:
- Transaction ID
- Amount paid and currency
- Payment date and status
OTP Mobil Kft. (SimplePay) – Online payment
Registered office: 1143 Budapest, Hungária krt. 17-19.
Company Registration Number: 01-09-174466
Website: simplepay.hu
Privacy notice: simplepay.hu/adatkezelesi-tajekoztatok
Certificates: PCI DSS Level 1
Outside the EU: No – Hungary
What does it do? SimplePay (OTP Mobil Kft.) is also an online payment solution in the Hungarian market. Providers can also choose SimplePay as their payment processor. Card data is handled directly by SimplePay.
Data processed by SimplePay:
- Payment card details (card number, expiry, CVC)
- Cardholder name
- Email address
What we see from SimplePay:
- Transaction ID
- Amount paid and currency
- Payment date and status
5.4. Billing Services
Billingo Technologies Zrt.
Registered office: 1085 Budapest, József körút 74. III/17.
Company Registration Number: 01-10-140802
Website: billingo.hu
Privacy notice: billingo.hu/adatkezelesi-tajekoztato
Outside the EU: No – Hungary
KBOSS.hu Kft. (Számlázz.hu)
Registered office: 1031 Budapest, Záhony utca 7.
Company Registration Number: 01-09-303201
Website: szamlazz.hu
Outside the EU: No – Hungary
What do they do? Online invoicing and data reporting to the NAV (Hungarian Tax Authority). Providers can choose which system to use.
What data do they have access to?
- Invoice recipient's name
- Billing address
- Tax number (if any)
- Name, quantity, and price of the purchased service
- Payment method and date
Important: In accordance with Hungarian law, invoicing systems automatically forward invoice data to the NAV Online Invoice system.
5.5. SMS Service
LINK Mobility Hungary Kft. (SeeMe) – SMS sending
Registered office: 1062 Budapest, Andrássy út 68. Building C, 1st floor, 1.
Company Registration Number: 01-09-694287
Tax number: 12598582-2-42
Website: seeme.hu
Privacy notice: seeme.hu/adatvedelem
Outside the EU: No – Hungary
What does it do? SeeMe handles the sending of SMS notifications. Providers can enable SMS reminders for bookings, which the system sends via the SeeMe API.
Data managed by SeeMe:
- Recipient's phone number
- SMS message text (booking reminder, confirmation)
- Send time and status
Important: SMS is only sent if the service provider has activated the SMS feature and the guest has provided their phone number. SMS messages can be transactional (booking confirmation, appointment reminder), or — at the service provider's discretion — marketing campaigns. Marketing SMS may only be sent with the recipient's prior, explicit consent (in accordance with Hungarian Act XLVIII of 2008 on commercial advertising activity), and every marketing SMS contains a unique, provider-specific unsubscribe link, with which the recipient can unsubscribe at any time, free of charge — exclusively from that particular provider's messages.
5.5.1. Platform marketing SMS to service providers. As the platform operator, AI Booking may occasionally send its own marketing or informational SMS messages to registered service providers (e.g. new features, promotions) at their provided phone number. Legal basis: the contractual relationship with the service provider, as well as the operator's legitimate interest (recommending its own, similar services); for natural person recipients — where the law requires it — based on prior consent. Every such SMS contains an unsubscribe link; unsubscribing is possible at any time, free of charge, and does not affect booking/system notifications. Delivery of these SMS messages is also carried out by LINK Mobility Hungary Kft. (SeeMe) as a processor.
5.6. Calendar and video conferencing integrations
Google LLC – Calendar, Meet, Analytics
Registered office: 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
European data controller: Google Ireland Limited, Dublin, Ireland
Privacy notice: policies.google.com/privacy
Outside the EU: Yes (USA) – Safeguard: SCC
Google Calendar integration:
- When does it activate? If you (or the provider) enable calendar synchronization
- What does it do? Bookings automatically appear in Google Calendar
- What data is transferred? Booking time, service name, participants
- Withdrawal: Can be disconnected anytime in account settings
Google Meet integration:
- When does it activate? If the provider offers an online consultation option
- What does it do? Automatically generates a meeting link that's included in the confirmation email
- What data is transferred? Meeting link, time slot, and attendees' email addresses
Google Analytics 4:
- When does it activate? If you have consented to analytics cookies
- Where Do We Use It? Both on the landing page (aibooking.hu) and in the app
- What does it do? Generates anonymous visitor statistics
- Details: See the Cookie section
Zoom Video Communications Inc.
Registered office: 55 Almaden Boulevard, San Jose, CA 95113, USA
Website: zoom.us
Privacy notice: explore.zoom.us/en/privacy
Outside the EU: Yes (USA) – Safeguard: SCC
What does it do? Providers can connect their Zoom account to the system, so a meeting link is automatically generated for online consultations.
Important: With the Zoom integration, the provider uses the their own Zoom account. Amikor Ön részt vesz egy Zoom hívásban, a Zoom saját adatkezelési tájékoztatója vonatkozik a hívás során keletkező adatokra (videó, hang, chat).
5.7. Marketing and analytics
Meta Platforms Inc. (Facebook Pixel)
Registered office: 1 Hacker Way, Menlo Park, CA 94025, USA
European data controller: Meta Platforms Ireland Limited, Dublin, Ireland
Privacy notice: facebook.com/privacy/policy
Outside the EU: Yes (USA) – Safeguard: SCC
What does it do? If you have consented to marketing cookies, using the Facebook Pixel:
- Measure the effectiveness of our Facebook ads
- We can show you more relevant ads
- We create statistics about visitors (in a non-identifiable way)
What data does it have access to?
- That you visited our website
- Which pages were viewed
- Which actions were taken (e.g. registration, booking)
- Technical data (browser, device)
Disabling: You can disable marketing cookies at any time in the cookie settings, and you can also limit targeted advertising in Facebook's ad settings.
5.8. Login providers (Social Login & Magic Link)
The AI Booking system uses the OAuth 2.0 protocol of the following third-party providers for login. These providers are involved only in the authentication process – the system does not get access to other data in the user's account (friends, messages, posts, etc.).
Google LLC – Google Login (OAuth 2.0 / OpenID Connect)
Registered office: 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA
European data controller: Google Ireland Limited, Dublin, Ireland
Privacy notice: policies.google.com/privacy
Outside the EU: Yes (USA) – Safeguard: EU-US DPF + SCCs
Data transferred: Name, email address, profile picture URL
Meta Platforms Inc. – Facebook Login
Registered office: 1 Hacker Way, Menlo Park, CA 94025, USA
European data controller: Meta Platforms Ireland Limited, Dublin, Ireland
Privacy notice: facebook.com/privacy/policy
Outside the EU: Yes (USA) – Safeguard: EU-US DPF + SCCs
Data transferred: Name, email address, profile picture URL
Apple Inc. – Sign in with Apple
Registered office: One Apple Park Way, Cupertino, CA 95014, USA
European data controller: Apple Distribution International Ltd., Cork, Ireland
Privacy notice: apple.com/legal/privacy
Outside the EU: Yes (USA) – Safeguard: EU-US DPF + SCCs
Data transferred: Name (optional), email address (real or Apple Private Relay address)
A unique feature of Apple login is that the user can decide whether to share their real email address or use a private relay address generated by Apple (e.g. xyz123@privaterelay.appleid.com). In both cases, the system works properly.
Microsoft Corporation – Microsoft Login
Registered office: One Microsoft Way, Redmond, WA 98052, USA
European data controller: Microsoft Ireland Operations Limited, Dublin, Ireland
Privacy notice: privacy.microsoft.com
Outside the EU: Yes (USA) – Safeguard: EU-US DPF + SCCs
Data transferred: Name, email address, profile picture URL
GitHub Inc. – GitHub Login
Registered office: 88 Colin P Kelly Jr St, San Francisco, CA 94107, USA
Parent company: Microsoft Corporation
Privacy notice: docs.github.com/privacy
Outside the EU: Yes (USA) – Safeguard: EU-US DPF + SCCs
Data transferred: Username, email address, profile picture URL
Magic Link – Passwordless login
How it works: The user enters their email address, and the system sends a one-time, time-limited login link.
Email sending: Through AI Booking's own SMTP configuration (see SendGrid / Hostinger Email in the sections above)
Token validity: Maximum 15 minutes, single use
Stored data: Only the email address. The token is automatically deleted after use or expiration.
6. Legal bases for data processing – Why may we process your data?
GDPR Article 6(1)
Under the GDPR, we may only process personal data if there is an appropriate our legal basis. A jogalap az a törvényes indok, amely feljogosít minket az adatkezelésre. Az alábbiakban részletesen bemutatjuk, milyen jogalapokat használunk.
6.1. Consent – GDPR Art. 6(1)(a)
What does it mean? You have actively and voluntarily consented to the data processing. The consent must be specific, informed, and unambiguous.
When do we use this legal basis?
| Data processing activity | How do you give your consent? | How can you withdraw it? |
|---|---|---|
| Newsletter, marketing emails | Subscription via form or at registration | Unsubscribe link at the bottom of the email, or account settings |
| Upload profile picture | Selecting and uploading an image | Remove photo from profile |
| Analytics cookies (GA4) | Cookie banner acceptance | Modify cookie settings |
| Marketing cookies (Facebook) | Cookie banner acceptance | Modify cookie settings |
| Google Calendar sync | Enabling the integration in settings | Disconnect integration |
About withdrawing consent
Ön anytime, without justification may withdraw their consent — just as easily as they gave it. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. For example: if you unsubscribe from the newsletter, we can't "undo" previously sent emails, but we won't send any more.
6.2. Performance of a contract – GDPR Article 6(1)(b)
What does it mean? The data processing is necessary for us to fulfil the contract concluded with you, or to take pre-contractual steps at your request.
When do we use this legal basis?
- Registration: Data required to create an account (name, email, password)
- Booking: Data required to record and fulfill the booking
- Confirmations and reminders: These are part of the service
- Payment: Data required to process the transaction
- Customer Service: To help resolve issues
Practical example
Situation: You are booking an appointment with a hairdresser.
Contract: By booking, a contract is formed between you and the provider (an agreement on the provision of the service).
Required data:
- Their name – so the hairdresser knows who to expect
- Email address – so we can send the confirmation
- Phone number – so we can reach you if something changes
- Time — so we know when they're coming
Without these we cannot fulfill the contract – meaning we cannot guarantee that the booking will work.
6.3. Legal obligation – GDPR Article 6(1)(c)
What does it mean? Data processing is necessary to fulfill a legal obligation. In such cases we have no choice – the law requires us to process this data.
When do we use this legal basis?
| Legal obligation | Legislation | Data concerned |
|---|---|---|
| Invoice retention | Számv. tv. 169. § (2) | Invoices, billing data – for 8 years |
| NAV data reporting | VAT Act | Automatic forwarding of invoice data |
| Authority Request | Criminal Procedure Act, etc. | Data requested based on a court order |
Important: We cannot delete this data
If you request deletion of your account, we will do so – but data required by law (e.g. invoices) must be retained. We are legally obliged to do this and have no other choice.
6.4. Legitimate interest – GDPR Art. 6(1)(f)
What does it mean? The processing is necessary for the purposes of the legitimate interests pursued by us (or a third party), except where such interests are overridden by your interests, rights and freedoms.
This legal basis legitimate interest assessment requires: in every case we must weigh whether our interest or your rights take precedence. We may only use it if our interest does not override your fundamental rights.
When do we use this legal basis?
| Legitimate interest | Data concerned | Why doesn't it override your rights? |
|---|---|---|
| IT security | IP address, browser, login attempts | Protecting your account and data is in our interest too; minimal data collection (90 days) |
| Fraud Prevention | Logging of suspicious activities | Fraud affects other users too; we investigate only in suspicious cases |
| Service development | Aggregated, anonymized usage statistics | Non-identifiable personal data; results in a better service for everyone |
| Enforcement of legal claims | Contractual data, communication | In case of a dispute, both parties have an interest in preserving evidence |
Can I object to data processing based on legitimate interest?
Yes! Under Article 21 of the GDPR, you may object to data processing based on legitimate interest. In this case, we must examine whether our legitimate interest overrides your interest. If not, we must cease the processing.
7. Data processed in detail — What data exactly do we process?
GDPR Article 13(1)(e) and Article 14(1)(d) – Information obligation regarding the categories of data processed
Below we present in detail what personal data the AI Booking system processes, for what purpose, and on what legal basis. We only collect data that is strictly necessary for providing the service.
7.1. Registration and account data
When are they generated? When you create an account in the AI Booking system.
| Data | Goal | Legal basis | Retention |
|---|---|---|---|
| Full name | Identification, greeting, booking confirmation | Contract (6.1.b) | Until account deletion + 60 days |
| Email address | Login, confirmations, reminders, password reset | Contract (6.1.b) | Until account deletion + 60 days |
| Phone number | Contact and SMS reminders (if enabled) | Contract (6.1.b) | Until account deletion + 60 days |
| Password (hash) | Account protection – we store passwords only as bcrypt hashes; we can't see them either | Contract (6.1.b) | Until account deletion |
| Profile picture | Visual identification in the system | Consent (6.1.a) | Until the image or account is deleted |
| Language setting | Displaying the interface in the selected language | Contract (6.1.b) | Until account deletion |
7.2. Booking Data
When are they generated? When you book an appointment with a service provider.
| Data | Goal | Legal basis | Retention |
|---|---|---|---|
| Booking date and time | Appointment booking, calendar sync | Contract (6.1.b) | 3 years |
| Selected service | The provider knows which service to prepare for | Contract (6.1.b) | 3 years |
| Selected provider/staff member | The booking should be assigned to the right person | Contract (6.1.b) | 3 years |
| Note (optional) | Sharing special requests or important information with the provider | Consent (6.1.a) | 3 years |
| Booking status | Confirmed, cancelled, completed – tracking the process | Contract (6.1.b) | 3 years |
Comment field — Please do not enter sensitive data!
In the booking notes field do not write special (sensitive) data (e.g. health information, allergies). If this is done nonetheless, responsibility for that the service provider is responsible as an independent data controller, not the AI Booking system.
7.3. Payment data
When are they generated? When you pay online for a service, or the provider purchases a subscription.
| Data | Goal | Who stores it? | Retention |
|---|---|---|---|
| Full card number, expiry date, CVC | Payment processing | Exclusively Stripe – we NEVER see it | According to Stripe's own policy |
| Transaction ID | Payment tracking and complaint handling | AI Booking + Stripe | 8 years (Accounting Act) |
| Amount paid, currency | Invoicing and financial record-keeping | AI Booking | 8 years (Accounting Act) |
| Last 4 digits of the card, type | Identifying the payment method for the user | AI Booking | 8 years (Accounting Act) |
| Billing name and address | Invoice issuance (statutory obligation) | AI Booking + Billingo/Számlázz.hu | 8 years (Accounting Act) |
7.4. Technical and security data
When are they generated? Automatically, every time you use the website or the app.
| Data | Goal | Legal basis | Retention |
|---|---|---|---|
| IP address | Security logging, abuse prevention, geographic region determination | Legitimate interest (6.1.f) | 90 days |
| Browser type, version | Ensuring compatibility, troubleshooting | Legitimate interest (6.1.f) | 90 days |
| Operating system | Ensuring compatibility, troubleshooting | Legitimate interest (6.1.f) | 90 days |
| Login log | Account security – detecting suspicious logins | Legitimate interest (6.1.f) | 1 year |
| Referring page (referrer) | Where the visitor came from (search engine, ad, etc.) | Legitimate interest (6.1.f) | 90 days |
7.5. Notification settings
| Data | Goal | Legal basis | Retention |
|---|---|---|---|
| Email notification preferences | What type of emails would you like to receive (booking, reminder, marketing) | Consent (6.1.a) / Contract (6.1.b) | Until account deletion |
| SMS notification preferences | Turn SMS reminders on/off | Consent (6.1.a) | Until account deletion |
| Newsletter subscription status | Handling marketing communications (Section 6 of the Hungarian Advertising Act) | Consent (6.1.a) | After unsubscribing, we retain the fact of consent for 5 years (as evidence) |
7.6. Data for social login and passwordless sign-in
When are they generated? If you register or log in to AI Booking using one of the following third-party providers: Google, Facebook, Apple, Microsoft, GitHub, or if Magic Link uses a passwordless login link sent by email.
| Data | Where Does It Come From? | Goal | Retention |
|---|---|---|---|
| Social account identifier (ID) | Google / Facebook / Apple / Microsoft / GitHub | Account linking, sign-in | Until account deletion or disconnection |
| Public name | Google / Facebook / Apple / Microsoft / GitHub | Automatic profile filling | Until account deletion |
| Email address | Google / Facebook / Apple / Microsoft / GitHub / Magic Link | Account identification, sending notifications | Until account deletion |
| Profile picture URL | Google / Facebook / Microsoft / GitHub | Profile picture display (we don't store it, only reference it) | Until disconnection |
| Magic Link token | AI Booking system (SMTP) | Generating and verifying a passwordless, one-time login link | It is automatically deleted after use or after 15 minutes |
Available login methods
| Service provider | Type | Transferred data |
|---|---|---|
| OAuth 2.0 (OpenID Connect) | Name, email, profile picture URL | |
| OAuth 2.0 (Meta Login) | Name, email, profile picture URL | |
| Apple | Sign in with Apple (OAuth 2.0) | Name (optional), email (real or Apple Private Relay) |
| Microsoft | OAuth 2.0 (Microsoft Identity Platform) | Name, email, profile picture URL |
| GitHub | OAuth 2.0 (GitHub Apps) | Username, email, profile picture URL |
| Magic Link | Email-based, passwordless authentication | Email address (a one-time link sent via SMTP) |
Important about social login
When using social login We NEVER get access to your password, contacts, messages, posts, or any other data not necessary for login. We only request the minimally necessary data listed above — this applies equally to every provider (Google, Facebook, Apple, Microsoft, GitHub).
Social login can be disconnected at any time in the account settings — the account then switches to email + password or Magic Link sign-in.
Apple Private Relay email: With Apple login, the user can choose to share their real email address or an Apple-generated private relay address. The system works correctly either way.
7.7. Provider (business) account data
Who does this apply to? To users who register as service providers (e.g. hairdresser, massage therapist, trainer) and use AI Booking for business purposes.
| Data | Goal | Legal basis | Retention |
|---|---|---|---|
| Business name | Display on the booking page | Contract (6.1.b) | Until account deletion + 60 days |
| Tax number | Invoicing (legal obligation) | Legal obligation (6.1.c) | 8 years (Accounting Act) |
| Business address | Display on the booking page, map navigation | Contract (6.1.b) | Until account deletion + 60 days |
| List of services, prices | Displaying booking options to guests | Contract (6.1.b) | Until account deletion + 60 days |
| Opening hours | Defining available appointment times | Contract (6.1.b) | Until account deletion |
| Gallery images | Portfolio showcase on the booking page (Cloudflare R2 storage) | Consent (6.1.a) | Until the image or account is deleted |
7.8. Staff Data
Who does this apply to? To those individuals whom a provider adds to their system as a team member (e.g., an employed hairdresser, assistant).
| Data | Goal | Legal basis | Retention |
|---|---|---|---|
| Staff member's name | Displayed in the booking system, informing guests | Legitimate interest (6.1.f) | Until the team member is removed |
| Team member's email address | Notifications about the team member's bookings | Legitimate interest (6.1.f) | Until the team member is removed |
| Work schedule | Display of bookable time slots in the staff member's calendar | Legitimate interest (6.1.f) | Until the team member is removed |
| Assigned services | Defines which services you can accept bookings for | Legitimate interest (6.1.f) | Until the team member is removed |
Important about staff data
For adding staff members and managing their data, the the given provider is responsible as data controller. The provider is obliged to inform their staff that their data will also appear in the AI Booking system. We (Imre Dobó, sole trader) act as data processor in this case.
Summary – Overview of data categories
| Data category | Legal basis | Retention |
|---|---|---|
| Registration data | Contract | Account deletion + 60 days |
| Booking data | Contract | 3 years |
| Payment / billing data | Legal obligation | 8 years |
| Technical logs | Legitimate interest | 90 days |
| Notification settings | Consent / Contract | Until account deletion |
| Social login data | Consent | Until disconnection / account deletion |
| Provider business data | Contract | Account deletion + 60 days |
| Staff data | Legitimate interest | Until the team member is removed |
9. Retention periods – How long do we store your data?
GDPR Art. 5(1)(e) – storage limitation principle, GDPR Art. 13(2)(a)
GDPR requires that personal data be stored only as long as the purpose of the processing requires. Below we specify exactly how long each category of data is retained, and what happens afterward.
9.1. Overview of retention periods
| Data category | Retention period | Legal Basis / Reason | What happens next? |
|---|---|---|---|
| Account data (name, email, phone, password hash) | Until account deletion + 60 days | Contract (6.1.b) – the 60 days is protection against accidental deletion | Final, irreversible deletion |
| Booking history | 3 years | Legitimate interest (6.1.f) – handling complaints and legal disputes (Civil Code limitation period) | Automatic anonymization (for statistical purposes) |
| Billing details (name, address, tax number, amount) | 8 years | Legal obligation (6.1.c) – Accounting Act Section 169(2) | Permanent deletion |
| Payment transactions (transaction ID, amount, status) | 8 years | Legal obligation (6.1.c) – Accounting Act Section 169(2) | Permanent deletion |
| Technical logs (IP, browser, referrer) | 90 days | Legitimate interest (6.1.f) – investigation of security incidents | Automatic deletion |
| Login log | 1 year | Legitimate interest (Art. 6(1)(f)) – retrospective investigation of suspicious logins | Automatic deletion |
| Cookie data | Varies by cookie (see Chapter 8) | Consent (6.1.a) / Legitimate interest (6.1.f) | Automatic expiration |
| Fact of marketing consent | After unsubscribing 5 years | Legitimate interest (6.1.f) – proof that consent was given (Grt. Section 6) | Permanent deletion |
| Notification settings | Until account deletion | Consent (6.1.a) / Contract (6.1.b) | Deleted together with the account |
| Social login linking | Until disconnection or account deletion | Consent (6.1.a) | Immediate deletion upon disconnection |
| Provider gallery images | Until the image or account is deleted | Consent (6.1.a) | It is also deleted from Cloudflare R2 |
| Staff data | Until the team member is removed | Legitimate interest (6.1.f) | Immediate Deletion |
9.2. Account Deletion Process
Account deletion happens in three steps:
| Step | Appointment | What happens? |
|---|---|---|
| 1. Deletion request | day 0 | Account deactivation – login is not possible, data is not public, booking is not possible |
| 2. Restoration Period | 1–60. nap | If you change your mind, you can request account restoration – all data remains intact |
| 3. Final deletion | day 61 | All personal data is irreversibly deleted (except data that must be retained by law, e.g. invoicing – 8 years) |
Important regarding retention periods
Certain data must be retained even after account deletion, based on legal obligation:
- Billing data (8 years): Pursuant to Section 169(2) of Act C of 2000 (Accounting Act), accounting documents must be retained for 8 years
- VAT data (8 years): Under Act CXXVII of 2007 (VAT Act), VAT documents must be retained for 8 years.
- Fact of marketing consent (5 years): Proof that the marketing outreach was carried out lawfully (Section 6 of the Hungarian Advertising Act)
We automatically and permanently delete this data once the retention period expires.
10. Data Security – How do we protect your data?
GDPR Article 32 – Security of processing, GDPR Article 25 – Data protection by design and by default
Data protection is not just our legal obligation, but also our technical responsibility. In the AI Booking system we apply multi-layered security measures that meet the security level "appropriate to the risk" required by Article 32 of the GDPR.
10.1. Encryption
| Measure | Details | What does it protect? |
|---|---|---|
| TLS/SSL encryption | All communication takes place over HTTPS (TLS 1.2 or newer). Certificates are renewed automatically. | Protection against eavesdropping — data cannot be read in transit |
| Password hashing | Bcrypt algorithm, with salt. Not even we can see your password – we only store the hash. | Protection against password theft – cannot be decrypted even in a data breach |
| Database encryption | The server's storage disks are encrypted (at-rest encryption). | Against physical access – if the disk were stolen, the data would be unreadable |
10.2. Access protection
| Measure | Details | What does it protect? |
|---|---|---|
| Role-based access control (RBAC) | Admin, provider, staff member, guest – everyone only sees the data appropriate to their own permission level. | Against unauthorized access |
| Two-factor authentication (2FA) | Available/recommended for provider accounts – TOTP app (e.g. Google Authenticator) or email-based code | Against password theft – the password alone is not enough to log in |
| Session management | Sessions automatically expire after inactivity. Simultaneous login from multiple devices is also supported. | Against forgotten logins (e.g. on a shared computer) |
| Admin access log | Every system administrator action is logged (who, what, when) | Against internal misuse |
10.3. Protection against attacks
| Measure | Details | What does it protect? |
|---|---|---|
| Rate limiting | Limiting login attempts – temporary lockout after too many failed attempts | Against brute-force attacks |
| CSRF protection | Every form includes a unique token that prevents request forgery | Against forged requests (e.g. cancellation initiated from another site) |
| XSS protection | Sanitization of input data, Content Security Policy (CSP) headers | Against malicious code injection |
| Cloudflare WAF | Web Application Firewall – automatically filters suspicious traffic and DDoS attacks | Against web attacks and denial-of-service attacks |
| SQL injection protection | Parameterized queries, ORM usage — user input never goes directly into the database query | Against database breaches |
10.4. Backup and recovery
| Measure | Details |
|---|---|
| Regular backups | Daily automatic backup — database and files. Backups are encrypted and stored in a geographically separate location. |
| Point-in-time recovery | Database restore is possible to any point in time within the last 30 days |
| Save & test | Regular restore tests to ensure that backups actually work |
10.5. Organizational measures
| Measure | Details |
|---|---|
| Principle of minimization | We only collect and process the data strictly necessary (GDPR Article 5(1)(c) – data minimization). |
| Access restriction | Personal data may only be accessed by the data controller (Dobó Imre E.V.) and the necessary systems of the data processors |
| Data processing agreements | A written data processing agreement (DPA) is in effect with every data processor (Hostinger, Stripe, Cloudflare, etc.) |
| Updates and maintenance | The server and application are regularly updated with security patches |
10.6. Handling of data protection incidents
What happens in the event of a data breach?
If a security incident affecting your personal data occurs (e.g. data breach, unauthorized access), we will proceed as follows regarding the GDPR Article 33-34 in accordance with its requirements:
| Step | Deadline | To-do |
|---|---|---|
| 1. Detection and assessment | Instantly | Assessment of the nature, extent and risks of the incident |
| 2. Regulatory Notification | within 72 hours | Notification to NAIH if the incident poses a risk to the rights of data subjects (GDPR Article 33) |
| 3. Notifying data subjects | Without undue delay | If the incident high risk occurs, we will notify the affected parties by email (GDPR Article 34) |
| 4. Damage Prevention | Instantly | Technical measures to reduce the damage (e.g. forcing a password reset, locking access) |
| 5. Documentation | Continuous | Full documentation of the incident in the register (GDPR Art. 33(5)) |
In summary
In the AI Booking system, data protection is "privacy by design" (privacy by design) and the "privacy by default" (privacy by default) principles. This means data protection is not an afterthought, but a fundamental element of the system's design.
11. Your rights – How can you control your data?
GDPR Art. 15-22, Hungarian Info Act §14-21
The GDPR grants you extensive rights over your personal data. Below we present these rights in detail and how you can exercise them within the AI Booking system.
11.1. Right of access (GDPR Article 15)
What does it mean? You have the right to receive confirmation from us as to whether we process your personal data, and if so, the right to access that data, as well as the following information:
- Purposes of data processing
- Categories of data processed
- Who has received or will receive the data (recipients)
- Planned data retention period
- Information about your further rights
- If the data does not come from you, its source is
How can you exercise it?
- Self-service: Under Account settings → "My Data" you can view most of the data we store
- Written request: Write to and within 30 days we will send you a copy of all data stored about you in a machine-readable format (JSON or CSV)
11.2. Right to rectification (GDPR Art. 16)
What does it mean? You have the right to request, without undue delay, the correction of your inaccurate personal data, or the completion of incomplete data.
How can you exercise it?
- Self-service: You can directly update your name, phone number, email address, and other details in the profile settings.
- Written request: If the data cannot be modified in the system, write to us – within 15 days we will correct it
11.3. Right to erasure – "The right to be forgotten" (GDPR Art. 17)
What does it mean? You have the right to request that we erase your personal data without undue delay, if one of the following conditions applies:
- The data is no longer needed for the purpose for which it was collected
- You withdraw your consent, and there is no other legal basis for processing
- You object to the processing, and there is no overriding legitimate ground
- The data was processed unlawfully
- The data must be deleted to fulfill a legal obligation
When can we NOT delete your data?
The right to erasure cannot be exercised if the processing is necessary:
- To fulfill a legal obligation: E.g. invoicing data — we must retain it for 8 years (Accounting Act Section 169)
- To assert or defend legal claims: E.g. in case of an ongoing legal dispute
- For public interest archiving: If required by law
How can you exercise it?
- Account deletion: Account Settings → "Delete Account" button → 60-day recovery period → permanent deletion
- Written request: Write to the address – within 30 days we fulfill
11.4. The right to restriction of processing (GDPR Article 18)
What does it mean? You may request that we not delete your data but temporarily "freeze" it — meaning we don't actively process it. This is useful if:
- You dispute the accuracy of the data – until we verify it, the data is restricted
- The processing is unlawful, but you request restriction instead of deletion
- We no longer need the data, but you need it to enforce a legal claim
- You have objected to the data processing – while we assess whether the objection is justified
During the period of restriction, the data we only store, but we do not actively process it (we do not forward or use it), except with your consent or to enforce legal claims.
11.5. Right to data portability (GDPR Article 20)
What does it mean? You have the right to receive your personal data in a structured, widely used, machine-readable format receives, and to transmit them to another data controller.
In what format can we export it?
- JSON – machine-readable structured format
- CSV – a format that can be opened with spreadsheet apps
What data does this apply to? Only to those you have provided us with, based on consent or contract:
- Registration data (name, email, phone)
- Booking history
- Notification settings
How can you exercise it?
Write to the address – within 30 days we will send the data in the requested format.
11.6. Right to object (GDPR Article 21)
What does it mean? You are entitled to object at any time against the processing of your personal data based on legitimate interest. In such cases, we must examine whether our legitimate interest overrides yours.
In particular, you may object to the following:
- Direct marketing: If you object, instantly we must stop marketing-related data processing — no discretion involved
- Logging based on legitimate interest: We review security logging, but for security reasons we cannot always discontinue it
- Data processing for statistical purposes: Does not apply to aggregated, anonymized data (as it is not personal data)
11.7. Protection against automated decision-making (GDPR Article 22)
What does it mean? You have the right not to be subject to a decision based solely on automated processing – including profiling – which produces legal effects concerning you or similarly significantly affects you.
AI Booking does NOT apply automated decision-making
We do not make decisions about your personal data based solely on automated processing. We do not reject bookings, change prices, or restrict access based on automated systems. All such decisions are made by a human.
Summary of rights exercise
| Right | GDPR article | How? | Deadline |
|---|---|---|---|
| Access | Article 15 | Account settings / email | 30 days |
| Rectification | Article 16 | Profile settings / email | 15 days |
| Delete | Article 17 | Account deletion / email | 30 days |
| Restriction | Article 18 | Email request | 30 days |
| Data portability | Article 20 | Email request (JSON/CSV) | 30 days |
| Objection | Article 21 | Email / unsubscribe link | Immediate (direct marketing) / 30 days |
| Against automated decision- | Article 22 | Not applied — not relevant | – |
Important information for exercising your rights
- Free: A kérelmek teljesítése ingyenes. Ha a kérelem nyilvánvalóan megalapozatlan vagy – különösen ismétlődő jellege miatt – túlzó, ésszerű díjat számíthatunk fel, vagy megtagadhatjuk a kérelem teljesítését.
- Identification: Before fulfilling the request, we must verify your identity. This is usually done via a request sent from the registered email address.
- Deadline extension: In particularly complex cases, the 30-day deadline may be extended by up to 2 months — you will be informed of this within the original deadline.
- Rejection: If we are unable to fulfill the request, we will provide a reasoned response and inform you of the available remedies.
12. Remedies – Where can you file a complaint?
GDPR Art. 77-79, Hungarian Info Act §22-23
If you feel your rights regarding the processing of your personal data have been violated, several remedies are available to you. We recommend that you contact us directly first — we can resolve most issues quickly.
12.1. Direct contact — Reach out to us first!
Get in touch with us
Most data protection questions and complaints quickly and directly we can resolve it. Write to us:
- Email: info@aibooking.hu
- Response time: General inquiry – within 15 days, request to exercise rights – within 30 days
Please state in your request the your registered email address, so we can identify you — this speeds up the process.
12.2. Complaint to the authority – NAIH
What is the NAIH? The National Authority for Data Protection and Freedom of Information is Hungary's independent data protection supervisory authority, which anyone can contact free of charge with a data protection complaint.
| Data | Contact |
|---|---|
| Full name | Hungarian National Authority for Data Protection and Freedom of Information (NAIH) |
| Registered office | 1055 Budapest, Falk Miksa utca 9-11. |
| Mailing address | 1363 Budapest, P.O. Box 9. |
| Phone | +36 (1) 391-1400 |
| Website | www.naih.hu |
The procedure of the NAIH (Hungarian Data Protection Authority)
- Filing a complaint: In writing (letter, email) or via the NAIH online form
- Fee: The procedure free
- Review: The NAIH investigates the complaint and informs you of the outcome
- Action: If it finds a violation, it may call on us to modify or suspend the data processing, or impose a fine
12.3. Legal recourse
If neither direct contact nor the NAIH procedure has brought the desired result, you are entitled to go to court.
| Question | Answer |
|---|---|
| Which court can I turn to? | to the court competent for your place of residence or stay, OR to the Debrecen Regional Court based on the data controller's registered seat (GDPR Art. 79, Infotv. Section 23) |
| What can I ask for? | Establishing the lawfulness of the data processing, terminating the data processing, restoring the data, and compensation for damages (Ptk. 2:52. §) |
| Who bears the burden of proof? | It is the data controller (us) who must prove that the processing was lawful (GDPR Article 5(2) – accountability principle) |
| Does It Cost Money? | The procedure is exempt from fees (Infotv. Section 23(5)) |
12.4. Summary of legal remedies
| Option | When is it worth it? | Cost | Expected time |
|---|---|---|---|
| 1. Direct contact | Always the first step — we can resolve most issues | Free | 15-30 nap |
| 2. NAIH complaint | If a direct inquiry did not resolve the issue | Free | 2-6 months |
| 3. Court Action | If you wish to claim damages, or if you disagree with the NAIH's decision | Duty-free | 6-18 months |
Important
The legal remedies are independent of each other regardless can also be used — you don't need to exhaust one path before choosing the other. Of course, we recommend that you contact us directly first.
13. Provider Features – Data Protection on the Provider Side
GDPR Article 26 – Joint Controllers, GDPR Article 28 – Processor
AI Booking is a multi-actor system: service providers (hairdresser, beautician, trainer, etc.) use the system as part of their own business, and they themselves become data controllers with regard to their guests' data. This chapter presents the data protection aspects of this.
13.1. Who is the data controller for provider-side operations?
Roles in the multi-user system
In the provider-guest relationship, the data processing roles are divided as follows:
| Action | Data Controller | Data processor |
|---|---|---|
| Guest registers with AI Booking | Dobó Imre E.V. (AI Booking) | – |
| A guest books with a provider | The provider (e.g. "Beauty Salon Ltd.") | Imre Dobó, sole proprietor (AI Booking as a platform) |
| Provider adds a staff member | the service provider | Imre Dobó, sole proprietor (AI Booking as a platform) |
| The provider views statistics about their guests | the service provider | Imre Dobó, sole proprietor (AI Booking as a platform) |
| The Provider subscribes to AI Booking | Dobó Imre E.V. (AI Booking) | Stripe (payment), Billingo (invoicing) |
| AI Booking sends a reminder email to the guest | The provider (on a commission basis) | Dobó Imre E.V. + SendGrid |
13.2. Data Processing Agreement (DPA)
What is a DPA? The Data Processing Agreement is a mandatory contract between the data controller (the service provider) and the data processor (AI Booking) that governs how the data processor handles personal data on the data controller's behalf.
When a provider registers and actively uses the AI Booking system, the General Terms and Conditions (GTC) by accepting this, you simultaneously accept the AI Booking Data Processing Agreement, which sets out:
- The subject, duration, nature and purpose of the data processing
- The types of personal data processed and the categories of data subjects
- The rights and obligations of the data controller (provider)
- The obligations of the data processor (AI Booking), including:
- Acts solely according to the service provider's instructions
- Ensures that persons with access are bound by confidentiality
- Implements security measures under GDPR Article 32
- If a sub-processor is engaged, the provider will be informed
- Helps the provider fulfill data subjects' rights
- Deletes the data after the agreement terminates
13.3. The provider's own obligations
Important for every service provider!
By using AI Booking, the provider an independent data controller in respect of your guests' personal data. This means the following:
| Obligation | What does this mean in practice? | Need help? |
|---|---|---|
| Our own data protection notice | The service provider must have its own privacy notice, referencing the use of AI Booking as a data processor | Yes – we provide a template |
| Fulfillment of data subject rights | If a guest contacts the provider (e.g. a cancellation request), the provider is responsible for fulfilling it — we provide technical support | Yes – the system supports it |
| Informing employees | The service provider is required to inform added staff members that their data will appear in the AI Booking system | Yes – automatic notification email |
| Data minimization | The provider should not request sensitive data (health, biometric, etc.) in the comment field. | Yes – a warning message appears at the comment field |
| Reporting a data breach | If the provider becomes aware that their guests' data has been compromised, they are required to report it to the NAIH (within 72 hours) | Yes – we notify the provider if an incident occurs affecting our system |
13.4. Provider data export and account deletion
What happens if a service provider leaves the AI Booking platform?
| Action | Details | Deadline |
|---|---|---|
| Data export | The service provider may request an export of the guest's booking data in CSV or JSON format — under the right to data portability | within 30 days |
| Account deactivation | The provider profile disappears from search, new bookings are no longer possible, and existing bookings are closed out. | Instantly |
| Recovery period | Account restoration can be requested for 60 days – all data remains intact | 60 days |
| Permanent deletion | The provider's personal data and guest-related bookings remain anonymized (for statistics), while the rest of the data is deleted | from day 61 |
Important regarding guest data upon account deletion
Deleting the provider's account does not delete guests' accounts. A vendégek továbbra is rendelkeznek AI Booking-fiókkal, és más szolgáltatóknál továbbra is foglalhatnak. A korábbi foglalási előzmények anonimizálva megmaradnak (a szolgáltató neve nélkül), hogy a vendég láthassa saját foglalási történetét.
13.5. Sub-processors for service provider functions
When AI Booking acts as a data processor on behalf of a provider, it uses the following sub-processors:
| Sub-processor | Goal | Location of data transfer |
|---|---|---|
| Hostinger | Server, database storage | EU (Netherlands) |
| Cloudflare | CDN, image storage (R2), WAF | EU / global network |
| SendGrid (Twilio) | Sending booking confirmations and reminders | USA (with EU SCC guarantees) |
| Google Calendar sync, Google Meet video calls | EU / USA (with EU SCC guarantees) | |
| Stripe | Online payment processing | EU (through an Irish entity) |
Providers about changes to the list of sub-processors we will notify you in advance, and we provide the opportunity to object under Article 28(2) of the GDPR.
In summary
AI Booking and the providers they cooperate in the field of data protection. We provide the technical infrastructure and the GDPR-compatible system, while providers are responsible for informing their own guests and complying with data handling rules. We support all this with templates, automations, and guides.
14. Frequently Asked Questions (FAQ)
How do I delete my account and all my data?
Answer: You'll find the "Delete account" option in account settings. After deletion, the account can still be restored for 60 days (in case you change your mind), after which it's permanently deleted. Important: by law we must keep billing data for 8 years, so that cannot be deleted.
How can I find out what data is stored about me?
Answer: You have two options:
- Under Account Settings, in the "My Data" menu, you can view most of your data
- Write to us at , and within 30 days we will send you a copy of all data stored about you
Why am I still receiving emails after unsubscribing from the newsletter?
Answer: Unsubscribing from the newsletter only affects marketing emails. You will still receive transactional emails (booking confirmation, reminders, password reset) because they are necessary for the service to function. If you don't want any emails at all, you need to delete your account.
Is my credit card data safe?
Answer: Yes! We NEVER see or store the full card number, expiry date, or CVC code. Payments are handled by Stripe, which holds PCI DSS Level 1 certification (the highest security level). We only see the transaction ID and the last 4 digits of the card.
Who can see my bookings?
Answer:
- Ön – in your own account
- the service provider – the party they booked with (and their staff, if any)
- We (AI Booking) – for technical reasons and customer support
Other users, other providers, or third parties CANNOT see your bookings.
What happens to my data if the service provider closes their account?
Answer: If a provider deletes their account from the AI Booking system:
- Your account and data related to AI Booking will be retained
- Previous bookings with the deleted provider are archived (but not deleted, due to accounting law requirements)
- You cannot create more bookings for the given provider
How can I turn off Facebook ads?
Answer: In two steps:
- On the AI Booking site: Cookie Settings → Turn off marketing cookies
- On Facebook: Settings → Ads → Ad Preferences → Restrict
Where can I turn if I am not satisfied with the data handling?
Answer: You have three options:
- Contact us: – in most cases we can solve it
- Complaint to NAIH: www.naih.hu – the Hungarian data protection authority
- Court: If you suffered damage, you may claim compensation
Do they use artificial intelligence to analyze my data?
Answer: We do not use AI to analyze your personal data, build profiles, or make automated decisions. The AI Booking system serves solely to simplify appointment scheduling.
15. Contact
If you have any questions, comments, or requests regarding this notice or our data processing, please feel free to contact us at the following:
Our Contact Details
| Data Controller: | Dobó Imre, sole trader |
| Email: | info@aibooking.hu |
| Phone: | +36 30 609 5404 |
| Postal address: | 4029 Debrecen, Hajnal utca 14. 2/13 |
| Website: | www.aibooking.hu |
| Client hours: | Monday-Friday 9:00 AM-5:00 PM (CET) |
Response times
| Request type | Response time |
|---|---|
| General questions | Within 5 business days |
| Access request (GDPR Article 15) | within 30 days |
| Erasure request (GDPR Article 17) | within 30 days |
| Data portability (GDPR Article 20) | within 30 days |
| Rectification request | within 15 days |
16. Protection of Minors
Age Limit: 16 YearsThe AI Booking service is not intended for persons under 16 years of age. A GDPR 8. cikke és az Infotv. alapján Magyarországon a 16. életévét be nem töltött személy hozzájárulása csak a szülői felügyeleti jogot gyakorló személy jóváhagyásával érvényes.
16.1. How do we handle this?
- Registration: During the registration process, the user must confirm that they have reached the age of 16
- Booking: Only persons over 16 years of age may initiate a booking
- Provider account: A service provider account may only be created by a natural person over 18 with legal capacity, or a legal entity
16.2. What happens if we identify data belonging to a minor?
If we become aware that a person under 16 has registered in the system without parental consent:
- Immediate account suspension – account use will be temporarily restricted
- Notification – we will attempt to contact the parent/guardian
- Delete – if parental consent is not received within 30 days, we permanently delete the account and all related personal data
Parental notification: If you are a parent or guardian and believe your child has registered without your knowledge, please let us know:
17. Data Protection Officer (DPO)
Under Article 37 of the GDPR, appointing a data protection officer is mandatory if the data controller:
- a public authority body or a body performing public duties,
- its main activity requires large-scale, regular and systematic monitoring, or
- main activity is the large-scale processing of special categories of data.
The status of AI Booking's data controller:
Dobó Imre, sole trader is not obliged to appoint a data protection officer, since none of the above conditions apply. AI Booking does not carry out large-scale data processing, does not process special categories of data, and does not operate as a public authority.
17.1. Data protection contact person
Although appointing a DPO is not mandatory, we are available for data protection questions at the following contact:
| Contact Person: | Dobó Imre (data controller) |
| Email: | info@aibooking.hu |
| Response time: | Within 5 business days |
18. International data transfer
AI Booking's primary server infrastructure is located in the in the European Union is located (Hostinger – Lithuania). However, some of our providers are located outside the EU, mainly in the in the United States work.
18.1. Overview of data transfers outside the EU
| Service provider | Country | Guarantee | Data processed |
|---|---|---|---|
| Stripe Inc. | USA | EU-US DPF + SCCs | Payment data, transaction ID |
| Cloudflare Inc. | USA | EU-US DPF + SCCs | IP address, security metadata |
| SendGrid (Twilio) | USA | EU-US DPF + SCCs | Email address, transactional emails |
| Google LLC | USA | EU-US DPF + SCCs | Calendar events, analytics, login (OAuth) |
| Meta Platforms Inc. | USA | EU-US DPF + SCCs | Facebook Pixel, login (OAuth) |
| Apple Inc. | USA | EU-US DPF + SCCs | Sign in (Sign in with Apple) |
| Microsoft Corporation | USA | EU-US DPF + SCCs | Sign in (Microsoft OAuth) |
| GitHub Inc. | USA | EU-US DPF + SCCs | Login (GitHub OAuth) |
18.2. Applied guarantees
EU-US Data Privacy Framework (DPF)
On July 10, 2023, the European Commission adopted an adequacy decision on the EU-US Data Privacy Framework. Every US provider listed above holds DPF certification.
Standard Contractual Clauses (SCCs)
Standard Contractual Clauses (SCCs) approved by the European Commission are in place with every non-EU data processor, ensuring GDPR-level protection of data even during transfer.
Important noteShould the EU-US Data Privacy Framework decision be invalidated by the European Court of Justice or another competent authority, we will immediately review the legal basis for data transfer, and if necessary apply alternative safeguards or suspend the use of the affected providers.
19. Amendment of the Notice
We reserve the right to amend this Privacy Notice when necessary. Amendment is particularly necessary in the following cases:
- Change in legislation (GDPR, applicable data protection laws, other relevant regulations)
- Introducing a new service or feature
- Change of data processor or involvement of a new processor
- Regulatory recommendation or notice
- Security or technological changes
19.1. How do we notify you of changes?
| Type of change | Method of notification | Deadline |
|---|---|---|
| Material change (e.g. new data processing purpose, change in legal basis) |
Email notification + in-app notification for every registered user | At least 15 days before taking effect |
| Minor modification (e.g. text refinement, availability update) |
App notification + publication of the updated notice | On the day it takes effect |
| Urgent modification (e.g. data breach, official authority request) |
Email notification + in-app notification, effective immediately | Instantly |
Tip: We recommend reviewing this page periodically to stay up to date with any changes. The current version number and date are always shown at the top of the page.
19.2. Version history
| Version | Date | Description of change |
|---|---|---|
| 1.00 | 2026. január 10. | First edition – publication of the full privacy policy |
| 1.10 | February 12, 2026 | Addition: protection of minors, DPO statement, international data transfer, notice amendment procedure, printer-friendly version. Expansion of login providers: adding Apple, Microsoft, GitHub, and Magic Link; replacing emojis with SVG icons; updating the international data transfer table |
Handling of Google user data – Limited Use
AI Booking uses the information received from Google APIs (Google Calendar) exclusively to provide the service's advertised, user-visible features: entering confirmed bookings into the provider's Google Calendar, and reading busy times to avoid double bookings.
We do not sell Google user data, do not use it for advertising purposes, do not pass it on to third parties beyond the functions described above, and do not carry out human reading or analysis of it — unless the user has given explicit consent, it is required for security or legal reasons, or the data is in aggregated/anonymized form.
AI Booking complies with the following when using information received from Google APIs: Google API Services User Data Policy requirements, including the Limited Use requirements.
AI Booking's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Barion Pixel – security for card payments
To ensure the security of online card payments and prevent fraud, our website Barion Pixel we use a fraud-prevention tool called Barion Payment Zrt. (registered office: 1117 Budapest, Infopark sétány 1. I. épület; hereinafter: Barion). Barion Pixel collects data from visitor and customer activity (such as actions taken on the site, as well as device and browser data), based on which Barion performs an automated risk assessment to filter out bank card fraud.
Purpose of data processing: preventing credit card payment fraud and increasing payment security. Legal basis: the legitimate interest of the data controller and Barion (GDPR Art. 6(1)(f)). Recipient of the data: Barion Payment Zrt. as an independent data controller.
For details on Barion's data processing, see the on Barion's legal background and privacy page you can find out more.
Utolsó frissítés: 2026. február 12. • Verzió: 1.10