Privacy Policy
New York Palace Event Website
https://www.newyorkpalota.hu/
Effective: August 1, 2026
This privacy notice explains the purposes, legal basis, duration, and conditions under which the operator of the New York Palota events website processes the personal data of website visitors, those requesting quotes, event contacts, newsletter subscribers, and individuals who use the contact channels available on the website.
This privacy notice covers the technical operation and security of the website, the receipt and processing of requests for quotes, the submission of quotes and event preparation, communication, newsletter distribution, the recording of cookie settings, and—depending on the actual technical configurations—data processing related to the use of analytics and marketing technologies.
1. Information about the Data Controller
| Data | Contents |
| Full Name of the Data Controller | CER Event Planning and Catering Limited Liability Company |
| Abbreviated name | CER, Ltd. |
| Brand Name / Business Unit | New York Palace – Event Venue |
| Headquarters | 1146 Budapest, Ajtósi Dürer sor 5, 1st floor, apt. 1. |
| Company Registration Number | 01-09-983650 |
| Tax ID Number | 23907795-2-42 |
| Representative | Jenő Magyary |
| Event Venue Address | 1073 Budapest, Erzsébet Boulevard 9–11. |
| Website | https://www.newyorkpalota.hu/ |
| General Contact Email | info@newyorkpalota.hu |
| Phone | +36 1 88 66 134 |
2. Fundamental Principles of Data Processing
The Data Controller processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (hereinafter: GDPR).
- Personal data is processed lawfully, fairly, and in a manner that is transparent to the data subjects.
- The Data Controller processes data solely for specific, explicit, and lawful purposes, and only to the extent that is necessary and proportionate.
- The Data Controller shall take reasonable measures to ensure the accuracy and, where necessary, the timeliness of the data.
- The Data Controller retains the data only for as long as is necessary to achieve the purpose and to comply with legal obligations.
- The Data Controller protects the data from unauthorized access, alteration, disclosure, loss, or destruction through appropriate technical and organizational measures.
- The Data Controller documents data processing activities in accordance with the requirement of accountability.
3. Specific Data Processing Activities
3.1. Technical Operation and IT Security of the Website
| Data Processing Element | Contents |
| Purpose of Data Processing | To ensure the secure and proper operation of the website; to detect and resolve errors; and to prevent, detect, log, and investigate cyberattacks and misuse. |
| Stakeholders | Visitors to the website and users of online forms. |
| Data Processed | IP address, date and time of visit, requested URL or resource, referring page, browser and device information, operating system, technical identifiers, error codes, server and security log data. |
| Legal Basis | Article 6(1)(f) of the GDPR: The Data Controller’s legitimate interest in operating the website, protecting the IT system and the personal data being processed, and preventing misuse. |
| Source of data | The user’s device and browser, as well as the systems that operate the website, web hosting, and security services. |
| Retention Period | The general duration is up to 30 days; in the event of a security incident, the duration is limited to the time necessary to investigate the matter and assert legal claims. |
| Recipients / Data Processors | Web Hosting Provider: Sybell Informatikai Kft. Developer: Marketing Astro Kft. Operator/Maintenance Provider: Eventrend Project Kft.; IT and Security Service Provider: Sybell Informatikai Kft. |
| Consequences of Data Reporting | Technical data processing is an inherent part of using the website. Without the processing of this data, the secure and stable operation of the website cannot be guaranteed. |
3.2. Contacting Us by Email or Phone
| Data Processing Element | Contents |
| Purpose of Data Processing | Receiving the inquiry, identifying the individual concerned, responding to the question or request, maintaining contact, preparing for any potential service or contract, and documenting the proceedings. |
| Stakeholders | Individuals, sole proprietors, as well as legal entities and other organizations that contact the New York Palace, and their designated contacts who are natural persons. |
| Data Processed | Name, company name/organization name, job title or contact role (if applicable), email address, phone number, the subject and content of the inquiry, the date and time of the communication, and any additional data generated during the handling of the matter. |
| Legal Basis | Article 6(1)(b) of the GDPR, if the processing is necessary for steps taken at the data subject’s request prior to entering into a contract or for the performance of a contract. Contact person for a legal entity or other organization, as well as in the case of general, partner, or professional inquiries: Article 6(1)(f) of the GDPR—the legitimate interests of the Data Controller and the inquiring organization in maintaining contact and conducting business. |
| Source of data | Directly from the individual concerned, or—in the case of an organizational contact person—from the employer, client, or colleague who designated that person. |
| Retention Period | S1 year from the date the matter is closed, provided no contract has been entered into; in the case of a contractual matter, 5 years from the date the contract terminates; in the case of a legal dispute, until the dispute is finally resolved. |
| Recipients / Data Processors | Sales, event planning, finance, legal, and management staff with jurisdiction over the matter; and, if necessary, the Data Controller’s contracted information technology and communications service providers. |
| Consequences of Data Reporting | Contacting us is voluntary. If the information necessary to respond to your inquiry is missing, the Data Controller will be unable to respond or will only be able to do so to a limited extent. |
3.3. Requesting a Quote for an Event Using the Website Form
Consent to data processing is not required to submit the request for proposal form. The legal basis for data processing is the pre-contractual process initiated by the contracting authority or, in the case of an organizational contact person, the legitimate interest of the parties in maintaining contact.
| Data Processing Element | Contents |
| Purpose of Data Processing | Receiving and recording event requests; identifying the client and ensuring contact information is available; assessing the event’s basic details; assessing capacity and feasibility; preparing a customized proposal; coordinating details of the proposal; preparing the contract; and documenting the sales process. |
| Stakeholders | Private individuals requesting quotes, sole proprietors, as well as the natural person contacts of companies, institutions, and other organizations. |
| Data Processed | Name, company name, email address, phone number, the content of the message and the request for a quote; as well as, during subsequent discussions, the planned date, type, number of attendees, venue and room requirements, technical and catering needs, budget, history of quotes and communications, the status of the quote, and technical details regarding the submission of the form. |
| Legal Basis | Article 6(1)(b) of the GDPR, if the requesting party, as a natural person, is requesting a quote for their own event. In the case of a contact person for a legal entity or other organization, Article 6(1)(f) of the GDPR: the legitimate interest of the Data Controller and the requesting organization in establishing a business relationship, submitting a bid, and preparing a contract. |
| Source of data | Directly from the person filling out the form; during further consultations, from the requesting party and the contacts designated by the requesting party. |
| Retention Period | In the case of a rejected offer or failed negotiations, 1 year from the date of the last substantive contact; in the case of a concluded contract, 5 years from the date of termination of the contract; in the case of accounting documents, 8 years. |
| Recipients / Data Processors | DYNEX Limited Liability Company (Dynex Kft.; registered office: 1238 Budapest, Hősök tere 37; company registration number: 01-09-439155; tax ID: 32722510-2-43) as the data processor. |
| Consequences of Data Reporting | Without the information marked as required, the Data Controller will not be able to process the request for a quote or contact the requester. You may omit the optional information. |
3.4. Managing Requests for Proposals in the Dynex CRM System
| Data Processing Element | Contents |
| Purpose of Data Processing | Centralized tracking of requests for proposals and inquiries; monitoring the sales process; managing tasks and communication history; documenting the status of proposals; and supporting service-related communication related to requests for proposals. |
| Stakeholders | Individuals who request quotes on the website and the natural persons serving as contacts for the events. |
| Data Processed | Data sets stored in Dynex, including, in particular, contact information, prospect profiles, request-for-quote and event data, statuses, internal notes, tasks, email/SMS communications, consent data, activity data, and delivery data. |
| Legal Basis | In accordance with the legal basis of the underlying request for proposal or contract, Article 6(1)(b) or (f) of the GDPR. |
| Source of data | From the form on the website, from communications with the requesting party, and from data recorded by the Data Controller’s staff during the processing of the request. |
| Retention Period | In the case of a rejected offer or failed negotiations, 1 year from the date of the last substantive contact; in the case of a concluded contract, 5 years from the date of termination of the contract; in the case of accounting documents, 8 years. |
| Recipients / Data Processors | DYNEX Limited Liability Company (Dynex Kft.; registered office: 1238 Budapest, Hősök tere 37; company registration number: 01-09-439155; tax ID: 32722510-2-43) as the data processor. |
| Consequences of Data Reporting | Recording the request for proposal in the CRM is an internal technical procedure for handling the request; it does not require any separate data reporting to the requesting party. |
3.5. Contract Execution and Event Planning Following the Submission of Bids
| Data Processing Element | Contents |
| Purpose of Data Processing | Entering into and fulfilling event planning or venue rental contracts; maintaining communication; handling the professional, technical, and catering preparations for the event; documenting orders and changes; invoicing; handling complaints; and managing legal claims. |
| Stakeholders | The customer is a natural person, a sole proprietor, a legal entity, or an organization; the natural persons acting as representatives or points of contact for such entities; and identifiable individuals involved in organizing the event. |
| Data Processed | Request for Proposal (RFP) details; contract and billing information; names, job titles, and contact information of points of contact; event details; orders and modifications; performance, financial, complaint, and legal dispute data; and, if necessary, other information essential for organizing the event. |
| Legal Basis | Article 6(1)(b) of the GDPR in the case of a natural person who is a contracting party; Article 6(1)(f) of the GDPR in the case of contact persons at the contracting organization; Article 6(1)(c) of the GDPR when fulfilling accounting, tax, and consumer protection obligations; Article 6(1)(f) of the GDPR for the purpose of asserting, exercising, or defending legal claims. |
| Source of data | From the data subject, the client, the representative of the contracting organization, and its points of contact, as well as from documents generated during the performance of the contract. |
| Retention Period | As a general rule, contracts and related documents must be retained for 5 years from the termination or fulfillment of the contract; accounting documents and supporting documents must be retained for 8 years; complaints for the period specified by applicable consumer protection regulations; and in the event of a legal dispute, until the matter is finally resolved. |
| Recipients / Data Processors | A subcontractors, technical service providers, catering providers, security providers, and other service providers who are actually involved in carrying out the event; in each case, only to the extent necessary for their tasks, with their legal roles precisely defined |
| Consequences of Data Reporting | Without the information required to enter into and fulfill the contract, the Data Controller cannot finalize an offer, enter into a contract, or carry out the event. |
3.6. Newsletters and Electronic Direct Marketing
Subscribing to the newsletter is separate from requesting a quote and from using any other services. Subscription requires separate, voluntary, specific, and unambiguous consent.
| Data Processing Element | Contents |
| Purpose of Data Processing | Sending newsletters, news, offers, and promotional messages related to event venues, catering, and the Data Controller’s services; documenting consent and unsubscriptions; measuring the effectiveness of campaigns. |
| Stakeholders | People who have voluntarily subscribed to the newsletter. |
| Data Processed | Email address; name; date, source, and version of the consent; IP address and technical log; date of unsubscription |
| Legal Basis | Consent pursuant to Article 6(1)(a) of the GDPR. Consent may be withdrawn at any time without providing a reason. |
| Source of data | Directly from the subscriber and from the technical logs of the newsletter distribution system. |
| Retention Period | Until consent is withdrawn or the newsletter service is discontinued. |
| Recipients / Data Processors | DYNEX Limited Liability Company (Dynex Kft.; registered office: 1238 Budapest, Hősök tere 37; company registration number: 01-09-439155; tax ID number: 32722510-2-43) as an email delivery service provider |
| Consequences of Data Reporting | Subscription is voluntary. Refusing or withdrawing consent will not affect your ability to request a quote or use any other services. |
3.7. Cookie Settings, Consents, and Web Analytics
| Data Processing Element | Contents |
| Purpose of Data Processing | To record and apply the user's cookie settings, and to provide evidence of consent or refusal; in the event of consent, to collect visitor statistics, measure performance, and conduct marketing-related tracking. |
| Stakeholders | Visitors to the website. |
| Data Processed | Consent ID, selected cookie categories, date and version of consent or opt-out, browser and device data; if consent is granted, online identifiers, event data, and usage data collected by the analytics or marketing system in use. |
| Legal Basis | In the case of strictly necessary technologies and the recording of consent choices, Article 6(1)(f) of the GDPR: legitimate interests related to the operation of the website, respect for user choices, and accountability. For analytics, convenience, and marketing technologies: prior consent pursuant to Article 6(1)(a) of the GDPR. |
| Source of data | The user's browser, device, and cookie management platform. |
| Retention Period | The actual duration of the consent log in the cookie management platform and of the specific cookies. The exact details are provided in the cookie management panel, specifically in the information regarding cookies. |
| Recipients / Data Processors | The cookie consent management platform, Google Analytics/Google Tag Manager, Google Ads, Meta Pixel, embedded maps, videos, social media, spam protection, or other technologies—based solely on the actual cookie scan and tag list. |
| Consequences of Data Reporting | Rejecting non-essential cookies does not restrict access to the website’s core content. Some optional embedded features become available only after you provide the appropriate consent. |
| Further Information | The detailed name, provider, purpose, category, and duration of each cookie are listed in a separate cookie management panel, in the cookie policy. You may modify or withdraw your consent at any time via the „Cookie Settings” page available on the website. |
3.8. Social Media Pages and External Links
| Data Processing Element | Contents |
| Purpose of Data Processing | Engaging with the community on social media platforms, responding to questions and messages, promoting the services of the New York Palace, and—where applicable—reviewing aggregate page statistics. |
| Stakeholders | People who visit, follow, send messages to, comment on, or otherwise interact with the New York Palota’s social media pages. |
| Data Processed | Profile names and profile information displayed publicly on the platform; messages, comments, and reactions; the content and timing of communications; and aggregated statistical data provided by the platform. |
| Legal Basis | Depending on the purpose of the request, Article 6(1)(b) or (f) of the GDPR; legitimate interest related to community communication and customer relations. The platform provider acts as a sole data controller with respect to the operation of its own platform, and as a joint data controller with respect to certain site statistics in conjunction with the relevant platform |
| Source of data | Directly from the person concerned and the social media platform. |
| Retention Period | According to internal message management practices, data is retained for up to 1 year after the case is closed, or up to 5 years in the event of a legal claim. The retention of data appearing on the platform is governed by the platform’s own rules and the user’s settings. |
| Recipients / Data Processors | Social media platforms and representatives involved in managing social media. |
| Consequences of Data Reporting | The use of social media is optional. The website may not transmit any data to the platform before you click on a simple external link posted on the website. Embedded social media content can only be loaded after the appropriate cookie settings have been configured. |
3.9. Handling Complaints, Incidents, and Legal Claims
| Data Processing Element | Contents |
| Purpose of Data Processing | Investigating complaints, quality-related issues, and extraordinary events; responding to them; complying with legal obligations; and asserting, enforcing, and defending legal claims. |
| Stakeholders | Persons filing complaints or claims, relevant contacts, witnesses, and other natural persons involved in the matter. |
| Data Processed | Name, contact information, address—if required by law or for administrative purposes—a description of the complaint or incident, its date and location, evidence, related communications and actions taken, as well as any additional information necessary to resolve the matter. |
| Legal Basis | Article 6(1)(c) of the GDPR: to comply with consumer protection and other legal obligations; Article 6(1)(f) of the GDPR: to assert and defend the legal claims of the Data Controller or a third party. |
| Source of data | From the person concerned, the client, witnesses, those involved, documents generated in connection with the case, and—as specified in a separate notice—from the on-site security systems. |
| Retention Period | Complaints and written responses are retained in accordance with the applicable consumer protection retention period; data required for other legal claims are generally retained for 5 years, or, in the case of an ongoing matter, until it is finally resolved. |
| Recipients / Data Processors | Legal and data protection advisors with jurisdiction over the matter, the insurance company, the regulatory authority, the court, and service providers whose involvement is necessary for the resolution of the matter. |
| Consequences of Data Reporting | In the absence of the information necessary to investigate the complaint or claim, the matter cannot be investigated, or can only be investigated to a limited extent. |
4. Data Processors, Recipients, and Access Within the Corporate Group
The Data Controller will disclose personal data only to recipients whose access to the data is necessary to fulfill the specific purpose and who have an appropriate legal basis for such access. Data processors may act solely in accordance with the Data Controller’s documented instructions and under the terms set forth in a contract pursuant to Article 28 of the GDPR.
| Recipient / Service Provider Category | Role and Responsibilities |
| CRM and Database Provider | Dynex Kft., 1238 Budapest, Hősök tere 37; company registration number: 01-09-439155; tax ID number: 32722510-2-43. Responsibilities: receiving/storing requests for proposals, CRM, newsletters, automation, communication |
| Web Hosting Provider | Sybell Informatika Kft., 34 Tomori Street, 2nd Floor, 1138 Budapest |
| Website Developer and Maintenance Specialist | Sybell, Marketing Astro, Ltd. |
| Email and Office System | Email: BlazeArts Kft. |
| Cookie Management Platform | CookieYes Limited (CMP name: CookieYes) The Consent Log (Proof of Consent) is available in your CookieYes account under the "Consent Log" menu item and can be exported from there (in CSV or PDF format). CookieYes acts as a data processor and records consent information (pseudonymized IP address, country, consent status, timestamp, Consent ID). |
| Analytics and Marketing Service Providers | Google Analytics / Google Tag Manager / Google Ads (Google Ireland Limited / Google LLC) Meta Pixel (Meta Platforms Ireland Limited) |
| Spam and Abuse Prevention | – |
| Professional Advisors and Government Agencies | Legal, accounting, auditing, data protection, and IT consultants, to the extent necessary for the performance of their duties; authorities and courts acting in accordance with the law. |
5. Data Transfers Outside the European Economic Area
The Data Controller primarily processes and has personal data processed within the European Economic Area. If a service provider or subprocessor processes data outside the EEA, the transfer of data may only take place under safeguards in accordance with Chapter V of the GDPR, including, in particular, an adequacy decision, valid participation in the EU-U.S. data protection framework, standard contractual clauses, and, where necessary, additional safeguards.
6. Automated Decision-Making and Profiling
The Data Controller does not make any decisions regarding the acceptance of a request for a quote, the content of a quote, or the conclusion of a contract that are based solely on automated processing and that have legal effects on the data subject or similarly significantly affect the data subject.
7. Data Security
The Data Controller implements technical and organizational measures commensurate with the risks. These include, in particular, access control, individual user access rights, strong authentication, logging, backups, encrypted data transmission, regular review of access rights, employee confidentiality obligations, contractual oversight of data processors, incident management, and the timely deletion of data.
Only those individuals who need access to requests for proposals and CRM data in order to perform their job duties may access such information. When access is no longer required, access rights must be revoked immediately.
8. Rights of Data Subjects
Under the terms of the GDPR, the data subject may exercise the following rights:
Right of access: You may request information regarding whether the Data Controller is processing your personal data, and you may request a copy of the data being processed.
Right to Correction: You may request that inaccurate information be corrected and that missing information be provided.
Right to erasure: You may request that your data be deleted if the conditions set forth in the GDPR are met.
Restriction of data processing: You may request that the processing of your data be restricted, for example, if you dispute the accuracy of the data or due to legal claims.
Data Portability: In the case of automated data processing based on consent or a contract, you may request that the data you have provided be provided to you or transferred to you in a machine-readable format.
Right to Protest: You may object to data processing based on legitimate interests for reasons related to your particular situation. You may object to direct marketing at any time, without having to provide a reason.
Withdrawal of Consent: Consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of previous data processing.
Rights related to automated decision-making: Subject to the applicable conditions, you may request human intervention, explain your position, and challenge the decision.
9. Exercising Rights and Handling Requests
The data subject may submit their request to the contact address specified in Section 1. As a general rule, the Data Controller will respond to the request without undue delay, but no later than one month after receipt. This deadline may be extended by an additional two months, taking into account the complexity of the request and the number of requests received; the Data Controller will provide notice of any such extension.
Before complying with a request, the Data Controller may request a reasonable verification of the data subject’s identity and eligibility. As a general rule, requests are processed free of charge. In the case of manifestly unfounded or particularly repetitive or excessive requests, the Data Controller may charge a reasonable fee or refuse to comply with the request in accordance with the provisions of the GDPR.
10. Legal Remedies
If the data subject believes that the processing of their personal data violates their right to data protection, they may file a complaint with the National Authority for Data Protection and Freedom of Information:
| Data | Contents |
| Name of the Authority | National Authority for Data Protection and Freedom of Information |
| Title | 1055 Budapest, 9–11 Falk Miksa Street. |
| Mailing Address | 1363 Budapest, P.O. Box 9. |
| ugyfelszolgalat@naih.hu | |
| Phone | +36 (1) 391-1400 |
| Website | https://www.naih.hu/ |
You may also bring the matter before the relevant court. You may file the lawsuit—at your discretion—with the court having jurisdiction over the Data Controller’s registered office or over your place of residence or place of stay.
11. Amendments to the Prospectus and Its Effective Date
The Data Controller may amend this privacy notice, particularly in the event of changes to the website’s features, data processing procedures, service providers, or the legal framework. The currently effective version is available on the website. The Data Controller will provide separate notice in an appropriate manner regarding any changes that substantially affect the rights of data subjects or the terms of data processing.
Effective Date: August 1, 2026
Version Number: 1.0