Pirate Empire - Navbar

GDPR

GDPR PRIVACY NOTICE

Effective: 17 August 2026

1. Purpose of the Privacy Notice

The purpose of this Privacy Notice is to provide information about the data processing activities carried out by Pirate Empire Kft., the operator of the websites kalozetterem.hu and pirateempire.hu (hereinafter referred to as the “Data Controller”), and to inform website visitors, purchasers of online gift vouchers, persons requesting table reservations, users of the contact form, and newsletter subscribers about the processing of their personal data.

The Data Controller places particular emphasis on the protection of personal data and on ensuring that all data processing activities comply with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR), Act CXII of 2011 on Informational Self-Determination and Freedom of Information, as well as all applicable Hungarian and European Union legislation.

The Data Controller processes personal data exclusively for purposes prescribed by law, to the extent necessary and for the period required. The Data Controller ensures that the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality are upheld in the processing of personal data.

2. Details of the Data Controller

Company name: Pirate Empire Korlátolt Felelősségű Társaság
Short company name: Pirate Empire Kft.
Registered office: 1065 Budapest, Hajós utca 25.
Place of operation (restaurant): 1065 Budapest, Nagymező utca 41. (corner of Lovag Street)
Company registration number: [Cg. 01-09-399444 – please verify this against the company extract before publication]
Tax number: 27826474-2-42
E-mail: [email protected]
Telephone: +36 30 710 9019
Website: kalozetterem.hu

3. Principles Applied During Data Processing

The Data Controller applies, in particular, the following principles when processing personal data:

lawfulness, fairness and transparency;

purpose limitation;

data minimisation;

accuracy;

storage limitation;

integrity and confidentiality;

accountability.

The Data Controller processes only personal data that are necessary for achieving the purpose of the processing and retains such data only for as long as necessary.

4. Legal Framework for Data Processing

The Data Controller's data processing activities are governed in particular by the following legislation:

Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR);

Act CXII of 2011 on Informational Self-Determination and Freedom of Information;

Act V of 2013 on the Civil Code;

Act CVIII of 2001 on Electronic Commerce and Information Society Services;

Act XLVIII of 2008 on Business Advertising Activity;

Act C of 2000 on Accounting;

Act CXXVII of 2007 on Value Added Tax;

as well as all applicable Hungarian and European Union data protection legislation.

5. Scope of the Privacy Notice

This Privacy Notice applies to all data processing activities carried out on the kalozetterem.hu website, including in particular:

visiting the website;

using the contact form;

purchasing online gift vouchers;

processing electronic payments;

subscribing to the newsletter;

processing data for marketing purposes;

statistical and analytical data processing;

the use of cookies;

data processing carried out in connection with online table reservations;

customer service communications;

data processing necessary for compliance with legal obligations.

6. Detailed Description of Individual Data Processing Activities

6.1 Data Processing During Website Visits

Purpose of data processing: Ensuring the proper functioning of the website, maintaining the security of the IT system, preventing misuse, and technically ensuring the operation of the website.

Categories of data processed: IP address, browser type and version, operating system, pages viewed, time of visit, referring website, session identifier, technical log data.

Legal basis for data processing: Article 6(1)(f) GDPR – the legitimate interest of the Data Controller.

Retention period: Technical log files are retained for a maximum of 30 days, unless a longer retention period is justified by law or a security incident.

6.2 Contact Form

Purpose of data processing: Responding to the User's enquiry, establishing contact and handling the matter.

Categories of data processed: name, e-mail address, telephone number (if provided), content of the message, date and time of submission.

Legal basis for data processing: Article 6(1)(a) GDPR – consent.

Retention period: Up to 1 year following the closure of the matter.

6.3 Contact by E-mail

If the User contacts the Data Controller directly by e-mail, the Data Controller processes the personal data necessary to respond.

Data processed: name, e-mail address, telephone number (if included), content of the e-mail, attachments, date and time of communication.

Legal basis: Article 6(1)(b) or (f) GDPR.

Retention period: Up to 5 years following the closure of the matter.

6.4 Contact by Telephone

If the User contacts the Data Controller by telephone, the Data Controller processes the data necessary for conducting the communication.

Data processed: telephone number, name (if provided), information provided during the conversation.

The Data Controller records telephone conversations only where separate notice has been provided.

Legal basis: Article 6(1)(b) or (f) GDPR.

6.5 Online Gift Voucher Purchase

The Data Controller processes the personal data necessary for the purchase of gift vouchers.

Data processed: name, billing name, billing address, e-mail address, telephone number, value of the gift voucher ordered, payment method, payment status, invoicing data.

Purpose of data processing: performance of the contract; processing of payments; issuing invoices; customer service; compliance with legal obligations.

Legal basis: Article 6(1)(b) GDPR. In the case of processing invoicing-related data: Article 6(1)(c) GDPR.

Retention period: 8 years in accordance with the legislation applicable to accounting documents.

6.6 Online Payment

The Customer may pay for the gift voucher by the following methods: payment on-site at the restaurant; bank transfer; or credit/debit card payment through the PayPal system.

Bank card details are not received by the Data Controller and are processed exclusively by PayPal. During the payment transaction, only the data necessary to complete the transaction are transferred to the payment service provider. The detailed rules governing data processing are set out in PayPal's own Privacy Notice.

Legal basis: Article 6(1)(b) GDPR.

6.7 Invoicing

Following successful payment, the Data Controller issues an invoice in accordance with the applicable accounting legislation.

[Please specify whether invoicing is carried out through an electronic system (e.g. Számlázz.hu) or on paper so that the name of the relevant data processor can be added accurately.]

Data processed: name, billing address, e-mail address, purchase details, tax number (in the case of a legal entity).

Legal basis: Article 6(1)(c) GDPR.

Retention period: 8 years.

6.8 Newsletter Subscription

The Data Controller provides Users with the opportunity to subscribe to the newsletter in order to receive information about news, events, promotions, offers and other marketing communications relating to the Pirate Empire restaurant.

Categories of data processed: name (if provided), e-mail address, time of subscription, IP address, fact of subscription, time of unsubscribing.

Purpose of data processing: sending electronic newsletters; marketing communications; providing information about promotions and events.

Legal basis for data processing: Article 6(1)(a) GDPR – the consent of the data subject.

Retention period: Until consent is withdrawn or the User unsubscribes from the newsletter. Unsubscribing is possible at any time and free of charge by using the unsubscribe link at the bottom of the newsletters or by sending an e-mail to the Data Controller.

6.9 Google Tag Manager and Related Measurement Tools

The website uses Google Tag Manager (GTM) (ID: GTM-TB6SCM4) to manage various tracking codes and marketing tools. Google Tag Manager itself does not store personal data; however, it enables other services – such as Google Analytics, Google Ads conversion tracking or the Meta Pixel – to operate where these services are activated through Tag Manager.

[Please confirm which of the above services actually operate through Tag Manager (e.g. Google Analytics 4, Google Ads, Meta Pixel) so that this section can be worded accurately.]

Where the individual services are active, the following generally applies:

Categories of data processed: IP address, cookie and device identifiers, browsing and click events, pages visited, conversion data.

Purpose of data processing: analysing website usage, preparing statistics, optimising advertisements, remarketing.

Legal basis for data processing: Article 6(1)(a) GDPR – consent.

6.10 Google Maps

Where a Google Maps map is embedded on the website (e.g. on the contact page), Google may process personal data in connection with its use, particularly IP addresses and other technical data.

Purpose of data processing: displaying the location of the restaurant and providing route-planning functionality.

Legal basis for data processing: Article 6(1)(a) GDPR – consent.

6.11 YouTube Videos

Where a video from the YouTube video-sharing service is embedded on the website, Google may process personal data and place cookies on the User's device when the video is played.

Purpose of data processing: displaying video content and improving the user experience.

Legal basis for data processing: Article 6(1)(a) GDPR – consent.

7. Data Processors and Data Transfers

The Data Controller uses data processors to perform certain data processing operations in order to provide its services.

Data processors may process personal data only on the instructions of the Data Controller and may not make independent decisions regarding such processing. The Data Controller uses only data processors that provide adequate guarantees for the secure processing of personal data.

7.1 Website Platform and Hosting Provider

The website operates on the platform of HighLevel, Inc. (GoHighLevel) (storage: msgsndr.com / leadconnectorhq.com), which is responsible for website operation, secure data storage, backups and server operation.

[Please verify and specify HighLevel's official company name and registered office based on the service agreement before the website goes live.]

7.2 Asztalfoglalás.com Online Reservation System

Online table reservations are handled through the Asztalfoglalás.com system. The processing of personal data provided during table reservations is also subject to the Privacy Notice of Asztalfoglalás.com. The Data Controller has access only to the data necessary to complete the reservation.

7.3 PayPal

Online card payments are provided by PayPal. The bank card details provided during payment do not come into the possession of the Data Controller. The Data Controller receives information only regarding the success and status of the transaction.

7.4 Invoicing Service Provider

[Please provide the name of the system used for invoicing (e.g. Számlázz.hu) so that this section can be completed.]

7.5 Google Services

The following Google services may participate in the operation of the website (activated through Google Tag Manager): Google Analytics, Google Ads, Google Maps and YouTube. During the use of these services, personal data may be transferred to Google.

7.6 Meta Platforms

Where the Meta Pixel is used on the website, the Data Controller may use Meta services to perform statistical analyses, measure conversions and display advertisements for remarketing purposes. Only the data necessary for the operation of the service are transferred to Meta.

7.7 Newsletter Service Provider

For sending newsletters, the Data Controller may use the built-in newsletter function of the website platform (HighLevel) or a separate newsletter service provider. The newsletter service provider processes only the data necessary for sending newsletters and does so on the instructions of the Data Controller.

8. Transfers to Third Countries

Certain service providers used by the Data Controller – in particular Google, Meta and HighLevel – may, due to the nature of their operations, use servers located outside the European Economic Area.

In all cases, data transfers are carried out using safeguards that comply with applicable data protection legislation. The legal basis for such transfers may be European Commission adequacy decisions, Standard Contractual Clauses (SCCs) adopted by the European Commission, or other appropriate safeguards provided for by the GDPR.

9. Data Security

The Data Controller applies appropriate technical and organisational measures to protect the personal data processed, in particular against:

unauthorised access;

unauthorised modification;

unauthorised transfer;

unauthorised disclosure;

deletion or destruction;

accidental data loss;

IT attacks.

The Data Controller ensures that personal data are accessible only to employees and collaborators whose duties require such access.

The Data Controller continuously monitors and maintains the IT systems used for processing personal data and protects them against external attacks to the extent permitted by available technology.

The Data Controller takes all reasonable measures to ensure the continuous confidentiality, integrity and availability of the personal data it processes.

10. Rights of Data Subjects

Under the GDPR, anyone whose personal data are processed by the Data Controller has the right to:

request information about the processing of their personal data (right of access);

request the correction of inaccurate data;

request the deletion of their data where the legal basis for processing has ceased to exist;

request restriction of processing;

object to the processing of their data;

exercise the right to data portability;

where processing is based on consent, withdraw consent at any time without giving a reason, without affecting the lawfulness of processing carried out before the withdrawal.

These rights may be exercised using the contact details provided above ([email protected]). The Data Controller shall respond to requests without undue delay and, at the latest, within one month of receiving the request.

11. Complaints and Legal Remedies

If you believe that the processing of your personal data does not comply with legal requirements, you may first submit your complaint to the Data Controller using the contact details provided above ([email protected]).

You may also submit a complaint to the supervisory authority:

National Authority for Data Protection and Freedom of Information (NAIH)

Address: 1055 Budapest, Falk Miksa utca 9–11.
Postal address: 1363 Budapest, P.O. Box 9.
Telephone: +36 (1) 391-1400
E-mail: [email protected]
Website: www.naih.hu

In the event of a violation of your rights, you may also bring proceedings before a court. The proceedings fall within the jurisdiction of the competent regional court. At your discretion, proceedings may also be initiated before the regional court having jurisdiction over your place of residence or place of stay.

12. Amendments to the Privacy Notice

The Data Controller reserves the right to amend this Privacy Notice unilaterally. The amended Privacy Notice shall become effective on the date of its publication on the website. Visitors will be informed of amendments through the website.

This Privacy Notice has been prepared in Hungarian and is continuously available in electronic form on the kalozetterem.hu website.

Effective date: 17 August 2026

Last amended: 17 August 2026

Pirate Empire – The Pirate Empire is one of Budapest’s most unique themed restaurants, where guests can step into a truly immersive pirate world. Spectacular sets, an exciting atmosphere and generous dishes await those looking for more than just an ordinary dinner. The restaurant is the perfect choice for a family outing, a get-together with friends, a birthday celebration or a truly special Budapest experience.

Opening hours

Hétfő - 11:00 - 22:00
Kedd 11:00-22:00

Szerda 11:00-22:00

Csütörtök 11:00-22:00

Péntek 11:00-22:00

Szombat 10:00-22:00

Vasárnap 10:00-22:00

Monday - 11:00 - 22:00
Tuesday 11:00-22:00

Wednesday 11:00-22:00

Thuresday 11:00-22:00

Friday 11:00-22:00

Saturday 10:00-22:00

Sunday 10:00-22:00

Kapcsolat

  • 1065 Budapest Nagymező utca 41.

  • 36 30 710 9019

Contact

  • 1065 Budapest Nagymező utca 41.

  • 36 30 710 9019

2026 • Pirateempire©

2025 • Pirateempire©