Privacy Notice
1. Identification of the Data Controller
Data Controller: the legal entity or sole proprietor operating the Pesti Pilates studio at any given time (hereinafter: Data Controller)
Data Controller: Molnárné Nagy Claudia (sole proprietor)
Address of Data Controller: 1137 Budapest, Újpesti rakpart 8.
Tax ID number: 92223189-1-41
Please of operation: 1092 Budapest, Erkel utca 4.
Email address: szia@pestipilates.hu
Website: www.pestipilates.hu
The Data Controller reserves the right to change its legal form (sole proprietor or business entity) during its operation. Such change does not affect the content of this Privacy Notice and shall not be considered a contractual amendment.
The specific details of the Data Controller (company name / sole proprietor’s name, registered office, tax number) are displayed on the booking platform and posted at the place of operation.
2. Legal Background of Data Processing
Data processing is governed by the following legislation: Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation – GDPR), and Act CXII of 2011 of Hungary (Infotv.).
3. Categories of Personal Data Processed and Purpose of Processing
3.1. Online Booking and Use of the Service
Data processed: name, email address, telephone number, billing address, booking data (date/time, class type).
Purpose of processing: managing bookings, maintaining contact with the Guest, and providing the service.
Legal basis: Article 6(1)(b) GDPR – performance of a contract.
3.2. Online Payment and Advance Payment
The Data Controller applies online bank card advance payment.
The Data Controller does not process or store bank card details; payment is carried out in accordance with the payment service provider’s own data processing terms.
Legal basis: Article 6(1)(b) and (c) GDPR.
3.3. Contact
The Guest may contact the Data Controller via email, website contact forms, or social media platforms.
Data processed: name, email address, content of the message.
Legal basis: Article 6(1)(a) GDPR – consent of the data subject.
4. Processing of Health Data
For the purpose of providing the service safely and professionally, the Data Controller may process health-related data to a limited extent.
Data processed may include in particular: information regarding injuries, musculoskeletal issues, pregnancy, and health-related information verbally shared with the instructor and subsequently recorded as notes in the booking system.
Purpose of processing: personalization of exercises, prevention of injuries, and ensuring the safety of Guests.
Legal basis: Article 9(2)(a) GDPR – explicit consent of the data subject.
Access to health data is limited to the Data Controller and the instructor conducting the class.
Data retention: for a maximum of 6 months from the Guest’s last participation, unless the data subject requests deletion earlier.
5. Data Processing for Marketing Purposes
Based on the Guest’s voluntary consent, the Data Controller may send messages for the following purposes: newsletters, promotional notifications, and marketing content.
Notifications related to the schedule and the booked service do not qualify as marketing communications; they form part of the communication necessary for contract performance.
Legal basis: Article 6(1)(a) GDPR.
Consent may be withdrawn at any time without justification.
6. Data Processors and Instructors
The Data Controller may engage data processors, in particular: website and booking system providers (Wix.com, Ltd.), online payment service providers (Stripe, Inc.), accountants, and invoicing software providers.
Instructors conducting classes are not employees of the Data Controller; however, when processing Guests’ personal data, they act on the instructions of the Data Controller, in the capacity of data processors.
The Data Controller enters into data processing agreements with instructors.
7. Data Processing Related to Video Surveillance
For the purposes of asset protection, personal and operational security, and the prevention and resolution of potential legal disputes, the Data Controller operates a video surveillance system at its place of operation.
7.1. Legal Basis
The legal basis for data processing is the Data Controller’s legitimate interest (Article 6(1)(f) GDPR).
Prior to introducing video surveillance, the Data Controller carried out a legitimate interest assessment.
7.2. Placement of Cameras
Cameras may operate at the entrance, in reception and circulation areas, and in the room used for providing the service (Pilates classes) solely for overview and area-monitoring purposes.
The cameras do not focus on specific individuals or body parts, are not suitable for detailed observation, are not used for performance or behavior monitoring, and do not record audio.
The Data Controller does not operate cameras in changing rooms, restrooms, showers, or other areas of an intimate nature.
7.3. Retention Period
Recorded footage is retained for a maximum of 7 days, unless a longer retention period is justified by a legal dispute, official procedure, or other legitimate interest.
8. Rights of Data Subjects
The data subject is entitled to request information, access their data, request rectification or erasure of personal data, request restriction of processing, and object to data processing.
Requests may be submitted via email to: szia@pestipilates.hu
9. Legal Remedies
The data subject may lodge a complaint with the following supervisory authority:
National Authority for Data Protection and Freedom of Information (NAIH)
1055 Budapest, Falk Miksa utca 9–11.
10. Final Provisions
The Data Controller reserves the right to amend this Privacy Notice.
Any foreign-language versions (in particular English versions) provided by the Data Controller are for informational purposes only. In case of discrepancies, the Hungarian-language version shall prevail.
