Privacy Policy

  1. INTRODUCTION

    Midmar Miskolci Idegenforgalmi Marketing Nonprofit Közhasznú Kft. (hereinafter: Data Controller) is committed to protecting the personal data of its users. The purpose of this notice is to present the data processing activities conducted on the erdeigasztroexpressz.hu website in a transparent and intelligible manner, in accordance with the General Data Protection Regulation (GDPR) of the European Union and the relevant national legislation on the right to informational self-determination.

    Personal data is stored and processed by the Data Controller in compliance with data protection laws. By using the website, the visitor accepts and acknowledges the provisions of this Privacy and Data Processing Notice as binding.

    Personal user data is not generated solely by visiting the website. However, through the user’s browser, an information file known as a “cookie” may be placed on the user’s storage device. This file uniquely identifies the user during subsequent visits and allows their browsing activities on the website to be tracked. The user can remove this information file at any time via their browser settings. Further information regarding the use of cookies, their application, and removal methods can be found below.

    Data Controller Details:

    • Company Name: Midmar Miskolci Idegenforgalmi Marketing Nonprofit Közhasznú Kft.

    • Registered Office: 3530 Miskolc, Széchenyi István u. 16., Hungary

    • Tax Number: 24113917-2-05

    • Phone Number: +36 46 350 425

    • E-mail Address: info@visitmiskolc.hu


    COOKIE POLICY

    No personal data is required to view the information publicly available on the erdeigasztroexpressz.hu website.

    By entering the erdeigasztroexpressz.hu website—provided that your browser settings allow it and you explicitly approve it during your first visit or at any time thereafter—the website may automatically save information from your computer or the device used for browsing (tablet, smartphone, etc.) and may place computer cookies or similar programs on it.

    The Data Controller uses two types of cookies during the operation of the website:

    1. Strictly Necessary Cookies: These are essential for the basic functioning of the website. These cookies are automatic and cannot be switched off. Strictly necessary cookies automatically record the following data about website visitors: browser type, time of visit, address of the page visited, operating system characteristics (e.g., type, set language), and the address of the previously visited page. The Data Controller uses this data exclusively for website analysis and monitoring secure operation.

      • Purpose of processing: Monitoring the secure operation of the website and conducting website-related analysis.

      • Legal basis for processing: The consent of the data subject.

    2. Analytical Cookies: These include Google Analytics cookies that affect the functioning of the measurement code. To accept these, the user must provide explicit consent by checking the relevant option. These cookies only become active after consent is given.

      • Legal basis for processing: The consent of the data subject.

    The website provides the opportunity for visitors to change their previous cookie settings at any time during use.


    COOKIES

    A Cookie is a file that may be placed on a computer or other browsing device when a visitor accesses a website. Cookies store information related to the use of the website. Cookies serve multiple functions, including collecting information, remembering user settings, and providing the website owner with insights into user habits to enhance the user experience. The purpose of processing data stored in cookies is to improve the user experience and develop the website’s online services. The cookies used on this website do not store information capable of identifying the user personally. You have the option to prohibit the storage of cookies in your browser.

    What types of cookies do we use?

    Some cookies are strictly necessary for the site to function, while others are used to improve performance and user experience.

    • Strictly Necessary Cookies: Some of the cookies we use are essential for you to navigate between pages and view certain protected content.

    • Session Cookies: Session cookies are temporary cookies that only remember your activity while you are on the site and expire when the web browser is closed.

    • Persistent Cookies: Persistent cookies are used to remember your settings within the site and remain on your desktop or mobile device even after you close the browser or restart your computer. We use these cookies to analyze user activity and create visit patterns to improve website functionality for you and other visitors. These cookies also allow us to display targeted advertisements and measure the effectiveness of our site’s features and ads.

    • Statistical Cookies: Our staff and service providers use analytical tools to assess the popularity of site content, the interests of our visitors, and how we can improve site operation. We use statistical cookies to examine how many unique users visit the site and how frequently. This data is used solely for statistical purposes, and visitors are not identified by name.

    • Third-Party Cookies: We use the following third-party cookies:

WordPress

Functional

Usage

We use WordPress for website development. Read more about WordPress

Sharing data

This data is not shared with third parties.

Functional

Name
Expiration
persistent
Function
Store user preferences
Name
Expiration
session
Function
Store browser details
Name
Expiration
persistent
Function
Store user preferences
Name
Expiration
session
Function
Read if cookies can be placed
Name
Expiration
session
Function
Store language settings
Name
Expiration
persistent
Function
Store logged in users

Elementor

Statistics (anonymous)

Usage

We use Elementor for content creation. Read more about Elementor

Sharing data

This data is not shared with third parties.

Statistics (anonymous)

Name
Expiration
persistent
Function
Store performed actions on the website

Polylang

Functional

Usage

We use Polylang for locale management. Read more about Polylang

Sharing data

This data is not shared with third parties.

Functional

Name
Expiration
persistent
Function
Store language settings

Google Analytics

Statistics

Usage

We use Google Analytics for website statistics. Read more about Google Analytics

Sharing data

For more information, please read the Google Analytics Privacy Statement.

Statistics

Name
Expiration
2 years
Function
Store and count pageviews
Name
Expiration
1 year
Function
Store and count pageviews

Complianz

Functional

Usage

We use Complianz for cookie consent management. Read more about Complianz

Sharing data

This data is not shared with third parties. For more information, please read the Complianz Privacy Statement.

Functional

Name
Expiration
365 days
Function
Store cookie consent preferences
Name
Expiration
365 days
Function
Store cookie consent preferences
Name
Expiration
365 days
Function
Store cookie consent preferences
Name
Expiration
365 days
Function
Store cookie consent preferences
Name
Expiration
365 days
Function
Store if the cookie banner has been dismissed
Name
Expiration
365 days
Function
Store accepted cookie policy ID
Name
Expiration
365 days
Function
Store cookie consent preferences
Name
Expiration
365 days
Function
Store cookie consent preferences
Name
Expiration
365 days
Function
Store cookie consent preferences
Name
Expiration
365 days
Function
Store cookie consent preferences

Google Fonts

Purpose pending investigation

Usage

We use Google Fonts for display of webfonts. Read more about Google Fonts

Sharing data

For more information, please read the Google Fonts Privacy Statement.

Purpose pending investigation

Name
Google Fonts API
Expiration
Function

YouTube

Purpose pending investigation

Usage

We use YouTube for video display. Read more about YouTube

Sharing data

For more information, please read the YouTube Privacy Statement.

Purpose pending investigation

Name
GPS
Expiration
Function
Name
VISITOR_INFO1_LIVE
Expiration
Function
Name
YSC
Expiration
Function
Name
PREF
Expiration
Function

Miscellaneous

Purpose pending investigation

Usage

Sharing data

Sharing of data is pending investigation

Purpose pending investigation

Name
elementor_sidebar_menu_expanded_v2_elementor-custom-elements
Expiration
Function
Name
e_event-tracker
Expiration
Function
Name
e_kit-elements-defaults
Expiration
Function
Name
elementor_onboarding_pending_experiment_data
Expiration
Function
Name
elementor_onboarding_initiated
Expiration
Function
Name
Expiration
Function
Name
elementor_onboarding_start_time
Expiration
Function
Name
elementor_onboarding_experiment101_variant
Expiration
Function
Name
elementor_sidebar_menu_expanded_v2_elementor-templates
Expiration
Function
Name
cmplz_task_filter
Expiration
365 days
Function
Name
cmplzSelectedRegion
Expiration
365 days
Function
Name
wp-settings-time-1
Expiration
Function
Name
wpr-show-sidebar
Expiration
Function
Name
wpr-hash
Expiration
Function
Name
wistia
Expiration
Function
Name
wistia-video-progress-7seqacq2ol
Expiration
Function
Name
wistia-video-progress-fj42vucf99
Expiration
Function
Name
wistia-video-progress-z1qxl7s2zn
Expiration
Function
Name
cmplz_user_data
Expiration
365 days
Function

Most browsers allow you to view active cookies on your computer, delete them individually, or block cookies from specific or all websites. Please note that if you delete all cookies, previously saved settings on the website will be lost, including your preference to opt-out of cookies, as this preference itself requires a specific cookie to function. For more information on how to disable cookies by adjusting your browser settings, please visit aboutcookies.org and cookiecentral.com/faq/.

With the exception of strictly necessary cookies, you may refuse or block all or specific cookies downloaded during your visit to the website.

You can modify settings for the Data Controller’s or any third-party website by changing your browser settings. Please note that most browsers automatically accept cookies. Therefore, if you do not wish to allow the use of cookies, you must explicitly disable them by clicking the “I do not allow” button in the pop-up window. If you refuse the use of cookies, you will still be able to visit our websites, but some functions may not work correctly. To view the content of a cookie, click on the cookie itself to open it. You will see a short string of text and numbers.

Operation and Significance of Cookies:

XSRF-TOKEN:

  • Description: This is a security cookie designed to prevent Cross-Site Request Forgery (CSRF) attacks. This attack involves an unauthorized party sending a request (e.g., a POST request) to the site from a third-party site or program. If the request lacks this token, the system will reject it as an untrusted source. This eliminates a significant portion of potential attacks.

  • If you refuse this cookie: Your requests will be discarded by the system. For example, if you wish to fill out a contact form but have not enabled this cookie, the system will terminate the connection due to an insecure source, preventing the normal use of services.

  • Encryption: The cookie is hashed and generated by the server before every request, making it virtually impossible to forge. It does not reveal any information about the user, as it is not stored on the server side.

Data identified by cookies: The following data is never stored on the user’s computer. Only a hashed “token” of the cookie is stored locally, which allows the server to identify which data to access. This token identifies the following data on the server side:

  • Session history: Previous page visited.

  • Token: Generated from the characteristics of the user’s device. This is not suitable for personal identification because we do not store this information; it is hashed one-way. Every request is hashed regardless of the device, but if a request hash matches a previous hash, we know it belongs to the same session. This allows us to track sessions. (Multiple users may log in from the same device; in this case, the session is the same but the user is different, therefore the session is not suitable for individual identification).

  • Referrer: The source from which the user arrived at the site. Data collected via cookies is managed by the operator.


DATA PROCESSING ON THE WEBSITE

Contact Details (Form)

If you send us a message via the form on the site or via e-mail, we process the following data:

  • Data processed: Name, e-mail address, phone number, message text.

  • Purpose of processing: Responding to inquiries, providing information about tours, scheduling appointments.

  • Legal basis: Article 6(1)(a) of the GDPR (consent of the data subject), as the user voluntarily chose to contact the Data Controller.

  • Duration of processing: Data is stored only until the purpose of the contact is fulfilled or for the legally required retention period (e.g., 3 years for complaint handling).

Information Regarding Ticket Purchases

Direct ticket sales do not take place on our website. Tickets for the Forest Gastro Express experience tour can be purchased via the external platform: visitmiskolc.jegyx1.hu.

  • Note: When you click the ticket purchase button, you leave the erdeigasztroexpressz.hu site. The processing of data provided during purchase (e.g., billing name, address, bank card details) is the responsibility of the ticketing system operator under their own privacy policy. No data processing for this purpose occurs on this website.

Technical and Analytical Data (Cookies)

  • Data processed: IP address, browser type, time spent on site, subpages visited.

  • Purpose of processing: Ensuring the technical operation of the website, preparing statistical analyses to improve user experience.

  • Legal basis: Article 6(1)(a) of the GDPR (consent of the data subject).

  • Duration of processing: Cookie data is stored until deleted, for a maximum of one year.


DATA STORAGE AND SECURITY

The Data Controller takes all necessary technical and organizational measures to ensure data security:

  • The website has an SSL certificate (encrypted channel).

  • Data is stored on secure servers accessible only by authorized personnel.

  • Access to your personal data is restricted to authorized employees and contracted partners involved in fulfilling the tasks related to the purpose of data processing.


DATA TRANSFER TO THIRD PARTIES

Data is not transferred to third parties for any purpose, including marketing. The Data Controller utilizes a data processor for website maintenance and hosting services: [Insert Name/Company of Hosting Provider].


LINKS TO EXTERNAL SITES

Our site may contain links to pages not operated by us (e.g., ticketing interface or social media). The Data Controller is not responsible for the content or privacy practices of these sites. We recommend reading the privacy policies on those websites as well.


RIGHTS OF THE VISITOR

The data subject may request the rectification, erasure, or restriction (blocking) of their personal data from the data controller. They may also request information regarding their data, its source, the purpose, legal basis, and duration of processing, as well as information on any data protection incidents.

  • Right to withdraw consent: The data subject has the right to withdraw consent at any time. This does not affect the lawfulness of processing based on consent before its withdrawal.

  • Right of access: The subject may request information on what personal data is processed, on what legal basis, for what purpose, from what source, for how long, and to whom access was granted.

  • Right to rectification: The subject may request the correction or completion of inaccurate or incomplete data.

  • Right to restriction (blocking): The subject may request that their data be restricted while a legal claim is being established or while an objection is being evaluated.

  • Right to object: The subject may object to the processing of their personal data. The controller must then prove compelling legitimate grounds for processing that override the interests of the data subject.

  • Right to erasure (“Right to be forgotten”): The subject may request deletion if the data is no longer necessary, consent is withdrawn (and no other legal basis exists), the objection is justified, the processing was unlawful, or deletion is required by law.

Requests can be sent to: info@visitmiskolc.hu. The controller shall respond within 25 days. This may be extended by two months for complex cases, with prior notification. If a request is clearly unfounded or excessive, a reasonable fee may be charged or the request refused.


LEGAL REMEDIES

If you believe your rights have been violated, please contact us first. You may also contact the authority: National Authority for Data Protection and Freedom of Information (NAIH)

  • Address: 1055 Budapest, Falk Miksa utca 9-11., Hungary

  • E-mail: ugyfelszolgalat@naih.hu

  • Website: www.naih.hu

You also have the right to seek direct judicial remedy in court.