PRIVACY POLICY

Last updated: 2026.07.12.

This is a courtesy translation provided for information purposes only. In the event of any discrepancy or dispute, the Hungarian-language version of this document shall prevail and is the sole legally binding version.

1. INTRODUCTION

1.1. Purpose of this Policy


The purpose of this Privacy Policy is to provide transparent information about the processing of personal data in connection with the services of bukio.hu (hereinafter: "Bukio", the "Platform", the "Service Provider").

Bukio provides a service through which Restaurants can register, create a restaurant profile and share a reservation form. Guests can initiate table reservations with the given Restaurant through that form.

Of particular importance: in relation to the processing of Guests' reservation data, the given Restaurant qualifies as the controller, while Bukio acts as a processor on behalf of the Restaurant (see Section 3).

1.2. Details of Bukio (the Service Provider)


Business name: Nagy György Ev. (Nagy György, sole proprietor)

Registered office: 6726 Szeged, Középkikötő Sor 14/b

Tax number: 59721639-1-26

E-mail: hello@bukio.hu

Data protection contact: privacy@bukio.hu

Website: bukio.hu

1.3. Definitions


Personal data: any information relating to an identified or identifiable natural person.


Data subject: the natural person whose personal data are processed.

Controller: the party that determines the purposes and means of the processing.

Processor: the party that processes personal data on behalf of the controller.

Recipient: the natural or legal person or body to which the personal data are disclosed.

Personal data breach: a breach of security leading to the unauthorised access to or disclosure of, or the loss, alteration or destruction of, personal data processed.

1.4. Legal background


When processing personal data, Bukio acts primarily in accordance with the following laws and guidelines:
  • Regulation (EU) 2016/679 (GDPR) – the general rules of data processing and the rights of data subjects
  • Act CXII of 2011 on Informational Self-Determination and Freedom of Information (Infotv.) – the Hungarian rules on data protection and freedom of information
  • Directive 2002/58/EC (ePrivacy), together with the related Hungarian legislation (e.g. Act C of 2003 on Electronic Communications – Eht., Act CVIII of 2001 on Electronic Commerce (Eker. tv.)) – in particular the provisions relating to cookies and similar technologies
  • Act C of 2000 on Accounting – where fee payment/invoicing and the retention of accounting records take place


    The purpose of this Policy is to meet the transparency requirements set out in Articles 12–14 of the GDPR.

2. PRINCIPLES OF DATA PROCESSING

2.1. Principles


We apply the principles of the GDPR when processing personal data, in particular:
  • Lawfulness, fairness and transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability

3. ROLES AND RESPONSIBILITIES

3.1. Bukio as controller


Bukio acts as an independent controller in particular in the following cases:
  • registration and management of Restaurant accounts
  • login (OTP by e-mail), security logging
  • operation of the service, bug fixing, maintenance
  • offers after the trial period / contract administration (towards Restaurants)
  • collection and invoicing of subscription fees (towards Restaurants)

3.2. Bukio as processor (Guest reservations)


In relation to the processing of Guests' reservation data, Bukio acts as a processor on behalf of the given Restaurant. The purposes and means of the reservation are determined by the Restaurant; Bukio performs the technical operations necessary for providing the service (e.g. storage, display, technical provision of the sending of e-mail notifications).

3.3. Restaurants as controllers (Guest data)


Restaurants are independent controllers in relation to the reservation data of Guests. Restaurants are responsible in particular for:
  • determining the purpose and legal basis of the processing
  • informing the Guests
  • handling data subject requests
  • retaining and deleting the data in accordance with their own rules

3.4. Guests (data subjects)


A Guest is a natural person who initiates a table reservation through the Restaurant's reservation form.
The processing necessary for fulfilling the reservation is typically related to steps prior to entering into a contract / the performance of a contract.

3.5. Data subject requests (contact and handling)


Data subjects (users of Restaurants, Guests) may submit their requests relating to data processing (e.g. access, rectification, erasure, objection) at the following address: privacy@bukio.hu.



Important: in relation to Guests' reservation data, the Restaurant qualifies as the controller; therefore, a Guest's request should primarily be submitted to the Restaurant concerned. If a Guest's request is received by Bukio, we forward it to the relevant Restaurant and, as a processor, cooperate in fulfilling the request.

4. LEGAL BASES OF DATA PROCESSING

4.1. Legal bases


In the course of its data processing, Bukio typically relies on the following legal bases:
  • Performance of a contract / steps prior to entering into a contract (Restaurant accounts, provision of the service)
  • Legal obligation (e.g. accounting obligations where fee payment/invoicing takes place)
  • Legitimate interest (IT security, prevention of abuse, system stability)
  • Consent only in cases where the processing is not necessary for the service (e.g. marketing, web push notifications).



    For the processing of Guests' reservation data, the Restaurant, as controller, applies its own legal basis; the processing necessary for the reservation is typically contractual in nature.

5. DATA PROCESSED, PURPOSES, RETENTION

5.1. Restaurant account registration and account management (Bukio as controller)


Categories of data: name, e-mail address.

Purpose: creation and management of the Restaurant account, customer service communication.

Legal basis: contract / steps prior to entering into a contract.

Retention: for the duration of the account; in the event of a deletion request, we act with due regard to our statutory obligations.

5.2. Login with an OTP code sent by e-mail (Bukio as controller)


Categories of data: e-mail address, one-time login code (OTP), time of the login event, technical identifiers (e.g. IP address, browser/device identifiers) for security purposes.

Purpose: ensuring secure access to the account.

Legal basis: performance of a contract + legitimate interest (security).

Retention: the OTP code is valid for a short period (typically a few minutes), after which it becomes automatically invalid. For the retention of login/security log data, see 5.9.

5.3. Restaurant profile data (Bukio as controller)


Categories of data: name of the restaurant, address, contact details (e-mail, telephone), website, social media links, opening hours, reservation settings, seating/table capacity, description.

Purpose: operation of the reservation form and the admin interface.

Legal basis: performance of a contract + legitimate interest (operation).

Retention: for the duration of the contractual relationship.

5.4. Guest reservation data (Bukio as processor, Restaurant as controller)


Categories of data: name, e-mail address and telephone number of the person making the reservation, date and time of the reservation, number of guests, status of the reservation, (optionally) the content of the "special request" field.

Purpose: recording and managing the reservation, keeping in contact, fulfilling the reservation.

Legal basis: the Restaurant, as controller, typically processes the data on a contractual legal basis (steps prior to entering into a contract / performance of a contract).

Retention: the retention period is determined by the Restaurant as controller in accordance with its own data processing rules. As a processor, Bukio stores the reservation data until instructed otherwise by the Restaurant (until the reservation is deleted by the Restaurant), and at most for the duration of the Restaurant's account; the termination of the account is governed by Section 5.11.

5.5. The "special request" field and special categories of data


The "special request" field may contain free text. Please avoid entering health-related data (e.g. allergies, illnesses) where possible.


If a Guest nevertheless shares such information, the Restaurant (controller) may process it for the purpose of fulfilling the reservation, and Bukio, as processor, acts in accordance with the Restaurant's instructions.

5.6. Reservation e-mail notifications (Bukio as processor, Restaurant as controller)


Categories of data: e-mail address, reservation data, type of notification (e.g. confirmation, reminder, feedback request, cancellation, deletion notice), as well as event data relating to delivery and feedback (e.g. delivery status, error cause, the fact and time of opening and, if the e-mail contains a link, the fact and time of clicking).

Purpose: ensuring transactional communication relating to the reservation, supporting deliverability and operation, and indicating to the Restaurant whether the message has been opened.

Legal basis: the Restaurant's contractual legal basis as controller for messages relating to the reservation (steps prior to entering into a contract / performance of a contract). Delivery and open/click event data are processed on the basis of the legitimate interest in the reliable operation and deliverability of the service and in the transparency of reservation communication.

Retention: in line with the retention period of the reservation record.



Restaurant setting: the Platform allows the Restaurant to set whether reservation confirmation, reminder and/or feedback request e-mails are sent to Guests. Accordingly, these messages are sent based on the Restaurant's decision and settings.



Cancellation and deletion notifications: if a Guest cancels the reservation through the Platform, or an operation affecting the status of the reservation takes place, the system may send a transactional notification to confirm the operation and to ensure transparent communication.



Open/click feedback – not for marketing purposes: open (and, where relevant, click) event data relating to reservation e-mails are not processed for marketing purposes. The event data are not public and are accessible only to the authorised users of the given Restaurant (and to Bukio for operational/security purposes). The event data are not used for marketing profiling and do not serve as a basis for advertising targeting.

5.7. Trial period and determination of the price tier (Bukio as controller)


Categories of data: usage summaries relating to the Restaurant account (e.g. number of reservations/period), contact details required for entering into a contract.

Purpose: determination of the price tier (based on the monthly number of reservations) after the 30-day free period and preparation of invoicing.

Legal basis: steps prior to entering into a contract + legitimate interest.

Retention: for the duration of the offer/contracting process, and in accordance with statutory obligations.

5.8. Acceptance of policies / declarations (Bukio as controller)


Categories of data: the fact of acceptance (time, version), technical identifiers.

Purpose: legal compliance, accountability.

Legal basis: legitimate interest + legal obligation (where applicable).

Retention: for the applicable limitation period for the enforcement of claims.

5.9. Security logging (Bukio as controller)


Categories of data: IP address, browser/device identifiers (e.g. user agent), timestamp, technical log events (login, errors, abuse patterns).

Purpose: IT security, prevention of abuse, incident management, system stability.

Legal basis: legitimate interest.

Retention: a maximum of 90 days, unless the investigation of a security incident justifies longer retention. Account-linked login history (the list of the user's logins, for the subsequent verification of account security) may be retained for the duration of the account.

5.10. Reservations page (https://www.bukio.hu/foglalasok) – viewing with a reservation identifier


After the reservation has been submitted, the system may redirect the Guest to the https://www.bukio.hu/foglalasok page, where the reservation is displayed.



Data processed: reservation identifier, reservation data, as well as security log data (e.g. IP address, browser/device data) for the prevention of abuse.

Purpose: enabling the reservation to be viewed, supporting administration (e.g. deletion/cancellation, where available), and system security.

Legal basis: the Restaurant's contractual legal basis as controller (steps prior to entering into a contract / performance of a contract), as well as legitimate interest (security, prevention of abuse).

Retention: in line with the retention period of the reservation record; for the retention of security logs, see 5.9.

5.11. Termination of the Restaurant account – deletion of reservations and guest data


If the Restaurant (User) terminates its Bukio account, Bukio, as processor – having regard to the Restaurant's status as controller – deletes/anonymises the reservation data belonging to the Restaurant, and the reservations can no longer be managed or tracked on the Platform.



Exceptions: the retention of certain data may be necessary for (i) compliance with a legal obligation, (ii) IT security and incident management, (iii) the establishment, exercise or defence of legal claims, and the settlement of disputes. In such cases, the retention of the data is limited to the extent and duration necessary.



Security logs: security log data are retained in accordance with Section 5.9.

5.12. Mobile application (Bukio app for restaurant staff)


Categories of data: the restaurant's identifier (slug/ID) and the mobile PIN for login; after login, a session token placed in secure storage on the device (Android Keystore / iOS Keychain). The application displays the reservation data of the given restaurant (name, e-mail address and telephone number of the person making the reservation, date and time, number of guests, status, notes).

Purpose: enabling restaurant staff to view and manage reservations on mobile devices (approval, rejection, internal notes).

Legal basis: the Restaurant's contractual legal basis as controller for the processing of reservation data, with Bukio acting as processor. Secure login and the prevention of abuse are based on the legitimate interest in system security.

Access and storage: the application accesses only the data of the logged-in restaurant via the Bukio API, over an encrypted HTTPS connection using a Bearer token. The app does not store reservation data persistently on the device; only the session token is stored securely, and it is deleted upon logout.

Data collection from the device: the application does not collect any data from the device that is not necessary for its operation (no geolocation, no contact access, no advertising identifier, and no third-party analytics or advertising).

Retention: reservation data are retained in line with the retention period of the relevant reservation record (see 5.4.); security logs in accordance with Section 5.9.

5.13. Payment, invoicing and accounting (Bukio as controller)


Categories of data: billing name/business name, registered office/address, tax number, contact e-mail, the fee tier and invoice items, payment status, as well as the payment identifiers returned by Stripe and partial data of the saved card (e.g. card type, last 4 digits, expiry date).

Purpose: collection and invoicing of the subscription fee, keeping records of payments, compliance with accounting and tax obligations.

Method of payment: payment is made by bank card via the Stripe payment service provider (recurring card charges based on the express consent of the User, see ToS 5.3.). Full card data are handled exclusively by Stripe (in compliance with PCI DSS); Bukio does not store and has no access to the full card number. In the event of an unsuccessful charge, the Service Provider may retry the charge (see ToS 5.5.).

Legal basis: legal obligation (Article 6(1)(c) GDPR; Section 169 of Act C of 2000 on Accounting), as well as the performance of a contract.

Retention: accounting records are retained for 8 years. In the event of account deletion, billing data are processed separately and solely until the accounting obligation has been fulfilled.

5.14. Product and feature information for Users (Bukio as controller)


Categories of data: name and e-mail address of the registered User (Restaurant), basic data on the use of the account (e.g. activated features, price tier).

Purpose: informing existing Users about new features and developments of the Platform, usage tips and offers relating to the service.

Legal basis: the data subject's consent (Article 6(1)(a) GDPR), which the User may give during registration or in the account settings; every such message includes a simple, free-of-charge unsubscribe option.

Unsubscribing / withdrawal: consent may be withdrawn at any time, free of charge, via the link in the footer of the message or at privacy@bukio.hu. Unsubscribing does not affect system messages concerning the operation of the Platform (e.g. maintenance, changes affecting the service or the contractual terms), transactional messages relating to reservations, or messages relating to invoicing — these are not marketing messages and are sent in connection with the performance of the contract.

Retention: for the duration of the account or until unsubscribing; the fact of unsubscribing is recorded in order to avoid future messages.

5.15. Analytics/marketing tools configured by the Restaurant on the guest-facing side (Restaurant as controller)


The Platform allows the Restaurant to connect external analytics or marketing tools (e.g. Google Analytics 4, Google Tag Manager, Meta Pixel, TikTok Pixel) to its own public reservation page, and to redirect the Guest to the Restaurant's own thank-you page after a successful reservation.



Enabling these tools is the Restaurant's decision, and in relation to the resulting processing (e.g. placing cookies, transmitting the Guest's device identifiers and browsing events to the third party), the Restaurant qualifies as the controller. Ensuring the required legal basis (typically the Guest's consent), the cookie banner and appropriate information is the responsibility of the Restaurant. Bukio only provides the technical possibility, and the third parties mentioned (Google, Meta, TikTok) act as independent controllers in accordance with their own policies.



If the Restaurant configures a custom thank-you page, the Guest is taken to the external address specified by the Restaurant after the reservation; the Restaurant, or the operator of the given page, is responsible for the data processing carried out on that page.

5.16. Web push notifications for restaurant users (Bukio as controller)


Categories of data: the technical identifier associated with the browser push subscription (push token / subscription identifier), the content of the notification (e.g. a message about the arrival of a new reservation, which may contain the basic data of the reservation), delivery event data.

Purpose: immediate browser notification of restaurant users about reservation events (e.g. new reservation, cancellation) in the admin interface.

Legal basis: the user's consent, given by accepting the permission request displayed in the browser; consent may be withdrawn at any time in the browser's notification settings or in the interface.

Processor: the delivery of notifications is provided by OneSignal, Inc. (see 6.7.). Web push is available exclusively in the restaurant (admin) interface; no OneSignal service is used on the guest-facing reservation form or in the mobile application.

Retention: the push subscription identifier is processed until the subscription is withdrawn or for the duration of the account.

5.17. Statistics and marketing on Bukio's own website (Bukio as controller)


Categories of data: online identifiers (cookie identifiers, device and browser data, IP address), pages viewed and events performed on the website.

Purpose: traffic analysis of the public marketing pages of bukio.hu (e.g. home page, pricing, contact) (Google Analytics 4), as well as the measurement and optimisation of advertising campaigns (Google Ads, Meta Pixel).

Legal basis: the data subject's consent (Article 6(1)(a) GDPR), given via the cookie banner. By default, all non-essential tools are disabled (Google Consent Mode v2); consent may be modified or withdrawn at any time (see the Cookie Policy).

Important: these tools do not run on the guest-facing reservation form/widget or in the admin interface, only on Bukio's own marketing pages.

Recipients: Google Ireland Ltd. and Meta Platforms Ireland Ltd., which act as independent (and, for certain operations, joint) controllers in respect of their own purposes (see 6.8.).

Retention: varies by cookie; details are set out in the Cookie Policy.

5.18. Guest block list (Restaurant as controller, Bukio as processor)


The Platform allows the Restaurant to prevent abusive, harassing or spam-like reservations by blocking the guest concerned.


Categories of data: the e-mail address of the blocked guest and their technical identifiers (IP address, browser/connection fingerprint).

Purpose: prevention of abusive reservations, protection of the resources of the Restaurant and the Platform.

Legal basis: the legitimate interest of the Restaurant as controller (Article 6(1)(f) GDPR); Bukio, as processor, provides the technical framework.

Retention: the block remains in place until it is withdrawn (deleted) by the Restaurant, and at most until the termination of the Restaurant's account. Creating and lifting a block is the decision and responsibility of the Restaurant.

6. PROCESSORS

6.1. Database / data storage


Provider: MongoDB Inc. (MongoDB Atlas)

Region: EU (Frankfurt)

Activity: database service, storage of data.


Privacy policy: MongoDB Privacy Policy

6.2. Application hosting / infrastructure


Provider: Vercel Inc.

Region: EU (Frankfurt) execution environment

Activity: serving the web application, infrastructure.


Privacy policy: Vercel Privacy Policy

6.3. E-mail delivery


Provider: Twilio SendGrid

Region: EU (Frankfurt / according to the EU endpoint configuration)

Activity: delivery of transactional e-mails (reservation notifications, login OTP).


Privacy policy: Twilio Privacy Notice

6.4. Cache, OTP storage, rate limiting


Provider: Upstash Inc.

Region: EU (Frankfurt)

Activity: Redis-based cache, temporary storage of one-time login codes (OTP) (with a short TTL of a few minutes), and request limiting (rate limiting) for the prevention of abuse.

Data processed: e-mail address, OTP code (temporarily), IP address.


Privacy policy: Upstash Privacy Policy

6.5. Payment service provider


Provider: Stripe Payments Europe, Ltd. (Ireland) and Stripe, Inc. (USA)

Region: EU / USA (with appropriate transfer safeguards: DPF / SCC)

Activity: processing of bank card payments, storage of saved card data (in compliance with PCI DSS), management of recurring card charges (mandates). Only Stripe has access to the full card number.

Data processed: name/business name, e-mail address, billing data, card data and transaction data of the Restaurant User.


Privacy policy: Stripe Privacy Policy

6.6. Backups


Provider: Hetzner Online GmbH

Region: EU (Germany)

Activity: storage of encrypted backups of the database on a server separated from the production system, for business continuity purposes.


Privacy policy: Hetzner Privacy Policy

6.7. Web push notifications


Provider: OneSignal, Inc.

Region: USA (with appropriate transfer safeguards: DPF / SCC)

Activity: delivery of browser (web push) notifications to restaurant users in the admin interface, management of push subscription identifiers (see 5.16.). Not used in the mobile application.


Privacy policy: OneSignal Privacy Policy

6.8. Statistics and marketing providers (independent controllers)


On the public marketing pages of bukio.hu – solely with the data subject's consent (see 5.17.) – the tools of the following providers operate. In respect of their own purposes, these providers act not as processors but as independent (and, for certain operations, joint) controllers:


Google Ireland Limited (Google Analytics 4, Google Ads) – Google Privacy Policy

Meta Platforms Ireland Limited (Meta Pixel) – Meta Privacy Policy

7. DATA SECURITY

7.1. Security measures


We apply technical and organisational measures proportionate to the risk, in particular:
  • access restriction and permission management
  • encrypted data transmission (TLS/SSL)
  • logging and prevention of abuse
  • regular updates
  • regular, encrypted backups in a separate environment
  • OTP-based login (with a short validity period), limitation of login attempts (e.g. rate limiting)

8. DATA TRANSFERS, INTERNATIONAL DATA FLOWS

8.1. Access / data transfers outside the EEA


The service operates in the EU (Frankfurt) region; however, some of the providers used are established in the US (e.g. Vercel, MongoDB, Upstash, Twilio/SendGrid, Stripe, OneSignal), and therefore administrative/support-type access or data transfers outside the EEA may occur.


In such cases, we apply appropriate transfer safeguards (e.g. the EU–US Data Privacy Framework and/or Standard Contractual Clauses – SCC), in accordance with the applicable laws.

8.2. Requests from authorities


On the basis of a legal obligation, we transfer data to the competent authorities only where this is done on an appropriate legal basis and pursuant to a lawful request.

9. RIGHTS OF DATA SUBJECTS

9.1. Right to information

The data subject is entitled to receive transparent information about the processing.

9.2. Right of access

The data subject is entitled to obtain confirmation as to whether their data are being processed, and to request a copy.

9.3. Right to rectification

The data subject is entitled to request the rectification of inaccurate data.

9.4. Right to erasure

The data subject is entitled to request the erasure of their data where the statutory conditions are met.

9.5. Right to restriction of processing

The data subject is entitled to request the restriction of processing in accordance with the statutory conditions.

9.6. Right to object

The data subject is entitled to object to processing based on legitimate interest on grounds relating to their particular situation.

9.7. Right to data portability


The data subject is entitled to receive the personal data concerning them, which they have provided, in a structured, commonly used and machine-readable format, and may also be entitled – where technically feasible – to request that the data be transmitted directly to another controller, in accordance with the statutory conditions.

9.8. Right to withdraw consent


Where the legal basis of a processing operation is the data subject's consent, the consent may be withdrawn at any time. Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.

9.9. Automated decision-making and profiling


In providing the service, Bukio does not apply automated decision-making or profiling that produces legal effects concerning the data subject or similarly significantly affects them. The automatic calculation of the restaurant's price tier (based on the monthly number of reservations) affects only the invoicing of the Restaurant and does not produce legal effects concerning the Guest.

11. REMEDIES

11.1. Contact


If you have any questions or comments regarding data processing, or wish to submit a data subject request (e.g. access, rectification, erasure, objection), please write to us at: privacy@bukio.hu.

11.2. Supervisory authority (NAIH)


Hungarian National Authority for Data Protection and Freedom of Information (Nemzeti Adatvédelmi és Információszabadság Hatóság – NAIH)

Registered office: 1055 Budapest, Falk Miksa utca 9-11.

Postal address: 1363 Budapest, Pf.: 9.

Telephone: +36 1 391 1400

E-mail: ugyfelszolgalat@naih.hu

Website: https://www.naih.hu/

11.3. Judicial remedy

In the event of an infringement of their rights, the data subject may bring an action before a court.

12. FINAL PROVISIONS

12.1. Amendment of this Policy


Bukio reserves the right to amend this Policy. The version in force at any given time is available on the website.

12.2. Entry into force


This Policy enters into force on 2026.07.12. and remains valid until revoked. Upon its entry into force, the previous Privacy Policy ceases to have effect.