Privacy Policy
1. General information
In connection with the processing of personal data by Tegla Pizza Kft. (hereinafter: the "Data Controller"), we provide the following detailed information on the basis of Act CXII of 2011 on Informational Self-Determination and Freedom of Information and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR):
The Data Controller processes personal data for the purposes and in the manner set out in the individual sections below, in full compliance with the applicable legislation in force at any given time and in line with the Data Controller's own objectives. The Data Controller further declares that it regards the right to informational self-determination — with particular regard to personal data — as being of the utmost importance, and that within its own sphere of authority it takes every available organisational, operational, regulatory and technological measure to ensure that these rights are observed and enforced.
2. Name and contact details of the Data Controller
Company name: Tegla Pizza Kft.
Registered office: 1083 Budapest, Losonci tér 4., 10th floor, door 43, Hungary
Company registration number: Cg.01-09-447705
Tax number: 32884379-2-42
Representative: Márton Tagscherer
Data protection officer: Márton Tagscherer
Email address: hello@budapestbakehouse.hu
3. Definitions
Personal data: any information relating to an identified or identifiable natural person (the "Data Subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, a number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Processing: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Data Controller: the natural or legal person, public authority, agency or any other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the Data Controller or the specific criteria for its nomination may be provided for by Union or Member State law.
Processor: the natural or legal person, public authority, agency or any other body which processes personal data on behalf of the Data Controller.
Consent of the Data Subject: any freely given, specific, informed and unambiguous indication of the Data Subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
Data Subject: a natural person identified or identifiable on the basis of any information.
Third party: a natural or legal person, public authority, agency or body other than the Data Subject, the Data Controller, the Processor and persons who, under the direct authority of the Data Controller or Processor, are authorised to process personal data.
Recipient: a natural or legal person, public authority, agency or another body to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.
4. Purpose of processing and categories of personal data processed
4.1. Personal data relating to enquiries and contact
Categories of personal data processed:
Personal data provided on the www.budapestbakehouse.hu website, through any of the Data Controller's contact channels, or via the contact form when getting in touch, in particular:
- Name
- Postal address
- Email address
- Telephone number
In addition, any other personal data provided by the Data Subject when getting in touch.
Purpose of processing:
General contact, enabling the Data Subject to request specific information from the Data Controller or ask the Data Controller to take action.
Legal basis for processing:
The Data Subject's voluntary consent given by initiating contact. (See section 5.a)
Duration of processing:
Until consent to processing is withdrawn.
4.2. Handling of job applications and CVs sent to the Data Controller
Categories of personal data processed:
Personal data provided on the www.budapestbakehouse.hu website or through any of the Data Controller's contact channels when getting in touch, in particular:
- Name
- Date and place of birth
- Home address / place of residence
- Email address
- Telephone number
- Educational qualifications
In addition, any other personal data provided by the Data Subject when getting in touch.
Purpose of processing:
General contact, enabling the Data Subject to request specific information from the Data Controller or ask the Data Controller to take action.
Legal basis for processing:
The Data Subject's voluntary consent given by initiating contact. (See section 5.a)
Duration of processing:
- In the case of CVs, applications, portfolios and cover letters submitted in response to a position advertised by the Data Controller: until the position is filled.
- In the case of CVs, applications, portfolios and cover letters submitted voluntarily by the Data Subject for a position not advertised by the Data Controller, the Data Controller shall ask the Data Subject to declare whether they consent to processing by the Data Controller. In such cases, the Data Controller retains the documents containing personal data for 1 year or until consent to processing is withdrawn.
4.3. Newsletters
Categories of personal data processed:
Personal data provided on the www.budapestbakehouse.hu website when subscribing to the newsletter, in particular:
- Name
- Email address
Purpose of processing:
We use the data collected to send newsletters, updates and promotional offers. This ensures that the Data Subject receives relevant content and valuable insights from the Data Controller.
Legal basis for processing:
The legal basis for processing the Data Subject's personal data is their voluntary consent, given when subscribing to the newsletter. (See section 5.a)
Duration of processing:
We process the personal data until the Data Subject withdraws their consent to the newsletter, which they may do using the unsubscribe link contained in the newsletters or by contacting the Data Controller directly and requesting removal.
5. Legal basis for processing
a. The Data Subject has given consent to the processing of their personal data for one or more specific purposes.
b. Processing is necessary for the performance of a contract to which the Data Subject is party or in order to take steps at the request of the Data Subject prior to entering into a contract.
c. Processing is necessary for compliance with a legal obligation to which the Data Controller is subject.
d. Processing is necessary in order to protect the vital interests of the Data Subject or of another natural person.
e. Processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the Data Subject which require protection of personal data, in particular where the Data Subject is a child.
6. Rights of the Data Subject in relation to processing
In relation to their personal data processed by the Data Controller, the Data Subject may exercise — among others — the rights described below.
a. Transparent information
Upon request, the Data Controller provides the Data Subject with information about its processing activities in a concise, transparent, intelligible and easily accessible form, using clear and plain language.
The Data Controller provides the requested information in writing within the shortest possible time from submission of the request, and in any event no later than 30 days from receipt of the request.
b. Right of access
The Data Subject has the right to obtain from the Data Controller confirmation as to whether or not personal data concerning them are being processed and, where that is the case, access to the personal data and to the following information — namely:
- which of their personal data,
- on what legal basis,
- for what purpose of processing,
- for how long
the Data Controller processes, as well as information about the recipients to whom the personal data have been or will be disclosed.
c. Right to rectification
The Data Subject has the right to obtain from the Data Controller, without undue delay, the rectification of inaccurate personal data concerning them. Taking into account the purposes of the processing, the Data Subject has the right to have incomplete personal data completed, including by means of providing a supplementary statement.
d. Right to erasure
The Data Subject has the right to obtain from the Data Controller the erasure of personal data concerning them without undue delay, and the Data Controller has the obligation to erase personal data concerning the Data Subject without undue delay where one of the following grounds applies:
- the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
- the Data Subject withdraws the consent on which the processing is based, and there is no other legal ground for the processing;
- the Data Subject objects to the processing and there are no overriding legitimate grounds for the processing;
- the personal data have been unlawfully processed;
- the personal data have to be erased for compliance with a legal obligation in Union or Member State law to which the Data Controller is subject.
e. Right to restriction of processing
The Data Subject has the right to obtain from the Data Controller restriction of processing where one of the following applies:
- the accuracy of the personal data is contested by the Data Subject, for a period enabling the Data Controller to verify the accuracy of the personal data;
- the processing is unlawful and the Data Subject opposes the erasure of the data and requests the restriction of their use instead;
- the Data Controller no longer needs the personal data for the purposes of the processing, but they are required by the Data Subject for the establishment, exercise or defence of legal claims.
f. Right to data portability
The Data Subject has the right to receive the personal data concerning them, which they have provided to a Data Controller, in a structured, commonly used and machine-readable format, and has the right to transmit those data to another controller without hindrance from the controller to which the personal data have been provided.
g. Right to object
The Data Subject has the right to object at any time, on grounds relating to their particular situation, to the processing of their personal data if, in their view, the Data Controller is not processing their personal data appropriately in relation to the purposes set out in this privacy notice. In such a case, the Data Controller shall no longer process the personal data unless it demonstrates compelling legitimate grounds for the processing which override the interests, rights and freedoms of the Data Subject, or for the establishment, exercise or defence of legal claims.
7. Data security
In order to preserve the confidentiality of personal data stored electronically by the Data Controller, we protect the data against unauthorised access, accidental destruction, damage and alteration by taking all reasonably expected precautions (password protection, backups, etc.). We do not transfer personal data to third parties, except in the mandatory cases prescribed by law. Data stored on paper is kept in a manner that prevents unauthorised access and ensures the preservation of the documents.
8. External service providers and cookies
The Data Controller uses the services of Webflow, Inc. (398 11th Street, 2nd Floor, San Francisco, CA 94103) to operate the www.budapestbakehouse.hu website. When the site loads, the service uses "persistent" cookies. Further information about the data-related activities of Webflow, Inc. is available on the service provider's website.
What are cookies? This Cookie Policy explains what cookies are and how we use them, what types of cookies we use — that is, what information we collect using cookies — how we use that information, and how cookie settings can be managed.
Cookies are small text files that store a small amount of information. They are stored on your device when you load the website in your browser. These cookies help the website function properly, make it more secure, provide a better user experience, and allow us to understand how the website performs and analyse what works well and where improvement is needed.
How do we use cookies? Like most online services, our website uses first-party and third-party cookies for various purposes. First-party cookies are mostly necessary for the website to function properly and do not collect any personally identifiable data.
The third-party cookies used on our website serve primarily to help us understand how the website performs, how you interact with our site, to keep our services secure, to display relevant advertising, and generally to provide a better, improved user experience and to speed up your future interactions with our website.
You can change your cookie settings at any time by clicking the "Cookies" link in the footer. This allows you to view the cookie consent banner again and change your preferences, or withdraw your consent immediately.
In addition, different browsers offer different methods for blocking and deleting the cookies used by websites. You can block or delete cookies by changing your browser settings. Below are links to the support documents on managing and deleting cookies for the most popular browsers:
- Chrome: https://support.google.com/accounts/answer/32050
- Safari: https://support.apple.com/en-in/guide/safari/sfri11471/mac
- Firefox: https://support.mozilla.org/en-US/kb/clear-cookies-and-site-data-firefox?redirectslug=delete-cookies-remove-info-websites-stored&redirectlocale=en-US
- Internet Explorer: https://support.microsoft.com/en-us/topic/how-to-delete-cookie-files-in-internet-explorer-bca9446f-d873-78de-77ba-d42645fa52fc
- Microsoft Edge: https://support.microsoft.com/en-us/windows/manage-cookies-in-microsoft-edge-view-allow-block-delete-and-use-168dab11-0753-043d-7c16-ede5947fc64d
If you use a different browser, please visit that browser's official support page.
9. Enforcement of rights
In the event of unlawful processing, the Data Subject may bring civil proceedings against the Data Controller. Such cases fall within the jurisdiction of the Budapest-Capital Regional Court (Fővárosi Törvényszék). At your choice, proceedings may also be brought before the regional court of your place of residence. You may also submit a report or complaint to the Hungarian National Authority for Data Protection and Freedom of Information (www.naih.hu, 1055 Budapest, Falk Miksa u. 9-11, telephone: +36-1-391-1400, email: ugyfelszolgalat@naih.hu) on the grounds that an infringement has occurred in connection with the processing of personal data, or that there is an imminent risk of such an infringement.
10. Final provisions
a. In the event of a request from an authority or from another body based on a statutory obligation, the Data Controller may be required, or may be obliged, to disclose data. In such cases, the Data Controller endeavours to disclose only such personal data, and only to such an extent, as is strictly necessary in view of the disclosure obligation.
b. In matters not regulated in this notice, the provisions of Act CXII of 2011 on Informational Self-Determination and Freedom of Information and of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 shall apply to the processing.
c. The Data Controller reserves the right to amend this privacy notice. Any amendment to the notice will be published on our website; any such amendments take effect only after publication.
This privacy notice is effective from 17 August 2026.
Budapest, 17 August 2026.