At CEU Residence and Conference Center (address: 1106 Budapest, Kerepesi ut 87, Hungary) (hereinafter CEU Center) we place great emphasis on the protection of your personal information and compliance with the EU General Data Protection Regulation (GDPR)*. This Privacy Notice relates to the collection, use, transfer, and retention of your personal data by CEU Center.
*Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.
1. Who are we and what we do
CEU Center is a residence and conference center operated by CEU Oktatási-Szolgáltató Nonprofit Kft. (seat: 1051 Budapest, Nador u. 9.). CEU Center provides housing and event facilities, related services for students, alumni, faculty, staff, and external guests and partners of CEU Center, Central European University and Közép – európai Egyetem.
In order to provide services and to comply with our legal obligations, CEU Center maintains and processes personal data collected during the course of our relationship with students, alumni, faculty, staff, and external guests and partners. The majority of the information we hold is obtained directly from you. We always aim to keep your details up to date and secure.
For further information about our data protection policy please see: https://documents.ceu.edu/documents/p-1805.
2. Contact details of the Data Controller
CEU Oktatási-Szolgáltató Nonprofit Kft.
Nador u. 9.
Phone: + 36 1 3273000
3. Contact details of the Data Protection Officer
Dora Sarosi, Director, CEU Residence and Conference Center
Kerepesi ut. 87.
Phone: + 36 1 3273000
4. What is the purpose for processing your data?
Your data is used by CEU Center for the purpose of providing housing and event services for you. More specifically, we use your data to:
- Comply with a legal obligation to which we are a subject
- Processing your bookings and cancellations
- Delivering services requested by you
- Verifying your identity when required
- Communicating with you about the services you required
- Implement and enforce our general terms and conditions of business or other agreements concluded with you
- Enable our suppliers and service providers to carry out certain functions on our behalf
- Administering financial operations
- Keep internal records, including the management of feedback and other meaningful interactions
- Perform administrative processes (e.g. processing your requests, payments, or event registrations you have made).
5. What is our legal basis for processing your data?
As part of our work, we process and store personal information relating to students, faculty, staff, alumni and external partners and we therefore adhere to the applicable data protection rules. We take our responsibilities under these rules seriously and ensure the personal information we obtain is held, used, transferred and processed in accordance with the applicable data privacy rules. CEU Center processes the information outlined in this Privacy Notice in pursuit of our legitimate interests in:
- Communicating with students, faculty, staff, alumni, external partners;
- Providing services to students, faculty, staff, alumni, external partners;
- Ensuring the security of our premises;
- Enabling CEU to achieve its strategic and operational goals.
We may pursue these legitimate interests by contacting you by telephone, email, post, or social media. Information about how you can manage the ways that we contact you, including how to opt out from some or all contact from CEU Center, is outlined in the ‘Your rights’ section below.
Although CEU Center relies on legitimate interest as the legal basis for processing where this is not overridden by the interests and rights or freedoms of the data subjects concerned, it recognizes that it is not the only lawful ground for processing data. As such, where appropriate, CEU Center will sometimes process your data on an alternative legal basis – for example, based on a legal obligation (when reporting may be required to the Hungarian or American authorities, for instance) or when you give your explicit consent to us to do so.
6. What kind of personal data do we collect?
CEU Center maintains records of all students, faculty, staff, alumni and external partners who have used or are currently using its facilities. If we become aware that your personal data has changed we will update our records to reflect this. In subsequent instances where we provide for example your name (e.g. a report to the authorities) we will use your current name alongside any previous names (such as your maiden name) to ensure you can be identified correctly. The personal data we store and process, the majority of which is given to us by you but some of which we may obtain from other sources, may include:
- Name, title, gender, date of birth, nationality, visa/residence permit number, passport or ID number;
- Contact details including postal address, email address, phone number;
- Check in check out dates;
- Credit card details;
- Family and spouse/partner details;
- Medical/health status information;
- Records of communications sent to you by CEU or received from you;
7. Who receives your information?
CEU Center and CEU offices work closely together to provide a coordinated approach. Any transmission of data between CEU Center and CEU units is managed through agreed processes which comply with relevant data protection legislation.
Unless we have a legal obligation to do so, we will not disclose your data to individuals, organizations, or other entities outside CEU Center other than those who are acting as agents and data processors working on our behalf.
For the purposes set out in section 4, we may need to pass your information to our third-party service providers, agents, subcontractors, CEU Center’s related organizations for the purposes of completing tasks and providing services to you on our behalf. However, with all external entities with whom data is shared, we share only those data needed to perform the specific service and require a contract and/or confidentiality and non-disclosure agreement to be signed before any data transfer—requiring them to keep your information secure and not to use it for their own purposes. We will not sell or rent your information to third parties.
When you are using our secure online reservation system your reservation is processed by a third-party reservation processor specializing in the secure processing of hotel room reservations worldwide and credit/debit card transactions. We do not retain credit card information for future use.
Specific third parties we work with include:
- Microsoft Office 365: Based in the US, with CEU’s data stored within EU in datacenters located in Amsterdam and Dublin. Software As A Service which provides CEU’s email and document management.
- Booking.com: Based in the Netherlands, Booking.com provides an online reservation platform on our website www.ceucenter.hu
- Hostware: Based in Hungary, this company provides the hotel software and support for our daily operation
- C3: Based in Hungary, C3 provides domain registration for our website www.ceucenter.hu
- SmartMe building technologies: Based in Hungary, this company provides the maintenance of security cameras.
- Assa Abloy Tesa: Based in Hungary and in Sweden this company provides the hotel access system
- In-Kal Zrt: Based in Hungary this company provides security services
- Regulators and other authorities acting as processors based in the US and Hungary who require reporting of processing activities in certain circumstances.
We require all third parties to respect the security of your personal data and to treat it in accordance with the law.
8. How long will your information be held?
We keep your personal information up to 5 years or as long as legally required.
9. What are your rights?
You have a right
- to access your personal information,
- to object to the processing of your personal information,
- to rectify,
- to erase and
- to restrict processing your personal information.
If you wish to exercise any of these rights, please email email@example.com or write to us at CEU Data Protection Officer, Kerepesi ut 87, 1106 Budapest, Hungary. CEU Center will make every effort to fulfill your request to the extent allowed by law and will respond in writing within 30 days of receiving your request.
Should you wish to request help from the relevant national authority, their details are as follows:
National Authority for Data Protection and Freedom of Information (1125 Budapest, Szilágyi Erzsébet fasor 22/c)
10. Security of your information
We are committed to holding your data securely and treating it with sensitivity. All data are held securely and in accordance with the relevant data privacy laws and our internal policies. We do not sell to or trade your data with any other organizations. For further details please see our Data Protection Policy referred to above in Point 1.
Although most of the information we store and process stays within Hungary, some information may be transferred to countries outside the European Economic Area (EEA). This may occur if, for example, one of our trusted partners’ servers are located in a country outside the EEA. Where these countries do not have similar data protection laws to the European Union, we will take steps to make sure they provide an adequate level of protection in accordance with EU data protection law.
11. Future changes
If our information policies or practices change at some time in the future, we will post the changes on our website among our Official Documents (https://documents.ceu.edu/).
Last updated on: May 24, 2018