Skip to content
Cross Country Valley

Legal

Privacy Policy

Controller

The controller for the processing of personal data on this website within the meaning of Art. 4(7) GDPR is: BALATON-ENDURO Kft. 8300 Tapolca, Külterület hrsz 0124/1., Hungary Email: info@ccv-tapolca.com Phone: +36 30 692 3357 Processing is governed by the General Data Protection Regulation (Regulation (EU) 2016/679) and by Hungarian Act CXII of 2011 on informational self-determination and freedom of information (Infotv.). No data protection officer has been appointed. The conditions under Art. 37 GDPR are not met: our core activity is operating a sports facility, not large-scale monitoring of individuals or processing of special categories of data.

Cookies and local storage

Visiting this website sets no cookies and stores no data in your device's local storage. No advertising or social media services are embedded, and there is no cross-device tracking or profiling. For anonymous audience measurement we use the self-hosted analytics tool Umami (see the next section), which works without cookies. Since neither cookies nor your device's local storage are used and no personal data is stored, a consent banner is not required. Fonts are served from our own server. No third-party content is loaded when you open the page.

Audience measurement with Umami

For anonymous, statistical evaluation of website usage we use Umami, a privacy-friendly analytics tool that we host on our own infrastructure within the European Union. No data is passed to third parties. Umami works without cookies and without accessing your device's local storage. It records only aggregated information such as pages viewed, referring page, approximate region of origin, and browser and device type. To distinguish visits, an anonymised, non-reversible hash is derived from the IP address and browser signature; the IP address is processed only briefly and is not stored. The hash changes daily, so recognition across days or devices is not possible. The legal basis is our legitimate interest in a needs-based, statistical evaluation of reach (Art. 6(1)(f) GDPR). The website's internal admin area is excluded from measurement. Session recording and heatmaps are not enabled.

Map display (Google Maps)

A Google Maps map is embedded on the site. It does not load automatically: by default you see only a preview area with a notice. Only when you actively click “Load map” is the map loaded from Google, transmitting your IP address and possibly further data to Google (Google Ireland Limited; processing by Google LLC in the USA cannot be ruled out). Without your click, no transmission takes place. The legal basis is your consent (Art. 6(1)(a) GDPR), given by clicking. You can withdraw it by reloading the page and not activating the map again; transmissions already made remain unaffected. The third-country transfer section below applies accordingly.

Reservation requests

For a reservation we process your name, email address, phone number and the details of your request: period or date, number of people, parking spaces, track tickets and electricity connection, and for training additionally age, motorcycle, level and discipline. You may optionally add a message; only we see its content. Purpose: processing, confirming and fulfilling your reservation. Legal basis: Art. 6(1)(b) GDPR (pre-contractual measures and performance of a contract). Providing this information is voluntary, but without it we cannot process the reservation. We derive the country of origin from your phone number internally so that we can reply in the right language. To protect against automated submissions we limit the number of submissions per internet connection and use a field invisible to you. For this limit your IP address is held briefly in the server's memory. It is not written to the database, not linked to your reservation, and discarded after ten minutes at the latest. The legal basis is our legitimate interest in protection against misuse (Art. 6(1)(f) GDPR).

Contact form

Via the contact form we process your name, email address, phone number and the content of your message. Purpose: answering your enquiry. Legal basis: Art. 6(1)(b) GDPR for contract-related enquiries, otherwise Art. 6(1)(f) GDPR (legitimate interest in communicating with prospective customers). The message is delivered to our email mailbox; it is not stored in the website database.

Data of children and young people

We also offer training for children and young people. For a training request we process the participant's age in order to assess group, motorcycle class and safety requirements correctly. Legal basis: Art. 6(1)(b) GDPR. Reservations for minors may only be made by their legal guardians. The information is not used for advertising and is deleted together with the other reservation data. If you find that a child has submitted data to us without consent, let us know. We will delete it immediately.

Photo and video recordings on the premises

Photos and videos of riding activity are taken on the premises and used to present the facility on this website and on our social media channels. Individual people may be identifiable in them. Purpose: presenting and promoting the facility. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in the public presentation of a sports business). For recordings in which a person is the focal point, and for children, we rely on explicit consent (Art. 6(1)(a) GDPR); for children, that of their legal guardians. We display a notice about recordings on site. You can object to publication at any time, informally by email to info@ccv-tapolca.com or directly on site to a member of staff. We will then remove the recording in question from our channels.

Retention period

Reservation and contact data are deleted 24 months after the respective stay or training date, unless statutory retention obligations require otherwise. Deletion takes place regularly and automatically. Documents subject to tax or commercial retention obligations (such as invoices and receipts) are kept for the period prescribed by law and deleted thereafter. Payment is made on site. No payment data is collected via this website.

Server logs

When you open the website, the hosting provider processes technically necessary connection data, including IP address, time, requested address and browser type. Purpose: secure and stable operation and prevention of misuse. Legal basis: Art. 6(1)(f) GDPR (legitimate interest). No statistical evaluation of browsing behaviour takes place. Logs are overwritten automatically after a short period.

Recipients and processors

Your data is not sold and not passed to unauthorised third parties. The processors used are named below: • Hosting of the website and database server: Hostinger International Ltd., server location Germany, European Union. The database and website run on our own, self-operated server; no additional database provider is involved. • Sending confirmation and cancellation emails and the mailbox used for correspondence: Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (Google Workspace). Agreements under Art. 28 GDPR are in place with all processors. Beyond that, we only disclose data where we are legally obliged to do so or where it is necessary to enforce our rights, for example to our tax advisor, authorities or legal representation.

Transfers to third countries

We use Google Workspace to send confirmation and cancellation emails and for our mailbox. The contracting party is Google Ireland Limited (Ireland); processing by Google LLC (USA) and further sub-processors outside the EU cannot be ruled out. Basis: the European Commission's adequacy decision on the EU-US Data Privacy Framework (Art. 45 GDPR), supplemented by the standard contractual clauses in Google's data processing agreement (Art. 46(2)(c) GDPR). A copy of the clauses can be requested from us. The same applies to the map display if you activate it by clicking. The website itself, its database and the audience measurement run on our own server within the European Union. Booking and contact data sent there only leave the EU to the extent described above for sending emails.

No automated decision-making

Automated decision-making, including profiling within the meaning of Art. 22 GDPR, does not take place. Every reservation request is decided by a person.

Your rights

You have the right to information about the data stored about you (Art. 15), to rectification (Art. 16), to erasure (Art. 17), to restriction of processing (Art. 18) and to data portability (Art. 20 GDPR). Where we rely on a legitimate interest, you may object to the processing at any time (Art. 21 GDPR). You may withdraw consent given at any time with effect for the future (Art. 7(3) GDPR). Simply write to info@ccv-tapolca.com. We reply within the statutory period of one month. You also have the right to lodge a complaint with a supervisory authority, in particular the Hungarian data protection authority: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) 1055 Budapest, Falk Miksa utca 9–11., Hungary Postal address: 1363 Budapest, Pf. 9. Email: ugyfelszolgalat@naih.hu Web: naih.hu You may also contact the supervisory authority where you habitually reside.

Data security

The website is served exclusively over encrypted HTTPS. Access to the internal admin area is restricted to individually authorised accounts and protected by password. Access to the database is limited to what is necessary for operation. We apply technical and organisational measures under Art. 32 GDPR to protect your data against loss, manipulation and unauthorised access.

Version and changes

This policy describes the technical state of this website. It will be adjusted as soon as the services used change. Effective: 1 August 2026