Privacy Policy
This English text is a translation of the Hungarian Privacy Policy (Adatkezelési Tájékoztató). In the event of any discrepancy, conflict, or difference in interpretation between this translation and the Hungarian version, the Hungarian version shall prevail and be the sole authoritative text.
Rezit online appointment booking (hereinafter: the “Service”) is a cloud-based online appointment booking system. DavenTech Solutions Kft. (hereinafter: the “Provider”) is the data controller and service provider, and also acts as a data processor for Users of the Service.
Users of the Rezit online appointment booking system
- Visitors: visitors who access our website and do not wish to use our services either as Users or as Appointment Bookers.
- Users or Customers: natural persons who, as directly or indirectly identifiable individuals, create an appointment booking system through registration by themselves or their representative and use the Service to manage their appointments. For the purposes of data processing concerning Appointment Bookers, Users qualify as data controllers.
- Appointment Bookers: persons who book an appointment for a specific service in a User’s system and, by making a booking on the User’s website, submit their personal data to our company’s system, where we act as a data processor.
The Rezit online appointment booking system collects and processes the personal data of its Users for the purposes and to the extent described below:
I. All Users (Visitors, Users, Appointment Bookers)
When visiting our website, Visitors transmit technical data from their devices to the web servers of https://rezit.hu/.
A.) Cookie management
1. The Provider’s website and the Appointment Booking System use cookies. Cookies are text files stored by your browser on your hard drive. Their content includes the websites and advertisements you have visited and searched for. However, cookies do not contain personal data such as names, addresses, email addresses, etc. Website visitors use cookies, for example, to access information available on the site.
2. No special browser settings are required to download cookies to your computer. By default, your browser accepts cookies and stores them in a list (e.g. “Temporary Internet Files”), as this does not pose a risk. If you do not want the operator to use cookies, you can disable cookie acceptance in your web browser. For further information, consult your browser’s help documentation.
3. If you accept cookies, they will be stored on your computer unless you delete them earlier. Please note, however, that declining cookies may result in limited functionality of our website.
4. Please note that while using the website, your device may also receive third-party cookies to help us share content on social media, provide traffic statistics, or support our marketing activities.
Cookies and similar technologies used by the Provider in connection with its website and the Appointment Booking System:
- Proprietary cookie consent manager
- OpenPanel (self-hosted analytics)
- Meta Pixel
5. If you do not wish to accept certain types of cookies, you can configure your browser not to permit unique identifiers or to warn you when a website attempts to send a cookie. Please consult your web browser’s guide or help documentation to learn more about these functions and adjust your cookie settings.
6. By using the Service, the User acknowledges that restricting cookies may cause certain website functions to become unavailable.
B.) Our data processors
Oracle Cloud Infrastructure
We use Oracle Cloud Infrastructure cloud services to operate the Service. The servers are located within the European Union in Frankfurt, Germany.
Data retention period: see the section concerning the processing of data recorded in the appointment booking system.
OpenPanel (self-hosted)
We collect technical and usage data about website visits and use of the Service through our self-hosted OpenPanel analytics system. OpenPanel data is not transferred to a separate analytics provider; it is processed within our Oracle Cloud Infrastructure system located in Frankfurt, Germany.
Data retention period: 1 year.
Cookie consent management (proprietary solution)
Consent to the use of cookies and similar technologies is recorded and stored using the Provider’s own solution; no separate consent management provider is used for this purpose.
Retention period: 6 months.
Meta Pixel (GDPR)
We use Meta Pixel to track user interactions on the website and in the application, helping us improve our services and provide personalized content. This tracking technology collects data such as page views, actions performed, and other browsing information, which we share with Meta to improve advertisements and the user experience.
Meta Platforms, Inc.
1 Hacker Way, Menlo Park
California 94025
USA
Retention period: 180 days
II. Users (Customers)
A.) Data processing related to registration, creation, and maintenance of the appointment booking system
Legal basis: processing is necessary for the performance of the contract concluded when the User or their natural-person representative registers for the Service, completes the registration form, and selects the checkbox indicating acceptance of the Privacy Policy (Article 6(1)(b) GDPR).
Purpose: performance of the agreement between the Customer and the Provider, including creating a new appointment booking system for the User with default settings, identifying the User, enabling communication, and providing information about functions and services.
Data processed: name, email address, password, telephone number, appointment booking system identifier, and data provided while configuring the appointment booking system (e.g. opening hours, services, language settings, etc.).
B.) Customer support-related data processing (product support)
Legal basis: the User’s explicit consent given when completing the registration form.
Purpose: proactive support for registered Users, including assistance with system setup, customer satisfaction, assessment of special requirements, responding to incoming customer calls, supporting Users in the use of the system, complaint handling, and other general contact functions.
Data processed: name, telephone number, non-personal customer support notes concerning requests, questions, and technical issues, as well as data provided during registration (see above).
Duration of processing: see the sections concerning processing related to registration and creation of the appointment booking system.
C) Our data processors
Oracle Cloud Infrastructure Email Delivery
Transactional emails from the Service are sent through Oracle Cloud Infrastructure Email Delivery. During email delivery, the recipient’s email address, the message content, and technical data related to delivery are processed.
Data retention period: 30 days.
MailerLite
Product update emails are sent using MailerLite (GDPR compliance). Data processed: name, email address, language.
MailerLite, Inc., Delaware corporation
548 Market St., PMB 98174
San Francisco, CA 94104-5401
United States
Data retention period: for the duration of the Service or until the data subject withdraws consent (requesting account deletion). Consent may be withdrawn using the link at the bottom of the email or by sending an email to kapcsolat@rezit.hu.
Grafana Cloud
We use Grafana Cloud to monitor application operation and investigate errors. This may involve processing software errors detected during use, technical log and diagnostic data, and technical data associated with the relevant device and network connection.
Data retention period: 14 days.
Szamlify
Our invoices are issued, invoice data is stored, and payment status is tracked in the Szamlify system. Data processed: billing name, billing address, payment method and associated data, email address, tax number.
Data retention period: issued invoices are retained for 8 years pursuant to Section 169(2) of Act C of 2000 on Accounting.
Stripe and Paypercut
Bank card payments are processed through the Stripe or Paypercut online payment system, as selected by the User. Bank card details, in particular the full card number, expiry date, and CVC code, are processed directly by the selected payment provider and are not stored by Rezit. Rezit receives and processes the payment result, status, and associated transaction identifier.
D) Access to Google Calendar data (optional function)
Rezit provides optional, one-way Google Calendar synchronization. When enabling the function, the User selects an existing Google calendar to which Rezit sends booking events.
Rezit requests permission to view the names of the User’s available Google calendars in order to select the target calendar, and to create, modify, and delete events in the selected calendar. Rezit does not read existing personal events from Google Calendar and does not use them to check for booking conflicts.
Rezit stores the identifier and time zone of the selected Google calendar to provide synchronization.
III. Appointment Bookers
A.) Processing of data recorded in Users’ appointment booking systems
Legal basis: when a natural-person Appointment Booker makes an appointment on a User’s website without registration, provides their personal data, and selects the checkbox indicating acceptance of the privacy notice, the data subject consents to the processing of their personal data (Article 6(1)(a) GDPR). With regard to this data, the Provider acts as data processor and the User acts as data controller.
Purpose: supporting the User in managing appointments, receiving customers, and carrying out practical and organizational tasks related to service provision, such as preparing to provide the service, identifying customers arriving at scheduled times, providing information about possible appointment modifications or cancellations, communication and follow-up, and processing technical information automatically transmitted by the browser (e.g. device type, operating system, language settings, screen size and type).
Data processed: full name, email address, telephone number, appointment booking system identifier, selected service provider, service selected for the booking, selected appointment time, arrival time, any other data requested by the User on the booking form, the IP address of the User recording the booking, technical information automatically received from the browser (e.g. device type, operating system, language setting, screen size and type), and, for bookings made through Facebook Messenger, the Facebook profile identifier and name.
Duration of processing: data is stored in the appointment booking system database for no longer than 1 year after the last booked appointment associated with the User’s customer.
B.) Appointment booking as a registered guest (with a Rezit Guest Account)
Guests may register a personal Rezit Guest Account, enabling them to book appointments with different service providers more easily and quickly.
Legal basis: the data subject’s consent (Article 6(1)(a) GDPR).
Purpose: simplifying the booking experience for returning guests, tracking previous bookings, accessing booking history, and managing appointment-related communication (e.g. reminders, modification options, cancellations, and billing information). The Guest Account enables guests to book appointments more efficiently with multiple service providers using the same data.
Data processed: name, email address, telephone number, and billing details (if provided by the User).
Duration of processing: until the Guest Account is deleted or for no longer than 2 years after the last login, unless legislation requires a longer retention period (e.g. for billing data).
C.) Children’s personal data
Rezit does not intend to request personal data from persons under 16 years of age. If Rezit nevertheless obtains such data, DavenTech Solutions Kft. will delete the child’s or minor’s data from the database without delay.
D.) Our data processors
Meta Platforms (Facebook Messenger)
The Facebook Messenger integration enables the Appointment Booker to complete the entire booking process within the service provider’s Messenger conversation. In this process, Meta Platforms processes the Appointment Booker’s Facebook profile identifier and name, email address, telephone number, and the selected service and appointment data.
Rezit processes the Facebook profile identifier temporarily and solely during the booking process, deleting it once the booking is completed. The retention period defined for booking data applies to the remaining data of the completed booking.
Google
If the Customer with whom the Appointment Booker made the booking uses the Google Calendar synchronization function, the guest’s name, the booked service, and the appointment start time and duration are synchronized with the Google calendar selected by the Customer. Rezit does not transfer the Appointment Booker’s email address, telephone number, or custom form responses to Google Calendar.
Google Ireland Limited (Company registration number: 368047 / Tax number: IE6388047V)
Gordon House, Barrow Street
Dublin 4
Ireland
https://policies.google.com/terms
The Provider reserves the right to amend and expand the list of data processors where necessary, taking into account that Users may request information from the Provider at any time regarding the identity and contact details of data processors. The Provider undertakes to ensure that the data processors it engages fully comply with the data protection rules in force at the relevant time.
IV. Liability provisions
The Provider (Rezit) is responsible for the proper operation of the technical infrastructure and the secure storage of data.
V. Data transfers
The Provider transfers personal data only to the data processors and recipients identified in this notice, for the purposes described and to the extent necessary to provide the Service. In addition to the data processors, Appointment Bookers’ personal data is transferred to the User with whom the appointment was booked. Any other transfer will take place only on the basis of a statutory obligation, an official request, or the data subject’s consent given on an appropriate legal basis.
VI. Data security
1. The Provider takes all necessary security, organizational, and technical measures to ensure the highest level of security for personal data and to prevent its unauthorized alteration, destruction, or use.
2. The Provider takes all necessary measures to ensure data integrity, meaning the accuracy and completeness of the personal data it controls and/or processes.
3. The Provider takes appropriate measures to protect data, in particular against unauthorized access, alteration, transfer, disclosure, deletion, or destruction, as well as accidental destruction, damage, and inaccessibility resulting from changes in the technology used.
4. The Provider makes every effort to preserve the authenticity and confidentiality of the data processed and to ensure that it remains available to data subjects and authorized persons.
5. To fulfil the obligations above, the Provider reserves the right, upon detecting a security vulnerability in its system, to inform its customers and partners and simultaneously restrict access to the Provider’s system, services, or certain functions until the vulnerability has been remedied.
VII. Rights of the data subject
1. Under applicable Hungarian and European Union data protection rules, data subjects are entitled to:
- obtain confirmation as to whether their personal data is being processed and, where such processing is taking place, request access to that personal data. This includes access to information concerning the purposes of processing, the categories of personal data processed, and the recipients or categories of recipients to whom their personal data has been or will be disclosed (Article 15 GDPR);
- request that the data controller provide them with a copy of their personal data;
- request the rectification of inaccurate personal data or completion of incomplete personal data (Article 16 GDPR);
- request erasure of their personal data (Article 17 GDPR);
- request restriction of processing of their personal data. In this case, processing of the data may be limited to certain purposes (Article 18 GDPR);
2. The Customer and the Provider make every effort to fulfil requests relating to data processing. However, the Customer and the Provider may refuse to erase data that is strictly necessary to fulfil legal obligations incumbent upon them or to enforce their legitimate interests. The Customer and the Provider endeavour to comply with any request to rectify the data provided or relating to data protection activities as soon as possible and, where feasible, within one week of receiving the relevant request.
3. In addition to the rights set out above, Users have the right under Article 21 GDPR to object to the processing of their personal data in the cases specified by the GDPR (for example, where processing is carried out for direct marketing purposes or where the legal basis for processing is the legitimate interests of third parties). If a User objects, the Customer or Provider may no longer process their personal data unless it demonstrates compelling legitimate grounds for the processing that override the User’s interests, rights, and freedoms, or that relate to the establishment, exercise, or defence of legal claims.
VIII. Right to lodge a complaint and seek judicial remedy
By accepting the Privacy Policy, the data subject declares that they have read and understood its content.
If you become aware that your rights have been infringed during the processing of your data, you have the following options:
- contact the Customer or the Provider directly;
- lodge a complaint with the competent supervisory authority or the Hungarian National Authority for Data Protection and Freedom of Information (hereinafter: “NAIH”). NAIH contact details: registered office: H-1055 Budapest, Falk Miksa utca 9-11; postal address: 1363 Budapest, Pf. 9; telephone: +36-1-391-1400; email: ugyfelszolgalat@naih.hu
- take legal action against the unlawful processing of your personal data and breaches of data security. You may be entitled to compensation and damages as provided by law. For information on court jurisdiction and contact details, please visit www.birosag.hu.
IX. Declaration
1. The Provider, as Data Controller and Data Processor, recognizes the content of this Privacy Policy as binding upon itself.
2. The Provider undertakes to ensure that its processing of data relating to the Service and its operation complies at all times with this document and applicable legislation, in particular Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation).
3. The Provider declares that, with regard to Users booking appointments, it acts as a data processor for Customers and, in that capacity, is not responsible for Customers’ instructions. The Provider confirms that the personal data of Users booking appointments is processed in the Customers’ interests and in the manner determined by them.
4. The Provider publishes this information on the https://rezit.hu website (hereinafter: the “Website”). Amendments to this Privacy Policy take effect upon publication on the Website.
Updated: September 1, 2026.