Privacy Policy
Last updated: 23 August 2025 · Website: accesstoparis.com (the "Website")
Owner / Data Controller: Andras Toth EV (individual entrepreneur, Hungary) · Tax number: 57631556-1-36
Contact: info@accesstoparis.com
1) About this Policy
This Privacy Policy explains how we collect, use, disclose, and protect personal data when you visit or buy tickets on the Website, contact us (e.g., email), or otherwise use our services (collectively, the "Services"). We process personal data as a controller under the EU General Data Protection Regulation (GDPR) and applicable Hungarian/EU laws. If you have questions about this Policy or your rights, contact us at the email above.
2) What data we collect
We only collect data that is necessary for providing the Services and complying with legal obligations:
- Identification & contact data – name, email address, phone number, billing country/address (if provided), company/VAT ID (if provided).
- Order & ticket data – product(s) purchased, booking date/time, quantity, price, currency, order ID, delivery method (e.g., PDF by email), refund/cancellation history.
- Payment data – payment method, partial card data (last 4 digits, expiry month/year), transaction ID, fraud checks. We never store full card numbers; these are processed primarily by our payment processor.
- Communications – messages you send us via email or the contact form, and related metadata.
- Technical & device data – IP address, device and browser type, operating system, referral source, cookie identifiers, time zone, and basic diagnostics/logs.
- Marketing preferences – newsletter/marketing opt-in status, unsubscribe status, and related consent records.
3) How we collect data
- Directly from you when you browse the Website, make a booking, create/update your order, or contact us.
- Automatically via cookies, pixels, and similar technologies (see Cookies below).
- From service providers (e.g., payment processor for fraud/risk signals and transaction confirmations).
4) Why we use your data (purposes & legal bases)
- Provide the Services – process and confirm orders; issue and deliver tickets; handle bookings, changes and cancellations. Legal basis: contract necessity (GDPR Art. 6(1)(b)).
- Payments & fraud prevention – process payments, refunds and chargebacks; verify transactions; prevent fraud/abuse. Legal basis: contract necessity (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)). Our payment processor may also act as an independent controller for certain antifraud/compliance checks.
- Customer support – respond to messages; resolve complaints and service issues. Legal basis: contract necessity and legitimate interests.
- Legal & tax compliance – maintain invoices and accounting records; comply with consumer protection and EU/HU tax rules. Legal basis: legal obligation (Art. 6(1)(c)).
- Security & diagnostics – operate hosting, logging and security; detect and remediate incidents. Legal basis: legitimate interests (Art. 6(1)(f)).
- Analytics & site improvement – measure traffic and conversions; improve user experience. Legal basis: consent (Art. 6(1)(a)) for non-essential cookies/analytics; you can withdraw consent at any time via the cookie banner.
- Marketing communications – send newsletters or special offers. Legal basis: consent (Art. 6(1)(a)); or soft opt-in where permitted. You can opt out at any time.
For non-essential cookies and tags (including Google Analytics and Google Ads tags) we rely on consent (analytics_storage / ad_storage = consent under GDPR Art. 6(1)(a)). Strictly necessary cookies rely on legitimate interests and/or contractual necessity where they are required to provide the Services (e.g., checkout, security). Where we rely on consent, you can withdraw it at any time. Where we rely on legitimate interests, you have the right to object.
5) Cookies & similar technologies
- Strictly necessary cookies – required for core site functions (e.g., checkout, security, storing your cookie choice). These run without consent.
- Analytics/performance cookies – help us understand how visitors use the site. These run only with your consent.
- Marketing/advertising cookies – for ad measurement and personalization. These run only with your consent.
We use Google Analytics and may use Google Ads tags. We only activate non-essential cookies after your consent (Google Consent Mode v2). You can change or withdraw your consent at any time via the "Cookie settings" link in the footer. For details, see our Cookie Policy.
6) Who we share data with
- Payment processor(Viva.com – Viva Payment Services S.A., Greece): card processing, fraud/risk management, and refunds. Card details are entered on Viva.com's own payment page and never reach this website.
- Hosting & infrastructure: web hosting, CDN, and security services.
- Email ticket delivery: email service provider(s) to send order confirmations and PDF tickets.
- Analytics & tag management: Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland) — analytics and advertising tags, only with your consent. Cookies are used for personalized and non-personalized ads. How Google uses data when you use our site: business.safety.google/privacy.
- Professional advisors & authorities: accountants, auditors, or regulators/courts when required by law.
We do not sell your personal data.
7) International data transfers
Some providers may process data outside the EEA/UK (e.g., in the US). Where this happens, we rely on an adequacy decision (if available) or on Standard Contractual Clauses (SCCs) and implement supplementary safeguards as needed.
8) Data retention
- Orders, invoices, and payment records: retained for up to 8 years to comply with Hungarian/EU accounting and tax laws.
- Customer support communications: typically 3 years after resolution.
- Marketing data: until you unsubscribe or after 24 months of inactivity.
- Analytics data: per tool settings (commonly 14–26 months).
- Server logs & security records: typically 12 months.
9) Your privacy rights (EEA/UK)
- Access your personal data and get a copy.
- Rectify inaccurate or incomplete data.
- Erase data (right to be forgotten) where the GDPR allows.
- Restrict processing in certain cases.
- Object to processing based on legitimate interests or to direct marketing.
- Portability of data you provided to us.
- Withdraw consent at any time (for consent-based processing).
To exercise these rights, contact us at info@accesstoparis.com. If you believe your rights have been violated, you can lodge a complaint with your local supervisory authority. In Hungary, this is the National Authority for Data Protection and Freedom of Information (NAIH).
10) Security
We implement technical and organizational measures to protect personal data, including encryption in transit (TLS), access controls, least-privilege policies, and regular monitoring. However, no online service can guarantee absolute security.
11) Children
Our Services are intended for adults and general audiences. We do not knowingly collect personal data from children under 16.
12) Automated decision-making
We do not use automated decision-making that produces legal or similarly significant effects about you without human involvement. Our payment processor may perform automated fraud/risk checks; if such checks affect your transaction, you can contact us to request a human review.
13) Third-party links
The Website may contain links to third-party sites. We are not responsible for their privacy practices.
14) Changes to this Policy
We may update this Policy to reflect legal, technical, or business changes. The updated version will be posted here with a new "Last updated" date.
15) Contact us
Data Controller: Andras Toth EV (individual entrepreneur, Hungary)
Email: info@accesstoparis.com
Postal address: Budapest 1143, Hungária krt. 50, Pf 122, Hungary
