Foreword
Last updated: March 2026
This Privacy Policy sets out how Ensana s.r.o. (“Ensana” or “we”) uses and protects your personal data. Ensana (or another Ensana group company, see section 5 below) is the controller of the personal data provided by guests or prospective guests when they use the ensanahotels.com website. This also applies to the processing of personal data of other groups of persons, such as guests who communicate with us through various channels, business contacts and our employees.
In the course of its business activity, Ensana requests, obtains and processes personal data from guests, prospective guests, business partners, employees and other individuals. Our goal is to provide the appropriate level of service while processing as little personal data as possible.
This Privacy Policy contains details on how we assure the protection of personal data. Most of the rules we follow are based on the General Data Protection Regulation (GDPR). However, we comply with all relevant legal requirements regarding data protection and privacy.
Although the Ensana group operates in a number of countries, the information in this Privacy Policy is generally valid and applies to the processing of personal data wherever you are. Beyond this, section 3 below also contains information about the specific conditions for processing personal data in the country in which you are located.
If you have any questions in relation to the content of this Policy or any comments or suggestions as to how we might improve it, please contact us at:
You can find your way through this Policy by clicking on the various points of the following table of contents.
Legal rights of natural persons (“data subjects”) under the GDPR
Data subjects have the following individual rights under the GDPR:
a) Right to receive transparent information
b) Right of access to your own data
c) Right to rectify inaccurate data
d) Right to erasure (“right to be forgotten”) in specific circumstances
e) Right to withdraw consent
f) Right to request restriction of processing
g) Right to object to processing
h) Right not be subject to automated decisions
i) Right to data portability
j) Right to complain to a “Supervisory Authority”
k) Right to effective judicial remedy against a controller or processor
We will respond to your requests related to any of these rights without undue delay but within a month at the most, and we will do our utmost to resolve even complicated cases within no more than three months. We will send the response to you via an electronic channel or by any other means requested by you. We will not charge a fee for the first request, but we reserve the right to charge an administrative fee for handling a request sent to us within a year, or in the case of any clearly unfounded or exaggerated request.
NB! We will need to verify your personal identity in order to be able to process your request.
If we believe that it is not necessary for us to act on your request, we will inform you in writing of the reason for our decision, as well as of the legal remedies available to you.
Apart from these rights, if you believe that Ensana has acted improperly with respect to your personal data or the protection of your data, please contact us so that we can remedy the situation and improve the service we provide to our guests. You can send a formal complaint to us by email or by post, at the addresses provided in section 1.12 “Contacting Ensana in relation to the GDPR”.
Right to receive transparent information
We will provide all information required by the GDPR to you in a concise, transparent, intelligible and easily accessible form, using clear and plain language. We will provide the information in writing or by electronic means. If you request, we can also provide this information verbally.
We help you exercise your rights as set out in section 1 below.
You will find our email and postal addresses in section 1.12 “Contacting Ensana in relation to the GDPR” below. In the sections of chapter 2 dealing with certain activities, you will also find contact details for various individual requests.
Right of access to your own data
You have the right to request confirmation from Ensana as to whether we process personal data about you and, if so, to request access to the data and to the following information:
a) Purpose of the processing
b) Categories of personal data concerned
c) Recipients to whom we have disclosed or will disclose the personal data, in particular recipients in countries outside the EU
d) The period for which the personal data will be stored
e) The fact that you have the right to request us to rectify or erase your personal data or to restrict the processing of your personal data, or to object to such processing
f) The fact that you have the right to lodge a complaint with the Supervisory Authority
g) If the personal data are not collected directly from you, then the source of these data
h) Whether there any automated decision-making is made based on the data and, if there is, understandable information regarding the logic used, as well as what significance such data processing has, and what the likely consequences of it are for you.
i) Where we send your personal data to a country outside the EU, the appropriate safeguards we have in place to protect your rights.
Right to rectify inaccurate data
If we hold inaccurate or incomplete personal data on you, you may request the rectification of such data. After receiving your request, we will correct such personal data without undue delay.
Right to erasure (“right to be forgotten”)
You have the right to have us erase your personal data and to ask us to fulfil your request without undue delay if one of the following grounds for this applies:
a) Your personal data is no longer needed in connection with the original purposes of the data processing
b) You have withdrawn your consent and thus we no longer have a legal basis for processing the data
c) The lawfulness of the data processing is based on our legitimate interests, but you claim that there is no legitimate reason for the data processing that takes precedence over your interests, rights and freedoms
d) The purpose of the data processing is direct marketing, and you object to this
e) We have been unlawfully processing your data
f) Your data must be deleted in order to fulfil the legal obligation prescribed by EU or member-state law that applies to us
g) The lawfulness of the processing of the data by us is based on the consent given by the guardian of a child, and or i. you are the guardian and the child is still under the age of consent, or ii. you are the child and are now above the age of consent. NB! We cannot erase your personal data if the data processing is necessary for the following reasons:
a) for exercising the right to freedom of expression and information;
b) fulfilment of a legal obligation that requires the processing of the personal data;
c) on the basis of public interest in the field of public health;
d) for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in so far as the request is likely to render impossible or seriously impair the achievement of the objectives of such processing; or
e) for the establishment, exercise or defence of legal claims.
Right to withdraw consent
Where you have given us consent for any processing, you have the right to withdraw consent at any time. You can do this by sending a request to the email address given in the relevant subsection of section 2 below, which lists the different activities for which we manage personal data. Alternatively, you can write to us at the address in section 1.11 below.
NB. The withdrawal of your consent does not affect the lawfulness of any processing we have already carried out.
Right to request restriction of processing
You can request that Ensana restrict the processing of your personal data if one of the following applies:
• You contest the accuracy of the personal data
• The data processing carried out by us is unlawful, but you do not agree to the erasure of the data and instead request the restriction of its use
• We no longer need the data for the original purpose, but you require the data for the establishment, exercise or defence of legal claims
• You object to our processing on the grounds that we state our legal basis as “our legitimate interests” but you claim that your “interests, rights and freedoms” override these.
If the data processing is restricted based on your objection, such personal data may only be processed with your consent, with the exception of storage, or:
a) for the establishment, exercise or defence of legal claims
b) for the protection of the rights of another person, or
c) for reasons of important public interest of the EU or of a Member State.
Where we restrict processing, we shall inform you before we lift the restriction.
Right to object to processing
You have the right to object to our processing your personal data where:
• Our basis of lawfulness for processing is “our legitimate interests” but you claim that your “interests, rights and freedoms” override these
• We process your data for direct marketing purposes, including “profiling” to the extent that this is related to the direct marketing. (Profiling is automated decision-making in which characteristics related to the financial situation, personal preferences or place of residence are analysed or predicted.) Where you make such an objection we shall no longer process your data for such purposes.
Right not be subject to automated decisions
You have the right not to be subject to the scope of a decision based solely on automated data processing that would have legal effects on you or would affect you in some other, similarly significant manner.
However, this does not apply if:
a) the decision is necessary in order to conclude or fulfil a contract between you and us, or
b) the automated process is made possible by EU or member-state law that also establishes appropriate measures to protect your rights and freedoms as well as your legitimate interests.
In case a), we must implement appropriate measures to protect your rights, freedoms and legitimate interests, including at least your right to request human intervention on our part, to express your point of view and to submit an objection to the decision.
Data portability
Pursuant to the GDPR, the data subject is entitled, under certain circumstances, to receive their personal data “in a structured, commonly used and machine-readable format”. The right includes having the personal data transmitted directly from one controller to another, where technically feasible.
If you request access to your personal data based on the above section 1.2, we will generally provide such data to you in a widely used electronic format, unless you specifically request that we send you the data in written (hard-copy) form.
Right to complain to a “Supervisory Authority”
If you believe that we have acted unfairly or unlawfully towards you pursuant to the GDPR, you can lodge a complaint with the data protection Supervisory Authority. You can find the name and contact information of the data protection authorities at the following link:
Right to an effective judicial remedy against a controller or processor
If you believe that your rights under the GDPR have been infringed as a result of the processing of your personal data in a manner not compliant with the GDPR, you have the right to effective judicial remedy.
Proceedings against the data controller or data processor must be initiated before the court of the EU Member State where the data controller or data processor operates. Such proceedings can also be initiated before the court of the EU Member State of your habitual residence.
Contacting Ensana in relation to the GDPR
In order to exercise the rights described above or in the case of a complaint addressed directly to Ensana or in the case of a general enquiry related to the GDPR or to data protection, the email address and correspondence address required for maintaining contact are as follows:
Email: [email protected]
Address: GDPR - Ensana s.r.o.; CZ- Senovázne námestí 992/8, CZ-110 00 Prague 1, Czech Republic
We will forward your request to the relevant hotel operator, as described in this Policy.
Data processing
A separate document attached to this Privacy Policy contains the list of intra-EU data transfers and controllers; data transfers to third countries are further highlighted in this Privacy Policy.
Please note that with respect to certain data processing activities described below Ensana Group entities and the respective Ensana Hotels providing the accommodation and related services act as the joint data controllers. This is to facilitate group administration, provide you with better services and does not affect your rights and our obligations in any way. Ensana Group entities and the Ensana Hotels as the joint controllers always strictly adhere to the highest standards of personal data protection and proceed in accordance with this Privacy Policy. For more information on the Ensana Group entities, please refer to section 3.
Information about data processing provisions/activities in the case of Ensana hotels in Hungary can be found here.
Booking
In the case of a room reservation made online, in person at the hotel or by telephone, we may request one or all of the following items of personal data:
Purpose of the data processing:
- The purpose of the data processing is to be able to identify the guest who made the booking, to provide the room to the right person on check-in, and to register the means of payment, in order to cover us in case the guest does not check into the hotel.
• We use your email address in the following cases:
if we need to notify you of a change affecting your booking;
ii. three days before your planned arrival, to remind you of details such as the hotel address and check-in time; and
iii. three days after your departure, to ask that you share your comments about your stay with us so that we can provide you and other guests with an even better service in the future.
• We process the data on the invoice for the purpose of fulfilling the related legal obligation
• After your departure, we will keep the data for the purpose of asserting claims or managing complaints within the limitation period stipulated under civil law.
Legal basis of the data processing:
• Specific rules may apply depending on the country in which your data will be processed (see section 3 for details). The standard period is between 5 and 10 years. Under no circumstances will we exceed the period necessary for the processing of your data.
• The legal basis of the data processing is that we need the data to fulfil a contract for room reservation. [GDPR Article 6(1)(b)]
• We process your name and your email address for up to the third day following the end of your stay in order that we can send you a post-stay email for the purpose of the “legitimate interests pursued by the controller, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject”. Our legitimate interests here are to maintain a high quality of service, and we believe that sending you the post-stay email does not affect your fundamental rights. [GDPR Article 6(1)(f)]
• We process the data on the invoice (name, address) based on our legal obligation. [GDPR Article 6(1)(c)]
• After your departure, we will retain the data based on our legitimate interest associated with the assertion of claims and the managing of complaints. [GDPR Article 6(1)(f)]
If you do not give us the data requested, we will either be unable to reserve a room for you or be unable to contact you if there is a problem.
Period of the data processing:
Processor:
For booking purposes, your personal data is processed by Virtual Zoom s.r.o. (registered office: Office center Zirkon, Sokolovská 131/86 - Karlín, 186 00 Praha 8), our data processor, who is responsible for the appropriate functioning of our CRM system and who is obliged to conduct the data processing activity in accordance with the terms of the contract between us and with the relevant statutory provisions.
Your personal data will be processed by THN (The Hotels Network, S.L., NIF B-65542714, Calle Muntaner, 262, 3º-1ª, 08021 Barcelona, Spain) as a data processor, responsible for the proper functioning of the forms, and obliged to carry out its processing activities in accordance with the contractual terms existing between us, and with the applicable legal requirements.
Data collected during the reservation process is subsequently processed within the local Property Management Systems (PMS) of the individual hotels within the Ensana network. This processing is essential for managing your stay, providing requested services, and fulfilling legal registration requirements.
For the purpose of sending out pre-stay and post-stay information emails, your data may be transferred to our processor, Servi Smart Solutions Ltd, an Isreal company that operates the Duve guest platform. As part of this, your data may also be transferred to a third country, namely Israel. Israel ensures adequate protection of personal data in accordance with Commission Decision of 31 January 2011 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of personal data by the State of Israel with regard to automated processing of personal data (which is the case here).
Other processors may be used in the country in which the processing of your data will take place (see section 3 for details).
Transfer of data outside the EU:
When you make a booking on our website you are entering data into the SynXis central reservation platform operated by Sabre GLBL Inc., a US company. Your personal data is therefore transferred to a third country (i.e. a country outside the EU). The adequacy of such data transfers is safeguarded through the application of the standard contractual clauses for international transfers. https://eur-lex.europa.eu/legal-content/HU/TXT/HTML/?uri=CELEX:32010D0087&from=en.
If you wish to exercise any of your rights referred to in section 1 in relation to the data thus provided, or you wish to contact us for any other reason in connection with the above data processing, please let us know by sending an email to [email protected].
Hotel registration cards
Scope of the data and legal basis of the data processing:
Personal data that must be provided (i.e. the guest must provide these in order to be able to use the hotel services):
• In order to fulfil our legal obligations, we record and store various identification data of our guests such as name, date of birth, details of personal ID document. The scope of the data may vary depending on the country where your data is processed and we refer you to section 3 for further information. [GDPR Article 6(1)(c)]
• In order to provide the requested services, e.g. accommodation and/or spa services (in accordance with the contract), we also process the following data: contact details, loyalty programme reference number, mode of payment, credit/debit card details, room number, number of guests. [GDPR Article 6(1)(b)]
• On the basis of the Ensana’s legitimate interest associated with the improving of its services, for three days after you leave we process your name and email address in order to ask you for your opinion on our services and thus to improve them. [GDPR Article 6(1)(f)]
• We process the data on the invoice (name, address) based on our legal obligation. [GDPR Article 6(1)(c)]
• After your departure, we will retain the data based on our legitimate interest associated with the assertion of claims and the managing of complaints. [GDPR Article 6(1)(f)]
Non-compulsory statistical data:
• For statistical purposes, the following data are processed separately from personal data: business trip, holiday.
Most of the data is completed based on the booking and the rest at the time of check-in using an ID document reader. We ask you to please always check the accuracy of your data.
Purpose of the data processing:
• Provision of hotel services, including maintaining contact with customers and improving the service.
• The purpose of recording and storing data specified by the relevant law is to ensure legal compliance.
• After your departure, we will keep the data for the purpose of asserting claims or managing complaints within the limitation period stipulated under civil law.
Period of the data processing:
• After your departure, we will keep the data for the period of limitation stipulated under civil law.• Further to that, specific rules apply depending on the country in which your data will be processed (see section 3 for details). The standard period is between 5 and 10 years. Under no circumstances will we exceed the period necessary for the processing of your data.
If you wish to exercise any of your rights referred to in section 1 in relation to the data recorded during check-in, or you wish to contact us for any other reason in connection with data recorded during check-in, please let us know by sending an email to [email protected]
Spa, health services and physical therapy
You can use the health services separately from the other services of the hotel. You can access the treatments offered by the hotel on the basis of the curative health package already requested or by selecting it on site. Before providing health-related services, an employee working in the separate section of the hotel that deals with this directs each guest to a doctor. At the doctor, you will receive a Treatment Record Card, which the doctor will fill in as follows:
• Data required for identification: name, social security number, date of birth, telephone number
• Past history: illnesses, medications, complaints, etc. The recording of health data is part of the medical treatment. The treating doctor decides which medical data needs to be recorded in accordance with the professional regulations.
The guest then shows up for the given treatment with his/her Treatment Record Card, where the staff participating in the treatment only see the minimum information required for providing the care specified on the Treatment Record Card. The detailed data on the patient will only be seen by the doctor and his/her assistant.
Purpose of the data processing:
Promoting the protection, improvement and maintenance of your health.
Legal basis of the data processing:
• with regard to the mandatory personal identification data for the use of healthcare services: The statutory requirement [GDPR Article 6(1)(c); GDPR Article 9(1)(h)];
• with regard to personal data that is not mandatory for the use of healthcare services, but deemed necessary by the doctor: Your consent [GDPR Article 6(1)(a); GDPR Article 9(1)(a)]; Consent can be withdrawn at any time in person at the doctor’s office or by email at [email protected]. Such withdrawal, however, shall not affect the lawfulness of any processing that preceded it.
Period of the data processing:
The rules may apply according to the country in which the processing of your data will take place (see section 3 for details).
Data transfer:
Health data will only be transferred at your request to another doctor or third party and your consent will be required in the event of a transfer to a doctor who has not treated you but still requires your data so recorded. Health data will not be passed to your GP unless you specifically prohibit this.
In addition, specific rules may apply depending on the country in which your data will be processed (see section 3 for details).
If you wish to exercise any of your rights referred to in section 1 in relation to the data recorded during the provision of health services, or you wish to contact us for any other reason in connection with data recorded during the provision of health services, please let us know by sending an email to [email protected].
Gym
Purpose of the data processing:
Provision of gym services and complaints management:
• the name, date of birth and photo are used for identification purposes;
• the data related to health and to your membership helps us provide you with a personalised service and avoid risks to your health;
• the other personal data (phone number, email address) is used for maintaining contact with you; providing these contact details is not compulsory, but it is necessary if you want us to be able to contact you.
Non-compulsory statistical data:
• for statistical purposes, we treat the following data separately from personal data: e.g. where you heard about the club.
Legal compliance:
• in the case of a private individual, the name and address.
To speed up the purchase process, some data will be left to be completed at check-in. We ask you to please always check the accuracy of your data.
Period of the data processing:
• We process your personal data for 1 year from the end of the year in which your gym membership expired or from the end of the year of your one-time entry to the gym, for the purpose of complaints management. If you withdraw your consent before the end of this period, your health data will be deleted as soon as you notify us of the withdrawal.
For guests signing up to the newsletter or consenting to receive promotional materials, Ensana shall process the data listed above further, in accordance with the provisions under section 2.7 of this Policy.
In addition, specific rules may apply depending on the country in which your data will be processed (see section 3 for details).
If you wish to exercise any of your rights referred to in section 1 in relation to the data recorded for the purpose of the provision of this service, or you wish to contact us for any other reason, please let us know by sending an email to [email protected].
Guest questionnaire and review system
Guest questionnaire and review system
As part of the Ensana’s quality assurance process, guests can give their opinion on the services of Ensana hotels by means of an email or paper-based guest questionnaire, or with the help of the review system. When completing the questionnaire, you can specify the following personal data:
• Name
• Date of visit
• Room number
• Contact details (address, email address, phone number, home address)
Giving the data is not compulsory; the purpose of the data is simply to allow us to accurately investigate possible complaints and to ensure we can respond to them.
Ensana may also use the opinions received in this way, and any data specified in relation thereto that cannot be traced back to the given Guest or linked to the Guest’s name, for statistical purposes.
If you provide your opinion in an anonymous way, we will not process any personal data. If you request feedback from us, our employee will contact you at one of the contact details provided (email, address, phone number) within 30 days at the latest.
Purpose of the data processing:
To maintain contact with the reviewer, and to manage complaints.
Legal basis of the data processing:
Your consent [GDPR Article 6(1)(a)]. Please note that if we do not receive your consent to the processing of your data or if you withdraw such consent, we will not be able to respond to your question. Withdrawal of consent does not affect the lawfulness of the data processing that preceded it.
Period of the data processing:
Messages and personal data received in this way will be deleted one year after the given request, question or complaint has been responded to.
If you wish to exercise any of your rights referred to in section 1 in relation to the data thus provided, or you wish to contact us for any other reason in connection with the above data processing, please let us know by sending an email to [email protected].
Video surveillance system
Cameras are used on the premises of the hotels in order to assure the safety of Guests and their personal belongings. Guests are reminded of the presence of these cameras through signs featuring a picture of a camera and an accompanying text.
You can ask for more information about the data processing related to the video surveillance system from the front-desk staff at the hotel concerned. We will send you the Privacy Policy of such video surveillance systems at your request. Please send your request to the hotel’s general email address or postal address, or by email to [email protected].
Newsletter and special offers
For the purpose of sending you newsletters and special offers (via email, SMS, and other appropriate channels), we process your name, phone number, email address and occasionally, your home address. In connection with the sending the newsletters and special offers, you have the option to set the topics and the region that you would like to receive newsletters or special offer on. We also store your language settings.
Purpose of the data processing:
To provide you with information on the latest promotions and on news items.
Legal basis of the data processing:
Your consent [GDPR Article 6(1)(a)]. Kindly note that if you do not consent to the processing of your data, we will not be able to send you a newsletter or special offer.
Period of the data processing:
We only send you our newsletter and special offers for as long as you request it. If you no longer wish to receive our newsletter or special offers, you can unsubscribe at any time either by using the dedicated link at the end of each newsletter or commercial communication or by notifying us at [email protected]. Withdrawal does not affect the lawfulness of the data processing that preceded it.
Data transfer:
Data is transferred to Ensana group companies that operate hotels functioning under the Ensana brand. Please note that Ensana s.r.o., CP Regents Park Two Ltd, Slovenské liečebné kúpele Piešťany, a.s., SC Balneoclimaterica SA, Borovete I AD and Léčebné lázně Mariánské Lázně a.s. may each be specified as senders of the newsletter or special offer. Data is transferred to Facebook (Meta Platforms Ireland Limited (Serpentine Avenue, Block J, Dublin 4, Ireland) for the purposes of “lookalike marketing”. In this context, using the name and email address, Facebook displays our ad to people with a similar profile. More information: https://www.facebook.com/business/help/164749007013531?id=401668390442328
Processor:
Your personal data is processed by Virtual Zoom s.r.o. (registered office: Office center Zirkon, Sokolovská 131/86 - Karlín, 186 00 Praha 8), our data processor, who is
responsible for the appropriate functioning of our CRM system and who is obliged to conduct the data processing activity in accordance with the terms of the contract between us and with the relevant statutory provisions.
Your personal data will be processed by THN (The Hotels Network, S.L., NIF B-65542714, Calle Muntaner, 262, 3º-1ª, 08021 Barcelona, Spain) as a data processor, responsible for the proper functioning of the forms, and obliged to carry out its processing activities in accordance with the contractual terms existing between us, and with the applicable legal requirements.
Furthermore, your personal data may be made available to agencies engaged in marketing mailings that we authorize for this purpose (e.g., email or SMS mailings).
If you wish to exercise any of your rights referred to in section 1 in relation to the data thus provided, or you wish to contact us for any other reason in connection with the above data processing, please let us know by sending an email to [email protected].
Loyalty Programme (Ensana Life)
Ensana offers its own loyalty program.
Ensana Life rewards the guest’s loyalty with discounts and other benefits based on nights spent at Ensana hotels.
Further information here: https://www.ensanahotels.com/en/ensana-life/terms-and-conditions
Danubius Friends is the new loyalty program of Danubius Hotels, which does not apply to Ensana hotels. More information is available here.
The Company’s Corporate Programme is an exclusive service provided to the hotels’ corporate partners – juridical persons (companies) – with the purpose of providing loyalty discounts to these partners.
Within the loyalty programmes, the company mainly processes the following personal data:
In the case of natural persons (private individuals):
• Name
• Gender
• Postal address
• Address
• Phone number
• Email address
• Date of birth (minors under eighteen years of age may not participate in the programme)
Personal data processed in the case of juridical persons (companies):
• Name of contact person
• Postal address
• Phone number
• Email address
In addition, information related to fulfilling the conditions of the loyalty programme (points earned, number of nights, use of discounts and benefits or other information relevant to the programme concerned), and the number, validity and password of your loyalty card.
Purpose of the data processing:
To provide discounts to the participants. Sending notifications about the discounts.
Legal basis of the data processing:
Your consent [GDPR Article 6(1)(a)]. You can withdraw your consent at any time and request the deletion of your data by email sent to [email protected] or [email protected], or by letter sent to: Danubius Hotels Zrt. 1051 Budapest, Szent István tér 11., on the understanding that this shall not affect the lawfulness of any processing preceding it. Please note that without giving your consent you may not participate in the Loyalty Programme.
Period of the data processing:
• The processing of the personal data provided shall last as long as the person concerned participates in the given programme.
• The membership status of natural/juridical persons in the Corporate Programme will become inactive after 2 (two) years from the date of the last hotel service used.
• The company stores the necessary personal data of the member for the period specified in the relevant tax and accounting regulations, and deletes them after that period.
Joint data processing:
Kindly note that for the sake of the interoperability of the hotels, Ensana s.r.o., CP Regents Park Two Ltd, Slovenské liečebné kúpele Piešťany, a.s., SC Balneoclimaterica SA, Borovete I AD and Mariánské Lázně a.s. are joint data controllers for the loyalty programme. You will find more information on the hotels in section 5. The joint data controllers shall act in all respects in accordance with the provisions of this Policy when processing data.
Participation in the programmes may occasionally require the provision of further personal data, in which case the Company may request the given data and inform the data subject about the purpose, manner and duration of the data processing.
If you wish to exercise any of your rights referred to in section 1 in relation to the data thus provided, or you wish to contact us for any other reason in connection with the above data processing, please let us know by sending an email to [email protected].
Credit/debit card details
In the case of room booking and online payment, we request the following credit/debit card details:
• Name on the card
• Card number
• Expiry date
• CVC (only in the case of payment)
• Address
• Email address
• IP address
Purpose of the data processing:
To secure the payment or the booking, and to be able to charge the total price of the booking or a part of it, depending on the conditions of the booking.
Legal basis of the data processing:
Fulfilment of the contract concluded for the purpose of room booking as a service. [GDPR Article 6(1)(b)] Giving the data is compulsory; it is a precondition for the provision of the service.
Period of the data processing:
The debit/credit card details are encrypted; release of this data is only possible for the purpose of the transaction, and only to the person authorised in relation thereto. After the guest has left the hotel, the data can no longer be released, and access to the data is no longer possible. The data will be deleted after 8 years.
Processor or data processor:
The service is provided by Adyen N.V. (registered office: Adyen N.V.; Simon Carmiggeltstraat 6-50, 1011 DJ in Amsterdam, the Netherlands.) as data processor.
If you wish to exercise any of your rights referred to in section 1 in relation to the data thus provided, or you wish to contact us for any other reason, please let us know by sending an email to [email protected].
Social media platforms (e.g. Facebook, Instagram)
Ensana and the hotels, restaurants and fitness clubs operated by Ensana can also be contacted individually via the social media platforms Facebook and Instagram. By hitting the “like” and “follow” button on the given page, Facebook users can subscribe to the news published on newsfeed; by hitting the “dislike” button they can unsubscribe to it, and by adjusting the newsfeed settings, they can hide the news they do not wish to follow from the newsfeed. Ensana is able to access its “followers’” profiles; however, it does not record or process them in its own internal system. On YouTube, you can follow and unfollow using the ‘subscribe/unsubscribe’ button.
Purpose of the data processing:
Sharing the contents on the websites of Ensana and of the hotels, restaurants and fitness clubs, etc. operated by Ensana; sharing other news and offers, maintaining contact. Via the Facebook pages, you can book a room, participate in prize draws and find out about our latest promotions.
Legal basis of the data processing:
Your consent [GDPR Article 6(1)(a)], which can be withdrawn at any time by unsubscribing. The withdrawal of consent does not affect the lawful processing that preceded it. In the case of withdrawal, you will not receive notifications on your newsfeed; our news will no longer appear on your newsfeed, though you will still be able to access the Ensana’s newsfeed, since our website is public.
Period of the data processing:
The data processing lasts until you unsubscribe.
Facebook and Instagram are separate data controllers, independent of us. You can find information about the data processing of the site from the data protection guidelines and regulations on the Facebook website, at the following links:
• https://www.facebook.com/policies/cookies/
• https://www.facebook.com/about/privacy/update
You can find information on Instagram’s data processing at the following link:
• help.instagram.com
YouTube: https://www.youtube.com/intl/ALL_en/howyoutubeworks/user-settings/privacy/
In the event of a room reservation, the system automatically redirects the guest to the Ensana’s website. The data processing takes place in accordance with the provisions of section 2.1.
If you wish to exercise any of your rights referred to in section 1 in relation to the data thus recorded, or you wish to contact us for any other reason, please let us know by sending an email to [email protected].
Web store
Hotel restaurant coupons and programme tickets, daily tickets for the use of various fitness and spa services, as well as passes and day spa programmes may also be purchased in the form of vouchers via the online system (web store), by filling out the online order form, for which the following data will be required:
• Family name
• Given name
• Email address
• Billing data (name, country, postcode, city, street, house number)
In addition to the above, Ensana processes the date and time of purchase, the name and price of the service, the total amount of the purchase and the IP address of the customer.
Purpose of the data processing:
Maintaining contact with the customers, the provision of service, the processing of the purchase and the fulfilment of the relevant accounting obligations. The purpose of retaining the data after the purchase is to enforce any claims and manage any complaints.
Legal basis of the data processing:
• Fulfilment of the contract and an compliance with legal obligations. Giving the data is compulsory; it is a precondition for the purchase. [GDPR Article 6(1)(b) and (c)]
• The legal basis of retaining the data after the purchase is our legitimate interest associated with the purpose of the processing, i.e. asserting claims and managing complaints. [GDPR Article 6(1)(f)]
Period of the data processing:
• The personal data will be kept for 5 years after the service has been provided.
• Specific rules may apply depending on the country in which your data will be processed (see section 3 for details). The standard period is between 5 and 10 years. Under no circumstances will we exceed the period necessary for the processing of your data.
For online card payments, you will be automatically redirected to the website of the following data controller:
OTP Bank Nyrt. (Registered office: 1051 Budapest, Nádor Street 16.; registration number: 01-10-041585; web: www.otpbank.hu)
If you wish to exercise any of your rights referred to in section 1 in relation to the data thus provided, or you wish to contact us for any other reason in connection with the above data processing, please let us know by sending an email to [email protected].
Prices subject to registration
Prices subject to registration
Booking at certain prices that offer an extra discount (e.g. Direct Discount) is subject to registration. The direct booking discount applies to many public deals, however, it cannot be combined with other coupons or percent (e.g. Ensana Life) discounts.
During registration, it is compulsory to provide your email address and possibly your name. By registering for the discounted price, you consent to us sending newsletters to the email address that you provide. You may naturally unsubscribe from the newsletter at any time.
Purpose of the data processing:
Provision of information about discounts and special offers.
Legal grounds for the data processing:
Your voluntary consent. You may withdraw your consent at any time, but this will not affect the legitimate data processing that occurred before the withdrawal of consent. Please note that if you do not consent to the processing of the data, we will not be able to keep you informed about our special offers. {GDPR 6. article (1)(a)}
Period of the data processing:
Until withdrawal of the consent.
If you wish to exercise any of your rights described in section 1 in relation to the data thus provided, or if you would like to contact us for any other reason regarding the data processing described above, please let us know by sending an email to [email protected].
If you subscribe via Facebook, the operator of the Facebook and Instagram pages (Meta Platforms Ireland Limited, seat: Serpentine Avenue, Block J, Dublin 4, Ireland; https://www.facebook.com/privacy/explanation; https://www.facebook.com/help/instagram/155833707900388/) provides the Controller the opportunity to display advertisements and use the page analytics function. The page analytics function displays aggregated data designed to help the Data Controller understand how visitors interact with the given page and its advertisements and to draw conclusions for a more efficient operation. No personal data are included in statistical analyses. The processing of data for advertising and statistical purposes on these pages is carried out jointly by the Data Controller and Meta Platforms Ireland Limited (Serpentine Avenue, Block J, Dublin 4, Ireland). The details of the joint data processing agreement can be found in the data processing appendix of the Facebook Page Analytics function. The appendix is available on the following link: https://www.facebook.com/legal/terms/page_controller_addendum
Specific rules may apply depending on the country in which your data will be processed (see section 3 for details).
Contact
You can contact us (e.g. to ask for a quote) at any of our contact details (email, Facebook, phone, post or through the forms designed for this purpose).
Purpose of the data processing:
Maintaining contact with the requester, answering and resolving the question/request.
Legal basis of the data processing:
Since it is you who is contacting us, the legal basis for data processing is your consent [GDPR Article 6(1)(a)]. You can withdraw your consent at any time, but in this case we will not be able to respond to your request. Withdrawal does not affect the lawfulness of the data processing that preceded it.
Please note that the data fields on the various forms were created based on our experience, and involve requesting the minimum of data that we need to answer the request concerned. Mandatory fields are marked with a red asterisk.
Period of the data processing:
Messages and personal data received in this way will be deleted one year after the given request, question or complaint has been responded to. However, if, due to the nature of the correspondence, it is necessary for tax or accounting reasons, or perhaps for the purpose of protecting the rights and interests of Enana or the requester, it will be archived and stored for the necessary time, which we assess individually in each case.
Processor:
Your personal data will be processed by THN (The Hotels Network, S.L., NIF B-65542714, Calle Muntaner, 262, 3º-1ª, 08021 Barcelona, Spain) as a data processor, responsible for the proper functioning of the forms, and obliged to carry out its processing activities in accordance with the contractual terms existing between us, and with the applicable legal requirements.
Data transfer:
An enquiry related to a particular hotel is forwarded to the relevant Ensana group member operating the respective hotel.
Complaint management record
During the management of a consumer complaint, if you do not agree with the way the complaint has been handled, or if it is not possible to investigate the complaint promptly, the respective company is obliged to draft, without delay, a report on the complaint and, if it has been able to formulate one, its position regarding it.
The report must contain the following data:
• The consumer’s name and address
• The place, time and mode of submitting the complaint
• A detailed description of the consumer’s complaint, a list of receipts, documents and other items of evidence provided by the consumer
• A statement by the respective company on its position regarding the consumer’s complaint, if a prompt investigation of the complaint is possible
• The signature of the person who took down the report and – except for verbal complaints made over the phone or by email – the signature of the consumer
• The place and time the report was taken down
• In the case of a verbal complaint made over the phone or by email, the unique reference number of the complaint
Purpose of the data processing:
Investigation of the complaint and maintaining contact with the complainant.
Legal basis of the data processing:
Fulfilling a legal obligation in accordance with the relevant consumer protection regulations to deal with customer complaints or claims.[GDPR Article 6(1)(c)]
Period of the data processing:
Three years from the time that the report was taken down.
If you wish to exercise any of your rights referred to in section 1 in relation to the data thus recorded, or you wish to contact us for any other reason, please let us know by sending an email to [email protected].
Maintaining contact with business clients
Maintaining contact with business clients
Like most companies, Ensana maintains a business relationship with certain employees of other organisations, whose names, job position and contact details we store.
Purpose of the data processing:
In all cases, such data storage is carried out with the consent of the person concerned, so that our companies can communicate for the purpose of co-operation.
Legal basis of the data processing:
The legal basis of our data processing activity is our legitimate interest associated with the performance of the contract or with maintaining contact between the companies [GDPR Article 6(1)(f)].
Period of the data processing:
We check the contact information of our business contacts at least once a year and remove those that are no longer up-to-date from the system.
We apply the same procedure when processing the personal data of press contacts.
Customers’ book (complaints book)
Purpose of the data processing:
Providing a customers’ book is a legal obligation.
Legal basis of the data processing:
Fulfilment of a legal obligation. Retention is necessary due to the consumer protection laws. Providing the data is a precondition for being able to respond. [GDPR Article 6(1)(c)].
Period of the data processing:
Entries are kept for 3 years.
If you wish to exercise any of your rights referred to in section 1 in relation to the data thus recorded, or you wish to contact us for any other reason, please let us know by sending an email to [email protected].
Wi-Fi
If you use wireless internet in our hotels, we must record the following data:
• date and start and end time of use,
• source IP address, source MAC address, target IP address (+ target port)
Purpose of the data processing:
The purpose of the data processing is to ensure the availability of services while you are using Wi-Fi, to monitor your departure, to handle complaints and to detect fraud or abuse.
Legal basis of the data processing:
The legal basis for processing the data is “performance of a contract”, given that achieving Wi-Fi is one of the services provided by our hotel [Article 6(1)(b) GDPR]. However, after your departure, the legal basis is the legitimate interest of the controller related to the handling of complaints and the detection of fraud or abuse [Article 6(1)(f) GDPR]. The provision of your data is a necessary condition for the use of the services.
Period of the data processing:
The data will be kept for 1 year.
Specific rules may apply depending on the country in which your data will be processed (see section 3 for details).
The guest must be informed that the Internet access is open access (lack of firewall protection) and the hotel recommends the guest to protect his/her laptop or desktop with a software Firewall.
If you wish to exercise any of your rights referred to in section 1 in relation to the data thus recorded, or you wish to contact us for any other reason, please let us know by sending an email to [email protected].
Prize draws, competitions
Ensana itself, or in cooperation with another member of the Ensana group or an external company, occasionally organises prize draws or competitions. Entrants can enter prize draws or competitions via paper or online registration (on the Ensana Hotels website or Facebook page), where the following details will usually be requested:
- Name
- Address
- Telephone number
- Email address
In certain circumstances, it will not be necessary to provide this data (e.g. in the case of a prize draw on Facebook) or, on the contrary, it will be required; thus, the scope of the data may vary.
Purpose of data processing:
Organising prize draws, competitions, keeping in touch so that the company can hand over the prize to the winner.
Legal basis for data processing:
Processing necessary for the performance of the terms of the competition or your consent [Article 6(1)(a) GDPR]. You can withdraw your consent at any time by sending an email to [email protected] or by sending a letter to the above address. Withdrawal of consent will not affect processing prior to withdrawal of consent.
Your consent is required to enter any prize draw or competition.
Retention period of personal data:
The processing of data will be carried out until the end of the prize draw/contest, within 30 days from the date of the event, data processed in this context will be deleted (with the exception of data on the winner(s) and alternate winner(s)). Data on the winner(s) and alternate winner(s) will be retained by the company for a period of 10 years in accordance with the provisions of the applicable tax and accounting regulations, and will be deleted after this period.
Information on data transfer and data processors and details of data processing that differ from the information set out in this Privacy Policy will always be provided during the competition or prize draw.
If you wish to exercise any of your rights referred to in section 1 in relation to the data thus recorded, or you wish to contact us for any other reason, please let us know by sending an email to [email protected].
Danubius Gift Card, Ensana Value Voucher
Both the Danubius Gift Card and the Ensana Gift Card are vouchers/gift cards that can currently be spent on services offered by Ensana and Danubius hotels.
The Danubius Gift Card is a gift card designed primarily for visitors to Danubius hotels and can no longer be purchased or used at Ensana hotels.
The Ensana Gift Card is a new voucher offered to customers of Ensana hotels that offers a wide range of personalisation options (in terms of value, layout, personalised messages, etc.).
Scope of data:
When purchasing a Danubius Gift Card or an Ensana Value Voucher (voucher), you will be asked to provide the following personal data:
In the case of a personal purchase:
- Name
- Billing name and address
In the case of an online order via the company's official website:
- Name
- Email address
- Phone number
- Billing name and address
- Delivery address and name & other information regarding the gift card or voucher (e.g. dedication, format of the voucher, etc.).
More information can be found at Danubius’ and Ensana’s websites.
Purpose of data processing:
To manage the contract for the delivery of gift cards or vouchers, cheques and for invoicing.
Legal basis for data processing:
Performance of the contract concluded for the delivery of the gift card or voucher. The provision of this data is necessary for the provision of the service [Article 6(1)(b) GDPR].
Retention period:
The personal data collected in this way will be retained for period stipulated by the provisions of the applicable tax and accounting regulations (usually 10 years).
Processor:
Your personal data will be processed by Virtual Zoom s.r.o., our data processor, which is responsible for the operation of the relevant booking system and which is bound by a data processing contract in accordance with applicable law.
If you wish to exercise any of your rights referred to in section 1 in relation to the data thus recorded, or you wish to contact us for any other reason, please let us know by sending an email to [email protected].
Data processing provisions / activities in the case of Ensana hotels in Hungary and Czech Republic
Data processing provisions / activities in the case of Ensana hotels in Czech Republic
Please note the specific rules below if the processing of your personal data is governed by Czech law (in particular if you are a guest of a hotel in the Czech Republic):
Contact details:
E-mail: [email protected]
Correspondence address: Ensana s.r.o., Senovážné náměstí 992/8, 110 00 Praha 1
In case of questions related to accommodation in Marianské Lázně you can also contact directly to:
Léčebné lázně Mariánské Lázně a.s.
Masarykova 22, 353 29 – Mariánské Lázně, Czech Republic
Supervisory authority:
Office for Personal Data Protection
Pplk. Sochora 727/27, 170 00 Prague, Holešovice, Czech Republic
Phone: +420 234 665 111
E-mail: [email protected]
Website: www.uoou.cz
Right to an effective judicial remedy:
In the Czech Republic, the adjudication of the lawsuit falls within the jurisdiction of the district courts. The lawsuit, at the choice of the data subject, may be initiated at the district court of the permanent address of the data subject.
Besides the provisions of the GDPR, the provisions of the Civil Code, the Civil Procedure Code shall, as well as other legal provisions relating to court proceedings, shall apply.
List of main legal acts where the legal basis for processing is the performance of our legal obligations:
In connection with your reservation (section 2.1.) and accommodation (section 2.2.) or in connection with the conclusion of a contract and the issue of tax documents (also sections 2.4, 2.11.), we are obliged to process your personal data in particular to fulfil our obligations under:
- Act No. 563/1991 Coll., on Accounting, and tax regulations, in particular Act No. 235/2004 Coll., on Value Added Tax, for bookkeeping and issuing tax documents;
- Act No. 326/1999 Coll., on the residence of foreigners, namely for keeping the house register and notifying the accommodation of persons;
- Act No. 565/1990 Coll., on local taxes, namely for keeping the guest register.
In connection with the provision of health services (section 2.3.), we are obliged to process your personal data in particular to fulfil our obligations under:
- Act No. 372/2011 Coll., on the provision of health services, in particular for the proper provision of health services and the maintenance of health records.
In matters related to the performance of contracts and ensuring consumer protection (Sections 2.1, 2.11, 2.14, 2.16), we are obliged to process your personal data in particular to fulfil our obligations under:
- Act No. 89/2012 Coll., Civil Code;
- Act No. 634/1992 Coll., on Consumer Protection.
Period of data processing where the data is processed for the performance of the above legal obligations:
- If we are obliged to keep your data for the purpose of keeping legal records of guests (Acts No. 565/1990 Coll. and 326/1999 Coll.) we are obliged to keep your data for 6 years from the last registration.
- If the information is necessary part of tax documents, we are legally obliged to keep this data for 10 years from the end of the calendar year (according to Act No. 235/2004 Coll.). If these are other accounting documents (Act No. 563/1991 Coll.), we are obliged to keep them for a period of 5 years.
- We keep medical records for 10 years or for any other period specified by the Ministry of Health Decree No. 444/2024 Coll. on medical records, as amended.
- In the event of a consumer protection obligation, we keep your data for the duration of the limitation period (the general limitation period is 3 years).
Data transfer where the data is processed for the performance of the above legal obligations:
- In case you are a foreigner in the Czech Republic, your personal data will be transferred to the foreign police for fulfilling the obligations under Act No. 326/1999 Coll.
- Any consultation and transfer of data from medical records is only possible under the conditions of Act No. 372/2011, e.g. under Section 65 and the rules for inspection of medical records.
Data processing provisions / activities in the case of Ensana hotels in Hungary
Information about data processing provisions / activities in the case of Ensana hotels in Hungary can be found here.
Automatically recorded data, cookies and codes
Detailed information below:
Automatically recorded data
Scope of data:
When you open our website on a device (such as a laptop or desktop computer, a smartphone or a tablet) select data of that device will be automatically recorded. The data automatically recorded include the IP address of your device, the date and time of your visiting our website, the browser type and the domain name and address of your Internet provider. The recorded data will be automatically logged by the web server of the website, without requiring your consent or any dedicated activity on your part. The system uses the recorded data to automatically generate statistical data. These data cannot be associated with other personal data except where such an association is mandated by law. These data will exclusively be used in an aggregated and processed form, to correct errors and improve the quality, of our services, and for statistical purposes.
Purpose of data processing:
The technical development of the informatics system, to monitor of the service, and to generate statistical data. In case of fraudulent and other criminal activities these data can also be used – in co-operation with the user’s Internet provider and the law enforcement authorities – to determine the source of such fraudulent activities.
Legal basis of data processing:
Necessity for the performance of the contract (provision of the requested service) and fulfillment of legal obligations in connection with the provision of certain information society services.
Period of data processing: 30 days from your opening our website.
Cookies and similar technologies
Cookies
This website uses cookies.
Cookies make websites more user-friendly and efficient for users. A cookie is a small text file used to save information. When you visit a website, this website can place a cookie on your computer. If at a later point in time you visit the website again, the website can read the information saved in the cookie and find out, for example, whether you have visited the website before and which areas of the website you are particularly interested in.
Changing cookie settings
The web browser settings determine how the web browser deals with cookies and which cookies are or are not allowed. These settings can be changed. How and where these changes can be made depends on the web browser. Use the ‘Help’ function in your web browser to find out more about how to change your cookie settings.
You should be aware that limiting the use of cookies may mean that not all functions on this website can be used to their full capacity.
For more information about cookies on our website and how to change the settings for each category of cookie and grant/revoke consent, please see the cookie bar. The cookie bar is displayed when you first visit our website and can also be viewed by clicking on the picture of the clip in the bottom left corner of the screen.
Cookies on our website
Our website uses the following providers:
• Our website: To save your consent for cookies to be used.
• Google: To save user data connected to Google’s website statistics software Google Analytics. For more information visit Google Analytics.
• Facebook: To save user data connected to Facebook Pixel. For more information visit Facebook Developer and read the information on Facebook cookies.
• Microsoft Clarity: To save user data connected to Microsoft Clarity. For details read the Microsoft Clarity cookie information.
Server Log Files
For the purposes of technical monitoring and increased security, this website processes the following personal data in a server log file. This processing is based on the principle of overwhelming interest of the person/company responsible (technical security measures).
• IP address
• site from which the file was accessed (“referrer URL”)
• name of the file
• date and time the file was accessed ("time stamp")
• amount of data transferred
• access status (file transferred, file not found, etc.)
• type of web browser used, e.g. Mozilla Firefox, Google Chrome, Microsoft Internet Explorer, Microsoft Edge, Apple Safari, Opera etc.)
These data are saved in personalised form only temporarily for a period of seven days. After that the log files are deleted.
Google Analytics
This website uses Google Analytics, a web analysis service operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (“Google”). Google Analytics is based on the legal principle of overriding legitimate interest (analysis of website use). To this end we have concluded an agreement with Google on contracted data processing.
When you visit our website, a piece of software creates a connection to Google servers and data is sent to these servers, some of which are located in the USA. Google Analytics also uses cookies to save information about the website user as well as to analyse how visitors use this website.
This website uses the function "Activation of IP anonymisation". This means that within Member States of the European Union and countries of the European Economic Area your IP address will be shortened. Only in exceptional circumstances will the full IP address be sent to a Google server in the USA and shortened there
According to Google, this data is used to analyse the use of the website, produce reports on website activity and provide additional services connected to use of the website and the internet.
Google may also transfer this information to third parties if this is legally required or if the third party is tasked with processing the data on behalf of Google.
For detailed information on the use of data by Google Analytics please consult the data protection declaration of Google and Google Analytics.
Google Analytics Remarketing
Our websites use the features of Google Analytics Remarketing combined with the cross-device capabilities of Google AdWords and DoubleClick. This service is provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Irland.
This feature makes it possible to link target audiences for promotional marketing created with Google Analytics Remarketing to the cross-device capabilities of Google AdWords and Google DoubleClick. This allows advertising to be displayed based on your personal interests, identified based on your previous usage and surfing behavior on one device (e.g. your mobile phone), on other devices (such as a tablet or computer).
Once you have given your consent, Google will associate your web and app browsing history with your Google Account for this purpose. That way, any device that signs in to your Google Account can use the same personalized promotional messaging.
To support this feature, Google Analytics collects Google-authenticated IDs of users that are temporarily linked to our Google Analytics data to define and create audiences for cross-device ad promotion.
You can permanently opt out of cross-device remarketing/targeting by turning off personalized advertising in your Google Account; follow this link.
The aggregation of the data collected in your Google Account data is based solely on your consent, which you may give or withdraw from Google per Art. 6 (1) (a) GDPR. For data collection operations not merged into your Google Account (for example, because you do not have a Google Account or have objected to the merge), the collection of data is based on Art. 6 (1) (f) GDPR. The website operator has a legitimate interest in analyzing anonymous user behavior for promotional purposes.
For more information read the Google Privacy Policy.
Deactivating Google Analytics
• It is possible to prevent our website from collecting your user data by activating the “Do Not Track” function in your web browser. Your web browser will then send a “Do Not Track” signal to all websites, including ours.
• You can prevent all websites from collecting your user data by downloading the following extension and installing it on your computer: Download Browser Extension.
• You can prevent only our website from collecting your user data via Google Analytics by clicking on the following link. This places an opt-out cookie on your computer, which prevents data being collected from you if you visit this website again. Deactivate Google Analytics.
Google Analytics Google Signals
We have enabled Google signals in Google Analytics. This updates existing Google Analytics features (advertising reports, remarketing, cross-device reports, and interest and demographic reports) to provide aggregated and anonymized data from you, provided you have allowed personalized ads in your google account.
What makes this special is that it is cross-device tracking. That means your data can be analyzed across devices. By enabling Google signals, data is collected and linked to the Google account. Google can thus recognize, for example, if you view our website via a smartphone and only mare reservation later via a laptop. Thanks to the activation of Google signals, we can launch cross-device remarketing campaigns that would otherwise not be possible in this form. Remarketing means that we can also show you our offer on other websites.
In Google Analytics, Google signals also collect other visitor data such as location, search history, YouTube history and data about your actions on our website. This gives us better advertising reports from Google and more useful information about your interests and demographics. This includes your age, what language you speak, where you live, or what gender you are. Furthermore, social criteria such as your profession, your marital status or your income are also added. All these characteristics help Google Analytics to define groups of people or target groups.
The reports also help us to better assess your behavior, your wishes and interests. This allows us to optimize and adapt our services and products for you. By default, this data expires after 26 months. Please note that this data collection only occurs if you have allowed personalized advertising in your Google account. This is always aggregated and anonymous data and never individual person data. In your Google account, you can manage this data or delete it.
Facebook Pixel
This website uses Facebook Pixel, a web analysis service operated by Facebook Ireland Limited, 4 Grand Canal Square, Dublin 2, Ireland (“Facebook”) based on the legal principle of overriding legitimate interest (analysis of website use). We have concluded an agreement with Facebook on contracted data processing. In some cases data will be transferred to the USA. This transfer of data to the USA takes place on the basis of the Privacy Shield.
When you visit our website a piece of software creates a connection to Facebook’s servers and sends data to these servers, some of which are located in the USA. Facebook Pixel also uses cookies to save information about the website user and to analyse how the website user uses the website.
According to Facebook, this data is used to analyse the use of the website, produce reports on website activity and provide additional services connected to use of the website and the internet.
Facebook may also transfer this information to third parties if this is legally required or if the third party is tasked with processing the data on behalf of Facebook.
We use Facebook Custom Audience as well as other tools offered by Facebook to advertise on websites like Facebook. In order to do this we share your data with providers like Facebook and use Cookies and similar technology on our website to analyze how effective our ads are on these third party platforms.
For detailed information on the use of data by Facebook please consult Facebook’s data protection declaration.
Deactivating Facebook Pixel
• It is possible to prevent our website from collecting your user data by activating the “Do Not Track” function in your web browser. Your web browser will then send a “Do Not Track” signal to all websites, including ours.
• You can prevent this website from collecting your data via Facebook Pixel by clicking on the following link. This places an opt-out cookie on your computer, which prevents data from being collected from you if you visit this website again. Deactivate Facebook Pixel.
“Share”-Buttons
Some pages of our website have buttons which allow users to share the content on social media platforms such as Facebook, Google Plus, Instagram, LinkedIn, Pinterest, Tumblr, Twitter, XING and YouTube.
These buttons have been designed to protect personal data. The script (computer programme) behind the buttons does not collect or process any personal data. Detailed information on the function of these buttons is available from Heise Verlag, the company which publishes the IT journal c’t and is also responsible for developing the buttons.
Website visitors who wish to share our website can click on one of these buttons. They will be forwarded to the “share” page of the respective social media platform. Only there will the scripts be loaded which are needed in order to share the content of the website. This sharing of information is subject to the terms and conditions as well as the data protection provisions of the respective social media platform. For more information visit Facebook, Google Plus, Instagram, Linkedin, Pinterest, Tumblr, Twitter, XING und Youtube.
Microsoft Clarity
We partner with Microsoft Clarity to capture how you use and interact with our website through behavioral metrics, heatmaps, and session replay to improve our services. Website usage data is captured using first and third-party cookies and other tracking technologies to determine the popularity of services and online activity. Additionally, we use this information for site optimization and fraud/security purposes. For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.
As noted, Microsoft Clarity's normal functioning requires that we set cookies on your web browser. The respective cookies send Microsoft non-personally identifiable information about you. For a full list of Microsoft Clarity cookies, please see the cookie bar on our website.
Joint data processing:
Regarding the processed data Ensana s.r.o., CP Regents Park Two Ltd., Slovenske liecebne kupele Piešťany, a.s., SC Balneoclimaterica SA and Léčebné lázně Mariánské Lázně a.s. are joint controllers. For more information please refer to section 5.
As regards the processing of data the joint controllers proceed in accordance with this Policy.
Web links
Our website may contain web links to sites which are not managed and operated by the company, and are linked to our site for the purpose of providing information to the users. The company has no influence over, and therefore may not be hold responsible for, the content and the safety situation of the websites managed by its partner companies. Please, consult their privacy policies before providing any information on such websites you visit.
Legal reference information (including contact details)
As the data controller of the personal data it uses, Ensana is obliged, under the GDPR, to publish information regarding its official name, contact details and other data. This section contains all the information required by the GDPR, as well as additional legal information.
We would like to start by informing you that, in order to make its activities more transparent, the Ensana group’s hotels have been divided into two divisions:
- City division managing hotels in cities (City hotels; see subchapter 5.1.)
- SPA division managing health, spa and wellness hotels (Ensana group; see subchapter 5.2.).
The City division is managed by the (Hungarian) company Danubius Hotels Zrt. The SPA division is managed by the (Czech) company Ensana s.r.o. Both companies Danubius Hotels Zrt. and Ensana s.r.o. jointly manage the hotels listed below, for which purpose personal data is shared and processed by these companies as separate or joint controllers on a case-by-case basis. The person responsible for data protection in the City division, Dr. Helga Sztanó, is also responsible for data protection in the SPA division.
Danubius City Hotels (City division)
Company leading the City division:
Name: Danubius Hotels Zrt.
Registered office: 1051 Budapest, Szent István tér 11.
Court of registration: Metropolitan Court of Budapest as Court of Registration
Company registration number: 01-10-041669
Tax number: 10594702-2-44
Represented by: Balázs Kovács CEO
Legal associate responsible for data protection is available at +36-1-889-4172
Email address: [email protected]
Ensana Health Spa Hotels (SPA division)
Company leading the SPA division:
Name of company: Ensana s.r.o.
Registered office: Senovážné náměstí 922/8, 110 00 Prague
Name of court of registration: Krajský soud v Plzni
Registration number: C 33301
ID number: 05456274.
The owners of the hotels operated by Ensana s.r.o., besides Danubius Hotels Zrt., are the following companies:
Companies managed by Ensana s.r.o.:
Name of company: CP Regents Park Two Ltd.
Registered office: CP House, Otterspool Way, Watford WD25 7JP, UK
Registration number: 5307946.
TAX ID: GB 848957555
Name of company: Slovenské liečebné kúpele Piešťany, a.s.
Abbreviated name: SLKP, a.s.
Registered office: Winterova 29, 921 29 Piešťany, Slovakia
Registration number: Obch. reg. KS Trnava, odd. Sa, vlozka č. 181/T
EU tax number: SK2020389668
Name of company: SC Balneoclimaterica SA Sovata
Registered office: Str, Trandafirilor nr. 99, Cod.545500, Romania
EU tax number: RO1245068
Registration number: J26/266/1991
Name of company: Borovete I AD
Registered office: 9000 Varna, Primorsky district, Sveti Konstantin i Elena resort, administrative building, Bulgaria
ID number: 204605689
Name of company: Léčebné lázně Mariánské Lázně a.s.
Registered office: Masarykova 22, 353 29 Mariánské Lázně, Czech Republic
Registration number: B 196
EU tax number: CZ45359113
The hotels involved in joint data processing are:
Danubius Hotels Zrt.:
Ensana Thermal Margitsziget
Ensana Grand Margitsziget
Ensana Thermal Sárvár
Ensana Thermal Aqua
Ensana Thermal Hévíz
Léčebné lázně Mariánské Lázně a.s.
Ensana Nové Lázně
Ensana Centrální Lázně
Ensana Hvězda
Ensana Pacifik
Ensana Butterfly
Ensana Vltava
Ensana Svoboda
Slovenské liečebné kúpele Piešťany, a.s.
Ensana Thermia Palace
Ensana Esplanade
Ensana Splendid
Ensana Vila Trajan
Ensana Jalta
Ensana Pro Patria
Ensana Smrdáky
SC Balneoclimaterica SRO A Sovata:
Ensana Bradet
Ensana Sovata
Ensana Ursina
Borovete I AD
Aquahouse
Terms and abbreviations used in this Policy
Most of the definitions are taken from the EU’s General Data Protection Regulation (GDPR). This is a legal document, and so the same content cannot be reproduced simply and briefly. Our goal here is to provide a clear explanation that makes the text easier to understand; this sometimes precludes providing the full legal definition. According to the Ensana’s policy, we fully comply with the requirements of the GDPR, and your rights are not impaired by the fact that the explanation provided here has been simplified.
Term or abbreviation Explanation
Controller or data controller: A person that, alone or jointly with others, determines the purposes and means of the processing and that regulates the processing of the personal data.
Data subject: A person living within the EU or outside the EU who has dealings with an organisation operating in the EU. Such an individual is considered a “data subject” and has rights under the GDPR in relation to the processing of his or her own data.
EU: The European Union
GDPR The EU’s General Data Protection Regulation, which entered into force on 25 May 2018.
Personal data: Any information relating to an individual that enables identification of that individual using a number of methods, with such data including but not limited to:
• the individual’s name, identification number, address, mothers name at birth, or
• one or more factors specific to the individual’s physical, physiological, genetic, mental, economic, cultural or social identity.
Processing or Data Processing: Any operation or set of operations performed on personal data, whether automatically or not, including but not limited to:
Collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, combination, restriction, erasure, or destruction.
Processor or data processor: A person that processes personal data on behalf of a controller.
Profiling: Automatic processing that uses personal data to analyse or make predictions about an individual’s work performance, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements.
Pseudonymisation: Coding or holding personal data in some other manner that ensures that it cannot be linked to a specific data subject without providing additional information. The additional information must be stored separately and protected from unauthorised use through technical and organisational measures.
Sensitive categories of personal data: There are very strict restrictions on the processing of “sensitive categories” of personal data. These are:
• Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade-union membership,
• The processing of genetic data or biometric data for the purpose of solely identifying a human being; data concerning health or a person’s sex life or sexual orientation, or
• Personal data relating to criminal convictions and offences.
Supervisory Authority: An independent public body set up by an EU Member State to monitor the application of the GDPR and – if necessary – to intervene to protect the rights of individuals under the GDPR.
Third country: Any country outside the EU.
Data transfer: Sending of personal data from the controller or processor to a legal entity outside the EU.
