Privacy
What we do with your data, why we are allowed to, and how to make us stop. This notice is given under Articles 13 and 14 of the GDPR.
Who is responsible
The controller of your personal data is Lorenz Development Kft., 2800 Tatabánya, Boróka utca 7., Hungary (company registration 11-09-032270, VAT 33092957-2-11). For anything in this notice, including every request described below, write to [email protected].
We have not appointed a data protection officer. We are not required to, and the address above reaches the people who decide these things.
What we collect
Only what the guide needs. There are no accounts, no advertising, no analytics and no tracking of any kind.
- Your email address
- To verify you, to send the guide, and to answer you if you write.
- The two places and the language
- Where you are travelling from and to, and the language to write in.
- Pro trip details
- Your dates, how many people are travelling, whether children or a pet are coming, the hotel or area you typed, the radius you chose, and any dietary requirements you ticked.
- The guide itself
- The text we produced and the PDF, kept so your link keeps working.
- Payment record
- The Stripe transaction reference. We never see or hold your card details.
- Technical records
- Server logs, which include your IP address, and a short-lived counter keyed to your IP that stops the form being hammered. The counter is discarded within an hour.
Dietary requirements: a special note
If you tick Halal or Kosher, that says something about your religious beliefs. If you tick a gluten, dairy, nut or shellfish option, that says something about your health. Both are special categories of data under Article 9 of the GDPR and deserve to be treated as such.
These fields are entirely optional and the guide is written without them if you leave them alone. By ticking one you explicitly consent to us processing it, and to it being passed to the language-model provider that writes the eating pages, for the single purpose of writing your guide. That is our legal basis under Article 9(2)(a).
You can withdraw that consent at any time by writing to us, and we will delete the answers. Withdrawing does not affect the guide already written, and does not affect anything else about your order.
Why we are allowed to use it
- To write and deliver your guide
- Performance of our contract with you — Article 6(1)(b). Without this data there is no guide to write.
- Dietary requirements
- Your explicit consent — Articles 6(1)(a) and 9(2)(a).
- Verifying your email and preventing abuse
- Our legitimate interest in not having the service used to send guides to people who did not ask for them — Article 6(1)(f).
- Keeping billing records
- A legal obligation under Hungarian accounting and tax law — Article 6(1)(c).
Who else sees it
We do not sell your data and we do not share it for anyone else's purposes. It reaches these categories of recipient, each acting under contract for us and only on our instructions, except where noted:
- Our payment provider
- Stripe, who act as seller of record and are a controller in their own right for the payment. They receive your email address and the transaction; we receive no card details.
- The language-model provider
- Receives the trip brief — the places, dates, party, hotel and any dietary rules — so the guide can be written. It does not receive your email address or your payment details.
- Our email provider
- Delivers the verification code and the finished guide.
- Our hosting provider
- Runs the servers the site and the database sit on.
Data leaving the EEA
Where a provider we use processes data outside the European Economic Area, that transfer is made under an adequacy decision of the European Commission where one covers the country in question, and otherwise under the Commission's Standard Contractual Clauses together with any additional measures the transfer requires. You can ask us which safeguard applies to a given provider, and we will tell you.
How long we keep it
Your order, your trip details and the guide are kept until you ask us to delete them, so that the link we sent you keeps working for as long as you want it. There is no automatic expiry.
Two things survive a deletion request. Billing records are kept for the eight years Hungarian accounting law requires, and server logs age out on their own within a short period. Neither contains your trip details.
Your rights
Under the GDPR you can ask us to do any of the following, free of charge, and we answer within one month:
- Access
- A copy of the personal data we hold about you.
- Rectification
- Correction of anything wrong.
- Erasure
- Deletion of your order and the guide with it.
- Restriction and objection
- That we pause our use of it, or that we stop relying on legitimate interests, which we will unless we have compelling grounds not to.
- Portability
- The data you gave us, in a machine-readable file you can take elsewhere.
- Withdraw consent
- For your dietary answers, at any time, without affecting what was done before you withdrew it.
Write to [email protected] for any of these. We may ask you to confirm the email address the order was made with, because it is the only thing tying an order to a person.
Complaining about us
If you think we have handled your data badly, please tell us first. You also have the right to complain to a supervisory authority — in Hungary that is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1055 Budapest, Falk Miksa utca 9-11., naih.hu — or to the authority in the EU country where you live or work.
Cookies
This site sets no cookies and uses no local storage, no analytics and no third-party scripts. That is why you were never asked to accept anything.
Automated processing
The text of your guide is generated by an AI language model rather than written by a person. That is automated processing, but it makes no decision about you: it produces a document. Nothing on this site makes automated decisions with legal or similarly significant effects, and there is no profiling.
Security
The site is served over HTTPS, order links carry a long random token rather than a guessable number, and access to the database is limited to the people who run the service. Card details never reach our servers.
Last updated 25 August 2026.