Skip to main content

Privacy Policy

Effective Date: July 2026

This Privacy Policy explains how Duna-Weser Kft. and Rubin Group Kft. (collectively referred to as the "Company", "we", "us", or "our"), operating under the brand Bud By Boat, collect, use, and protect your personal data when you use our website, book a cruise, or use our services. We comply with the General Data Protection Regulation (EU) 2016/679 (GDPR), Hungarian Act CXII of 2011 on the Right of Informational Self-Determination and Freedom of Information ("Infotv."), and other applicable Hungarian data protection laws.

1. Data Controllers and Allocation of Responsibilities

The joint Data Controllers for your personal information are:

  •     Duna-Weser Kft. (Company Reg: 01-09-293625, Registered Office: 1137 Budapest, Szent István körút 26. 2. emelet 15/b.)
  •     Rubin Group Kft. (Company Reg: 01-09-274932, Registered Office: 1137 Budapest, Szent István körút 26. 2. emelet 15/b.)

Contact Email: This email address is being protected from spambots. You need JavaScript enabled to view it.

In accordance with Article 26 of the GDPR, the Controllers have arranged the essence of their joint responsibilities as follows:

  •     Rubin Group Kft. is primarily responsible for processing carried out through the website, the TicketDock booking system, ticketing, invoicing, and marketing communications.
  •     Duna-Weser Kft. is primarily responsible for processing carried out on board the Vessels in connection with maritime operations, on-board safety, the passenger manifest, and the CCTV system described in Section 2.5.

Regardless of this internal allocation, you may exercise your rights under this Policy against either Controller by contacting This email address is being protected from spambots. You need JavaScript enabled to view it., and each Controller remains available to you as a contact point for the essence of the arrangement referred to in this section.

2. What Personal Data We Collect

We collect data necessary to provide our sightseeing and event cruise services:

2.1 Identity & Contact Data

First name, last name, email address, phone number (collected during the booking process or via inquiries).

2.2 Booking Data

Cruise date, time, number of passengers, special requests (e.g., catering needs), and ticket/booking IDs.

2.3 Financial & Billing Data

Billing address and payment transaction details. (Note: We do not store your full credit card details; these are processed securely by our payment gateway providers, including Stripe.)

2.4 Technical Data

IP address, browser type, operating system, and tracking data via cookies (detailed in our Cookie Policy, available at [insert link]).

2.5 Video Surveillance (CCTV) Data

For safety, security, and crime-prevention purposes, our Vessels are equipped with a CCTV system covering common and public areas of the ship (this does not include restrooms or private cabins, where applicable). Recordings may capture your image if you board or travel on the Vessel.

Legal basis: Legitimate interest of the Company (Art. 6(1)(f) GDPR) in protecting the safety of passengers and crew, safeguarding Company property, and establishing evidence in the event of an incident, accident, or complaint.

Retention: Recordings are retained for a maximum of 30 days from the date of recording, unless a specific incident, complaint, accident, or legal claim requires a segment of footage to be preserved for a longer period strictly necessary to investigate or resolve that matter.

Notice: Clearly visible signage is displayed at the boarding point and on board to inform Passengers that CCTV recording is in operation.

2.6 Age Verification Data (ID / Passport)

Where the Passenger orders alcoholic beverages, crew members may request to see a valid physical ID card or passport solely to visually verify that the Passenger is at least 18 years of age.

Legal basis: Compliance with a legal obligation relating to the responsible service of alcohol, and the Company's legitimate interest in preventing underage drinking (Art. 6(1)(c) and 6(1)(f) GDPR).

Retention: The document is viewed by crew for verification purposes only. No copy, photograph, or record of the document or its data is made or retained, unless the Passenger is found to be underage and a written incident record is required under Section 4.4 of the GTC, in which case only the fact of the incident and the Passenger's name are noted.

2.7 Health-Related Data in Emergencies

In the event of an on-board medical emergency, illness, or visible infectious disease affecting a Passenger, crew members may need to record or share limited health-related information with emergency responders (e.g., ambulance services) or port authorities.

Legal basis: This constitutes a special category of personal data under Article 9 GDPR, processed only where necessary to protect the vital interests of the Passenger or other individuals (Art. 9(2)(c) GDPR), such as where the Passenger is physically or legally incapable of giving consent.

Such data is shared only with the parties strictly necessary to respond to the emergency (e.g., ambulance crew, port authority) and is not otherwise retained by the Company beyond the incident record referred to in Section 5.

3. Purpose and Legal Basis for Processing

We process your personal data under the following lawful bases defined by the GDPR:

Performance of a Contract (Art. 6(1)(b) GDPR): To process your booking, issue your tickets, manage your reservation via our TicketDock system, and communicate with you regarding your scheduled cruise.

Legal Obligation (Art. 6(1)(c) GDPR): To comply with Hungarian tax and accounting laws (e.g., issuing official invoices) and age-verification obligations relating to alcohol service.

Legitimate Interests (Art. 6(1)(f) GDPR): To maintain the safety and security of our vessels (e.g., passenger manifests, CCTV as described in Section 2.5), handle legal claims, and improve our website functionality.

Vital Interests (Art. 9(2)(c) GDPR): To protect the life, health, or physical safety of a Passenger or other individuals in a medical emergency, as described in Section 2.7.

Consent (Art. 6(1)(a) GDPR): To send marketing communications or use non-essential tracking cookies. You may withdraw your consent at any time.

4. Data Sharing and Third-Party Processors

To operate our business effectively, we may share your data with trusted third-party service providers (Data Processors). We ensure they are GDPR-compliant:

Booking & Reservation Systems: We use platforms such as TicketDock to process and manage your cruise reservations.

Online Travel Agencies (OTAs): If you book through partners like GetYourGuide, Viator, Tripadvisor, Booking.com, or Expedia, booking data is shared between us to fulfill your reservation.

Payment Gateways: Secure third-party providers, including Stripe, handle financial transactions.

Accounting & Legal: Hungarian authorities (NAV) for taxation purposes, and our contracted accounting firms.

Emergency Responders and Authorities: Ambulance services, police, and port authorities, where necessary to respond to an incident, accident, or medical emergency, or as otherwise required by law.

5. International Data Transfers

Some of our third-party providers are located, or process data on servers located, outside the European Economic Area (EEA) — for example, Stripe, GetYourGuide, Viator, Tripadvisor, and Expedia, which are established in or operate from the United States or other non-EEA countries.

Where personal data is transferred outside the EEA, we ensure an appropriate safeguard is in place, such as:

  •     an adequacy decision of the European Commission covering the destination country; or
  •     Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our agreements with the relevant provider.

You may request further information about the specific safeguard applicable to a given transfer by contacting us at This email address is being protected from spambots. You need JavaScript enabled to view it..

6. Data Retention Periods

We only retain your personal data for as long as necessary to fulfill the purposes we collected it for:

Accounting and Invoices: By Hungarian law (Act C of 2000 on Accounting), all billing and invoicing data must be retained for 8 years.

Booking Data: Retained for 5 years after the completion of the service to address any potential legal claims or complaints.

CCTV Recordings: Retained for a maximum of 30 days, except where a segment must be preserved longer to investigate or resolve a specific incident or claim, as described in Section 2.5.

Age Verification (ID/Passport): Not retained, except for a written incident record where a minor is found to have been served alcohol, as described in Section 2.6.

Marketing Data: Retained until you unsubscribe or withdraw your consent.

7. Data of Minors

Where a booking is made on behalf of a minor (e.g., by a parent or legal guardian), we process the minor's identity and booking data solely for the purpose of providing the cruise service and ensuring on-board safety. We do not knowingly collect marketing consent from minors, and any age-verification check under Section 2.6 is carried out visually by crew without retention of the minor's document data.

8. Your Data Protection Rights

Under the GDPR, you have the following rights regarding your personal data:

Right of Access: Request a copy of the personal data we hold about you.

Right to Rectification: Request correction of inaccurate or incomplete data.

Right to Erasure ("Right to be Forgotten"): Request deletion of your data (unless we are legally required to keep it, e.g., for invoicing).

Right to Restriction: Request the suspension of processing your data.

Right to Data Portability: Request the transfer of your data to you or a third party.

Right to Object: Object to processing based on legitimate interests or for direct marketing.

To exercise any of these rights, please contact us at This email address is being protected from spambots. You need JavaScript enabled to view it..

9. Data Protection Officer

The Company is not required by law to appoint a Data Protection Officer (DPO) given the nature and scale of its data processing activities. Should you have any questions or concerns regarding this Policy or our data processing practices, please contact us directly at This email address is being protected from spambots. You need JavaScript enabled to view it..

10. Supervisory Authority and Right to Judicial Remedy

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Hungarian National Authority for Data Protection and Freedom of Information (NAIH):

Website: http://www.naih.hu

Address: 1055 Budapest, Falk Miksa utca 9-11.

Email: This email address is being protected from spambots. You need JavaScript enabled to view it.

In addition to, or instead of, lodging a complaint with the NAIH, you also have the right to an effective judicial remedy under Article 79 of the GDPR. Such proceedings may be brought before the courts of Hungary, including the court having jurisdiction over the registered seat of the Company.

 

END OF DOCUMENT