Privacy Policy
Last updated: 2026.01.01.
This is a preliminary version. The final text will be published before the official launch of the system.
1. Data Controller
- Controller: [company name to be filled in]
- Address: [address to be filled in]
- Email: [privacy email to be filled in]
- Data Protection Officer (if appointed): [name, contact to be filled in]
2. Categories of personal data
The Controller processes the following personal data of users:
- Account data: name, username, email, password (hashed), preferred language
- Contact: phone number (with country code), address (postal code, county, city, street)
- Login data: IP address, browser fingerprint, login timestamps, failed attempts
- Security data: two-factor authentication (TOTP secret, backup codes), activation and password reset tokens
- Audit log: events related to Service use (login, account changes, admin actions)
3. Purpose and legal basis of processing
Personal data processing is based on GDPR Article 6:
- Contract performance (GDPR 6(1)(b)): registration, account management, login, service provision.
- Legal obligation (GDPR 6(1)(c)): invoicing, tax obligations, government reporting.
- Legitimate interest (GDPR 6(1)(f)): abuse prevention, security incident investigation, audit logging.
- Consent (GDPR 6(1)(a)): newsletter subscription, optional services (where applicable).
4. Data retention periods
- Account data: while the account is active, and up to 5 years after deletion (due to legal obligations and legitimate interest).
- Login and audit logs: 12 months, then deleted or anonymized.
- Activation and password reset tokens: immediately after token use or expiration.
5. Data processors, data transfer
The Controller may engage the following data processors:
- Hosting provider: [name to be filled in] — server operations
- Email provider: [name to be filled in] — transactional email delivery
- Developer (MICKEY LAKE DEVELOPER TEAM): system development and maintenance to the extent necessary
Personal data is not transferred to third countries (outside the EU), except where required by law or with explicit user consent.
6. Data subject rights (GDPR)
Every user has the right to:
- request information about data processed about them;
- request rectification of incorrect data;
- request erasure (right to be forgotten), when the legal basis ceases;
- request restriction of processing;
- request data portability (machine-readable export);
- object to processing based on legitimate interest;
- withdraw consent (with future effect).
The user can submit requests via the contact details above. The Controller will respond substantively within 30 days at the latest.
7. Remedies
If a user believes their data is being processed unlawfully, they may file a complaint with:
- Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
- 1055 Budapest, Falk Miksa utca 9-11.
- Phone: +36 (1) 391-1400
- Email: ugyfelszolgalat@naih.hu
- Website: www.naih.hu
The user may also turn to court — at the user's choice, the court of jurisdiction at the user's place of residence or stay.
8. Cookies and technologies
The Service uses cookies essential for operation (session cookies, security tokens). Analytics and marketing cookies are only placed with explicit consent.
9. Data security
The Controller applies technical and organizational measures to protect personal data: encrypted transmission (HTTPS), password hashing, two-factor authentication option, account lockout after failed logins, audit logging, access control.
This page is a placeholder, content under preparation. The final, legally precise Privacy Policy will be published before the official launch of the Service.