Tudatos Diak Iskolaszovetkezet
Help Center
Magyar
+36 1 815 8990[email protected]
Request a Quote

Privacy Notice

Version: v2026-07-06 · Effective from: 6 July 2026
The previous versions (the v2026-05-01 unified notice, as well as 2025-08-01 on tudatosdiak.hu and 2025-05-01 on anyway.hu) are superseded by this notice.

This privacy notice describes the personal-data-processing activities carried out by the joint controllers named in Section 1 (collectively: the “Controller”) in connection with the use of tudatosdiak.hu, anyway.hu, office.tudatosdiak.hu, and the TudatOS Karrier / Partner / Staff mobile applications. This is a single, umbrella notice: the listed legal entities act as joint controllers under Article 26 GDPR, on shared infrastructure and under unified rules. No separate privacy notice applies to any of these services.

This notice has been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (GDPR) and Act CXII of 2011 on Informational Self-Determination and Freedom of Information (“Privacy Act”).

1. § The Controller — Joint Controllers (Article 26 GDPR)

(1) Personal data is processed by the following three Hungarian legal entities as joint controllers:

Tudatos Diák IskolaszövetkezetTudatos Dolgozók Szociális SzövetkezetT-Digital Solutions Kft.
Registered seat1117 Budapest, Dombóvári út 9.2161 Csomád, Kossuth Lajos út 103.1117 Budapest, Dombóvári út 9.
Company reg. no.01-02-05458413-02-05156101-09-428831
Tax no.26777748-2-4332644953-2-1332526620-2-43
Postal address1117 Budapest, Dombóvári út 9.2161 Csomád, Kossuth Lajos út 103.1117 Budapest, Dombóvári út 9.
E-mail[email protected][email protected][email protected]
Represented byAttila Zoltán YilmazLeonárd Henrik SzabóAttila Zoltán Yilmaz

(2) The Controllers have entered into a joint controller arrangement under Article 26(1) GDPR. Its essence is as follows: in the course of the joint processing, T-Digital Solutions Kft. is responsible for fulfilling the administrative obligations relating to the joint processing; data subjects may exercise their rights against any of the joint controllers through a single, unified point of contact.

(3) Single point of contact:
E-mail: [email protected]
Postal address: 1117 Budapest, Dombóvári út 9.
Phone: +36 1 815 8990

(4) Contact details of the Controllers’ Data Protection Officer:
Name: Gábor Varga
E-mail: [email protected] / [email protected] / [email protected]

2. § The Software Operator — Processor (Article 28 GDPR)

(1) The software concerned (the tudatosdiak.hu marketing and recruiting website, the anyway.hu ATS platform, the office.tudatosdiak.hu back-office system and the TudatOS Karrier / Partner / Staff mobile applications) is developed and operated on behalf of the Controller by the following company:

T-Cloud Solutions Kft.
Registered seat1117 Budapest, Dombóvári út 9. 4th floor
Company reg. no.01 09 438601
Tax no.32710148243
ActivitySoftware development, software operation, infrastructure management, technical support

(2) T-Cloud Solutions Kft. processes personal data exclusively on the documented instructions of the Controller, under a written Data Processing Agreement (DPA). T-Cloud Solutions Kft. also engages further sub-processors; the full list is set out in Section 11.

3. § Definitions

  • Processing: any operation or set of operations performed on personal data.
  • Controller: the natural or legal person that determines the purposes and means of the processing of personal data.
  • Joint controller: a controller jointly determining processing under an arrangement pursuant to Article 26 GDPR.
  • Processor: a person that processes personal data on behalf of the controller.
  • Data transfer: making personal data accessible to a third party (recipient).
  • Data subject: the natural person whose personal data is processed by the Controller.
  • Consent: a freely given, specific, informed and unambiguous indication of the data subject’s wishes.
  • Personal data: information relating to an identified or identifiable natural person.
  • Special category data: a category under Article 9 GDPR (e.g. health data).
  • Cookie: a small data file placed on the user’s device.
  • Personal data breach: a breach of the security of personal data.
  • GDPR: Regulation (EU) 2016/679 of the European Parliament and of the Council.
  • Privacy Notice: this document.

4. § Scope of the Notice

(1) This umbrella notice covers the processing carried out by all of the following services; no separate privacy notice applies to any of them:

ServiceSurface
Marketing and recruiting websitetudatosdiak.hu
Student / job-seeker interfacetudatosdiak.hu/karrier, anyway.hu
ATS (applicant and recruitment tracking platform)anyway.hu
Cooperative-membership and payroll back-officeoffice.tudatosdiak.hu
TudatOS Karrier mobile applicationiOS App Store, Google Play
TudatOS Partner mobile applicationiOS App Store, Google Play
TudatOS Staff mobile application (internal)iOS App Store, Google Play
Messaging channelse-mail (Mailjet), SMS (SeeMe), push (FCM / APNs)
External recruitment channelsProfession.hu, Facebook, LinkedIn
AI processing layerAnthropic Claude, Google Gemini

5. § Purposes, Legal Bases, Data Categories and Retention

5.1. Website Registration

Mandatory data: last name, first name, e-mail, password (hashed).
Optional data: phone, language, newsletter opt-in, gender, nationality, sign-up source (UTM, referrer, landing URL).
Purpose: identification of the registered user, account management, communication.
Legal basis: Art. 6(1)(b) GDPR — pre-contractual measures (account agreement).
Retention: until the registration is deleted; if the e-mail is not confirmed, automatic deletion after 90 days; automatic deletion after 2 years of inactivity.

5.2. Detailed Job-Seeker and Membership Profile

Data: address, place and date of birth, mother’s maiden name, nationality, student-ID number, tax-ID, TAJ (social-security) number, bank-account number, parent’s e-mail, languages, work experience, interests, driving licence.
Purpose: job application, preparation of the cooperative-membership relationship.
Legal basis: Art. 6(1)(b) GDPR — contract; for financial/tax fields Art. 6(1)(c) — legal obligation (PIT Act, Social Security Contributions Act).
Retention: until membership is established or the profile is deleted; duration of membership + 5-year limitation period.

5.3. Student ID and Enrolment Certificate Photographs

Data: photo of the front and back of the student ID, student enrolment certificate.
Purpose: verification of cooperative-membership eligibility, verification of student status.
Legal basis: Art. 6(1)(c) GDPR — legal obligation (Act X of 2006).
Retention: automatically deleted from the file storage and the database within 7 days of the announcement; immediately upon rejection.
Recipients: joint controllers; KEF-IF (NEAK / OEP) authority query.

5.4. Occupational-Health Data — Special Category under Article 9 GDPR

Data: examination date, examining physician, place of examination, fitness statement (PDF), validity, FEOR code, position.
Purpose: statutory certification of occupational-health fitness.
Legal basis: Art. 9(2)(b) GDPR — employment-law obligation; Act XCIII of 1993 (Labour Safety Act) §§ 49–55; Decree 33/1998 (VI. 24.) NM.
Retention: 30 years after the employment relationship ends (Labour Safety Act § 64(1)).
Recipients: occupational-health service provider, joint controllers, T-Cloud.

5.5. Cooperative-Membership Contract and Payroll

Data: natural-person identification data, address, tax-ID, TAJ number, bank-account number; data required for family and personal tax allowances (number of children, number of children under 16, child with a disability, single parent, date of first marriage, recent-graduate status).
Purpose: creation and performance of the membership contract, payroll, tax and contribution filings.
Legal basis: Art. 6(1)(b) GDPR (contract) and Art. 6(1)(c) (PIT Act, Social Security Contributions Act, Cooperatives Act, Act X of 2006).
Retention: accounting vouchers: 8 years (Accounting Act § 169); payroll source data: 50 years from the last day of the calendar year following the end of employment (Pension Act § 99/A); other membership data: 5 years (Civil Code).
Recipients: joint controllers, NAV (Online Invoice), payroll provider (Hessyn / RLB), accountant, OTP Bank, Számlázz.hu.

5.6. Signing Identity — Electronic Signature

Data: name at signing, place and date of birth, mother’s name, address; OTP-authentication channel (e-mail / SMS) and recipient; IP address, user-agent; handwritten signature image and seal; RFC 3161 timestamp, hash.
Purpose: provable electronic signature (PAdES) for contracts and authority filings.
Legal basis: Art. 6(1)(b) GDPR — contract + Regulation (EU) 910/2014 (eIDAS).
Retention: limitation period of the relationship underpinned by the contract (generally 5 years, as an accounting voucher 8 years).
Recipients: joint controllers; FreeTSA (timestamping); Wiredsign Zrt.

5.7. Job Application (ATS — Anyway platform)

Data: name, e-mail, phone, CV (PDF), cover letter, content of the job-seeker profile, answers to application questions, time of application.
Purpose: conducting the recruitment procedure, forwarding to the employer partner.
Legal basis: Art. 6(1)(a) GDPR — explicit consent.
Retention: until the given application is closed, up to 60 days from the application; with an “Open to Work” mark (CV-pool opt-in), up to 2 years or until withdrawal.
Recipients: the employer partner selected by the data subject; joint controllers; T-Cloud.

5.8. AI-Based CV Analysis, Application Scoring and Matching

Data sent to the AI: the full text of the CV uploaded by the data subject (PDF), name, e-mail, phone, date of birth, nationality, languages, work experience, driving licence, application answers.
Data NOT sent to the AI: TAJ number, tax-ID, mother’s name, bank-account number, family-tax-allowance data, occupational-health data, password, salary.
Purpose: structured data extraction (editable by the user), scoring of the match to the job, preliminary categorisation (pass / borderline / fail), embedding-based semantic matching.
Legal basis: Art. 6(1)(b) GDPR — efficient performance of the recruitment process.
Automated decision (Article 22 GDPR): no decision producing legal effects concerning the data subject is taken solely on the basis of automated processing; the AI score is merely a ranking aid, and the final HR decision is always taken by a natural-person staff member. The data subject may at any time request that the AI result be disregarded and that an exclusively human evaluation be carried out, using the “Request human review” function available on the interface or by writing to [email protected].
Providers used: Anthropic PBC (Claude), Google LLC (Gemini) — see Section 11.

5.9. Recruitment Communication (e-mail, SMS, push)

Data: e-mail, phone, push token, message content and delivery metadata (time, opens, clicks).
Purpose: notifications about the recruitment process, reminders, job alerts, newsletter.
Legal basis: for service-type messages Art. 6(1)(b) GDPR; for marketing-type messages Art. 6(1)(a) — revocable consent.
Retention: mail and SMS logs: 24 months, then anonymised statistics; push: only until delivery.
Recipients: Mailjet (e-mail), SeeMe / smsapi.hu (SMS), Google FCM and Apple APNs (push).

5.10. Operational, Security and Audit Logs

Data: IP address, user-agent, browsed URL and Laravel route, event type, session ID, mobile app screen, app version, push opens; data-change audit (old and new value, who and when).
Purpose: error handling, fraud and abuse prevention, accountability (Art. 5(2) GDPR).
Legal basis: Art. 6(1)(f) GDPR — legitimate interest.
Right to object: at any time, at [email protected].
Retention: detailed event log: 90 days, then aggregate; financial audit log: 5 years; login and session data: up to 30 days.

5.11. Mobile-Device and App-Event Data

Data: device ID, platform (iOS / Android), OS version, app version, push token, screen-event history.
Purpose: recipient identification for push delivery, measurement of app stability and feature usage.
Legal basis: for push delivery: Art. 6(1)(b) GDPR; for analytics: Art. 6(1)(f) — with an opt-out option.
Retention: push token: as long as the app is installed; mobile event log: 90 days.

5.12. Employer Partner (Company) — Contact and Corporate Data

Data: contact name, e-mail, phone, role; company name, registered seat, tax-ID, company-registry data, representative, basic financial data (from Cégadat / Opten queries).
Purpose: contracting and performance, invoicing, recruitment-project management, partner-risk checks.
Legal basis: Art. 6(1)(b) GDPR contract, Art. 6(1)(c) AML Act, Art. 6(1)(f) legitimate interest.
Retention: duration of the business relationship + 5 years; accounting vouchers 8 years.

6. § Cookies and Website Tracking

On the tudatosdiak.hu, anyway.hu and office.tudatosdiak.hu surfaces we use the following cookies. Consent to non-essential cookies is managed by our own cookie-settings banner(your choice is stored in your browser’s local storage under the td_cookie_consent key); consent can be changed at any time via the “Cookie settings” button placed in the footer.

Strictly necessary cookies

CookieSourcePurposeLifetime
laravel_sessiontudatosdiak.hu / anyway.hu / office.tudatosdiak.huStoring login and session stateuntil end of session or max. 30 days
XSRF-TOKENas aboveProtection against CSRF attacksuntil end of session
remember_web_<hash>as above"Remember me" login persistence5 years (opt-in)
td_cookie_consenttudatosdiak.hu (localStorage)Recording cookie settings (consent)12 months
NEXT_LOCALEtudatosdiak.huRemembering the chosen language (Hungarian / English)1 year

Functional cookies

CookieSourcePurposeLifetime
i18n_localetudatosdiak.hu / anyway.huLanguage selection1 year
theme_preferenceanyway.huLight / dark theme1 year

Statistical (analytics) cookies

CookieSourcePurposeLifetime
_gaGoogle Analytics 4Unique visitor ID2 years
_ga_<container-id>Google Analytics 4Session state2 years
_gidGoogle AnalyticsSession ID24 hours
_clck / _clskMicrosoft ClarityAnonymous behaviour analytics, heatmaps (with consent)1 year / session
td_web_visitor_id, td_session_idtudatosdiak.hu (localStorage) → TudatOSVisit attribution (source, UTM) — only with analytics consent1 year

The analytics and marketing tools (Google Analytics 4, Google Tag Manager, Microsoft Clarity, the Meta Pixel, and the TudatOS visitor-attribution tracker) are loaded only after the relevant consent has been given; Google Tag Manager is the container through which we manage these tags.

Bot and abuse screening

CookieSourcePurposeLifetime
_GRECAPTCHAGoogle reCAPTCHABot and abuse screening on forms6 months
__cf_bmCloudflareBot management30 minutes

Marketing cookies are placed only where the marketing category has been explicitly accepted. Currently we use Google Ads conversion measurement (Enhanced Conversions): with consent, certain data entered when submitting a form (e.g. e-mail, phone number, name) is transmitted to Google for the purpose of matching conversions. In addition, we run a Meta (Facebook) Pixel via Google Tag Manager (provider: Meta Platforms Ireland Ltd.) for remarketing and ad-performance measurement. The Meta Pixel is activated only after the marketing cookie category has been accepted; through its Advanced Matching feature, certain contact data provided by the user (e-mail address, phone number) may be transmitted to Meta in hashed form for the purpose of matching conversions. Meta may also use the data received in accordance with its own privacy policy (facebook.com/privacy/policy); the transfer of data to Meta Platforms, Inc. (USA) takes place under the EU–US Data Privacy Framework (DPF) (see Section 9). We do not currently run any LinkedIn pixel. The on-site chat assistant is loaded from our own system (app.tudatosdiak.hu); the handling of conversations is governed by Section 7 (AI).

We use Google Analytics 4 with IP anonymisation; the Google Signals advertising features are disabled. Data is transferred under the EU–US Data Privacy Framework (DPF) (see Section 9).

7. § AI Processing and Automated Decision-Making

(1) To speed up the recruitment and application process, we use large language models (LLMs) and vector-embedding models. These models run at external providers, within a processor relationship with the Controller and under EU–US DPF certification.

ProviderModel familyPurpose
Anthropic PBCClaude Sonnet 4.x, Claude HaikuCV analysis (fallback), student-ID OCR, report generation, e-mail-text generation, internal assistant
Google LLCGemini 2.5 Pro, Flash, EmbeddingCV analysis (primary), embedding-based job matching, translation, ad-copy generation

(2) No decision producing legal effects concerning the data subject is taken solely on the basis of automated processing. The AI score is a ranking aid; the final HR decision is in all cases taken by a natural-person staff member.

(3) The data subject’s rights in relation to AI processing (Article 22 GDPR):

  • Request human review — the “Request human review” function is available on every AI-related screen;
  • Fully disable AI processing in the profile settings;
  • Request an explanation of an AI decision in human language;
  • Delete / modify AI-extracted data in the profile;
  • Object at any time at [email protected].

(4) Anthropic and Google provide contractual guarantees that data submitted via the API is not used for model training (zero-retention API mode). At the providers, data is stored temporarily for abuse-investigation purposes (typically for up to 30 days), after which it is automatically deleted.

8. § Mobile Application Permissions

The TudatOS Group operates three mobile applications. Application permissions can be revoked at any time at the operating-system level (iOS → Settings → Privacy; Android → App permissions). Neither application uses geolocation or contacts.

TudatOS Karrier (job-seeker) — hu.tudatosdiak.career

PermissionPurposeMandatory?
InternetAPI connectionyes
Notifications (push)Job alerts, interview and occupational-health remindersno
CameraStudent-ID photo, profile avatar (7-day auto-delete)no (only on use)
Apple Sign-In / Google Sign-InQuick loginno
Biometric (Face ID / Touch ID)Quick login (local, never leaves the device)no
Phone call (tel: link)Calling a job contactno
Local storage (Capacitor Preferences)Login token, UI preferencesyes

TudatOS Partner (employer) — hu.tudatosdiak.partner

PermissionPurposeMandatory?
InternetAPI connectionyes
Notifications (push)New application, interview slot, contract statusno
BiometricQuick loginno
Phone call (tel:)Calling an applicantno
Local storageLogin token, multi-company switcher, UIyes

TudatOS Staff (internal) — hu.tudatosdiak.staff

PermissionPurposeMandatory?
InternetAPI connectionyes
Notifications (push)Check-in reminder, tickets, sales/recruiter eventsno
BiometricQuick loginno
Phone call (tel:)Calling a partner / applicant from the CRMno
Local storageLogin token, role-override, call logyes

The check-in feature records only a timestamp; it does not record GPS coordinates.

9. § International Data Transfers

Some processors are established outside the European Economic Area (EEA). Such transfers always take place with appropriate safeguards:

RecipientDataCountryLegal basis
DigitalOcean LLCHosting, file storage (Spaces)USAEU–US DPF + SCC fallback
Cloudflare Inc.DNS, CDN, WAFUSAEU–US DPF
Anthropic PBCAI (Claude)USAEU–US DPF
Google LLCAI (Gemini), FCM, OAuth, Maps, AnalyticsUSAEU–US DPF
Google reCAPTCHA (Google LLC)Bot and abuse screeningUSAEU–US DPF
Meta Platforms, Inc.Meta Pixel — remarketing, conversion measurement (hashed e-mail address, phone number)USAEU–US DPF
Apple Inc.App Store, Sign In, APNsUSAEU–US DPF
Canva Pty Ltd.Marketing materialsAustraliaAdequacy decision

The status of the certifications can be checked at dataprivacyframework.gov. The EU 2021/914 standard data-protection contractual clauses (SCC) are available on request at [email protected].

10. § Domestic Data Transfers

RecipientDataLegal basis
NAV (National Tax and Customs Administration)Tax data, invoices, filingsLegal obligation
OH / NEAK / OEP (KEF-IF)Student status verificationLegal obligation
Court, prosecutor, investigating authorityData as per the requestLegal obligation
Employer partner (job applied for)Name, contact, CV, application answersData subject consent
Occupational-health service providerOccupational-health dataLegal obligation (Labour Safety Act)
OTP BankBank account, payout dataPerformance of contract
Hessyn / RLBPayroll dataProcessor (DPA)
Számlázz.huInvoicing dataProcessor (DPA)

11. § Processors and Sub-Processors

T-Cloud Solutions Kft. (as the Controller’s processor) engages the following sub-processors. It notifies the Controller before engaging a new sub-processor.

#CompanySeatActivity
1T-Cloud Solutions Kft.1117 Budapest, Dombóvári út 9. 4th floorSoftware development, operation
2DigitalOcean LLCNew York, USAHosting, storage (Spaces)
3Cloudflare Inc.San Francisco, USADNS, CDN, WAF
4Anthropic PBCSan Francisco, USAAI (Claude)
5Google LLCMountain View, USAAI (Gemini), FCM, OAuth, Maps, Analytics
6Apple Inc.Cupertino, USAApp Store, Sign In, APNs
7Microsoft Ireland Operations Ltd.Dublin, IEOffice 365
8Mailjet SAS (Sinch Group)Paris, FRTransactional and marketing e-mail
9SeeMe Solutions Kft. (smsapi.hu)BudapestSMS gateway
10Wiredsign Zrt.DiósjenőElectronic signature
11FreeTSAGermanyRFC 3161 timestamping
12Hessyn Szoftver Informatikai Kft.BudapestPayroll software
13RLB-60 Bt.HatvanPayroll software
14FireBird Foundation z.s.Prague, CZDatabase software
15KBOSS.hu Kft. (Számlázz.hu)BudapestInvoicing
16OTP Bank Nyrt.BudapestBanking transactions (Elektra)
17Cégadat API operatorBudapestCompany-registry query
18Opten Kft.BudapestCompany data / risk
19Canva Pty Ltd.Sydney, AustraliaDesign tool (marketing)
20MiniCRM Zrt.BudapestInternal CRM
21Profession.hu (DBH-Group)BudapestRecruitment channel
22tárhely.eu kft.BudapestStatic website hosting
23Meta Platforms Ireland Ltd.Dublin, IEMeta Pixel — remarketing, conversion measurement, only with marketing consent

12. § Retention Periods

Data categoryPeriod
Active membershipRelationship + 5-year limitation period
Accounting data8 years (Accounting Act § 169)
E-mail-unverified registration90 days
Student ID + enrolment certificate photo7 days after the announcement
Occupational-health dataEnd of employment + 30 years (Labour Safety Act)
Application (ATS)60 days / "Open to Work" pool: 2 years
Mail and SMS logs24 months
Detailed event log90 days
Login and session30 days
Financial audit log5 years
Signature image and signature metadataLimitation period of the contract (5 years) / accounting (8 years)
Backup7 days
CookiesIndividual lifetime listed in the cookie table (see Section 6)

13. § Data Security Measures

  • Encryption: TLS 1.2+ (HTTPS) for all communication; AES-256 encryption at rest on the databases and the DigitalOcean Spaces storage.
  • Access control: role-based access control (RBAC), two-factor login on the staff interface, password hashing (bcrypt).
  • Logging and audit: every material change is audit-logged, recording the old and new values.
  • Backup: daily backup, 7-day recovery point; automatic overwrite; restoration only with the approval of an executive officer.
  • WAF and DDoS protection: Cloudflare.
  • Staff confidentiality obligation under contract; annual data-protection training for staff with access rights.

14. § Data-Subject Rights

Under the GDPR, the data subject has the following rights. The rights may be exercised at [email protected] or in the user account (“My Data → GDPR requests”). The data subject may exercise their rights against any of the joint controllers through the single point of contact. We provide our response within 1 month, extendable in justified cases by a further 2 months.

  1. Right of access (Article 15 GDPR) — self-service JSON/CSV data export available.
  2. Right to rectification (Article 16) — generally directly in the profile.
  3. Right to erasure / “right to be forgotten” (Article 17).
  4. Right to restriction of processing (Article 18).
  5. Right to data portability (Article 20) — JSON/CSV.
  6. Right to object (Article 21) — against processing based on legitimate interest.
  7. Right to withdraw consent (Article 7(3)) — at any time; withdrawal does not affect the lawfulness of processing before withdrawal.
  8. Rights related to automated decision-making (Article 22) — human review, expression of a point of view, contesting the decision. A “Request human review” button is available on every AI-related screen.
  9. Right to lodge a complaint with a supervisory authority (Article 77) — NAIH (see Section 16).
  10. Right to a judicial remedy (Article 79) — the regional court competent for the place of residence (birosag.hu/torvenyszekek).
  11. Rights of a deceased data subject — upon presentation of the death certificate and proof of identity, a close relative under the Civil Code may exercise the data-subject rights within 5 years of the death (Act LIII of 2018 §§ 25/G–25/J).

15. § Personal Data Breach

(1) Upon detecting a personal data breach, the Controller notifies NAIH without undue delay, but at the latest within 72 hours (Article 33 GDPR).

(2) Where the breach is likely to result in a high risk to the rights and freedoms of data subjects, we also notify the data subjects directly (Article 34 GDPR).

(3) We keep an internal register of breaches: categories and number of data subjects affected, time, circumstances, effects, and measures taken.

16. § Supervisory Authority

The data subject has the right to lodge a complaint with the supervisory authority:
Hungarian National Authority for Data Protection and Freedom of Information (NAIH)
Address: 1055 Budapest, Falk Miksa u. 9–11.
Postal address: 1363 Budapest, P.O. Box 9.
Phone: +36 1 391 1400
E-mail: [email protected]
Web: naih.hu

17. § Final Provisions — Version Control

(1) The Controller reserves the right to amend this notice unilaterally (in particular in the event of a change in legislation). We inform data subjects of material changes in advance through the main communication channel (e-mail, application login screen, website header).

(2) On their first login after a new version takes effect, the data subject confirms that they have read the new notice; the time, IP address and browser characteristics of this are recorded in the policy_acceptances log.

(3) Version v2026-07-06 of this Privacy Notice is effective from 6 July 2026.